Windows WFP Event 5156: RDP traffic via loopback when hosted by svchost termsvcs

Flags Windows EventID 5156 where svchost RDP (3389) traffic targets loopback addresses, suggesting tunneled local RDP usage.

FreeReviewedSigma · High · v2
Product
windows
Service
security
Author
Samir Bousseaden (SigmaHQ), DRL 1.1
Published
2019-02-16
Updated
2026-07-31

ATT&CK techniques

Lateral Movement → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Collection

  11. Exfiltration

  12. Impact

What it detects

Identifies Windows Security audit events (EventID 5156) where RDP port 3389 is used with loopback destinations/sources (127.* or ::1), with activity tied to svchost hosting termsvcs. This pattern can indicate an RDP session being tunneled or proxied locally using a reverse SSH-style loopback flow. The rule relies on Security log telemetry capturing WFP connection details, including ports and loopback IP matching, and filters out AppContainer loopback noise and thor.exe usage.

Related detections9 linkedT1021.001 — drag to rearrange
Suspicious Enabling of Remote Desktop via fDenyTSConnections Registry by DeadLock Ransomware
Malicious SOCKS Proxy Tunnel via Earthworm Rssocks by UAT-8837
Suspicious Plink SSH Tunnel Execution (via process_creation)
Suspicious Remote Desktop Enabled via fDenyTSConnections Registry by Sandworm
Suspicious RDP Shadow Session Started - Native (via rdp)
Malicious RDP BlueeKeep Connection Closed - CVE-2019-0708 (via rdp)
Obfuscated RDP Tunneling Configuration Enabled for Port Forwarding (via process_creation)
Malicious RDP Shadow Session Configuration Enabled - Registry (via registry_event)
Malicious RDP Tunneling (via rdp)
Windows WFP Event 5156: RDP traffic via loopback when hosted by svchost termsvcs
Pivot detection · T1021.001 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.