Suspicious Remote Desktop Enablement via Registry By Ransomware

PremiumReviewedSigma · Medium · v1
Product
windows
Category
registry_set
Author
HuntRule
Published
2026-10-05
Updated
2026-10-05

ATT&CK techniques

Persistence → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects the registry change that clears fDenyTSConnections to enable inbound RDP on a host. The Qilin ransomware group flips this key to open a Terminal Server access path for lateral movement. Enabling RDP on a workstation that normally has it disabled is a strong pre-encryption footprint.

Related detections9 linkedT1112 — drag to rearrange
Suspicious RDP Enablement via fDenyTSConnections Registry Modification
Suspicious RDP Enablement via fDenyTSConnections Registry Modification [Huntress] #2
Suspicious Enabling of Remote Desktop via fDenyTSConnections Registry by DeadLock Ransomware
Suspicious Remote Desktop Enabled via fDenyTSConnections Registry by Sandworm
Malicious Remote Desktop Enablement via Registry
Enabling RDP service via reg.exe command execution
Suspicious LocalAccountTokenFilterPolicy Enabled via Registry (UAT-7237)
Windows reg.exe Used to Modify RDP Terminal Server Registry Values
Suspicious VBScript Payload Stored in CurrentVersion Registry Value (via registry_set)
Suspicious Remote Desktop Enablement via Registry By Ransomware
Pivot detection · T1112 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.