> For the complete documentation index, see [llms.txt](https://nk0.gitbook.io/dfir/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://nk0.gitbook.io/dfir/windows/forensics/3rd-party-apps/rmm/screenconnect-forensics.md).

# ScreenConnect Forensics

{% embed url="<https://www.huntandhackett.com/blog/revil-the-usage-of-legitimate-remote-admin-tooling>" %}

{% embed url="<https://digitalforensicsdotblog.wordpress.com/tag/screenconnect/>" %}

{% embed url="<https://docs.acceptto.com/docs/cloud/connectwise-control>" %}
SSO SAML
{% endembed %}

## Attack&#x20;

Get a user to download an agent and enter the code to join session.&#x20;

<figure><img src="/files/VadjlgFKpQu4Tj0PMaE5" alt=""><figcaption></figcaption></figure>

Or download the agent yourself and execute it on the victim workstation if you have access.

<figure><img src="/files/oxczgtEDG1NbaODIHlor" alt=""><figcaption></figcaption></figure>

Once the executable is ran, you can join the session as the host from the web console.

<figure><img src="/files/5IAW8NFJ8s3ZflzDxlJg" alt=""><figcaption></figcaption></figure>

ScreenConnect relay.

<figure><img src="/files/CgFrc9rjRIr3jrlBa064" alt=""><figcaption></figcaption></figure>

Once the session is established, we can execute all sorts of commands

* Run executables
* Transfer files
* Run commands
* Install Permenant Access (Most important for persistence).

<figure><img src="/files/g1zzgLeNiXu8k1rpOp0t" alt=""><figcaption></figcaption></figure>

We can see that the ScreenConnect instance is being run by the highly privileged&#x20;

NT AUTHORITY\SYSTEM user.

<figure><img src="/files/JgQLPxHQKX1gXYrKKNSr" alt=""><figcaption></figcaption></figure>

If we run the command install access, this will permanently install the client on the victim machine and allow us access to it without them having to rejoin or enter any codes. This is ideal to stay persistent on a victim machine and also stay in an elevate privilege state.

<figure><img src="/files/ddSsj2fFPLU6SXdYQ4SP" alt=""><figcaption></figcaption></figure>

Client session is now listed in access area of console.

<figure><img src="/files/J00luQujiu2YKjJTLzgT" alt=""><figcaption></figcaption></figure>

Run commands in web portal terminal.

<figure><img src="/files/ZHWG4gkng3n1LZuFIk2m" alt=""><figcaption></figcaption></figure>

## Detect

Once you're connected, the Applications logs will show what account has connected to this device. This will not show the source IP of the TA connection as the connection is brokered by ScreenConnects relay servers.

* Application logs
* Source: ScreenConnect

<figure><img src="/files/oucWqKSxFNX4Qd2v6Q8A" alt=""><figcaption></figcaption></figure>

ScreenConnect relay.

<figure><img src="/files/71vdeFUe50xIzWGt8Ccm" alt=""><figcaption></figcaption></figure>

User disconnected.

<figure><img src="/files/f3PPEf3zvIl1fFYpfjus" alt=""><figcaption></figcaption></figure>

### Regular Client Installation

Regular client installation, not permanent. Event ID 7045 will appear for base ScreenConnect installations, a good indicator of when it was executed.

<figure><img src="/files/No1cnfECMOv3KST04ss0" alt=""><figcaption></figcaption></figure>

