RPC Firewall detects remote scheduled task reconnaissance via AtScv
Identifies remote AtScv RPC calls that access scheduled task information via RPC Firewall telemetry.
FreeUnreviewedSigmahighv1
rpc-firewall-detects-remote-scheduled-task-reconnaissance-via-atscv-f177f2bc
title: RPC Firewall detects remote scheduled task reconnaissance via AtScv
id: 41803828-6853-42da-86c3-dd0931b7c849
status: test
description: This rule flags RPC Firewall events indicating remote procedure calls to the AtScv interface used to read scheduled task information. Attackers can use scheduled task data to understand persistence mechanisms and plan follow-on actions. The detection relies on RPC Firewall logs (EventLog RPCFW), specifically EventID 3 with the AtScv interface UUID, while allowing only non-operation-number 0 or 1 calls.
references:
- https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-tsch/d1058a28-7e02-4948-8b8d-4a347fa64931
- https://github.com/zeronetworks/rpcfirewall
- https://github.com/jsecurity101/MSRPC-to-ATTACK/blob/ddd4608fe8684fcf2fcf9b48c5f0b3c28097f8a3/documents/MS-TSCH.md
- https://zeronetworks.com/blog/stopping-lateral-movement-via-the-rpc-firewall/
- https://github.com/SigmaHQ/sigma/blob/master/rules/application/rpc_firewall/rpc_firewall_atsvc_recon.yml
author: Sagie Dulce, Dekel Paz, Huntrule Team
date: 2022-01-01
tags:
- attack.discovery
logsource:
product: rpc_firewall
category: application
definition: 'Requirements: install and apply the RPC Firewall to all processes with "audit:true action:block uuid:1ff70682-0a51-30e8-076d-740be8cee98b"'
detection:
selection:
EventLog: RPCFW
EventID: 3
InterfaceUuid: 1ff70682-0a51-30e8-076d-740be8cee98b
filter:
OpNum:
- 0
- 1
condition: selection and not filter
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: f177f2bc-5f3e-4453-b599-57eefce9a59c
type: derived
What it detects
This rule flags RPC Firewall events indicating remote procedure calls to the AtScv interface used to read scheduled task information. Attackers can use scheduled task data to understand persistence mechanisms and plan follow-on actions. The detection relies on RPC Firewall logs (EventLog RPCFW), specifically EventID 3 with the AtScv interface UUID, while allowing only non-operation-number 0 or 1 calls.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.