{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/lateral-movement-detection/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Elastic Defend (\u003e= 8.18)","Lateral Movement Detection"],"_cs_severities":["low"],"_cs_tags":["lateral-movement","rdp","machine-learning","elastic-defend"],"_cs_type":"advisory","_cs_vendors":["Elastic"],"content_html":"\u003cp\u003eThis brief details a machine learning detection rule from Elastic, designed to identify lateral movement activities within a network. The rule triggers when an anomalous spike is observed in the number of distinct destination IP addresses that a single source IP initiates Remote Desktop Protocol (RDP) connections to. This behavior often signifies that an attacker, having initially compromised a system, is attempting to expand their foothold by identifying and connecting to additional systems within the environment to locate valuable assets, exfiltrate data, or establish further access points. The detection leverages Elastic's anomaly detection capabilities and requires the Lateral Movement Detection integration and Elastic Defend to collect relevant RDP process events from Windows hosts. This rule is crucial for early identification of potential unauthorized access attempts and limiting an adversary's ability to move freely across the network.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003eInitial Access\u003c/strong\u003e: An attacker gains initial access to an internal system within the target network through various means (e.g., phishing, exploiting a public-facing application).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eInternal Reconnaissance\u003c/strong\u003e: From the compromised system, the attacker performs internal reconnaissance to identify other potential target systems, often scanning for active RDP services.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eCredential Access\u003c/strong\u003e: The attacker obtains valid credentials for other systems through techniques like credential dumping, keylogging, or exploiting credential stores on the initial host.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eRDP Connection Attempts\u003c/strong\u003e: Using the compromised system as a pivot, the attacker initiates RDP connections to a large number of discovered internal hosts using the stolen credentials, aiming to find further exploitable systems.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eSuccessful RDP Sessions\u003c/strong\u003e: The attacker successfully establishes multiple RDP sessions with several internal hosts, indicating expanded access. This activity generates a spike in distinct RDP connections from the initial compromised source IP.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFurther Lateral Movement \u0026amp; Persistence\u003c/strong\u003e: The attacker utilizes the newly accessed systems to continue lateral movement, establish persistence, or conduct further reconnaissance to identify high-value targets.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eObjective Attainment\u003c/strong\u003e: The attacker executes their final objective, which could include data exfiltration, deployment of ransomware, or critical infrastructure disruption.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eIf lateral movement through RDP goes undetected, attackers can significantly broaden their access within an organization's network. This can lead to the compromise of multiple sensitive systems, exfiltration of critical data, deployment of ransomware across numerous endpoints, or establishment of persistent access mechanisms. The undetected lateral movement allows adversaries to escalate privileges, discover and exploit high-value targets, and ultimately achieve their mission objectives with greater ease and impact, potentially leading to severe financial, reputational, and operational damage.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eEnable\u003c/strong\u003e the Lateral Movement Detection integration in Elastic Fleet, ensuring the \u003ccode\u003elmd_high_rdp_distinct_count_destination_ip_for_source_ea\u003c/code\u003e machine learning job is deployed and active to detect anomalous RDP connection spikes.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eConfigure\u003c/strong\u003e Elastic Defend on all Windows endpoints (version 8.18 and above) to collect \u003ccode\u003ehost.ip\u003c/code\u003e fields as outlined in Elastic's helper guide, which is essential for this rule's operation.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eReview\u003c/strong\u003e and \u003cstrong\u003ewhitelist\u003c/strong\u003e IP addresses associated with legitimate administrative tasks, automated network management tools, load balancers, proxy servers, security scans, or remote work solutions (VPNs) to reduce false positives, as mentioned in the rule's \u003ccode\u003efalse positive analysis\u003c/code\u003e section.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eImplement\u003c/strong\u003e network segmentation and strong access controls to limit RDP access to only necessary systems and users, minimizing the attack surface.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eEstablish\u003c/strong\u003e a process for reviewing alerts generated by the \u003ccode\u003eSpike in Number of Connections Made from a Source IP\u003c/code\u003e rule and follow the recommended investigation steps to quickly identify and respond to potential threats.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T18:09:23Z","date_published":"2026-07-28T18:09:23Z","id":"https://feed.craftedsignal.io/briefs/2026-07-spike-in-rdp-connections/","summary":"A machine learning detection rule identifies lateral movement by flagging an unusual spike in the number of destination IPs establishing Remote Desktop Protocol (RDP) connections with a single source IP, indicating an attacker attempting to expand access within the network to discover valuable assets or further access points.","title":"Spike in Number of Connections Made from a Source IP","url":"https://feed.craftedsignal.io/briefs/2026-07-spike-in-rdp-connections/"}],"language":"en","title":"CraftedSignal Threat Feed - Lateral Movement Detection","version":"https://jsonfeed.org/version/1.1"}