Analytics Low

Possible external RDP Brute-Force

Multiple failed remote logins originated from an external IP with at least one successful login. This may indicate a successful brute-force attack.

Module:
Identity Analytics
Data source:
XDR Agent
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Brute Force: Password Guessing (T1110.001)
Attacker's goals:

The attacker attempts to gain access to the accounts.

Investigative actions:

If the source IP is an internal IP, adjust network IP ranges. Identify the user performing RDP and check that it is authorized. Check whether this IP has a malicious reputation. Reset the user's password. Follow further actions done by the user.

Test period:
10 Minutes
Deduplication:
1 Day
2 variations:
  • Possible external RDP Brute-Force on a Honey User Account Medium (parent: Low)
  • Potential External Brute-Force via RDP on Sensitive User Medium (parent: Low)