Files
splunk-security_content/baselines/identify_systems_using_remote_desktop.yml
2021-02-11 11:25:21 -05:00

22 lines
753 B
YAML

name: Identify Systems Using Remote Desktop
id: 063dfe9f-b1d7-4254-a16d-1e2e7eadd6a8
version: 1
date: '2019-04-01'
author: David Dorsey, Splunk
type: batch
datamodel:
- Endpoint
description: This search counts the numbers of times the remote desktop process, mstsc.exe,
has run on each system.
search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Processes
where Processes.process_name="*mstsc.exe*" by Processes.dest Processes.process_name
| `drop_dm_object_name(Processes)` | sort - count'
how_to_implement: To successfully implement this search you must be ingesting endpoint
data that records process activity.
references: []
tags:
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud