Jan. 31, 2024, 3:10 p.m. | /u/DeadBirdRugby

Computer Forensics www.reddit.com

Good morning DFIR community,

I was wondering if I could pick your brain on something:

I've got a case where there is suspected RDP access between two devices. On the triage image for the destination device we see EventID 1149 as well as Event ID 21 and 22, but no 4624. I was wondering if anyone had any insight as to why we might see Event IDs for the Network Connection (1149) as well as the Logon (21 and 22), …

access brain case community computerforensics device devices dfir event good image question rdp rdp access triage yes

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC