域渗透:mstsc连接记录清理

参考文章:https://p-3a0x.tower.im/p/39pu

rem clear all
reg delete "HKEY_CURRENT_USERSoftwareMicrosoftTerminal Server ClientDefault" /va /f
reg delete "HKEY_CURRENT_USERSoftwareMicrosoftTerminal Server ClientLocalDevices" /va /f
reg delete "HKEY_CURRENT_USERSoftwareMicrosoftTerminal Server ClientServers" /f
(ver | find "5.1") && (del /a /f /q "%USERPROFILE%My DocumentsDefault.rdp") || (del /a /f /q "%USERPROFILE%DocumentsDefault.rdp")

rem backup
mkdir cache
attrib +h +s cache
reg export "HKEY_CURRENT_USERSoftwareMicrosoftTerminal Server ClientDefault" cacheDefault.reg
reg export "HKEY_CURRENT_USERSoftwareMicrosoftTerminal Server ClientLocalDevices" cacheLocalDevices.reg
reg export "HKEY_CURRENT_USERSoftwareMicrosoftTerminal Server ClientServers" cacheServers.reg
(ver | find "5.1") && (xcopy /c /q /y /h "%USERPROFILE%My DocumentsDefault.rdp" cacheDefault.rdp) || (xcopy /c /q /y /h "%USERPROFILE%DocumentsDefault.rdp" cacheDefault.rdp)

rem restore
reg import cacheDefault.reg
reg import cacheLocalDevices.reg
reg import cacheServers.reg
(ver | find "5.1") && (xcopy /c /q /y /h cacheDefault.rdp "%USERPROFILE%My DocumentsDefault.rdp") || (xcopy /c /q /y /h cacheDefault.rdp "%USERPROFILE%DocumentsDefault.rdp")
rmdir /s /q cache
原文地址:https://www.cnblogs.com/zpchcbd/p/12128709.html