Remote Access Utility - ScreenConnect Potential Suspicious Remote Command Execution (via process_creation)
This rule detects potentially anomalous child processes launched via the ScreenConnect client service.
SigmamediumWindowsv1
sigma
remote-access-utility-screenconnect-potential-suspicious-remote-command-execution-via-process-creation
title: Remote Access Utility - ScreenConnect Potential Suspicious Remote Command Execution (via process_creation)
id: d8abce51-5fb4-5680-876f-0b89dd9a319f
status: stable
description: This rule detects potentially anomalous child processes launched via the ScreenConnect client service.
references:
- https://attack.mitre.org/techniques/T1219/002/
- https://www.mandiant.com/resources/telegram-malware-iranian-espionage
- https://docs.connectwise.com/ConnectWise_Control_Documentation/Get_started/Host_client/View_menu/Backstage_mode
- https://www.huntress.com/blog/slashandgrab-screen-connect-post-exploitation-in-the-wild-cve-2024-1709-cve-2024-1708
- https://www.trendmicro.com/en_us/research/24/b/threat-actor-groups-including-black-basta-are-exploiting-recent-.html
author: Huntrule Team
date: 2026-03-05
tags:
- attack.command-and-control
- attack.t1219.002
logsource:
product: windows
category: process_creation
detection:
selection:
ParentCommandLine|contains|all:
- ':\Windows\TEMP\ScreenConnect\'
- 'run.cmd'
Image|endswith:
- '\bitsadmin.exe'
- '\cmd.exe'
- '\curl.exe'
- '\dllhost.exe'
- '\net.exe'
- '\nltest.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\rundll32.exe'
- '\wevtutil.exe'
condition: selection
falsepositives:
- Unknown
level: medium
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.