RDP Event ID 39: Session disconnected by another session
- Event ID
- 39
- Channel
- Microsoft-Windows-TerminalServices-LocalSessionManager/Operational
- Provider
- Microsoft-Windows-TerminalServices-LocalSessionManager
- Log file
- Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx
- Category
- Remote access
- Default logging
- Logged by default
What event 39 means
Event 39 is logged when a session is disconnected by an action taken from a different session — for example an administrator using Task Manager or tscon to connect to someone else's session, or a user logging on again and taking over their own existing session.
It names both sessions: the one that was disconnected and the session that caused it. On servers where users do not share accounts, a session being disconnected by a different user's session is unusual and worth checking against RDP hijacking.
When it is logged
None — the LocalSessionManager/Operational channel is enabled by default.
Key fields
| Field | What it tells you |
|---|---|
| TargetSession | Session that was disconnected. |
| Source | Session that initiated the disconnect. |
Common benign sources
- A user reconnecting from a new device, which disconnects their previous connection.
- Administrators taking over a session for support.
What attackers do that produces it
- RDP session hijacking — running
tscon <id>as SYSTEM to attach to another user's disconnected session without their password.
Investigation tips
- Map both session numbers to users with events 21/25 and check whether they belong to the same account.
- Look for
tscon.exein process creation logs (4688, Sysmon 1) at the same time, especially run as SYSTEM.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1563.002 Remote Service Session Hijacking: RDP Hijacking | Lateral Movement |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.