Event ID 4771: Kerberos pre-authentication failed
- Event ID
- 4771
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Kerberos
- Default logging
- Needs configuration
What event 4771 means
Event 4771 is the domain controller's record of a failed Kerberos logon at the pre-authentication step. The most common cause is a wrong password (0x18); others are an expired password, a disabled or locked account, or clock skew.
Because Kerberos is the default protocol in a domain, failed password attempts against domain accounts appear here rather than in 4625 on the DC. A password spray over Kerberos shows up as one IP producing 4771 for many accounts — and never touches member servers, so this event may be the only trace.
When it is logged
Advanced Audit Policy Configuration > Account Logon > Audit Kerberos Authentication Service (Failure). Only meaningful on domain controllers.
Key fields
| Field | What it tells you | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| TargetUserName | Account whose pre-authentication failed. | ||||||||||||
| TargetSid | SID of that account. | ||||||||||||
| ServiceName | Requested service, normally krbtgt/<DOMAIN>. | ||||||||||||
| TicketOptions | Ticket options (hex). | ||||||||||||
| Status | Kerberos failure code.
| ||||||||||||
| PreAuthType | Pre-authentication type attempted (2 = password, 15/16 = smart card or certificate). | ||||||||||||
| IpAddress | Client IP address. | ||||||||||||
| IpPort | Client source port. |
Common benign sources
- Users typing a wrong password; devices with a cached old password after a change.
- Services or scheduled tasks still configured with an old password — repeated failures on a fixed schedule.
- Clock problems on a client (
0x25).
What attackers do that produces it
- Password spraying over Kerberos — one source, many accounts, Status
0x18, often a few attempts per account to stay under the lockout threshold (Kerbrute, Rubeus). - Password guessing against a single account, usually ending in 4740 lockout.
Investigation tips
- Count distinct TargetUserName per IpAddress in short windows to separate spraying from user error.
- Check for a 4768 with Status
0x0for the same accounts and IP after the failures. - Map IpAddress to a host; failures from servers usually mean a misconfigured service account.
- Correlate with 4740 on the PDC emulator for accounts that were locked.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- HighKerberos ManipulationRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.