persistence-info.github.io

View on GitHub

TS Initial Program

Location:

Classification:

Criteria Value
Permissions Admin; User1
Security context User
Persistence type Registry
Code type EXE
Launch type User initiated2
Impact Non-destructive
OS Version All OS versions
Dependencies OS only
Toolset Scriptable

Description:

If the fInheritInitialProgram value is set to 1, the exe indicated in the InitialProgram value is automatically started on RDP connection.

References:

https://twitter.com/JacqBens/status/1560380971777662983

Credits:

@JacqBens

See also:

Remarks:

  1. For HKCU 

  2. Terminal Services connection must be established