The remote desktop puzzle. DFIR techniques for dealing with RDP Bitmap Cache
ID: f9585c38-7ca8-5e2f-9a67-144cc27142ff
STIX ID: report--f9585c38-7ca8-5e2f-9a67-144cc27142ff
Feed Name: Pen Test Partners Blog
This report explains how the RDP bitmap cache can be used in DFIR to recover evidence of user activity during remote desktop sessions when logs are missing, detailing cache locations, extraction, and reconstruction with BMC-Tools and RDPCacheStitcher, along with the heuristics that aid tile placement. A case study shows recovery of reconnaissance, credential exposure, and data exfiltration activity despite anti-forensic log wiping, and it highlights recent reporting that attackers can reconstruct RDP session frames to harvest screen-based credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
