T1563 RDP/SSH Session ID Reuse or Hijack Detected
Detects potential remote service session hijacking by monitoring for RDP session ID reuse by a different user or unauthorized SSH session reattachment (e.g., tmux/screen hijacking). It correlates logon events with process execution to identify instances where an existing session is accessed by an account other than the original owner, while excluding legitimate service/support account activity.
Microsoft Sentinel (KQL)

