Encapsulated and encrypted within TCP 3389/tcp
program name is mstsc.exe.
Source device artifacts: USN journal, event logs, userassist, jumplists, MFT, prefetch, registry entries, MRU
destination device artifacts: USN journal, event logs, prefetch(tstheme.exe and RDPclip.exe), registry entries
There was an error while loading. Please reload this page.