Week 1
Investigate Exposed RDP Compromise
Client Background
A mid-size healthcare provider reports suspicious login activity on an internet-facing server.
Business Environment
The client operates a hybrid IT environment supporting roughly 200 staff across two clinics, including a legacy Windows Server 2016 host that a third-party vendor accesses remotely for administrative support.
Security Incident
The client's IT team noticed a spike of failed and successful login attempts against an internet-facing RDP service (port 3389) from unfamiliar international IP addresses, followed by unusual account activity on the affected host.
Scope
This engagement covers only the single internet-facing Windows Server and its authentication/process logs. Internal network segmentation, other endpoints, and the client's EHR application are out of scope.
Objectives
- Identify the exposed service
- Trace attacker login attempts
- Recommend remediation
Required Deliverables