RDP client Event ID 1024: Outbound connection attempt
- Event ID
- 1024
- Channel
- Microsoft-Windows-TerminalServices-RDPClient/Operational
- Provider
- Microsoft-Windows-TerminalServices-ClientActiveXCore
- Log file
- Microsoft-Windows-TerminalServices-RDPClient%4Operational.evtx
- Category
- Remote access
- Default logging
- Logged by default
What event 1024 means
Event 1024 lives on the client side of Remote Desktop, in the TerminalServices-RDPClient/Operational log of the machine running mstsc.exe (or another client built on the RDP ActiveX control). It records each attempt to connect and the server name or address the user typed.
That makes it the source-side counterpart of the server's 1149 and 4624 type 10: on a compromised workstation or jump host it lists where an attacker went next over RDP. It is logged per user session, so pair it with the logon that was active at the time.
When it is logged
None — the Microsoft-Windows-TerminalServices-RDPClient/Operational channel is enabled by default on Windows.
Key fields
| Field | What it tells you |
|---|---|
| Value | Target server as entered in the client — host name, FQDN or IP address, possibly with a port. |
Common benign sources
- Administrators and users connecting to servers and jump hosts they manage.
What attackers do that produces it
- Lateral movement over RDP from a compromised host — a list of internal targets, sometimes contacted in quick succession.
- Connections to external IPs from servers, which should rarely start outbound RDP.
Investigation tips
- Build the list of targets per host and user; match each with 1149 / 4624 type 10 on the target servers.
- Look for targets addressed by IP rather than name, and for unusual ports.
- The user's
Default.rdpfile and Terminal Server Client registry keys (MRU) corroborate the targets.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1021.001 Remote Services: Remote Desktop Protocol | Lateral Movement |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.