SKIP TO CONTENT
ACCOUNTS AND AUTHENTICATION29 / 36

Remote Desktop Artifacts

Also called RDP forensics, TerminalServices logs, Event ID 1149, Event ID 21, RDP bitmap cache.

PLATFORM
Windows
CATEGORY
Accounts and Authentication
INDEX
29 of 36
PROVES
4 findings
CANNOT PROVE
5 limits
QUESTIONS
3 answered
WHAT IT IS

Server- and client-side records of remote desktop sessions: who connected, from what address, when the session started and ended, and which servers a machine connected out to.

Where it lives

Microsoft-Windows-TerminalServices-LocalSessionManager/Operational and ...-RemoteConnectionManager/Operational; client side, %LocalAppData%\Microsoft\Terminal Server Client\Cache and the Servers key under NTUSER.DAT\Software\Microsoft\Terminal Server Client

Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of remote desktop artifacts” is neither.

What it records

On the receiving machine, the remote connection manager records authentication succeeding for a named user from a source address, and the local session manager records session logon, disconnection, reconnection and logoff with session identifiers. On the connecting machine, a registry key lists servers connected to and the usernames used, and a bitmap cache stores fragments of the remote screen for reuse. The Security log's remote-interactive logon events sit alongside these and are usually read together with them.

What it proves — and what it cannot

These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.

What it proves

FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.

  • That a named account connected to a machine over remote desktop, from a recorded source address, at a recorded time
  • Session lifecycle — connect, disconnect, reconnect, logoff — which distinguishes a brief connection from hours of use
  • From the client side, which servers a machine reached out to and under what usernames
  • Fragments of what was displayed during a session, from the bitmap cache, where those tiles survive

What it cannot prove

INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.

  • That authentication succeeding means a session was established. The remote connection manager records a connection attempt whose user authenticated; the session can still fail afterwards, and treating that event alone as proof of a session is a common error
  • That the source address identifies a device or a person. Remote access is normally mediated by VPN concentrators, jump hosts and network address translation, so the address frequently names infrastructure shared by everyone
  • When any image in the bitmap cache was displayed. Cache tiles are fragments stored for reuse, unordered and undated, and a reconstructed image carries no timestamp
  • What was done inside the session. Activity inside a remote session leaves its evidence on the remote machine, in that session's own artifacts, not in the connection records
  • That an absent record means no session. These channels roll like any other, and the client-side registry key holds only a most-recently-used list

How the finding is attacked

An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.

  • Separating an authentication event from an established session where the examiner has treated them as the same finding
  • Showing the source address is a shared egress point, breaking the attempt to place a specific person at a specific location
  • Attacking a bitmap cache reconstruction as an undated composite assembled by the examiner rather than an image the system ever displayed as such
  • Establishing that credentials were shared or that a jump host was used by several administrators

What survives, and for how long

The operational channels roll on size like any event log, typically covering weeks on a workstation and less on a heavily used server. The client-side server list persists in the user hive indefinitely but records only recent entries; bitmap cache files persist until overwritten and are trivially deleted.

More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.

Questions counsel ask

Does Event ID 1149 prove someone logged in over RDP?

No, and this is the most common misreading of RDP evidence. That event records that a connecting user authenticated to the remote connection manager. The session can still fail after that point, and no logon may follow. Proof of an established session comes from the local session manager's session-logon events and from the Security log's remote-interactive logon record, read together.

Can RDP logs show where a remote connection came from?

They record a source address, which is not the same as a location or a device. Remote access is normally mediated by VPN concentrators, jump hosts and network address translation, so the recorded address frequently belongs to shared infrastructure that many people sit behind. It narrows the origin to a network path; identifying the machine or person at the other end takes records from that infrastructure.

What is the RDP bitmap cache worth as evidence?

It can show fragments of what was displayed during a remote session, which is occasionally decisive where nothing else survives. The limits are real: tiles are stored for reuse, are unordered and undated, and any picture assembled from them is a reconstruction by the examiner rather than a screen the system ever presented that way. It should be offered with that stated.

Terms used on this page

Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.

No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.

A FINDING ON THIS ARTIFACT

Whether the remote desktop artifactsevidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.

A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.

WEEKLY BRIEFING

Digital evidence, explained for litigators.

One email a week on forensic method, digital evidence, and expert testimony — written for counsel, not for technicians. No pitches.

DOUBLE OPT-IN · UNSUBSCRIBE ANY TIME · PRIVACY POLICY

  • Can This Artifact Prove That?

    Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.

  • Computer forensics

    The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.

  • The artifact index

    All 36 entries, grouped by what they bear on and filterable by platform.

  • Daubert and digital evidence

    Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.

← BACK TO THE ARTIFACT INDEX

Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.