Event ID 4800: Workstation locked
- Event ID
- 4800
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Logon
- Default logging
- Needs configuration
What event 4800 means
Event 4800 is written when an interactive session is locked, whether by the user (Win+L, Ctrl+Alt+Del > Lock) or automatically by the screen saver or inactivity policy. It names the user (TargetUserName, TargetUserSid), the logon session (TargetLogonId) and the terminal session number (SessionId).
Lock and unlock events (4800/4801) build a presence timeline: activity inside a session while it was locked is unlikely to be the user at the keyboard. That helps separate a user's own actions from those of malware or a remote operator using the same session.
The event is part of the Other Logon/Logoff Events subcategory, which is not audited by default, so many machines will not have it.
When it is logged
Advanced Audit Policy Configuration > Logon/Logoff > Audit Other Logon/Logoff Events (Success). Not enabled in the default audit policy.
Key fields
| Field | What it tells you |
|---|---|
| TargetUserName | Account whose session was locked. |
| TargetDomainName | Domain or computer name of that account. |
| TargetUserSid | SID of that account. |
| TargetLogonId | Logon session that was locked; the same value appears in the session's 4624 and in 4801 on unlock. |
| SessionId | Terminal Services session number (console, RDP session) that was locked. |
Common benign sources
- Users locking their screen when leaving their desk.
- Automatic locks from screen saver or inactivity timeouts.
What attackers do that produces it
- Process activity (4688) or outbound connections in a session while it was locked suggests malware or a remote operator rather than the user.
Investigation tips
- Build lock/unlock intervals per TargetLogonId and overlay other activity from the same session.
- Pair with 4801 and 4624 LogonType 7 to confirm who unlocked the session and when.
- Compare with RDP events (4778/4779, 24/25) when the session is remote.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- Info · 1
- InfoLocked WorkstationRule by Alexandr Yampolskyi, SOC Prime, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.