SMB server Event ID 551: SMB session auth failure
- Event ID
- 551
- Channel
- Microsoft-Windows-SMBServer/Security
- Provider
- Microsoft-Windows-SMBServer
- Log file
- Microsoft-Windows-SMBServer%4Security.evtx
- Category
- Network shares
- Default logging
- Logged by default
What event 551 means
Event 551 is logged in the Microsoft-Windows-SMBServer/Security channel on the file server when a client's SMB session setup fails authentication. It records the client name and address, the user name supplied, the SMB session ID and the NT status (raw and translated).
It is logged by default, which makes it valuable where Logon failure auditing (4625) is missing or where the Security log has rolled over. It is also SMB-specific: it tells you the failure happened on an SMB session, not RDP or another protocol.
Microsoft's own guidance in the event lists common benign causes: wrong credentials, mismatched LM compatibility levels between client and server, SPN problems or duplicate SPNs, bad Kerberos service tickets, and guest access attempts when guest is disabled. Non-Windows clients and devices (NAS, printers, scanners) trigger it often.
When it is logged
Microsoft-Windows-SMBServer/Security channel, enabled by default.
A later version of the event adds SPN and SPNValidationPolicy for SMB server SPN validation failures.
Key fields
| Field | What it tells you | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| ClientName | Name of the client as recorded by the server for the session. | ||||||||||
| ClientAddress | Network address of the client. | ||||||||||
| UserName | User name supplied in the failed session setup. | ||||||||||
| SessionId | SMB session ID assigned by the server. | ||||||||||
| Status | NT status code of the failure.
| ||||||||||
| TranslatedStatus | Text version of Status (e.g. the logon-invalid message for 0xC000006D). | ||||||||||
| SPN | Service principal name presented by the client (newer event version only). | ||||||||||
| SPNValidationPolicy | SMB server SPN validation setting in effect (newer event version only). |
Common benign sources
- Users or services with stale passwords in mapped drives, scripts or scheduled tasks.
- NAS appliances, scanners and non-Windows clients using incompatible NTLM settings or guest access.
- Kerberos SPN misconfiguration (duplicate SPNs, DNS aliases) causing session setup failures.
What attackers do that produces it
- SMB password guessing or password spraying — many failures from one
ClientAddressfor one or many user names. - Credential testing of stolen hashes or passwords across file servers before lateral movement.
Investigation tips
- Group by
ClientAddressandUserName; many user names from one address suggests spraying, many failures for one account suggests guessing. - Correlate with Security 4625 (LogonType 3) and, on domain controllers, 4776 or 4771 for the same account and time.
- Check whether the same client later succeeded (4624 LogonType 3, 5140) — a success after a failure burst is a strong signal.
- On the client host, look for SMB client 31001 events and the process that initiated the connections.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.