Welcome to mRDPf’s documentation!

Command Line Interface

usage: mrdpf_cli [-h] (-d DIR | -f FILE) -o OUT [--no-recurse] [--clear]

Named Arguments

-d, --dir

Directory to search for compatible files

-f, --file

File to parse

-o, --out

Folder to write results to

--no-recurse

Do not recurse. If input option is not –dir this option is ignored.

Default: False

--clear

Clear output directory before writing results (will delete all files below out directory)

Default: False

Command Line Interface - Documentation

Classes:

DataclassJSONEncoder(*[, skipkeys, …])

Parsers

An enumeration.

Functions:

colored(text[, color, on_color, attrs])

Colorize text.

cprint(text[, color, on_color, attrs])

Print colorize text.

create_dir(path)

Create directory at path.

create_file(path, name, extension)

Create file with name and extension at given base path.

get_parser()

Create argument parser

write_data(path, name, extension, data)

Write a list of dataclasses to a CSV file at given path with name and extension.

write_dataclass_list_to_csv(path, data)

Write a list of dataclasses to a CSV file at path

write_dataframe(path, name, extension, data)

Write a pandas dataframe to a CSV file at path with name and extension.

mrdpf_cli.create_dir(path)[source]

Create directory at path. Returns path to created directory.

If a directory already exists at the provided path, a number will be appended until the directory does not exist.

mrdpf_cli.create_file(path, name, extension)[source]

Create file with name and extension at given base path.

If a file with the given name and extension already exists, a number will be appended until a file does not exist.

Returns

Path to created file

mrdpf_cli.get_parser()[source]

Create argument parser

mrdpf_cli.write_data(path, name, extension, data)[source]

Write a list of dataclasses to a CSV file at given path with name and extension.

Returns

Path to created file or None if data is empty

mrdpf_cli.write_dataclass_list_to_csv(path: str, data: list)[source]

Write a list of dataclasses to a CSV file at path

mrdpf_cli.write_dataframe(path, name, extension, data)[source]

Write a pandas dataframe to a CSV file at path with name and extension.

Returns

Path to created file or None if data is empty

Parsers

Classes:

AppSupportDbParser(path)

Parses the com.microsoft.rdc.application-data.sqlite database

Bookmark(pk, ent, opt, friendly_name, …)

Models rows in the ZBOOKMARKENTITY table of the com.microsoft.rdc.application-data.sqlite SQLite database

BookmarkOrder(pk, ent, opt, root)

Models rows in the ZBOOKMARKORDERENTITY table of the com.microsoft.rdc.application-data.sqlite SQLite database

ClientFolderRedirectionEntity(readOnly, …)

Models ClientFolderRedirectionEntity PLIST class

Enum

Generic enumeration.

Metadata(version, uuid, data)

Models rows in the Z_METADATA table of the com.microsoft.rdc.application-data.sqlite SQLite database

OfflineStorageHighParser(path)

Parses the offlinestorageHigh.dat file

Parsers

An enumeration.

Preferences(…)

Models the com.microsoft.rdc.macos.plist binary plist file

PreferencesPlistParser(path)

Parses the com.microsoft.rdc.macos.plist file

UserIdHistoryInfo(userIdKey, timestampKey)

Models UserIdHistory PLIST class

datetime(year, month, day[, hour[, minute[, …)

The year, month and day arguments are required.

Functions:

b64decode(s[, altchars, validate])

Decode the Base64 encoded bytes-like object or ASCII string s.

b64encode(s[, altchars])

Encode the bytes-like object s using Base64 and return a bytes object.

dataclass([cls, init, repr, eq, order, …])

Returns the same class as was passed in, with dunder methods added based on the fields defined in the class.

dataclass_json([_cls, letter_case, undefined])

Based on the code in the dataclasses module to handle optional-parens decorators.

decode_plist(data[, format])

Decode byte string into dictionary using provided format.

read_bplist(path)

Read binary plist from file at path.

read_nskeyedarchive(data)

Decode binary string encoded using NSKeyedArchiver.

class mrdpf.parsers.AppSupportDbParser(path)[source]

Bases: mrdpf.parsers.BaseParser

Parses the com.microsoft.rdc.application-data.sqlite database

Methods:

parse()

Parse data from file

parse()[source]

Parse data from file

Returns

Returns a reference to the parser

Return type

AppSupportDbParser

class mrdpf.parsers.Bookmark(pk: str, ent: str, opt: str, friendly_name: str, hostname: str, zid: str, rdp_string: str, folder_redirection_config: mrdpf.io.plist.ClientFolderRedirectionEntity, last_connected: datetime.datetime, redirect_camera: bool, redirect_folders: bool, redirect_clipboard: bool, redirect_printers: bool, redirect_smartcard: bool, bookmark_folder: int, fok_bookmark_folder: int, credential: int, gateway: int, creation_source: str, authoring_tool: str, admin_mode: bool, audio_capture_enabled: bool, audio_playback: str, auto_reconnect_enabled: bool, color_depth: int, dynamic_resolution_enabled: bool, retina_enabled: bool, input_mode: str, use_all_monitors: bool, screen_type: str, screen_type_height: int, screen_type_width: int, screen_type_resolution: int, screen_type_scale: bool, swap_mouse_button: bool)[source]

Bases: object

Models rows in the ZBOOKMARKENTITY table of the com.microsoft.rdc.application-data.sqlite SQLite database

class mrdpf.parsers.BookmarkOrder(pk: int, ent: int, opt: int, root: str)[source]

Bases: object

Models rows in the ZBOOKMARKORDERENTITY table of the com.microsoft.rdc.application-data.sqlite SQLite database

class mrdpf.parsers.Metadata(version: int, uuid: str, data: str)[source]

Bases: object

Models rows in the Z_METADATA table of the com.microsoft.rdc.application-data.sqlite SQLite database

class mrdpf.parsers.OfflineStorageHighParser(path)[source]

Bases: mrdpf.parsers.BaseParser

Parses the offlinestorageHigh.dat file

Methods:

parse()

Parse data from file

parse()[source]

Parse data from file

Returns

Returns a reference to the parser

Return type

OfflineStorageHighParser

class mrdpf.parsers.Parsers[source]

Bases: enum.Enum

An enumeration.

class mrdpf.parsers.Preferences(telemetry_previous_send_diagnostics: bool, nswindow_frame_mainwindow: str, kms_analytics_is_enabled: bool, removed_home_folder_redirection: bool, telemetry_previous_daily_events_time: datetime.datetime, user_id_history: {}, past_devices_key: {}, first_run_experience_launched_version: str, telemetry_device_id: str, ms_install_id: str, telemetry_previous_app_launch_version: str, session_id_history: {})[source]

Bases: object

Models the com.microsoft.rdc.macos.plist binary plist file

class mrdpf.parsers.PreferencesPlistParser(path)[source]

Bases: mrdpf.parsers.BaseParser

Parses the com.microsoft.rdc.macos.plist file

Methods:

parse()

Parse data from file

parse() → mrdpf.parsers.Preferences[source]

Parse data from file

Returns

Returns a reference to the parser

Return type

PreferencesPlistParser

Core

Classes:

AppSupportDbParser(path)

Parses the com.microsoft.rdc.application-data.sqlite database

OfflineStorageHighParser(path)

Parses the offlinestorageHigh.dat file

ParsedResult(path, data)

Parsers

An enumeration.

PreferencesPlistParser(path)

Parses the com.microsoft.rdc.macos.plist file

Functions:

dataclass([cls, init, repr, eq, order, …])

Returns the same class as was passed in, with dunder methods added based on the fields defined in the class.

class mrdpf.core.ParsedResult(path: str, data: object)[source]

Parser Definitions

Data:

OFFLINE_STORAGE_PARAMETERS

Defines parameters extracted from offlinestorageHigh.dat by OfflineStorageHighParser

mrdpf.parser_definitions.OFFLINE_STORAGE_PARAMETERS = [b'AppInfo.Id', b'AppInfo.Language', b'AppInfo.Version', b'DeviceInfo.Id', b'DeviceInfo.Make', b'DeviceInfo.Model', b'DeviceInfo.NetworkType', b'DeviceInfo.OsBuild', b'DeviceInfo.OsName', b'DeviceInfo.OsVersion', b'DeviceInfo.SDKUid', b'EventInfo.InitId', b'EventInfo.Name', b'EventInfo.SdkVersion', b'EventInfo.Sequence', b'EventInfo.Source', b'EventInfo.Time', b'S_e', b'S_j', b'S_k', b'S_p', b'S_t', b'S_v', b'TenantId', b'UserInfo.Id', b'UserInfo.Language', b'UserInfo.TimeZone', b'eventpriority', b'records_received_count', b'high_priority_records_sent_count', b'high_priority_records_tried_to_send_count', b'n_r_count', b'n_r_inv', b'normal_priority_records_received_count', b'r_count', b'r_inv', b'high_priority_records_received_count', b'records_sent_count', b'records_tried_to_send_count', b'AppLifeCycle.State', b'Session.Duration', b'Session.DurationBucket', b'Session.FirstLaunchTime', b'Session.Id', b'Session.State', b'h_inol', b'inol', b'h_inq']

