Uncommon RDP connection
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Hour
Required Data
XDR Agent
Detector Tags
Enhanced RDP Analytics
ATT&CK Tactic
Lateral Movement (TA0008)
ATT&CK Technique
Remote Services: Remote Desktop Protocol (T1021.001)
Severity
Informational
Description
RDP is used by attackers to laterally move to new hosts. Standard processes do not usually implement RDP on their own, and attackers might inject or tunnel using a non-standard process.
Attacker's Goals
Use an account that was possibly compromised to gain access to the network.
Investigative actions
Validate if the process is a legitimate IT software.
Verify if the process is known to be malicious.
Look into actions done on the remote host.
PreviousUncommon PowerShell commands used to create or alter scheduled task parameters
NextUncommon recurring rare external host access
Was this helpful?
