{"id":2282,"date":"2021-04-07T21:12:52","date_gmt":"2021-04-07T19:12:52","guid":{"rendered":"http:\/\/soci.hu\/blog\/?p=2282"},"modified":"2021-04-07T21:12:52","modified_gmt":"2021-04-07T19:12:52","slug":"rdp-brute-force-protection-with-powershell-and-windows-firewall-rules","status":"publish","type":"post","link":"https:\/\/soci.hu\/blog\/index.php\/2021\/04\/07\/rdp-brute-force-protection-with-powershell-and-windows-firewall-rules\/","title":{"rendered":"RDP Brute Force Protection with PowerShell and Windows Firewall Rules"},"content":{"rendered":"\n<p>Az \u00f6tlet <a href=\"http:\/\/woshub.com\/block-rdp-brute-force-powershell-firewall-rules\/?fbclid=IwAR31HifhwurndOvuUnnLAnNwoM4WfeLUERTS-a7By4_2izyRgjMLhxeG6P4\">innen<\/a> j\u00f6tt. Kicsit \u00e1t\u00edrtam a k\u00f3dot, mert az eredeti minden egyes kitiltott IP-t egyes\u00e9vel appendelte a log f\u00e1jlhoz, ami nagyon lass\u00fav\u00e1 tette, valamint nem kezelte a duplik\u00e1t bejegyz\u00e9seket.<\/p>\n\n\n\n<p>\u00cdme az \u00e1t\u00edrt verzi\u00f3:<\/p>\n\n\n<div class=\"wp-block-syntaxhighlighter-code \"><pre class=\"brush: powershell; title: ; notranslate\" title=\"\">\n$Last_n_Hours = &#x5B;DateTime]::Now.AddHours(-24)\n$badRDPlogons = Get-EventLog -LogName &#039;Security&#039; -after $Last_n_Hours -InstanceId 4625 | ?{$_.Message -match &#039;logon type:\\s+(3)\\s&#039;} | Select-Object @{n=&#039;IpAddress&#039;;e={$_.ReplacementStrings&#x5B;-2]} }\n$getip = $badRDPlogons | group-object -property IpAddress | where {$_.Count -gt 10} | Select -property Name\n\n$uniqueIps = @{}\n\n$current_ips = (Get-NetFirewallRule -DisplayName &quot;BlockRDPBruteForce&quot; | Get-NetFirewallAddressFilter ).RemoteAddress\n\nforeach ($ip in $current_ips)\n{\n    $uniqueIps&#x5B;$ip] = $true\n}\n\nforeach ($ip in $getip)\n{\n    $uniqueIps&#x5B;$ip.Name] = $true\n}\n\n$finalBlockedIps = $uniqueIps.Keys | Sort-Object\n\nSet-NetFirewallRule -DisplayName &quot;BlockRDPBruteForce&quot; -RemoteAddress $finalBlockedIps\n\nWrite-Output &quot;Blocked addresses:&quot;\n$finalBlockedIps \n\nWrite-Output &quot;Blocked address count:&quot;\n$finalBlockedIps.Count\n\n$log = &quot;C:\\ware\\secu\\rdp_blocked_ip.txt&quot;\n$finalBlockedIps | Select-Object {(Get-Date).ToString() + &#039; &#039; + $_} | Out-File $log\n\n<\/pre><\/div>\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"950\" height=\"1024\" src=\"https:\/\/soci.hu\/blog\/wp-content\/uploads\/2021\/04\/image-950x1024.png\" alt=\"\" class=\"wp-image-2283\" srcset=\"https:\/\/soci.hu\/blog\/wp-content\/uploads\/2021\/04\/image-950x1024.png 950w, https:\/\/soci.hu\/blog\/wp-content\/uploads\/2021\/04\/image-600x647.png 600w, https:\/\/soci.hu\/blog\/wp-content\/uploads\/2021\/04\/image-278x300.png 278w, https:\/\/soci.hu\/blog\/wp-content\/uploads\/2021\/04\/image-768x828.png 768w, https:\/\/soci.hu\/blog\/wp-content\/uploads\/2021\/04\/image-624x673.png 624w, https:\/\/soci.hu\/blog\/wp-content\/uploads\/2021\/04\/image.png 1309w\" sizes=\"auto, (max-width: 950px) 100vw, 950px\" \/><\/figure>\n\n\n\n<p>Itt l\u00e1that\u00f3, hogy 1 nap ut\u00e1n m\u00e1r 260 c\u00edmet tiltott ki.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Az \u00f6tlet innen j\u00f6tt. Kicsit \u00e1t\u00edrtam a k\u00f3dot, mert az eredeti minden egyes kitiltott IP-t egyes\u00e9vel appendelte a log f\u00e1jlhoz, ami nagyon&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[28,4,22,55],"tags":[],"class_list":["post-2282","post","type-post","status-publish","format-standard","hentry","category-powershell","category-szakmai-elet","category-security","category-windows"],"_links":{"self":[{"href":"https:\/\/soci.hu\/blog\/index.php\/wp-json\/wp\/v2\/posts\/2282","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/soci.hu\/blog\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/soci.hu\/blog\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/soci.hu\/blog\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/soci.hu\/blog\/index.php\/wp-json\/wp\/v2\/comments?post=2282"}],"version-history":[{"count":1,"href":"https:\/\/soci.hu\/blog\/index.php\/wp-json\/wp\/v2\/posts\/2282\/revisions"}],"predecessor-version":[{"id":2284,"href":"https:\/\/soci.hu\/blog\/index.php\/wp-json\/wp\/v2\/posts\/2282\/revisions\/2284"}],"wp:attachment":[{"href":"https:\/\/soci.hu\/blog\/index.php\/wp-json\/wp\/v2\/media?parent=2282"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/soci.hu\/blog\/index.php\/wp-json\/wp\/v2\/categories?post=2282"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/soci.hu\/blog\/index.php\/wp-json\/wp\/v2\/tags?post=2282"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}