Analytics BIOC
Low
✕
RDP connections enabled remotely via Registry
An attacker may remotely enable RDP connections to a machine by setting the fDenyTSConnections Registry key to 0.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Lateral Movement (TA0008)
ATT&CK techniques: Remote Services: Remote Desktop Protocol (T1021.001)
Detector tags: Enhanced RDP Analytics
Attacker's goals:
Remotely enable RDP on the host for lateral movement.
Investigative actions:
Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow. Search for RDP sessions to this host and investigate them for malicious activities.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- RDP connections enabled by a remote process via Registry Low
- RDP connections enabled remotely via Registry using WinRM Low Adds Remote Services: Windows Remote Management (T1021.006)