Windows: Detect tscon.exe launched under SYSTEM context
Alerts on tscon.exe starting under a SYSTEM-associated user context based on Windows process creation logs.
FreeUnreviewedSigmahighv1
windows-detect-tscon-exe-launched-under-system-context-9847f263
title: "Windows: Detect tscon.exe launched under SYSTEM context"
id: d7c1aa79-4313-437b-9123-2be8b7523264
status: test
description: This rule flags process creations where tscon.exe is started and the recorded user context contains strings like 'AUTHORI' or 'AUTORI', consistent with execution as LOCAL SYSTEM. Attackers can use tscon to redirect or hijack sessions while operating with high privileges, making anomalous SYSTEM-context launches high risk. The detection relies on Windows process creation telemetry, matching the tscon.exe image filename and specific user-context substrings.
references:
- http://www.korznikov.com/2017/03/0-day-or-feature-privilege-escalation.html
- https://medium.com/@networksecurity/rdp-hijacking-how-to-hijack-rds-and-remoteapp-sessions-transparently-to-move-through-an-da2a1e73a5f6
- https://www.ired.team/offensive-security/lateral-movement/t1076-rdp-hijacking-for-lateral-movement
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_tscon_localsystem.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2018-03-17
modified: 2022-05-27
tags:
- attack.command-and-control
- attack.t1219.002
logsource:
category: process_creation
product: windows
detection:
selection:
User|contains:
- AUTHORI
- AUTORI
Image|endswith: \tscon.exe
condition: selection
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: 9847f263-4a81-424f-970c-875dab15b79b
type: derived
What it detects
This rule flags process creations where tscon.exe is started and the recorded user context contains strings like 'AUTHORI' or 'AUTORI', consistent with execution as LOCAL SYSTEM. Attackers can use tscon to redirect or hijack sessions while operating with high privileges, making anomalous SYSTEM-context launches high risk. The detection relies on Windows process creation telemetry, matching the tscon.exe image filename and specific user-context substrings.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.