Analytics BIOC
Informational
✕
Suspicious External RDP Login
An unusual successful RDP connection by a user from an external IP. This may be indicative of using stolen credentials or malicious activity.
- Module:
- Identity Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Initial Access (TA0001)
ATT&CK techniques: External Remote Services (T1133)
Attacker's goals:
The attacker attempts to gain access to the accounts through RDP from an external source.
Investigative actions:
Identify the user performing RDP and check that it is authorized. Check whether this IP has a malicious reputation. Reset the user's password. Follow further actions done by the user.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day