OpenCanary VNC Connection Attempt Observed

Alerts when OpenCanary records a VNC service connection attempt on an instrumented node.

FreeReviewedSigma · High · v5
Product
opencanary
Category
application
Author
Security Onion Solutions (SigmaHQ), DRL 1.1
Published
2024-03-08
Updated
2026-07-31

ATT&CK techniques

Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule identifies OpenCanary instances where a VNC service connection attempt is recorded. Attackers commonly probe remote desktop interfaces to test access or prepare lateral movement, so connection attempts are a useful signal for exposure. It relies on OpenCanary application telemetry events indicating a VNC-related connection attempt, matched by the specific logtype value.

Related detections9 linkedT1021 — drag to rearrange
Suspicious LocalAccountTokenFilterPolicy Enabled via Registry by BlackByte Ransomware
Windows: Detect NetExec (nxc.exe) Process Execution with Network Service Commands
OpenCanary SMB service records file open requests
OpenCanary FTP Login Attempt on Port 2000
OpenCanary application logs: SSH new connection attempt on monitored node
OpenCanary SNMP OID Requests Observed on Node
OpenCanary Application Logs: SSH Login Attempt on Monitoring Node
Windows Process Creation: SSH Port-Forwarding Commands Targeting RDP (3389)
Windows PsExec Execution Triggered by psexec.exe Process Creation
OpenCanary VNC Connection Attempt Observed
Pivot detection · T1021 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.