RDP Event Log Forensics
RDP Event Log Forensics
Event ID 4624
Event ID 1149 Type 10, 7 for Reconnect Event ID 21 Event ID 22
}
Network Connection Authentication Logon
youtube.com/13cubed
Source: https://ponderthebits.com/2018/02/windows-rdp-related-event-logs-identification-tracking-and-investigation
RDP Unsuccessful Logon
Event ID 4625
Event ID 1149 Type 10, 7 for Reconnect
}
Network Connection Authentication
youtube.com/13cubed
Source: https://ponderthebits.com/2018/02/windows-rdp-related-event-logs-identification-tracking-and-investigation
RDP Session Disconnect
(Window Close)
“Remote Desktop Services: “Session <X> has been disconnected, “A session was disconnected “An account was logged off”
Session has been disconnected:” reason code <Z>” from a Window Station”
youtube.com/13cubed
Source: https://ponderthebits.com/2018/02/windows-rdp-related-event-logs-identification-tracking-and-investigation
RDP Session Disconnect
(Purposeful Disconnect via Start > Disconnect)
“Remote Desktop Services: “Session <X> has been disconnected “Session <X> has been disconnected, “A session was disconnected “An account was
Session has been disconnected:” by session <Y>” reason code <Z>” from a Window Station” logged off”
}
Session Disconnect / Reconnect
youtube.com/13cubed
Source: https://ponderthebits.com/2018/02/windows-rdp-related-event-logs-identification-tracking-and-investigation
RDP Session Reconnect
Event ID 4624
Event ID 1149 Event ID 25 Event ID 40* Event ID 4778
Type 7
“User authentication succeeded” “Remote Desktop Services: “Session <X> has been disconnected, “A session was reconnected
“An account was successfully logged on” Session reconnection succeeded:” to a Window Station”
reason code <Z>”
Microsoft-Windows-TerminalServices- Security.evtx
RemoteConnectionManager%4Operational.evtx Microsoft-Windows-TerminalServices- Microsoft-Windows-TerminalServices- Security.evtx
LocalSessionManager%4Operational.evtx LocalSessionManager%4Operational.evtx
}
Network Connection Authentication Session Disconnect / Reconnect
youtube.com/13cubed
Source: https://ponderthebits.com/2018/02/windows-rdp-related-event-logs-identification-tracking-and-investigation
RDP Session Logoff
Event ID 4634
Event ID 23 Type 10, 7 for Reconnect Event ID 4647 Event ID 9009
“Remote Desktop Services: “An account was logged off” “The Desktop Window Manager has
Session logoff succeeded:” “User initiated logoff:” exited with code (<X>).”
Security.evtx Security.evtx System.evtx
Microsoft-Windows-TerminalServices-
LocalSessionManager%4Operational.evtx
}
Logoff
youtube.com/13cubed
Source: https://ponderthebits.com/2018/02/windows-rdp-related-event-logs-identification-tracking-and-investigation