1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1505.005 Terminal Services DLL — Detection Rules

Detection workspace for T1505.005 Terminal Services DLL: 1 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

No exact concept selected.

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0212 Detection Strategy for T1505.005 – Terminal Services DLL Modification (Windows)

AN0595 Analytic 0595

Adversary modifies or replaces the Terminal Services DLL (`termsrv.dll`) or changes the associated `ServiceDll` Registry value to load an arbitrary or patched DLL that enables persistent and enhanced RDP access. This may include binary replacement, registry tampering, and unexpected module loads by the `svchost.exe -k termsvcs` process.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1505.005 simulation workspace

No reviewed association in this snapshot.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.