Radmin Viewer Utility Execution on Windows (Process Creation)

Alerts when Radmin Viewer (Radmin.exe) is launched, based on process metadata in Windows process creation logs.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-01-22
Updated
2026-07-30

ATT&CK techniques

Execution → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags process creation events where the executable is identified as Radmin Viewer (Radmin.exe) via the Description, Product, and OriginalFileName fields. Radmin can be used for remote control of Windows machines, so its execution may indicate legitimate remote administration or malicious lateral movement. The detection relies on Windows process creation telemetry containing executable metadata.

Related detections3 linkedT1072 — drag to rearrange
Windows SRP restricted application access (Event IDs 865, 866, 867, 868, 882)
Windows PDQ Deploy Console Execution
Windows Process Creation: Suspicious Microsoft Csi.exe or Rcsi.exe with C# Execution Capability
Radmin Viewer Utility Execution on Windows (Process Creation)
Pivot detection · T1072 · 3 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.