Windows TeamViewer Remote Session Process Command Line Start

Flags TeamViewer_Desktop.exe being launched by TeamViewer_Service.exe with the expected IPCport and module parameters on Windows.

FreeReviewedSigma · Low · v1
Product
windows
Category
process_creation
Author
Josh Nickels, Qi Nan (SigmaHQ), DRL 1.1
Published
2024-03-11
Updated
2026-07-30

ATT&CK techniques

Initial Access → Persistence
  1. Recon

  2. Resource Dev

  3. Execution

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule matches process creation for TeamViewer’s desktop executable when it is started via the TeamViewer service and uses a specific IPC port and module argument. Attackers can use remote access tooling like TeamViewer to establish interactive access from a remote host, so correlating this startup command helps identify remote session initiation. It relies on Windows process creation telemetry, specifically the executable path, parent process image, and the command line ending pattern.

Related detections9 linkedT1133 — drag to rearrange
SplashTop Network
Suspicious SoftEther VPN Hamcore Config Written to ProgramData (via file_event)
SplashTop Process
AnyDesk Network
OpenCanary RDP New Connection Attempt on Application Logtype 14001
ArcSOC.exe Creates Suspicious Script/Executable Files on Windows
FortiGate: Addition of VPN SSL Web Portal via Event Logs
FortiGate SSL VPN Settings Edited
Windows Process Creation: GoAnywhere child command execution indicating possible MFT exploitation
Windows TeamViewer Remote Session Process Command Line Start
Pivot detection · T1133 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.