πŸ”
Windows Forensic Handbook
search
Ctrlk
  • πŸ‘‹Welcome
  • Artifacts by Type
    • πŸ—„οΈRegistry Artifactschevron-right
    • πŸ“‚Filesystem Artifactschevron-right
    • πŸ“…Event Log Artifactschevron-right
  • Artifacts by Activity
    • πŸƒβ€β™‚οΈExecutionchevron-right
    • πŸ—’οΈFile Activitychevron-right
    • πŸ‘¨β€πŸ”§Account Activitychevron-right
    • 🌎Network Activitychevron-right
      • Evidence of Network Activitychevron-right
        • Tracing Registry Keysarrow-up-right-from-square
        • EventID 1024: RDP ClientActiveX is trying to connect to the serverarrow-up-right-from-square
        • EventID 21: Session logon succeededarrow-up-right-from-square
        • EventID 24: Session has been disconnectedarrow-up-right-from-square
        • EventID 1149: User Authentication Succeededarrow-up-right-from-square
      • Destination Identificationchevron-right
      • Source Identificationchevron-right
      • Transmit Volumechevron-right
      • Firewall Activitychevron-right
      • Wireless Activity
    • πŸ”Browser Activitychevron-right
    • πŸ–₯️System Enumerationchevron-right
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. Artifacts by Activitychevron-right
  2. 🌎Network Activity

Evidence of Network Activity

Tracing Registry Keyschevron-rightEventID 1024: RDP ClientActiveX is trying to connect to the serverchevron-rightEventID 21: Session logon succeededchevron-rightEventID 24: Session has been disconnectedchevron-rightEventID 1149: User Authentication Succeededchevron-right

Last updated 2 years ago