[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$frAAeoxW4xKquDzM7ql3cdsFTGm8id6CTSHehSV5aTN8":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},591,"How can a penetration tester enumerate RDP connection history for users currently logged into the system using PowerShell?","First, retrieve all user SIDs with `Get-WmiObject -Class Win32_UserAccount`. Then for each SID, query the registry path `Registry::HKEY_USERS\\SID\\Software\\Microsoft\\Terminal Server Client\\Servers`. Use a `foreach` loop with a try-catch block to handle missing keys. The PowerShell script in the article demonstrates this and also displays the account status. This method only works for users who have an active session, similar to accessing [multi-user login](\u002Fnews\u002Fpenetration-techniques-multi-user-login-for-windows-remote-desktop) scenarios where multiple users are logged in simultaneously.","\u003Cp>First, retrieve all user SIDs with `Get-WmiObject -Class Win32_UserAccount`. Then for each SID, query the registry path `Registry::HKEY_USERS\\SID\\Software\\Microsoft\\Terminal Server Client\\Servers`. Use a `foreach` loop with a try-catch block to handle missing keys. The PowerShell script in the article demonstrates this and also displays the account status. This method only works for users who have an active session, similar to accessing [multi-user login](\u002Fnews\u002Fpenetration-techniques-multi-user-login-for-windows-remote-desktop) scenarios where multiple users are logged in simultaneously.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-obtaining-remote-desktop-connection-history-on-windows-systems\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-a-penetration-tester-enumerate-rdp-connection-history-for-users-currentl-1777482763996","logged-in users, PowerShell script, WMI, Win32_UserAccount, HKEY_USERS, RDP history",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},145,"Penetration Techniques - Obtaining Remote Desktop Connection History on Windows Systems","penetration-techniques-obtaining-remote-desktop-connection-history-on-windows-systems","Learn how to export Remote Desktop connection history on Windows systems for penetration testing, including current user, logged-in users, and all users via registry and PowerShell.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, the history of Remote Desktop connections cannot be overlooked. Historical records often help locate critical servers.\u003C\u002Fp>\u003Cp>A few days ago, an article explained how to clear these records. This article will introduce how to export the connection history.\u003C\u002Fp>\u003Cp>The article on clearing records is available at:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwoshub.com\u002Fhow-to-clear-rdp-connections-history\u002F#h2_3\u003C\u002Fp>\u003Cp>The initial idea was to achieve this by enumerating the registry. However, further research revealed that to obtain the history of all users, it is necessary to acquire each user's NTUSER.DAT file, load the configuration unit via the registry, import the user configuration information, and then perform enumeration.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Approach to obtaining historical records\u003C\u002Fli>\u003Cli>Exporting the history of the logged-in user\u003C\u002Fli>\u003Cli>Exporting the history of all users\u003C\u002Fli>\u003Cli>Implementation ideas and script writing details for both methods\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Approach to Obtain Remote Desktop Connection History\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Obtain the current user's history:\u003C\u002Fh3>\u003Cp>Enumerate registry key values at HKCU:\\Software\\Microsoft\\Terminal Server Client\\Servers\u003C\u002Fp>\u003Cp>Each registry entry stores the connected server address, with the key value UsernameHint corresponding to the login username\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017269400_0_b27dece1db.jpeg\">\u003C\u002Fp>\u003Ch3>2. Obtain the history of logged-in users:\u003C\u002Fh3>\u003Cp>The registry information of logged-in users is synchronized under HKEY_USERS\\SID, where SID corresponds to each user's SID\u003C\u002Fp>\u003Cp>Currently, two users are logged into the system, each with two subkeys, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017292966_1_a00d2ebf78.