RDP attack containment

Advanced EPDR generates an incident when it detects and blocks traffic from computers that use the RDP (Remote Desktop Protocol) as an infection vector:

  • Logs remote access attempts via RDP on each protected computer over the last 24 hours, which originated outside the customer network.

  • Determines whether the computer is subject to an RDP brute force attack.

  • Detects if any of the computer accounts have already been compromised to access resources on the system.

  • Blocks RDP connections to mitigate the attack.

This topic includes these sections:

RDP attack containment modes

RDP attack containment can have these statuses:

Initial RDP attack containment mode

When a computer receives a large number of RDP connection attempts, Advanced EPDR puts the computer into Initial RDP attack containment mode. In this mode, RDP access to the computer is blocked from IPs outside the customer network that have sent a large number of connection attempts over the last 24 hours.

Restrictive RDP attack containment mode

When the attacker is able to successfully log in to an account that previously failed due to invalid credentials, the computer in Initial RDP attack containment mode moves to the Restrictive RDP attack containment mode. The account is considered to be compromised. Depending on the settings you have configured, all external RDP connections that have tried to connect at least once with the target computer in the previous 24 hours are blocked. See Indicators of attack settings.

Automatically end RDP attack containment mode

Twenty-four hours after containment mode begins, Advanced EPDR evaluates the number of connection attempts via RDP. If it is below default threshold, Advanced EPDR automatically ends RDP attack containment mode. If the attempts continue, then the containment mode continues for another 24 hours.

IP addresses blocked in restrictive RDP attack containment mode continue to be blocked even after the RDP attack has finished. The security software identifies the IP addresses that cybercriminals are using to attack the customer network and, as they are blocked, the attack is neutralized and the containment mode ends.

If Advanced EPDR automatically ends containment mode, it does not release the IP addresses and continues to block them.

Manually end RDP attack containment mode

To manually end RDP attack containment mode from a list:

  • Open the list and select the checkboxes for the computers you want to end RDP attack containment mode for. A toolbar appears.

  • Click End RDP attack containment mode . When the device is accessible and has real-time communication enabled, the action is executed immediately. If Advanced EPDR is unable to contact the computer, the computer continues in containment mode. Advanced EPDR sends the command again every 4 hours for the next 7 days.

To manually end RDP attack containment mode on the computer details page:

  • Open one of the lists specified in Finding network computers in RDP attack containment mode. Select the computer. The computer details page opens.

  • Click End RDP attack containment mode. When the device is accessible and has real-time communication enabled, the action is executed immediately. If Advanced EPDR is unable to contact the computer, the computer continues in containment mode. Advanced EPDR sends the command again every 4 hours for the next 7 days.

When you manually end containment mode:

  • All IP addresses recorded and blocked on the computer are released.

  • The computer allows RDP connections.

Finding network computers in RDP attack containment mode

You can use these resources to find computers in containment mode: