Skip to content

Glossary

RDPClient Operational log

The Microsoft-Windows-TerminalServices-RDPClient/Operational event log on the source host; event 1024 records connection attempts with the target name.

Microsoft-Windows-TerminalServices-RDPClient/Operational is the event log of the Remote Desktop client, kept on the machine the connection is made from. Event 1024 records that the client is trying to connect to a server and names the target.

Because the bitmap cache holds no timestamps, this log is one of the main ways to date and attribute it: it gives times and target names for the account that ran the client. It records attempts; confirm logons with the target host's logs. See RDP lateral movement: source host artifacts.