RDP logs in with Windows credentials (local or domain), which makes it a direct target for guessing and reuse attacks and one of the most common ways stolen or sprayed credentials turn into interactive access. Brute force and spraying work against the logon, credential stuffing replays breached username/password pairs, and Network Level Authentication (NLA) only moves the check earlier (into CredSSP) rather than preventing guessing. A valid credential yields a full interactive desktop, frequently with administrative or domain rights, so RDP authentication is a high-value, high-frequency attack surface, subject to Windows account lockout.
# spray/guess against RDP, respecting lockout (domain\user forms from enumeration)
nxc rdp <target> -u users.txt -p 'Winter2025!' # marks valid + whether admin
hydra -L users.txt -p 'Winter2025!' rdp://<target> -t 1
Subtopics#
- Password brute force: online guessing against the logon.
- Credential stuffing: replaying breached and reused credentials.
- NLA bypass: Network Level Authentication considerations and misconfigurations.