https://www.crowdstrike.com/blog/how-falcon-complete-team-stopped-an-rdp-attack-part-1/