RDP Access Followed by Ransomware Execution
This rule detects a sequence of events indicative of ransomware deployment following a successful Remote Desktop Protocol (RDP) connection. Specifically, it looks for an inbound RDP connection (RemotePort 3389) to a device, followed within 60 minutes by the execution of known ransomware executables ('servertool.exe', 'encrypt.exe') on the same device. This pattern suggests an attacker gaining initial access or moving laterally via RDP and then deploying ransomware.
Microsoft Sentinel (KQL)

