Stop RDP Brute-Force Attacks: Find Attackers, Block IPs and Set Account Lockout
Thousands of failed logons in the Security log? Find the attacking IPs with PowerShell, block them, enable account lockout and put RDP behind a VPN.
Common Symptoms and Quick Fixes
| Symptom | Likely Cause | Quick Fix |
|---|---|---|
| Many Event ID 4625 entries | Brute-force or password spraying | Identify and block source IPs |
| Accounts locking out all day | Attacks hitting real usernames | Set lockout policy; hide RDP behind VPN |
| Server slow during attacks | Constant logon attempts | Restrict RDP source addresses |
Method 1: Find the Attacking IP Addresses
This lists the top sources of failed logons in the last 24 hours. Run in an elevated PowerShell window.
Get-WinEvent -FilterHashtable @{LogName='Security';Id=4625;StartTime=(Get-Date).AddHours(-24)} |
ForEach-Object { $_.Properties[19].Value } |
Group-Object | Sort-Object Count -Descending |
Select-Object -First 10 Count, Name
Method 2: Block the Addresses
Replace the example addresses with the ones found above.
New-NetFirewallRule -DisplayName "Block Brute Force IPs" -Direction Inbound -Action Block -RemoteAddress 203.0.113.10,203.0.113.11
Method 3: Set an Account Lockout Policy
Lock accounts for 30 minutes after 5 failures.
net accounts /lockoutthreshold:5 /lockoutduration:30 /lockoutwindow:30
Method 4: Require NLA and Restrict RDP
Network Level Authentication stops unauthenticated sessions from consuming resources.
Set-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication -Value 1
Pro Tip for AdministratorsNever expose TCP 3389 to the internet. Use a VPN or Remote Desktop Gateway and allow RDP only from trusted addresses.
Frequently Asked Questions (FAQ)
Q: Is changing the RDP port enough?
No. It only hides the service briefly. Use a VPN and strong MFA.
Q: Will the lockout policy block me too?
It can. Keep a break-glass admin account and use a gateway so attackers never reach the logon prompt.