AuthenticationwindowsPro

RDP session logs

Remote Desktop writes to several channels, and no single one tells the whole story. Reading only the Security log is why "we saw no RDP" is said about hosts that were reached over RDP.

What members see here

  • Every path this artifact lives at, and which builds each applies to.
  • What it proves, and what it does not prove, which is the part that matters.
  • How to parse it, and the tooling that reads it correctly.
  • Hunting queries for Splunk, Sentinel and Elastic, with their false-positive notes.