RDP security guide

Recognize the patterns
behind RDP attacks.

A burst of failed logins, many short connections and a slow campaign across user accounts leave different signals. Understanding those differences helps you choose useful defenses.

RDP Brute-Force Attacks: many guesses against an account

An attacker repeatedly tries credentials to obtain a valid Remote Desktop sign-in. In your logs, look for a concentration of failed authentication attempts over a short period, often against common account names.

Repeated failures from one source are a useful blocking signal, but a single failure can also be a legitimate typing error. Thresholds should reflect normal usage. Strong unique passwords and appropriate authentication controls reduce the chance that a guess succeeds.

Relevant VARQOO feature: authentication thresholds and automatic IP blocking.

Pre-Authentication Attacks: activity before a valid login

Pre-authentication is a stage of a connection, not one specific attack. Scanners and abusive clients may interact with an exposed RDP service without completing a valid login. A failed-login counter alone cannot describe all of that activity.

Look at connection activity as well as authentication events. Repeated connections without corresponding login events are a signal to investigate, not proof of an exploit. Keep Windows patched and review how the RDP service is exposed.

Relevant VARQOO feature: monitoring observed TCP connections before sign-in. Connection thresholds do not inspect or patch every RDP vulnerability.

RDP Connection Flooding: pressure on the service

A connection flood creates many connections or attempts with the aim of consuming service resources. Indicators can include unusually high connection activity alongside degraded responsiveness. Legitimate monitoring or reconnecting clients can also produce bursts, so compare activity with your normal baseline.

Blocking detected sources can reduce their subsequent traffic. If an attack saturates the internet link itself, filtering on the server cannot restore the bandwidth: upstream controls are needed.

Relevant VARQOO feature: connection thresholds and temporary source bans.

Distributed RDP Scanning & Attacks: many sources

Scanning looks for reachable services; an authentication attack tries to obtain access. Both may be distributed across many IP addresses. Each source can remain below a simple per-IP threshold even when the combined activity is significant.

For authentication attempts, compare the accounts being targeted and the number of distinct sources in a shared time window. A group of addresses repeatedly targeting the same account is a different pattern from unauthenticated scanning or password spraying across many accounts.

Relevant VARQOO feature: same-account correlation across multiple public source IPs. Scanning without authentication signals is not automatically covered by that detector.

Password Spray / Password Spraying against RDP

Password spraying tries one or a few common passwords across many accounts. Brute force typically tries many guesses against one account. A spray can progress slowly to avoid per-account lockouts, and it can originate from one source or many.

Look for failures spread across multiple accounts, recurring sources and unusual authentication patterns over longer windows. Standard failed-login logs do not reveal the attempted password, so account and source patterns alone do not prove the same password was used. MITRE ATT&CK classifies the technique as Password Spraying (T1110.003).

VARQOO source thresholds and geographic restrictions can reduce activity when it creates detectable signals. Its current distributed detector correlates attempts against the same account; it is not a dedicated classifier for cross-account password-spray campaigns. Review the authentication features and use identity controls alongside network blocking.

Geographic access: reduce exposure to unwanted sources

If your legitimate users connect from a limited set of countries, geographic restrictions can reduce unwanted traffic. Location is an access-policy signal rather than proof that a source is malicious. Allowed locations can still contain attackers, and VPNs or mobile users can change apparent location.

Relevant VARQOO features: country policies and trusted IP exceptions.

A practical RDP defense checklist

  • Reduce direct public exposure where possible, using an appropriate gateway or VPN.
  • Keep Windows updated and enable Network Level Authentication where supported.
  • Use strong unique passwords and multi-factor authentication in your access architecture.
  • Review successful and failed sign-ins, connection activity and changes from your normal baseline.
  • Use source blocking and geographic policies as additional layers, with tested trusted-access exceptions.

See how these signals map to VARQOO product features, or evaluate the configuration in your environment with the 15-day free trial.