RDP Connection to localhost
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Hour
Required Data
XDR Agent
Detector Tags
Enhanced RDP Analytics
ATT&CK Tactic
Lateral Movement (TA0008)
ATT&CK Technique
Remote Services: Remote Desktop Protocol (T1021.001)
Severity
Medium
Description
An RDP connection to localhost can be used for privilege escalation by leveraging Windows accessibility features.
Attacker's Goals
An attacker may initiate RDP tunneling for a more convenient and stable interface.
Investigative actions
Identify the process/user performing RDP and check that it is authorized.
Check whether the initiating process also connects to an external host.
PreviousRarely seen sender domain in the organization
NextRDP connections enabled remotely via Registry
Was this helpful?
