First-Seen External RDP Logon

Detects the first-seen external Remote Desktop Protocol (RDP) logon event for a specific user and network provider (ASN) within the last 24 hours, compared against a 14-day historical baseline. This can indicate initial access via compromised credentials or RDP exploitation.