Viralmaniar/Remote-Desktop-Caching-
This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to extract juicy information such as LAPS passwords or any sensitive information on the screen. Blue Team member can reconstruct PNG files to see what an attacker did on a compromised host. It is extremely useful for a forensics team to extract timestamps after an attack on a host to collect evidences and perform further analysis.
Topics
Explore related topics
Jump into the topic listings this repository belongs to.
Join the conversation
Reviews · Questions · Posts
Share what you know about Remote-Desktop-Caching- — write a review from your real experience, ask an implementation question, or publish a post about how you use it.
Share your experience
Write or update your review
Explain what worked, what broke down, and what another team should know before adopting Remote-Desktop-Caching-.
Project Q&A
Questions and answers
Browse implementation threads tied directly to Viralmaniar/Remote-Desktop-Caching-. Each question links through to the full answer page.
Be the first to ask how teams run Remote-Desktop-Caching- in production. Every question you post becomes a durable, searchable answer page other developers can find.
Ask the first questionRelated posts
Posts tagged with the same topics
These posts come from the same topic surface as this repo, so readers can move from project evaluation into practical writeups and migration notes without leaving context.
Share how your team uses Remote-Desktop-Caching- — a migration note, an architecture writeup, or a comparison. Your post reaches everyone browsing these same topics.
Write the first post