{"id":"T1505.005","name":"Terminal Services DLL","url":"https://attack.mitre.org/techniques/T1505/005","tactics":["persistence"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0212","stix_id":"x-mitre-detection-strategy--d9073646-f875-4c38-9b37-e9ac11c40188","name":"Detection Strategy for T1505.005 – Terminal Services DLL Modification (Windows)","url":"https://attack.mitre.org/detectionstrategies/DET0212","analytics":[{"id":"AN0595","stix_id":"x-mitre-analytic--01f18cc1-2948-4ea7-adaf-017da939b9ff","name":"Analytic 0595","description":"Adversary modifies or replaces the Terminal Services DLL (`termsrv.dll`) or changes the associated `ServiceDll` Registry value to load an arbitrary or patched DLL that enables persistent and enhanced RDP access. This may include binary replacement, registry tampering, and unexpected module loads by the `svchost.exe -k termsvcs` process.","url":"https://attack.mitre.org/detectionstrategies/DET0212#AN0595","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4657","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TargetDLLPath","description":"Defenders may tune for non-standard DLLs loaded by svchost.exe or termsrv.exe processes."},{"field":"RegistryKeyTarget","description":"Environment-specific variations in the path to `ServiceDll` registry key (e.g., nested group policies)."},{"field":"TimeWindow","description":"Correlation time window for registry change followed by DLL load or svchost restart."},{"field":"ParentProcessName","description":"Some environments may spawn registry changes from automation tools or administrative scripts."}],"live":true,"detection_strategies":["DET0212"],"techniques":["T1505.005"]}],"live":true,"version":"1.0","techniques":["T1505.005"]}],"sigma_rules":[{"id":"c2c76b77-32be-4d1f-82c9-7e544bdfe0eb","title":"Potential Suspicious Activity Using SeCEdit","author":"Janantha Marasinghe","status":"test","level":"medium","date":"2022-11-18","modified":"2022-12-30","description":"Detects potential suspicious behaviour using secedit.exe. Such as exporting or modifying the security policy","references":["https://blueteamops.medium.com/secedit-and-i-know-it-595056dee53d","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/secedit"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.discovery","attack.persistence","attack.credential-access","attack.privilege-escalation","attack.execution","attack.stealth","attack.defense-impairment","attack.t1685.001","attack.t1547.001","attack.t1505.005","attack.t1556.002","attack.t1685","attack.t1574.007","attack.t1564.002","attack.t1546.008","attack.t1546.007","attack.t1547.014","attack.t1547.010","attack.t1547.002","attack.t1557","attack.t1082"],"path":"rules/windows/process_creation/proc_creation_win_secedit_execution.yml","techniques":["T1685.001","T1547.001","T1505.005","T1556.002","T1685","T1574.007","T1564.002","T1546.008","T1546.007","T1547.014","T1547.010","T1547.002","T1557","T1082"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}