LoFP LoFP / t1021.001

t1021.001

TitleTags
administrative activity
administrative activity using a remote port forwarding to a local port
although it is recommended to not have rdp exposed to the internet, verify that this is a) allowed b) the server has not already been compromised via some brute force or remote exploit since it has been exposed to the internet. work to secure the server if you are unable to remove it from being exposed to the internet.
legitimate system administrators enabling rdp for remote support
programs that connect locally to the rdp port
system configuration scripts during deployment
third party rdp tools
unknown
unlikely
valid user was not added to rdp group
wsl (windows sub system for linux)