Event ID 4625: Failed logon
- Event ID
- 4625
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Logon
- Default logging
- Logged by default
What event 4625 means
Event 4625 is written by the computer that rejected a logon attempt. For domain accounts the password check happens on a domain controller, but the failure is still recorded on the machine where the user tried to log on — the DC records its side as 4771 (Kerberos) or 4776 (NTLM).
The two most useful fields are Status and SubStatus, NTSTATUS codes that give the failure reason. 0xC000006D alone is generic ("unknown user name or bad password"); the SubStatus tells you which: 0xC0000064 for a user name that does not exist, 0xC000006A for a wrong password. Combined with LogonType and IpAddress this separates a user fumbling a password from a brute force or password spray.
Volume matters more than any single record: dozens of failures for one account from one source is guessing; one failure each for hundreds of accounts from one source is spraying.
When it is logged
Advanced Audit Policy Configuration > Logon/Logoff > Audit Logon (Failure). Failure auditing for this subcategory is part of the default audit policy on current Windows client and server versions; confirm with auditpol /get /subcategory:Logon.
Also produced by Audit Account Lockout (Failure) when the account is locked (Status 0xC0000234). IpAddress is empty for local attempts and for some NTLM network failures where only WorkstationName is known.
Key fields
| Field | What it tells you | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| TargetUserName | Account name that was tried. It is logged as typed, so typos, user names that do not exist and spray lists all appear here. | ||||||||||||||||||||||
| TargetDomainName | Domain or computer name supplied with the account. | ||||||||||||||||||||||
| Status | Top-level failure reason (NTSTATUS).
| ||||||||||||||||||||||
| SubStatus | Detailed failure reason (NTSTATUS).
| ||||||||||||||||||||||
| FailureReason | Message string for the failure (stored as a %% insertion such as %%2313, rendered by Event Viewer as "Unknown user name or bad password"). | ||||||||||||||||||||||
| LogonType | Type of logon that failed (same values as 4624): 2 console, 3 network (SMB, NTLM over HTTP), 8 cleartext network, 10 RDP. | ||||||||||||||||||||||
| LogonProcessName | Logon process, e.g. User32, NtLmSsp, Advapi. | ||||||||||||||||||||||
| AuthenticationPackageName | Package used for the attempt, usually NTLM, Kerberos or Negotiate. | ||||||||||||||||||||||
| WorkstationName | Source computer name supplied by the client — spoofable, but useful for NTLM failures without an IP. | ||||||||||||||||||||||
| IpAddress | Source IP address of a remote attempt. | ||||||||||||||||||||||
| IpPort | Source TCP port. | ||||||||||||||||||||||
| ProcessName | Local process that attempted the logon (for example winlogon.exe for the console, svchost.exe for RDP on some versions); - for network logons. |
Common benign sources
- Users mistyping a password, or a password change not yet propagated to all their devices.
- Stale credentials stored in services, scheduled tasks, mapped drives or phones — repeated failures at a fixed interval.
- Vulnerability scanners and monitoring tools configured with wrong credentials.
- Disabled or expired accounts still used by an old script.
What attackers do that produces it
- Password guessing — many 4625 for one account from one source, SubStatus
0xC000006A. - Password spraying — a few failures each for many different accounts from one source, often with SubStatus
0xC000006Amixed with0xC0000064. - RDP brute force from the internet — LogonType 3 or 10 failures from public IP addresses, often with generic user names such as administrator, admin or test.
- User enumeration, visible as a burst of
0xC0000064(user does not exist) for a list of names.
Investigation tips
- Count failures by IpAddress and by TargetUserName over short windows (5–15 minutes); spraying shows as one source across many accounts.
- Always check for a 4624 with the same TargetUserName and IpAddress after the failures — a failure run ending in success is the finding.
- Look at SubStatus distribution;
0xC0000064for real-looking names means someone is guessing user names. - On domain controllers pair with 4771 (Kerberos pre-auth failed) and 4776 (NTLM) to see failures that never reach the member server.
- If the account got locked, 4740 on the PDC emulator names the caller computer that produced the lockout.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
4 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 2
- Medium · 2
- HighHacktool RulerRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighMetasploit SMB AuthenticationRule by Chakib Gzenayi (@Chak092), Hosni Mribah, SigmaHQ, DRL 1.1
- MediumAccount Tampering - Suspicious Failed Logon ReasonsRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- MediumFailed Logon From Public IPRule by NVISO, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.