@justhackingtraining · Just Hacking Training
Saved 2026-05-19 · Posted 2026-05-17 · Status: New
RDP shadowing is built directly into Windows.
Using a technique demonstrated by Slavi Parpulev, we attach to an active RDP session on a domain controller using native functionality and server-side configuration.
Understanding how these features work is critical in Active Directory environments.
Click the link in bio to learn more in the Mastering Active Directory Security course.
#cybersecurity #windows #infosec #activedirectory
Content ideas (0)
No ideas generated yet. Run /instagram-sync ideate from Claude Code to create some.
Comments (15)
It’s built-in to rdp, it’s been there years. We used to use it to support users
How do I block shadowing?
THAT ONLY WORKS ON WIN10 before 1500 lol
Learn directly from Slavi with hands-on virtual labs in 3 affordable courses on MADS, Mastering AD Security: https://www.justhacking.com/course/mastering-active-directory-security-mads-vol-1-credentials/
interesting
It's old news but just as a lot of things, they were built for doing good but now are used to doing wrong stuff.
It’s not a big thing chill they did it on purpose to be used by support IT’s to help the user as an admin
Is this remediated in one of the CIS controls
Thats concerning
feel like i remember this from a long time ago?
Is this kid called slavi?
Old news since 2006
Very cool. I wonder if the method is derived through the remote support function?
This is old-school
This meant to help a user as an administrator