Search notes:

Registry: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\SessionData

This key seems to have a numbered subkey for each currently active session.

See also

query.exe session

Index