NF – Norwegian_Nynorsk layout in RDP connection setup

This alert is triggered when an RDP connection setup from an internal network device to an external server includes a specific input layout identifier (|08 14 00 00|) associated with the Norwegian Nynorsk keyboard layout. This could indicate a specific regional configuration being used.

Categories:

ID Number

5012028

Signature

alert tcp $HOME_NET any -> $EXTERNAL_NET 3389 (msg:"NF - Norwegian_Nynorsk layout in RDP connection setup"; flow:established; content:"|08 14 00 00|"; nocase; reference:url,networkforensic.dk; metadata:26092014; classtype:misc-activity; sid:5012028; rev:1;)

Severity

Low

Recommendations/Investigative actions

Identify which internal device is initiating the RDP session to verify if it is authorized and expected. Confirm whether the Norwegian Nynorsk layout is expected in your environment or if this is indicative of potentially suspicious activity. Block unauthorized RDP traffic.