Rare RDP session to a remote host
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
2 Days
Required Data
Requires one of the following data sources: Palo Alto Networks Firewall traffic Logs OR XDR Agent OR Third-Party Firewalls
Detector Tags
NDR Lateral Movement Analytics, Enhanced RDP Analytics
ATT&CK Tactic
Lateral Movement (TA0008)
ATT&CK Technique
Remote Services: Remote Desktop Protocol (T1021.001)
Severity
Low
Description
The endpoint performed a rare RDP session to a remote host.
Attacker's Goals
Attackers may attempt to move laterally over the network by using compromised accounts or machines to connect to remote hosts using the RDP protocol.
Investigative actions
Inspect the legitimacy of the user who initiated the RDP session.
Verify that this isn't routine IT activity.
Variations
Was this helpful?
