LoFP LoFP / legitimate incoming connections (e.g. sysadmin activity). most of the time i would expect outgoing connections (initiated locally).

Techniques

Sample rules

Remote Access Tool - AnyDesk Incoming Connection

Description

Detects incoming connections to AnyDesk. This could indicate a potential remote attacker trying to connect to a listening instance of AnyDesk and use it as potential command and control channel.

Detection logic

condition: selection
selection:
  Image|endswith: \AnyDesk.exe
  Initiated: 'false'