Defines parameters extracted from offlinestorageHigh.dat by OfflineStorageHighParser

Helpers

Classes:

DataclassJSONEncoder(*[, skipkeys, …])

class mrdpf.helpers.DataclassJSONEncoder(*, skipkeys=False, ensure_ascii=True, check_circular=True, allow_nan=True, sort_keys=False, indent=None, separators=None, default=None)[source]

Methods:

default(obj)

Implement this method in a subclass such that it returns a serializable object for o, or calls the base implementation (to raise a TypeError).

default(obj)[source]

Implement this method in a subclass such that it returns a serializable object for o, or calls the base implementation (to raise a TypeError).

For example, to support arbitrary iterators, you could implement default like this:

def default(self, o):
    try:
        iterable = iter(o)
    except TypeError:
        pass
    else:
        return list(iterable)
    # Let the base class default method raise the TypeError
    return JSONEncoder.default(self, o)

I/O - General

Classes:

Parsers

An enumeration.

Path

PurePath subclass that can make system calls.

I/O - PLIST

Classes:

BookmarkOrderItemEntity(id, children)

Models BookmarkOrderItemEntity PLIST class

ClientFolderRedirectionEntity(readOnly, …)

Models ClientFolderRedirectionEntity PLIST class

DataclassArchiver

Helper to easily map python dataclasses (PEP557) to archived objects.

Device(model, sdkVersion, osBuild, …)

Models Device PLIST class

DeviceHistoryInfo(deviceKey, timestampKey)

Models DeviceHistoryInfo PLIST class

SessionHistoryInfo(sessionIdKey, timestampKey)

Models SessionHistoryInfo PLIST class

UserIdHistoryInfo(userIdKey, timestampKey)

Models UserIdHistory PLIST class

datetime(year, month, day[, hour[, minute[, …)

The year, month and day arguments are required.

Functions:

dataclass_json([_cls, letter_case, undefined])

Based on the code in the dataclasses module to handle optional-parens decorators.

decode_plist(data[, format])

Decode byte string into dictionary using provided format.

read_bplist(path)

Read binary plist from file at path.

read_nskeyedarchive(data)

Decode binary string encoded using NSKeyedArchiver.

read_plist(path)

Read plaintext XML plist from file at path.

class mrdpf.io.plist.BookmarkOrderItemEntity(id: str, children: list)[source]

Models BookmarkOrderItemEntity PLIST class

class mrdpf.io.plist.ClientFolderRedirectionEntity(readOnly: bool, path: str, name: str, id: str)[source]

Models ClientFolderRedirectionEntity PLIST class

class mrdpf.io.plist.Device(model: str, sdkVersion: str, osBuild: str, appVersion: str, timeZoneOffset: str, osVersion: str, locale: str, liveUpdatePackageHash: str, liveUpdateReleaseLabel: str, liveUpdateDeploymentKey: str, osApiLevel: str, wrapperRuntimeVersion: str, wrapperSdkVersion: str, carrierCountry: str, appNamespace: str, sdkName: str, appBuild: str, wrapperSdkName: str, screenSize: str, osName: str, carrierName: str, oemName: str)[source]

Models Device PLIST class

class mrdpf.io.plist.DeviceHistoryInfo(deviceKey: str, timestampKey: str)[source]

Models DeviceHistoryInfo PLIST class

class mrdpf.io.plist.SessionHistoryInfo(sessionIdKey: str, timestampKey: str)[source]

Models SessionHistoryInfo PLIST class

class mrdpf.io.plist.UserIdHistoryInfo(userIdKey: str, timestampKey: str)[source]

Models UserIdHistory PLIST class

mrdpf.io.plist.decode_plist(data: bytes, format: plistlib.PlistFormat = <PlistFormat.FMT_BINARY: 2>) → dict[source]

Decode byte string into dictionary using provided format.

Returns

Parsed PLIST

Rtye

dict

mrdpf.io.plist.read_bplist(path: str) → dict[source]

Read binary plist from file at path.

Returns

Parsed PLIST

Rtye

dict

mrdpf.io.plist.read_nskeyedarchive(data: bytes) → dict[source]

Decode binary string encoded using NSKeyedArchiver.

Returns

Parsed PLIST

Rtye

dict

mrdpf.io.plist.read_plist(path: str) → dict[source]

Read plaintext XML plist from file at path.

Returns

Parsed PLIST

Rtye

dict