Remote Desktop Connection Initiated by Scripting Engines

This rule detects inbound Remote Desktop Protocol (RDP) connections (ports 3389, 3390, 3391) that are initiated by common scripting engines such as wscript.exe, cscript.exe, or powershell.exe. This behavior can be indicative of post-exploitation activity where an attacker uses scripts to establish remote access.