INSIGHT
From Remote Desktop Protocol to Domain Administrator
How one weak control can expose the entire network
A poorly protected remote connection can become an entry point into the organisation, allowing an attacker to move from one compromised system towards more privileged access.


Download the Full Article
Explore how weaknesses in remote access can potentially escalate to privileged access, and the controls organisations can use to protect the entire path.
RDP Is Useful — But It Needs Strong Controls
Remote Desktop Protocol (RDP) allows employees and IT teams to access a computer or server from another location. That capability can be useful for remote administration and support.
The risk arises when the controls protecting that connection are weak. An attacker may only need a weak password, a stolen login or an account without multi-factor authentication to gain access to the first computer.
From there, the attacker may look for saved passwords, confidential information and connections to other systems. A single compromised computer can therefore become the starting point for a much wider security problem.
The question organisations should ask is not simply whether remote access is secure. It is how far an attacker could go if one remote account were compromised.
THE ATTACK PATH
How a Remote Access Compromise Can Escalate
A compromised remote account may be only the first step. If an attacker can discover additional credentials or move between insufficiently separated systems, the potential impact can extend far beyond the first computer.
01
Compromised Computer
A weak password, stolen login or missing multi-factor authentication can provide the initial entry point.
02
Compromised Computer
The attacker gains access to the first computer and may begin looking for saved passwords, confidential information and connections to other systems.
03
Stolen Administrator Credentials
Credentials discovered on the compromised system may provide a route to additional systems and more privileged access.
04
Control of the Network
Highly privileged access can potentially give an attacker extensive control across the organisation’s systems and accounts.