MITRE ATT&CK

RDP is a Microsoft protocol built into Windows for remote administration, enabling a user to access and control another system via a graphical interface. It’s widely enabled in enterprise environments, making its traffic generally considered legitimate.


How Attackers Use It


Detection

Screenshot 2025-02-24 072119.png

Important Windows Event Logs

Important Sysmon Event IDs


Threat Hunting