EricZimmerman / evtx

C# based evtx parser with lots of extras
MIT License
282 stars 59 forks source link

Update Microsoft-Windows-TerminalServices-RDPClient-Operational_Micro… #199

Closed forensenellanebbia closed 2 years ago

forensenellanebbia commented 2 years ago

…soft-Windows-TerminalServices-ClientActiveXCore_1027.map

Description

I added the extraction of the SessionId value to the existing map.

Checklist:

Please replace every instance of [ ] with [X] OR click on the checkboxes after you submit your PR

Thank you for your submission and for contributing to the DFIR community!