[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/wireshark-tutorial-decrypting-rdp-traffic/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/wireshark-tutorial-decrypting-rdp-traffic/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/ "Learning Hub")
* [Cybersecurity Tutorials](https://unit42.paloaltonetworks.com/category/cybersecurity-tutorials/ "Cybersecurity Tutorials")  
  [Cybersecurity Tutorials](https://unit42.paloaltonetworks.com/category/cybersecurity-tutorials/)

# Wireshark Tutorial: Decrypting RDP Traffic

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 10 min read

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Vijay Prakash](https://unit42.paloaltonetworks.com/author/vijay-prakash/)
  * [Brad Duncan](https://unit42.paloaltonetworks.com/author/brad-duncan/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:April 1, 2021

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Cybersecurity Tutorials](https://unit42.paloaltonetworks.com/category/cybersecurity-tutorials/)
  * [Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [RDP](https://unit42.paloaltonetworks.com/tag/rdp/)
  * [Windows](https://unit42.paloaltonetworks.com/tag/windows/)
  * [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/)
  * [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/wireshark-tutorial-decrypting-rdp-traffic/?pdf=download&lg=en&_wpnonce=7570bbad6f "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/wireshark-tutorial-decrypting-rdp-traffic/?pdf=print&lg=en&_wpnonce=7570bbad6f "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Wireshark%20Tutorial:%20Decrypting%20RDP%20Traffic&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fwireshark-tutorial-decrypting-rdp-traffic%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fwireshark-tutorial-decrypting-rdp-traffic%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fwireshark-tutorial-decrypting-rdp-traffic%2F&title=Wireshark%20Tutorial:%20Decrypting%20RDP%20Traffic "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fwireshark-tutorial-decrypting-rdp-traffic%2F&text=Wireshark%20Tutorial:%20Decrypting%20RDP%20Traffic "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fwireshark-tutorial-decrypting-rdp-traffic%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Wireshark%20Tutorial:%20Decrypting%20RDP%20Traffic%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fwireshark-tutorial-decrypting-rdp-traffic%2F "Share in Mastodon")

## Executive Summary

In recent years, Remote Desktop Protocol (RDP) has been exploited by attackers to access unsecured servers and enterprise networks. Since 2017, RDP has become a significant vector in malware attacks using ransomware. Security professionals have increasingly focused their attention on this protocol by writing signatures to detect RDP vulnerabilities and prevent attacks.

As a proprietary protocol from Microsoft, RDP supports several operating modes that encrypt network traffic. Unfortunately, this encryption makes writing RDP signatures difficult because RDP content is hidden.

Fortunately, we can establish a test environment that provides a key file, and we can use that key to decrypt a packet capture (pcap) of the RDP traffic in Wireshark.

This blog demonstrates how to prepare the environment, obtain a decryption key and use it to decrypt RDP traffic.

## Requirements

The following are necessary to get the most value from this tutorial:

* A virtual environment to run two Windows hosts like VirtualBox or VMware.
* An understanding of how to set up and use RDP.
* An RDP client. We use a host running Windows 10 Professional for this tutorial.
* An RDP server. This can be another Windows host with RDP enabled, or it can be a non-Windows host running FreeRDP.
* A way to record the network traffic between these two hosts. This is most easily done within a virtual environment.
* Wireshark version 3.0 or better.
* A basic knowledge of network traffic fundamentals.

## Overall Process

The overall process follows seven general steps:

Step 1: Set up a virtual environment with two hosts, one acting as an RDP client and one acting as an RDP server.

Step 2: Remove forward secrecy ciphers from the RDP client.

Step 3: Obtain the RDP server's private encryption key.

Step 4: Capture RDP traffic between the RDP server and Windows client.

Step 5: Open the pcap in Wireshark.

Step 6: Load the key in Wireshark.

Step 7: Examine RDP data.

