1. Enable Logon auditing in group policy.
2. Subscribe to that particular event using Event Log API's EvtSubscribe[^]
Your program would need to run as a service, because it's possible that noone is logged in at the very moment. I have to little detailed understandiong of the matter toto provide better help, btu that might get you started.