Suspicious External RDP Login
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detection Modules
Identity Analytics
ATT&CK Tactic
Initial Access (TA0001)
ATT&CK Technique
External Remote Services (T1133)
Severity
Informational
Description
An unusual successful RDP connection by a user from an external IP. This may be indicative of using stolen credentials or malicious activity.
Attacker's Goals
The attacker attempts to gain access to the accounts through RDP from an external source.
Investigative actions
Identify the user performing RDP and check that it is authorized.
Check whether this IP has a malicious reputation.
Reset the user's password.
Follow further actions done by the user.
PreviousSuspicious Encrypting File System Remote call (EFSRPC) to domain controller
NextSuspicious failed HTTP request - potential Spring4Shell exploit
Was this helpful?
