Detecting and Blocking RDP Attack With Wazuh
Detecting and Blocking RDP Attack With Wazuh
Rule:
<group name=”rdp”>
<rule id=”100100” level=”10” frequency=”3” timeframe=”120”>
<if_mached_sid>60122</if_mached_sid>
<description> Possible RDP Attack “You can write your own msg” </description>
</rule>
</group>
Brute-forcing on Windows7
Go to Security Evens of Windows7 agent here is detecting and blocking brute-
force attack.
-------------------THE END-------------------→
Follow Me: www.linkedin.com/in/moizuddinrafay