Suspicious Use of Windows Quick Assist as Observed in UNC6692 Attacks
Detects the execution of Quick Assist, as leveraged by UNC6692 for post-phishing IT impersonation and lateral movement.
Sigmamediumv12026-07-28
sigmasuspicious-use-of-windows-quick-assist-as-observed-in-unc6692-attacks-37cf84fe
title: Suspicious Use of Windows Quick Assist as Observed in UNC6692 Attacks
id: 9b56d7b8-cd7c-4f06-bc18-f06d76e0454d
description: Detects the launch of Quick Assist (quickassist.exe), a remote assistance tool, which was abused by UNC6692 for remote control after IT impersonation and email bombing attacks.
logsource:
product: windows
category: process_creation
detection:
selection:
Image|endswith: '\\quickassist.exe'
condition: selection
level: medium
references:
- https://www.esentire.com/blog/email-bombing-it-impersonation-quick-assist-and-edgecution-breaking-down-unc6692s-tradecraft
tags:
- attack.t1219
falsepositives:
- Legitimate use of Quick Assist by IT support or helpdesk
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.