T1133
External Remote Services
Adversaries may leverage external-facing remote services to gain initial access. Remote services such as VPNs, Citrix, and other access mechanisms can be abused.
ATT&CK / Initial Access
Defense strategies
- Multi-factor authentication
- Network segmentation
- Limit external service exposure
- Regular credential rotation
Detection methods
- Monitor authentication logs
- Detect unusual login times/locations
- Track failed authentication attempts