Esc
Remote Service Session Hijacking - T1563
(ATT&CK® Technique)
Definition
Adversaries may take control of preexisting sessions with remote services to move laterally in an environment. Users may use valid credentials to log into a service specifically designed to accept remote connections, such as telnet, SSH, and RDP. When a user logs into a service, a session will be established that will allow them to maintain a continuous interaction with that service.
D3FEND Inferred Relationships
Browse the D3FEND knowledge graph by clicking on the nodes below.