BIOC
Low
✕
RDP connections enabled via Registry by unsigned process
An attacker may enable RDP connections to a machine by setting the fDenyTSConnections Registry key to 0.
- Module:
- Platform Analytics
- Agent event type:
- Registry
- Category:
- Persistence
- Status:
- Enabled
ATT&CK tactics: Lateral Movement (TA0008)
ATT&CK techniques: Remote Services: Remote Desktop Protocol (T1021.001)
Indicator:
Registry registry data = 0 AND registry key name = HKEY_LOCAL_MACHINE\SYSTEM\*ControlSet*\Control\Terminal Server AND registry value name = fDenyTSConnections AND action type = set_registry_value Process initiator signature != Signed AND N/A AND cgo signature != Signed AND N/A AND initiated by != SCCService.exe AND ZenworksWindowsService.exe AND DTPlayerMonitor.exe, AND AdisVDIDesktopAgent.exe AND RDPConf.exe AND cgo name != SCCService.exe AND ZenworksWindowsService.exe AND DTPlayerMonitor.exe, AND AdisVDIDesktopAgent.exe AND RDPConf.exe Host host os = windows
Preventable: yes