Elastic medium stable eql
Remote Desktop Enabled in Windows Firewall by Netsh
Identifies use of the network shell utility (netsh.exe) to enable inbound Remote Desktop Protocol (RDP) connections in the Windows Firewall.
Detection Logic
process where host.os.type == "windows" and event.type == "start" and
(process.name : "netsh.exe" or ?process.pe.original_file_name == "netsh.exe") and
process.args : ("localport=3389", "RemoteDesktop", "group=\"remote desktop\"") and
process.args : ("action=allow", "enable=Yes", "enable") Field Validations
Loading…
Comments (0)
Loading comments...