@port139 Blog

基本的にはデジタル・フォレンジックの技術について取り扱っていますが、記載内容には高確率で誤りが含まれる可能性があります。

RDP and UserAssist (Win 10)

Note:I translated Japanese into English using Google Translate.
Thank you, Google.


Summary:

----------

I used two Windows 10 to test RDP. The destination of RDP connection is Windows 10 ver 1809.(192.168.1.16).

In the MSTSC setting, assign F: drive.

f:id:hideakii:20190120100800p:plain

Connect to the remote system with RDP and browse F drive. There is an Autoruns tool on the F drive. Run Autoruns64.exe and Autorunsc64.exe.

f:id:hideakii:20190120102407p:plain

Load NTUSER.DAT into the Registry Explorer. (I'm very happy to be able to load the registry with Live!! :-)

You can check that Run Counter and Last Executed are recorded. 

f:id:hideakii:20190120104658p:plain

I read the article of "No run counts in UserAssist" and tested the execution of Task Scheduler.

f:id:hideakii:20190120110021p:plain

As Matthew Seyer wrote in the article, Run Counter and Last Executed were not recorded.

f:id:hideakii:20190120110220p:plain
Also, we tried executing the GUI program from CMD described on Twitter of Maxim Suhanov. Run Counter and Last Executed were not recorded.

f:id:hideakii:20190120111111p:plain

f:id:hideakii:20190120111517p:plain

 

There was nothing new in my test. ;-)
Thanks to everyone who has published validation results about UserAssist.

  

Verification environment: Windows 10 1809, Time zone UTC

Reference URL:

www.hecfblog.com

www.hecfblog.com

medium.com

 

binaryforay.blogspot.com

 

f:id:hideakii:20190120094750j:plain