Windows RDP Session Hijacking via tscon.exe from System Integrity

Flags tscon.exe executions on Windows running at System integrity, indicating potential RDP session hijacking.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
@juju4 (SigmaHQ), DRL 1.1
Published
2022-12-27
Updated
2026-07-30

What it detects

This rule identifies suspicious use of tscon.exe associated with RDP session redirection or hijacking. It focuses on process creation events where tscon.exe executes with a high integrity level (System), which attackers may abuse to take control of sessions or move them between contexts. Telemetry relies on Windows process creation logs, including the image path or OriginalFileName and the process integrity level.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.