Windows Registry: RDP PortNumber changed from default 3389
Alerts on Windows registry updates to the RDP-Tcp PortNumber when it changes away from default 3389.
FreeUnreviewedSigmahighv1
windows-registry-rdp-portnumber-changed-from-default-3389-509e84b9
title: "Windows Registry: RDP PortNumber changed from default 3389"
id: aa7952b7-76ee-4bc6-8dca-2e2eb23fe454
status: test
description: This rule identifies changes to the RDP server’s configured listening port by monitoring the registry value that sets Terminal Server RDP-Tcp PortNumber. Attackers may modify the default port to make Remote Desktop Services harder to find or to evade basic detections focused on 3389. It relies on Windows registry set telemetry and matches when the port value is changed to a value other than the default 3389 (0x00000d3d).
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1021.001/T1021.001.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_change_rdp_port.yml
author: frack113, Huntrule Team
date: 2022-01-01
modified: 2024-03-25
tags:
- attack.privilege-escalation
- attack.persistence
- attack.t1547.010
logsource:
category: registry_set
product: windows
detection:
selection:
TargetObject|endswith: \Control\Terminal Server\WinStations\RDP-Tcp\PortNumber
filter_main_port:
Details: DWORD (0x00000d3d)
condition: selection and not 1 of filter_main_*
falsepositives:
- Unknown
level: high
regression_tests_path: regression_data/rules/windows/registry/registry_set/registry_set_change_rdp_port/info.yml
simulation:
- type: atomic-red-team
name: Changing RDP Port to Non Standard Port via Powershell
technique: T1021.001
atomic_guid: 2f840dd4-8a2e-4f44-beb3-6b2399ea3771
- type: atomic-red-team
name: Changing RDP Port to Non Standard Port via Command_Prompt
technique: T1021.001
atomic_guid: 74ace21e-a31c-4f7d-b540-53e4eb6d1f73
license: DRL-1.1
related:
- id: 509e84b9-a71a-40e0-834f-05470369bd1e
type: derived
What it detects
This rule identifies changes to the RDP server’s configured listening port by monitoring the registry value that sets Terminal Server RDP-Tcp PortNumber. Attackers may modify the default port to make Remote Desktop Services harder to find or to evade basic detections focused on 3389. It relies on Windows registry set telemetry and matches when the port value is changed to a value other than the default 3389 (0x00000d3d).
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.