Windows reg.exe Used to Modify RDP Terminal Server Registry Values

Flags reg.exe command lines that modify Terminal Server registry values controlling RDP enablement and behavior.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
pH-T (Nextron Systems), @Kostastsale, TheDFIRReport (SigmaHQ), DRL 1.1
Published
2022-02-12
Updated
2026-07-30

ATT&CK techniques

Persistence → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies process execution where reg.exe is used to edit the Terminal Server registry area under CurrentControlSet\Control\Terminal Server, including specific value modifications related to RDP behavior. Such registry tampering can enable, disable, or adjust remote access settings to support persistence and lateral movement or to impair defenses. It relies on Windows process creation telemetry, specifically the executable identity (reg.exe) and the command-line strings indicating which RDP-related values are being changed, with an exclusion to reduce matches involving a specific TLS-related SecurityLayer value.

Reporting behind it

Related detections9 linkedT1112 — drag to rearrange
Suspicious Enabling of Remote Desktop via fDenyTSConnections Registry by DeadLock Ransomware
Suspicious Remote Desktop Enabled via fDenyTSConnections Registry by Sandworm
Malicious Remote Desktop Enablement via Registry
Enabling RDP service via reg.exe command execution
Suspicious LocalAccountTokenFilterPolicy Enabled via Registry (UAT-7237)
Malicious Enabling of Restricted Admin Mode via Registry by UAT-8837
Malicious Service DLL Hijack for Persistence via Lotus Blossom
Suspicious Loopback Proxy Server Configured via Registry (via registry_set)
Malicious WDigest Credential Caching Enabled via Registry (via registry_set)
Windows reg.exe Used to Modify RDP Terminal Server Registry Values
Pivot detection · T1112 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.