BigHugger
sk Skill · mukul975

detecting-rdp-brute-force-attacks

Detect RDP brute force attacks by parsing Windows Security Event Logs (EVTX files, via python-evtx) for failed logon patterns (Event ID 4625, Logon Type 10/3), correlating with successful logons (Event ID 4624), and analyzing NLA failures and source IP frequency. Use when investigating exposed RDP endpoints, building SIEM detection rules for credential guessing, or confirming whether a compromised account followed a…

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
Pythonsiemblue-teamwindows-event-logsbrute-forcerdpthreat-detection
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python