{"id":4454,"date":"2023-08-09T09:00:15","date_gmt":"2023-08-09T16:00:15","guid":{"rendered":"https:\/\/www.gosecure.net\/?p=4454"},"modified":"2025-05-20T12:59:42","modified_gmt":"2025-05-20T19:59:42","slug":"how-unparalleled-rdp-monitoring-reveal-attackers-tradecraft","status":"publish","type":"post","link":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2023\/08\/09\/how-unparalleled-rdp-monitoring-reveal-attackers-tradecraft\/","title":{"rendered":"How Unparalleled RDP Monitoring Reveal Attackers\u2019 Tradecraft"},"content":{"rendered":"<p><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}\"><span data-contrast=\"none\"><img class=\"wp-image-4504 size-medium alignright\" src=\"https:\/\/www.legacy.gosecure.ai\/wp-content\/uploads\/DnD-All-1-300x169.jpeg\" alt=\"\" width=\"300\" height=\"169\" \/>Authors: Andr\u00e9anne Bergeron and Olivier Bilodeau<\/span><\/span><\/p>\n<p><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}\"><span data-contrast=\"none\">With <\/span><a href=\"https:\/\/github.com\/gosecure\/pyrdp\"><span data-contrast=\"none\">our RDP interception tool<\/span><\/a><span data-contrast=\"none\">, we managed to collect a great de<\/span><\/span><span data-contrast=\"none\">al of information\u00a0(screen, keyboard, mouse, metadata) about opportunistic attackers, and have it on video. <\/span><span data-contrast=\"auto\">An engineer and a crime data scientist partner to deliver an epic story, presented <\/span><a href=\"https:\/\/www.blackhat.com\/us-23\/briefings\/schedule\/index.html#i-watched-you-roll-the-die-unparalleled-rdp-monitoring-reveal-attackers-tradecraft-33110\"><span data-contrast=\"none\">at BlackHat USA<\/span><\/a><span data-contrast=\"auto\"> titled \u201cI Watched You Roll the Die: Unparalleled RDP Monitoring Reveal Attackers\u2019 Tradecraft\u201d for the first time, which includes luring, <\/span><span data-contrast=\"none\">understanding and characterizing attackers, allowing to collectively focus our attention on more sophisticated threats.\u202f<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span data-contrast=\"auto\">The Remote Desktop Protocol (RDP) is a critical attack vector used by evil threat actors including ransomware groups. To study RDP attacks, we created PyRDP, an open-source RDP interception tool with unmatched screen, keyboard, mouse, clipboard and file collection capabilities. You can learn more about our tool in our <\/span><a href=\"https:\/\/www.legacy.gosecure.ai\/blog\/2020\/10\/20\/announcing-pyrdp-1-0\/\"><span data-contrast=\"none\">previous blogs<\/span><\/a><span data-contrast=\"auto\">. We then built a honeynet that is composed of several RDP Windows servers exposed on the cloud. We ran them<\/span><span data-contrast=\"auto\"> for three years and accumulated over 190 million events, including 100 hours of video footage, 470 files collected from threat actors, and more than 20,000 RDP captures.\u202f<\/span><\/p>\n<p><span data-contrast=\"auto\">The data collected allowed the study of attackers\u2019 behavior, which was used to classify attackers into different groups. The groups are presented below.<\/span><\/p>\n<p><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><i><span data-contrast=\"auto\"><img class=\"alignleft wp-image-4469\" src=\"https:\/\/www.legacy.gosecure.ai\/wp-content\/uploads\/DnDgoSec-01-Ranger-solo-264x300.png\" alt=\"Digital fantasy art showcasing a DnD Ranger\" width=\"155\" height=\"176\" \/><\/span><\/i><i><span data-contrast=\"auto\">Rangers <\/span><\/i><span data-contrast=\"auto\">explore all the folders of the computer, check the network and host performance characteristics, run reconnaissance by\u00a0<\/span><span data-contrast=\"auto\">clicking or by using programs\/scripts. No other meaningful actions are undertaken. Our hypothesis is that they are evaluating the system they compromised so that another profile of attacker can come back later. To see a ranger in action, <\/span><a href=\"https:\/\/youtu.be\/l6FV__uq_dQ\"><span data-contrast=\"none\">view a recorded session on YouTube<\/span><\/a><span data-contrast=\"auto\">. <\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><i><span data-contrast=\"auto\"><img class=\" wp-image-4470 alignright\" src=\"https:\/\/www.legacy.gosecure.ai\/wp-content\/uploads\/DnDgoSec-01-Rogue-solo-e1691526841708-241x300.png\" alt=\"Digital fantasy art showcasing a DnD Thief\" width=\"129\" height=\"161\" \/>Thieves <\/span><\/i><span data-contrast=\"auto\">try to monetize the RDP access. After taking control of the computer by changing the credentials to access it, they perform different activities that aim to take advantage of this access. They use tools like traffmonetizer (proxyware), monetized browsers (participating in <\/span><a href=\"https:\/\/en.wikipedia.org\/wiki\/Pay_to_surf\"><span data-contrast=\"none\">pay to surf<\/span><\/a><span data-contrast=\"auto\"> schemes), they install and use cryptominers, download Android emulators (mobile fraud), etc.