As discussed in the Logon Timeout section, the uniqueness of an event is determined by various source and target attributes of a logon. When the Logon Tracker endpoint module observes a duplicate logon, an internal cache is incremented. If the Logon Timeout has expired, the event is then published to the server to include the number of cache hits (that is, the total number of times a duplicate event has been observed on the endpoint). This count is exposed in the UI grid view in the “Cache Hits” column. Cache Hits can be a useful data point when investigating lateral movement as it implies the uniqueness of an event.
Cache Hits
- Published on Sep 11, 2026
- 1 minute(s) read
Was this article helpful?