---
title: Microsoft announces solution to detect suspicious processes running on hidden desktops
description: With remote desktop protocol (RDP) compromises on the rise, Microsoft Defender for Endpoint has introduced a new field that can provide analysts with full visibility into potentially malicious RDP session use.
image: https://csacyber.com/hubfs/standard-quality-control-concept-m.jpg
---

[Skip to content](https://csacyber.com/blog/microsoft-announces-solution-to-detect-suspicious-processes-running-on-hidden-desktops#main-content)

[![CSA Cyber - Cyber Security Solutions to Protect your People](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Full%20Logo.png?width=300&height=108&name=CSA%20Cyber%20Logo%20FNL_Full%20Logo.png "CSA Cyber - Cyber Security Solutions to Protect your People")](https://csacyber.com/)

- Services 
    - [Offensive Security Services](https://csacyber.com/offensive-security-services) 
          - [Penetration Testing](https://csacyber.com/penetration-testing)
          - [Red Teaming and attack simulations](https://csacyber.com/offensive-security-services#red-teaming)
          - [Continuous testing](https://csacyber.com/offensive-security-services#continuous-assurance)
          - [Managed offensive security](https://csacyber.com/offensive-security-services#managed-offensive)
    - [Consultancy Services](https://csacyber.com/cyber-consultancy-services) 
          - [Frameworks & assessments](https://csacyber.com/cyber-consultancy-services/frameworks-and-assessments)
          - [Data protection](https://csacyber.com/cyber-consultancy-services#data-protection)
          - [Virtual leadership](https://csacyber.com/cyber-consultancy-services#virtual-leadership)
          - [Technical security consulting](https://csacyber.com/cyber-consultancy-services#technical-consultancy)
          - [Governance, Risk & Compliance (GRC)](https://csacyber.com/cyber-consultancy-services/governance-risk-and-compliance-services)
    - [Extended Managed Security Services](https://csacyber.com/extended-managed-security-services) 
          - [Microsoft Sentinel SIEM](https://csacyber.com/extended-managed-security-services#microsoft-sentinel)
          - [SOC services](https://csacyber.com/extended-managed-security-services#soc-services)
          - [SentinelOne Endpoint Detection & Response (EDR)](https://csacyber.com/extended-managed-security-services#cyber-helpdesk)
    - [Incident Response Services](https://csacyber.com/incident-response-services) 
          - [Emergency Incident Response](https://csacyber.com/urgent/emergency-incident-response)
          - [Incident Response Retainer](https://csacyber.com/incident-response-services)
          - [Cyber Incident Readiness & Response Planning](https://csacyber.com/incident-response-services)
          - [Tabletop Exercises & Live-Range Engagements](https://csacyber.com/incident-response-services)
    - [Specialist Security Services](https://csacyber.com/specialist-services) 
          - [AI Security](https://csacyber.com/cyber-services-for-ai)
          - [Operational Technology (OT)](https://csacyber.com/specialist-services#operational-technology)
          - [Cyber security for Private Equity](https://csacyber.com/specialist-services#mergers-and-acquisitions)
          - [Cyber training and education](https://csacyber.com/specialist-services#training-and-education)
          - [Virtual leadership](https://csacyber.com/specialist-services#leadership)
    - [Cyber Technologies](https://csacyber.com/cyber-technologies) 
          - [SentinelOne Endpoint Detection & Response (EDR)](https://csacyber.com/cyber-technologies#sentinelone)
          - [AppGuard Endpoint & Server Zero Trust Protection](https://csacyber.com/cyber-technologies#appguard)
          - [Qualys Vulnerability Management as a Service (VMaaS)](https://csacyber.com/cyber-technologies#qualys-vmaas)
          - [Lookout Mobile Device Protection](https://csacyber.com/cyber-technologies#lookout)
          - [ThreatER DNS Protection](https://csacyber.com/cyber-technologies#threater-dns)
          - [Cyber Security Awareness & Training platform](https://csacyber.com/cyber-technologies#boxphish)
- [About](https://csacyber.com/about-us) 
    - [Careers](https://csacyber.com/careers)
    - [Certifications](https://csacyber.com/certifications-and-awards)
- [Blog](https://csacyber.com/blog)
- [Support Centre](https://csacyber.com/support)
- Resources 
    - [Case Studies](https://csacyber.com/case-studies)
    - [Downloads & Reports](https://csacyber.com/downloads-and-reports)
    - [Webinars](https://csacyber.com/webinars)
    - [Partners](https://csacyber.com/partners)
    - [Cyber Bundles (IT MSPs)](https://csacyber.com/cyber-bundles)
- [Contact](https://csacyber.com/contact-us)

