kevmap

TechniquesT1021.001 › AN0931

AN0931 Analytic 0931

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Remote Desktop (RDP) logon by a user followed by unusual process execution, file access, or lateral movement activity within a short timeframe.</p>
Detects
T1021.001 Remote Desktop Protocol
Part of
DET0327 Multi-event Detection Strategy for RDP-Based Remote Logins and Post-Access Activity

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SecurityEventCode=4624, 4648DC0067 Logon Session Creation
WinEventLog:SecurityEventCode=4778, EventCode=4779DC0088 Logon Session Metadata
WinEventLog:SysmonEventCode=3, 22DC0082 Network Connection Creation
WinEventLog:SysmonEventCode=1DC0032 Process Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
TimeWindowTemporal threshold to correlate login with post-login activity (e.g., 5 minutes)
UserContextTune for non-admin users or service accounts expected to use RDP
ProcessListDefine suspicious post-login processes such as cmd.exe, powershell.exe, certutil.exe
HostAccessPatternsScope detection to uncommon or first-time access between source and destination hosts

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2023-22952SugarCRM Multiple ProductsStale
CVE-2024-53704SonicWall SonicOSMapped