heroui logo

Link: ScreenConnect remote access tool delivery with unattended guest access

Sublime Rules

View Source
Summary
This rule detects inbound messages that attempt to deliver ScreenConnect remote access tooling by directing recipients to download a Guest Access installer (.msi or .exe) from screenconnect.com. It requires at least one link to screenconnect.com (excluding customer tenant subdomains) and that all such links point to an installer file (.msi or .exe) with query parameters indicating e=Access (SessionType: Access) and y=Guest (ProcessType: Guest). The combination of a ScreenConnect download link and Guest-Session parameters signals an unsolicited remote-access deployment, commonly accompanied by social-engineering lures (e.g., fake invoices, payment proofs, event invites). Given the potential for full remote control, the rule is rated high severity. Detection relies on URL analysis (domain, path endings, and query params) and content analysis to identify lure patterns. This rule protects against ScreenConnect-based intrusions and should be complemented with controls around executable downloads, email filtering, and user awareness training.
Categories
  • Endpoint
  • Web
  • Windows
Data Sources
  • Network Traffic
  • File
Created: 2026-07-22