logo

The remote desktop puzzle. DFIR techniques for dealing with RDP Bitmap Cache

ID: f9585c38-7ca8-5e2f-9a67-144cc27142ff

STIX ID: report--f9585c38-7ca8-5e2f-9a67-144cc27142ff

Feed Name: Pen Test Partners Blog

Threat Score

Date Published: 2025-05-01

Date Updated: 2026-03-24

Author: Joseph Williams

...
...

This report explains how the RDP bitmap cache can be used in DFIR to recover evidence of user activity during remote desktop sessions when logs are missing, detailing cache locations, extraction, and reconstruction with BMC-Tools and RDPCacheStitcher, along with the heuristics that aid tile placement. A case study shows recovery of reconnaissance, credential exposure, and data exfiltration activity despite anti-forensic log wiping, and it highlights recent reporting that attackers can reconstruct RDP session frames to harvest screen-based credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.