🔍
Windows Forensic Handbook
More
Search
Ctrl + K
Evidence of Network Activity
Last updated
1 year ago
Tracing Registry Keys
EventID 1024: RDP ClientActiveX is trying to connect to the server
EventID 21: Session logon succeeded
EventID 24: Session has been disconnected
EventID 1149: User Authentication Succeeded