Skip to content
RDP Client

RDP client Event ID 1102: Multi-transport connection

The client has initiated a multi-transport connection to the serverRDP client event 1102 is logged on the source host when the client opens a multi-transport connection; Value holds the server IP address.
1102
Event ID
1102
Channel
Microsoft-Windows-TerminalServices-RDPClient/Operational
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Log file
Microsoft-Windows-TerminalServices-RDPClient%4Operational.evtx
Category
Remote access
Default logging
Logged by default

What event 1102 means

Event 1102 in the RDPClient log (not to be confused with Security 1102, "audit log cleared") is written by the Remote Desktop client when it sets up an additional transport to the server, such as UDP alongside TCP. Its Value field usually holds the server's IP address, which complements event 1024 where the user may have typed a host name.

Seen together, 1024 and 1102 give both the name and the resolved address of each RDP target contacted from the host.

When it is logged

Audit policy / configuration

None — the TerminalServices-RDPClient/Operational channel is enabled by default.

Not every connection negotiates multi-transport, so some 1024 events have no matching 1102.

Key fields

FieldWhat it tells you
ValueIP address of the server the client connected to.

Common benign sources

  • Normal RDP use from administrators' workstations.

What attackers do that produces it

  • Outbound RDP lateral movement; the IP helps when the attacker used names that no longer resolve.

Investigation tips

  • Pair with the 1024 just before it to map host names to IP addresses.
  • Search target servers' 1149 and 4624 for this host's IP at the same time.

MITRE ATT&CK techniques

TechniqueTactics
T1021.001 Remote Services: Remote Desktop ProtocolLateral Movement

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading