Samirbous
4741f70fad
[New Rule] Potential Remote Desktop Tunneling Detected ( #374 )
...
* [New Rule] Remote Desktop Tunneling using SSH Plink Utility
* Update lateral_movement_rdp_tunnel_plink.toml
* Update lateral_movement_rdp_tunnel_plink.toml
* changed tags
* expanded condition to more than plink
there are other SSH utilities that can be used as Plink thus removed the process original filename condition and added mandatory switches such as -L -P and -R.
* Update lateral_movement_rdp_tunnel_plink.toml
* more args options
Co-authored-by: David French <56409778+threat-punter@users.noreply.github.com >
2020-11-17 21:25:48 +01:00
..
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-10-26 13:50:45 -05:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-10-26 13:50:45 -05:00
2020-10-26 13:50:45 -05:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-17 21:23:28 +01:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-17 21:25:48 +01:00
2020-11-17 21:19:30 +01:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-17 21:21:15 +01:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00
2020-11-03 09:51:53 -09:00