BIOC Informational

RDP connections enabled via Registry from a script host or rundll32.exe

An attacker may enable RDP connections to a machine by setting the fDenyTSConnections Registry key to 0.

Module:
Platform Analytics
Agent event type:
Registry
Category:
Persistence
Status:
Enabled
ATT&CK tactics: Lateral Movement (TA0008)
ATT&CK techniques: Remote Services: Remote Desktop Protocol (T1021.001)
Indicator:

Registry registry data = 0 AND registry key name = HKEY_LOCAL_MACHINE\SYSTEM\*ControlSet*\Control\Terminal Server AND registry value name = fDenyTSConnections AND action type = set_registry_value Process initiated by = cmd.exe , powershell.exe , wscript.exe , cscript.exe , mshta.exe , rundll32.exe , cgo name = cmd.exe , powershell.exe , wscript.exe , cscript.exe , mshta.exe , rundll32.exe AND initiator cmd != *\\*netlogon* AND *\\*sysvol* AND *LiteTouch.wsf* AND *Puppet* AND cgo cmd != system32\osdsetuphook.exe /execute Host host os = windows

Preventable: yes