T1133

External Remote Services

Adversaries may leverage external-facing remote services to gain initial access. Remote services such as VPNs, Citrix, and other access mechanisms can be abused.

ATT&CK / Initial Access

Defense strategies

  • Multi-factor authentication
  • Network segmentation
  • Limit external service exposure
  • Regular credential rotation

Detection methods

  • Monitor authentication logs
  • Detect unusual login times/locations
  • Track failed authentication attempts

T1133 on MITRE ATT&CK ↗