Skip to content
Security

Event ID 4625: Failed logon

An account failed to log onEvent 4625 is logged when a logon attempt fails. Status and SubStatus say why: bad password, unknown user, locked or disabled account.
4625
Event ID
4625
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Logon
Default logging
Logged by default

What event 4625 means

Event 4625 is written by the computer that rejected a logon attempt. For domain accounts the password check happens on a domain controller, but the failure is still recorded on the machine where the user tried to log on — the DC records its side as 4771 (Kerberos) or 4776 (NTLM).

The two most useful fields are Status and SubStatus, NTSTATUS codes that give the failure reason. 0xC000006D alone is generic ("unknown user name or bad password"); the SubStatus tells you which: 0xC0000064 for a user name that does not exist, 0xC000006A for a wrong password. Combined with LogonType and IpAddress this separates a user fumbling a password from a brute force or password spray.

Volume matters more than any single record: dozens of failures for one account from one source is guessing; one failure each for hundreds of accounts from one source is spraying.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Logon/Logoff > Audit Logon (Failure). Failure auditing for this subcategory is part of the default audit policy on current Windows client and server versions; confirm with auditpol /get /subcategory:Logon.

Also produced by Audit Account Lockout (Failure) when the account is locked (Status 0xC0000234). IpAddress is empty for local attempts and for some NTLM network failures where only WorkstationName is known.

Key fields

FieldWhat it tells you
TargetUserNameAccount name that was tried. It is logged as typed, so typos, user names that do not exist and spray lists all appear here.
TargetDomainNameDomain or computer name supplied with the account.
StatusTop-level failure reason (NTSTATUS).
ValueMeaning
0xC000006DGeneric bad user name or authentication information — read SubStatus.
0xC000015BThe user has not been granted the requested logon type on this machine.
0xC0000234Account is locked out.
0xC0000413Authentication firewall — the account is not allowed to authenticate to this machine.
SubStatusDetailed failure reason (NTSTATUS).
ValueMeaning
0xC0000064User name does not exist.
0xC000006AUser name is correct but the password is wrong.
0xC000006FLogon outside the account's allowed hours.
0xC0000070Logon from a workstation the account is not allowed to use.
0xC0000071Password has expired.
0xC0000072Account is disabled.
0xC0000133Clock skew between the machine and the domain controller is too large.
0xC0000193Account has expired.
0xC0000224User must change the password at next logon.
0xC0000234Account is locked out.
FailureReasonMessage string for the failure (stored as a %% insertion such as %%2313, rendered by Event Viewer as "Unknown user name or bad password").
LogonTypeType of logon that failed (same values as 4624): 2 console, 3 network (SMB, NTLM over HTTP), 8 cleartext network, 10 RDP.
LogonProcessNameLogon process, e.g. User32, NtLmSsp, Advapi.
AuthenticationPackageNamePackage used for the attempt, usually NTLM, Kerberos or Negotiate.
WorkstationNameSource computer name supplied by the client — spoofable, but useful for NTLM failures without an IP.
IpAddressSource IP address of a remote attempt.
IpPortSource TCP port.
ProcessNameLocal process that attempted the logon (for example winlogon.exe for the console, svchost.exe for RDP on some versions); - for network logons.

Common benign sources

  • Users mistyping a password, or a password change not yet propagated to all their devices.
  • Stale credentials stored in services, scheduled tasks, mapped drives or phones — repeated failures at a fixed interval.
  • Vulnerability scanners and monitoring tools configured with wrong credentials.
  • Disabled or expired accounts still used by an old script.

What attackers do that produces it

  • Password guessing — many 4625 for one account from one source, SubStatus 0xC000006A.
  • Password spraying — a few failures each for many different accounts from one source, often with SubStatus 0xC000006A mixed with 0xC0000064.
  • RDP brute force from the internet — LogonType 3 or 10 failures from public IP addresses, often with generic user names such as administrator, admin or test.
  • User enumeration, visible as a burst of 0xC0000064 (user does not exist) for a list of names.

Investigation tips

  • Count failures by IpAddress and by TargetUserName over short windows (5–15 minutes); spraying shows as one source across many accounts.
  • Always check for a 4624 with the same TargetUserName and IpAddress after the failures — a failure run ending in success is the finding.
  • Look at SubStatus distribution; 0xC0000064 for real-looking names means someone is guessing user names.
  • On domain controllers pair with 4771 (Kerberos pre-auth failed) and 4776 (NTLM) to see failures that never reach the member server.
  • If the account got locked, 4740 on the PDC emulator names the caller computer that produced the lockout.

MITRE ATT&CK techniques

TechniqueTactics
T1110 Brute ForceCredential Access
T1110.001 Brute Force: Password GuessingCredential Access
T1110.003 Brute Force: Password SprayingCredential Access

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

4 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 2
  • Medium · 2

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

In-depth guideEvent ID 4625 explained: detecting brute force, sprays and enumeration

Sources and further reading