Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0327 — Multi-event Detection Strategy for RDP-Based Remote Logins and Post-Access Activity
DET0327

Multi-event Detection Strategy for RDP-Based Remote Logins and Post-Access Activity

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0931 Analytic 0931
Windows

Remote Desktop (RDP) logon by a user followed by unusual process execution, file access, or lateral movement activity within a short timeframe.

WinEventLog:Security EventCode=4624, 4648 WinEventLog:Security EventCode=4778, EventCode=4779 WinEventLog:Sysmon EventCode=3, 22 WinEventLog:Sysmon EventCode=1
[TimeWindow] Temporal threshold to correlate login with post-login activity (e.g., 5 minutes)
[UserContext] Tune for non-admin users or service accounts expected to use RDP
[ProcessList] Define suspicious post-login processes such as cmd.exe, powershell.exe, certutil.exe
[HostAccessPatterns] Scope detection to uncommon or first-time access between source and destination hosts

Detected Techniques

1

Details

MITRE ID
DET0327
STIX ID
x-mitre-detection-strategy--722d2e3d-c3ad-4878-bcef-ca3161465342
Analytics
1
Techniques Detected
1
By Tactic
Lateral Movement
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.