Sub-technique of T1021 Remote Services.View on attack.mitre.org
Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.
Remote desktop is a common feature in operating systems. It allows a user to log into an interactive session with a system desktop graphical user interface on a remote system. Microsoft refers to its implementation of the Remote Desktop Protocol (RDP) as Remote Desktop Services (RDS).
Adversaries may connect to a remote system over RDP/RDS to expand access if the service is enabled and allows access to accounts with known credentials. Adversaries will likely use Credential Access techniques to acquire credentials to use with RDP. Adversaries may also use RDP in conjunction with the Accessibility Features or Terminal Services DLL for Persistence.
Rules on DetectionCode tagged with T1021.001.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Allow Inbound Traffic By Firewall Rule Registry | TTP | NULL | Sysmon EventID 13 |
| Allow Inbound Traffic In Firewall Rule | TTP | NULL | Powershell Script Block Logging 4104 |
| Remote Desktop Network Traffic | Anomaly | NULL | Zeek Conn |
| Remote Desktop Process Running On System | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Default RDP File Creation | Anomaly | NULL | Sysmon EventID 11 |
| Windows Default RDP File Creation By Non MSTSC Process | Anomaly | NULL | Sysmon EventID 1 AND Sysmon EventID 11 |
| Windows Default Rdp File Unhidden | Anomaly | NULL | Sysmon EventID 1 |
| Windows MSTSC RDP Commandline | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Process Execution From RDP Share | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows RDP Bitmap Cache File Creation | Anomaly | NULL | Sysmon EventID 11 |
| Windows RDP Client Launched with Admin Session | Anomaly | NULL | Sysmon EventID 1 |
| Windows RDP File Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows RDP Login Session Was Established | Anomaly | NULL | Windows Event Log Security 4624 |
| Windows RDP Server Registry Entry Created | Anomaly | NULL | Sysmon EventID 13 |
| Windows Remote Service Rdpwinst Tool Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Remote Services Allow Rdp In Firewall | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Remote Services Allow Remote Assistance | Anomaly | NULL | Sysmon EventID 13 |
| Windows Remote Services Rdp Enable | TTP | NULL | Sysmon EventID 13 |
| Used by | Procedure example |
|---|---|
| GroupAgrius | Agrius tunnels RDP traffic through deployed web shells to access victim environments via compromised accounts. Agrius used the Plink tool to tunnel RDP connections for remote access and lateral movement in victim environments. |
| GroupAkira | Akira has used RDP for lateral movement. |
| GroupAPT1 | The APT1 group is known to have used RDP during operations. |
| GroupAPT3 | APT3 enables the Remote Desktop Protocol for persistence. APT3 has also interacted with compromised systems to browse and copy files through RDP sessions. |
| GroupAPT39 | APT39 has been seen using RDP for lateral movement and persistence, in some cases employing the rdpwinst tool for mangement of multiple sessions. |
| GroupAPT41 | APT41 used RDP for lateral movement. APT41 used NATBypass to expose local RDP ports on compromised systems to the Internet. |
| GroupAPT5 | APT5 has moved laterally throughout victim environments using RDP. |
| GroupAquatic Panda | Aquatic Panda leveraged stolen credentials to move laterally via RDP in victim environments. |
| Used by | Procedure example |
|---|---|
| MalwareCarbanak | Carbanak enables concurrent Remote Desktop Protocol (RDP) sessions. |
| MalwareCobalt Strike | Cobalt Strike can start a VNC-based remote desktop server and tunnel the connection through the already established C2 channel. |
| MalwareDarkComet | DarkComet can open an active screen of the victim’s machine and take control of the mouse and keyboard. |
| ToolImminent Monitor | Imminent Monitor has a module for performing remote desktop access. |
| MalwarejRAT | jRAT can support RDP control. |
| ToolKoadic | Koadic can enable remote desktop on the victim's machine. |
| MalwarenjRAT | njRAT has a module for performing remote desktop access. |
| ToolPupy | Pupy can enable/disable RDP connection and can start a remote desktop session using a browser web socket client. |
| Used by | Procedure example |
|---|---|
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, adversaries utilized RDP to log into jump hosts and then moved laterally to other victim devices to include a domain controller. |
| CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 used RDP for lateral movement. |
| CampaignC0015 | During C0015, the threat actors used RDP to access specific network hosts of interest. |
| CampaignC0018 | During C0018, the threat actors opened a variety of ports to establish RDP connections, including ports 28035, 32467, 41578, and 46892. |
| CampaignC0032 | During the C0032 campaign, TEMP.Veles utilized RDP throughout an operation. |
| CampaignCutting Edge | During Cutting Edge, threat actors used RDP with compromised credentials for lateral movement. |
| CampaignHomeLand Justice | During HomeLand Justice, threat actors primarily used RDP for lateral movement in the victim environment. |
| CampaignOperation Digital Eye | During Operation Digital Eye, threat actors moved laterally using RDP. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.