Skip to content
RDP Client

RDP client Event ID 1024: Outbound connection attempt

RDP ClientActiveX is trying to connect to the serverRDP client event 1024 is logged on the source host when mstsc starts connecting to a server; the Value field holds the target name or IP.
1024
Event ID
1024
Channel
Microsoft-Windows-TerminalServices-RDPClient/Operational
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Log file
Microsoft-Windows-TerminalServices-RDPClient%4Operational.evtx
Category
Remote access
Default logging
Logged by default

What event 1024 means

Event 1024 lives on the client side of Remote Desktop, in the TerminalServices-RDPClient/Operational log of the machine running mstsc.exe (or another client built on the RDP ActiveX control). It records each attempt to connect and the server name or address the user typed.

That makes it the source-side counterpart of the server's 1149 and 4624 type 10: on a compromised workstation or jump host it lists where an attacker went next over RDP. It is logged per user session, so pair it with the logon that was active at the time.

When it is logged

Audit policy / configuration

None — the Microsoft-Windows-TerminalServices-RDPClient/Operational channel is enabled by default on Windows.

Key fields

FieldWhat it tells you
ValueTarget server as entered in the client — host name, FQDN or IP address, possibly with a port.

Common benign sources

  • Administrators and users connecting to servers and jump hosts they manage.

What attackers do that produces it

  • Lateral movement over RDP from a compromised host — a list of internal targets, sometimes contacted in quick succession.
  • Connections to external IPs from servers, which should rarely start outbound RDP.

Investigation tips

  • Build the list of targets per host and user; match each with 1149 / 4624 type 10 on the target servers.
  • Look for targets addressed by IP rather than name, and for unusual ports.
  • The user's Default.rdp file and Terminal Server Client registry keys (MRU) corroborate the targets.

MITRE ATT&CK techniques

TechniqueTactics
T1021.001 Remote Services: Remote Desktop ProtocolLateral Movement

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading