RDP Event ID 24: Session disconnected
- Event ID
- 24
- Channel
- Microsoft-Windows-TerminalServices-LocalSessionManager/Operational
- Provider
- Microsoft-Windows-TerminalServices-LocalSessionManager
- Log file
- Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx
- Category
- Remote access
- Default logging
- Logged by default
What event 24 means
Event 24 records that a session was detached from its client — the RDP window was closed, the network dropped, or another client took the session over. The session keeps running on the server with its processes and credentials, so it can be picked up again (event 25).
The Address field gives the client that was connected at the time. Series of 24/25 pairs from changing addresses show a session being used from several places.
When it is logged
None — the LocalSessionManager/Operational channel is enabled by default.
Key fields
| Field | What it tells you |
|---|---|
| User | Account whose session was disconnected. |
| SessionID | Session number. |
| Address | IP address of the client that was connected, or LOCAL. |
Common benign sources
- Users closing the RDP window instead of signing out, laptops going to sleep, flaky networks.
What attackers do that produces it
- Operators leaving a session running to come back later with 25.
- Session hijacking or takeover — a disconnect followed by a reconnect of the same session from a different address or by a different session (see 39).
Investigation tips
- Follow the SessionID to the next 25 or 23; compare Address values.
- Pair with Security 4779 for the logon ID, and 40 for the disconnect reason code.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1021.001 Remote Services: Remote Desktop Protocol | Lateral Movement |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.