persistence-info.github.io

View on GitHub

RDP WDS Startup Programs

Location:

HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms

Classification:

Criteria Value
Permissions Admin
Security context User
Persistence type Registry
Code type EXE
Launch type Any logon required1
Impact Non-destructive
OS Version All OS versions2
Dependencies OS only
Toolset Scriptable

Description:

Not very widely known. Launches applications (server side) after connecting RDP session. You can specify multiple values separate with comas (,) and without spaces.

References:

Credits:

See also:

Remarks:

  1. RDP logon required 

  2. Practically it is more server-related, as workstations with RDP are not so common