RDP client Event ID 1102: Multi-transport connection
- Event ID
- 1102
- Channel
- Microsoft-Windows-TerminalServices-RDPClient/Operational
- Provider
- Microsoft-Windows-TerminalServices-ClientActiveXCore
- Log file
- Microsoft-Windows-TerminalServices-RDPClient%4Operational.evtx
- Category
- Remote access
- Default logging
- Logged by default
What event 1102 means
Event 1102 in the RDPClient log (not to be confused with Security 1102, "audit log cleared") is written by the Remote Desktop client when it sets up an additional transport to the server, such as UDP alongside TCP. Its Value field usually holds the server's IP address, which complements event 1024 where the user may have typed a host name.
Seen together, 1024 and 1102 give both the name and the resolved address of each RDP target contacted from the host.
When it is logged
None — the TerminalServices-RDPClient/Operational channel is enabled by default.
Not every connection negotiates multi-transport, so some 1024 events have no matching 1102.
Key fields
| Field | What it tells you |
|---|---|
| Value | IP address of the server the client connected to. |
Common benign sources
- Normal RDP use from administrators' workstations.
What attackers do that produces it
- Outbound RDP lateral movement; the IP helps when the attacker used names that no longer resolve.
Investigation tips
- Pair with the 1024 just before it to map host names to IP addresses.
- Search target servers' 1149 and 4624 for this host's IP at the same time.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1021.001 Remote Services: Remote Desktop Protocol | Lateral Movement |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.