> For the complete documentation index, see [llms.txt](https://windows.dfirhandbook.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://windows.dfirhandbook.com/windows-artifacts/account-usage/rdp.md).

# RDP

### Key Points

1. **Remote Desktop Protocol (RDP) Artifacts**: RDP is a proprietary protocol developed by Microsoft which allows a user to connect to another computer over a network connection. Key artifacts include event logs, registry entries, and file system traces.
2. **RDP-Related Processes**:
   * **Source Host**: The process `mstsc.exe` is launched when initiating an RDP connection.
   * **Destination Host**: Processes like `svchost.exe` and `termsrv.dll` are involved in handling incoming RDP connections.
3. **Important Registry Key**:
   * On the Source Host, the key `NTUSER\Software\Microsoft\Terminal Server Client\Servers` records recent RDP connections.
4. **Event Log Analysis**:
   * Essential for tracking RDP sessions, with specific Event IDs (4624, 4778, 4779) providing detailed information about RDP activities.

### Considerations

* **Security Implications**: Unauthorized RDP access is a common method for lateral movement in cyber attacks.
* **Log Centralization**: Centralizing logs aids in quickly identifying malicious patterns across all endpoints.
* **Tool Usage**: Attackers often use the same tools as network administrators for lateral movement.

### Technical Explanations

### **Event Log Tracking**

* **Event IDs**:
  * **4624**: Logs RDP logons (Logon Type 10 – Remote Interactive).
  * **4778**: Tracks RDP session reconnections.
  * **4779**: Records session disconnections.
* **Locations**:
  * Security Event Logs: `%SYSTEMROOT%\System32\winevt\logs\Security.evtx`.
  * RDP-specific Logs:
    * `Microsoft-Windows-RemoteDesktopServices-RDPCoreTS/Operational`
    * `Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational`
    * `Microsoft-Windows-TerminalServices-LocalSessionManager/Operational`

### **Source Host Artifacts**

* **Registry Entries**:
  * Recent Connections: `NTUSER\Software\Microsoft\Terminal Server Client\Servers`.
  * RegRipper Plugin: `rdphint` for parsing RDP registry keys.
* **File System Traces**:
  * Default RDP Connection File: `Default.rdp` in the user profile.
  * RDP Bitmap Cache Files: Fragments can be reassembled using `bmc-tools.py`.
  * Jump List Data: Traces from `mstsc.exe`.

{% tabs %}
{% tab title="Event Log" %}
**security.evtx:**

[Event ID 4648](https://system32.eventsentry.com/security/event/4648) – Logon specifying alternate credentials&#x20;

* Current logged-on User Name
* Alternate User Name&#x20;
* Destination Host Name/IP&#x20;
* Process Name

**Microsoft-WindowsTerminalServicesRDPClient%4Operational.evtx**\
[Event ID 1024 ](https://salt4n6.com/2019/09/22/event-id-1024/)\
&#x20;    \- Destination Host Name \
Event ID 1102 \
&#x20;    \- Destination IP Address
{% endtab %}

{% tab title="Registry" %}

* Remote desktop destinations are tracked per-user
  * <mark style="color:purple;">`NTUSER\Software`</mark>\ <mark style="color:purple;">`Microsoft\Terminal Server Client\Servers`</mark>
* [ShimCache](broken://spaces/LHltGerC23QVyjq1LSxc/pages/ihpcmfjBmYkTGpgSNWk5) – SYSTEM
  * mstsc.exe Remote Desktop Client
* [BAM/DAM](broken://spaces/LHltGerC23QVyjq1LSxc/pages/izxtnm4GeGsoJOftuxvi) – SYSTEM – Last Time Executed
  * mstsc.exe Remote Desktop Client
* [AmCache.hve](broken://spaces/LHltGerC23QVyjq1LSxc/pages/BicH3sBBfCQNkjhCDL2w) – First Time Executed
  * mstsc.exe
* [UserAssist](broken://spaces/LHltGerC23QVyjq1LSxc/pages/BGfQvBR8PSlmeRDHGLjb) – NTUSER.DAT
  * mstsc.exe Remote Desktop Client execution&#x20;
  * Last Time Executed&#x20;
  * Number of Times Executed
* RecentApps – NTUSER.DAT
  * mstsc.exe Remote Desktop Client execution&#x20;
  * Last Time Executed&#x20;
  * Number of Times Executed&#x20;
  * RecentItems subkey tracks connection destinations and times
    {% endtab %}

{% tab title="File System" %}

* [Jumplists ](broken://spaces/LHltGerC23QVyjq1LSxc/pages/oNWH7ISNNtZHVOEEcQgG)– <mark style="color:orange;">C:\Users\<Username></mark>\ <mark style="color:orange;">AppData\Roaming\Microsoft\Windows</mark>\ <mark style="color:orange;">Recent\AutomaticDestinations\\</mark>
  * {MSTSC-APPID}- automaticDestinations-ms
  * Tracks remote desktop connection destination and times
* [Prefetch ](broken://spaces/LHltGerC23QVyjq1LSxc/pages/mngP23Kjwo0DI64Sadh3)– C:\Windows\Prefetch
  * mstsc.exe-{hash}.pf
* Bitmap Cache – <mark style="color:orange;">C:\USERS\<USERNAME></mark>\ <mark style="color:orange;">AppData\Local\Microsoft\Terminal Server Client\Cache</mark>
  * bcache##.bmc&#x20;
  * cache####.bin
    {% endtab %}
    {% endtabs %}

### **Destination Host Artifacts**

* **Event Log IDs**: 4624 (Type 10), 4778, 4779.
* **Specialized Logs**:
  * `Microsoft-Windows-TerminalServices-RDPClient/Operational` for tracking attacker movement from the source system.

### **Alternate Remote Access Tools**

* **VNC**:
  * Event Log ID 4624 (Type 2 – Console logon).
  * Application-specific logs and registry entries.
* **TeamViewer**:
  * Source System: `TeamViewerX_Logfile.log` in `C:\Program Files\TeamViewer\VersionX`.
  * Target System: `Connections_incoming.txt`.

### **Security Settings**

* **Active Directory Settings**: “Deny log on through Remote Desktop Services” for sensitive accounts.
* **Host Level Settings**: Disabling RDP service, configuring Windows Firewall to deny inbound RDP connections.

### Example Logs

* **Event ID 4624**:

  ```yaml
  Log Name: Security
  Event ID: 4624
  Logon Type: 10
  Account Name: [Username]
  Source Network Address: [IP Address]
  ```
* **Event ID 4778**:

  ```yaml
  Log Name: Security
  Event ID: 4778
  Account Name: [Username]
  Session Reconnected to: [Target Machine Name]
  ```
* **Event ID 4779**:

  ```yaml
  Log Name: Security
  Event ID: 4779
  Account Name: [Username]
  Session Disconnected from: [Target Machine Name]
  ```

### Example Command Lines

* **Starting RDP Session**:

  ```bash
  mstsc.exe /v:[TargetHost]
  ```
* **Using VNC**:

  ```bash
  vncviewer.exe [TargetHost]
  ```
* **Launching TeamViewer**:

  ```bash
  TeamViewer.exe
  ```
