Windows CreateRemoteThread in mstsc.exe From Suspicious Source Paths

Alerts when mstsc.exe creates remote threads from processes running out of common suspicious directories.

FreeReviewedSigma · High · v2
Product
windows
Category
create_remote_thread
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-07-28
Updated
2026-07-31

What it detects

This rule identifies create-remote-thread activity where the target process is mstsc.exe, and the creating process originates from paths commonly associated with staging or temporary files. Attackers may use this behavior to inject or hook into mstsc.exe during RDP-related workflows to enable credential theft. Telemetry relied upon is process creation events that include both the target image (mstsc.exe) and the source image path for the remote thread creator.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.