Potential Tampering With RDP Related Registry Keys Via Reg.EXE — Detection Rule

Detects the execution of "reg.exe" for enabling/disabling the RDP service on the host by tampering with the 'CurrentControlSet\Control\Terminal Server' values

Read the full analysis on IntelFusions