← Back to SOC feed Coverage →

detect-bluekeep-exploitation-attempts

kql MEDIUM Azure-Sentinel
DeviceNetworkEvents
backdoorexploithuntingmicrosoftofficial
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Azure-Sentinel →
Retrieved: 2026-05-23T11:00:00Z · Confidence: medium

Hunt Hypothesis

Adversaries may attempt to exploit the BlueKeep vulnerability (CVE-2019-0708) by leveraging outdated Windows Remote Desktop Protocol services to execute arbitrary code remotely. SOC teams should proactively hunt for this behavior in Azure Sentinel to identify and mitigate potential remote code execution threats before they cause widespread damage.

KQL Query

DeviceNetworkEvents
| where InitiatingProcessFileName =~ "spoolsv.exe"
| where RemotePort == "3389"

Analytic Rule Definition

id: e380a30d-03ff-4d20-b2d5-d0683033d813
name: detect-bluekeep-exploitation-attempts
description: |
  This query was originally published in the threat analytics report, Exploitation of CVE-2019-0708 (BlueKeep).
  CVE-2019-0708, also known as BlueKeep, is a critical remote code execution vulnerability involving RDP. Soon after its disclosure, the NSA issued a rare advisory about this vulnerability, out of concern that it could be used to quickly spread malware. Attackers have since used this vulnerability to install cryptocurrency miners on targets.
  Microsoft has issued updates for this vulnerability, as well as guidance for protecting operating systems that we no longer support. Microsoft Defender ATP also contains behavioral detections for defending against this threat.
  The following query detects devices with RDP connections that could be exploitation attempts.
  References:
  https://nvd.nist.gov/vuln/detail/CVE-2019-0708
  https://www.nsa.gov/News-Features/News-Stories/Article-View/Article/1865726/nsa-cybersecurity-advisory-patch-remote-desktop-services-on-legacy-versions-of/
  https://www.wired.com/story/bluekeep-hacking-cryptocurrency-mining/
  https://portal.msrc.microsoft.com/security-guidance/advisory/CVE-2019-0708
  https://support.microsoft.com/help/4500705/customer-guidance-for-cve-2019-0708
  https://www.microsoft.com/security/blog/2019/11/07/the-new-cve-2019-0708-rdp-exploit-attacks-explained/
requiredDataConnectors:
- connectorId: MicrosoftThreatProtection
  dataTypes:
  - DeviceNetworkEvents
tactics:
- Initial access
- Lateral movement
query: |
  DeviceNetworkEvents
  | where InitiatingProcessFileName =~ "spoolsv.exe"
  | where RemotePort == "3389"

Required Data Sources

Sentinel TableNotes
DeviceNetworkEventsEnsure this data connector is enabled

MITRE ATT&CK Context

References

False Positive Guidance

Original source: https://github.com/Azure/Azure-Sentinel/blob/main/Hunting Queries/Microsoft 365 Defender/Initial access/detect-bluekeep-exploitation-attempts.yaml