Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Added ScreenConnect event log artifacts. #38

Open
wants to merge 6 commits into
base: main
Choose a base branch
from
Open
Changes from 3 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 13 additions & 2 deletions yaml/screenconnect.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ Description: ScreenConnect is a remote monitoring and management (RMM) tool. Mor
information will be added as it becomes available.
Author: Ali Alwashali, Nasreddine Bencherchali
Created: '2023-10-01'
LastModified: '2024-08-03'
LastModified: '2024-10-08'
Details:
Website: https://www.connectwise.com
PEMetadata:
Expand Down Expand Up @@ -56,7 +56,17 @@ Artifacts:
- File: C:\ProgramData\ScreenConnect Client*\user.config
Description: ScreenConnect client user configuration
OS: Windows
EventLog: []
EventLog:
- EventID: 7045
ProviderName: ["ScreenConnect", "ScreenConnect Client (<hex string>)"]
nasbench marked this conversation as resolved.
Show resolved Hide resolved
LogFile: Application.evtx
nasbench marked this conversation as resolved.
Show resolved Hide resolved
ServiceName: ScreenConnect Client (<hex string>)
nasbench marked this conversation as resolved.
Show resolved Hide resolved
Description: Service installation event as a result of ScreenConnect installation.
- EventID: 20
ProviderName: ["ScreenConnect", "ScreenConnect Client (<hex string>)"]
nasbench marked this conversation as resolved.
Show resolved Hide resolved
LogFile: Application.evtx
ServiceName: ScreenConnect Client (<hex string>)
nasbench marked this conversation as resolved.
Show resolved Hide resolved
Description: Logs events such as successful or failed connections, and user logins.
Registry: []
Network:
- Description: Known remote domains
Expand All @@ -74,4 +84,5 @@ Detections:
Description: Detects potential processes activity of ScreenConnect RMM tool
References:
- https://thedfirreport.com/2023/09/25/from-screenconnect-to-hive-ransomware-in-61-hours/
- https://www.huntandhackett.com/blog/revil-the-usage-of-legitimate-remote-admin-tooling
Acknowledgement: []
Loading