Title:RDP Connection Allowed Via Netsh.EXE Status:test Description:Detects usage of the netsh command to open and allow connections to port 3389 (RDP). As seen used by Sarwent Malware References: -https://labs.sentinelone.com/sarwent-malware-updates-command-detonation/ Author: Sander Wiebing Date: 2020-05-23 modified:2023-12-11 Tags: