Suspicious Child Processes Spawned by TightVNC

Rule Info

Name
Suspicious Child Processes Spawned by TightVNC
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects suspicious child processes spawned by TightVNC process. This could indicate the presence of a remote management tool (RMM) or remote access tool (RAT) on the system. Threat actors may use these tools to gain unauthorized access to systems and networks and perform malicious activities.
Reference
Internal Research
Date
2026-02-11 00:00:00
Modified
None
Id
a61c6b8f-7865-4938-8a38-f583cfc4cfb1
Tags
attack.command-and-control attack.t1219.002
Type
Nextron Sigma feed only (private)

Rule History