Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0212 — Detection Strategy for T1505.005 – Terminal Services DLL Modification (Windows)
DET0212

Detection Strategy for T1505.005 – Terminal Services DLL Modification (Windows)

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0595 Analytic 0595
Windows

Adversary modifies or replaces the Terminal Services DLL (`termsrv.dll`) or changes the associated `ServiceDll` Registry value to load an arbitrary or patched DLL that enables persistent and enhanced RDP access. This may include binary replacement, registry tampering, and unexpected module loads by the `svchost.exe -k termsvcs` process.

WinEventLog:Security EventCode=4657 WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=7 WinEventLog:Sysmon EventCode=1
[TargetDLLPath] Defenders may tune for non-standard DLLs loaded by svchost.exe or termsrv.exe processes.
[RegistryKeyTarget] Environment-specific variations in the path to `ServiceDll` registry key (e.g., nested group policies).
[TimeWindow] Correlation time window for registry change followed by DLL load or svchost restart.
[ParentProcessName] Some environments may spawn registry changes from automation tools or administrative scripts.

Detected Techniques

1

Details

MITRE ID
DET0212
STIX ID
x-mitre-detection-strategy--d9073646-f875-4c38-9b37-e9ac11c40188
Analytics
1
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.