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>HKEY_USERS only contains default user settings and information of logged-in users; user settings are unavailable when the user is not logged in\u003C\u002Fp>\u003Cp>That is, if two users are currently logged in, the registry information of both users will be stored under HKEY_USERS\\SID. If a third user is not logged in, their registry information cannot be directly obtained, and thus the remote desktop connection history of that user cannot be exported\u003C\u002Fp>\u003Cp>Therefore, by enumerating the registry key values at HKEY_USERS\\SID\\Software\\Microsoft\\Terminal Server Client\\Servers, the remote desktop connection history of logged-in users can be obtained\u003C\u002Fp>\u003Ch3>3. Obtain all users' historical records:\u003C\u002Fh3>\u003Cp>For users who are not logged in, registry configuration information cannot be directly obtained. This can be resolved by loading a configuration unit.\u003C\u002Fp>\u003Cp>Select the HKEY_USERS item, go to File -&gt; Load Hive, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017324759_2_aba61d1b8d.jpeg\">\u003C\u002Fp>\u003Cp>Open the user's NTUSER.DAT file, located at C:\\Documents and Settings\\Username\\NTUSER.DAT.\u003C\u002Fp>\u003Cp>Then specify a key name to read the user's registry configuration information under HKEY_USERS, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017374987_3_a7be7e3443.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>To delete this item, it must be cleared by unloading the configuration unit.\u003C\u002Fp>\u003Cp>Therefore, to obtain all users' remote desktop connection history, first enumerate the registry key HKEY_USERS\\SID\\. For users not logged in, load the corresponding NTUSER.DAT file, enumerate again to obtain complete records, and finally unload the corresponding registry key.\u003C\u002Fp>\u003Cp>\u003Cstrong>Supplement:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Example of loading a configuration unit via command line:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Reg load HKEY_USERS\\S-1-5-21-1170783345-3748964848-1387080272-1003 C:\\Documents and Settings\\c\\NTUSER.DAT\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example of unloading a configuration unit via command line:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Reg unload HKEY_USERS\\S-1-5-21-1170783345-3748964848-1387080272-1003\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x03 PowerShell Implementation Details\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Obtain the current user's history\u003C\u002Fh3>\u003Cp>Location: HKEY_CURRENT_USER\\Software\\Microsoft\\Terminal Server Client\\Servers\u003C\u002Fp>\u003Cp>Enumerate subkeys under the specified registry key:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dir \"Registry::HKEY_CURRENT_USER\\Software\\Microsoft\\Terminal Server Client\\Servers\" -Name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Query registry key values for the specified registry key:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>(Get-ItemProperty -Path \"Registry::HKEY_CURRENT_USER\\Software\\Microsoft\\Terminal Server Client\\Servers\\192.168.62.137\").UsernameHint\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Implement enumeration using a foreach loop:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$RegPath = \"Registry::HKEY_CURRENT_USER\\Software\\Microsoft\\Terminal Server Client\\Servers\\\"\u003Cbr>$QueryPath = dir $RegPath -Name\u003Cbr>foreach($Name in $QueryPath)\u003Cbr>{\u003Cbr>    (Get-ItemProperty -Path $RegPath$Name).UsernameHint\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Add exception handling, do not output error messages; if the registry key value cannot be found, return 'Unable to obtain'\u003C\u002Fp>\u003Cp>Complete script:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$RegPath = \"Registry::HKEY_CURRENT_USER\\Software\\Microsoft\\Terminal Server