Windows: AnyDesk Execution Using Revoked Certificate Versions

Detects AnyDesk.exe execution on Windows when the file version matches known revoked-certificate releases (excluding uninstall/remove).

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Sai Prashanth Pulisetti, Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2024-02-08
Updated
2026-07-30

What it detects

This rule flags process creation events where AnyDesk is launched and the binary’s file version indicates a release prior to 8.0.8 (specific 7.x and 8.0.1–8.0.7 versions). Older versions are associated with a previously compromised signing certificate, so attackers could potentially sign binaries to evade detections. It relies on Windows process creation telemetry and file version information from the executed AnyDesk.exe. It excludes uninstall/remove command-line activity to reduce noise.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.