- Search Search
  
  Search

 July 2, 2024

 4 min read time

# Microsoft announces solution to detect suspicious processes running on hidden desktops

![Aidan Matthews](https://app.hubspot.com/settings/avatar/d41d8cd98f00b204e9800998ecf8427e) [Written by: Aidan Matthews -](https://csacyber.com/blog/author/aidan-matthews) 

![](https://csacyber.com/hubfs/standard-quality-control-concept-m.jpg)

### Overview

With remote desktop protocol (RDP) compromises on the rise, Microsoft Defender for Endpoint has introduced a new field that can provide analysts with full visibility into potentially malicious RDP session use.

### Importance of RDP and RMM

But first, what is RDP and why is it used?

RDP stands for remote desktop protocol and it is used by many organisations as it allows users to take control of a remote computer or virtual machine as if they were in front of the computer in person. This makes it possible to access a desktop, open and edit files, or use applications over a network connection making it practical for those that are travelling or working from home. By performing these actions remotely, it is possible to provide and receive technical support or troubleshooting allowing for network servers to be configured.

While this protocol has its practical uses, adversaries take advantage of the fact that RDP is unfortunately often misconfigured, such as RDP ports being exposed to the internet.

### Remote Compromise

Windows only allows one remote RDP session and this can prevent attackers from connecting to a device at the same time as legitimate users. Therefore, some attackers may attempt to use remote monitoring and management (RMM) approaches, such as the two approaches detailed in the blogpost.

##### Windows Stations

The first approach exploits the fact that Windows user sessions can be assigned with multiple Windows Station objects. Each Windows Station can contain multiple desktop objects and this allows the attacker to create and use their own ‘hidden desktop’, which gives them the ability to control a victims device by using a separate interface that is not visible to the victim. From this hidden desktop, the attacker can monitor the user’s activities, move laterally within the system and exfiltrate data, all while remaining undetected. Furthermore, since the clipboard is shared by all desktops within the window station, the attacker can steal sensitive information, such as credentials from the clipboard.

##### Hidden Virtual Network Computing (hVNC)

While also relying on the use of hidden desktops, the second approach uses hidden virtual network computing, or hVNC, which is a technology that allows for multiple interactive desktops to exist simultaneously in a single user session. Unlike the previous approach, using hVNC opens a hidden instance as a virtual desktop, which allows the attacker to remotely interact with the victim device making it suitable for advanced persistent threat (APT) campaigns.

Both of these approaches show how hidden desktops can be abused by attackers and highlights the importance of the new ‘DesktopName’ field in Defender for Endpoint. More on this in the **How to Protect Yourself** section.

## Rise in RDP Abuse

A recent [adversary report from Sophos](https://news.sophos.com/en-us/2024/04/03/active-adversary-report-1h-2024/) found that RDP abuse was involved in 90% of its incident response cases and that ransomware groups often abuse it as an entry point for their attacks.

Recent examples of malware that make use of hidden desktops include Pandora hVNC, Escanor and Xeno RAT (which are open-source and available for attackers to download). Many of these are trojans and have been seen promoted in Google ads, such as LOBSHOT which was [distributed via Google ads in 2023](https://www.bleepingcomputer.com/news/security/new-lobshot-malware-gives-hackers-hidden-vnc-access-to-windows-devices/) that led to a fake AnyDesk site giving attackers complete control over any device that ran the executable.

### How to Protect Yourself

To protect yourself from attacks similar to those described above, we recommend that you take the following steps:

 

###### Take control with Defender for Endpoint

Microsoft has showcased how the ‘DesktopName’ field can be used in Defender for Endpoint, such as generating alerts when PowerShell is detected on a hidden desktop. This can detect and prevent attackers who abuse hidden desktops to gain information, or further their attacks.

