RDP
Remote Desktop Protocol
PS > Get-ADComputer -LDAPFilter "(&(objectClass=computer)(memberOf=CN=Terminal Server License Servers,CN=Builtin,$((Get-ADRootDSE).rootDomainNamingContext)))" | select dNSHostNameTerminal Services API
qwinsta
Enable RDP
meterpreter > run getgui -eCmd > reg add "HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0 /fRestricted Admin
Remote Credential Guard
Smart Card Authentication
Emulating PIV
NLA
Hijack RDP Sessions
Tools
Wipe Connection Artifacts
Tools
SharpRDP
SharpRDPHijack
TakeMyRDP
Last updated