<\/span><span data-contrast=\"auto\">\u202f<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><i><span data-contrast=\"auto\"><img class=\"wp-image-4467 alignleft\" src=\"https:\/\/www.legacy.gosecure.ai\/wp-content\/uploads\/DnDgoSec-01-Barbar-solo-259x300.png\" alt=\"Digital fantasy art showcasing a DnD Barbarian\" width=\"142\" height=\"165\" \/>Barbarians <\/span><\/i><span data-contrast=\"auto\">use a large array of tools to brute-force their way into more computers. They leverage the compromised system to attempt compromising other systems by working with lists of IP addresses, usernames and passwords.<\/span><span data-contrast=\"auto\">\u202fHere <\/span><a href=\"https:\/\/youtu.be\/ZZAJz9OeTeQ\"><span data-contrast=\"none\">we can see a barbarian using Masscan<\/span><\/a><span data-contrast=\"auto\">, a brute-forcing tool. <\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><i><span data-contrast=\"auto\">\u00a0<\/span><\/i><\/p>\n<p><i><span data-contrast=\"auto\"><img class=\"wp-image-4471 alignright\" src=\"https:\/\/www.legacy.gosecure.ai\/wp-content\/uploads\/DnDgoSec-01-Wizard-solo-216x300.png\" alt=\"Digital fantasy art showcasing a DnD Wizard\" width=\"148\" height=\"206\" \/>Wizards <\/span><\/i><span data-contrast=\"auto\">use the RDP access as a portal to connect to another computer that was compromised in a similar fashion. This strategy is good operational security: they hide their identity via jumps over compromised hosts. To do so, they demonstrate a high level of skill by carefully <\/span><a href=\"https:\/\/www.youtube.com\/watch?v=j-r6UonEkUw\"><span data-contrast=\"none\">living off the land<\/span><\/a><span data-contrast=\"auto\">. Being able to monitor and see the actions of these attackers is of utmost importance for threat intelligence gathering, enabling defenders and researchers to reach deeper into compromised infrastructure.<\/span><span data-contrast=\"auto\">\u202fYou can see <\/span><a href=\"https:\/\/youtu.be\/STP5MuzyJ1k\"><span data-contrast=\"none\">a wizard in action by following this YouTube link<\/span><\/a><span data-contrast=\"auto\">. <\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><i><span data-contrast=\"auto\"><img class=\"wp-image-4468 alignleft\" src=\"https:\/\/www.legacy.gosecure.ai\/wp-content\/uploads\/DnDgoSec-01-Barde-solo-217x300.png\" alt=\"Digital fantasy art showcasing a DnD Bard\" width=\"136\" height=\"188\" \/>Bards <\/span><\/i><span data-contrast=\"auto\">are individuals with no apparent hacking skills. They access the system to accomplish basic tasks like looking for viruses through a simple Google search or to watch pornography. The evidence shows that they might have bought RDP access from someone who has compromised the system for them, aka Initial Access Brokers (IABs).<\/span><span data-contrast=\"auto\">\u202f<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">Understanding and characterizing attackers allows us to<\/span><span data-contrast=\"auto\"> collectively focus our attention on the most popular <\/span><i><span data-contrast=\"auto\">modus operandi<\/span><\/i><span data-contrast=\"auto\"> and on the more sophisticated threats. In the next couple of months, we will detail the tools used by the different threat actors in our attackers\u2019 weaponry blog post series. Stay tuned to learn more.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p>&nbsp;<\/p>\n<h3 aria-level=\"2\"><b><span data-contrast=\"none\">Conclusion<\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:200,&quot;335559739&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">This presentation demonstrates the tremendous capability in RDP, not only for research benefits, but also for law enforcement and blue teams. Law enforcement could <\/span><span data-contrast=\"auto\">lawfully intercept the RDP environments used by ransomware groups and collect intelligence in recorded sessions for use in investigations. Blue teams for their part can consume the IOCs and roll out their own traps in order to further protect their organization, as this will give them <\/span><span data-contrast=\"auto\">extensive documentation of opportunistic attackers\u2019 tradecraft. Plus, <\/span><span data-contrast=\"none\">if attackers are scared enough, they will have to change their strategies, and this will influence their attacks\u2019 cost-benefit, leading to a slow down which will ultimately benefit everyone.