BIOC
Informational
✕
RDP connections enabled via Registry from a script host or rundll32.exe
An attacker may enable RDP connections to a machine by setting the fDenyTSConnections Registry key to 0.
- Module:
- Platform Analytics
- Agent event type:
- Registry
- Category:
- Persistence
- Status:
- Enabled
ATT&CK tactics: Lateral Movement (TA0008)
ATT&CK techniques: Remote Services: Remote Desktop Protocol (T1021.001)
Indicator:
Registry registry data = 0 AND registry key name = HKEY_LOCAL_MACHINE\SYSTEM\*ControlSet*\Control\Terminal Server AND registry value name = fDenyTSConnections AND action type = set_registry_value Process initiated by = cmd.exe , powershell.exe , wscript.exe , cscript.exe , mshta.exe , rundll32.exe , cgo name = cmd.exe , powershell.exe , wscript.exe , cscript.exe , mshta.exe , rundll32.exe AND initiator cmd != *\\*netlogon* AND *\\*sysvol* AND *LiteTouch.wsf* AND *Puppet* AND cgo cmd != system32\osdsetuphook.exe /execute Host host os = windows
Preventable: yes