RDP Brute-Force Password Spraying via Repeated TCP Connections to 3389

Detects repeated inbound TCP connection attempts to port 3389 (RDP) from a single source address within a short timeframe. This behavior is indicative of an RDP brute-force or password spraying attack targeting remote desktop services.