RDP Brute Force - Rapid TCP Connection Attempts to Port 3389
This rule detects rapid, successive TCP connection attempts directed to port 3389 (RDP) from a single external source IP within a short timeframe. This behavior is indicative of a brute force attack or automated credential guessing activity targeting remote desktop services.
Suricata

