Windows: Outbound RDP (3389) Connections Initiated by Non-Standard Processes

Alerts on outbound port 3389 connections on Windows when initiated by an unapproved process, suggesting non-standard RDP tooling.

FreeReviewedSigma · High · v2
Product
windows
Category
network_connection
Author
Markus Neis (SigmaHQ), DRL 1.1
Published
2019-05-15
Updated
2026-07-31

ATT&CK techniques

Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies outbound network connections to destination port 3389 that are initiated by processes other than the expected mstsc.exe RDP client and other commonly allowed RDP-related binaries. Attackers may use alternate tools to establish RDP sessions for lateral movement while avoiding detection tied to mstsc.exe. The rule relies on Windows network connection telemetry with fields for destination port, initiation status, and the initiating process image path (including image exceptions).

Related detections9 linkedT1021.001 — drag to rearrange
Suspicious Enabling of Remote Desktop via fDenyTSConnections Registry by DeadLock Ransomware
Suspicious Plink SSH Tunnel Execution (via process_creation)
Suspicious Remote Desktop Enabled via fDenyTSConnections Registry by Sandworm
Suspicious RDP Shadow Session Started - Native (via rdp)
Malicious RDP BlueeKeep Connection Closed - CVE-2019-0708 (via rdp)
Obfuscated RDP Tunneling Configuration Enabled for Port Forwarding (via process_creation)
Malicious RDP Shadow Session Configuration Enabled - Registry (via registry_event)
Malicious RDP Tunneling (via rdp)
Suspicious Denied RDP Login with Valid Credentials (via security)
Windows: Outbound RDP (3389) Connections Initiated by Non-Standard Processes
Pivot detection · T1021.001 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.