Analytics
Low
✕
Possible external RDP Brute-Force
Multiple failed remote logins originated from an external IP with at least one successful login. This may indicate a successful brute-force attack.
- Module:
- Identity Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Brute Force: Password Guessing (T1110.001)
Attacker's goals:
The attacker attempts to gain access to the accounts.
Investigative actions:
If the source IP is an internal IP, adjust network IP ranges. Identify the user performing RDP and check that it is authorized. Check whether this IP has a malicious reputation. Reset the user's password. Follow further actions done by the user.
- Test period:
- 10 Minutes
- Deduplication:
- 1 Day
2 variations:
- Possible external RDP Brute-Force on a Honey User Account Medium (parent: Low)
- Potential External Brute-Force via RDP on Sensitive User Medium (parent: Low)