Skip to content
Security

Event ID 4778: Session reconnected

A session was reconnected to a Window StationEvent 4778 is logged when a user reconnects to an existing interactive session, typically an RDP reconnect or fast user switching.
4778
Event ID
4778
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Remote access
Default logging
Needs configuration

What event 4778 means

Event 4778 records a reconnection to an existing logon session: an RDP client reattaching to a disconnected session, or a user switching back to a session with fast user switching. No new 4624 is written in that case for the session itself, so 4778 is how you see that someone came back.

The ClientName and ClientAddress fields identify the device that reconnected. Comparing them with the original logon shows when a session was picked up from a different machine.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Logon/Logoff > Audit Other Logon/Logoff Events (Success).

Key fields

FieldWhat it tells you
AccountNameUser who reconnected.
AccountDomainDomain of that user.
LogonIDLogon session ID of the session that was resumed (matches its original 4624).
SessionNameWindow station/session name, e.g. RDP-Tcp#3 or Console.
ClientNameComputer name of the connecting client (for RDP).
ClientAddressIP address of the connecting client (for RDP).

Common benign sources

  • Users reconnecting to their RDP sessions after a network drop or from another device.
  • Fast user switching on shared workstations.

What attackers do that produces it

  • An intruder reattaching to a disconnected admin session, possibly from a new IP.
  • Session hijacking (for example with tscon) moves a session to another client; the reconnect is recorded here.

Investigation tips

  • Compare ClientAddress with the IP in the original 4624 type 10 for the same LogonID.
  • Pair with LocalSessionManager event 25 (reconnection) and 4779 (disconnect) to build the RDP session timeline.

MITRE ATT&CK techniques

TechniqueTactics
T1021.001 Remote Services: Remote Desktop ProtocolLateral Movement
T1563.002 Remote Service Session Hijacking: RDP HijackingLateral Movement

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading