Detection rules › Kusto Query Language

Rare RDP Connections

Author
Microsoft Security Research
Source
upstream

'Identifies when an RDP connection is new or rare related to any logon type by a given account today compared with the previous 14 days. RDP connections are indicated by the EventID 4624 with LogonType = 10'

MITRE ATT&CK coverage

TacticTechniques
Lateral MovementT1021 Remote Services

Event coverage

ProviderEvent IDTitle
Security-Auditing4624An account was successfully logged on.

Stages and Predicates

Stage 1: source

<union>

Stage 2: union

union of 2 branches

Stage 3: join

Stage 4: summarize

Stage 5: extend

Stage 6: extend

Stage 7: extend

Stage 8: project-away