Event ID 4648: Logon with explicit credentials
- Event ID
- 4648
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Logon
- Default logging
- Logged by default
What event 4648 means
Event 4648 is written on the machine where the credentials were typed or supplied, not on the target. It fires when a process logs on with an account other than the one it is running as: runas /user, net use \\server /user:..., PsExec -u, a scheduled task with stored credentials, or a tool calling LogonUser or CreateProcessWithLogonW.
The record links three things: who was already logged on (SubjectUserName), which account's credentials were used (TargetUserName), and where they were sent (TargetServerName, TargetInfo). That makes it one of the few source-side records of lateral movement — the destination only shows a 4624 from the attacker's IP.
Expect noise: on domain controllers and servers SYSTEM produces 4648 constantly for service accounts. Filter for SubjectUserName values that are real users.
When it is logged
Advanced Audit Policy Configuration > Logon/Logoff > Audit Logon (Success). Enabled for Success in the default audit policy.
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserName | Account that was running the process which supplied the credentials. |
| SubjectLogonId | Logon session of that process; pivot to its 4624 and to 4688 events. |
| TargetUserName | Account whose credentials were used. |
| TargetDomainName | Domain of that account. |
| TargetServerName | Server the credentials were used against (localhost for local runas). A remote host name here is a lateral movement lead. |
| TargetInfo | Additional target information, often the SPN or the target name again. |
| ProcessName | Process that used the credentials, e.g. C:\Windows\System32\runas.exe, svchost.exe, lsass.exe, a PsExec binary. |
| ProcessId | PID of that process (hex). |
| IpAddress | Target IP address when known. |
Common benign sources
- Administrators using
runasor Run as different user. - Scheduled tasks and services configured with stored credentials.
- Mapping a drive with different credentials (
net use /user). - Domain controllers and management servers where SYSTEM performs explicit logons for service accounts.
What attackers do that produces it
- Lateral movement with stolen passwords — PsExec -u,
net useto admin shares, WMI or WinRM with explicit credentials, all logged on the source host. - A compromised workstation where a regular user's session suddenly supplies a domain admin account's credentials to servers.
- Credential validation loops where one process tries many TargetUserName values against one server.
Investigation tips
- Filter out SubjectUserName ending in
$and SYSTEM, then list TargetUserName → TargetServerName pairs. - Look for admin accounts used from workstations where those admins never log on interactively.
- Correlate with 4624 type 3 or type 9 on the target server at the same time; the 4624 IpAddress should be this host.
- Check ProcessName; unusual binaries in user-writable paths are a strong signal.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- Medium · 1
- MediumSuspicious Remote Logon with Explicit CredentialsRule by oscd.community, Teymur Kheirkhabarov @HeirhabarovT, Zach Stanford @svch0st, Tim Shelton, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.