SA - SOC176-234 - RDP Brute Force Detected
Автор: InfoSec_Bret
Загружено: 2025-09-20
Просмотров: 222
Continuing with the Security Analyst Path, we tackle an MEDIUM alert for 'RDP Brute Force Detected' event. Was this actual exploitation or just a false alarm?
EventID: 234
Event Time: Mar, 07, 2024, 11:44 AM
Rule: SOC176 - RDP Brute Force Detected
Level: Security Analyst
Source IP Address: 218.92.0.56
Destination IP Address: 172.16.17.148
Destination Hostname: Matthew
Protocol: RDP
Firewall Action: Allowed
Alert Trigger Reason: Login failure from a single source with different non existing accounts
Items in question:
https://www.virustotal.com/gui/ip-add...
https://talosintelligence.com/reputat...
https://otx.alienvault.com/indicator/...
https://www.abuseipdb.com/check/218.9...
NOTES:
https://reliaquest.com/blog/rdp-brute...
https://www.paloaltonetworks.com/blog...
Доступные форматы для скачивания:
Скачать видео mp4
-
Информация по загрузке: