T1021
Remote Services
Adversaries may use Valid Accounts to log into a service specifically designed to accept remote connections, such as RDP, SSH, or SMB.
ATT&CK / Lateral Movement
After initial compromise, ransomware operators often use RDP to move laterally within networks, deploying ransomware to multiple systems.
Defense strategies
- Network segmentation
- Just-in-time access
- Privileged access workstations
- Monitor lateral connections
Detection methods
- Track remote connection patterns
- Monitor for unusual RDP/SSH activity
- Detect admin tool usage
- Baseline normal remote access
D3FEND mappings
3