Windows RDP Enable/Disable via Win32_TerminalServiceSetting WMI Tool Commands

Flags WMIC/PowerShell command lines that reference Win32_TerminalServiceSetting SetAllowTSConnections to change RDP.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Daniel Koifman (KoifSec), Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2025-11-15
Updated
2026-07-30

ATT&CK techniques

Execution → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies process executions that use WMI-related command lines to change RDP access by referencing the Win32_TerminalServiceSetting class and the SetAllowTSConnections method. Attackers may use this to quickly enable or disable Remote Desktop for remote access using built-in Windows tooling such as WMIC or PowerShell. It relies on process creation telemetry, specifically the executable image names and command-line substrings that match the expected WMI alias/class and property method.

Related detections9 linkedT1047 — drag to rearrange
Suspicious Enabling of Remote Desktop via fDenyTSConnections Registry by DeadLock Ransomware
Malicious UAT-8302 Remote Process Execution via wmic
Malicious Remote Encryptor Execution via WMIC Process Call Create (Chaos Ransomware)
Malicious Impacket Wmiexec Remote Command Execution Pattern
Malicious Shadow Copy Deletion Via WMI
Suspicious Plink SSH Tunnel Execution (via process_creation)
Suspicious Remote Desktop Enabled via fDenyTSConnections Registry by Sandworm
Suspicious Remote Process Creation via WMIC Process Call Create (via process_creation)
Suspicious RDP Shadow Session Started - Native (via rdp)
Windows RDP Enable/Disable via Win32_TerminalServiceSetting WMI Tool Commands
Pivot detection · T1047 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.