Suspicious successful RDP connection to localhost
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detection Modules
Identity Analytics
Detector Tags
Enhanced RDP Analytics
ATT&CK Tactic
Initial Access (TA0001)
ATT&CK Technique
External Remote Services (T1133)
Severity
Informational
Description
An unusual process created a successful RDP connection to localhost. This may indicate the use of a tunnel to bypass a firewall.
Attacker's Goals
The attacker attempts to gain access to the accounts through RDP from an external source.
Investigative actions
Investigate the actor process to determine if it was used for legitimate purposes or malicious activity.
Identify the user performing RDP and check that it is authorized.
Follow further actions done by the user.
Variations
Was this helpful?
