Event ID 4776: NTLM credential validation
- Event ID
- 4776
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- NTLM
- Default logging
- Logged by default
What event 4776 means
Event 4776 is written by the computer that is authoritative for the account when it validates credentials with NTLM: the domain controller for domain accounts, or the local machine for local accounts (SAM). It fires for successes and failures, and the Status field says which.
It fills the gap left by Kerberos events: NTLM logons do not produce 4768/4769, so on a DC 4776 is the only record of an NTLM authentication. The Workstation field is the client-supplied name of the source computer — there is no IP address, so map it back through 4624 on the target server.
Pass-the-hash and relay attacks use NTLM, so bursts of NTLM validations for privileged accounts, or from unexpected workstations, deserve attention.
When it is logged
Advanced Audit Policy Configuration > Account Logon > Audit Credential Validation (Success, Failure). Success is audited by default on servers; enable Failure explicitly.
Key fields
| Field | What it tells you | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| PackageName | Authentication package, normally MICROSOFT_AUTHENTICATION_PACKAGE_V1_0. | ||||||||||||||||||||||
| TargetUserName | Account whose credentials were validated. | ||||||||||||||||||||||
| Workstation | Name of the client computer as supplied in the NTLM exchange (spoofable, may be empty). | ||||||||||||||||||||||
| Status | Result (NTSTATUS).
|
Common benign sources
- Applications and devices that only speak NTLM (older NAS, printers, some web apps).
- Logons by IP address instead of host name, which fall back to NTLM.
- Local account logons on standalone machines.
What attackers do that produces it
- Pass-the-hash — NTLM validations for admin accounts from workstations that normally use Kerberos.
- NTLM password spraying — many accounts failing with
0xC000006Afrom the same Workstation name. - NTLM relay — validations for an account arriving from a machine that is not where the user is.
Investigation tips
- On DCs, group by TargetUserName and Workstation; look for privileged accounts authenticating via NTLM.
- For failures, compare
0xC0000064versus0xC000006Acounts to separate enumeration from guessing. - Find the matching 4624 (AuthenticationPackageName NTLM) on member servers to recover the source IP.
- Consider NTLM auditing (NTLM operational log 8001–8004) to see which servers still receive NTLM.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
3 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 2
- Medium · 1
- HighHacktool RulerRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighMetasploit SMB AuthenticationRule by Chakib Gzenayi (@Chak092), Hosni Mribah, SigmaHQ, DRL 1.1
- MediumAccount Tampering - Suspicious Failed Logon ReasonsRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.