Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

An internet-reachable Remote Desktop Protocol (RDP) service is an exposure finding. It tells you that a remote-access door is visible from outside your network. It does not tell you that credentials were stolen, that a host was compromised, or that anyone got in. The defensive job is to find every such service you own, decide whether each one has a justified business purpose, remove the access that does not, protect the access that does, and watch for successful logons that deserve investigation.

CISA’s baseline for public internet assets is that they should expose no exploitable services such as RDP. If a business need requires exposure, compensating controls should be in place around it. Everything below follows from that baseline.

What an exposed RDP finding does and does not establish

A scan or search result can show that a service on the usual RDP port, TCP 3389 by default, answered from an address you own, under the conditions the scan ran in. That is a reachability observation. It is useful, but it is narrower than it sounds.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • It establishes: a service appeared reachable from the scanning location at the time of observation.
  • It does not establish: that the port is RDP (another service can listen on 3389), that the host is still at that address, that the service is patched, or that any account has been abused.
  • It does not establish: that the endpoint is vulnerable. Exposure raises the risk that weak credentials, misconfiguration, or an unpatched flaw can be exploited. Whether that happens is a separate question answered by logs and investigation.

Keep these two claims apart in every report. “This RDP service is reachable from the internet and needs a decision” is a remediation item. “This host was breached through RDP” requires evidence of a successful logon and the activity that followed, and no scan supplies that.

#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

Step 1: Set the authorized scope before you look

Define what you are allowed to assess: owned public IPv4 ranges, cloud accounts and their public addresses, and any third-party hosted assets your contracts cover. Scanning outside that scope is not measurement; it is an unauthorized activity with its own legal and operational risk.

Also decide in advance that a public search platform is not a complete inventory. It is one input. Your own asset records and cloud configuration are the other inputs, and they are the basis for deciding what is missing.

Step 2: Discover external RDP and verify it

CISA names Censys, Shodan, and Shadowserver as web-based asset-discovery resources, and its guidance describes scanning as a way to gain visibility into what is publicly reachable. Shadowserver, according to CISA, scans IPv4 addresses and publishes daily reports. Those reports are leads, not verdicts.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Before counting an item as an organizational RDP exposure, check three things:

  1. Ownership. Confirm the address or name belongs to your organization or an authorized provider, using your cloud inventory and DNS or registration records.
  2. Current reachability. Confirm the service still answers, because cloud addresses change and old results persist in indexes.
  3. Service identity. Confirm the protocol is RDP. A service seen on port 3389 is a port observation. Protocol-confirmed RDP means the responding service was identified as RDP by an authorized check from your side.

Also check the other direction. Hosts that run RDP on a nonstandard port will not appear in a search for port 3389, and filtering or scan timing can hide a service that is reachable at other times. An empty search result is not proof of no exposure.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

Step 3: Classify each finding

Give every item a record that a later reader can act on. The minimum useful set is below.

Field What to record
Asset owner Named team or person accountable for the host or service
Address or name Public IP or hostname, with the cloud account or provider if known
Observation time When reachability was seen, and by which source or scan
Evidence of RDP Port observed only, or protocol-confirmed
Business purpose The workflow that needs the access, or “none identified”
Exposure path Direct to host, via load balancer or NAT, or via a gateway
Status Confirmed, or needs validation

Step 4: Decide whether the exposure is necessary

Do not change access until you know what depends on it. CISA’s guidance explicitly asks teams to evaluate necessity, weigh business justification against available security measures, and consider whether access can be restricted through a VPN or protected with MFA. The answer falls into one of three outcomes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Finding Typical decision Follow-up
No current user or dependency identified Disable RDP or close the port Confirm no scheduled jobs or vendors rely on it before the change
Needed by a defined group, but only from known locations Move behind a VPN, gateway, or jump host Restrict source networks and apply MFA at the gateway
Needed and must stay directly reachable Keep, with compensating controls, and document the exception Set an owner, a review date, and monitoring requirements

The third row should be rare and written down. An undocumented exception is the most common way exposure outlives the reason for it.

Step 5: Reduce the public surface

Disable RDP where it is not required

On a Windows host, you can check whether Remote Desktop connections are allowed with PowerShell:

Get-ItemProperty -Path 'HKLM:SystemCurrentControlSetControlTerminal Server' -Name fDenyTSConnections

Rank #3
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

A value of 0 means connections are allowed; 1 means they are denied. Change the setting through your management tooling so the change is recorded, then re-check. Close the inbound rule on the perimeter firewall or cloud security group as well, because a disabled service behind an open rule is still a configuration to track.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Close unused ports and unnecessary protocols

CISA recommends closing unused RDP ports and disabling unnecessary applications and protocols on internet-facing systems. Remove the rule, not just the service, so that a later service restart does not reopen the path.

