Original: www.safe3.cn. for reprinting, please indicate the source
@ Echo off
Setlocal enabledelayedexpansion
Date/T> C: \ WINDOWS \ 3389log.txt
Set lflag = nolog
Set rip = 0.0.0.0
: Ts3389
Ping-N 10-W 500 0.0.0.1> NUL
For/F "tokens = 4 delims =:" % A in ('netstat-an ^ | find "3389" ^ | find "established "') do set lrip = %
If "% lrip %" = "! Rip! "Goto: ts3389
Netstat-an | find "3389" | find "established" & set lflag = Log
If "% lflag %" = "log "(
For/F "tokens = 4 delims =:" % A in ('netstat-an ^ | find "3389" ^ | find "established "') do set rip = %
Set lflag = nolog
Time/T> C: \ WINDOWS \ 3389log.txt
Netstat-an | find "3389" | find "established"> C: \ WINDOWS \ 3389log.txt
)
Goto: ts3389
Windows has no security record for the time and IP address of Remote Desktop login, so a batch is written. By default, logs are saved to c: \ windows \ 3389log.txt.
The monitoring port is 3389. If you are interested, change it as needed!