What is the “RDP Client” Windows forensic artifact?
When a user initiates an outbound Remote Desktop connection, Windows quietly records the client-side details inside that user’s registry hive (NTUSER.DAT). This artifact captures the servers and hosts the user connected to, the usernames they authenticated with, and the configuration of each session — display settings, resource redirection, and connection preferences. Unlike server-side logs, which record who knocked on a machine’s door, the RDP Client artifact is the diary of where a specific user went, written on the device they actually sat at.
For a DFIR investigator, this distinction is decisive. Server-side event logs are scattered across every host a subject touched — but the client-side history lives in one place and persists even when the destination machines are unavailable, wiped, or outside the organization’s control. Correlating RDP Client entries with logon events, process execution, and file activity allows analysts to reconstruct remote access behavior with precision: which internal systems a user pivoted to, when, and with what credentials.
Enterprise Forensic Applications
RDP Client analysis is central to reconstructing lateral movement and unauthorized remote access. During Proactive Compromise Assessments, TensorGuard parses client-side RDP history across the fleet to surface workstations that initiated connections to sensitive or unmanaged systems — a hallmark of an intruder moving between machines with stolen credentials, or of an employee reaching systems outside their role. In insider investigations, these records quietly answer the question every other tool struggles with: not just what happened on this device, but where else its user has been.
Collecting, Decoding, and Viewing “RDP Client” with TensorGuard
- Create a TensorGuard account and sign in to the TensorGuard console at https://app.tensorguard.com.
- Select “Case Manager”, then the plus button to create a case. This will contain your enrolled devices, their reports, and any manually submitted collections.
- Linked inside the case menu, download the TensorGuard Forensic Collector and run it on your target system.
- In the console, click the plus button for “New Enrollment”, copy the enrollment key, and paste it into the TensorGuard Forensic Collector on your target device.
- Now that you have a device enrolled, select the device(s), and click “Send Signal”. Answer the questions regarding what you want to look for in the analysis, any alerting on positive findings, and if the collection and analysis should be recurring.
- Once the report is generated, you’ll have RDP Client delivered in the browser, alongside an executive summary and timeline of findings.
Get Started
TensorGuard™ is a trademark of TensorGuard Inc. All other trademarks are the property of their respective owners. The information provided on this website is for educational and informational purposes only and does not constitute legal, forensic, or professional advice. Due to the complexities of Digital Forensics and potential legal implications, you should always consult with qualified legal counsel or a certified digital forensics expert before taking action based on findings.
RDP Client
Windows
The client-side diary of every Remote Desktop session a user has initiated — servers, usernames, and settings, recorded in the user’s own registry hive.
Start with a Compromise Assessment.
One flat fee, fully credited toward a subscription. We conduct a complete, AI-driven Compromise Assessment across your critical systems — with evidence-linked findings your team can validate in minutes.

