AzureDetection & ResponseRetrospectives

Detecting Exposed RDP Exploitation: Defender for Cloud and Sentinel KQL

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from May 2019, written in 2026 with the benefit of hindsight.

Even with patches, exposed RDP invites brute force, credential stuffing and exploitation. Detecting both the exposure and attacks against it is essential for cloud VMs.

Detect the exposure

  • Defender for Cloud recommendations for open management ports and for VMs with public IPs.
  • Azure Resource Graph or NSG flow log analysis for inbound traffic on TCP 3389 from the internet.
  • Attack path analysis in Defender CSPM showing internet-exposed VMs with vulnerabilities.

Detect attacks against it

  • Large numbers of failed Windows logons (event ID 4625) with logon type 10 (RemoteInteractive) or network-level failures.
  • Successful RDP logons from unfamiliar public IPs.
  • New local administrator accounts created after an RDP logon.
  • Defender for Servers alerts for brute force and suspicious RDP activity.

A starting query

With Defender for Endpoint data:

DeviceLogonEvents
| where LogonType == "RemoteInteractive"
| where RemoteIPType == "Public"
| summarize Failed = countif(ActionType == "LogonFailed"),
    Succeeded = countif(ActionType == "LogonSuccess") by DeviceName, RemoteIP, bin(Timestamp, 1h)
| where Failed > 20 or Succeeded > 0

Any successful RDP logon from a public IP to a server that shouldn't be exposed deserves investigation.

Response

  1. Close the port immediately (NSG rule or move behind Bastion).
  2. Investigate successful logons: what was done, which accounts, any new users or tools installed.
  3. Reset credentials used on the machine.
  4. Check other VMs created from the same image or template.
detect exposed rdp exploitationBlueKeep2019

More on this story