Elastic medium stable eql
Remote Desktop File Opened from Suspicious Path
Identifies attempts to open a remote desktop file from suspicious paths. Adversaries may abuse RDP files for initial access.
Detection Logic
process where host.os.type == "windows" and event.type == "start" and
process.name : "mstsc.exe" and
process.args : ("?:\\Users\\*\\Downloads\\*.rdp",
"?:\\Users\\*\\AppData\\Local\\Temp\\Temp?_*.rdp",
"?:\\Users\\*\\AppData\\Local\\Temp\\7z*.rdp",
"?:\\Users\\*\\AppData\\Local\\Temp\\Rar$*\\*.rdp",
"?:\\Users\\*\\AppData\\Local\\Temp\\BNZ.*.rdp",
"?:\\Users\\*\\AppData\\Local\\Microsoft\\Windows\\INetCache\\Content.Outlook\\*.rdp") Field Validations
Loading…
Comments (0)
Loading comments...