![](https://csa.limited/assets/img/blog/MicrosoftDefenderEdnpoint-fig1.png)

Defender for Endpoint ‘hidden desktop’ detection capability

 

## Mitigate unauthorised Remote Access

These attacks often prey on misconfiguration, so by ensuring the following steps, you can protect your organisation from unauthorised remote access:

- Limit connections to port 3389 to whitelisted IP addresses and specific devices.
- Enable automatic Windows updates to ensure patching of RDP vulnerabilities.
- Ensure that strong passwords and MFA are mandatory, specifically MFA with number matching as this can help mitigate MFA Bombing/MFA Fatigue attacks.
- Enable NLA (Network-Level Authentication) for RDP.

 

## Conclusion

The cyber landscape is constantly changing and it is important to ensure that your organisation is following the trends. Currently, with RDP and RMM compromise on the rise, organisations that are not sufficiently protected can fall victim to command and control, lateral movement, or even ransomware. By implementing Microsoft Defender for Endpoint and making use of the new field, it is possible to detect these hidden desktop attacks and by ensuring you have configured RDP correctly, it is possible to stop unauthorised remote connections to your organisation’s devices and servers.

### Bibliography

[\[1\] Microsoft Blogpost](https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/detect-suspicious-processes-running-on-hidden-desktops/ba-p/4072322#:~:text=The%20ability%20to%20identify%20malicious,of%20the%20evolving%20threat%20landscape)

[\[2\] V2 Cloud RDP](https://v2cloud.com/blog/remote-desktop-services/)

[\[3\] Microsoft RDP](https://learn.microsoft.com/en-us/troubleshoot/windows-server/remote/understanding-remote-desktop-protocol)

[\[4\] Cloudflare RDP](https://www.cloudflare.com/learning/access-management/what-is-the-remote-desktop-protocol/)

[\[5\] What are RDP attacks and how to mitigate](https://www.parallels.com/blogs/ras/rdp-attack/)

[\[6\] Sophos Report 2024](https://news.sophos.com/en-us/2024/04/03/active-adversary-report-1h-2024/)

[\[7\] Pandora hVNC RAT](https://slashnext.com/blog/silent-yet-powerful-pandora-hvnc-the-popular-cybercrime-tool-that-flies-under-the-radar/?web_view=true)

[\[8\] Lobshot distributed via google ads](https://www.bleepingcomputer.com/news/security/new-lobshot-malware-gives-hackers-hidden-vnc-access-to-windows-devices/)

Related Posts

## You may also like this

[Similar Articles](https://csacyber.com/blog)

[![](https://csacyber.com/hs-fs/hubfs/20230510-N1005919-Edit1.jpg?width=624&height=427&name=20230510-N1005919-Edit1.jpg)](https://csacyber.com/blog/fluidone-group-appoints-charly-davis-as-managing-director-of-csa-cyber-to-advance-its-security-first-strategy)

 August 24, 2026

 2 min read

### [FluidOne Group appoints Charly Davis as Managing Director of CSA Cyber to advance its security-first strategy](https://csacyber.com/blog/fluidone-group-appoints-charly-davis-as-managing-director-of-csa-cyber-to-advance-its-security-first-strategy)

 Experienced industry leader joins FluidOne to strengthen integrated cyber, IT and secure networking...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![](https://csacyber.com/hs-fs/hubfs/Untitled%20design.jpg?width=624&height=427&name=Untitled%20design.jpg)](https://csacyber.com/blog/csa-cyber-and-fluidone-named-as-suppliers-on-g-cloud-15)

 August 20, 2026

 2 min read

### [CSA Cyber and FluidOne named as suppliers on G-Cloud 15](https://csacyber.com/blog/csa-cyber-and-fluidone-named-as-suppliers-on-g-cloud-15)

 CSA Cyber (CSA), part of the FluidOne Group, has been named as a supplier on Government Commercial...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![](https://csacyber.com/hs-fs/hubfs/Engineered%20to%20Endure%20Campaign%20Assets%20(2).png?width=624&height=427&name=Engineered%20to%20Endure%20Campaign%20Assets%20(2).png)](https://csacyber.com/blog/why-organisations-lose-security-visibility-without-realising-it)

 August 20, 2026

 6 min read

### [Why organisations lose security visibility without realising it](https://csacyber.com/blog/why-organisations-lose-security-visibility-without-realising-it)

 Before an organisation can understand risk, maintain control or respond effectively to emerging...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![CSA Cyber Logo FNL_Full Logo](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Full%20Logo.png?width=3463&height=1248&name=CSA%20Cyber%20Logo%20FNL_Full%20Logo.png "CSA Cyber Logo FNL_Full Logo")](https://csacyber.com/)

Established in 2013, Cyber Security Associates Limited trading as CSA Cyber provides cyber consultancy and cyber managed services which help to detect, protect and educate against the ever-changing cyber threat. We have built our team from a foundation of Government (ex-Military) and Commercially experienced specialists all holding current and relevant cyber certifications. Today our core services are based around a 24/7 Security Operations Centre (SOC) based in Gloucester.

