{"id":"T1021.001","name":"Remote Desktop Protocol","url":"https://attack.mitre.org/techniques/T1021/001","tactics":["lateral-movement"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0327","stix_id":"x-mitre-detection-strategy--722d2e3d-c3ad-4878-bcef-ca3161465342","name":"Multi-event Detection Strategy for RDP-Based Remote Logins and Post-Access Activity","url":"https://attack.mitre.org/detectionstrategies/DET0327","analytics":[{"id":"AN0931","stix_id":"x-mitre-analytic--63fcb4be-f5c2-47da-951d-cd1b4f1a2cc0","name":"Analytic 0931","description":"Remote Desktop (RDP) logon by a user followed by unusual process execution, file access, or lateral movement activity within a short timeframe.","url":"https://attack.mitre.org/detectionstrategies/DET0327#AN0931","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4624, 4648","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Security","channel":"EventCode=4778, EventCode=4779","data_component":"DC0088","data_component_name":"Logon Session Metadata","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Temporal threshold to correlate login with post-login activity (e.g., 5 minutes)"},{"field":"UserContext","description":"Tune for non-admin users or service accounts expected to use RDP"},{"field":"ProcessList","description":"Define suspicious post-login processes such as cmd.exe, powershell.exe, certutil.exe"},{"field":"HostAccessPatterns","description":"Scope detection to uncommon or first-time access between source and destination hosts"}],"live":true,"detection_strategies":["DET0327"],"techniques":["T1021.001"]}],"live":true,"version":"1.0","techniques":["T1021.001"]}],"sigma_rules":[{"id":"0d5675be-bc88-4172-86d3-1e96a4476536","title":"Potential Tampering With RDP Related Registry Keys Via Reg.EXE","author":"pH-T (Nextron Systems), @Kostastsale, TheDFIRReport","status":"test","level":"high","date":"2022-02-12","modified":"2025-11-22","description":"Detects the execution of \"reg.exe\" for enabling/disabling the RDP service on the host by tampering with the 'CurrentControlSet\\Control\\Terminal Server' values","references":["https://thedfirreport.com/2022/02/21/qbot-and-zerologon-lead-to-full-domain-compromise/","http://etutorials.org/Microsoft+Products/microsoft+windows+server+2003+terminal+services/Chapter+6+Registry/Registry+Keys+for+Terminal+Services/","http://woshub.com/rds-shadow-how-to-connect-to-a-user-session-in-windows-server-2012-r2/","https://admx.help/HKLM/SOFTWARE/Policies/Microsoft/Windows%20NT/Terminal%20Services","https://bazaar.abuse.ch/sample/6f3aa9362d72e806490a8abce245331030d1ab5ac77e400dd475748236a6cc81/","https://blog.sekoia.io/darkgate-internals/","https://blog.talosintelligence.com/understanding-the-phobos-affiliate-structure/","https://github.com/redcanaryco/atomic-red-team/blob/02c7d02fe1f1feb0fc7944550408ea8224273994/atomics/T1112/T1112.md#atomic-test-63---disable-remote-desktop-anti-alias-setting-through-registry","https://github.com/redcanaryco/atomic-red-team/blob/02c7d02fe1f1feb0fc7944550408ea8224273994/atomics/T1112/T1112.md#atomic-test-64---disable-remote-desktop-security-settings-through-registry","https://github.com/redcanaryco/atomic-red-team/blob/dd526047b8c399c312fee47d1e6fb531164da54d/atomics/T1112/T1112.yaml#L790","https://learn.microsoft.com/en-us/windows-hardware/customize/desktop/unattend/microsoft-windows-terminalservices-rdp-winstationextensions-securitylayer","https://threathunterplaybook.com/hunts/windows/190407-RegModEnableRDPConnections/notebook.html","https://twitter.com/SagieSec/status/1469001618863624194?t=HRf0eA0W1YYzkTSHb-Ky1A&s=03","https://web.archive.org/web/20200929062532/https://blog.menasec.net/2019/02/threat-hunting-rdp-hijacking-via.html","https://www.trendmicro.com/en_us/research/25/i/unmasking-the-gentlemen-ransomware.