Skip to content
Security

Event ID 4771: Kerberos pre-authentication failed

Kerberos pre-authentication failedEvent 4771 is logged on domain controllers when Kerberos pre-authentication fails, most often because of a wrong password (Status 0x18).
4771
Event ID
4771
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Kerberos
Default logging
Needs configuration

What event 4771 means

Event 4771 is the domain controller's record of a failed Kerberos logon at the pre-authentication step. The most common cause is a wrong password (0x18); others are an expired password, a disabled or locked account, or clock skew.

Because Kerberos is the default protocol in a domain, failed password attempts against domain accounts appear here rather than in 4625 on the DC. A password spray over Kerberos shows up as one IP producing 4771 for many accounts — and never touches member servers, so this event may be the only trace.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Logon > Audit Kerberos Authentication Service (Failure). Only meaningful on domain controllers.

Key fields

FieldWhat it tells you
TargetUserNameAccount whose pre-authentication failed.
TargetSidSID of that account.
ServiceNameRequested service, normally krbtgt/<DOMAIN>.
TicketOptionsTicket options (hex).
StatusKerberos failure code.
ValueMeaning
0x18KDC_ERR_PREAUTH_FAILED — wrong password.
0x12KDC_ERR_CLIENT_REVOKED — account disabled, expired or locked out.
0x17KDC_ERR_KEY_EXPIRED — password expired.
0x25KRB_AP_ERR_SKEW — clock skew too large.
0x10KDC_ERR_PADATA_TYPE_NOSUPP — smart card logon problem (for example missing KDC certificate).
PreAuthTypePre-authentication type attempted (2 = password, 15/16 = smart card or certificate).
IpAddressClient IP address.
IpPortClient source port.

Common benign sources

  • Users typing a wrong password; devices with a cached old password after a change.
  • Services or scheduled tasks still configured with an old password — repeated failures on a fixed schedule.
  • Clock problems on a client (0x25).

What attackers do that produces it

  • Password spraying over Kerberos — one source, many accounts, Status 0x18, often a few attempts per account to stay under the lockout threshold (Kerbrute, Rubeus).
  • Password guessing against a single account, usually ending in 4740 lockout.

Investigation tips

  • Count distinct TargetUserName per IpAddress in short windows to separate spraying from user error.
  • Check for a 4768 with Status 0x0 for the same accounts and IP after the failures.
  • Map IpAddress to a host; failures from servers usually mean a misconfigured service account.
  • Correlate with 4740 on the PDC emulator for accounts that were locked.

MITRE ATT&CK techniques

TechniqueTactics
T1110 Brute ForceCredential Access
T1110.003 Brute Force: Password SprayingCredential Access

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading