Analytics BIOC Informational

Suspicious successful RDP connection to localhost

An unusual process created a successful RDP connection to localhost. This may indicate the use of a tunnel to bypass a firewall.

Module:
Identity Analytics
Data source:
XDR Agent
ATT&CK tactics: Initial Access (TA0001)
ATT&CK techniques: External Remote Services (T1133)
Detector tags: Enhanced RDP Analytics
Attacker's goals:

The attacker attempts to gain access to the accounts through RDP from an external source.

Investigative actions:

Investigate the actor process to determine if it was used for legitimate purposes or malicious activity. Identify the user performing RDP and check that it is authorized. Follow further actions done by the user.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • Suspicious successful RDP connection to localhost via reverse SSH tunnel Low (parent: Informational)
  • Suspicious successful RDP connection to localhost on DC server Low (parent: Informational)