logo

Threat Hunting - Outbound RDP Surprises

ID: b5ab633b-b1fa-5178-a88c-89b6abc22e35

STIX ID: report--b5ab633b-b1fa-5178-a88c-89b6abc22e35

Feed Name: TrustedSec blog

Threat Score
55/100

Date Published: 2025-04-25

Date Updated: 2026-05-01

...
...

This threat-hunting write-up describes detection and investigation of suspicious outbound RDP and VPN client connections from internal hosts to an externally exposed Synology NAS in Hungary. Using SIEM, firewall syslog, Shodan, Urlscan, and EDR data the author identified exposed RDP and web services, a recently issued SSL certificate, and evidence that the NAS may be port-forwarding RDP and hosting VPN services; the report highlights gaps in egress controls, lack of baselining, and recommends restricting outbound RDP, enforcing B2B VPNs, and detecting unauthorized VPN usage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.