OpenSSH Event ID 4: sshd informational message
- Event ID
- 4
- Channel
- OpenSSH/Operational
- Provider
- OpenSSH
- Log file
- OpenSSH%4Operational.evtx
- Category
- Remote access
- Default logging
- Logged by default
What event 4 means
Event 4 is the generic informational event of the Windows port of OpenSSH. Every INFO-level line that sshd would write to syslog on Linux becomes an event 4 in OpenSSH/Operational, with two fields: process (the emitting program) and payload (the log line itself).
All the forensic value is in payload. Typical messages are Accepted password for <user> from <ip> port <port> ssh2, Accepted publickey for <user> ..., Failed password for <user> ..., Invalid user <name> from <ip>, and connection close or disconnect lines. You have to parse the text to extract user, source IP and authentication method.
OpenSSH Server ships as an optional Windows feature since Windows 10 1809 and Windows Server 2019. An SSH server on a workstation is unusual; attackers sometimes install or enable it for persistent remote access or tunneling, so its presence and its accepted logons deserve attention.
When it is logged
Logged by default once the OpenSSH Server (sshd) service is installed and running: sshd logs to ETW, which feeds the OpenSSH/Operational channel.
Setting SyslogFacility LOCAL0 in %programdata%\ssh\sshd_config switches sshd to file logging under %programdata%\ssh\logs instead of the event log. Warnings use event 3 in the same channel; errors and critical messages go to OpenSSH/Admin. A successful SSH logon also creates a Windows logon session (4624) on the server.
Key fields
| Field | What it tells you |
|---|---|
| process | Program that emitted the message, e.g. sshd. The process ID is also in the event's System section. |
| payload | The log line. Parse it for the outcome (Accepted / Failed), the method (password, publickey), the user name, and from <ip> port <port>. |
Common benign sources
- Administrators or automation (Ansible, backup, deployment tools) connecting with keys to managed Windows servers.
- Developers using SSH or SFTP to reach build servers.
- Internet or network scanners producing
Invalid userandFailed passwordlines on exposed hosts.
What attackers do that produces it
- Password guessing against sshd — many
Failed passwordorInvalid usermessages from one or many source IPs. - Logons with stolen credentials or planted keys (
Accepted publickeyfor an account that never used SSH before). - OpenSSH Server installed or enabled by an intruder on a workstation to keep remote access or tunnel traffic.
Investigation tips
- Extract user, method and source IP from
payloadand build a table of accepted logons; review first-seen sources and accounts. - Look for failures followed by an
Acceptedline from the same IP (successful brute force). - Correlate accepted logons with 4624 on the host and with processes launched by
sshd.exe(4688, Sysmon 1). - For public-key logons, review
administrators_authorized_keysand users'.ssh\authorized_keysfiles for unexpected keys.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- Medium · 1
- MediumOpenSSH Server Listening On SocketRule by mdecrevoisier, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.