Analytics BIOC Medium

Possible RDP session hijacking using tscon.exe

The executable tscon.exe can be used to hijack other sessions on the same computer. The attacker may use another user's credentials to proceed with the lateral movement or disguise the activity.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Lateral Movement (TA0008)
ATT&CK techniques: Remote Service Session Hijacking: RDP Hijacking (T1563.002)
Attacker's goals:

Attackers might hijack existing sessions on the same host to gain access to private data or leverage the logged-in user credentials to laterally move across the network.

Investigative actions:

Verify if the executing process is suspicious. Investigate if the interactive user did any more suspicious or malicious actions.

Test period:
N/A (single event)
Deduplication:
1 Day