#### News & Resources

- [Blog](https://csacyber.com/blog)
- [Case Studies](https://csacyber.com/case-studies)
- [Downloads & Reports](https://csacyber.com/downloads-and-reports)
- [Webinars](https://csacyber.com/webinars)
- [Careers](https://csacyber.com/careers)
- [Cyber Bundles (IT MSPs)](https://csacyber.com/cyber-bundles)

#### Quick Links

- [About Us](https://csacyber.com/about-us)
- [Certifications](https://csacyber.com/certifications-and-awards)
- [Our Parent Company](https://www.fluidone.com)
- [Partners](https://csacyber.com/partners)
- [Contact Us](https://csacyber.com/contact-us)
- [Anti Bribery Policy](https://csacyber.com/hubfs/CSAAnti-BriberyPolicy.pdf)
- [Complaints Policy](https://csacyber.com/hubfs/CSAComplaintsPolicy.pdf)
- [Corporate Social Responsibility Policy](https://csacyber.com/hubfs/CSACorporateSocialResponsibilityPolicy.pdf)
- [Slavery and Human Trafficking Statement](https://csacyber.com/hubfs/CSASlaveryandHumanTraffickingStatement.pdf)
- [NCSC CHECK Status Verification](https://www.ncsc.gov.uk/organisation/csa-cyber/check-penetration-testing)
- [CREST Approved Certification Verification](https://www.crest-approved.org/member_companies/csa-cyber/)

#### Contact Information

**United Kingdom - London**

Cyber Security Associates Ltd

5 Hatfields, London, SE1 9PG

 

**United Kingdom - Gloucester**

Cyber Security Associates Ltd

Unit 11, Wheatstone Court, Waterwells Business Park, GL2 2AQ

 

**Phone:** [+44(0) 300 303 4691](tel:03003034691)

**Email:** [hello@csacyber.com](mailto:hello@csacyber.com)

 

**United States of America**

Cyber Security Associates Inc.

6010 W. Spring Creek Pkwy, Plano, Texas, 75024

 

**Phone:** [+1 469 750 1695](tel:14697501695) 

**Email:** [hello@csacyber.com](mailto:hello@csacyber.com)

 

[![trust-pilot](https://csacyber.com/hs-fs/hubfs/trust-pilot.png?width=178&height=104&name=trust-pilot.png)](https://uk.trustpilot.com/review/csa.limited)

 

---

- [Website Terms of Use](https://csacyber.com/website-terms-of-use)
- [Website Privacy Policy](https://csacyber.com/privacy-notice)
- [Website Cookie Policy](https://csacyber.com/cookie-policy)

 Copyright 2026. Cyber Security Associates Ltd [Follow us on Facebook](https://www.facebook.com/CSALIMITED/) [Follow us on LinkedIn](https://www.linkedin.com/company/csa-cyber/) [Follow us on Twitter](https://twitter.com/cybersecurityis) [Follow us on Facebook](https://www.youtube.com/@cybersecurityassociateslim) [Follow us on Facebook](https://www.instagram.com/cybersecurityassociates)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Aidan Matthews",
    "url" : "https://csacyber.com/blog/author/aidan-matthews"
  },
  "dateModified" : "2024-12-06T11:11:13.598Z",
  "datePublished" : "2024-07-02T04:15:00.000Z",
  "headline" : "Microsoft announces solution to detect suspicious processes running on hidden desktops",
  "image" : [ "https://csacyber.com/hubfs/standard-quality-control-concept-m.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://csacyber.com/blog/microsoft-announces-solution-to-detect-suspicious-processes-running-on-hidden-desktops",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://csacyber.com/hubfs/csacyber-logo-black-01.svg"
    },
    "name" : "Cyber Security Associates Ltd"
  }
}
```