RDP Hopping: User Authenticating to Multiple Hosts Rapidly
This rule detects potential lateral movement via Remote Desktop Protocol (RDP) by identifying a single user account establishing RemoteInteractive (logon type 10) sessions to three or more distinct destination hosts within a 15-minute timeframe. This pattern is indicative of an attacker attempting to traverse a network from a compromised host.
YARA-L

