Skip to content
OpenSSH

OpenSSH Event ID 4: sshd informational message

OpenSSH informational messageOpenSSH event 4 carries informational sshd messages on Windows: accepted and failed logons, invalid users and disconnects, with source IP and port in the text.
4
Event ID
4
Channel
OpenSSH/Operational
Provider
OpenSSH
Log file
OpenSSH%4Operational.evtx
Category
Remote access
Default logging
Logged by default

What event 4 means

Event 4 is the generic informational event of the Windows port of OpenSSH. Every INFO-level line that sshd would write to syslog on Linux becomes an event 4 in OpenSSH/Operational, with two fields: process (the emitting program) and payload (the log line itself).

All the forensic value is in payload. Typical messages are Accepted password for <user> from <ip> port <port> ssh2, Accepted publickey for <user> ..., Failed password for <user> ..., Invalid user <name> from <ip>, and connection close or disconnect lines. You have to parse the text to extract user, source IP and authentication method.

OpenSSH Server ships as an optional Windows feature since Windows 10 1809 and Windows Server 2019. An SSH server on a workstation is unusual; attackers sometimes install or enable it for persistent remote access or tunneling, so its presence and its accepted logons deserve attention.

When it is logged

Audit policy / configuration

Logged by default once the OpenSSH Server (sshd) service is installed and running: sshd logs to ETW, which feeds the OpenSSH/Operational channel.

Setting SyslogFacility LOCAL0 in %programdata%\ssh\sshd_config switches sshd to file logging under %programdata%\ssh\logs instead of the event log. Warnings use event 3 in the same channel; errors and critical messages go to OpenSSH/Admin. A successful SSH logon also creates a Windows logon session (4624) on the server.

Key fields

FieldWhat it tells you
processProgram that emitted the message, e.g. sshd. The process ID is also in the event's System section.
payloadThe log line. Parse it for the outcome (Accepted / Failed), the method (password, publickey), the user name, and from <ip> port <port>.

Common benign sources

  • Administrators or automation (Ansible, backup, deployment tools) connecting with keys to managed Windows servers.
  • Developers using SSH or SFTP to reach build servers.
  • Internet or network scanners producing Invalid user and Failed password lines on exposed hosts.

What attackers do that produces it

  • Password guessing against sshd — many Failed password or Invalid user messages from one or many source IPs.
  • Logons with stolen credentials or planted keys (Accepted publickey for an account that never used SSH before).
  • OpenSSH Server installed or enabled by an intruder on a workstation to keep remote access or tunnel traffic.

Investigation tips

  • Extract user, method and source IP from payload and build a table of accepted logons; review first-seen sources and accounts.
  • Look for failures followed by an Accepted line from the same IP (successful brute force).
  • Correlate accepted logons with 4624 on the host and with processes launched by sshd.exe (4688, Sysmon 1).
  • For public-key logons, review administrators_authorized_keys and users' .ssh\authorized_keys files for unexpected keys.

MITRE ATT&CK techniques

TechniqueTactics
T1021 Remote ServicesLateral Movement
T1110 Brute ForceCredential Access
T1133 External Remote ServicesPersistence, Initial Access

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Medium · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading