FortiGate Allowed RDP Connection

Detects network traffic identified by FortiGate as Remote Desktop Protocol (RDP) that has been explicitly permitted (Accept action) by the firewall policy. This rule monitors for successful packet flow through the firewall, providing visibility into potential lateral movement paths via RDP.