Skip to content
SMB Client

SMB client Event ID 31001: Logon failure

SMB client authentication failureSMB client event 31001 records a failed authentication from this computer to an SMB server, with server name, user name, SPN and error codes. Source-side view.
31001
Event ID
31001
Channel
Microsoft-Windows-SMBClient/Security
Provider
Microsoft-Windows-SMBClient
Log file
Microsoft-Windows-SMBClient%4Security.evtx
Category
Network shares
Default logging
Logged by default

What event 31001 means

Event 31001 is logged in the Microsoft-Windows-SMBClient/Security channel on the computer that initiated the SMB connection, when authentication to the remote server fails. The message text is the Reason string, followed by the NT status, the security (SSPI) status, the user, the logon session, the server and the service principal name used.

It is the client-side counterpart of server-side failures (4625 and SMB server 551 on the target). Because it is written on the source host, it shows where a failing connection came from even when the target's logs are unavailable, and LogonId ties the attempt to a local logon session.

Most 31001 events are operational: expired passwords in mapped drives, Kerberos SPN problems (cifs/server), unreachable domain controllers. A burst of failures against many servers from one host, or with many different user names, points to password guessing or a tool testing stolen credentials.

When it is logged

Audit policy / configuration

Microsoft-Windows-SMBClient/Security channel, enabled by default on current Windows versions.

Key fields

FieldWhat it tells you
ReasonHuman-readable failure reason; it is also the first line of the rendered message.
StatusNT status code of the failure.
ValueMeaning
0xC000006DSTATUS_LOGON_FAILURE — bad user name or authentication information.
0xC0000234STATUS_ACCOUNT_LOCKED_OUT — the account is locked out.
0xC0000072STATUS_ACCOUNT_DISABLED — the account is disabled.
SecurityStatusSSPI status returned by the security package.
ValueMeaning
0x8009030CSEC_E_LOGON_DENIED — the logon attempt failed.
0x80090311SEC_E_NO_AUTHENTICATING_AUTHORITY — no authority (domain controller) could be contacted.
0x80090322SEC_E_WRONG_PRINCIPAL — the target principal name is incorrect (often an SPN or DNS alias problem).
UserNameAccount used for the connection attempt.
LogonIdLocal logon session that made the attempt; match it with 4624 TargetLogonId on this host.
ServerNameTarget server, e.g. \fileserver01 or \10.0.0.5. An IP address forces NTLM instead of Kerberos.
PrincipalNameSPN used for Kerberos, e.g. cifs/fileserver01.contoso.local.

Common benign sources

  • Mapped drives or scheduled tasks still using an old password after a password change.
  • Laptops off the corporate network failing to reach a domain controller.
  • SPN or DNS alias misconfiguration causing Kerberos errors against a file server.

What attackers do that produces it

  • Credential testing over SMB (for example with CrackMapExec/NetExec style tools run from a compromised host) producing many failures against many servers.
  • Lateral movement attempts with wrong or expired stolen credentials.
  • Connections to external or unusual SMB servers, which can indicate forced authentication or data exfiltration attempts.

Investigation tips

  • Group by ServerName and UserName to separate a single broken mapping from a spray across servers or accounts.
  • Match LogonId with 4624 on the source host to identify the user session, then with process creation (4688, Sysmon 1) around the timestamp.
  • On the target, look for the matching SMB server 551 and Security 4625 events.
  • Check for successful connections after the failures (5140 on the target, 4624 LogonType 3) to see whether an attempt eventually worked.

MITRE ATT&CK techniques

TechniqueTactics
T1110 Brute ForceCredential Access
T1021.002 Remote Services: SMB/Windows Admin SharesLateral Movement

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading