Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0001 ✕ technique: T1133 ✕
Download CSV Show ATT&CK heatmapSuspicious successful RDP connection to localhost Informational Identity Analytics 2 variations
An unusual process created a successful RDP connection to localhost. This may indicate the use of a tunnel to bypass a firewall.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: External Remote Services (T1133)Required data: XDR AgentDetector tags: Enhanced RDP AnalyticsAttacker's goals: The attacker attempts to gain access to the accounts through RDP from an external source.Investigative actions: Investigate the actor process to determine if it was used for legitimate purposes or malicious activity. Identify the user performing RDP and check that it is authorized. Follow further actions done by the user.Variations
Suspicious successful RDP connection to localhost via reverse SSH tunnel
Low overridden
An unusual process created a successful RDP connection to localhost. The command line indicates the usage of SSH tunnel to bypass the firewall. overridden
Suspicious successful RDP connection to localhost on DC server
Low overridden
An unusual process created a successful RDP connection to localhost on a DC server. This may indicate the use of a tunnel to bypass a firewall. overridden