Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
title: AnyDesk Accepted Incoming Connection
id: d58ba5c6-0ed7-4b9d-a433-6878379efda9
status: experimental
description: Detects accepted incoming connections via AnyDesk.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1219/T1219.md#atomic-test-2---anydesk-files-detected-test-on-windows
author: '@d4ns4n_ (Wuerth-Phoenix)'
date: 2024/07/02
tags:
- attack.persistence
- attack.command_and_control
- attack.t1219
logsource:
category: network_connection
product: windows
detection:
selection:
Image|endswith: '\AnyDesk.exe'
direction: 'ingress'
action:
- 'connection_accepted'
- 'network connection'
condition: selection
falsepositives:
- Legitimate incoming connections on the monitored machine via AnyDesk (most of the time I would expect outgoing connections).
level: high