Techniques
Sample rules
Unusual Windows Remote User
- source: elastic
- technicques:
- T1078
Description
A machine learning job detected an unusual remote desktop protocol (RDP) username, which can indicate account takeover or credentialed persistence using compromised accounts. RDP attacks, such as BlueKeep, also tend to use unusual usernames.
Detection logic