Source System Artifacts - Quick Reference
security.evtx:
Event ID 4648 β Logon specifying alternate credentials
Current logged-on User Name
Alternate User Name
Destination Host Name/IP
Process Name
Microsoft-WindowsTerminalServicesRDPClient%4Operational.evtx Event ID 1024 - Destination Host Name Event ID 1102 - Destination IP Address
Last updated
Was this helpful?