#### Step 1: Set Up Virtual Environment

The two most common virtual environments for this type of analysis are [VirtualBox](https://www.virtualbox.org/) or VMware Workstation for Windows and Linux. VMWare Fusion is used for macOS. VirtualBox is free, while VMware is a commercial product.

This tutorial does not cover setting up virtual machines (VMs) in a virtual environment. The basic structure of our lab used for this tutorial is shown below in Figure 1.
![The lab setup used for this tutorial on decrypting RDP traffic includes a physical host running a virtualization environment, a virtual LAN, a Windows VM acting as an RDP client and a Windows VM acting as an RDP server.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/03/word-image-122.png) Figure 1. Lab setup used for this tutorial.

Our lab environment contained two Windows 10 hosts. One of the hosts acted as an RDP client, and the other acted as an RDP server. We recorded network traffic from an RDP session between these two hosts from the virtual LAN.

#### Step 2: Remove Forward Secrecy Ciphers From RDP Client

Some encryption ciphers provide [forward secrecy](https://www.keycdn.com/blog/perfect-forward-secrecy), which is also known as perfect forward secrecy. These types of ciphers create multiple session keys for an SSL/TLS connection. With forward secrecy, we cannot decrypt SSL/TLS traffic using a single private encryption key from the RDP server. Therefore, we had to remove configuration options that support forward secrecy on the RDP client.

For this tutorial, our RDP client was a host running Windows 10 Pro. This host has a built-in RDP client.

Microsoft has published details on removing configuration options that support forward secrecy in the articles, "[Manage Transport Layer Security (TLS)](https://docs.microsoft.com/en-us/windows-server/security/tls/manage-tls)" and "[Prioritizing Schannel Cipher Suites](https://docs.microsoft.com/en-us/windows/win32/secauthn/prioritizing-schannel-cipher-suites)." Below is a step-by-step process that we used.

Open the Group Policy Management Console ***gpedit.msc*** as an administrator as shown below in Figure 2.
![Open the Group Policy Management Console gpedit.msc as an administrator by clicking "Run as administrator," as shown here.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/03/word-image-123.png) Figure 2. Running the Group Policy Editor in Windows 10 Pro as an administrator.

From the console, use the following menu path:

* Computer Configuration.
* Administrative Templates.
* Network.
* SSL Configuration Settings.

Below, Figure 3 shows how to find SSL Configuration Settings.
![The large black arrow in the screenshot indicates the location of the SSL Configuration Settings in the file system.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/03/word-image-124.png) Figure 3. Getting to the SSL Configuration Settings.

Under SSL Configuration Settings, double-click the entry for ***SSL Cipher Suite Order*** as shown below in Figure 4.
![Figure 4. Getting to the SSL Cipher Suite Order.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/03/word-image-125.png) Figure 4. Getting to the SSL Cipher Suite Order.

Under the SSL Cipher Suite Order, click the ***Enabled*** option as shown below in Figure 5.
![The large black arrow indicates where to click to enable SSL Cipher Suite Order. An explanation in the screenshot states, "This policy setting determines the cipher suites used by the Secure Socket Layer. If you enable this policy setting, SSL cipher suites are prioritized in the order specifiied."](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/03/word-image-126.png) Figure 5. Enabling the SSL Cipher Suite Order.

Next, double-click the list of ciphers and select the entire list as shown below in Figure 6.
![The next step is to select the entire list of ciphers as shown in the screenshot.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/03/word-image-127.png) Figure 6. Selecting the list of ciphers.

Once the list has been selected, copy it as shown below in Figure 7.
![Copy the list of ciphers as shown.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/03/word-image-128.png) Figure 7. Copying the list of ciphers.

