From e96131d72259837d06b993af6aea3ccd9d71d040 Mon Sep 17 00:00:00 2001 From: Andrey Lutsenko Date: Sun, 3 May 2026 18:52:18 +1000 Subject: [PATCH] docs: refresh README, add English README_eng.md Document daily report, deploy marker, SkipScheduledTaskMaintenance, and legacy watchdog scripts. Add full English translation. --- README.md | 15 ++++++--- README_eng.md | 87 +++++++++++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 98 insertions(+), 4 deletions(-) create mode 100644 README_eng.md diff --git a/README.md b/README.md index 4152617..243eebd 100644 --- a/README.md +++ b/README.md @@ -1,15 +1,15 @@ -# RDP Login Monitor +# RDP Login Monitor PowerShell-набор для мониторинга входов в Windows с отправкой уведомлений в Telegram. ## Актуальная схема (рекомендуется) - Базовый путь установки: **`C:\ProgramData\RDP-login-monitor\`**. -- Основной скрипт: **`Login_Monitor.ps1`** (Security `4624/4625`, опционально RD Gateway `302/303`, heartbeat, ротация логов, уведомления). +- Основной скрипт: **`Login_Monitor.ps1`** — журнал Security **`4624`/`4625`** (логика зависит от типа ОС: рабочая станция или сервер/КД), при наличии журнала — **Remote Connection Manager `1149`** (часто актуально для РС с RDP), при роли **RD Gateway** — **`302`/`303`**, **ежедневный отчёт** в Telegram (активные сессии через `quser`), **heartbeat**, **ротация логов**, уведомления в Telegram. - Установка задач: запуск **`Login_Monitor.ps1 -InstallTasks`** создаёт: - `RDP-Login-Monitor` (основной монитор), - `RDP-Login-Monitor-Watchdog` (контроль процесса каждые 5 минут). -- Доменная доставка и обновления: **`Deploy-LoginMonitor.ps1`** + **`version.txt`** с шары `NETLOGON`. +- Доменная доставка и обновления: **`Deploy-LoginMonitor.ps1`** + **`version.txt`** с шары `NETLOGON`. После успешного деплоя в приветственном сообщении Telegram может появиться отметка об обновлении (файл **`deploy_last_update.txt`** рядом с логами). - Для полной инструкции по деплою/GPO используйте **[DEPLOY.md](DEPLOY.md)**. - **`Encrypt-DpapiForRdpMonitor.ps1`** — опционально для подготовки DPAPI-строк токена/chat id. @@ -64,7 +64,8 @@ powershell.exe -NoProfile -ExecutionPolicy Bypass -File "C:\ProgramData\RDP-logi - `C:\ProgramData\RDP-login-monitor\Logs\login_monitor.log` - `C:\ProgramData\RDP-login-monitor\Logs\watchdog.log` - Heartbeat: - - `C:\ProgramData\RDP-login-monitor\Logs\last_heartbeat.txt` обновляется примерно раз в час (по `$HeartbeatInterval`). + - `C:\ProgramData\RDP-login-monitor\Logs\last_heartbeat.txt` обновляется по интервалу **`$HeartbeatInterval`** (по умолчанию раз в час). +- Ежедневный отчёт: после первого прохождения дневного слота (по умолчанию **09:00**, задаётся **`$DailyReportHour`** / **`$DailyReportMinute`** в `Login_Monitor.ps1`) в Telegram уходит сводка по **`quser`**; метка последнего отчёта — `Logs\last_daily_report.txt`. - Telegram при старте: при установленном **RD Session Host** (или аналогичных компонентах RDS, не только шлюз) — строка про входы по RDP/RDS на этом сервере; при доступном журнале **RD Gateway** — отдельная строка про подключения к **внутренним целевым ПК** через шлюз (302/303). Узел только с ролью RD Gateway не дублирует формулировку «хост сессий». ## 5) Автоматический перезапуск при падении @@ -75,6 +76,12 @@ powershell.exe -NoProfile -ExecutionPolicy Bypass -File "C:\ProgramData\RDP-logi - если процесса нет — запускает монитор; - если монитор