Cross-source coverage
T1021.001 / ATT&CK
Remote Services: Remote Desktop Protocol
From MITRE ATT&CK 19.2
Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.
Remote desktop is a common feature in operating systems. It allows a user to log into an interactive session with a system desktop graphical user interface on a remote system. Microsoft refers to its implementation of the Remote Desktop Protocol (RDP) as Remote Desktop Services (RDS).
Adversaries may connect to a remote system over RDP/RDS to expand access if the service is enabled and allows access to accounts with known credentials. Adversaries will likely use Credential Access techniques to acquire credentials to use with RDP. Adversaries may also use RDP in conjunction with the Accessibility Features or Terminal Services DLL for Persistence.
- Tactics
- Lateral Movement
- Platforms
- Windows
- Telemetry
-
WinEventLog:SecurityWinEventLog:Sysmon
How MITRE says to detect it DET0327
Multi-event Detection Strategy for RDP-Based Remote Logins and Post-Access Activity
Windows Analytic 0931
Remote Desktop (RDP) logon by a user followed by unusual process execution, file access, or lateral movement activity within a short timeframe.
WinEventLog:SecurityEventCode=4624, 4648WinEventLog:SecurityEventCode=4778, EventCode=4779WinEventLog:SysmonEventCode=3, 22WinEventLog:SysmonEventCode=1
elastic/detection-rules
18 rules| Detection | Severity | Format |
|---|---|---|
| Execution via TSClient Mountpoint | High | Elastic TOML |
| Lateral Movement via Startup Folder | High | Elastic TOML |
| Potential Remote Desktop Shadowing Activity | High | Elastic TOML |
| Potential Remote Desktop Tunneling Detected | High | Elastic TOML |
| Potential SharpRDP Behavior | High | Elastic TOML |
| RDP Enabled via Registry | Medium | Elastic TOML |
| RDP (Remote Desktop Protocol) from the Internet | Medium | Elastic TOML |
| Remote Desktop Enabled in Windows Firewall by Netsh | Medium | Elastic TOML |
| Suspicious RDP ActiveX Client Loaded | Medium | Elastic TOML |
| High Mean of Process Arguments in an RDP Session | Low | Elastic TOML |
+ 8 more from elastic/detection-rules → showing the 10 highest-severity
splunk/security_content
17 rules| Detection | Severity | Format |
|---|---|---|
| Allow Inbound Traffic By Firewall Rule Registry | Undefined | SPL |
| Allow Inbound Traffic In Firewall Rule | Undefined | SPL |
| Remote Desktop Network Traffic | Undefined | SPL |
| Remote Desktop Process Running On System | Undefined | SPL |
| Windows Default RDP File Creation By Non MSTSC Process | Undefined | SPL |
| Windows Default Rdp File Unhidden | Undefined | SPL |
| Windows MSTSC RDP Commandline | Undefined | SPL |
| Windows Process Execution From RDP Share | Undefined | SPL |
| Windows RDP Bitmap Cache File Creation | Undefined | SPL |
| Windows RDP Client Launched with Admin Session | Undefined | SPL |
+ 7 more from splunk/security_content → showing the 10 highest-severity
SigmaHQ/sigma
16 rules| Detection | Severity | Format |
|---|---|---|
| Hermetic Wiper TG Process Patterns | High | Sigma |
| OpenCanary - RDP New Connection Attempt | High | Sigma |
| Outbound RDP Connections Over Non-Standard Tools | High | Sigma |
| Potential Tampering With RDP Related Registry Keys Via Reg.EXE | High | Sigma |
| Publicly Accessible RDP Service | High | Sigma |
| RDP Login from Localhost | High | Sigma |
| RDP Over Reverse SSH Tunnel | High | Sigma |
| RDP over Reverse SSH Tunnel WFP | High | Sigma |
| RDP to HTTP or HTTPS Target Ports | High | Sigma |
| Suspicious Plink Port Forwarding | High | Sigma |
+ 6 more from SigmaHQ/sigma → showing the 10 highest-severity
Wazuh Core Ruleset
7 rules · 6 familieselastic/protections-artifacts
2 rules| Detection | Severity | Format |
|---|---|---|
| Sensitive File Access - Remote Desktop Connection Manager | Undefined | Elastic TOML |
| Unusual Remote Desktop Client Process | Undefined | Elastic TOML |