Copy this list of ciphers into a text editor such as Notepad. Remove any ciphers that support Elliptic Curve cryptography using Diffie-Hellman Ephemeral (ECDHE) or Digital Signature Algorithm (ECDSA) encryption. These should be any entries with ECDHE and/or ECDSA in the name. In the example shown below in Figure 8, these ciphers were all located sequentially, so they were easy to delete from the text.
![Delete ciphers that support Elliptic Curve cryptography by removing any entries with ECDHE and/or ECDHA in the name. In our example, the ciphers were located sequentially and were therefore easy to delete.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/03/word-image-129.png) Figure 8. Deleting entries for ECDHE and ECDSA.

Our updated list of ciphers from Figure 8 is listed below in Table 1.

|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| TLS\_AES\_256\_GCM\_SHA384,TLS\_AES\_128\_GCM\_SHA256,TLS\_RSA\_WITH\_AES\_256\_GCM\_SHA384,TLS\_RSA\_WITH\_AES\_128\_GCM\_SHA256,TLS\_RSA\_WITH\_AES\_256\_CBC\_SHA256,TLS\_RSA\_WITH\_AES\_128\_CBC\_SHA256,TLS\_RSA\_WITH\_AES\_256\_CBC\_SHA,TLS\_RSA\_WITH\_AES\_128\_CBC\_SHA,TLS\_RSA\_WITH\_3DES\_EDE\_CBC\_SHA,TLS\_RSA\_WITH\_NULL\_SHA256,TLS\_RSA\_WITH\_NULL\_SHA,TLS\_PSK\_WITH\_AES\_256\_GCM\_SHA384,TLS\_PSK\_WITH\_AES\_128\_GCM\_SHA256,TLS\_PSK\_WITH\_AES\_256\_CBC\_SHA384,TLS\_PSK\_WITH\_AES\_128\_CBC\_SHA256,TLS\_PSK\_WITH\_NULL\_SHA384,TLS\_PSK\_WITH\_NULL\_SHA256 |

^*Table 1. Updated list after removing forward secrecy ciphers.*^

Paste the updated cipher list back into the SSL Cipher Suites Field, making sure to overwrite the original list. Click the Apply button, then click OK to close the window. You have now updated the list and can close the Group Policy Editor.

After we accomplished this step, we had to obtain the RDP server's private key.

#### Step 3: Obtain RDP Server's Private Key

FreeRDP is one option to use as an RDP server. You can get FreeRDP from [this GitHub repository](https://github.com/FreeRDP), as well as [build instructions](https://github.com/FreeRDP/FreeRDP/wiki/Compilation). Make sure to set the ***WITH\_SERVER=ON*** flag when creating the server. Once the server is built, you must provide it with a private key, or use one that comes with FreeRDP.

For our RDP server in this tutorial, we used another host running Windows 10 Pro. Then we extracted the private key from the host's operating system.

To ensure our second Windows host acted as an RDP server, we enabled RDP. To enable RDP on a host running Windows 10 Pro, go to Windows Settings from the Start Menu, then select the ***System*** icon as shown below in Figure 9.
![To ensure our second Windows host acted as an RDP server, we enabled RDP by selecting the System icon as shown here.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/03/word-image-130.png) Figure 9. Getting to the Windows System settings.

Under the system settings, select ***Remote Desktop*** and click the switch for ***Enable Remote Desktop*** as shown below in Figure 10.
![The large black arrows show where to select Remote Desktop and where to click the switch for Enable Remote Desktop.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/03/word-image-131.png) Figure 10. Enabling RDP in WIndows 10.

After setting up our second Windows host as an RDP server, we extracted the private key from its operating system.

To extract the server key, we could either use either Jailbreak or [Mimikatz](https://www.varonis.com/blog/what-is-mimikatz/). We chose Jailbreak.

[Jailbreak](https://github.com/iSECPartners/jailbreak) is a tool by iSECPartners that can export the server's RDP certificate. From the exported certificate, we could extract the private key.

