CVE-2019-0708 BlueKeep RDP MCS Connect Initial Exploitation Attempt

Detection rules identifying malformed RDP MCS Connect Initial PDUs and unusual service crashes following RDP connection attempts, both indicative of exploitation attempts against the CVE-2019-0708 (BlueKeep) vulnerability.