RDP Brute Force - Repeated TLS ClientHello to Port 3389
Detects repeated RDP connection attempts to port 3389 from a single source within a short timeframe, characteristic of brute force or password spraying activity. The rule monitors for consecutive TLS ClientHello or MCS Connect-Initial packets.
Suricata

