Possible RD Web Access Brute Force via Repeated Login POST Requests

PremiumReviewedSigma · Low · v1
Category
webserver
Author
HuntRule
Published
2026-10-02
Updated
2026-10-02

ATT&CK techniques

Initial Access → Cred Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Priv Esc

  5. Defense Evasion

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects HTTP POST requests to the Remote Desktop Web Access login endpoint, matching the RDWeb brute-force activity observed in a terminal server phishing intrusion. Adversaries automate large volumes of credential guesses against the RDWeb form where an HTTP 302 response indicates a successful authentication. High-volume POSTs to this endpoint signal password guessing against externally exposed remote access.

Related detections9 linkedT1110.003 — drag to rearrange
Suspicious M365 Sign-In from Programmatic Password Spraying User Agent
Suspicious Entra ID Password Spraying via ROPC Grant to Azure CLI App
Suspicious Entra ROPC Password Spray Against Azure CLI Client
Suspicious Security Group Ingress Rule Opened to the Internet via CloudTrail
SplashTop Network
Suspicious SoftEther VPN Hamcore Config Written to ProgramData (via file_event)
Suspicious Go HTTP Client User Agent via Proxy
Suspicious macOS Local Credential Validation via dscl authonly
Suspicious Bruteforce via Password Reset (via security)
Possible RD Web Access Brute Force via Repeated Login POST Requests
Pivot detection · T1110.003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.