Detected RDP port network activity from to · win.eventdata.destinationPort = 3389
Description
Detected RDP port network activity from $(win.eventdata.sourceIp) to $(win.eventdata.destinationIp)
Query · wazuh
field win.eventdata.destinationPort="^3389$"
Fires when
Wazuh evaluates a chain top-down. Every rule above this one must match on the same event before this rule is tested at all.
-
92108Detected RDP port network activity from to · win.eventdata.destinationPort = 3389 anchor level 0 this rulefield win.eventdata.destinationPort="^3389$"
Refined by
1 rule chains off this one, narrowing it further.
Rule dependencies
Depends on
-
composes · Wazuh if_group
sysmon_event344 rules in this analytic story