To use Jailbreak, we downloaded the following Jailbreak binaires from [this GitHub repository](https://github.com/iSECPartners/jailbreak/tree/master/binaries) on our newly established RDP server:

* EasyHook64.dll
* jailbreak64.exe
* jailbreakhook64.dll
* jbstore2\_64.exe

Note: The above files were used on a Windows 10 Pro 64-bit host downloaded on March 4, 2021. A screenshot of the GitHub page is shown below in Figure 11.
![A screenshot of the Jailbreak GitHub page taken on March 4 shows the Jailbreak binaries we downloaded.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/03/word-image-132.png) Figure 11. GitHub page for Jailbreak binaries.

After we downloaded the Jailbreak binaries, we opened a Command prompt with administrator privileges as shown below in Figure 12.
![The large black arrow indicates how to open a Command prompt with administrator privileges.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/03/word-image-133.png) Figure 12. Opening a command prompt as an administrator.

In the command prompt, we went to the directory with the downloaded Jailbreak binaries. We ran the following command from this directory:

* jailbreak64.exe %WINDIR%\\system32\\mmc.exe %WINDIR%\\system32\\certlm.msc -64

If we were running a 32-bit version of Windows, we would use:

* jailbreak32.exe %WINDIR%\\system32\\mmc.exe %WINDIR%\\system32\\certlm.msc -32

See Figure 13 below for an example of running the 64-bit command on our Windows host acting as the RDP server.
![The screenshot shows an example of running the 64-bit command on our Windows host acting as the RDP server.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/03/word-image-134.png) Figure 13. Running Jailbreak from the command prompt.

This command opened the certificate manager for our local machine. From the left column, we expanded ***Remote Desktop*** and went to the ***Certificates*** folder. This showed one certificate. If there had been more than one certificate, we would have selected the one with the most recent expiration date. We right-clicked on the certificate, selected ***All Tasks*** then used ***Export*** as shown below in Figure 14.
![We right-clicked on the certificate, selected All Tasks then used Export as shown.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/03/word-image-135.png) Figure 14. Exporting the RDP certificate.

When exporting the certificate, we made sure to select the option to export the private key as shown below in Figure 15.
![The screenshot reads: "Export Private Key: You can choose to export the private key with the certificate. Private keys are password protected. If you want to export the private key with the certificate, you must type a password on a later page. Do you want to export the private key with the certificate?" The large black arrow shows what to select to ensure the private key is exported with the certificate.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/03/word-image-136.png) Figure 15. Ensuring the private key is exported with the certificate.

For our host, we could only export the certificate as a PKCS #12 (.PFX) file as shown below in Figure 16.
![For the host used in this tutorial on decrypting RDP traffic in Wireshark, we could only export the certificate as a PKCS #12 (.PFX) file, as shown.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/03/word-image-137.png) Figure 16. Could only export the certificate as a .pfx file.

As shown below in Figure 17, the certificate had to have a password. Fortunately, we had no complexity requirements, so we used a single letter as the password.
![As shown, the certificate had to have a password. Because we had not complexity requirements, we used a single letter as the password.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/03/word-image-138.png) Figure 17. The export process required a password for the certificate.

Finally, we exported our certificate with the private key as shown below in Figure 18.
![We exported our certificate with the private key as shown.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/03/word-image-139.png) Figure 18. Completing our certificate export.

As an alternative, we could have extracted the server's certificate using Mimikatz instead of Jailbreak. The instructions for using Mimikatz to get the RDP server certificate are listed on [GitHub](https://github.com/FreeRDP/FreeRDP/wiki/Mimikatz).

Since our certificate was obtained using Jailbreak, we moved it to a Linux host and used OpenSSL to extract the key. First, we used the following OpenSSL command to extract the key in PEM format:

* openssl pkcs12 -in server\_certificate.pfx -nocerts -out server\_key.pem -nodes

To remove the passphrase form the key, we also used the following command:

* openssl rsa -in server\_key.pem -out server.key

This provided us with the RDP server's private key as shown below in Figure 19.
![The black arrow and label "private key" indicate where the private server key was extracted from the certificate.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/03/word-image-140.png) Figure 19. Private server key extracted from the certificate.

