daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

rdp.md (11544B)


      1 ---
      2 title: "RDP"
      3 description: "export RDP=sdl-freerdp"
      4 category: linux-it
      5 tags: ["linux-it", "adcs"]
      6 tools: []
      7 difficulty: intermediate
      8 updated: "2026-08-10"
      9 source: "vault:Linux/RDP CheatSheet.md"
     10 ---
     11 # macOS: native SDL client (recommended)
     12 export RDP=sdl-freerdp
     13 
     14 # Linux examples:
     15 # export RDP=xfreerdp3
     16 # export RDP=xfreerdp
     17 
     18 export TARGET='10.10.10.10'
     19 export DOMAIN='DOMAIN'
     20 export USER='username'
     21 ```
     22 
     23 > [!tip]+ Secure baseline
     24 > 1. `/from-stdin:force` prompts before connecting, keeping the password out of shell history and process arguments.
     25 > 2. `/cert:tofu` trusts a certificate on the first connection, then rejects an unexpected change.
     26 > 3. `+dynamic-resolution` keeps the session usable when the client window is resized.
     27 
     28 ```bash
     29 "$RDP" /v:"$TARGET" /d:"$DOMAIN" /u:"$USER" \
     30   /from-stdin:force /cert:tofu +dynamic-resolution
     31 ```
     32 
     33 ---
     34 
     35 ## // CONNECTION_&_AUTHENTICATION
     36 
     37 ### 1. Identity formats
     38 
     39 | Identity type | Example |
     40 |---|---|
     41 | Local account | `/u:Administrator` |
     42 | Domain account | `/d:DOMAIN /u:username` |
     43 | Down-level domain name | `/u:'DOMAIN\username'` |
     44 | User principal name | `/u:'user@domain.example'` |
     45 
     46 ```bash
     47 # Local account
     48 "$RDP" /v:"$TARGET" /u:Administrator /from-stdin:force /cert:tofu
     49 
     50 # Domain account
     51 "$RDP" /v:"$TARGET" /d:"$DOMAIN" /u:"$USER" /from-stdin:force /cert:tofu
     52 
     53 # UPN
     54 "$RDP" /v:"$TARGET" /u:'user@domain.example' /from-stdin:force /cert:tofu
     55 ```
     56 
     57 > [!warning]+ Avoid inline passwords `fas:TriangleExclamation`
     58 > `/p:<password>` is supported, but the password can end up in shell history, terminal scrollback, process listings, screenshots, and copied commands. Use `/from-stdin:force` unless a disposable authorised lab requires otherwise.
     59 
     60 ### 2. Kerberos and smart-card authentication
     61 
     62 ```bash
     63 # Use an existing Kerberos ticket cache
     64 kinit 'user@DOMAIN.EXAMPLE'
     65 "$RDP" /v:"$TARGET" /u:'user@DOMAIN.EXAMPLE' \
     66   /sec:nla /kerberos:cache:"$KRB5CCNAME" /cert:tofu
     67 
     68 # Smart-card logon (the reader/card must be available locally)
     69 "$RDP" /v:"$TARGET" /smartcard-logon /sec:nla /cert:tofu
     70 ```
     71 
     72 > [!info]+ Authentication notes
     73 > 1. `/sec:nla` explicitly requires Network Level Authentication and disables weaker alternatives.
     74 > 2. Kerberos depends on DNS, realm configuration, and clock alignment; inspect the ticket with `klist` before troubleshooting RDP itself.
     75 > 3. Smart-card logon activates the local reader; it is distinct from `/smartcard`, which redirects a smart card into an already authenticated remote session.
     76 
     77 ### 3. Pass-the-hash — authorised lab/admin use only
     78 
     79 ```bash
     80 export NT_HASH='0123456789ABCDEF0123456789ABCDEF'
     81 "$RDP" /v:"$TARGET" /u:Administrator /pth:"$NT_HASH" \
     82   +restricted-admin /cert:tofu
     83 ```
     84 
     85 > [!danger]+ Credential material `fas:Skull`
     86 > A hash is credential material. Use this only with explicit authority, do not save it in the note, and clear the variable with `unset NT_HASH` when finished. Restricted Admin mode must be permitted by the target policy.
