1200KM / detection
T1505.005 Terminal Services DLL — Detection Rules
Detection workspace for T1505.005 Terminal Services DLL: 1 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Potential Suspicious Activity Using SeCEdit · test · medium · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0212 Detection Strategy for T1505.005 – Terminal Services DLL Modification (Windows)
AN0595 Analytic 0595
Adversary modifies or replaces the Terminal Services DLL (`termsrv.dll`) or changes the associated `ServiceDll` Registry value to load an arbitrary or patched DLL that enables persistent and enhanced RDP access. This may include binary replacement, registry tampering, and unexpected module loads by the `svchost.exe -k termsvcs` process.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1505.005 simulation workspace
- File Creation · DC0039
- Module Load · DC0016
- Process Creation · DC0032
- Windows Registry Key Modification · DC0063
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.