RDP connections enabled remotely via Registry
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detector Tags
Enhanced RDP Analytics
ATT&CK Tactic
Lateral Movement (TA0008)
ATT&CK Technique
Remote Services: Remote Desktop Protocol (T1021.001)
Severity
Low
Description
An attacker may remotely enable RDP connections to a machine by setting the fDenyTSConnections Registry key to 0.
Attacker's Goals
Remotely enable RDP on the host for lateral movement.
Investigative actions
Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.
Search for RDP sessions to this host and investigate them for malicious activities.
Variations
Was this helpful?
