RDP Port Forwarding Rule Added Via Netsh.EXE (782d6f3e-4c5d-4b8c-92a3-1d05fed72e63)
Detects the execution of netsh to configure a port forwarding of port 3389 (RDP) rule
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
RDP Port Forwarding Rule Added Via Netsh.EXE (782d6f3e-4c5d-4b8c-92a3-1d05fed72e63) | Sigma-Rules | Proxy - T1090 (731f4f55-b6d0-41d1-a7a9-072a66389aea) | Attack Pattern | 1 |