SMB client Event ID 31001: Logon failure
- Event ID
- 31001
- Channel
- Microsoft-Windows-SMBClient/Security
- Provider
- Microsoft-Windows-SMBClient
- Log file
- Microsoft-Windows-SMBClient%4Security.evtx
- Category
- Network shares
- Default logging
- Logged by default
What event 31001 means
Event 31001 is logged in the Microsoft-Windows-SMBClient/Security channel on the computer that initiated the SMB connection, when authentication to the remote server fails. The message text is the Reason string, followed by the NT status, the security (SSPI) status, the user, the logon session, the server and the service principal name used.
It is the client-side counterpart of server-side failures (4625 and SMB server 551 on the target). Because it is written on the source host, it shows where a failing connection came from even when the target's logs are unavailable, and LogonId ties the attempt to a local logon session.
Most 31001 events are operational: expired passwords in mapped drives, Kerberos SPN problems (cifs/server), unreachable domain controllers. A burst of failures against many servers from one host, or with many different user names, points to password guessing or a tool testing stolen credentials.
When it is logged
Microsoft-Windows-SMBClient/Security channel, enabled by default on current Windows versions.
Key fields
| Field | What it tells you | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Reason | Human-readable failure reason; it is also the first line of the rendered message. | ||||||||
| Status | NT status code of the failure.
| ||||||||
| SecurityStatus | SSPI status returned by the security package.
| ||||||||
| UserName | Account used for the connection attempt. | ||||||||
| LogonId | Local logon session that made the attempt; match it with 4624 TargetLogonId on this host. | ||||||||
| ServerName | Target server, e.g. \fileserver01 or \10.0.0.5. An IP address forces NTLM instead of Kerberos. | ||||||||
| PrincipalName | SPN used for Kerberos, e.g. cifs/fileserver01.contoso.local. |
Common benign sources
- Mapped drives or scheduled tasks still using an old password after a password change.
- Laptops off the corporate network failing to reach a domain controller.
- SPN or DNS alias misconfiguration causing Kerberos errors against a file server.
What attackers do that produces it
- Credential testing over SMB (for example with CrackMapExec/NetExec style tools run from a compromised host) producing many failures against many servers.
- Lateral movement attempts with wrong or expired stolen credentials.
- Connections to external or unusual SMB servers, which can indicate forced authentication or data exfiltration attempts.
Investigation tips
- Group by
ServerNameandUserNameto separate a single broken mapping from a spray across servers or accounts. - Match
LogonIdwith 4624 on the source host to identify the user session, then with process creation (4688, Sysmon 1) around the timestamp. - On the target, look for the matching SMB server 551 and Security 4625 events.
- Check for successful connections after the failures (5140 on the target, 4624 LogonType 3) to see whether an attempt eventually worked.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.