Exposed remote desktop is accessed
A remote desktop service is reachable from the internet and protected only by a password. Using guessed or reused credentials, the attacker logs in and gains an interactive session on the host.
Log in interactively to an internet-exposed remote desktop host.
- Remove direct internet exposure of remote desktop; require VPN + MFA or a gateway
- Account lockout and strong, unique credentials
- Geo/IP restrictions and network-level authentication
- Remote-desktop logon attempts and successes from external IPs
- Brute-force / spraying patterns against the service
- Interactive logon at unusual times
- External assessment identifying exposed remote-desktop services
- Test credential strength and lockout behaviour
- Review exposure and gateway/MFA controls
The attacker has hands-on-keyboard access to a system inside the network.