Windows mstsc.exe launched with local .rdp file argument
Alerts on mstsc.exe executions that reference local .rdp files via the command line.
- Product
- windows
- Category
- process_creation
- Author
- Nasreddine Bencherchali (Nextron Systems), Christopher Peacock @securepeacock (SigmaHQ), DRL 1.1
- Published
- 2023-04-18
- Updated
- 2026-07-30
ATT&CK techniques
C2Recon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact
What it detects
This rule flags process creation where mstsc.exe is executed with a command line ending in a local .rdp file path. Attackers can use mstsc with crafted or staged RDP connection files to initiate unauthorized remote sessions and move from initial access to command and control. It relies on Windows process creation telemetry, including the image name (or original filename) and the command line containing a .rdp argument.
Reporting behind it
- blackhillsinfosec.comhttps://www.blackhillsinfosec.com/rogue-rdp-revisiting-initial-access-methods/
- web.archive.orghttps://web.archive.org/web/20230726144748/https://blog.thickmints.dev/mintsights/detecting-rogue-rdp/
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_mstsc_run_local_rdp_file.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows mstsc.exe launched with local .rdp file argument
id: e3790948-b43d-4327-b767-76e8af78173b
status: test
description: This rule flags process creation where mstsc.exe is executed with a command line ending in a local .rdp file path. Attackers can use mstsc with crafted or staged RDP connection files to initiate unauthorized remote sessions and move from initial access to command and control. It relies on Windows process creation telemetry, including the image name (or original filename) and the command line containing a .rdp argument.
references:
- https://www.blackhillsinfosec.com/rogue-rdp-revisiting-initial-access-methods/
- https://web.archive.org/web/20230726144748/https://blog.thickmints.dev/mintsights/detecting-rogue-rdp/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_mstsc_run_local_rdp_file.yml
author: Nasreddine Bencherchali (Nextron Systems), Christopher Peacock @securepeacock, Huntrule Team
date: 2023-04-18
modified: 2023-04-30
tags:
- attack.command-and-control
- attack.t1219.002
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith: \mstsc.exe
- OriginalFileName: mstsc.exe
selection_cli:
CommandLine|endswith:
- .rdp
- .rdp"
filter_optional_wsl:
ParentImage: C:\Windows\System32\lxss\wslhost.exe
CommandLine|contains: C:\ProgramData\Microsoft\WSL\wslg.rdp
condition: all of selection_* and not 1 of filter_optional_*
falsepositives:
- Likely with legitimate usage of ".rdp" files
level: low
license: DRL-1.1
related:
- id: 5fdce3ac-e7f9-4ecd-a3aa-a4d78ebbf0af
type: derived