MH IT SOLUTION — Production Tech Knowledge Base & IT Troubleshooting Guides ▶ YouTube Channel

Stop RDP Brute-Force Attacks: Find Attackers, Block IPs and Set Account Lockout

MH IT SOLUTION Editorial Team · Updated August 09, 2026 · 8 min readIntermediate

Thousands of failed logons in the Security log? Find the attacking IPs with PowerShell, block them, enable account lockout and put RDP behind a VPN.

Common Symptoms and Quick Fixes

Symptom Likely Cause Quick Fix
Many Event ID 4625 entries Brute-force or password spraying Identify and block source IPs
Accounts locking out all day Attacks hitting real usernames Set lockout policy; hide RDP behind VPN
Server slow during attacks Constant logon attempts Restrict RDP source addresses

Method 1: Find the Attacking IP Addresses

This lists the top sources of failed logons in the last 24 hours. Run in an elevated PowerShell window.

Get-WinEvent -FilterHashtable @{LogName='Security';Id=4625;StartTime=(Get-Date).AddHours(-24)} |
  ForEach-Object { $_.Properties[19].Value } |
  Group-Object | Sort-Object Count -Descending |
  Select-Object -First 10 Count, Name

Method 2: Block the Addresses

Replace the example addresses with the ones found above.

New-NetFirewallRule -DisplayName "Block Brute Force IPs" -Direction Inbound -Action Block -RemoteAddress 203.0.113.10,203.0.113.11

Method 3: Set an Account Lockout Policy

Lock accounts for 30 minutes after 5 failures.

net accounts /lockoutthreshold:5 /lockoutduration:30 /lockoutwindow:30

Method 4: Require NLA and Restrict RDP

Network Level Authentication stops unauthenticated sessions from consuming resources.

Set-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication -Value 1
Pro Tip for AdministratorsNever expose TCP 3389 to the internet. Use a VPN or Remote Desktop Gateway and allow RDP only from trusted addresses.

Frequently Asked Questions (FAQ)

Q: Is changing the RDP port enough?

No. It only hides the service briefly. Use a VPN and strong MFA.

Q: Will the lockout policy block me too?

It can. Keep a break-glass admin account and use a gateway so attackers never reach the logon prompt.

Leave a Reply

Your email address will not be published. Required fields are marked *