Search notes:
Registry: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\SessionData
This
key
seems to have a numbered subkey for each currently active
session
.
See also
query.exe session
Index