Source System Artifacts - Quick Reference

security.evtx:

Event ID 4648 – Logon specifying alternate credentials

  • Current logged-on User Name

  • Alternate User Name

  • Destination Host Name/IP

  • Process Name

Microsoft-WindowsTerminalServicesRDPClient%4Operational.evtx Event ID 1024 - Destination Host Name Event ID 1102 - Destination IP Address

Last updated

Was this helpful?