OpenCanary VNC Connection Attempt Observed
Alerts when OpenCanary records a VNC service connection attempt on an instrumented node.
- Product
- opencanary
- Category
- application
- Author
- Security Onion Solutions (SigmaHQ), DRL 1.1
- Published
- 2024-03-08
- Updated
- 2026-07-31
ATT&CK techniques
Lateral MovementRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies OpenCanary instances where a VNC service connection attempt is recorded. Attackers commonly probe remote desktop interfaces to test access or prepare lateral movement, so connection attempts are a useful signal for exposure. It relies on OpenCanary application telemetry events indicating a VNC-related connection attempt, matched by the specific logtype value.
Reporting behind it
- opencanary.readthedocs.iohttps://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration
- github.comhttps://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/application/opencanary/opencanary_vnc_connection_attempt.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: OpenCanary VNC Connection Attempt Observed
id: e20f4314-064d-4268-b9d5-6cdf97d14323
status: test
description: This rule identifies OpenCanary instances where a VNC service connection attempt is recorded. Attackers commonly probe remote desktop interfaces to test access or prepare lateral movement, so connection attempts are a useful signal for exposure. It relies on OpenCanary application telemetry events indicating a VNC-related connection attempt, matched by the specific logtype value.
references:
- https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration
- https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52
- https://github.com/SigmaHQ/sigma/blob/master/rules/application/opencanary/opencanary_vnc_connection_attempt.yml
author: Security Onion Solutions, Huntrule Team
date: 2024-03-08
tags:
- attack.lateral-movement
- attack.t1021
logsource:
category: application
product: opencanary
detection:
selection:
logtype: 12001
condition: selection
falsepositives:
- Unlikely
level: high
license: DRL-1.1
related:
- id: 9db5446c-b44a-4291-8b89-fcab5609c3b3
type: derived