Skip to content
RDP RdpCoreTS

RDP Event ID 131: TCP connection accepted

The server accepted a new TCP connection from clientRdpCoreTS event 131 is logged when the RDP server accepts a TCP connection, with the client IP and port — even for failed or scanner connections.
131
Event ID
131
Channel
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Log file
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS%4Operational.evtx
Category
Remote access
Default logging
Logged by default

What event 131 means

Event 131 is written by the RDP protocol stack when a TCP connection to the Remote Desktop listener is accepted. It happens before any authentication, so it captures every client that reached the port: legitimate users, brute-force tools and internet scanners alike.

That makes it useful for two things: seeing connection attempts that never produced 1149 or 4624 (failed or aborted logons, scanning), and getting the client's source port for correlation with firewall or network logs.

When it is logged

Audit policy / configuration

None — the Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational channel is enabled by default on hosts with Remote Desktop enabled.

Key fields

FieldWhat it tells you
ConnTypeTransport of the accepted connection (for example TCP).
ClientIPClient IP address and source port (address:port).

Common benign sources

  • Every legitimate RDP connection starts with one.
  • Load balancers and monitoring probes checking that the port is open.

What attackers do that produces it

  • Internet-wide scanning and RDP brute force, visible as many 131 events from external IPs, most without a following 1149.
  • The first trace of a tunneled RDP connection (ClientIP on loopback).

Investigation tips

  • Count 131 per ClientIP and compare with 1149 and 4624 type 10; a high ratio of connections to successful logons means brute force or scanning.
  • For a confirmed malicious logon, use the source port with network logs to identify the flow.

MITRE ATT&CK techniques

TechniqueTactics
T1021.001 Remote Services: Remote Desktop ProtocolLateral Movement
T1110 Brute ForceCredential Access

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading