For the complete documentation index, see llms.txt. This page is also available as Markdown.

RDP connections enabled remotely via Registry

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent with eXtended Threat Hunting (XTH)

Detector Tags

Enhanced RDP Analytics

ATT&CK Tactic

Lateral Movement (TA0008)

ATT&CK Technique

Remote Services: Remote Desktop Protocol (T1021.001)

Severity

Low

Description

An attacker may remotely enable RDP connections to a machine by setting the fDenyTSConnections Registry key to 0.

Attacker's Goals

Remotely enable RDP on the host for lateral movement.

Investigative actions

  • Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.

  • Search for RDP sessions to this host and investigate them for malicious activities.

Variations

RDP connections enabled by a remote process via Registry

Synopsis

Field
Value

ATT&CK Tactic

Lateral Movement (TA0008)

ATT&CK Technique

Remote Services: Remote Desktop Protocol (T1021.001)

Severity

Low

Description

An attacker may remotely enable RDP connections to a machine by setting the fDenyTSConnections Registry key to 0.

Attacker's Goals

Remotely enable RDP on the host for lateral movement.

Investigative actions

  • Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.

  • Search for RDP sessions to this host and investigate them for malicious activities.

RDP connections enabled remotely via Registry using WinRM

Synopsis

Field
Value

ATT&CK Tactic

Lateral Movement (TA0008)

ATT&CK Technique

Remote Services: Remote Desktop Protocol (T1021.001), Remote Services: Windows Remote Management (T1021.006)

Severity

Low

Description

An attacker may remotely enable RDP connections to a machine by setting the fDenyTSConnections Registry key to 0.

Attacker's Goals

Remotely enable RDP on the host for lateral movement.

Investigative actions

  • Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.

  • Search for RDP sessions to this host and investigate them for malicious activities.

Was this helpful?