Windows Remote Desktop Logon Detection

Remote Desktop account activity events are not easily identifiable using the Event Viewer GUI. When an account remotely connects to a client, a generic successful logon event is created. A custom Query Filter can aid in clarifying the type of logon that was performed. The query below shows logins using Remote Desktop. Remote Desktop activity should be monitored since only certain administrators should be using it, and they should be from a limited set of management workstations. Any Remote Desktop logins outside of expected activity should be investigated.The XPath queries below are used for the Event Viewer’s Custom Views. Event ID 4624 and Event ID 4634 respecively indicate when a user has logged on and logged off with RDP. A LogonType with the value of 10 indicates a Remote Interactive logon.

AIS Managed SIEM

Explore our Solutions

AIS delivers a wide range of technology solutions, managed services, and consulting services that allow businesses to compete in today’s market. Whether deploying AIS solutions or other best-of-breed tools, the experienced, reliable AIS team delivers projects on time while streamlining IT services.
Headphones

AIS Labs

AIS offers a variety of technology solutions leveraging enterprise open-source software, developed and maintained by AIS engineers. These include AIS Managed Firewall, NMS, SIEM, and VoIP.

computer illustration

Managed Services

Partner with our experienced team for peace of mind when it comes to your IT needs. AIS offers proactive, ongoing IT support and maintenance, including regular monitoring, break/fix support, preventive maintenance, software upgrades and more.

Headphones

Consulting

Leverage our team of experts for on-demand consulting and project-based support. AIS can advise on and support all of your urgent and critical IT projects, from upgrades and migrations to departmental IT budgets and information security.

AIS offers top-notch security solutions to keep your business safe from potential breaches. Don't leave your data vulnerable - partner with AIS for peace of mind.

Last modified September 14, 2021