Network Perimeter
Exposed Remote Access Services
RDP, VPN appliances, and legacy management interfaces are primary ransomware entry points.
What it is
Remote Desktop Protocol exposed to the internet (TCP 3389) is brute-forced and credential-stuffed continuously. Legacy VPN appliances from Citrix, Ivanti, Fortinet, and Cisco have been the subject of CISA emergency advisories due to mass exploitation before patches are applied. These devices sit at the perimeter and, when compromised, give attackers a fully authenticated foothold with no further exploitation required.
Attack techniques
- RDP Brute Force (T1110)
- Exploitation of perimeter device CVE (T1190)
- Valid credentials on VPN (T1078)
- Exposed management interfaces (T1133)
Business impact
Compromised perimeter devices give direct, authenticated access to the internal network — bypassing all inbound security controls that assume the threat comes from outside.