Windows: Detect tscon.exe launched under SYSTEM context

Alerts on tscon.exe starting under a SYSTEM-associated user context based on Windows process creation logs.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2018-03-17
Updated
2026-07-30
title: "Windows: Detect tscon.exe launched under SYSTEM context"
id: d7c1aa79-4313-437b-9123-2be8b7523264
status: test
description: This rule flags process creations where tscon.exe is started and the recorded user context contains strings like 'AUTHORI' or 'AUTORI', consistent with execution as LOCAL SYSTEM. Attackers can use tscon to redirect or hijack sessions while operating with high privileges, making anomalous SYSTEM-context launches high risk. The detection relies on Windows process creation telemetry, matching the tscon.exe image filename and specific user-context substrings.
references:
  - http://www.korznikov.com/2017/03/0-day-or-feature-privilege-escalation.html
  - https://medium.com/@networksecurity/rdp-hijacking-how-to-hijack-rds-and-remoteapp-sessions-transparently-to-move-through-an-da2a1e73a5f6
  - https://www.ired.team/offensive-security/lateral-movement/t1076-rdp-hijacking-for-lateral-movement
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_tscon_localsystem.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2018-03-17
modified: 2022-05-27
tags:
  - attack.command-and-control
  - attack.t1219.002
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    User|contains:
      - AUTHORI
      - AUTORI
    Image|endswith: \tscon.exe
  condition: selection
falsepositives:
  - Unknown
level: high
license: DRL-1.1
related:
  - id: 9847f263-4a81-424f-970c-875dab15b79b
    type: derived