Skip to content
SMB Server

SMB server Event ID 551: SMB session auth failure

SMB Session Authentication FailureSMB server event 551 records a failed SMB session authentication, with client address, user name and status code. Complements 4625 for SMB brute force.
551
Event ID
551
Channel
Microsoft-Windows-SMBServer/Security
Provider
Microsoft-Windows-SMBServer
Log file
Microsoft-Windows-SMBServer%4Security.evtx
Category
Network shares
Default logging
Logged by default

What event 551 means

Event 551 is logged in the Microsoft-Windows-SMBServer/Security channel on the file server when a client's SMB session setup fails authentication. It records the client name and address, the user name supplied, the SMB session ID and the NT status (raw and translated).

It is logged by default, which makes it valuable where Logon failure auditing (4625) is missing or where the Security log has rolled over. It is also SMB-specific: it tells you the failure happened on an SMB session, not RDP or another protocol.

Microsoft's own guidance in the event lists common benign causes: wrong credentials, mismatched LM compatibility levels between client and server, SPN problems or duplicate SPNs, bad Kerberos service tickets, and guest access attempts when guest is disabled. Non-Windows clients and devices (NAS, printers, scanners) trigger it often.

When it is logged

Audit policy / configuration

Microsoft-Windows-SMBServer/Security channel, enabled by default.

A later version of the event adds SPN and SPNValidationPolicy for SMB server SPN validation failures.

Key fields

FieldWhat it tells you
ClientNameName of the client as recorded by the server for the session.
ClientAddressNetwork address of the client.
UserNameUser name supplied in the failed session setup.
SessionIdSMB session ID assigned by the server.
StatusNT status code of the failure.
ValueMeaning
0xC000006DSTATUS_LOGON_FAILURE — bad user name or password (or other authentication information).
0xC0000234STATUS_ACCOUNT_LOCKED_OUT — the account is locked out.
0xC0000072STATUS_ACCOUNT_DISABLED — the account is disabled.
0xC000015BSTATUS_LOGON_TYPE_NOT_GRANTED — the account is not allowed network logon on this server.
TranslatedStatusText version of Status (e.g. the logon-invalid message for 0xC000006D).
SPNService principal name presented by the client (newer event version only).
SPNValidationPolicySMB server SPN validation setting in effect (newer event version only).

Common benign sources

  • Users or services with stale passwords in mapped drives, scripts or scheduled tasks.
  • NAS appliances, scanners and non-Windows clients using incompatible NTLM settings or guest access.
  • Kerberos SPN misconfiguration (duplicate SPNs, DNS aliases) causing session setup failures.

What attackers do that produces it

  • SMB password guessing or password spraying — many failures from one ClientAddress for one or many user names.
  • Credential testing of stolen hashes or passwords across file servers before lateral movement.

Investigation tips

  • Group by ClientAddress and UserName; many user names from one address suggests spraying, many failures for one account suggests guessing.
  • Correlate with Security 4625 (LogonType 3) and, on domain controllers, 4776 or 4771 for the same account and time.
  • Check whether the same client later succeeded (4624 LogonType 3, 5140) — a success after a failure burst is a strong signal.
  • On the client host, look for SMB client 31001 events and the process that initiated the connections.

MITRE ATT&CK techniques

TechniqueTactics
T1110 Brute ForceCredential Access
T1110.003 Brute Force: Password SprayingCredential Access
T1021.002 Remote Services: SMB/Windows Admin SharesLateral Movement

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading