Destination System Artifacts - Quick Reference
Last updated
Was this helpful?
Last updated
Was this helpful?
Security Event Log – security.evtx
Logon Type 10
Source IP/Logon User Name
/
IP Address of Source/Source System Name
Logon User Name
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS%4Operational.evtx
131 – Connection Attempts
Source IP
98 – Successful Connections
Microsoft-Windows-Terminal Services-RemoteConnection Manager%4Operational.evtx
1149
Source IP/Logon User Name
Blank user name may indicate use of Sticky Keys
Microsoft-Windows-Terminal Services-LocalSession Manager%4Operational.evtx
21, 22, 25
Source IP/Logon User Name
41
Logon User Name
– C:\Windows\Prefetch