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}\"><span data-contrast=\"none\"><img class=\"wp-image-4504 size-medium alignright\" src=\"https:\/\/www.legacy.gosecure.ai\/wp-content\/uploads\/DnD-All-1-300x169.jpeg\" alt=\"\" width=\"300\" height=\"169\" \/>With <\/span><a href=\"https:\/\/github.com\/gosecure\/pyrdp\"><span data-contrast=\"none\">our RDP interception tool<\/span><\/a><span data-contrast=\"none\">, we managed to collect a great de<\/span><\/span><span data-contrast=\"none\">al of information\u00a0(screen, keyboard, mouse, metadata) about opportunistic attackers, and have it on video. <\/span><span data-contrast=\"auto\">An engineer and a crime data scientist partner to deliver an epic story, presented <\/span><a href=\"https:\/\/www.blackhat.com\/us-23\/briefings\/schedule\/index.html#i-watched-you-roll-the-die-unparalleled-rdp-monitoring-reveal-attackers-tradecraft-33110\"><span data-contrast=\"none\">at BlackHat USA<\/span><\/a><span data-contrast=\"auto\"> titled \u201cI Watched You Roll the Die: Unparalleled RDP Monitoring Reveal Attackers\u2019 Tradecraft\u201d for the first time, which includes luring, <\/span><span data-contrast=\"none\">understanding and characterizing attackers, allowing to collectively focus our attention on more sophisticated threats.\u202f<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n","protected":false},"author":3,"featured_media":4504,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[115,104,37],"tags":[363,170,371,161],"class_list":["post-4454","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-pyrdp","category-rdp","category-tool","tag-penetration-testing","tag-rdp","tag-red-team","tag-tool"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v23.0 (Yoast SEO v23.0) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>How Unparalleled RDP Monitoring Reveal Attackers\u2019 Tradecraft - GoSecure<\/title>\n<meta name=\"description\" content=\"Luring threat actors into RDP traps reveals attackers&#039; tactics. This blog summarizes an hour-long presentation about what can be found in those traps.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2023\/08\/09\/how-unparalleled-rdp-monitoring-reveal-attackers-tradecraft\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How Unparalleled RDP Monitoring Reveal Attackers\u2019 Tradecraft\" \/>\n<meta property=\"og:description\" content=\"Luring threat actors into RDP traps reveals attackers&#039; tactics. This blog summarizes an hour-long presentation about what can be found in those traps.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2023\/08\/09\/how-unparalleled-rdp-monitoring-reveal-attackers-tradecraft\/\" \/>\n<meta property=\"og:site_name\" content=\"GoSecure\" \/>\n<meta property=\"article:published_time\" content=\"2023-08-09T16:00:15+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-05-20T19:59:42+00:00\" \/>\n<meta name=\"author\" content=\"GoSecure\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@GoSecure_Inc\" \/>\n<meta name=\"twitter:site\" content=\"@GoSecure_Inc\" \/>\n<meta name=\"twitter:label1\" content=\"\u00c9crit par\" \/>\n\t<meta name=\"twitter:data1\" content=\"GoSecure\" \/>\n\t<meta name=\"twitter:label2\" content=\"Dur\u00e9e de lecture estim\u00e9e\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2023\/08\/09\/how-unparalleled-rdp-monitoring-reveal-attackers-tradecraft\/\",\"url\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2023\/08\/09\/how-unparalleled-rdp-monitoring-reveal-attackers-tradecraft\/\",\"name\":\"How Unparalleled RDP Monitoring Reveal Attackers\u2019 Tradecraft - GoSecure\",\"isPartOf\":{\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2023\/08\/09\/how-unparalleled-rdp-monitoring-reveal-attackers-tradecraft\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2023\/08\/09\/how-unparalleled-rdp-monitoring-reveal-attackers-tradecraft\/#primaryimage\"},\"thumbnailUrl\":\"\",\"datePublished\":\"2023-08-09T16:00:15+00:00\",\"dateModified\":\"2025-05-20T19:59:42+00:00\",\"author\":{\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/#\/schema\/person\/11f4bfed2ab7b748dfc255aa91baedca\"},\"description\":\"Luring threat actors into RDP traps reveals attackers' tactics. This blog summarizes an hour-long presentation about what can be found in those traps.