{% code overflow="wrap" %}

```
Time: 11/29/2023 11:02:05 PM
Event ID: 7045
Message: A service was installed in the system.

Service Name:  ScreenConnect Client (99087e24-f8c7-47eb-8855-4d63ac3c55e2)
Service File Name:  "C:\Users\Administrator\AppData\Local\Apps\2.0\3XED1J4P.ZWE\NHXKMX9B.6B0\scre..tion_25b0fbb6ef7eb094_0017.0008_c2f57e8a00a9f92d\ScreenConnect.ClientService.exe" "?e=Support&y=Guest&h=instance-j24yfa-relay.screenconnect.com&p=443&s=99087e24-f8c7-47eb-8855-4d63ac3c55e2&k=BgIAAACkAABSU0ExAAgAAAEAAQB5YtrCzQNpuIufSOv1Ok14VGIGcn%2fI2D9MpSVoJkcw75oQm%2fD0U918EOAefys5dC%2b0c4EO7rDs%2bf8rFBH%2fIfm5OeNm5pzCrAs5EUhM1W%2fW19n1KEchs6fr1TX518EBE6wm1Fs3ZaIh%2f3TsZue2LRyAboOanpH3bQqe7qCVKmTAYSsxWPjG2ONbk%2bc5q%2fnGndEgA6GB84spU%2fMJN4%2feA6utzQ9T7KiwjdgkXoWsXqyLM6xOkCPPKwoDyBMMfQLZTAi5Yk6z4CwFoMc7FyD0EKBhkrR4PnChBHxAJci28WYJmXig8PTSoSaTRBV4xHmc%2fBUsmPUP4AIHqndI1M2%2f7pbV&r=&i=Untitled%20Session" "1"

Service Type:  user mode service
Service Start Type:  auto start
Service Account:  LocalSystem
```

{% endcode %}

### Install Access

Permanent access installed. This will allow the TA persistent access to the host without the user having to enter any codes.

These executables can be built with the Build + button.

<figure><img src="/files/N5JUbKI9TUzh1KAHQZWw" alt=""><figcaption></figcaption></figure>

&#x20;These will also make a service, creating another 7045 entry even if this is upgraded through a base install. Two 7045s will be present.

<figure><img src="/files/gxCVFpX8Yg7VvljX0eo2" alt=""><figcaption></figcaption></figure>

<pre data-overflow="wrap"><code>Time: 11/29/2023 11:13:12 PM
Event ID: 7045
Message: A service was installed in the system.

Service Name:  ScreenConnect Client (e6f5ce1d563c8e3f)
Service File Name:  "C:\Program Files (x86)\ScreenConnect Client (e6f5ce1d563c8e3f)\ScreenConnect.ClientService.exe" "?e=Access&#x26;y=Guest&#x26;h=instance-j24yfa-relay.screenconnect.com&#x26;p=443&#x26;s=2d33b2a8-44d2-4100-89ac-28d73a703389&#x26;k=BgIAAACkAABSU0ExAAgAAAEAAQB5YtrCzQNpuIufSOv1Ok14VGIGcn%2fI2D9MpSVoJkcw75oQm%2fD0U918EOAefys5dC%2b0c4EO7rDs%2bf8rFBH%2fIfm5OeNm5pzCrAs5EUhM1W%2fW19n1KEchs6fr1TX518EBE6wm1Fs3ZaIh%2f3TsZue2LRyAboOanpH3bQqe7qCVKmTAYSsxWPjG2ONbk%2bc5q%2fnGndEgA6GB84spU%2fMJN4%2feA6utzQ9T7KiwjdgkXoWsXqyLM6xOkCPPKwoDyBMMfQLZTAi5Yk6z4CwFoMc7FyD0EKBhkrR4PnChBHxAJci28WYJmXig8PTSoSaTRBV4xHmc%2fBUsmPUP4AIHqndI1M2%2f7pbV"
<strong>
</strong><strong>Service Type:  user mode service
</strong>Service Start Type:  auto start
Service Account:  LocalSystem
</code></pre>

ScreenConnect.ClientSetup.exe can be used as evidence of ScreenConnect installing itself persistently.

<figure><img src="/files/y9Jm8sFfXE99wc79wlX3" alt=""><figcaption></figcaption></figure>

<pre data-overflow="wrap"><code><strong>Time: 11/29/2023 11:13:07 PM
</strong>Event ID: 201
Message: Transferred files with action 'RunSilentElevated':
ScreenConnect.ClientSetup.exe

Version: 23.8.5.8707
Executable Path: C:\Users\Administrator\AppData\Local\Apps\2.0\3XED1J4P.ZWE\NHXKMX9B.6B0\scre..tion_25b0fbb6ef7eb094_0017.0008_c2f57e8a00a9f92d\ScreenConnect.ClientService.exe

</code></pre>

### Uninstall Access

ScreenConnect.ClientUninstall.vbs can be used as evidence of an uninstallation.

