Event ID 4778: Session reconnected
- Event ID
- 4778
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Remote access
- Default logging
- Needs configuration
What event 4778 means
Event 4778 records a reconnection to an existing logon session: an RDP client reattaching to a disconnected session, or a user switching back to a session with fast user switching. No new 4624 is written in that case for the session itself, so 4778 is how you see that someone came back.
The ClientName and ClientAddress fields identify the device that reconnected. Comparing them with the original logon shows when a session was picked up from a different machine.
When it is logged
Advanced Audit Policy Configuration > Logon/Logoff > Audit Other Logon/Logoff Events (Success).
Key fields
| Field | What it tells you |
|---|---|
| AccountName | User who reconnected. |
| AccountDomain | Domain of that user. |
| LogonID | Logon session ID of the session that was resumed (matches its original 4624). |
| SessionName | Window station/session name, e.g. RDP-Tcp#3 or Console. |
| ClientName | Computer name of the connecting client (for RDP). |
| ClientAddress | IP address of the connecting client (for RDP). |
Common benign sources
- Users reconnecting to their RDP sessions after a network drop or from another device.
- Fast user switching on shared workstations.
What attackers do that produces it
- An intruder reattaching to a disconnected admin session, possibly from a new IP.
- Session hijacking (for example with
tscon) moves a session to another client; the reconnect is recorded here.
Investigation tips
- Compare ClientAddress with the IP in the original 4624 type 10 for the same LogonID.
- Pair with LocalSessionManager event 25 (reconnection) and 4779 (disconnect) to build the RDP session timeline.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.