Skip to content
RDP LocalSessionManager

RDP Event ID 25: Session reconnected

Remote Desktop Services: Session reconnection succeededRDP event 25 is logged when a user reconnects to an existing disconnected session, with the new client address.
25
Event ID
25
Channel
Microsoft-Windows-TerminalServices-LocalSessionManager/Operational
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Log file
Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx
Category
Remote access
Default logging
Logged by default

What event 25 means

Event 25 records that a client reattached to a session that was disconnected (24). No new session is created, so there is no event 21 — this event and Security 4778 are the records of the reconnection.

Its Address field is the IP of the client that reconnected, which can differ from the one that originally logged on. That makes 25 essential when tracking RDP access: an attacker who reconnects to an admin's disconnected session never produces a fresh 21.

When it is logged

Audit policy / configuration

None — the LocalSessionManager/Operational channel is enabled by default.

Key fields

FieldWhat it tells you
UserAccount owning the session.
SessionIDSession number that was resumed.
AddressIP address of the reconnecting client, or LOCAL.

Common benign sources

  • Users resuming their RDP session after a disconnect or from another device.

What attackers do that produces it

  • Reconnecting to a disconnected privileged session with the same credentials from another host.
  • RDP session takeover, where a session is attached to a different client.

Investigation tips

  • Compare Address with the one in the original 21 for the SessionID.
  • Pair with the preceding 1149 (the new connection) and Security 4778 / 4624 LogonType 7 or 10.

MITRE ATT&CK techniques

TechniqueTactics
T1021.001 Remote Services: Remote Desktop ProtocolLateral Movement
T1563.002 Remote Service Session Hijacking: RDP HijackingLateral Movement

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading