Windows MSTSC Shadowing CommandLine Using shadow:

Flags Windows processes launching MSTSC with noconsentprompt and shadow: parameters consistent with RDP session shadowing.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2020-01-24
Updated
2026-07-30

ATT&CK techniques

Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule identifies RDP session shadowing activity on Windows by matching process command lines containing both 'noconsentprompt' and 'shadow:'. Attackers use MSTSC shadowing to observe or interact with an existing user session without establishing a typical new session channel. It relies on process creation telemetry with command-line arguments to reliably capture these distinctive parameters.

Related detections4 linkedT1563.002 — drag to rearrange
Malicious RDP Session Hijacking via tscon Command Line
Malicious Service Creation to Execute tscon for RDP Session Hijacking
Malicious RDP Session Hijack via Service Creation Abuse (via security)
Windows Suspicious RDP Session Redirect via tscon.exe /dest:rdp-tcp#
Windows MSTSC Shadowing CommandLine Using shadow:
Pivot detection · T1563.002 · 4 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.