RDP-Parser extracts RDP activities from Microsoft Windows Event Logs. This tool has been designed for any
investigation involving exploitation of RDP service. It supports Evt and Evtx formats.
How it works
RDP-Parser can be installed using the installer or used as a standalone application. In order to start using it,
just run the executable file from the start menu or from the program directory.
If you used the installer, you can also start the tool using the link in the Send To folder after
right-clicking on any folder or file(s).
What do you need
Windows XP SP2 or newer
Screenshots
Version History
Version
Comments
2.0 2019-06-04
New:
New: The new version include an installer and a GUI. See documentation for
more information about the new options and features.
1.1 2018-12-09
New:
Extraction of Event IDs 131 and 140 from Microsoft-Windows-RemoteDesktopServices-RdpCoreTS%4Operational.evtx
Fixed:
Details were not correctly extracted for event 56 and 1149 with types 2, 4 or 5.
1.0 2018-09-23
First release.
Translation
To translate RDP-Parser to other languages:
In Settings window, use the Export Lang.ini function. The file will be
saved in the same directory of the tool;
Open the file in any text editor like Notepad;
Translate each expression at the right of the = symbol;
The expression on the left side is used by the tool to identify the expression so do not change it. Also,
be sure to have a space between the = symbol and your expression (ex. Key = Value);
Authorized characters are alphanumerics, spaces and these symbols: ",", ".", "-", "!", ",", "(" and ")".
Any other character will be deleted;
For some controls, string length must be the same as original. A longer string could be truncated if it
doesn't match the length of the field;
The value associated with the translatorName will be used in the About
window to identify you as translator (if you want). You can also add your email or a short url (ex. YourName
(youraddress@email.com));
Restart the tool so the strings in Lang.ini will be used instead of the default language.
To install, save the appropriate Lang.ini file in the default folder of the tool (if you
used the installer, it should be AppData. Otherwise, it's the same folder of the program).
No translation available for the moment.
Known Problems
For old format (evt), parsing string for event id 528 (and probably the whole range 528 to 540)
is buggy, so you won't get all events, because strings are not correctly parsed.
This program is free software: you can redistribute it and/or modify it under the terms of the GNU General
Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option)
any later version.
This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the
implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
for more details.
You should have received a copy of the GNU General Public License along with this program. If not, see
http://www.gnu.org/licenses/.
Credits
Main logo has been created by Oxygen Team and is distributed
on term of the GNU Lesser General Public License.
The icon used for Open folder button comes from Basic Icons by PixelMixer and is distributed as Freeware.
The "Open folder in Explorer" icon comes from Danish Royalty Free Icons by Jonas Rask Design. This icon is distributed as Freeware.
The icons used for Process, Settings and About buttons come from the Blue Bits collection of Icojam (licensed as "Public Domain").
Documentation button icons has been created by Oxygen
Team and is distributed on term of the GNU Lesser General Public License.