security.evtx:
– Logon specifying alternate credentials
Current logged-on User Name
Microsoft-WindowsTerminalServicesRDPClient%4Operational.evtx
Event ID 1024
- Destination Host Name
Event ID 1102
- Destination IP Address
Remote desktop destinations are tracked per-user
NTUSER\Software
Microsoft\Terminal Server Client\Servers
ShimCache – SYSTEM
mstsc.exe Remote Desktop Client
BAM/DAM – SYSTEM – Last Time Executed
mstsc.exe Remote Desktop Client
AmCache.hve – First Time Executed
UserAssist – NTUSER.DAT
mstsc.exe Remote Desktop Client execution
RecentApps – NTUSER.DAT
mstsc.exe Remote Desktop Client execution
RecentItems subkey tracks connection destinations and times
Jumplists
C:\Users<Username>
AppData\Roaming\Microsoft\Windows
Recent\AutomaticDestinations\
{MSTSC-APPID}- automaticDestinations-ms
Tracks remote desktop connection destination and times
C:\USERS<USERNAME>
AppData\Local\Microsoft\Terminal Server Client\Cache