Skip to content

Collect the two pre-session RDP logs - #86

Merged
spydisec merged 1 commit into
mainfrom
feat/rdp-logs
Sep 24, 2026
Merged

spydisec merged 1 commit into
mainfrom
feat/rdp-logs

Conversation

@spydisec

Copy link
Copy Markdown
Owner

From the review of darkoperator/Windows-Auditing-Guide, which relies on these logs for RDP.

Added (Core, all roles, 1 MB -> 128 MB, kept enabled, may be absent)

  • Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational: 261 (listener received a connection), 1149 (Remote Desktop Services: user authentication succeeded, with user and source address).
  • Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational: 131 (server accepted a new connection from client address), 140 (connection failed because the user name or password is incorrect).

Event IDs and which log each lands in were checked with Get-WinEvent -ListProvider on Windows 11: the darkoperator catalogue files 131/140 under RemoteConnectionManager and describes 140 as a success; both are wrong, and the kit follows the providers. Both logs were confirmed enabled at 1 MB by default.

Kit additions (no Yamato "Y" on the Reference page); role presets select them, ASD stays faithful. Reference, Settings catalog and Group Policy pages regenerated (no CSP / template for either log). ATT&CK coverage unchanged (no analytics name these logs; Core + HighVolume still 283). Disk check on this machine: 25 kit logs, 2.6 GB growth headroom.

Checks: Pester 70/70 on PowerShell 7 and 5.1; PSScriptAnalyzer clean for the kit; mkdocs build --strict passes.

🤖 Generated with Claude Code

Adds Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational
(261, 1149) and Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational
(131, 140) as Core channels, 128 MB, kept enabled. Both are on by default
at 1 MB and wrap within hours on an exposed host. Event IDs and log
locations checked against the providers' own event definitions. Kit
additions (no Yamato Y on the Reference page); role presets select them.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 24, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 41 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: spydisec/WinLogKit/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 40bc517f-f238-49d2-929f-90b6bab2bcf4

📥 Commits

Reviewing files that changed from the base of the PR and between b3c6669 and 842dfa9.

⛔ Files ignored due to path filters (4)
  • presets/ASD.csv is excluded by !**/*.csv
  • presets/DomainController.csv is excluded by !**/*.csv
  • presets/MemberServer.csv is excluded by !**/*.csv
  • presets/Workstation.csv is excluded by !**/*.csv
📒 Files selected for processing (6)
  • CHANGELOG.md
  • WinLogKit.Settings.ps1
  • docs/gpo-paths.md
  • docs/intune-csp.md
  • docs/reference.md
  • tools/Export-ReferenceTable.ps1

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@spydisec
spydisec merged commit ab69fb1 into main Sep 24, 2026
6 checks passed
@spydisec
spydisec deleted the feat/rdp-logs branch September 24, 2026 04:23
@spydisec spydisec mentioned this pull request Sep 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant