Home / Blog / RDP Brute Force
Guide

RDP Brute Force Detection: Port 3389 and Correlation

Internet-facing RDP is one of the most common entry vectors. firewall + Windows log correlation.

K
Kerem M.

If RDP (3389) is open to the internet, bots will scan it in minutes. One type of defense is not enough — firewall and identity logs must be monitored together.

signals

Rule proposal

First block it on the firewall; incident escalation if there is successful RDP inside. OxiSec rdp_chain pattern combines this flow.

Analyze your logs with OxiSec

Installation in 15 minutes · community plan is free

Start Free →