T1021.001 - Remote Services: RDP - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
January 8, 2026
Last Seen
January 8, 2026

MITRE ATT&CK T1021.001 Remote Services: RDP refers to adversaries leveraging Remote Desktop Protocol to access and control a remote Windows host, enabling initial access, lateral movement, and potential persistence.

Overview

MITRE ATT&CK T1021.001 Remote Services: RDP refers to adversaries leveraging Remote Desktop Protocol to access and control a remote Windows host, enabling initial access, lateral movement, and potential persistence. It remains a high-risk vector due to widespread RDP exposure, misconfigurations, and weak credentials, making robust authentication, network segmentation, and monitoring critical for defense.

Related Threat Clusters

Recent Intelligence Reports

  • VMware ESXi zero — Bleepingcomputer · January 8, 2026

CVSS v3.1 Breakdown