RDP Tunneling via plink.exe, netsh portproxy, or SSH over Non-Standard Ports
Detects the use of living-off-the-land tools like plink.exe, netsh.exe, and ssh.exe to create tunnels that forward RDP traffic (port 3389). This behavior is often indicative of an adversary attempting to bypass network controls or hide RDP sessions by tunneling them through other protocols or non-standard port configurations.
SentinelOne

