這次來看一下一台Windows主機被另一台主機用遠端桌面會有什麼紀錄
首先確認使否啟用中Audit Police
本地設定 gpedit.msc
AD網域設定 Group policy management > 選擇要調整的Group
MSTSC
PS C:\Windows\system32> Get-WinEvent -FilterXml '
>> <QueryList>
>>     <Query Id="0" Path="Security">
>>         <Select Path="Security">
>>             *[System[(
>>                 EventID=4624
>>             ) and
>>             (TimeCreated[timediff(@SystemTime) <= 3600000])]]
>>         </Select>
>>     </Query>
>> </QueryList>
>> ' |
>> Select-Object Id, TimeCreated,
>> @{Name="LogonType"; Expression={$_.Properties[8].Value}},
>> @{Name="AdditionalInfo"; Expression={$_.Properties[10].Value}}
  Id TimeCreated          LogonType AdditionalInfo
  -- -----------          --------- --------------
4624 9/20/2024 8:54:56 PM        10 Negotiate
4624 9/20/2024 8:54:56 PM        10 Negotiate
4624 9/20/2024 8:54:53 PM         5 Negotiate
4624 9/20/2024 8:54:52 PM         2 Negotiate
4624 9/20/2024 8:54:52 PM         2 Negotiate
4624 9/20/2024 8:54:52 PM         2 Negotiate
4624 9/20/2024 8:54:52 PM         3 NTLM
從紀錄來看,時間抓8:54分前後可觀察整個行為
分析一下,從第一個4624 Logon Type: 3已經完成網路驗證,接著Type2 為一些驅動 User-Mode Driver Framework (UMDF) ,Type2 系統服務,最後 Type 10 遠端桌面
前一個連線中斷後,再重新遠端連線登入,重新調整搜尋語法,將261,4776,4672,1149也加入
Get-WinEvent -FilterXml '
<QueryList>
  <Query Id="0" Path="Security">
    <Select Path="Security">*[System[(EventID=4624) and TimeCreated[timediff(@SystemTime) <= 3600000]]]</Select>
    <Select Path="Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational">*[System[(EventID=261 or EventID=1149) and TimeCreated[timediff(@SystemTime) <= 3600000]]]</Select>
  </Query>
</QueryList>
' |
Select-Object Id, TimeCreated, 
@{Name="LogonType"; Expression={$_.Properties[8].Value}}, 
@{Name="AdditionalInfo"; Expression={$_.Properties[10].Value}}
輸出
  Id TimeCreated          LogonType AdditionalInfo
  -- -----------          --------- --------------
4624 9/21/2024 7:21:42 AM 7         Negotiate     
4624 9/21/2024 7:21:42 AM 7         Negotiate     
4776 9/21/2024 7:21:42 AM                         
4672 9/21/2024 7:21:41 AM                         
4624 9/21/2024 7:21:41 AM 5         Negotiate     
1149 9/21/2024 7:21:40 AM                         
4624 9/21/2024 7:21:40 AM 3         NTLM          
4672 9/21/2024 7:21:40 AM                         
4672 9/21/2024 7:21:40 AM                         
4776 9/21/2024 7:21:40 AM                         
 261 9/21/2024 7:21:40 AM                         
分析4624之間的差別,從Type 10 變成7,7的說明是Unlock-This workstation was unlocked.,猜測是遠端桌面的服務還在,本次NTLM驗證完做解鎖畫面動作。
https://jpcertcc.github.io/ToolAnalysisResultSheet/details/mstsc.htm