Client\\Servers\\\"\u003Cbr>$QueryPath = dir $RegPath -Name\u003Cbr>foreach($Name in $QueryPath)\u003Cbr>{   \u003Cbr>\tTry  \u003Cbr>\t{  \u003Cbr>\t\t$User = (Get-ItemProperty -Path $RegPath$Name -ErrorAction Stop ).UsernameHint\u003Cbr>    \t\tWrite-Host \"Server:\"$Name\u003Cbr>    \t\tWrite-Host \"User:\"$User\"`n\"\u003Cbr>    \t}\u003Cbr>    \tCatch  \u003Cbr>    \t{\u003Cbr>\t\tWrite-Host \"No RDP Connections History\"\u003Cbr>    \t}\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Obtain the history of logged-in users\u003C\u002Fh3>\u003Cp>Location: HKEY_USERS\\SID\\Software\\Microsoft\\Terminal Server Client\\Servers\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>SID corresponds to the SID of each user\u003C\u002Fp>\u003Cp>First, enumerate all user SIDs\u003C\u002Fp>\u003Cp>PowerShell:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-WmiObject -Class Win32_UserAccount\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>WMI:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_UserAccount GET \u002Fall  \u002FFORMAT:list\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Enumerate usernames and their corresponding SIDs:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$AllUser = Get-WmiObject -Class Win32_UserAccount\u003Cbr>\u003Cbr>foreach($User in $AllUser)\u003Cbr>{\u003Cbr>\tWrite-Host $User.Name\":\"$User.SID\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Combine the above scripts: first enumerate user SIDs, query corresponding registry entries under HKEY_USERS, then enumerate registry key values to obtain complete results:\u003C\u002Fp>\u003Cp>(Administrator privileges required)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$AllUser = Get-WmiObject -Class Win32_UserAccount\u003Cbr>foreach($User in $AllUser)\u003Cbr>{\u003Cbr>\t$RegPath = \"Registry::HKEY_USERS\\\"+$User.SID+\"\\Software\\Microsoft\\Terminal Server Client\\Servers\\\"\u003Cbr>\tWrite-Host \"User:\"$User.Name\u003Cbr>\tWrite-Host \"SID:\"$User.SID\u003Cbr>\tWrite-Host \"Status:\"$User.Status\u003Cbr>\tTry\u003Cbr>    \t{\u003Cbr>\t\t$QueryPath = dir $RegPath -Name -ErrorAction Stop\u003Cbr>\t}\u003Cbr>\tCatch\u003Cbr>\t{\u003Cbr>\t\tWrite-Host \"No RDP Connections History\"\u003Cbr>\t\tWrite-Host \"----------------------------------\"\u003Cbr>\t\tcontinue\u003Cbr>\t}\u003Cbr>\tforeach($Name in $QueryPath)\u003Cbr>\t{   \u003Cbr>\t\tTry  \u003Cbr>    \t\t{  \u003Cbr>    \t\t\t$User = (Get-ItemProperty -Path $RegPath$Name -ErrorAction Stop).UsernameHint\u003Cbr>    \t\t\tWrite-Host \"Server:\"$Name\u003Cbr>    \t\t\tWrite-Host \"User:\"$User\u003Cbr>    \t\t}\u003Cbr>    \t\tCatch  \u003Cbr>    \t\t{\u003Cbr>\t\t\tWrite-Host \"No RDP Connections History\"\u003Cbr>    \t\t}\u003Cbr>\t}\u003Cbr>\tWrite-Host \"----------------------------------\"\t\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>$User.Status indicates the account status, which cannot be directly queried via Get-WmiObject -Class Win32_UserAccount; it can be obtained using the wmi command:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_UserAccount GET \u002Fall  \u002FFORMAT:list\u003C\u002Fp>\u003Ch3>3、Obtain history records for all users\u003C\u002Fh3>\u003Cp>File location for loading the hive:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"C:\\Documents and Settings\\Username\\NTUSER.DAT\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Implementation approach:\u003C\u002Fh4>\u003Col>\u003Cli>Obtain the SID corresponding to each user, concatenate the corresponding registry key value \"Registry::HKEY_USERS\\\"+$User.SID+\"\\Software\\Microsoft\\Terminal Server Client\\Servers\\\"\u003C\u002Fli>\u003Cli>If reading fails, it indicates that this user has not logged in; then attempt to load the hive\u003C\u002Fli>\u003Cli>Concatenate hive file location \"C:\\Documents and Settings\\\"+$User.Name+\"\\NTUSER.DAT\"\u003C\u002Fli>\u003Cli>The registry key corresponding to the hive is named after the user's SID\u003C\u002Fli>\u003Cli>Enumerate the registry to obtain history records\u003C\u002Fli>\u003Cli>Unload registry key\u003C\u002Fli>\u003C\u002Fol>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>A