RDP Event ID 25: Session reconnected
- Event ID
- 25
- Channel
- Microsoft-Windows-TerminalServices-LocalSessionManager/Operational
- Provider
- Microsoft-Windows-TerminalServices-LocalSessionManager
- Log file
- Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx
- Category
- Remote access
- Default logging
- Logged by default
What event 25 means
Event 25 records that a client reattached to a session that was disconnected (24). No new session is created, so there is no event 21 — this event and Security 4778 are the records of the reconnection.
Its Address field is the IP of the client that reconnected, which can differ from the one that originally logged on. That makes 25 essential when tracking RDP access: an attacker who reconnects to an admin's disconnected session never produces a fresh 21.
When it is logged
None — the LocalSessionManager/Operational channel is enabled by default.
Key fields
| Field | What it tells you |
|---|---|
| User | Account owning the session. |
| SessionID | Session number that was resumed. |
| Address | IP address of the reconnecting client, or LOCAL. |
Common benign sources
- Users resuming their RDP session after a disconnect or from another device.
What attackers do that produces it
- Reconnecting to a disconnected privileged session with the same credentials from another host.
- RDP session takeover, where a session is attached to a different client.
Investigation tips
- Compare Address with the one in the original 21 for the SessionID.
- Pair with the preceding 1149 (the new connection) and Security 4778 / 4624 LogonType 7 or 10.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.