Windows: Uncommon Process Creates .rdp Remote Desktop File

Alerts on creation of .rdp files by processes that are not typically associated with producing them on Windows.

FreeReviewedSigma · High · v2
Product
windows
Category
file_event
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-04-18
Updated
2026-07-31

What it detects

This rule identifies file creation events where the target filename ends with .rdp and the creating process image matches a set of applications that are uncommon sources for generating Remote Desktop Protocol files. Attackers can use rogue .rdp files as an initial access or stealth mechanism, so alerting on these unexpected creators helps surface suspicious file artifacts. The rule relies on Windows file event telemetry that records the created filename and the process image responsible for the creation.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.