new process needs to be started to unload the hive, otherwise it will prompt failure\u003C\u002Fp>\u003Cp>To avoid using multiple try-catch blocks to catch exceptions, the code structure has been changed to use If-Else for judgment. The complete implementation code can be referenced from:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Test results are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017395896_4_d2ef135ece.jpeg\">\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces how to obtain the Remote Desktop connection history of a Windows system via PowerShell. It should be noted that registry configuration information for users who are not logged in cannot be obtained directly (this can be resolved by loading the hive). Based on the Remote Desktop connection history, critical servers can often be identified.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, the history of Remote Desktop connections cannot be overlooked. Historical records often help locate critical servers.\u003C\u002Fp>\u003Cp>A few days ago, an article explained how to clear these records. This article will introduce how to export the connection history.\u003C\u002Fp>\u003Cp>The article on clearing records is available at:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwoshub.com\u002Fhow-to-clear-rdp-connections-history\u002F#h2_3\u003C\u002Fp>\u003Cp>The initial idea was to achieve this by enumerating the registry. However, further research revealed that to obtain the history of all users, it is necessary to acquire each user's NTUSER.DAT file, load the configuration unit via the registry, import the user configuration information, and then perform enumeration.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Approach to obtaining historical records\u003C\u002Fli>\u003Cli>Exporting the history of the logged-in user\u003C\u002Fli>\u003Cli>Exporting the history of all users\u003C\u002Fli>\u003Cli>Implementation ideas and script writing details for both methods\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Approach to Obtain Remote Desktop Connection History\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Obtain the current user's history:\u003C\u002Fh3>\u003Cp>Enumerate registry key values at HKCU:\\Software\\Microsoft\\Terminal Server Client\\Servers\u003C\u002Fp>\u003Cp>Each registry entry stores the connected server address, with the key value UsernameHint corresponding to the login username\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017269400_0_b27dece1db-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Obtain the history of logged-in users:\u003C\u002Fh3>\u003Cp>The registry information of logged-in users is synchronized under HKEY_USERS\\SID, where SID corresponds to each user's SID\u003C\u002Fp>\u003Cp>Currently, two users are logged into the system, each with two subkeys, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017292966_1_a00d2ebf78-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>HKEY_USERS only contains default user settings and information of logged-in users; user settings are unavailable when the user is not logged in\u003C\u002Fp>\u003Cp>That is, if two users are currently logged in, the registry information of both users will be stored under HKEY_USERS\\SID. If a third user is not logged in, their registry information cannot be directly obtained, and thus the remote desktop connection history of that user cannot be exported\u003C\u002Fp>\u003Cp>Therefore, by enumerating the registry key values at HKEY_USERS\\SID\\Software\\Microsoft\\Terminal Server Client\\Servers, the remote desktop connection history of logged-in users can be obtained\u003C\u002Fp>\u003Ch3>3. Obtain all users' historical records:\u003C\u002Fh3>\u003Cp>For users who are not logged in, registry configuration information cannot be directly obtained. This can be resolved by loading a configuration unit.\u003C\u002Fp>\u003Cp>Select the HKEY_USERS item, go to File -&gt; Load Hive, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017324759_2_aba61d1b8d-1.jpeg\">\u003C\u002Fp>\u003Cp>Open the user's NTUSER.DAT file, located at C:\\Documents and Settings\\Username\\NTUSER.DAT.