What is it

RDP-Parser extracts RDP activities from Microsoft Windows Event Logs. This tool has been designed for any investigation involving exploitation of RDP service. It supports Evt and Evtx formats.


RDP-Parser Main Window

RDP-Parser Main Window
Click image to view in full size

How it works

RDP-Parser can be installed using the installer or used as a standalone application. In order to start using it, just run the executable file from the start menu or from the program directory.

If you used the installer, you can also start the tool using the link in the Send To folder after right-clicking on any folder or file(s).

What do you need

  • Windows XP SP2 or newer

Version History

  • New: The new version include an installer and a GUI. See documentation for more information about the new options and features.
  • New: Extraction of Event IDs 131 and 140 from Microsoft-Windows-RemoteDesktopServices-RdpCoreTS%4Operational.evtx
  • Fixed: Details were not correctly extracted for event 56 and 1149 with types 2, 4 or 5.
First release.

Known Problems

  • For old format (evt), parsing string for event id 528 (and probably the whole range 528 to 540) is buggy, so you won't get all events, because strings are not correctly parsed.


To translate RDP-Parser to other languages:

  1. In Settings Window, use the Export Lang.ini function. The file will be saved in the same directory of the tool;
  2. Open the file in any text editor like Notepad;
  3. Translate each expression at the right of the = symbol;
    • The expression on the left side is used by the tool to identify the expression so do not change it. Also, be sure to have a space between the = symbol and your expression (ex. Key = Value);
    • Authorized characters are alphanumerics, spaces and these symbols: ",", ".", "-", "!", ",", "(" and ")". Any other character will be deleted;
    • For some controls, string length must be the same as original. A longer string could be truncated if it doesn't match the length of the field;
    • The value associated with the translatorName will be used in the About window to identify you as translator (if you want). You can also add your email or a short url (ex. YourName (youraddress@email.com));
  4. Restart the tool so the strings in Lang.ini will be used instead of the default language.

If you translate the tool and you want to share, contact the author.

Available translations:

To install, save the appropriate Lang.ini file in the default folder of the tool (if you used the installer, it should be AppData. Otherwise, it's the same folder of the program).

No translation available for the moment.


Copyright (c) 2018-2019 Alain Rioux

This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.

This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.

You should have received a copy of the GNU General Public License along with this program. If not, see http://www.gnu.org/licenses/.


If you have any problem, suggestion, comment, or you found a bug in my utility, contact the author.


  • Main logo has been created by Oxygen Team and is distributed on term of the GNU Lesser General Public License.
  • The icon used for Open folder button comes from Basic Icons by PixelMixer and is distributed as Freeware.
  • The "Open folder in Explorer" icon comes from Danish Royalty Free Icons by Jonas Rask Design. This icon is distributed as Freeware.
  • The icons used for Process, Settings and About buttons come from the Blue Bits collection of Icojam (licensed as "Public Domain").
  • Documentation button icons has been created by Oxygen Team and is distributed on term of the GNU Lesser General Public License.


Source code is hosted on SourceForge and GitHub. Binaries are hosted on SourceForge.

Filename MD5 SHA256
RDP-Parser 2.0 Setup.exe 2a0f3d540a456fd8e4ce92bfc73f63ea 75fde901598b61a346375610fcb6cbf8287632cea0a2f0bd330c80a198108145
RDP-Parser 2.0.zip bc99451493f359a554da8eb8bc9c4812 931ccb18c767e3f877e9e896015805153884e0a719b03c314cf1d6b8fec38c69
RDP-Parser 1.1.zip 143e3d5b91e7e8839c8c4c49dfd0bdd0 864b715ca58f1216472f3cb6d8b7899eb575c0e901da0158780b1ab4919ab1ed


If you want to download the standalone version or an older version, check on SourceForge.


Credits to Free Website Templates for the template of this Website