Before we could use the private server key, we needed to record an RDP session between our two Windows hosts and save it as a pcap.

#### Step 4: Capture RDP Traffic

With our two Windows hosts in the same virtual environment, we could use a tool like [dumpcap](https://www.wireshark.org/docs/man-pages/dumpcap.html), [tcpdump](https://www.tcpdump.org/) or Wireshark itself to record network traffic in the VLAN using promiscuous mode. Once the recording started, our WIndows client used RDP to log in to the other Windows host acting as an RDP server. The host name of the server was ***DESKTOP-USER1PC***.
![The screenshot shows how our Windows client used RDP to log in to the other Windows host acting as an RDP server.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/03/word-image-141.png) Figure 20. Using the Remote Desktop Connection tool to log into our RDP server.

While the pcap was being recorded, we logged into ***DESKTOP-USER1PC*** and performed some basic tasks like opening documents and web browsing.
![While the pcap was being recorded, we logged in to DESKTOP-USER1PC and performed some basic tasks, such as opening documents and web browsing.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/03/word-image-142.png) Figure 21. Performing some common desktop tasks through RDP.

After a minute or so, we logged off RDP and stopped recording network traffic from our VLAN.

#### Step 5: Open the pcap in Wireshark

We opened the pcap of our RDP session in Wireshark. When filtering on ***rdp*** in our Wireshark display filter, we saw no results because the RDP traffic was encrypted. Figure 22 shows the blank column display we saw when filtering for RDP in our pcap.
![Because RDP traffic was encrypted, we see a blank column display, as shown, when filtering for RDP in our pcap.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/03/word-image-143.png) Figure 22. Filtering for RDP information, but no results, due to encrypted RDP traffic.

However, when we used our private server key to decrypt RDP traffic in Wireshark, the results looked much different.

#### Step 6: Load the Key in Wireshark

In the pcaps we recorded, the RDP server ***DESKTOP-USER1PC*** was at IP address ***10.3.4.138***, and RDP traffic took place over TCP port 3389. We needed this information to properly decrypt RDP traffic in Wireshark.

In Wireshark, we used the Preferences window and expanded the ***Protocols*** section as shown below in Figure 23.
![For decrypting RDP traffic in Wireshark, we need IP address and port information. In Wireshark, we used the Preferences window and expanded the Protocols section as shown.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/03/word-image-144.png) Figure 23. Getting to the Protocols section of Wireshark's preferences menu.

With Wireshark 3.x, use the ***TLS*** entry. If you are using Wireshark 2.x, use the ***SSL*** entry. For this section, there should be a button to edit the ***RSA keys list***. We clicked the button and added the IP address of the RDP server, the RDP port (3389) and the location of the private key file. Our example is shown below in Figure 24.
![We clicked the button and added the IP address of the RDP server, the RDP port (3389) and the location of the private key file.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/03/word-image-145.png) Figure 24. Go to the TLS section and add the private key to the RSA keys list.

After Wireshark was set up to decrypt RDP traffic, we had much better results when reviewing the pcap.

#### Step 7: Examine RDP Data

After our key was loaded, our column display was no longer blank when filtering for RDP. We had several results as shown below in Figure 25.
![After our key was loaded, decrypting RDP traffic became possible. The screenshot shows that our column display was no longer blank when filtering for RDP.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/03/word-image-146.png) Figure 25. Viewing the same RDP activity after the private key was loaded in Wireshark.

For security professionals who write signatures to find RDP vulnerabilities and attacks, the type of information revealed above in Figure 25 is critical to their work.

## Conclusion

This blog reviewed how to establish an environment to decrypt traffic from an RDP session. This is easiest to do in a virtual LAN with two hosts running Windows 10 Professional. After ensuring the client did not use any forward secrecy ciphers, we extracted the private key from our Windows host acting as the RDP server. Then we easily recorded a pcap of network traffic. After the session finished, we were able to decrypt RDP traffic using the server's private key.