\u003C\u002Fp>\u003Cp>Then specify a key name to read the user's registry configuration information under HKEY_USERS, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017374987_3_a7be7e3443-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>To delete this item, it must be cleared by unloading the configuration unit.\u003C\u002Fp>\u003Cp>Therefore, to obtain all users' remote desktop connection history, first enumerate the registry key HKEY_USERS\\SID\\. For users not logged in, load the corresponding NTUSER.DAT file, enumerate again to obtain complete records, and finally unload the corresponding registry key.\u003C\u002Fp>\u003Cp>\u003Cstrong>Supplement:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Example of loading a configuration unit via command line:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Reg load HKEY_USERS\\S-1-5-21-1170783345-3748964848-1387080272-1003 C:\\Documents and Settings\\c\\NTUSER.DAT\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example of unloading a configuration unit via command line:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Reg unload HKEY_USERS\\S-1-5-21-1170783345-3748964848-1387080272-1003\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x03 PowerShell Implementation Details\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Obtain the current user's history\u003C\u002Fh3>\u003Cp>Location: HKEY_CURRENT_USER\\Software\\Microsoft\\Terminal Server Client\\Servers\u003C\u002Fp>\u003Cp>Enumerate subkeys under the specified registry key:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dir \"Registry::HKEY_CURRENT_USER\\Software\\Microsoft\\Terminal Server Client\\Servers\" -Name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Query registry key values for the specified registry key:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>(Get-ItemProperty -Path \"Registry::HKEY_CURRENT_USER\\Software\\Microsoft\\Terminal Server Client\\Servers\\192.168.62.137\").UsernameHint\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Implement enumeration using a foreach loop:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$RegPath = \"Registry::HKEY_CURRENT_USER\\Software\\Microsoft\\Terminal Server Client\\Servers\\\"\u003Cbr>$QueryPath = dir $RegPath -Name\u003Cbr>foreach($Name in $QueryPath)\u003Cbr>{\u003Cbr>    (Get-ItemProperty -Path $RegPath$Name).UsernameHint\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Add exception handling, do not output error messages; if the registry key value cannot be found, return 'Unable to obtain'\u003C\u002Fp>\u003Cp>Complete script:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$RegPath = \"Registry::HKEY_CURRENT_USER\\Software\\Microsoft\\Terminal Server Client\\Servers\\\"\u003Cbr>$QueryPath = dir $RegPath -Name\u003Cbr>foreach($Name in $QueryPath)\u003Cbr>{   \u003Cbr>\tTry  \u003Cbr>\t{  \u003Cbr>\t\t$User = (Get-ItemProperty -Path $RegPath$Name -ErrorAction Stop ).UsernameHint\u003Cbr>    \t\tWrite-Host \"Server:\"$Name\u003Cbr>    \t\tWrite-Host \"User:\"$User\"`n\"\u003Cbr>    \t}\u003Cbr>    \tCatch  \u003Cbr>    \t{\u003Cbr>\t\tWrite-Host \"No RDP Connections History\"\u003Cbr>    \t}\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Obtain the history of logged-in users\u003C\u002Fh3>\u003Cp>Location: HKEY_USERS\\SID\\Software\\Microsoft\\Terminal Server Client\\Servers\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>SID corresponds to the SID of each user\u003C\u002Fp>\u003Cp>First, enumerate all user SIDs\u003C\u002Fp>\u003Cp>PowerShell:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-WmiObject -Class Win32_UserAccount\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>WMI:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_UserAccount GET \u002Fall  \u002FFORMAT:list\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Enumerate usernames and their corresponding SIDs:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$AllUser = Get-WmiObject -Class Win32_UserAccount\u003Cbr>\u003Cbr>foreach($User in $AllUser)\u003Cbr>{\u003Cbr>\tWrite-Host $User.Name\":\"$User.SID\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Combine