     87 
     88 ---
     89 
     90 ## // TRANSPORT_&_CERTIFICATE_SECURITY
     91 
     92 | Goal | Option | When to use it |
     93 |---|---|---|
     94 | Secure default | `/cert:tofu` | First connection to a known target; detects later certificate changes |
     95 | Pin known certificate | `/cert:fingerprint:sha256:<hex>` | You have a verified SHA-256 fingerprint from a trusted channel |
     96 | Fail on mismatch | `/cert:deny` | Strict environments that should never prompt |
     97 | Require NLA | `/sec:nla` | Normal domain or local-account RDP |
     98 | TLS without NLA | `/sec:tls` | Only when the target intentionally does not require NLA |
     99 | Legacy RDP security | `/sec:rdp` | Legacy, authorised compatibility testing only |
    100 
    101 ```bash
    102 # Pin a certificate fingerprint received through a trusted channel
    103 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force \
    104   /cert:fingerprint:sha256:<hex_fingerprint>
    105 
    106 # Require NLA and TLS 1.2 or newer where the target requires an explicit floor
    107 "$RDP" /v:"$TARGET" /d:"$DOMAIN" /u:"$USER" /from-stdin:force \
    108   /sec:nla /tls:enforce:1.2 /cert:tofu
    109 ```
    110 
    111 > [!danger]+ Never make this the default `fas:TriangleExclamation`
    112 > `/cert:ignore` disables certificate validation and makes a rogue or intercepted server much harder to detect. Use it only in a disposable, explicitly authorised lab when certificate validation is the subject of the test.
    113 
    114 ---
    115 
    116 ## // DISPLAY_&_PERFORMANCE
    117 
    118 ### 1. Display and window controls
    119 
    120 ```bash
    121 # Fullscreen; Ctrl+Alt+Enter toggles back to a window
    122 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu +f
    123 
    124 # Fixed initial size, then allow resize-driven updates
    125 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu \
    126   /size:1600x1000 +dynamic-resolution
    127 
    128 # Use 80% of display height or scale the rendered desktop
    129 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu /size:80%h
    130 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu /scale:140
    131 
    132 # Multiple displays or selected display IDs (list IDs with /list:monitor)
    133 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu /multimon
    134 "$RDP" /list:monitor
    135 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu /monitors:0,1
    136 ```
    137 
    138 ### 2. Low-bandwidth profile
    139 
    140 ```bash
    141 "$RDP" /v:"$TARGET" /d:"$DOMAIN" /u:"$USER" /from-stdin:force \
    142   /cert:tofu /network:modem /compression-level:2 \
    143   -wallpaper -themes -menu-anims -fonts /gdi:sw
    144 ```
    145 
    146 ### 3. High-quality workstation profile
    147 
    148 ```bash
    149 "$RDP" /v:"$TARGET" /d:"$DOMAIN" /u:"$USER" /from-stdin:force \
    150   /cert:tofu +f +dynamic-resolution /gdi:hw \
    151   /gfx:progressive:on,AVC444:on /network:lan
    152 ```
    153 
    154 > [!tip]+ Performance tuning `fas:Lightbulb`
    155 > 1. Start with `/network:auto` or `/network:lan`; move toward `/network:modem` only when the connection is genuinely constrained.
    156 > 2. Disable wallpaper, themes, animations, and smooth fonts before compromising authentication or certificate checks.
    157 > 3. If hardware rendering misbehaves, use `/gdi:sw` as a compatibility fallback.
    158 
    159 ---
    160 
    161 ## // LOCAL_RESOURCE_REDIRECTION
    162 
    163 ### 1. Clipboard and drives
    164 
    165 ```bash
    166 # Disable clipboard redirection for sensitive sessions
    167 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu -clipboard
    168 
    169 # Redirect one selected directory as a named remote share
    170 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu \
    171   /drive:Share,"$PWD"
    172 
    173 # Redirect the home directory or every mounted filesystem
    174 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu +home-drive
    175 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu +drives
    176 
    177 # Permit hot-plugged removable drives
    178 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu /drive:hotplug,*
    179 ```
    180 
    181 ### 2. Audio, printers, smart cards, and USB
    182 
    183 ```bash
    184 # Audio output and microphone input
    185 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu /sound /microphone
    186 
    187 # Redirect a printer or smart card into the session
    188 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu /printer
    189 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu /smartcard
    190 
    191 # Redirect a USB device by vendor and product ID
    192 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu /usb:id:1234:5678
    193 ```
    194 
    195 > [!warning]+ Data-boundary check `fas:TriangleExclamation`
    196 > Clipboard, drive, USB, printer, microphone, and smart-card redirection expand the trust boundary between your machine and the remote host. Enable only the one feature you need and disable it for untrusted or assessment targets.
    197 
    198 ---
    199 
    200 ## // GATEWAYS_PROXY_&_REMOTEAPP
    201 
    202 ```bash
    203 # RD Gateway; omit /p: values so FreeRDP prompts for required credentials
    204 export GATEWAY='rdgateway.example.com'
    205 export GW_USER='gateway-user'
    206 "$RDP" /v:"$TARGET" /d:"$DOMAIN" /u:"$USER" /from-stdin:force \
    207   /gateway:g:"$GATEWAY",u:"$GW_USER",d:"$DOMAIN",usage-method:detect \
    208   /cert:tofu
    209 
    210 # HTTP or SOCKS5 proxy
    211 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu \
    212   /proxy:http://proxy.example.com:8080
    213 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu \
    214   /proxy:socks5://127.0.0.1:1080
    215 
    216 # A gateway also honours an HTTPS proxy set in the environment
    217 export https_proxy='http://proxy.example.com:3128'
    218 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force \
    219   /gateway:g:"$GATEWAY" /cert:tofu
    220 
    221 # RemoteApp example
    222 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu \
    223   /app:program:'||notepad',name:'Notepad'
    224 ```
    225 
    226 > [!info]+ Gateway credentials
    227 > A gateway can use credentials different from the target. Keep gateway passwords out of the command line too; FreeRDP prompts when the relevant `/p:` value is omitted.
