DETECTION OVERVIEW
Risk Factors
The Remote Desktop Protocol (RDP) is a common target for attackers because RDP provides remote access to a Windows device. Attackers can find weak passwords with low-cost techniques such as brute force attacks. If an attacker has credentials for several devices on the network, they can easily open multiple RDP sessions from a single device to control many devices on the network.
The system might change the risk score for this detection.
Kill Chain
Risk Score
60
Implement strong authentication methods for remote access services
Implement network segmentation and firewall policies to limit how devices can communicate and enforce security zones
Review access controls to ensure that only necessary users can connect to remote access services
Review authentication methods and enforce policies for secure credential creation and multi-factor authentication