Why does reaching a host by RDP leave the operator's credential on that host, while remote service creation or WMI does not?
answer
- some logons leave more behind
- interactive versus network logon
- RemoteInteractive caches on the target
- RDP burns the credential per host
basics
~10 sRDP is an interactive logon, which materialises the account's reusable secrets in memory on the target. Service creation and WMI use a network logon that authenticates and runs without leaving reusable credential material behind.
solid answer
~40 sRDP produces an interactive (RemoteInteractive) logon on the destination — logon type 10 — and an interactive logon caches the account's reusable secrets in memory on that host so the desktop session can use them. Anyone who later controls that host can steal them from there. Remote service creation over the admin share and WMI use a network logon (type 3), which proves the credential and runs the code without depositing reusable secrets on the target. So an operator who RDPs to 900 tills has put a stealable copy of the credential on 900 hosts, while one who uses non-interactive channels has not. This is why a competent operator refuses the easiest, most familiar channel: it is the most self-exposing.
code
text · 7 lines# RDP session to the target -> an interactive class logon:
Logon Type: 10 (RemoteInteractive)
-> account's reusable secrets materialised in memory on the target
# Remote service-create / WMI to the same target -> a network logon:
Logon Type: 3 (Network)
-> authenticates, runs, leaves no reusable secret in memory (by default)go deeper
Know that RDP logs you in interactively while service-create and WMI do not, and that this affects what stays on the target.
Explain that an interactive (type 10) logon materialises reusable secrets on the destination while a network (type 3) logon does not, by default.
Reason about the scale consequence: RDP to a whole fleet deposits a stealable credential copy on every host, so a good operator avoids it.
Weigh the operational reality that interactive access is sometimes required, and where standing interactive rights across an estate are the real exposure to argue down.
## Not all remote logons cost the same Every one of the estate's remote-admin channels authenticates the operator, but they do not all leave the same thing behind on the destination. The difference is the **logon type** each one produces, and it decides whether the operator's own credential ends up sitting on the target for someone else to take. ## Interactive versus network logon Windows classifies logons by type. Two matter here: - **Interactive / RemoteInteractive (RDP) — logon type 10.** This draws a desktop session for the account. To run that session, the host materialises the account's **reusable secrets** in memory. They stay resident for the life of the session. - **Network — logon type 3.** Used by the admin-share service-create and by WMI. It proves the credential to the target and runs the requested code, but it does **not** cache the account's reusable secrets on that host by default. So the same credential, used two different ways against the same host, leaves two very different residues. ## The reflexive cost Call it the reflexive cost: **the easy channel bites the operator back.** An interactive logon deposits a reusable copy of the credential on the target. If that host is later controlled by anyone else — a rival intruder, or the defenders — the credential can be lifted from memory and reused. This is trivial at one host and decisive at scale. Reaching 900 tills by RDP means 900 hosts now each hold a stealable copy of the operator's credential. Reaching the same 900 by a network-logon channel keeps the credential's exposure at the source. A publicity-deadline crew that wants simultaneous reach and a patient crew that wants dwell both have the same reason to avoid RDP here: it multiplies their own exposure by the size of the fleet. ```text # RDP session to the target -> an interactive class logon on that host: Logon Type: 10 (RemoteInteractive) -> account's reusable secrets are materialised in memory on the target # Remote service-create / WMI to the same target -> a network logon: Logon Type: 3 (Network) -> authenticates, runs, leaves no reusable secret in memory (by default) ``` ## The caveats that keep the claim honest 'Network logon leaves nothing reusable' is a strong default, not an absolute. Configuration can change it: unconstrained delegation can forward the credential, cached-credential settings can retain material, and a channel that deliberately stores a secret for later reuse exposes it too. The safe framing is that a network logon does **not** cache reusable secrets by default, whereas an interactive logon does — so the choice of channel changes the operator's own attack surface, and a good operator treats RDP as the self-exposing option it is. ## Why interviewers ask it The naive answer picks RDP because it is the most familiar and 'feels' safe because the session is encrypted. Encryption protects the wire, not the credential resident on the target. The point being tested is whether you understand that the channel you pick determines what you leave behind on every host you touch.
- Why does this matter more across 900 hosts than against one?Each interactive logon deposits a reusable copy of the credential on that host, so RDP to every till multiplies the theft surface by the fleet size. A network-logon channel keeps the credential's exposure at the source. Pursuing simultaneous reach through the interactive channel is self-defeating.
- Is a network logon guaranteed to leave nothing reusable on the target?No. Unconstrained delegation, cached-credential settings, or a channel that stores a secret for reuse can still expose material. The default network logon does not cache reusable secrets, but configuration can change that, so treat 'non-interactive' as a strong default rather than an absolute.
saying these in an interview costs you the question
- Thinks all remote channels expose the credential equally
- Believes RDP is safest because the session is encrypted
- Assumes a network logon never leaves any credential material