this RDP logon log 4624 is related to an rdp tunneling activity, you can see SrcIP is != loopbackaddress or 10.0.0.4 is the IP @ of same host, while investigating RDP 4624 always make sure to correlate with DHCP client logs, SrcPort=0 is not abnormal (thanks Microsoft 🤓) #dfir