Skip to content
Security

Event ID 4776: NTLM credential validation

The computer attempted to validate the credentials for an accountEvent 4776 records an NTLM credential check: on the domain controller for domain accounts, on the local machine for local accounts.
4776
Event ID
4776
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
NTLM
Default logging
Logged by default

What event 4776 means

Event 4776 is written by the computer that is authoritative for the account when it validates credentials with NTLM: the domain controller for domain accounts, or the local machine for local accounts (SAM). It fires for successes and failures, and the Status field says which.

It fills the gap left by Kerberos events: NTLM logons do not produce 4768/4769, so on a DC 4776 is the only record of an NTLM authentication. The Workstation field is the client-supplied name of the source computer — there is no IP address, so map it back through 4624 on the target server.

Pass-the-hash and relay attacks use NTLM, so bursts of NTLM validations for privileged accounts, or from unexpected workstations, deserve attention.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Logon > Audit Credential Validation (Success, Failure). Success is audited by default on servers; enable Failure explicitly.

Key fields

FieldWhat it tells you
PackageNameAuthentication package, normally MICROSOFT_AUTHENTICATION_PACKAGE_V1_0.
TargetUserNameAccount whose credentials were validated.
WorkstationName of the client computer as supplied in the NTLM exchange (spoofable, may be empty).
StatusResult (NTSTATUS).
ValueMeaning
0x0Success.
0xC0000064User name does not exist.
0xC000006AWrong password.
0xC000006FLogon outside allowed hours.
0xC0000070Workstation restriction.
0xC0000071Password expired.
0xC0000072Account disabled.
0xC0000193Account expired.
0xC0000224User must change password at next logon.
0xC0000234Account locked out.

Common benign sources

  • Applications and devices that only speak NTLM (older NAS, printers, some web apps).
  • Logons by IP address instead of host name, which fall back to NTLM.
  • Local account logons on standalone machines.

What attackers do that produces it

  • Pass-the-hash — NTLM validations for admin accounts from workstations that normally use Kerberos.
  • NTLM password spraying — many accounts failing with 0xC000006A from the same Workstation name.
  • NTLM relay — validations for an account arriving from a machine that is not where the user is.

Investigation tips

  • On DCs, group by TargetUserName and Workstation; look for privileged accounts authenticating via NTLM.
  • For failures, compare 0xC0000064 versus 0xC000006A counts to separate enumeration from guessing.
  • Find the matching 4624 (AuthenticationPackageName NTLM) on member servers to recover the source IP.
  • Consider NTLM auditing (NTLM operational log 8001–8004) to see which servers still receive NTLM.

MITRE ATT&CK techniques

TechniqueTactics
T1550.002 Use Alternate Authentication Material: Pass the HashLateral Movement
T1110 Brute ForceCredential Access
T1110.003 Brute Force: Password SprayingCredential Access

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

3 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 2
  • Medium · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading