Forensics Artifacts on Remote Desktop Protocol and Service.

Authors

  • Muhammad Shairoze Malik School of Electrical engineering and computer Sciences, National University of Science and Technology, Islamabad

Keywords:

RDP, artifacts, Log analysis, bitmaps, Registry artifacts

Abstract

Remote Desktop Protocol provides users a graphical user interface to access a system remotely, and its implementation is called “remote desktop services”. This is widely used by network administrators and remote workers. Due to vulnerabilities and weak configurations, the protocol is hugely abused by threat actors and hackers to perform malicious acts such as data infiltration, deploying backdoors, malwares and lateral movements. In this article, there will be a discussion on the importance of RDP in digital forensics, understanding RDP-based artifacts, and their use in forensic investigations where RDP is suspected to be involved.

Downloads

Published

2025-12-26

Issue

Section

Articles