EventID 1149: User Authentication Succeeded

This event, logged to the Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational channel, is logged when an RDP connection is established.

triangle-exclamation
circle-info

This event is logged on the destination endpoint.

Analysis Value

Usernamechevron-rightEvidence of Network Activitychevron-rightSource Identificationchevron-right

Operating System Availability

Major Version
Support
Major Version
Support

Windows 11

βœ…

Server 2019

βœ…

Windows 10

βœ…

Server 2016

βœ…

Windows 8

βœ…

Server 2012

βœ…

Windows 7

βœ…

Server 2008

βœ…

Windows Vista

βœ…

Server 2003

❌

Windows XP

❌

Artifact Location(s)

  • %SystemRoot%\System32\Winevt\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx

Artifact Interpretation

Field
Interpretation
Reference

UserData/EventXML/Param1

This field logs only the username and domain for the RDP session.

UserData/EventXML/Param3

This field provides the source IP address of an RDP session.

System/Correlation ActivityID

Provides the ActivityID for the RDP session.

Analysis Tips

circle-info

Correlation by ActivityID

This event logs an ActivityID, available in the XML path System/Correlation ActivityID. This may be used to correlate activity between other events logged that are related to this activity, such as:

EventID 21: Session logon succeeded

EventID 24: Session has been disconnected

circle-exclamation

Example

This example was produced on Windows 10, Version 10.0.19044 Build 19044

Last updated