NTLM Event ID 8004: Domain controller authentication audit
- Event ID
- 8004
- Channel
- Microsoft-Windows-NTLM/Operational
- Provider
- Microsoft-Windows-Security-Netlogon
- Log file
- Microsoft-Windows-NTLM%4Operational.evtx
- Category
- NTLM
- Default logging
- Needs configuration
What event 8004 means
Event 8004 is written on a domain controller when it validates an NTLM authentication and domain NTLM auditing is enabled. It is logged in the NTLM operational channel but by the Netlogon provider (Microsoft-Windows-Security-Netlogon), because NTLM pass-through validation arrives over the Netlogon secure channel.
Each record links three parties: the account (UserName, DomainName), the client that started the authentication (WorkstationName) and the server that forwarded it to the DC over its secure channel (SChannelName). Collected from all DCs, it gives a domain-wide view of who uses NTLM, from where, to which servers — something 4776 alone does not show.
NTLM authentication with local accounts never reaches the DC, so it will not appear here; check 8003 and 4624 on the target for those.
When it is logged
Security Options > Network security: Restrict NTLM: Audit NTLM authentication in this domain = Enable all (or one of the narrower Enable options), set on domain controllers.
Only authentication handled by the domain controller where the policy is set is logged; enable it on every DC. Volume can be large in environments with heavy NTLM use.
Key fields
| Field | What it tells you | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| SChannelName | Name of the computer whose Netlogon secure channel carried the request — normally the server the user was connecting to. | ||||||||
| UserName | Account that authenticated with NTLM. | ||||||||
| DomainName | Domain of the account. | ||||||||
| WorkstationName | Client computer name supplied in the NTLM exchange (can be spoofed or empty). | ||||||||
| SChannelType | Type of Netlogon secure channel used by SChannelName.
|
Common benign sources
- File, print and web servers forwarding NTLM logons of users who connect by IP address or alias.
- Legacy applications and appliances that only support NTLM.
- Servers without proper SPNs causing Kerberos to fall back to NTLM.
What attackers do that produces it
- Pass-the-hash and NTLM relay using domain accounts, showing the account, the client and the targeted server in one record.
- Privileged accounts authenticating with NTLM from unexpected workstations, or to servers they do not normally access.
Investigation tips
- Aggregate by
UserName,WorkstationNameandSChannelNameacross all DCs to build an NTLM usage map, then look for new combinations. - Match with 4776 on the same DC for the result code (success or failure) of the validation.
- Go to the server named in
SChannelNamefor 8003 and 4624 (source IP), and to the client for 8001 (process name).
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- Medium · 1
- MediumNTLM Brute ForceRule by Jerry Shockley '@jsh0x', SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.