Forum Discussion
blurn
Apr 18, 2019Copper Contributor
Account enumeration reconnaissance from an unresolved computer.
Hi, we are getting an alert about account enumeration reconnaissance on our network. It says "an actor on MSTSC performed suspicious account enumeration exposing 2 existing account names." This enume...
- Apr 18, 2019
It happens if the connection was attempted via RDP.
It's a protocol limitation, in the NTLM event, this is what the protocol is putting in the machine name field, and there is no IP address in this event.
I think this post can give hints on it:
Sundarsoma
Mar 23, 2021Copper Contributor
Hi blurn I'm facing similar issues.
How to find unresolved computer ip address / rdp session originating from?
How to find unresolved computer ip address / rdp session originating from?