the above scripts: first enumerate user SIDs, query corresponding registry entries under HKEY_USERS, then enumerate registry key values to obtain complete results:\u003C\u002Fp>\u003Cp>(Administrator privileges required)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$AllUser = Get-WmiObject -Class Win32_UserAccount\u003Cbr>foreach($User in $AllUser)\u003Cbr>{\u003Cbr>\t$RegPath = \"Registry::HKEY_USERS\\\"+$User.SID+\"\\Software\\Microsoft\\Terminal Server Client\\Servers\\\"\u003Cbr>\tWrite-Host \"User:\"$User.Name\u003Cbr>\tWrite-Host \"SID:\"$User.SID\u003Cbr>\tWrite-Host \"Status:\"$User.Status\u003Cbr>\tTry\u003Cbr>    \t{\u003Cbr>\t\t$QueryPath = dir $RegPath -Name -ErrorAction Stop\u003Cbr>\t}\u003Cbr>\tCatch\u003Cbr>\t{\u003Cbr>\t\tWrite-Host \"No RDP Connections History\"\u003Cbr>\t\tWrite-Host \"----------------------------------\"\u003Cbr>\t\tcontinue\u003Cbr>\t}\u003Cbr>\tforeach($Name in $QueryPath)\u003Cbr>\t{   \u003Cbr>\t\tTry  \u003Cbr>    \t\t{  \u003Cbr>    \t\t\t$User = (Get-ItemProperty -Path $RegPath$Name -ErrorAction Stop).UsernameHint\u003Cbr>    \t\t\tWrite-Host \"Server:\"$Name\u003Cbr>    \t\t\tWrite-Host \"User:\"$User\u003Cbr>    \t\t}\u003Cbr>    \t\tCatch  \u003Cbr>    \t\t{\u003Cbr>\t\t\tWrite-Host \"No RDP Connections History\"\u003Cbr>    \t\t}\u003Cbr>\t}\u003Cbr>\tWrite-Host \"----------------------------------\"\t\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>$User.Status indicates the account status, which cannot be directly queried via Get-WmiObject -Class Win32_UserAccount; it can be obtained using the wmi command:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_UserAccount GET \u002Fall  \u002FFORMAT:list\u003C\u002Fp>\u003Ch3>3、Obtain history records for all users\u003C\u002Fh3>\u003Cp>File location for loading the hive:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"C:\\Documents and Settings\\Username\\NTUSER.DAT\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Implementation approach:\u003C\u002Fh4>\u003Col>\u003Cli>Obtain the SID corresponding to each user, concatenate the corresponding registry key value \"Registry::HKEY_USERS\\\"+$User.SID+\"\\Software\\Microsoft\\Terminal Server Client\\Servers\\\"\u003C\u002Fli>\u003Cli>If reading fails, it indicates that this user has not logged in; then attempt to load the hive\u003C\u002Fli>\u003Cli>Concatenate hive file location \"C:\\Documents and Settings\\\"+$User.Name+\"\\NTUSER.DAT\"\u003C\u002Fli>\u003Cli>The registry key corresponding to the hive is named after the user's SID\u003C\u002Fli>\u003Cli>Enumerate the registry to obtain history records\u003C\u002Fli>\u003Cli>Unload registry key\u003C\u002Fli>\u003C\u002Fol>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>A new process needs to be started to unload the hive, otherwise it will prompt failure\u003C\u002Fp>\u003Cp>To avoid using multiple try-catch blocks to catch exceptions, the code structure has been changed to use If-Else for judgment. The complete implementation code can be referenced from:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Test results are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017395896_4_d2ef135ece-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces how to obtain the Remote Desktop connection history of a Windows system via PowerShell. It should be noted that registry configuration information for users who are not logged in cannot be obtained directly (this can be resolved by loading the hive). Based on the Remote Desktop connection history, critical servers can often be identified.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",948,"Onedaysec",5,"published","2026-02-02T07:38:21.455Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Export Windows RDP Connection History: Penetration Testing Guide","Windows RDP history, remote desktop connection, penetration testing, registry enumeration, NTUSER.DAT, PowerShell scripts",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46,47],590,589,588,587,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.529Z","2026-07-23T16:01:48.710Z","draft","2026-07-23T16:13:36.673Z"]