Windows ScreenConnect Installation Execution via Remote Access Parameters

Flags Windows executions of ScreenConnect with remote access command-line parameters indicating remote session setup.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2021-02-11
Updated
2026-07-30

ATT&CK techniques

Initial Access → Persistence
  1. Recon

  2. Resource Dev

  3. Execution

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule matches Windows process creation events where the command line contains ScreenConnect-specific remote access parameters (e=Access, y=Guest, and p=, c=, k=). Attackers commonly use remote access tooling to establish interactive control and persistence after initial access. The detection relies on process creation telemetry, specifically the full command-line string in process start events.

Related detections9 linkedT1133 — drag to rearrange
Suspicious Security Group Ingress Rule Opened to the Internet via CloudTrail
SplashTop Network
Suspicious SoftEther VPN Hamcore Config Written to ProgramData (via file_event)
SplashTop Process
AnyDesk Network
OpenCanary RDP New Connection Attempt on Application Logtype 14001
ArcSOC.exe Creates Suspicious Script/Executable Files on Windows
FortiGate: Addition of VPN SSL Web Portal via Event Logs
FortiGate SSL VPN Settings Edited
Windows ScreenConnect Installation Execution via Remote Access Parameters
Pivot detection · T1133 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.