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.lateral-movement","attack.defense-impairment","attack.t1021.001","attack.t1112"],"path":"rules/windows/process_creation/proc_creation_win_reg_rdp_keys_tamper.yml","techniques":["T1021.001","T1112"],"cves":[]},{"id":"1fc0809e-06bf-4de3-ad52-25e5263b7623","title":"Publicly Accessible RDP Service","author":"Josh Brower @DefensiveDepth","status":"test","level":"high","date":"2020-08-22","modified":"2024-03-13","description":"Detects connections from routable IPs to an RDP listener. Which is indicative of a publicly-accessible RDP service.\n","references":[],"logsource":{"product":"zeek","service":"rdp"},"tags":["attack.lateral-movement","attack.t1021.001"],"path":"rules/network/zeek/zeek_rdp_public_listener.yml","techniques":["T1021.001"],"cves":[]},{"id":"2f974656-6d83-4059-bbdf-68ac5403422f","title":"Hermetic Wiper TG Process Patterns","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-02-25","modified":"2022-09-09","description":"Detects process execution patterns found in intrusions related to the Hermetic Wiper malware attacks against Ukraine in February 2022","references":["https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/ukraine-wiper-malware-russia"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.lateral-movement","attack.t1021.001","detection.emerging-threats"],"path":"rules-emerging-threats/2022/Malware/Hermetic-Wiper/proc_creation_win_malware_hermetic_wiper_activity.yml","techniques":["T1021.001"],"cves":[]},{"id":"327f48c1-a6db-4eb8-875a-f6981f1b0183","title":"Port Forwarding Activity Via SSH.EXE","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-10-12","modified":"2024-03-05","description":"Detects port forwarding activity via SSH.exe","references":["https://www.absolomb.com/2018-01-26-Windows-Privilege-Escalation-Guide/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.lateral-movement","attack.t1572","attack.t1021.001","attack.t1021.004"],"path":"rules/windows/process_creation/proc_creation_win_ssh_port_forward.yml","techniques":["T1572","T1021.001","T1021.004"],"cves":[]},{"id":"48a61b29-389f-4032-b317-b30de6b95314","title":"Suspicious Plink Port Forwarding","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2021-01-19","modified":"2022-10-09","description":"Detects suspicious Plink tunnel port forwarding to a local port","references":["https://www.real-sec.com/2019/04/bypassing-network-restrictions-through-rdp-tunneling/","https://medium.com/@informationsecurity/remote-ssh-tunneling-with-plink-exe-7831072b3d7d"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1572","attack.lateral-movement","attack.t1021.001"],"path":"rules/windows/process_creation/proc_creation_win_plink_port_forwarding.yml","techniques":["T1572","T1021.001"],"cves":[]},{"id":"4b8f6d3a-9c5e-4f2a-a7d8-6b9c3e5f2a8d","title":"RDP Enable or Disable via Win32_TerminalServiceSetting WMI Class","author":"Daniel Koifman (KoifSec), Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"medium","date":"2025-11-15","modified":null,"description":"Detects enabling or disabling of Remote Desktop Protocol (RDP) using alternate methods such as WMIC or PowerShell.\nIn PowerShell one-liner commands, the \"SetAllowTSConnections\" method of the \"Win32_TerminalServiceSetting\" class may be used to enable or disable RDP.\nIn WMIC, the \"rdtoggle\" alias or \"Win32_TerminalServiceSetting\" class may be used for the same purpose.