Analytics BIOC Low

RDP connections enabled remotely via Registry

An attacker may remotely enable RDP connections to a machine by setting the fDenyTSConnections Registry key to 0.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Lateral Movement (TA0008)
ATT&CK techniques: Remote Services: Remote Desktop Protocol (T1021.001)
Detector tags: Enhanced RDP Analytics
Attacker's goals:

Remotely enable RDP on the host for lateral movement.

Investigative actions:

Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow. Search for RDP sessions to this host and investigate them for malicious activities.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • RDP connections enabled by a remote process via Registry Low
  • RDP connections enabled remotely via Registry using WinRM Low Adds Remote Services: Windows Remote Management (T1021.006)