3.5 logon-session-destroyed

Fires when a logon session loses its last token reference and the kernel destroys it.

Event type string: logon-session-destroyed.

KeyTypeMeaning
session_iduintThe destroyed session's LUID.
user_sidbinThe session's user SID.
logon_typeuintInteractive, Network, and so on.
auth_packagestringThe authenticating package — Kerberos, NTLM, local.
created_atuintWhen the session was created.

Every field is always present.

3.5.1 No subject, no process #

This is the only KACS event with neither. The session was the subject, and it has just ended. No process caused it — the last reference simply went away, which may have been any process exiting, or none in particular.

3.5.2 Correlating #

session_id is the same LUID that every token in that session reported as subject.auth_id (§2.1), and that LCS events report as caller.authentication_id (§2.3). It is the join key for everything that session ever did.

With created_at, the event bounds a session's whole lifetime, which is what makes it useful for reconstructing a login after the fact.

The event fires exactly once per session. Consumers — authd especially — use it to release session-scoped state: Kerberos tickets, cached directory data, per-session credentials.

3.5.3 There is no matching creation event #

Nothing is emitted when a session is created, so the pair is asymmetric. See §3.6 for what else is absent and why.

Edit this page