Skip to content
RDP LocalSessionManager

RDP Event ID 24: Session disconnected

Remote Desktop Services: Session has been disconnectedRDP event 24 is logged when a Remote Desktop session is disconnected without logoff, with the user, session ID and client address.
24
Event ID
24
Channel
Microsoft-Windows-TerminalServices-LocalSessionManager/Operational
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Log file
Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx
Category
Remote access
Default logging
Logged by default

What event 24 means

Event 24 records that a session was detached from its client — the RDP window was closed, the network dropped, or another client took the session over. The session keeps running on the server with its processes and credentials, so it can be picked up again (event 25).

The Address field gives the client that was connected at the time. Series of 24/25 pairs from changing addresses show a session being used from several places.

When it is logged

Audit policy / configuration

None — the LocalSessionManager/Operational channel is enabled by default.

Key fields

FieldWhat it tells you
UserAccount whose session was disconnected.
SessionIDSession number.
AddressIP address of the client that was connected, or LOCAL.

Common benign sources

  • Users closing the RDP window instead of signing out, laptops going to sleep, flaky networks.

What attackers do that produces it

  • Operators leaving a session running to come back later with 25.
  • Session hijacking or takeover — a disconnect followed by a reconnect of the same session from a different address or by a different session (see 39).

Investigation tips

  • Follow the SessionID to the next 25 or 23; compare Address values.
  • Pair with Security 4779 for the logon ID, and 40 for the disconnect reason code.

MITRE ATT&CK techniques

TechniqueTactics
T1021.001 Remote Services: Remote Desktop ProtocolLateral Movement

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading