Windows Process Creation: SSH Port-Forwarding Commands Targeting RDP (3389)

Flags Windows command lines using SSH port-forwarding switches that also reference RDP port :3389.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Tim Rauch, Elastic (idea) (SigmaHQ), DRL 1.1
Published
2022-09-27
Updated
2026-07-30

ATT&CK techniques

Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule flags Windows process creation events where the command line includes the RDP port indicator ':3389' along with common SSH port-forwarding related switches. Attackers can use SSH tunnels to forward or route RDP traffic through intermediate hosts, helping them reach systems that would otherwise be unreachable. The detection relies on process command-line telemetry to identify these tunneling patterns.

Related detections9 linkedT1021 — drag to rearrange
Suspicious LocalAccountTokenFilterPolicy Enabled via Registry by BlackByte Ransomware
Windows: Detect NetExec (nxc.exe) Process Execution with Network Service Commands
OpenCanary SMB service records file open requests
OpenCanary FTP Login Attempt on Port 2000
OpenCanary VNC Connection Attempt Observed
OpenCanary application logs: SSH new connection attempt on monitored node
OpenCanary SNMP OID Requests Observed on Node
OpenCanary Application Logs: SSH Login Attempt on Monitoring Node
Windows PsExec Execution Triggered by psexec.exe Process Creation
Windows Process Creation: SSH Port-Forwarding Commands Targeting RDP (3389)
Pivot detection · T1021 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.