Forum Discussion

Mtee-'s avatar
Mtee-
Copper Contributor
Sep 10, 2019

Azure ATP read-only user hammering RDP and TCP35 ports

Hi!

Our Security scans showed that the user account used in Azure ATP as read-only account (Only domain user) is used to try RDP and TCP35 ports from domain controllers a lot.

As the source is domain controllers, it is probably nothing because sensors are on DC:s but did not find any information about RDP and TCP 35 ports related to Azure ATP so could you specify what that port hammering could be?

2 Replies