Windows: Detect tscon.exe launched under SYSTEM context

Alerts on tscon.exe starting under a SYSTEM-associated user context based on Windows process creation logs.

FreeUnreviewedSigmahighv1
title: "Windows: Detect tscon.exe launched under SYSTEM context"
id: d7c1aa79-4313-437b-9123-2be8b7523264
status: test
description: This rule flags process creations where tscon.exe is started and the recorded user context contains strings like 'AUTHORI' or 'AUTORI', consistent with execution as LOCAL SYSTEM. Attackers can use tscon to redirect or hijack sessions while operating with high privileges, making anomalous SYSTEM-context launches high risk. The detection relies on Windows process creation telemetry, matching the tscon.exe image filename and specific user-context substrings.
references:
  - http://www.korznikov.com/2017/03/0-day-or-feature-privilege-escalation.html
  - https://medium.com/@networksecurity/rdp-hijacking-how-to-hijack-rds-and-remoteapp-sessions-transparently-to-move-through-an-da2a1e73a5f6
  - https://www.ired.team/offensive-security/lateral-movement/t1076-rdp-hijacking-for-lateral-movement
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_tscon_localsystem.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2018-03-17
modified: 2022-05-27
tags:
  - attack.command-and-control
  - attack.t1219.002
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    User|contains:
      - AUTHORI
      - AUTORI
    Image|endswith: \tscon.exe
  condition: selection
falsepositives:
  - Unknown
level: high
license: DRL-1.1
related:
  - id: 9847f263-4a81-424f-970c-875dab15b79b
    type: derived

What it detects

This rule flags process creations where tscon.exe is started and the recorded user context contains strings like 'AUTHORI' or 'AUTORI', consistent with execution as LOCAL SYSTEM. Attackers can use tscon to redirect or hijack sessions while operating with high privileges, making anomalous SYSTEM-context launches high risk. The detection relies on Windows process creation telemetry, matching the tscon.exe image filename and specific user-context substrings.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.