\n","references":["https://www.trendmicro.com/en_gb/research/22/e/uncovering-a-kingminer-botnet-attack-using-trend-micro-managed-x.html","https://github.com/HackTricks-wiki/hacktricks/blob/72f20a3fa26775b932bd819f1824c6377802a768/src/windows-hardening/basic-cmd-for-pentesters.md#firewall","https://github.com/Lifailon/RSA/blob/rsa/Sources/RSA-1.4.1.ps1#L1468"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.lateral-movement","attack.t1021.001","attack.execution","attack.t1047"],"path":"rules/windows/process_creation/proc_creation_win_rdp_enable_or_disable_via_win32_terminalservicesetting_wmi_class.yml","techniques":["T1021.001","T1047"],"cves":[]},{"id":"51e33403-2a37-4d66-a574-1fda1782cc31","title":"RDP Login from Localhost","author":"Thomas Patzke","status":"test","level":"high","date":"2019-01-28","modified":"2022-10-09","description":"RDP login with localhost source address may be a tunnelled login","references":["https://www.fireeye.com/blog/threat-research/2019/01/bypassing-network-restrictions-through-rdp-tunneling.html"],"logsource":{"product":"windows","service":"security"},"tags":["attack.lateral-movement","car.2013-07-002","attack.t1021.001"],"path":"rules/windows/builtin/security/account_management/win_security_rdp_localhost_login.yml","techniques":["T1021.001"],"cves":[]},{"id":"598290cf-5932-45cd-9123-be1e05ab4f2e","title":"OpenCanary - RDP New Connection Attempt","author":"Marco Pedrinazzi (@pedrinazziM)","status":"experimental","level":"high","date":"2026-01-06","modified":null,"description":"Detects instances where an RDP service on an OpenCanary node has had a connection attempt.","references":["https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration","https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52"],"logsource":{"product":"opencanary","category":"application"},"tags":["attack.initial-access","attack.lateral-movement","attack.persistence","attack.t1133","attack.t1021.001"],"path":"rules/application/opencanary/opencanary_rdp_connection_attempt.yml","techniques":["T1133","T1021.001"],"cves":[]},{"id":"5bed80b6-b3e8-428e-a3ae-d3c757589e41","title":"RDP over Reverse SSH Tunnel WFP","author":"Samir Bousseaden","status":"test","level":"high","date":"2019-02-16","modified":"2022-09-02","description":"Detects svchost hosting RDP termsvcs communicating with the loopback address","references":["https://twitter.com/SBousseaden/status/1096148422984384514","https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES/blob/44fbe85f72ee91582876b49678f9a26292a155fb/Command%20and%20Control/DE_RDP_Tunnel_5156.evtx"],"logsource":{"product":"windows","service":"security"},"tags":["attack.command-and-control","attack.lateral-movement","attack.t1090.001","attack.t1090.002","attack.t1021.001","car.2013-07-002"],"path":"rules/windows/builtin/security/win_security_rdp_reverse_tunnel.yml","techniques":["T1090.001","T1090.002","T1021.001"],"cves":[]},{"id":"5f699bc5-5446-4a4a-a0b7-5ef2885a3eb4","title":"RDP Over Reverse SSH Tunnel","author":"Samir Bousseaden","status":"test","level":"high","date":"2019-02-16","modified":"2024-03-12","description":"Detects svchost hosting RDP termsvcs communicating with the loopback address and on TCP port 3389","references":["https://twitter.com/cyb3rops/status/1096842275437625346"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.command-and-control","attack.t1572","attack.lateral-movement","attack.t1021.001","car.2013-07-002"],"path":"rules/windows/network_connection/net_connection_win_rdp_reverse_tunnel.yml","techniques":["T1572","T1021.001"],"cves":[]},{"id":"8e5c03fa-b7f0-11ea-b242-07e0576828d9","title":"Denied Access To Remote Desktop","author":"Pushkarev Dmitry","status":"test","level":"medium","date":"2020-06-27","modified":"2021-11-27","description":"This event is generated when an authenticated user who is not allowed to log on remotely attempts to connect to this computer through Remote Desktop.\nOften, this event can be generated by attackers when searching for available windows servers in the network.\n","references":["https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4825"],"logsource":{"product":"windows","service":"security"},"tags":["attack.lateral-movement","attack.t1021.001"],"path":"rules/windows/builtin/security/win_security_not_allowed_rdp_access.yml","techniques":["T1021.001"],"cves":[]},{"id":"954f0af7-62dd-418f-b3df-a84bc2c7a774","title":"New Remote Desktop Connection Initiated Via Mstsc.EXE","author":"frack113","status":"test","level":"medium","date":"2022-01-07","modified":"2024-06-04","description":"Detects the usage of \"mstsc.exe\" with the \"/v\" flag to initiate a connection to a remote server.