Techniques
Sample rules
Publicly Accessible RDP Service
- source: sigma
- technicques:
- t1021
- t1021.001
Description
Detects connections from routable IPs to an RDP listener. Which is indicative of a publicly-accessible RDP service.
Detection logic
condition: not selection
selection:
id.orig_h|cidr:
- ::1/128
- 10.0.0.0/8
- 127.0.0.0/8
- 172.16.0.0/12
- 192.168.0.0/16
- 169.254.0.0/16
- 2620:83:8000::/48
- fc00::/7
- fe80::/10