Detection rules › Sigma

Denied Access To Remote Desktop

Severity
medium
Author
Pushkarev Dmitry
Source
upstream

This event is generated when an authenticated user who is not allowed to log on remotely attempts to connect to this computer through Remote Desktop. Often, this event can be generated by attackers when searching for available windows servers in the network.

MITRE ATT&CK coverage

TacticTechniques
Lateral MovementT1021.001 Remote Services: Remote Desktop Protocol

Event coverage

ProviderEvent IDTitle
Security-Auditing4825A user was denied the access to Remote Desktop.

Stages and Predicates

Stage 1: selection