Threat hunts for RDP
41 hunts covering RDP, each with a hypothesis, the queries that test it and what the hunt cannot see.
41 hunts
-
critical Part 3 of 3Research by The DFIR Report
Akira Ransomware Exfiltration and Impact
An adversary is exfiltrating bulk data via SFTP using FileZilla and executing Akira ransomware, evidenced by massive outbound network transfers and the destruction of Volume Shadow Copies.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 2 of 3Research by The DFIR Report
Bumblebee Persistence and AD Credential Harvesting
An adversary has established internal persistence through unauthorized remote access tools like RustDesk and is performing Active Directory credential harvesting by dumping the NTDS database and LSASS memory.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 1 of 3Research by The DFIR Report
Bumblebee Delivery and C2 Establishment
An intruder has lured an administrator to a look-alike download page via SEO poisoning, leading to a trojanized installer that side-loads Bumblebee via consent.exe and establishes AdaptixC2.
4 query2 analytic2 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 2 of 2Research by Rapid7
Internal Coercion and Editor Persistence
An adversary is using rogue DHCPv6 services to perform DNS takeover for Kerberos relaying, or has established persistence via unauthorized Kate editor plugins on compromised hosts.
3 query1 analytic1 checkpoint1 action2 taskCVE-2026-18729 · CVE-2026-20929 -
high Part 1 of 2Research by Rapid7
Exploitation of Web-Facing GitLab and Langflow
An adversary is exploiting GitLab unauthenticated file reads or Langflow authenticated RCE to access repository secrets or execute code on the server host, starting from public-facing assets.
3 query1 analytic1 checkpoint1 action2 taskCVE-2026-18729 · CVE-2026-20929 -
critical Part 3 of 3Research by Microsoft
Storm-2570 Data Exfiltration and Ransomware Impact
An intruder is exfiltrating staged directories and Active Directory database fragments using synchronization tools before deploying a ransomware payload for mass encryption.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 1 of 3Research by Microsoft
Storm-2570 Persistent Remote Access and Discovery
An intruder has established redundant persistent access using commercial RMM tools and outbound tunneling utilities to bypass firewalls and conduct internal reconnaissance.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 3 of 3Research by The DFIR Report
Lateral Movement and Ransomware Deployment: The Gentlemen
An adversary has moved laterally from an RMM-controlled beachhead using NetExec or GoTo Resolve to dump credentials and exfiltrate data to Wasabi before initiating domain-wide encryption via GPO.
5 query2 analytic1 checkpoint1 action2 taskCVE-2025-55182 -
high Part 2 of 3Research by The DFIR Report
Decentralized and SaaS C2 Infrastructure
An intruder uses decentralized blockchain gateways or SaaS platforms to resolve C2 configuration and tunnel traffic, bypassing static network perimeter filters.
3 query1 analytic1 checkpoint1 action2 taskCVE-2025-55182 -
high Part 1 of 3Research by The DFIR Report
EtherRAT and TukTuk Initial Infection and Discovery
An intruder has gained initial access via a trojanized MSI installer, established persistence using a Node.js-based EtherRAT, and is currently performing system discovery or sideloading TukTuk payloads.
5 query2 analytic1 checkpoint1 action2 taskCVE-2025-55182 -
high Part 1 of 2Research by The DFIR Report
Bumblebee Delivery and Persistence
An intruder has delivered Bumblebee malware through a trojanized MSI installer via SEO poisoning, using DLL side-loading of consent.exe and establishing persistence with remote management tools like RustDesk.
4 query2 analytic2 checkpoint1 action2 taskcredential access · execution · exfiltration -
high Part 3 of 3Research by The DFIR Report
Persistence and Exfiltration of Lunar Spider
An adversary is maintaining long-term access via a masqueraded .NET backdoor and exfiltrating data via Rclone over FTP to a rare external destination.
4 query1 analytic1 checkpoint1 action2 taskCVE-2020-1472 -
high Part 3 of 3Research by The DFIR Report
Apache ActiveMQ Lateral Movement and Ransomware Impact
An attacker has transitioned from an exploited ActiveMQ server to lateral movement via RDP using stolen credentials, ultimately deploying LockBit ransomware from user-writable directories or with specific execution flags.
