Processed through Paypal
No account required.


Donate Bitcoin to this wallet:
1KkUMXvQ2ko3xcJkzitB7WYgoW6m79WFfm
Donate Ethereum to this wallet:
0x40E56922F43637224935CDC35e2c96E0392A8505
Donate Litecoin to this wallet:
LLYAFEyqjH69gkyCEpRjXNyedRCWrVChfL

  Buy our over-priced crap here to support this project.  


Facebook Follow @GeekOnTheLoose




 Home » OlderGeeks.com Freeware Downloads » Surveillance, Forensics and Sneaky Stuff » RDP-Parser v1.1   
File - Download RDP-Parser v1.1
Description

Always scroll to the bottom of the page to download files on OlderGeeks.com.
We don't believe in fake/misleading download buttons and tricks.


RDP-Parser v1.1

RDP-Parser extracts RDP activities from Microsoft Windows Event Logs. This tool has been designed for any investigation involving exploitation of RDP service. It supports Evt and Evtx formats.

How it works

This is a command line tool and there is no installer. You should unzip and copy the program where you want to use it.

Open a command line in the directory where the program is. You can print help message using "RDP-Parser --h":






More details about options:

--p: By default, RDP-Parser will check in the current directory, so you can copy the program in the same folder as the Event Logs you want to parse. If there is no given path and current directory doesn't contain Event Logs, RDP-Parser will copy the live system Event Logs in the current directory. This command require admin priviledge and it doesn't work for old format logs.
--t: There are three types of report:
1: minimal: This is the default type. The report will contain following columns: TimeGenerated, Source, EventID and Details. Only events with public IP addresses will be extracted and all details will be removed except IP address.
2: minimal with all IP addresses: Same as type 1, but it also includes private IP addresses.






3: normal: The report will contain all columns and all details. Columns are: TimeGenerated, Timewritten, Computer, Source, RecordNumber, Category, EventID, EventType and Details. Only events with public IP addresses will be extracted but all details will be included.
4: normal with all IP addresses: Same as type 3, but it also includes private IP addresses.






5: full: All events related to RDP or login activities will be included. Included events IDs are:
New format (evtx):
From Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx, event ids 21 to 25, 39 and 40;
From Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx, event ids 261 and 1149;
From Microsoft-Windows-RemoteDesktopServices-RdpCoreTS%4Operational.evtx, event ids 131 and 140;
From Security.evtx, event ids 4624, 4625, 4634, 4647, 4778 and 4779;
From System.evtx, event ids 56.
Old format (security.evt or SecEvent.Evt):
Event ids 528 to 540, 552, 682 and 683. Also, all events that contain IP addresses involved with RDP activities will be included. Some events may be not extracted (See known problems about this).
--l: With this option, all strings in Details column are on a single line.
--b: This is the backup function. It copies all Event logs from live system. All other options will be ignored. This command require admin priviledge and it doesn't work for old format logs.

In the command line interface, RDP-Parser provides some important informations about logs as the date and time of the first entry, the last entry and the total number of entries.







What do you need

Windows XP SP2 or newer


Changes:
1.1
2018-12-09

New: Extraction of Event IDs 131 and 140 from Microsoft-Windows-RemoteDesktopServices-RdpCoreTS%4Operational.evtx
Fixed: Details were not correctly extracted for event 56 and 1149 with types 2, 4 or 5.

Known Problems

For old format (evt), parsing string for event id 528 (and probably the whole range 528 to 540) is buggy, so you won't get all events, because strings are not correctly parsed.





Click here to visit the author's website.
Continue below to download this file.


Downloads Views Developer Last Update Version Size Type Rank
203 419 Alain Rioux <img src="https://www.oldergeeks.com/downloads/gallery/thumbs/RDPParser1_th.png"border="0"> Feb 27, 2019 - 01:46 1.1 2.87MB ZIP 5/5, out of 1 Votes.
File Tags
RDP-Parser  v1.1  
   

Whoa, Speedy. Your download link is below
but ya gotta read this first:

Isn't it like 1996 again? No ads anywhere! No ad income either
so we really need your help to keep this project alive and kickin'.
By making a donation, you help cover the costs of the site and
we get to eat on a daily basis. If we haven't passed out from hunger,
we can add more freeware. See? Win, win!!
Donating takes just a bunch of seconds so please consider it.
Thank you very much! -Randy & Deanna (The Older Geeks)
Missouri, USA

Monthly operating costs = $480
Donations for May = $747
Donations over our monthly goal
are set aside for future upgrades.

Processed securely through Paypal.
No PayPal account required.

Donate Bitcoin:
1KkUMXvQ2ko3xcJkzitB7WYgoW6m79WFfm

Donate Ethereum:
0x40E56922F43637224935CDC35e2c96E0392A8505

Donate Litecoin:
LLYAFEyqjH69gkyCEpRjXNyedRCWrVChfL



Recent Super Donors ($50+)
Thanks, Robert
Thanks, John
Thanks, John

Recent Donors
Thanks, Buddy's Plant Plus
Thanks, Henry
Thanks, Tim
Thanks, B.
Thanks, Ron
Thanks, Claus
Thanks, Steve
Thanks, Natalie
Thanks, Jerry
Thanks, David

   →→ Download Now ←← - Click to Rate File -
Like? Share this page on Twitter →


Copyright (c) 2019