AN0931
Analytic 0931
Windows
Remote Desktop (RDP) logon by a user followed by unusual process execution, file access, or lateral movement activity within a short timeframe.
WinEventLog:Security
EventCode=4624, 4648
WinEventLog:Security
EventCode=4778, EventCode=4779
WinEventLog:Sysmon
EventCode=3, 22
WinEventLog:Sysmon
EventCode=1
[TimeWindow]
Temporal threshold to correlate login with post-login activity (e.g., 5 minutes)
[UserContext]
Tune for non-admin users or service accounts expected to use RDP
[ProcessList]
Define suspicious post-login processes such as cmd.exe, powershell.exe, certutil.exe
[HostAccessPatterns]
Scope detection to uncommon or first-time access between source and destination hosts