Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0001 ✕

Download CSV Show ATT&CK heatmap
  • Suspicious successful RDP connection to localhost Informational Identity Analytics 2 variations

    An unusual process created a successful RDP connection to localhost. This may indicate the use of a tunnel to bypass a firewall.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: External Remote Services (T1133)
    Required data: XDR Agent
    Detector tags: Enhanced RDP Analytics
    Attacker's goals: The attacker attempts to gain access to the accounts through RDP from an external source.
    Investigative actions: Investigate the actor process to determine if it was used for legitimate purposes or malicious activity. Identify the user performing RDP and check that it is authorized. Follow further actions done by the user.

    Variations

    Suspicious successful RDP connection to localhost via reverse SSH tunnel

    Low overridden

    An unusual process created a successful RDP connection to localhost. The command line indicates the usage of SSH tunnel to bypass the firewall. overridden

    Suspicious successful RDP connection to localhost on DC server

    Low overridden

    An unusual process created a successful RDP connection to localhost on a DC server. This may indicate the use of a tunnel to bypass a firewall. overridden