3 query1 analytic1 checkpoint1 action2 taskCVE-2023-46604 -
high Part 1 of 3Research by The DFIR Report
ActiveMQ Exploitation and Metasploit Staging
An intruder has exploited CVE-2023-46604 on an ActiveMQ server to run arbitrary code, staged a Metasploit payload, and escalated to SYSTEM privileges using named pipe impersonation.
4 query2 analytic1 checkpoint1 action2 taskCVE-2023-46604 -
high Part 2 of 2Research by The DFIR Report
Bissa Scanner C2 and S3 Exfiltration
An attacker is using Telegram for command-and-control alerts and Filebase S3 for data exfiltration after harvesting secrets from vulnerable application servers.
3 query1 analytic1 checkpoint1 action2 taskCVE-2025-55182 · CVE-2025-9501 -
high Part 1 of 2Research by The DFIR Report
Bissa Scanner Mass Exploitation and Credential Harvesting
An attacker is using the Bissa scanner to exploit unauthenticated vulnerabilities in Next.js or WordPress, then harvesting sensitive credentials from .env files and cloud metadata.
3 query2 analytic2 checkpoint1 action2 taskCVE-2025-55182 · CVE-2025-9501 -
high Part 2 of 2Research by Huntress
INC Ransomware Wave 2: BYOVD and RAT Deployment
An adversary has deployed remote access tools and Bring Your Own Vulnerable Driver (BYOVD) loaders to neutralize security products before executing INC ransomware.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
high Part 1 of 2Research by Sekoia
ErrTraffic: WordPress Infrastructure and Backdoor Maintenance
An adversary has compromised a WordPress server using harvested credentials and installed a PHP backdoor or malicious plugin to facilitate the delivery of ErrTraffic ClickFix lures.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution -
high Part 3 of 3Research by The DFIR Report
SystemBC C2 and WinSCP Exfiltration
An adversary is using SystemBC for proxy tunneling and WinSCP for unencrypted FTP exfiltration from the Public Music directory to known ransomware affiliate infrastructure.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 2 of 3Research by The DFIR Report
Identity-Based Lateral Movement and Credential Access
An intruder has moved laterally to high-value infrastructure like domain controllers and backup servers using hijacked accounts or newly created local admins, then executed scripts to harvest credentials.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 1 of 3Research by The DFIR Report
EarthTime Trojan to Ransomware Reconnaissance
An adversary has gained initial access via a trojanized EarthTime installer, established a beachhead using SectopRAT with MSBuild injection, and is now performing environment discovery using specialized ransomware reconnaissance tools.
6 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 1 of 2Research by Mandiant
Interactive Remote Access and Support Tool Abuse
An intruder uses vishing to direct users to a self-destructing note service and installs unauthorized RMM tools to pivot into corporate VDI infrastructure.
3 query2 analytic2 checkpoint1 action2 taskcollection · execution · exfiltration -
highResearch by Unit 42
Endpoint AI-Assisted Scripting and Credential Dumping
An intruder is using AI-generated scripts with iterative naming conventions to facilitate credential dumping and proxy tunneling across target organizations in Latin America.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution -
high Part 2 of 2Research by The DFIR Report
Interlock RAT C2 and RDP Lateral Movement
An intruder has established a PHP-based RAT beachhead and is using Cloudflare Tunnels for C2 before moving laterally via RDP.
4 query1 analytic1 checkpoint1 action2 taskcommand and control · discovery · execution -
high Part 1 of 2Research by The DFIR Report
Interlock RAT Endpoint Execution and Reconnaissance
An intruder has deployed a PHP-based RAT into user-writable directories via a PowerShell stager and is conducting automated system reconnaissance to map the environment.
6 query2 analytic1 checkpoint1 action2 taskcommand and control · discovery · execution -
critical Part 3 of 3Research by The DFIR Report
Akira Ransomware Deployment and Credential Access
An intruder has escalated privileges through NTDS dumping and database credential harvesting, and is now exfiltrating data before deploying Akira ransomware.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 2 of 3Research by The DFIR Report
Bumblebee Reconnaissance and Privileged Persistence
An intruder is performing domain discovery and establishing privileged persistence by creating rogue administrator accounts and external SSH tunnels from compromised systems.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 1 of 3Research by The DFIR Report
Bumblebee SEO Poisoning and DLL Sideloading
An intruder compromises privileged workstations by poisoning search results for IT tools, tricking users into running a trojanized MSI that side-loads Bumblebee malware via consent.exe.
