Detect Remote Desktop Protocol (RDP) activity that could indicate malicious or unauthorised access.
This activity is categorised as Lateral Movement / Remote Desktop Protocol in the killchain and ATT&CK frameworks respectively.
The strategy consists of:
- Collecting Windows authentication logs
- Checking remote logon type events for unauthorised user access