Skip to content
Security

Event ID 4648: Logon with explicit credentials

A logon was attempted using explicit credentialsEvent 4648 is logged on the source host when a process uses explicitly supplied credentials, such as runas, net use /user or PsExec -u.
4648
Event ID
4648
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Logon
Default logging
Logged by default

What event 4648 means

Event 4648 is written on the machine where the credentials were typed or supplied, not on the target. It fires when a process logs on with an account other than the one it is running as: runas /user, net use \\server /user:..., PsExec -u, a scheduled task with stored credentials, or a tool calling LogonUser or CreateProcessWithLogonW.

The record links three things: who was already logged on (SubjectUserName), which account's credentials were used (TargetUserName), and where they were sent (TargetServerName, TargetInfo). That makes it one of the few source-side records of lateral movement — the destination only shows a 4624 from the attacker's IP.

Expect noise: on domain controllers and servers SYSTEM produces 4648 constantly for service accounts. Filter for SubjectUserName values that are real users.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Logon/Logoff > Audit Logon (Success). Enabled for Success in the default audit policy.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that was running the process which supplied the credentials.
SubjectLogonIdLogon session of that process; pivot to its 4624 and to 4688 events.
TargetUserNameAccount whose credentials were used.
TargetDomainNameDomain of that account.
TargetServerNameServer the credentials were used against (localhost for local runas). A remote host name here is a lateral movement lead.
TargetInfoAdditional target information, often the SPN or the target name again.
ProcessNameProcess that used the credentials, e.g. C:\Windows\System32\runas.exe, svchost.exe, lsass.exe, a PsExec binary.
ProcessIdPID of that process (hex).
IpAddressTarget IP address when known.

Common benign sources

  • Administrators using runas or Run as different user.
  • Scheduled tasks and services configured with stored credentials.
  • Mapping a drive with different credentials (net use /user).
  • Domain controllers and management servers where SYSTEM performs explicit logons for service accounts.

What attackers do that produces it

  • Lateral movement with stolen passwords — PsExec -u, net use to admin shares, WMI or WinRM with explicit credentials, all logged on the source host.
  • A compromised workstation where a regular user's session suddenly supplies a domain admin account's credentials to servers.
  • Credential validation loops where one process tries many TargetUserName values against one server.

Investigation tips

  • Filter out SubjectUserName ending in $ and SYSTEM, then list TargetUserName → TargetServerName pairs.
  • Look for admin accounts used from workstations where those admins never log on interactively.
  • Correlate with 4624 type 3 or type 9 on the target server at the same time; the 4624 IpAddress should be this host.
  • Check ProcessName; unusual binaries in user-writable paths are a strong signal.

MITRE ATT&CK techniques

TechniqueTactics
T1078 Valid AccountsStealth, Persistence, Privilege Escalation, Initial Access
T1021.002 Remote Services: SMB/Windows Admin SharesLateral Movement

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Medium · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading