Files
splunk-security_content/baselines/identify_systems_using_remote_desktop.yml

19 lines
899 B
YAML

name: Identify Systems Using Remote Desktop
id: 063dfe9f-b1d7-4254-a16d-1e2e7eadd6a8
version: 3
creation_date: '2019-10-16'
modification_date: '2026-05-13'
author: David Dorsey, Splunk
status: production
description: This search counts the numbers of times the remote desktop process, mstsc.exe, has run on each system.
search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Processes where Processes.process_name="*mstsc.exe*" by Processes.dest Processes.process_name | `drop_dm_object_name(Processes)` | sort - count'
how_to_implement: To successfully implement this search you must be ingesting endpoint data that records process activity.
known_false_positives: No false positives have been identified at this time.
references: []
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
security_domain: endpoint
schedule: Default Baseline