Suspicious Use of Windows Quick Assist as Observed in UNC6692 Attacks

Detects the execution of Quick Assist, as leveraged by UNC6692 for post-phishing IT impersonation and lateral movement.

Sigmamediumv12026-07-28
sigmasuspicious-use-of-windows-quick-assist-as-observed-in-unc6692-attacks-37cf84fe
title: Suspicious Use of Windows Quick Assist as Observed in UNC6692 Attacks
id: 9b56d7b8-cd7c-4f06-bc18-f06d76e0454d
description: Detects the launch of Quick Assist (quickassist.exe), a remote assistance tool, which was abused by UNC6692 for remote control after IT impersonation and email bombing attacks.
logsource:
  product: windows
  category: process_creation
detection:
  selection:
    Image|endswith: '\\quickassist.exe'
  condition: selection
level: medium
references:
  - https://www.esentire.com/blog/email-bombing-it-impersonation-quick-assist-and-edgecution-breaking-down-unc6692s-tradecraft
tags:
  - attack.t1219
falsepositives:
  - Legitimate use of Quick Assist by IT support or helpdesk

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.