Route required access through a gateway

If remote desktop must remain, MITRE’s mitigation guidance for RDP as a remote service points to remote desktop gateways, network segmentation, and access restrictions instead of direct internet exposure. The gateway becomes the single place that enforces MFA, logging, and source restrictions. Expect some operational cost: users need the gateway client or portal, and support teams need a documented procedure for when the gateway is down.

Harden what must stay reachable

  • Multi-factor authentication on every remote login path.
  • Current patches on the host and the gateway, since CISA and MITRE both list maintenance as part of the control set.
  • Account controls: review who is in the local and domain groups permitted to log on through Remote Desktop, limit remote user permissions, and configure account lockout thresholds.
  • Source restrictions where the user population is predictable, so that the service does not accept connections from anywhere.
  • Logging of RDP login attempts, not only successes.

Step 6: Verify the change and keep measuring

Re-run the external discovery against the same scope and confirm that the item no longer answers. Then check for drift: a rule restored by an automation job, a new cloud address that inherited an old security group, or a second listener on another port. Repeat the assessment on a schedule that matches how often your infrastructure changes. CISA recommends routine assessments and ongoing monitoring of internet-accessible assets, and the cadence should follow your change rate rather than a fixed calendar.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Step 7: Monitor successful use of remaining access

Exposure reduction lowers the number of doors. Detection covers what happens after someone walks through one. MITRE’s detection strategy DET0327, version 1.0, last modified 2026-05-12, is built around one correlation: an RDP logon followed by unusual process execution, file access, or lateral movement within a short window.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display
Data source (as listed in DET0327) What it contributes
Windows Security event 4624 Logon session creation
Windows Security event 4648 Logon using explicitly supplied credentials
Windows Security events 4778 and 4779 Session reconnect and disconnect metadata
Sysmon events 3 and 22 Network activity
Sysmon event 1 Process creation

DET0327 treats its time window, expected user context, suspicious process list, and unusual host-access patterns as elements to tune. The five-minute window often quoted for this kind of correlation is an example, not a standard. Set the window from how quickly your own users and tools normally act after logging on, and whitelist known administrative jobs so the alerts stay meaningful.

When an alert fires, investigate the logon first: which account, from which source, at what time, and whether that account and source are expected for that host. Then review the processes, files, and outbound or internal connections started in the same session.

How to explain RDP risk to non-specialists

The useful framing for executives and asset owners is a chain. Public reachability creates an opportunity. Weak or stolen credentials, misconfiguration, or an unpatched vulnerability make the opportunity usable. A successful logon then gives an interactive foothold, and MITRE documents the use of valid accounts over RDP as an access technique and as a route for lateral movement. CISA’s #StopRansomware guide makes the same point from the attacker side, noting that threat actors gain initial access through exposed, poorly secured remote services and may later move through networks using RDP.

Describe each link as a control point. Removing exposure breaks the first link. MFA and patching weaken the second. Logging and detection address the third and fourth. This avoids overstating a single scan result while still explaining why it matters.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Measurement limits to state in every report

  • Address churn: cloud public addresses change, so a finding can refer to infrastructure that no longer exists.
  • Incomplete ownership records: an address may be real and reachable but not yet assigned to anyone who can act on it.
  • Filtering and timing: a firewall, a scanner’s location, or the hour of the scan can change what is observed.
  • Nonstandard ports: RDP outside 3389 needs a different discovery approach and is easy to miss.
  • Third-party infrastructure: services run by a vendor or hosting provider may be visible under your name but governed by someone else’s controls.

Treat scanner output as a list of leads to validate and remediation candidates to track. A count of reachable RDP services without ownership, service identity, and status is not yet a measurement of your risk.

What the evidence does not support

No reliable global count or trend for internet-exposed RDP was established in the sources behind this guidance, so no such figure should be used to size your own problem. Use your own validated inventory instead. Likewise, the official guidance that is directly quotable is CISA’s recommendation that public internet assets expose no exploitable services such as RDP, with compensating controls where exposure is required. No named individual’s statement on this topic was established, and this article does not attribute one.

Sources referenced: CISA, “CISA CPG Checklist: Account Security and Internet-Exposed Services” (PDF, dated 2022-12-05); CISA, “Internet Exposure Reduction Guidance” (publication date not shown on the page); CISA, “#StopRansomware Guide” (current guidance, no dependable date shown); MITRE ATT&CK, technique T1021.001 “Remote Services: Remote Desktop Protocol,” version 1.4, modified 2026-05-12; MITRE ATT&CK, detection strategy DET0327 “Multi-event Detection Strategy for RDP-Based Remote Logins and Post-Access Activity,” version 1.0, modified 2026-05-12.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.