AN0595
Analytic 0595
Windows
Adversary modifies or replaces the Terminal Services DLL (`termsrv.dll`) or changes the associated `ServiceDll` Registry value to load an arbitrary or patched DLL that enables persistent and enhanced RDP access. This may include binary replacement, registry tampering, and unexpected module loads by the `svchost.exe -k termsvcs` process.
WinEventLog:Security
EventCode=4657
WinEventLog:Sysmon
EventCode=11
WinEventLog:Sysmon
EventCode=7
WinEventLog:Sysmon
EventCode=1
[TargetDLLPath]
Defenders may tune for non-standard DLLs loaded by svchost.exe or termsrv.exe processes.
[RegistryKeyTarget]
Environment-specific variations in the path to `ServiceDll` registry key (e.g., nested group policies).
[TimeWindow]
Correlation time window for registry change followed by DLL load or svchost restart.
[ParentProcessName]
Some environments may spawn registry changes from automation tools or administrative scripts.