<figure><img src="/files/EizFCpTuhsALCkcdfHP7" alt=""><figcaption></figcaption></figure>

{% code overflow="wrap" %}

```
Event ID 201
Message: Transferred files with action 'RunSilentElevated':
ScreenConnect.ClientUninstall.vbs

Version: 23.8.5.8707
Executable Path: C:\Program Files (x86)\ScreenConnect Client (e6f5ce1d563c8e3f)\ScreenConnect.ClientService.exe
```

{% endcode %}

### Commands Run

This will allow shell access to the victim host and the ability to run commands remotely. The length of each command run from the ScreenConnect shell will be recorded in the application IDs. This can be used to correlate the length of command lines with the length of commands recorded in Application event logs.&#x20;

<figure><img src="/files/UjAnrT06kD81O0gT26S0" alt=""><figcaption></figcaption></figure>

Length of "Dir" command = 3

<figure><img src="/files/jfju1RdLJIJqliCQhhQ6" alt=""><figcaption></figcaption></figure>

### Run Tool

Using the run tool command will execute any file that has been uploaded to the host. In this case, a cute picture of a wide gator will be shown (or ransomware!).

<figure><img src="/files/humU4zeXSmqYRAKsd0VS" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/Zv5pV5nmDyHqdcHaKjeR" alt=""><figcaption></figcaption></figure>

The upload and execution of this file can be seen in the Application logs.

<figure><img src="/files/s9ReFDMqJJk51yBH0kju" alt=""><figcaption></figcaption></figure>

<pre data-overflow="wrap"><code><strong>Event ID 201
</strong><strong>Message: Transferred files with action 'RunElevated':
</strong>rrlpva9z6tz11.png

Version: 23.8.5.8707
Executable Path: C:\Program Files (x86)\ScreenConnect Client (e6f5ce1d563c8e3f)\ScreenConnect.ClientService.exe
</code></pre>

### ScreenConnect Audit Logs

Screen connect audit logs will record commands run and output of those commands, IPs and usernames of those logging into machines, and the user-agents of those connecting to sessions.

<figure><img src="/files/qJGLXd8Qgxq9cwpJmgqR" alt=""><figcaption></figcaption></figure>

You can also generate reports based on types of logs you want to parse.

<figure><img src="/files/0VxAl6u4gkUfXkGSkwhh" alt=""><figcaption></figcaption></figure>

## Mitigate

### Change Cloud Admin Password

Go to Control Panel to reset the password of the Cloud Administrator Account.

<figure><img src="/files/IivkB3vJNjiBwevQTmg5" alt=""><figcaption></figcaption></figure>

Change password to prevent re-access of Cloud Administrator Account by the TA.

<figure><img src="/files/NF4kaB0QQYh69hVNxrIZ" alt=""><figcaption></figcaption></figure>

### Revoke Sessions

Revoking authenticated sessions can be used to terminate all active authentication sessions in the web portal. If SAML or Active Directory login is setup, it's a good idea to rotate those credentials in the case of compromised credentials.

* Reset compromised user creds.
* Revoke ConnectWise portal sessions.
* Revoke ScreenConnect host session connections.

<figure><img src="/files/Gujk7bu6csGpTo2csRPC" alt=""><figcaption></figcaption></figure>

Disconnecting users from host connections can also be done to ensure the TA doesn't still have access to victim machines even after the first two recommendations are completed.

## ScreenConnect Exploit:

Users folder gets wiped and adds a new user for the TA to leverage.

* C:\ScreenConnect/App\_Data/User.xml

{% embed url="<https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass>" %}

### Analysis

Users folder gets wiped and adds a new user for the TA to leverage.

* C:\ScreenConnect/App\_Data/User.xml
* Look at SQLite DB on the on-prem server to see logs of what actions TA took while leveraging ScreenConnect.

{% embed url="<https://docs.connectwise.com/ConnectWise_ScreenConnect_Documentation/Developers/Session_Manager_API_Reference/Enumerations>" %}

### Mitigations

* Rollback host to recover wiped accounts
* Update to latest version
* Kill all sessions and reset any compromised passwords
* Check for any left over users

{% embed url="<https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8>" %}
