Beyond the IP: Identifying Compromised Identities in RDP Sessions
ID: 145905f5-ffb2-5595-ad0d-e0fb4b663114
STIX ID: report--145905f5-ffb2-5595-ad0d-e0fb4b663114
Feed Name: Detect FYI
This research article argues defenders should look beyond network-layer indicators (like IPs) and baseline RDP client artifacts—keyboard layout, display resolution, timezone, and OS type—to identify compromised identities and RDP-based hopping. It explains how application-layer metadata is often conveyed unchanged through VPNs or proxies, outlines common attacker obfuscation methods, and provides four practical anomaly-based hunting techniques (locale mismatches, impossible hardware/display resolutions, unexpected clients, and timezone anomalies) to surface unauthorized RDP access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