    228 
    229 ---
    230 
    231 ## // SESSION_CONTROL_&_TROUBLESHOOTING
    232 
    233 | Symptom or task | Command / response |
    234 |---|---|
    235 | Confirm the installed version | `"$RDP" /version` |
    236 | Inspect locally supported options | `"$RDP" /help` |
    237 | Find available display IDs | `"$RDP" /list:monitor` |
    238 | Test authentication without opening a desktop | Add `+auth-only` |
    239 | Reconnect after a transient drop | Add `+auto-reconnect /auto-reconnect-max-retries:10` |
    240 | Keep an authorised session awake | Add `/prevent-session-lock:300` |
    241 | Release keyboard/mouse grab | Press `Right Ctrl` |
    242 | Toggle fullscreen | Press `Ctrl+Alt+Enter` |
    243 | Minimise the session | Press `Ctrl+Alt+M` |
    244 
    245 ```bash
    246 # Verify credentials and transport without starting the GUI desktop
    247 "$RDP" /v:"$TARGET" /d:"$DOMAIN" /u:"$USER" /from-stdin:force \
    248   /cert:tofu +auth-only
    249 
    250 # Reconnect a flaky authorised session, up to ten times
    251 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu \
    252   +auto-reconnect /auto-reconnect-max-retries:10
    253 ```
    254 
    255 > [!failure]+ Common fixes `fas:CircleXmark`
    256 > 1. **`$DISPLAY` error on macOS:** use `sdl-freerdp`, or install and start XQuartz before using `xfreerdp`.
    257 > 2. **Certificate changed:** stop and verify the server identity through a trusted channel; do not switch to `/cert:ignore` just to connect.
    258 > 3. **NLA / Kerberos failure:** verify DNS, target time, realm configuration, and the ticket cache with `klist`.
    259 > 4. **Option rejected:** your package may differ from this reference; use `"$RDP" /help` and update the client.
    260 
    261 ---
    262 
    263 ## // MACOS_INSTALL `fas:Apple`
    264 
    265 ```bash
    266 # Homebrew installs FreeRDP 3.30.0, including sdl-freerdp and xfreerdp
    267 brew update
    268 brew install freerdp
    269 
    270 # Only required when using the X11 client (xfreerdp)
    271 brew install --cask xquartz
    272 open -a XQuartz
    273 
    274 # Verify both available clients
    275 sdl-freerdp /version
    276 xfreerdp /version
    277 ```
    278 
    279 > [!success]+ macOS client choice
    280 > Use `sdl-freerdp` by default on macOS. The Homebrew formula builds the SDL client, while its `xfreerdp` client requires a running X11 server and otherwise produces a `$DISPLAY` error.
    281 
    282 ---
    283 
    284 ## // LESSONS_LEARNED `fas:Lightbulb`
    285 
    286 1. Set the client, target, domain, and user once; then every recipe remains copy-ready across macOS and Linux.
    287 2. Prefer `/from-stdin:force` and `/cert:tofu`; a convenient command should not weaken credential or server authentication.
    288 3. Treat clipboard, drive, device, audio, and smart-card redirection as deliberate data-sharing decisions.
    289 4. Use `+auth-only` to separate authentication and certificate failures from GUI/display problems.
    290 5. FreeRDP packages differ by platform; `"$RDP" /help` is the local source of truth.
    291 
    292 ---
    293 
    294 ## // REFERENCES `fas:BookOpen`
    295 
    296 1. [FreeRDP project](https://www.freerdp.com/)
    297 2. [FreeRDP 3.30.0 release](https://github.com/FreeRDP/FreeRDP/releases/tag/3.30.0)
    298 3. [FreeRDP macOS installation guidance](https://github.com/FreeRDP/FreeRDP/wiki/Prebuilds)
    299 4. [Homebrew `freerdp` formula](https://formulae.brew.sh/formula/freerdp)
    300 5. [Homebrew formula source — enabled X11 and SDL clients](https://github.com/Homebrew/homebrew-core/blob/HEAD/Formula/f/freerdp.rb)
    301 
    302 #Cheatsheet #CommandReference #RDP #FreeRDP #RemoteAccess #Windows