Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

App Control: What Determines Last Logged In Users?

App Control: What Determines Last Logged In Users?

Environment

  • App Control Console: All Supported Versions
  • App Control Agent: All Supported Versions

Question

How does the Agent determine the list of Last Logged In User(s) shown in the Console > Assets > Computers > Connection History?

Answer

The Agent queries the operating system for this list. This list is managed by the operating system, and in most circumstances the OS will not purge entries until the system is rebooted.

Additional Notes

  • On Windows this data is returned using LsaEnumerateLogonSessions. For each session the WTSConnectState is queried.
    • If the state is WTSActive, the session is reported to the Server.
    • If the state is WTSDisconnected, the user will not be reported.
    • When a user session logs off, Windows does not clear the WTSActive state, so the user will be reported.
    • When a user disconnects, Windows changes the state to WTSDisconnected, so the user will not be reported.

Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎11-24-2023
Views:
104
Contributors