Analytics BIOC Informational

Suspicious External RDP Login

An unusual successful RDP connection by a user from an external IP. This may be indicative of using stolen credentials or malicious activity.

Module:
Identity Analytics
Data source:
XDR Agent
ATT&CK tactics: Initial Access (TA0001)
ATT&CK techniques: External Remote Services (T1133)
Attacker's goals:

The attacker attempts to gain access to the accounts through RDP from an external source.

Investigative actions:

Identify the user performing RDP and check that it is authorized. Check whether this IP has a malicious reputation. Reset the user's password. Follow further actions done by the user.

Test period:
N/A (single event)
Deduplication:
1 Day