Cross-source coverage

T1021.001 / ATT&CK

Remote Services: Remote Desktop Protocol

60 rules · 59 families across 5 sources.

From MITRE ATT&CK 19.2

Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.

Remote desktop is a common feature in operating systems. It allows a user to log into an interactive session with a system desktop graphical user interface on a remote system. Microsoft refers to its implementation of the Remote Desktop Protocol (RDP) as Remote Desktop Services (RDS).

Adversaries may connect to a remote system over RDP/RDS to expand access if the service is enabled and allows access to accounts with known credentials. Adversaries will likely use Credential Access techniques to acquire credentials to use with RDP. Adversaries may also use RDP in conjunction with the Accessibility Features or Terminal Services DLL for Persistence.

Platforms
Windows
Telemetry
WinEventLog:SecurityWinEventLog:Sysmon

How MITRE says to detect it DET0327

Multi-event Detection Strategy for RDP-Based Remote Logins and Post-Access Activity

Windows Analytic 0931

Remote Desktop (RDP) logon by a user followed by unusual process execution, file access, or lateral movement activity within a short timeframe.

  • WinEventLog:Security EventCode=4624, 4648
  • WinEventLog:Security EventCode=4778, EventCode=4779
  • WinEventLog:Sysmon EventCode=3, 22
  • WinEventLog:Sysmon EventCode=1

elastic/detection-rules

18 rules
Detection Severity Format
Execution via TSClient Mountpoint High Elastic TOML
Lateral Movement via Startup Folder High Elastic TOML
Potential Remote Desktop Shadowing Activity High Elastic TOML
Potential Remote Desktop Tunneling Detected High Elastic TOML
Potential SharpRDP Behavior High Elastic TOML
RDP Enabled via Registry Medium Elastic TOML
RDP (Remote Desktop Protocol) from the Internet Medium Elastic TOML
Remote Desktop Enabled in Windows Firewall by Netsh Medium Elastic TOML
Suspicious RDP ActiveX Client Loaded Medium Elastic TOML
High Mean of Process Arguments in an RDP Session Low Elastic TOML

+ 8 more from elastic/detection-rules → showing the 10 highest-severity

splunk/security_content

17 rules
Detection Severity Format
Allow Inbound Traffic By Firewall Rule Registry Undefined SPL
Allow Inbound Traffic In Firewall Rule Undefined SPL
Remote Desktop Network Traffic Undefined SPL
Remote Desktop Process Running On System Undefined SPL
Windows Default RDP File Creation By Non MSTSC Process Undefined SPL
Windows Default Rdp File Unhidden Undefined SPL
Windows MSTSC RDP Commandline Undefined SPL
Windows Process Execution From RDP Share Undefined SPL
Windows RDP Bitmap Cache File Creation Undefined SPL
Windows RDP Client Launched with Admin Session Undefined SPL

+ 7 more from splunk/security_content → showing the 10 highest-severity

SigmaHQ/sigma

16 rules
Detection Severity Format
Hermetic Wiper TG Process Patterns High Sigma
OpenCanary - RDP New Connection Attempt High Sigma
Outbound RDP Connections Over Non-Standard Tools High Sigma
Potential Tampering With RDP Related Registry Keys Via Reg.EXE High Sigma
Publicly Accessible RDP Service High Sigma
RDP Login from Localhost High Sigma
RDP Over Reverse SSH Tunnel High Sigma
RDP over Reverse SSH Tunnel WFP High Sigma
RDP to HTTP or HTTPS Target Ports High Sigma
Suspicious Plink Port Forwarding High Sigma

+ 6 more from SigmaHQ/sigma → showing the 10 highest-severity

Wazuh Core Ruleset

7 rules · 6 families
Detection Severity Format
Network activity using RDP port from-to loopback address, possible exploit using reverse tunneling Critical Wazuh XML
User: \ logged using Remote Desktop Connection (RDP) from loopback address, possible exploit over reverse tunneling using stolen credentials. · win.eventdata.logonType = 10, win.eventdata.ipAddress = ::1|127\.0\.0\.1 Critical Wazuh XML
Successful Remote Logon Detected - User:\ - NTLM authentication, possible pass-the-hash attack - Possible RDP connection. Verify that is allowed to perform RDP connections · win.eventdata.workstationName = .+ Medium Wazuh XML
Amazon Security Lake - VPC - RDP connection established. 2 variants Low Wazuh XML
Amazon Security Lake - VPC - RDP connection established. 2 variants Low Wazuh XML
RDP: . · win.system.providerName = Microsoft-Windows-TerminalServices-ClientActiveXCore, win.system.eventID = 1024 Low Wazuh XML
User: \ logged using Remote Desktop Connection (RDP) from ip:. · win.eventdata.logonType = 10 Low Wazuh XML

elastic/protections-artifacts

2 rules
Detection Severity Format
Sensitive File Access - Remote Desktop Connection Manager Undefined Elastic TOML
Unusual Remote Desktop Client Process Undefined Elastic TOML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.