BIOC Low

RDP connections enabled via Registry by unsigned process

An attacker may enable RDP connections to a machine by setting the fDenyTSConnections Registry key to 0.

Module:
Platform Analytics
Agent event type:
Registry
Category:
Persistence
Status:
Enabled
ATT&CK tactics: Lateral Movement (TA0008)
ATT&CK techniques: Remote Services: Remote Desktop Protocol (T1021.001)
Indicator:

Registry registry data = 0 AND registry key name = HKEY_LOCAL_MACHINE\SYSTEM\*ControlSet*\Control\Terminal Server AND registry value name = fDenyTSConnections AND action type = set_registry_value Process initiator signature != Signed AND N/A AND cgo signature != Signed AND N/A AND initiated by != SCCService.exe AND ZenworksWindowsService.exe AND DTPlayerMonitor.exe, AND AdisVDIDesktopAgent.exe AND RDPConf.exe AND cgo name != SCCService.exe AND ZenworksWindowsService.exe AND DTPlayerMonitor.exe, AND AdisVDIDesktopAgent.exe AND RDPConf.exe Host host os = windows

Preventable: yes