Here is a collection of RDP decrypted capture files, showing various scenarios.
- Username: [email protected]
- Server: IT-HELP-TEST.ad.it-help.ninja
- Authentication: RDP NLA with Kerberos
- Username: IT-HELP\Administrator
- Server: IT-HELP-TEST.ad.it-help.ninja
- Authentication: RDP NLA with Kerberos
- Username: IT-HELP\Administrator
- Server: 10.10.0.10
- Authentication: RDP NLA with NTLM
The client connected using the IP address instead of the FQDN, causing an NTLM downgrade on a server configured to reject inbound NTLM.
- Username: [email protected]
- Server: IT-HELP-TEST.ad.it-help.ninja
- Authentication: RDP NLA with Kerberos (password), followed by an NTLM downgrade
The client connected using the FQDN of the server and attempted Kerberos password-based authentication, but after entering the wrong password, the RDP client downgraded to NTLM which is then rejected by the server due to the user being a member of the Protected Users group in Active Directory.
rdp-nla-smartcard-auth1.pcapng
- Username: [email protected]
- Server: IT-HELP-TEST.ad.it-help.ninja
- Authentication: RDP NLA with Kerberos (smartcard)
rdp-nla-smartcard-auth2.pcapng
- Username: [email protected]
- Server: IT-HELP-TEST.ad.it-help.ninja
- Authentication: RDP NLA with Kerberos (smartcard)
rdp-no-nla-smartcard-auth1.pcapng
- Username: [email protected]
- Server: IT-HELP-TEST.ad.it-help.ninja
- Authentication: RDP without NLA (smartcard)
- Username: [email protected]
- Server: IT-HELP-TEST.ad.it-help.ninja
- Authentication: RDP without NLA (password)
- Username: [email protected]
- Server: IT-HELP-TEST.ad.it-help.ninja
- Authentication: RDP without NLA (password)
- Username: [email protected]
- Server: IT-HELP-TEST.ad.it-help.ninja
- Authentication: RDP without NLA, without TLS (password)
rdp-restricted-admin-accepted1.pcapng
- Username: [email protected]
- Server: IT-HELP-TEST.ad.it-help.ninja
- Authentication: RDP with NLA + Restricted Admin Mode
rdp-restricted-admin-rejected1.pcapng
- Username: [email protected]
- Server: IT-HELP-TEST.ad.it-help.ninja
- Authentication: RDP with NLA + Restricted Admin Mode
rdp-credential-guard-accepted1.pcapng
- Username: [email protected]
- Server: IT-HELP-TEST.ad.it-help.ninja
- Authentication: RDP with NLA + Remote Credential Guard
rdp-credential-guard-rejected1.pcapng
- Username: [email protected]
- Server: IT-HELP-TEST.ad.it-help.ninja
- Authentication: RDP with NLA + Remote Credential Guard
rdp-rdg-diff-creds-kerberos-password.pcapng
RD Gateway:
- Username: [email protected]
- Server: IT-HELP-GW.ad.it-help.ninja
- Authentication: Kerberos, password-based
RDP server:
- Username: [email protected]
- Server: IT-HELP-TEST.ad.it-help.ninja
- Authentication: Kerberos, password-based
rdp-rdg-diff-creds-kerberos-smartcard.pcapng
RD Gateway:
- Username: [email protected]
- Server: IT-HELP-GW.ad.it-help.ninja
- Authentication: Kerberos, smartcard-based
RDP server:
- Username: [email protected]
- Server: IT-HELP-TEST.ad.it-help.ninja
- Authentication: Kerberos, smartcard-based
rdp-rdg-no-kdc-proxy-ntlm-downgrade-failure.pcapng
RD Gateway:
- Username: [email protected]
- Server: IT-HELP-GW.ad.it-help.ninja
- Authentication: Kerberos, password-based
rdp-rdg-no-kdc-proxy-ntlm-downgrade-success.pcapng
RD Gateway:
- Username: [email protected]
- Server: IT-HELP-GW.ad.it-help.ninja
- Authentication: Kerberos, password-based
rdp-rdg-same-creds-kerberos-password-success1.pcapng
RD Gateway:
- Username: [email protected]
- Server: IT-HELP-GW.ad.it-help.ninja
- Authentication: Kerberos, password-based
RDP server:
- Username: [email protected]
- Server: IT-HELP-TEST.ad.it-help.ninja
- Authentication: Kerberos, password-based
rdp-rdg-same-creds-kerberos-password-success2.pcapng
RD Gateway:
- Username: [email protected]
- Server: IT-HELP-GW.ad.it-help.ninja
- Authentication: Kerberos, password-based
RDP server:
- Username: [email protected]
- Server: IT-HELP-TEST.ad.it-help.ninja
- Authentication: Kerberos, password-based
rdp-rdg-same-creds-kerberos-smartcard-success1.pcapng
RD Gateway:
- Username: [email protected]
- Server: IT-HELP-GW.ad.it-help.ninja
- Authentication: Kerberos, smartcard-based
RDP server:
- Username: [email protected]
- Server: IT-HELP-TEST.ad.it-help.ninja
- Authentication: Kerberos, smartcard-based
rdp-rdg-same-creds-kerberos-smartcard-success2.pcapng
RD Gateway:
- Username: [email protected]
- Server: IT-HELP-GW.ad.it-help.ninja
- Authentication: Kerberos, smartcard-based
RDP server:
- Username: [email protected]
- Server: IT-HELP-TEST.ad.it-help.ninja
- Authentication: Kerberos, smartcard-based