Skip to content
RDP LocalSessionManager

RDP Event ID 39: Session disconnected by another session

Session has been disconnected by sessionRDP event 39 records that one session was disconnected by another session, as with a session takeover or tscon.
39
Event ID
39
Channel
Microsoft-Windows-TerminalServices-LocalSessionManager/Operational
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Log file
Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx
Category
Remote access
Default logging
Logged by default

What event 39 means

Event 39 is logged when a session is disconnected by an action taken from a different session — for example an administrator using Task Manager or tscon to connect to someone else's session, or a user logging on again and taking over their own existing session.

It names both sessions: the one that was disconnected and the session that caused it. On servers where users do not share accounts, a session being disconnected by a different user's session is unusual and worth checking against RDP hijacking.

When it is logged

Audit policy / configuration

None — the LocalSessionManager/Operational channel is enabled by default.

Key fields

FieldWhat it tells you
TargetSessionSession that was disconnected.
SourceSession that initiated the disconnect.

Common benign sources

  • A user reconnecting from a new device, which disconnects their previous connection.
  • Administrators taking over a session for support.

What attackers do that produces it

  • RDP session hijacking — running tscon <id> as SYSTEM to attach to another user's disconnected session without their password.

Investigation tips

  • Map both session numbers to users with events 21/25 and check whether they belong to the same account.
  • Look for tscon.exe in process creation logs (4688, Sysmon 1) at the same time, especially run as SYSTEM.

MITRE ATT&CK techniques

TechniqueTactics
T1563.002 Remote Service Session Hijacking: RDP HijackingLateral Movement

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading