kevmap

TechniquesT1133 › AN1004

AN1004 Analytic 1004

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Unusual or unauthorized external remote access attempts (e.g., RDP, VPN, Citrix) → repeated failed logins followed by a successful session from uncommon geolocations or outside business hours → subsequent internal lateral movement or data exfiltration activities.</p>
Detects
T1133 External Remote Services
Part of
DET0354 Behavior-chain detection for T1133 External Remote Services across Windows, Linux, macOS, Containers

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SecurityEventCode=4776, 4625DC0002 User Account Authentication
WinEventLog:ApplicationVPN, Citrix, or remote access gateway logs showing external IP addressesDC0038 Application Log Content
WinEventLog:SysmonEventCode=3, 22DC0082 Network Connection Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
BusinessHoursNormal business hours for logon activity.
KnownRemoteIPsList of approved external IPs or VPN endpoints.
FailedLogonThresholdNumber of failed logons before raising suspicion (e.g., >5).
GeoIPWhitelistGeographic regions allowed for remote access.
TimeWindowTime window to correlate failed attempts and success (e.g., 15m).

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2014-6271GNU Bourne-Again Shell (Bash)Mapped
CVE-2014-7169GNU Bourne-Again Shell (Bash)Mapped
CVE-2018-4939Adobe ColdFusionMapped
CVE-2019-0708Microsoft Remote Desktop ServicesMapped
CVE-2019-11510Ivanti Pulse Connect SecureMapped
CVE-2019-19781Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP ApplianceMapped
CVE-2019-3396Atlassian Confluence Server and Data ServerMapped
CVE-2019-5591Fortinet FortiOSMapped
CVE-2020-1472Microsoft NetlogonMapped
CVE-2020-25506D-Link DNS-320 DeviceMapped
CVE-2020-5902F5 BIG-IPStale
CVE-2020-8515DrayTek Multiple Vigor RoutersMapped
CVE-2021-1497Cisco HyperFlex HXMapped
CVE-2021-1498Cisco HyperFlex HXMapped
CVE-2021-22986F5 BIG-IP and BIG-IQ Centralized ManagementMapped
CVE-2021-26855Microsoft Exchange ServerMapped
CVE-2021-26857Microsoft Exchange ServerMapped
CVE-2022-20699Cisco Small Business RV160, RV260, RV340, and RV345 Series RoutersMapped
CVE-2023-20269Cisco Adaptive Security Appliance and Firepower Threat DefenseMapped
CVE-2023-27532Veeam Backup & ReplicationMapped
CVE-2023-39780ASUS RT-AX55 RoutersMapped
CVE-2023-48365Qlik SenseMapped
CVE-2024-11120GeoVision Multiple DevicesMapped
CVE-2024-45195Apache OFBizMapped
CVE-2025-32756Fortinet Multiple ProductsMapped