RDP Lateral Movement via mstsc.exe Remote Host Args or Unusual Child Processes
This rule detects potentially unauthorized or suspicious Remote Desktop Protocol (RDP) activity by monitoring for instances of 'mstsc.exe' initiated with specific command-line arguments, or identifying child processes spawned by RDP-related binaries ('mstsc.exe', 'rdpclip.exe') that are not typically associated with standard RDP functionality.
SentinelOne