This type of environment can help security professionals when writing signatures to detect RDP vulnerabilities and attacks.

For more help with Wireshark, see our previous tutorials:

* [Wireshark Tutorial: Examining Emotet Infection Traffic](https://unit42.paloaltonetworks.com/wireshark-tutorial-emotet-infection/)
* [Changing Your Column Display](https://unit42.paloaltonetworks.com/unit42-customizing-wireshark-changing-column-display/)
* [Display Filter Expressions](https://unit42.paloaltonetworks.com/using-wireshark-display-filter-expressions/)
* [Identifying Hosts and Users](https://unit42.paloaltonetworks.com/using-wireshark-identifying-hosts-and-users/)
* [Exporting Objects from a Pcap](https://unit42.paloaltonetworks.com/using-wireshark-exporting-objects-from-a-pcap/)
* [Examining Trickbot Infections](https://unit42.paloaltonetworks.com/wireshark-tutorial-examining-trickbot-infections/)
* [Examining Ursnif Infections](https://unit42.paloaltonetworks.com/wireshark-tutorial-examining-ursnif-infections/)
* [Examining Qakbot Infections](https://unit42.paloaltonetworks.com/tutorial-qakbot-infection/)
* [Decrypting HTTPS Traffic](https://unit42.paloaltonetworks.com/wireshark-tutorial-decrypting-https-traffic/)
* [Examining Dridex Infection Traffic](https://unit42.paloaltonetworks.com/wireshark-tutorial-dridex-infection-traffic/)
  Back to top

### Tags

* [RDP](https://unit42.paloaltonetworks.com/tag/rdp/ "RDP")
* [Windows](https://unit42.paloaltonetworks.com/tag/windows/ "Windows")
* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")
* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Threat Assessment: Matrix Ransomware](https://unit42.paloaltonetworks.com/matrix-ransomware/ "Threat Assessment: Matrix Ransomware")

### Table of Contents

* 

### Related Articles

* [How We Added WebAuthn to a Browser-Based RDP Client](https://unit42.paloaltonetworks.com/webauthn-added-to-browser-based-rdp/ "article - table of contents")
* [01flip: Multi-Platform Ransomware Written in Rust](https://unit42.paloaltonetworks.com/new-ransomware-01flip-written-in-rust/ "article - table of contents")
* [You Thought It Was Over? Authentication Coercion Keeps Evolving](https://unit42.paloaltonetworks.com/authentication-coercion/ "article - table of contents")

## Related Cybersecurity Tutorials Resources

![A Black man in business attire using a tablet, with illuminated skyscrapers in the background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/01_Tutorial_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) March 1, 2024 [#### Wireshark Tutorial: Exporting Objects From a Pcap](https://unit42.paloaltonetworks.com/using-wireshark-exporting-objects-from-a-pcap/)

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")

* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/using-wireshark-exporting-objects-from-a-pcap/ "Wireshark Tutorial: Exporting Objects From a Pcap")  
  ![A man wearing headphones with a microphone is focused on multiple computer screens displaying graphs and data, indicating involvement in a professional tech or analytics environment.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/02_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) October 10, 2023 [#### Wireshark Tutorial: Identifying Hosts and Users](https://unit42.paloaltonetworks.com/using-wireshark-identifying-hosts-and-users/)

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")

* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/using-wireshark-identifying-hosts-and-users/ "Wireshark Tutorial: Identifying Hosts and Users")  
  ![An abstract illustration of a video that has been paused. It includes a red progress bar and a large white Play button.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/03_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) September 8, 2023 [#### Wireshark Tutorial: Display Filter Expressions](https://unit42.paloaltonetworks.com/using-wireshark-display-filter-expressions/)

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")

* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/using-wireshark-display-filter-expressions/ "Wireshark Tutorial: Display Filter Expressions")  
  ![A person focuses intently on a screen, with many lines of code on the monitor reflected in their glasses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/04_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) September 1, 2023 [#### RedLine Stealer: Answers to Unit 42 Wireshark Quiz](https://unit42.paloaltonetworks.com/wireshark-quiz-redline-stealer-answers/)

