• Platformchevron right
  • Solutionschevron right
  • Modern NDRchevron right
  • Resourceschevron right
  • Companychevron right

DETECTION OVERVIEW

Unconventional RDP Behavior

Risk Factors

The Remote Desktop Protocol (RDP) is a common target for attackers because RDP provides remote access to a Windows device. Attackers can find weak passwords with low-cost techniques such as brute force attacks. If an attacker has credentials for several devices on the network, they can easily open multiple RDP sessions from a single device to control many devices on the network.

The system might change the risk score for this detection.

Kill Chain

Exploitation

Risk Score

60

Next in Exploitation: Unconventional SSH Behavior

Attack Background

Mitigation Options

Implement strong authentication methods for remote access services

Implement network segmentation and firewall policies to limit how devices can communicate and enforce security zones

Review access controls to ensure that only necessary users can connect to remote access services

Review authentication methods and enforce policies for secure credential creation and multi-factor authentication

MITRE ATT&CK ID

What else can RevealX do for you?