Elastic low stable eql

Unusual Windows Remote User

A machine learning job detected an unusual remote desktop protocol (RDP) username, which can indicate account takeover or credentialed persistence using compromised accounts. RDP attacks, such as BlueKeep, also tend to use unusual usernames.

View Source

Detection Logic

False Positives

  • Uncommon username activity can be due to an engineer logging onto a server instance in order to perform manual troubleshooting or reconfiguration.

Field Validations

Loading…

Comments (0)

Loading comments...