mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
19 lines
899 B
YAML
19 lines
899 B
YAML
name: Identify Systems Using Remote Desktop
|
|
id: 063dfe9f-b1d7-4254-a16d-1e2e7eadd6a8
|
|
version: 3
|
|
creation_date: '2019-10-16'
|
|
modification_date: '2026-05-13'
|
|
author: David Dorsey, Splunk
|
|
status: production
|
|
description: This search counts the numbers of times the remote desktop process, mstsc.exe, has run on each system.
|
|
search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Processes where Processes.process_name="*mstsc.exe*" by Processes.dest Processes.process_name | `drop_dm_object_name(Processes)` | sort - count'
|
|
how_to_implement: To successfully implement this search you must be ingesting endpoint data that records process activity.
|
|
known_false_positives: No false positives have been identified at this time.
|
|
references: []
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
security_domain: endpoint
|
|
schedule: Default Baseline
|