4 query2 analytic2 checkpoint1 action2 taskcommand and control · credential access · discovery -
mediumResearch by Huntress
VSS Manipulation and Lateral Movement Correlation
An attacker has moved laterally into the environment and is abusing Volume Shadow Copy Service utilities to either steal the Active Directory database or inhibit system recovery before a ransomware event.
4 query2 analytic1 checkpoint1 action2 taskcredential access · discovery · impact -
high Part 1 of 2Research by Wiz
TeamPCP Credential Validation and Discovery
An adversary validates stolen cloud credentials and enumerates cloud infrastructure using offensive tools like TruffleHog or specialized Boto3 scripts following a supply chain compromise.
4 query1 analytic1 checkpoint1 action2 taskdiscovery · execution · exfiltration -
high Part 2 of 2Research by Rapid7
wp2shell: Endpoint RCE and Lateral Movement
An intruder has exploited the WordPress wp2shell vulnerability to gain shell access and is now attempting to move laterally within the network via RDP or SSH using credentials compromised from the web server.
3 query1 analytic1 checkpoint2 taskCVE-2026-60137 · CVE-2026-63030 -
high Part 1 of 2Research by Rapid7
WordPress Core REST API RCE (wp2shell)
An unauthenticated attacker executes code on an internet-facing WordPress server by exploiting a logic flaw in the REST API batch endpoint to perform SQL injection and upload a malicious plugin.
3 query1 analytic1 checkpoint2 taskCVE-2026-60137 · CVE-2026-63030 -
highResearch by Proofpoint
TA488 OWA XSS Exploitation and OWAReaper Network Operations
An intruder has exploited CVE-2026-42897 in Outlook Web Access to deploy the OWAReaper implant, evidenced by anomalous sign-ins, OWA session data access, and covert exfiltration via image CDNs and GitHub.
5 query2 analytic1 checkpoint1 action3 taskCVE-2026-42897 -
high Part 2 of 2Research by Sekoia
iClickFix: NetSupport RAT Execution and Persistence
An intruder has used a ClickFix social engineering lure to execute a PowerShell downloader that installs NetSupport RAT and establishes persistent communication with a multi-hop proxy C2 infrastructure.
3 query2 analytic2 checkpoint1 action2 taskcollection · command and control · execution -
high Part 1 of 2Research by Sekoia
iClickFix Web Redirection and Delivery
An adversary is using compromised WordPress sites to redirect visitors through a YOURLS-based Traffic Distribution System to fetch ClickFix-style malicious scripts.
3 query1 analytic1 checkpoint1 action2 taskcollection · command and control · execution -
high Part 2 of 3Research by Cisco Talos
UAT-10147: Host Elevation and Evasion
An adversary is executing automated staging scripts to deploy privilege escalation tools and blind security software on compromised web servers.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · discovery -
high Part 1 of 3Research by Cisco Talos
Web Exploit and Telemetry Theft (UAT-10147)
The adversary exploits known web vulnerabilities in Zimbra, Telerik, or AjaxPro to achieve initial access and exfiltrates system identifiers to a Nacos configuration server via HTTP POST requests.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · discovery -
high Part 2 of 2Research by Huntress
RMM Command and Control and Redundancy
An attacker is using rogue ScreenConnect instances and secondary RMM tools to maintain persistence, identified by non-standard port connections and rare binaries running from user-writable directories.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · discovery · execution -
high Part 1 of 2Research by Huntress
Rogue ScreenConnect Host Execution and Persistence
An adversary is using social engineering to deploy rogue ScreenConnect clients that execute a multi-stage VBScript chain for host profiling and persistent access via registry run keys.
6 query2 analytic1 checkpoint1 action2 taskcommand and control · discovery · execution -
high Part 2 of 2Research by Elastic Security Labs
Web Server Shell Execution and wp2shell Post-Exploitation
An attacker has exploited a WordPress vulnerability to spawn a shell from a web server process and is currently performing system discovery or cleaning up traces of the wp2shell plugin.
3 query2 analytic2 checkpoint1 action2 taskCVE-2026-60137 · CVE-2026-63030 -
high Part 1 of 2Research by Elastic Security Labs
WordPress REST API Exploitation and Plugin Staging
An attacker is exploiting the wp2shell WordPress Core RCE chain to upload and stage a malicious plugin by abusing the unauthenticated REST batch API.
3 query1 analytic1 checkpoint1 action2 taskCVE-2026-60137 · CVE-2026-63030