RDP Event ID 131: TCP connection accepted
- Event ID
- 131
- Channel
- Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational
- Provider
- Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
- Log file
- Microsoft-Windows-RemoteDesktopServices-RdpCoreTS%4Operational.evtx
- Category
- Remote access
- Default logging
- Logged by default
What event 131 means
Event 131 is written by the RDP protocol stack when a TCP connection to the Remote Desktop listener is accepted. It happens before any authentication, so it captures every client that reached the port: legitimate users, brute-force tools and internet scanners alike.
That makes it useful for two things: seeing connection attempts that never produced 1149 or 4624 (failed or aborted logons, scanning), and getting the client's source port for correlation with firewall or network logs.
When it is logged
None — the Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational channel is enabled by default on hosts with Remote Desktop enabled.
Key fields
| Field | What it tells you |
|---|---|
| ConnType | Transport of the accepted connection (for example TCP). |
| ClientIP | Client IP address and source port (address:port). |
Common benign sources
- Every legitimate RDP connection starts with one.
- Load balancers and monitoring probes checking that the port is open.
What attackers do that produces it
- Internet-wide scanning and RDP brute force, visible as many 131 events from external IPs, most without a following 1149.
- The first trace of a tunneled RDP connection (ClientIP on loopback).
Investigation tips
- Count 131 per ClientIP and compare with 1149 and 4624 type 10; a high ratio of connections to successful logons means brute force or scanning.
- For a confirmed malicious logon, use the source port with network logs to identify the flow.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.