Zeek: Public RDP Connections from Non-Private IPv4/IPv6 Ranges

Alert on Zeek-observed RDP connections originating from non-excluded IP ranges, suggesting external accessibility.

FreeReviewedSigma · High · v2
Product
zeek
Service
rdp
Author
Josh Brower @DefensiveDepth (SigmaHQ), DRL 1.1
Published
2020-08-22
Updated
2026-07-31

ATT&CK techniques

Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags RDP connection attempts where the source IP is in routable or non-routable categories excluded from private or loopback ranges, indicating possible externally reachable RDP access. Attackers may probe or attempt lateral movement via exposed remote desktop services, making unintended exposure a key risk. It relies on Zeek RDP service connection telemetry, using the origin IP address to determine whether the connection matches the specified CIDR ranges.

Related detections9 linkedT1021.001 — drag to rearrange
Suspicious Enabling of Remote Desktop via fDenyTSConnections Registry by DeadLock Ransomware
Suspicious Plink SSH Tunnel Execution (via process_creation)
Suspicious Remote Desktop Enabled via fDenyTSConnections Registry by Sandworm
Suspicious RDP Shadow Session Started - Native (via rdp)
Malicious RDP BlueeKeep Connection Closed - CVE-2019-0708 (via rdp)
Obfuscated RDP Tunneling Configuration Enabled for Port Forwarding (via process_creation)
Malicious RDP Shadow Session Configuration Enabled - Registry (via registry_event)
Malicious RDP Tunneling (via rdp)
Suspicious Denied RDP Login with Valid Credentials (via security)
Zeek: Public RDP Connections from Non-Private IPv4/IPv6 Ranges
Pivot detection · T1021.001 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.