Contact
Glass office building representing enterprise IT access

Library

RDP from an attacker's perspective

Share via

Remote Desktop Protocol is widely used for administration and remote work, but it is also a common attack vector. Misconfiguration, weak authentication, unpatched vulnerabilities and public exposure make RDP one of the first services attackers investigate.

Explanation

Remote Desktop Protocol provides interactive administrative and user sessions on Windows systems. It is functional and widely supported, but creates a valuable access path when exposed directly to the internet or broadly permitted internally. Attackers use RDP both for initial access with valid credentials and for lateral movement after an earlier compromise. Security depends on exposure, Network Level Authentication, MFA, gateway configuration, account privileges, patch level and logging. Checking only whether TCP port 3389 is closed is therefore insufficient; RDP may remain available through gateways, alternative ports or internal routes.

Risk

A valid account can provide an attacker with a complete graphical session containing normal administrative functions, files and network connections. Weak passwords, missing lockout, shared administrator accounts and limited segmentation increase the likelihood of abuse. Clipboard, drive and printer redirection can support data transfer after access. RDP traffic also resembles legitimate administration, making unusual time, source host, session duration and privilege use more relevant than the protocol alone. Incomplete logging or central correlation can leave lateral movement and persistent access unnoticed.

Points to check

  • Publicly exposed RDP without firewall restrictions.
  • Weak or reused credentials without MFA.
  • Missing patches for known RDP vulnerabilities.
  • No monitoring of unusual times and source locations.
  • Limited visibility into sessions and lateral movement.

Approach

DeepBlue inventories where RDP is required and through which paths it is reachable. External exposure is removed or placed behind a secured gateway using phishing-resistant MFA. Access is restricted to named roles, management networks and managed devices; local administrator rights, redirection features and session policy are assessed separately. Controlled testing validates password and lockout policy, segmentation, gateway controls and detection of anomalous sessions. Endpoint, gateway and identity logs are correlated. Where RDP is unnecessary it is disabled; where it is operationally critical, compensating controls are demonstrably tested.

Conclusion

RDP is powerful but high risk when poorly controlled. Layered protection and deliberate testing turn it from an exposed entry point into controlled administrative access.

Contact

Want to understand the impact in your own environment? Contact DeepBlue Security & Intelligence at info@deepbluesecurity.nl or +31 (0) 70 290 6 290.

← Back to library

Direct access to senior cybersecurity expertise

Discuss a security requirement, active risk or complex IT or OT environment with one of our senior specialists. The initial conversation focuses on the technical context, operational constraints and the most appropriate course of action.

  • No mailing lists or automated sales follow-up
  • Information is handled confidentially

Urgent assistance required?

Call +31 (0) 70 290 6 290
or email  info@deepbluesecurity.nl

Thank you. The message has been received and will be reviewed by one of our specialists.
The form could not be submitted. Please try again or contact info@deepbluesecurity.nl.