ScreenConnect Service temp XML user database file modification (Windows Event 4663)

Alerts when ScreenConnect.Service.exe performs write access to temporary ScreenConnect XML user database files on Windows.

FreeReviewedSigma · Medium · v5
Product
windows
Service
security
Author
Matt Anderson, Kris Luzadre, Andrew Schwartz, Huntress (SigmaHQ), DRL 1.1
Published
2024-02-20
Updated
2026-07-31

What it detects

This rule flags attempts by ScreenConnect.Service.exe to modify a temporary XML user database file by matching Windows Security Event ID 4663 for file access with an ObjectType of File and an AccessMask of 0x6. Attackers may use this to alter local user or permission data during ScreenConnect exploitation, though the same telemetry can also occur during legitimate user or permission changes. The detection relies on detailed file auditing (successful 4663 events) enabled via SACLs on the ScreenConnect directory so file modifications to matching .xml Temp/ScreenConnect files are recorded.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.