T1021.001 Remote Desktop Protocol
Sub-technique of T1021 Remote Services
Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user. Remote desktop is a common feature in operating systems. It allows a user to log into an interactive session with a system desktop graphical user interface on a remote system. Microsoft refers…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Hermetic Wiper TG Process Patternshightest · windows
- Outbound RDP Connections Over Non-Standard Toolshightest · windows
- Potential Tampering With RDP Related Registry Keys Via Reg.EXEhightest · windows
- Publicly Accessible RDP Servicehightest · zeek
- RDP Login from Localhosthightest · windows
- RDP Over Reverse SSH Tunnelhightest · windows
- RDP over Reverse SSH Tunnel WFPhightest · windows
- RDP to HTTP or HTTPS Target Portshightest · windows
- Suspicious Plink Port Forwardinghightest · windows
- Suspicious RDP Redirect Using TSCONhightest · windows
- User Added to Remote Desktop Users Grouphightest · windows
- OpenCanary - RDP New Connection Attempthighexperimental · opencanary
- Denied Access To Remote Desktopmediumtest · windows
- New Remote Desktop Connection Initiated Via Mstsc.EXEmediumtest · windows
- Port Forwarding Activity Via SSH.EXEmediumtest · windows
- RDP Enable or Disable via Win32_TerminalServiceSetting WMI Classmediumexperimental · windows
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.