Windows RDP Successful Logon (4624 LogonType 10) from Public IP

Alerts on successful RDP (LogonType 10) from a non-private, non-local source IP in Windows Security Event 4624.

FreeReviewedSigma · Medium · v2
Product
windows
Service
security
Author
Micah Babinski (@micahbabinski), Zach Mathis (@yamatosecurity) (SigmaHQ), DRL 1.1
Published
2023-01-19
Updated
2026-07-31

ATT&CK techniques

Initial Access → Cred Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule flags successful Windows logon events (Event ID 4624) with LogonType 10, excluding logons where the source IP is within common private/local IPv4 and IPv6 ranges or is blank. Such activity can indicate a client connecting over RDP from an internet-facing or otherwise public address, which may correspond to publicly exposed RDP services. It relies on Windows Security log telemetry, specifically the IpAddress, EventID, and LogonType fields from the 4624 event.

Related detections9 linkedT1078 — drag to rearrange
Windows Successful SMB Logon (Event ID 4624 Logon Type 3) From Public IPs
OpenCanary Telnet Login Attempt Recorded in Application Logs
OpenCanary application logs: SSH new connection attempt on monitored node
OpenCanary Application Logs: SSH Login Attempt on Monitoring Node
Cisco LDP MD5 Authentication Failure Events
Cisco BGP Authentication Failure Events Indicating Potential Credential Attacks
Huawei BGP Authentication Failures Indicating Failed Session Attempts
Juniper BGP Logs: Missing MD5 Digest in Route Authentication
Windows Failed Logon (Event ID 4625) From Non-Private Public IP
Windows RDP Successful Logon (4624 LogonType 10) from Public IP
Pivot detection · T1078 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.