уже есть — не дублирует экземпляр. +## 6) Дополнительные параметры и прочие файлы + +- **`-SkipScheduledTaskMaintenance`**: при обычном запуске монитора не выполнять проверку/пересоздание задач планировщика (если регистрацию задач ведёте только через **`-InstallTasks`** или вручную). +- **`Install-DeployScheduledTask.ps1`** — helper для периодического запуска **`Deploy-LoginMonitor.ps1`** с шары (см. **[DEPLOY.md](DEPLOY.md)**). +- **`Watchdog_RDP_Monitor.ps1`** и **`Install-ScheduledTasks.ps1`** — **альтернативная** схема с отдельным watchdog-файлом и путями по умолчанию **`D:\Soft`**. Для новых установок рекомендуется встроенный режим **`-Watchdog`** в **`Login_Monitor.ps1`** и задачи **`RDP-Login-Monitor`** / **`RDP-Login-Monitor-Watchdog`**. + ## Ключевые слова (для поиска репозитория) `rdp`, `rd-gateway`, `rdp-gateway`, `rds`, `remote-desktop`, `windows-security-log`, `eventlog`, `event-id-4624`, `event-id-4625`, `event-id-302`, `event-id-303`, `powershell`, `telegram-bot`, `watchdog`, `gpo`, `netlogon`, `domain-deployment`, `windows-server`, `monitoring` diff --git a/README_eng.md b/README_eng.md new file mode 100644 index 0000000..55802a0 --- /dev/null +++ b/README_eng.md @@ -0,0 +1,87 @@ +# RDP Login Monitor + +PowerShell toolkit for monitoring Windows logons with Telegram notifications. + +## Recommended layout + +- Installation root: **`C:\ProgramData\RDP-login-monitor\`**. +- Main script: **`Login_Monitor.ps1`** — Security log **`4624`/`4625`** (behavior depends on OS type: workstation vs server/domain controller), optional **Remote Connection Manager `1149`** when the log is available (often useful for RDP-enabled workstations), **RD Gateway** events **`302`/`303`** when the gateway role/log is present, **daily report** to Telegram (active sessions via `quser`), **heartbeat**, **log rotation**, Telegram alerts. +- Scheduled tasks: run **`Login_Monitor.ps1 -InstallTasks`** to register: + - `RDP-Login-Monitor` (main monitor), + - `RDP-Login-Monitor-Watchdog` (process health check every 5 minutes). +- Domain delivery and upgrades: **`Deploy-LoginMonitor.ps1`** + **`version.txt`** on a share such as `NETLOGON`. After a successful deploy, the startup Telegram message may include an update note (file **`deploy_last_update.txt`** next to logs). +- Full deploy/GPO guidance: **[DEPLOY.md](DEPLOY.md)**. +- **`Encrypt-DpapiForRdpMonitor.ps1`** — optional helper to prepare DPAPI-protected Base64 for the bot token / chat id. + +## Notable behavior + +- **`.ps1` encoding**: `.editorconfig` and `.gitattributes` encourage **`*.ps1`** as **UTF-8 with BOM** and **CRLF**, reducing mojibake and PowerShell parse issues. +- **Log encoding**: `login_monitor.log` / `watchdog.log` are written as **UTF-8 with BOM** (BOM is applied to existing files if missing) so viewers like **FAR Manager** do not mis-detect encoding. +- **`auditpol` on Russian Windows**: auditing checks use the **`Вход/выход`** category and **`Вход в систему` / `Выход из системы`** subcategories (expect **`Успех и сбой`**), avoiding errors such as `0x00000057` when English names like `Logon` are absent on a localized OS. +- **Stability**: `auditpol` is invoked via `cmd.exe` with merged stdout/stderr so `$ErrorActionPreference = 'Stop'` does not abort on stderr-only output. + +## 1) Preparation + +1. Create the install folder: + - `C:\ProgramData\RDP-login-monitor\` +2. Copy at least: + - `Login_Monitor.ps1` + - (for domain rollout on a share) `Deploy-LoginMonitor.ps1` and `version.txt`. +3. Edit `Login_Monitor.ps1` and set the bot token / chat: + - `$TelegramBotToken` or `$TelegramBotTokenProtectedB64` + - `$TelegramChatID` or `$TelegramChatIDProtectedB64` +4. Run elevated (Security log access and task registration). +5. Logs and auxiliary files: + - `C:\ProgramData\RDP-login-monitor\Logs\` + +## 2) Manual run + +Use this to validate startup/logic without registering scheduled tasks. + +```powershell +powershell.exe -NoProfile -ExecutionPolicy Bypass -File "C:\ProgramData\RDP-login-monitor\Login_Monitor.ps1" +``` + +The monitor keeps running in the session until you stop it (for example `Ctrl+C`). + +## 3) Task Scheduler + +You do not need to create tasks manually in the GUI. + +Run: + +```powershell +powershell.exe -NoProfile -ExecutionPolicy Bypass -File "C:\ProgramData\RDP-login-monitor\Login_Monitor.ps1" -InstallTasks +``` + +The script registers `RDP-Login-Monitor` and `RDP-Login-Monitor-Watchdog`, then triggers an immediate first run. + +For domain deployment from a share you do not configure the scheduler on clients by hand — use `Deploy-LoginMonitor.ps1` (see `DEPLOY.md`). + +## 4) Post-install checks + +- Logs: + - `C:\ProgramData\RDP-login-monitor\Logs\login_monitor.log` + - `C:\ProgramData\RDP-login-monitor\Logs\watchdog.log` +- Heartbeat: + - `C:\ProgramData\RDP-login-monitor\Logs\last_heartbeat.txt` updates on **`$HeartbeatInterval`** (hourly by default). +- Daily report: after the first daily window (default **09:00**, controlled by **`$DailyReportHour`** / **`$DailyReportMinute`** in `Login_Monitor.ps1`), Telegram receives a `quser` summary; last run marker: `Logs\last_daily_report.txt`. +- Startup Telegram message: with **RD Session Host** (or broader RDS session components, not gateway-only) you get the RDS/RDP session-host line; when the **RD Gateway** log is available you get a separate line about connections to **internal targets** through the gateway (302/303). A gateway-only node does not duplicate the “session host” wording. + +## 5) Automatic restart on failure + +`-Watchdog` inside `Login_Monitor.ps1`: + +- looks for `powershell.exe` / `pwsh.exe` whose command line references `Login_Monitor.ps1`; +- if the main monitor is missing, starts it; +- if the monitor is already running, does not spawn a second instance. + +## 6) Extra parameters and other repo files + +- **`-SkipScheduledTaskMaintenance`**: during normal monitor startup, skip verification/recreation of scheduled tasks (if you manage tasks only via **`-InstallTasks`** or manually). +- **`Install-DeployScheduledTask.ps1`** — helper to run **`Deploy-LoginMonitor.ps1`** from a share on a schedule (see **[DEPLOY.md](DEPLOY.md)**). +- **`Watchdog_RDP_Monitor.ps1`** and **`Install-ScheduledTasks.ps1`** — **alternate** layout with a separate watchdog script and default paths under **`D:\Soft`**. For new installs, prefer the built-in **`-Watchdog`** in **`Login_Monitor.ps1`** and tasks **`RDP-Login-Monitor`** / **`RDP-Login-Monitor-Watchdog`**. + +## Keywords (for discovery) + +`rdp`, `rd-gateway`, `rdp-gateway`, `rds`, `remote-desktop`, `windows-security-log`, `eventlog`, `event-id-4624`, `event-id-4625`, `event-id-302`, `event-id-303`, `powershell`, `telegram-bot`, `watchdog`, `gpo`, `netlogon`, `domain-deployment`, `windows-server`, `monitoring`