Skip to content
Security

Event ID 4779: Session disconnected

A session was disconnected from a Window StationEvent 4779 is logged when an interactive session is disconnected without logging off — an RDP window closed or a user switch.
4779
Event ID
4779
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Remote access
Default logging
Needs configuration

What event 4779 means

Event 4779 records that an interactive session was detached from its client but kept running: the RDP window was closed, the network dropped, or the user switched to another account. The logon session stays alive, so no 4634 or 4647 follows until an actual logoff.

For RDP timelines, 4779 and 4778 mark the gaps inside a single logon session. A session left disconnected keeps its processes and credentials in memory, which matters when assessing what an intruder could still reach.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Logon/Logoff > Audit Other Logon/Logoff Events (Success).

Key fields

FieldWhat it tells you
AccountNameUser whose session was disconnected.
AccountDomainDomain of that user.
LogonIDLogon session ID (matches the original 4624).
SessionNameSession name, e.g. RDP-Tcp#3.
ClientNameClient computer that was connected.
ClientAddressClient IP address that was connected.

Common benign sources

  • Users closing the RDP window instead of signing out.
  • Idle-session policies disconnecting sessions.

What attackers do that produces it

  • Operators disconnecting from a session to come back later, leaving tools running.

Investigation tips

  • Pair with 4778 and LocalSessionManager 24 to see disconnect and reconnect times and client IPs.
  • Long-lived disconnected admin sessions are a credential-exposure risk; note them in the report.

MITRE ATT&CK techniques

TechniqueTactics
T1021.001 Remote Services: Remote Desktop ProtocolLateral Movement

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading