# RDP from Internet rule triggering on bogon ip address

**URL:** <https://discuss.elastic.co/t/rdp-from-internet-rule-triggering-on-bogon-ip-address/253269>\
**Category:** SIEM\
**Created:** [October 26, 2020, 7:59am UTC](https://discuss.elastic.co/t/rdp-from-internet-rule-triggering-on-bogon-ip-address/253269 "2020-10-26T07:59:45Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [October 26, 2020, 7:59am UTC](https://discuss.elastic.co/t/rdp-from-internet-rule-triggering-on-bogon-ip-address/253269/1 "2020-10-26T07:59:46Z")

</div>

Hello,

Noticed the SIEM rule" RDP (Remote Desktop Protocol) from the Internet" triggered on `source.ip: "169.254.231.41"` which is a bogon link-local address.

![image](https://us1.discourse-cdn.com/elastic/original/3X/5/e/5e37c6f950b63bc4bc10b9c6ddb5b24d9e5e9f58.png)

So this should not be considered as "from the Internet" and so "169.254.0.0/16" should be excluded in the query?

`event.category:(network or network_traffic) and network.transport:tcp and (destination.port:3389 or event.dataset:zeek.rdp) and not source.ip:(10.0.0.0/8 or 172.16.0.0/12 or 192.168.0.0/16) and destination.ip:(10.0.0.0/8 or 127.0.0.0/8 or 172.16.0.0/12 or 192.168.0.0/16 or "::1")`

Grtz

Willem

---

<div class="post-metadata">

**Author:** ![Mike\_Paquette](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mike_paquette/32/119011_2.png) [@Mike\_Paquette](https://discuss.elastic.co/u/Mike_Paquette)\
**Post date:** [October 26, 2020, 10:35am UTC](https://discuss.elastic.co/t/rdp-from-internet-rule-triggering-on-bogon-ip-address/253269/2 "2020-10-26T10:35:27Z")

</div>

Hi Willem, thanks for submitting this rule improvement suggestion!

I've created an issue in our public detection-rules repo, passing along your suggested improvement

> <https://github.com/elastic/detection-rules/issues/409>
>
> Origin
> Submitted to discuss forum on 26-Oct-2020 by @willemdh
> Description
> Noticed the SIEM rule" RDP (Remote Desktop Protocol) from the Internet" triggered on source.ip:...

BTW, you can create issues directly in that repo if you prefer, as it is a public repo!

Thanks for your continued contributions to our community!

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [October 26, 2020, 10:53am UTC](https://discuss.elastic.co/t/rdp-from-internet-rule-triggering-on-bogon-ip-address/253269/3 "2020-10-26T10:53:32Z")

</div>

> [@Mike\_Paquette](#):
>
> BTW, you can create issues directly in that repo if you prefer, as it is a public repo!

Well it's kind of confusing, because sometimes when I create some GH issue, I get the message I need to create a forum post first...

Anyway, thanks for creating the GH issue!

By the way, the same consideration might be valid for other "from / to the Internet" rules.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 23, 2020, 10:53am UTC](https://discuss.elastic.co/t/rdp-from-internet-rule-triggering-on-bogon-ip-address/253269/4 "2020-11-23T10:53:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
