Add RdpClientInfo artifact for RDP session analysis#1166
Add RdpClientInfo artifact for RDP session analysis#1166Guzzy711 wants to merge 2 commits intoVelocidex:masterfrom
Conversation
This artifact extracts client-side characteristics recorded during RDP session connections, including timezone configuration and operating system type information.
|
I have an internal artifact for this but also include the other EIDs and features like time boxing. LMK if you are ok for me to add to this. |
|
@mgreen27 sounds cool! |
|
cool - there is not much to this one, mostly in the analysis. Run once once to collect historical then group by and find outliers. |
|
Hi @mgreen27 - cool artifact. |
|
What is the difference between the two? IMHO It would be better if we consolidated them into one |
|
Its collect once and notebook or collect per usecase. |


This artifact extracts client-side characteristics recorded during RDP session connections, including timezone configuration and operating system type information.