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")

* [Redline infostealer](https://unit42.paloaltonetworks.com/tag/redline-infostealer/ "Redline infostealer")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/wireshark-quiz-redline-stealer-answers/ "RedLine Stealer: Answers to Unit 42 Wireshark Quiz")  
  ![A man wearing headphones with a microphone is focused on multiple computer screens displaying graphs and data, indicating involvement in a professional tech or analytics environment.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/02_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) August 31, 2023 [#### Wireshark Tutorial: Changing Your Column Display](https://unit42.paloaltonetworks.com/unit42-customizing-wireshark-changing-column-display/)

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")

* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/unit42-customizing-wireshark-changing-column-display/ "Wireshark Tutorial: Changing Your Column Display")  
  ![Person wearing glasses and a hoodie, sitting in a dimly lit room, focused on a computer screen displaying complex data visualizations.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/06_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) August 18, 2023 [#### Crossing the Line: Unit 42 Wireshark Quiz for RedLine Stealer](https://unit42.paloaltonetworks.com/wireshark-quiz-redline-stealer/)

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Redline infostealer](https://unit42.paloaltonetworks.com/tag/redline-infostealer/ "Redline infostealer")

* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/wireshark-quiz-redline-stealer/ "Crossing the Line: Unit 42 Wireshark Quiz for RedLine Stealer")  
  ![A man wearing headphones with a microphone is focused on multiple computer screens displaying graphs and data, indicating involvement in a professional tech or analytics environment.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/02_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) May 30, 2023 [#### Cold as Ice: Answers to Unit 42 Wireshark Quiz for IcedID](https://unit42.paloaltonetworks.com/wireshark-quiz-icedid-answers/)

* [Banking trojans](https://unit42.paloaltonetworks.com/tag/banking-trojans/ "banking trojans")

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/wireshark-quiz-icedid-answers/ "Cold as Ice: Answers to Unit 42 Wireshark Quiz for IcedID")  
  ![A woman is intently working on a computer in a modern office environment, surrounded by screens displaying dynamic digital data and stock market numbers, highlighting a focus on financial analysis.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/04_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) May 26, 2023 [#### Cold as Ice: Unit 42 Wireshark Quiz for IcedID](https://unit42.paloaltonetworks.com/wireshark-quiz-icedid/)

* [Banking trojans](https://unit42.paloaltonetworks.com/tag/banking-trojans/ "banking trojans")

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/wireshark-quiz-icedid/ "Cold as Ice: Unit 42 Wireshark Quiz for IcedID")  
  ![Two people working in a modern office environment with one person concentrating on a computer screen displaying code while another person works in the background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/10_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) May 15, 2023 [#### It's All in the Name: How Unit 42 Defines and Tracks Threat Adversaries](https://unit42.paloaltonetworks.com/from-activity-to-formal-naming/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/ "Advanced Persistent Threat")

* [Nomenclature](https://unit42.paloaltonetworks.com/tag/nomenclature/ "nomenclature")

* [Threat actors](https://unit42.paloaltonetworks.com/tag/threat-actors/ "threat actors")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/from-activity-to-formal-naming/ "It’s All in the Name: How Unit 42 Defines and Tracks Threat Adversaries")  
  ![A Black man in business attire using a tablet, with illuminated skyscrapers in the background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/01_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) March 27, 2023 [#### Finding Gozi: Answers to Unit 42 Wireshark Quiz, March 2023](https://unit42.paloaltonetworks.com/march-wireshark-gozi-answers/)

* [Gozi](https://unit42.paloaltonetworks.com/tag/gozi/ "Gozi")

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/march-wireshark-gozi-answers/ "Finding Gozi: Answers to Unit 42 Wireshark Quiz, March 2023")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
