Adventures of an RDP Honeypot – Part One: RDP Security
ID: 91266a67-162c-5a66-b04c-245154a58ab2
STIX ID: report--91266a67-162c-5a66-b04c-245154a58ab2
Feed Name: TrustedSec blog
Threat Score
This post warns that exposing Microsoft RDP to the Internet is highly risky, documents prolific brute-force activity observed on an RDP honeypot (58,000+ attempts in nine days), describes how attackers pivot to deploy crypto-miners and ransomware or gain domain admin, and provides mitigation advice—use VPNs/MFA, enable NLA, restrict logon rights, use RD Gateway, and maintain strong logging and password/account policies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
