Windows Suspicious RDP Session Redirect via tscon.exe /dest:rdp-tcp#

Alerts on Windows process executions using tscon.exe-style RDP redirection to an "rdp-tcp#" destination.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2018-03-17
Updated
2026-07-30

ATT&CK techniques

Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags process creation events where the command line contains " /dest:rdp-tcp#", indicating use of tscon.exe to redirect or reattach an RDP session to an RDP transport endpoint. Attackers may use this technique to hijack or move interactive sessions while remaining inside established remote access workflows. The detection relies on Windows process creation telemetry, specifically the command line field from process-start events.

Related detections9 linkedT1021.001 — drag to rearrange
Malicious RDP Session Hijacking via tscon Command Line
Suspicious Enabling of Remote Desktop via fDenyTSConnections Registry by DeadLock Ransomware
Suspicious Plink SSH Tunnel Execution (via process_creation)
Suspicious Remote Desktop Enabled via fDenyTSConnections Registry by Sandworm
Suspicious RDP Shadow Session Started - Native (via rdp)
Malicious RDP BlueeKeep Connection Closed - CVE-2019-0708 (via rdp)
Obfuscated RDP Tunneling Configuration Enabled for Port Forwarding (via process_creation)
Malicious RDP Shadow Session Configuration Enabled - Registry (via registry_event)
Malicious RDP Tunneling (via rdp)
Windows Suspicious RDP Session Redirect via tscon.exe /dest:rdp-tcp#
Pivot detection · T1021.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.