MITRE ATT&CK technique
External Remote Services detection rulesT1133
External Remote Services (T1133) is a MITRE ATT&CK technique in the Persistence tactic. This page lists the 20 community-maintained Sigma detection rules in the library mapped to T1133 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, opencanary, fortigate.
Top products
Tactic
External Remote SMB Logon from Public IP
highDetects successful logon from public IP address via SMB. This can indicate a publicly-exposed SMB port.
windows
OpenCanary - RDP New Connection Attempt
highDetects instances where an RDP service on an OpenCanary node has had a connection attempt.
opencanary · application
OpenCanary - SSH Login Attempt
highDetects instances where an SSH service on an OpenCanary node has had a login attempt.
opencanary · application
OpenCanary - SSH New Connection Attempt
highDetects instances where an SSH service on an OpenCanary node has had a connection attempt.
opencanary · application
OpenCanary - Telnet Login Attempt
highDetects instances where a Telnet service on an OpenCanary node has had a login attempt.
opencanary · application
Potential Exploitation of GoAnywhere MFT Vulnerability
highDetects suspicious command execution by child processes of the GoAnywhere Managed File Transfer (MFT) application, which may indicate exploitation such as CVE-2025-10035. This behavior is indicative of post-exploitation activity related to CVE-2025-10035, as observed in campaigns by the threat actor Storm-1175.
windows · process_creation
Running Chrome VPN Extensions via the Registry 2 VPN Extension
highRunning Chrome VPN Extensions via the Registry install 2 vpn extension
windows · registry_set
Suspicious File Created by ArcSOC.exe
highDetects instances where the ArcGIS Server process ArcSOC.exe, which hosts REST services running on an ArcGIS server, creates a file with suspicious file type, indicating that it may be an executable, script file, or otherwise unusual.
windows · file_event
Unusual Child Process of dns.exe
highDetects an unexpected process spawning from dns.exe which may indicate activity related to remote code execution or other forms of exploitation as seen in CVE-2020-1350 (SigRed)
windows · process_creation
Unusual File Deletion by Dns.exe
highDetects an unexpected file being deleted by dns.exe which my indicate activity related to remote code execution or other forms of exploitation as seen in CVE-2020-1350 (SigRed)
windows · file_delete
Unusual File Modification by dns.exe
highDetects an unexpected file being modified by dns.exe which my indicate activity related to remote code execution or other forms of exploitation as seen in CVE-2020-1350 (SigRed)
windows · file_change
User Added to Remote Desktop Users Group
highDetects addition of users to the local Remote Desktop Users group via "Net" or "Add-LocalGroupMember".
windows · process_creation
External Remote RDP Logon from Public IP
mediumDetects successful logon from public IP address via RDP. This can indicate a publicly-exposed RDP port.
windows
Failed Logon From Public IP
mediumDetects a failed logon attempt from a public IP. A login from a public IP can indicate a misconfigured firewall or network boundary.
windows
FortiGate - New VPN SSL Web Portal Added
mediumDetects the addition of a VPN SSL Web Portal on a Fortinet FortiGate Firewall. This behavior was observed in pair with modification of VPN SSL settings.
fortigate
FortiGate - VPN SSL Settings Modified
mediumDetects the modification of VPN SSL Settings (for example, the modification of authentication rules). This behavior was observed in pair with the addition of a VPN SSL Web Portal.
fortigate
Remote Access Tool - ScreenConnect Installation Execution
mediumDetects ScreenConnect program starts that establish a remote access to a system.
windows · process_creation
Remote Access Tool - Team Viewer Session Started On Linux Host
lowDetects the command line executed when TeamViewer starts a session started by a remote host. Once a connection has been started, an investigator can verify the connection details by viewing the "incoming_connections.txt" log file in the TeamViewer folder.
linux · process_creation
Remote Access Tool - Team Viewer Session Started On MacOS Host
lowDetects the command line executed when TeamViewer starts a session started by a remote host. Once a connection has been started, an investigator can verify the connection details by viewing the "incoming_connections.txt" log file in the TeamViewer folder.
macos · process_creation
Remote Access Tool - Team Viewer Session Started On Windows Host
lowDetects the command line executed when TeamViewer starts a session started by a remote host. Once a connection has been started, an investigator can verify the connection details by viewing the "incoming_connections.txt" log file in the TeamViewer folder.
windows · process_creation