1200KM / detection
T1021.001 Remote Desktop Protocol — Detection Rules
Detection workspace for T1021.001 Remote Desktop Protocol: 15 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- OpenCanary - RDP New Connection Attempt · experimental · high · {"category":"application","product":"opencanary"}
- Publicly Accessible RDP Service · test · high · {"product":"zeek","service":"rdp"}
- RDP Login from Localhost · test · high · {"product":"windows","service":"security"}
- Denied Access To Remote Desktop · test · medium · {"product":"windows","service":"security"}
- RDP over Reverse SSH Tunnel WFP · test · high · {"product":"windows","service":"security"}
- Outbound RDP Connections Over Non-Standard Tools · test · high · {"category":"network_connection","product":"windows"}
- RDP Over Reverse SSH Tunnel · test · high · {"category":"network_connection","product":"windows"}
- RDP to HTTP or HTTPS Target Ports · test · high · {"category":"network_connection","product":"windows"}
- New Remote Desktop Connection Initiated Via Mstsc.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Plink Port Forwarding · test · high · {"category":"process_creation","product":"windows"}
- RDP Enable or Disable via Win32_TerminalServiceSetting WMI Class · experimental · medium · {"category":"process_creation","product":"windows"}
- Potential Tampering With RDP Related Registry Keys Via Reg.EXE · test · high · {"product":"windows","category":"process_creation"}
- Port Forwarding Activity Via SSH.EXE · test · medium · {"category":"process_creation","product":"windows"}
- User Added to Remote Desktop Users Group · test · high · {"category":"process_creation","product":"windows"}
- Suspicious RDP Redirect Using TSCON · test · high · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
T1021.001 Remote Desktop Protocol
MATCH(successful_rdp_session) AND source_host NOT_IN approved_rdp_sources -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0327 Multi-event Detection Strategy for RDP-Based Remote Logins and Post-Access Activity
AN0931 Analytic 0931
Remote Desktop (RDP) logon by a user followed by unusual process execution, file access, or lateral movement activity within a short timeframe.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Axiom · G0001
- APT1 · G0006
- APT3 · G0022
- Lazarus Group · G0032
- Dragonfly · G0035
- FIN6 · G0037
- Patchwork · G0040
- menuPass · G0045
- FIN7 · G0046
- OilRig · G0049
- FIN10 · G0051
- Magic Hound · G0059
- FIN8 · G0061
- Leviathan · G0065
- Cobalt Group · G0080
- APT39 · G0087
- Silence · G0091
- Kimsuky · G0094
- APT41 · G0096
- Wizard Spider · G0102
- Blue Mockingbird · G0108
- Chimera · G0114
- Fox Kitten · G0117
- Indrik Spider · G0119
- Aquatic Panda · G0143
- HEXANE · G1001
- Scattered Spider · G1015
- FIN13 · G1016
- Volt Typhoon · G1017
- APT5 · G1023
- Akira · G1024
- Agrius · G1030
- INC Ransom · G1032
- BlackByte · G1043
- Medusa Group · G1051
- MirrorFace · G1054
- VOID MANTICORE · G1055
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.