\",\"breadcrumb\":{\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2023\/08\/09\/how-unparalleled-rdp-monitoring-reveal-attackers-tradecraft\/#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2023\/08\/09\/how-unparalleled-rdp-monitoring-reveal-attackers-tradecraft\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2023\/08\/09\/how-unparalleled-rdp-monitoring-reveal-attackers-tradecraft\/#primaryimage\",\"url\":\"\",\"contentUrl\":\"\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2023\/08\/09\/how-unparalleled-rdp-monitoring-reveal-attackers-tradecraft\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/legacy.gosecure.ai\/fr\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How Unparalleled RDP Monitoring Reveal Attackers\u2019 Tradecraft\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/#website\",\"url\":\"https:\/\/legacy.gosecure.ai\/fr\/\",\"name\":\"GoSecure\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/legacy.gosecure.ai\/fr\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/#\/schema\/person\/11f4bfed2ab7b748dfc255aa91baedca\",\"name\":\"GoSecure\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"How Unparalleled RDP Monitoring Reveal Attackers\u2019 Tradecraft - GoSecure","description":"Luring threat actors into RDP traps reveals attackers' tactics. This blog summarizes an hour-long presentation about what can be found in those traps.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2023\/08\/09\/how-unparalleled-rdp-monitoring-reveal-attackers-tradecraft\/","og_locale":"fr_FR","og_type":"article","og_title":"How Unparalleled RDP Monitoring Reveal Attackers\u2019 Tradecraft","og_description":"Luring threat actors into RDP traps reveals attackers' tactics. This blog summarizes an hour-long presentation about what can be found in those traps.","og_url":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2023\/08\/09\/how-unparalleled-rdp-monitoring-reveal-attackers-tradecraft\/","og_site_name":"GoSecure","article_published_time":"2023-08-09T16:00:15+00:00","article_modified_time":"2025-05-20T19:59:42+00:00","author":"GoSecure","twitter_card":"summary_large_image","twitter_creator":"@GoSecure_Inc","twitter_site":"@GoSecure_Inc","twitter_misc":{"\u00c9crit par":"GoSecure","Dur\u00e9e de lecture estim\u00e9e":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2023\/08\/09\/how-unparalleled-rdp-monitoring-reveal-attackers-tradecraft\/","url":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2023\/08\/09\/how-unparalleled-rdp-monitoring-reveal-attackers-tradecraft\/","name":"How Unparalleled RDP Monitoring Reveal Attackers\u2019 Tradecraft - GoSecure","isPartOf":{"@id":"https:\/\/legacy.gosecure.ai\/fr\/#website"},"primaryImageOfPage":{"@id":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2023\/08\/09\/how-unparalleled-rdp-monitoring-reveal-attackers-tradecraft\/#primaryimage"},"image":{"@id":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2023\/08\/09\/how-unparalleled-rdp-monitoring-reveal-attackers-tradecraft\/#primaryimage"},"thumbnailUrl":"","datePublished":"2023-08-09T16:00:15+00:00","dateModified":"2025-05-20T19:59:42+00:00","author":{"@id":"https:\/\/legacy.gosecure.ai\/fr\/#\/schema\/person\/11f4bfed2ab7b748dfc255aa91baedca"},"description":"Luring threat actors into RDP traps reveals attackers' tactics. This blog summarizes an hour-long presentation about what can be found in those traps.","breadcrumb":{"@id":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2023\/08\/09\/how-unparalleled-rdp-monitoring-reveal-attackers-tradecraft\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/legacy.gosecure.ai\/fr\/blog\/2023\/08\/09\/how-unparalleled-rdp-monitoring-reveal-attackers-tradecraft\/"]}]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2023\/08\/09\/how-unparalleled-rdp-monitoring-reveal-attackers-tradecraft\/#primaryimage","url":"","contentUrl":""},{"@type":"BreadcrumbList","@id":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2023\/08\/09\/how-unparalleled-rdp-monitoring-reveal-attackers-tradecraft\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/legacy.gosecure.ai\/fr\/"},{"@type":"ListItem","position":2,"name":"How Unparalleled RDP Monitoring Reveal Attackers\u2019 Tradecraft"}]},{"@type":"WebSite","@id":"https:\/\/legacy.gosecure.ai\/fr\/#website","url":"https:\/\/legacy.gosecure.ai\/fr\/","name":"GoSecure","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/legacy.gosecure.ai\/fr\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"fr-FR"},{"@type":"Person","@id":"https:\/\/legacy.gosecure.ai\/fr\/#\/schema\/person\/11f4bfed2ab7b748dfc255aa91baedca","name":"GoSecure"}]}},"_links":{"self":[{"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/posts\/4454","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/comments?post=4454"}],"version-history":[{"count":0,"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/posts\/4454\/revisions"}],"wp:attachment":[{"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/media?parent=4454"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/categories?post=4454"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/tags?post=4454"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}