RDP
Event Logs:


Disconnect/Reconnect: 4778/4779


Forensics:
Souce and Destination artifacts:


Bitmap Cache



RDP Clipbaord Forensics
RDP Lateral Movement
Dump Passwords in Terminal Services:
Detection:
Dump saved credentials via DPAPI:
Detection:
Tscon to hijack open RDP connections:
Detection:
Rogue RDP:
RDP Files:
RDP Keyboard Layout:
Anti-Forensics:
Last updated

