T1021.001Remote Desktop Protocol
T1021.001 — Remote Desktop Protocol is a MITRE ATT&CK technique in the Lateral Movement tactic. Clankerusecase tracks 20 detection use cases covering it and 14 threat-intel articles citing it.
Lateral Movement
20Use cases
14Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1021 · Remote Services
Use cases covering this technique (20)
Allow Inbound Traffic By Firewall Rule Registry Allow Inbound Traffic In Firewall Rule Remote Desktop Process Running On System Windows Default RDP File Creation By Non MSTSC Process Windows Default Rdp File Unhidden Windows MSTSC RDP Commandline Windows Process Execution From RDP Share Windows RDP Bitmap Cache File Creation Windows RDP Client Launched with Admin Session Windows RDP File Execution Windows RDP Login Session Was Established Windows RDP Server Registry Entry Created Windows Remote Service Rdpwinst Tool Execution Windows Remote Services Allow Rdp In Firewall Windows Remote Services Allow Remote Assistance Windows Remote Services Rdp Enable Remote Desktop Network Traffic Windows Default RDP File Creation [LLM] mstsc.exe child process after outbound RDP to external server (RDC heap overflow) [LLM] termsrv.dll patched (multi-RDP enabling) - takeown + binary write + TermService restartArticles citing this technique (14)
crit Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload art-219
crit CISA KEV: CVE-2025-5777 — Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability art-848