Back to category

Week 1

Investigate Exposed RDP Compromise

Intermediate
SOC Analyst
Cybersecurity Analyst
MITRE ATT&CK
NIST CSF
Windows Event Log Analysis
RDP/Remote Access Security
Incident Timeline Reconstruction

Client Background

A mid-size healthcare provider reports suspicious login activity on an internet-facing server.

Business Environment

The client operates a hybrid IT environment supporting roughly 200 staff across two clinics, including a legacy Windows Server 2016 host that a third-party vendor accesses remotely for administrative support.

Security Incident

The client's IT team noticed a spike of failed and successful login attempts against an internet-facing RDP service (port 3389) from unfamiliar international IP addresses, followed by unusual account activity on the affected host.

Scope

This engagement covers only the single internet-facing Windows Server and its authentication/process logs. Internal network segmentation, other endpoints, and the client's EHR application are out of scope.

Objectives

  • Identify the exposed service
  • Trace attacker login attempts
  • Recommend remediation

Required Deliverables

Executive Summary
Incident Timeline
Remediation Recommendations
3 hrs estimated