\nAdversaries may use valid accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1021.001/T1021.001.md#t1021001---remote-desktop-protocol","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/mstsc"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.lateral-movement","attack.t1021.001"],"path":"rules/windows/process_creation/proc_creation_win_mstsc_remote_connection.yml","techniques":["T1021.001"],"cves":[]},{"id":"b1e5da3b-ca8e-4adf-915c-9921f3d85481","title":"RDP to HTTP or HTTPS Target Ports","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-04-29","modified":"2022-07-14","description":"Detects svchost hosting RDP termsvcs communicating to target systems on TCP port 80 or 443","references":["https://twitter.com/tekdefense/status/1519711183162556416?s=12&t=OTsHCBkQOTNs1k3USz65Zg","https://www.mandiant.com/resources/bypassing-network-restrictions-through-rdp-tunneling"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.command-and-control","attack.t1572","attack.lateral-movement","attack.t1021.001","car.2013-07-002"],"path":"rules/windows/network_connection/net_connection_win_rdp_to_http.yml","techniques":["T1572","T1021.001"],"cves":[]},{"id":"ed74fe75-7594-4b4b-ae38-e38e3fd2eb23","title":"Outbound RDP Connections Over Non-Standard Tools","author":"Markus Neis","status":"test","level":"high","date":"2019-05-15","modified":"2024-02-09","description":"Detects Non-Standard tools initiating a connection over port 3389 indicating possible lateral movement.\nAn initial baseline is required before using this utility to exclude third party RDP tooling that you might use.\n","references":["https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.lateral-movement","attack.t1021.001","car.2013-07-002"],"path":"rules/windows/network_connection/net_connection_win_rdp_outbound_over_non_standard_tools.yml","techniques":["T1021.001"],"cves":[]},{"id":"f72aa3e8-49f9-4c7d-bd74-f8ab84ff9bbb","title":"Suspicious RDP Redirect Using TSCON","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2018-03-17","modified":"2023-05-16","description":"Detects a suspicious RDP session redirect using tscon.exe","references":["http://www.korznikov.com/2017/03/0-day-or-feature-privilege-escalation.html","https://medium.com/@networksecurity/rdp-hijacking-how-to-hijack-rds-and-remoteapp-sessions-transparently-to-move-through-an-da2a1e73a5f6","https://www.hackingarticles.in/rdp-session-hijacking-with-tscon/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.lateral-movement","attack.t1563.002","attack.t1021.001","car.2013-07-002"],"path":"rules/windows/process_creation/proc_creation_win_tscon_rdp_redirect.yml","techniques":["T1563.002","T1021.001"],"cves":[]},{"id":"ffa28e60-bdb1-46e0-9f82-05f7a61cc06e","title":"User Added to Remote Desktop Users Group","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2021-12-06","modified":"2022-09-09","description":"Detects addition of users to the local Remote Desktop Users group via \"Net\" or \"Add-LocalGroupMember\".","references":["https://www.microsoft.com/security/blog/2021/11/16/evolving-trends-in-iranian-threat-actor-activity-mstic-presentation-at-cyberwarcon-2021/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.initial-access","attack.persistence","attack.lateral-movement","attack.t1133","attack.t1136.001","attack.t1021.001"],"path":"rules/windows/process_creation/proc_creation_win_susp_add_user_remote_desktop_group.yml","techniques":["T1133","T1136.001","T1021.001"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2024-53704","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-22952","state":"stale","mapping_types":["secondary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}