1200KM / simulation
T1021.001 Remote Desktop Protocol — Attack Simulation
Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user. Remote desktop is a common feature in operating systems. It allows a user to log into an interactive session with a system desktop graphical user interface on a remote system. Microsoft refers to its implementation of the Remote Desktop Protocol (RDP) as Remote Desktop Services (RDS).…
Technique description
Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user. Remote desktop is a common feature in operating systems. It allows a user to log into an interactive session with a system desktop graphical user interface on a remote system. Microsoft refers to its implementation of the Remote Desktop Protocol (RDP) as Remote Desktop Services (RDS).…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Disable NLA for RDP via Command Prompt
Procedure 01d1c6c0-faf0-408e-b368-752a02285cb2; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Changing RDP Port to Non Standard Port via Powershell
Procedure 2f840dd4-8a2e-4f44-beb3-6b2399ea3771; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- RDP to Remote Host
Procedure 355d4632-8cb9-449d-91ce-b566d0253d3e; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Changing RDP Port to Non Standard Port via Command_Prompt
Procedure 74ace21e-a31c-4f7d-b540-53e4eb6d1f73; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Axiom · G0001
- APT1 · G0006
- APT3 · G0022
- Lazarus Group · G0032
- Dragonfly · G0035
- FIN6 · G0037
- Patchwork · G0040
- menuPass · G0045
- FIN7 · G0046
- OilRig · G0049
- FIN10 · G0051
- Magic Hound · G0059
- FIN8 · G0061
- Leviathan · G0065
- Cobalt Group · G0080
- APT39 · G0087
- Silence · G0091
- Kimsuky · G0094
- APT41 · G0096
- Wizard Spider · G0102
- Blue Mockingbird · G0108
- Chimera · G0114
- Fox Kitten · G0117
- Indrik Spider · G0119
- Aquatic Panda · G0143
- HEXANE · G1001
- Scattered Spider · G1015
- FIN13 · G1016
- Volt Typhoon · G1017
- APT5 · G1023
- Akira · G1024
- Agrius · G1030
- INC Ransom · G1032
- BlackByte · G1043
- Medusa Group · G1051
- MirrorFace · G1054
- VOID MANTICORE · G1055
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.