RDP Brute-Force High-Frequency Inbound Connection Attempts Port 3389
This rule detects a high frequency of incoming TCP synchronization (SYN) packets on port 3389 (RDP) from a single external source within a short timeframe. This behavior is indicative of a brute-force or credential-stuffing attack against Remote Desktop services.
Suricata

