Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1021 ✕

Download CSV Show ATT&CK heatmap
  • RDP connections enabled remotely via Registry Low 2 variations

    An attacker may remotely enable RDP connections to a machine by setting the fDenyTSConnections Registry key to 0.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Lateral Movement (TA0008)
    ATT&CK techniques: Remote Services: Remote Desktop Protocol (T1021.001)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Detector tags: Enhanced RDP Analytics
    Attacker's goals: Remotely enable RDP on the host for lateral movement.
    Investigative actions: Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow. Search for RDP sessions to this host and investigate them for malicious activities.

    Variations

    RDP connections enabled by a remote process via Registry

    Low overridden

    An attacker may remotely enable RDP connections to a machine by setting the fDenyTSConnections Registry key to 0. overridden

    RDP connections enabled remotely via Registry using WinRM

    Low overridden

    An attacker may remotely enable RDP connections to a machine by setting the fDenyTSConnections Registry key to 0. overridden