Skip to content
System

System Event ID 5827: Vulnerable Netlogon channel denied

The Netlogon service denied a vulnerable Netlogon secure channel connection from a machine accountSystem event 5827: a DC denied a machine account's Netlogon secure channel without secure RPC. Key Zerologon (CVE-2020-1472) signal.
5827
Event ID
5827
Channel
System
Provider
NETLOGON
Log file
System.evtx
Category
Active Directory
Default logging
Logged by default

What event 5827 means

Event 5827 is logged by the NETLOGON service on domain controllers that have the CVE-2020-1472 (Zerologon) updates. It means a client authenticating as a machine account attempted a Netlogon secure channel connection that does not use secure RPC, and the DC refused it.

After the enforcement phase (February 2021 updates) DCs deny these connections by default, so 5827 is what remains of both legacy devices that were never fixed and Zerologon exploitation attempts. The event names the machine account, its domain, account type and the operating system it reported. Related events: 5828 (same, for a trust account), 5829 (vulnerable connection allowed, pre-enforcement), and 5830/5831 (allowed by the "Allow vulnerable Netlogon secure channel connections" policy).

Zerologon tooling typically targets the DC's own computer account, so a 5827 naming a domain controller account, or coming from a system that claims an odd or empty operating system, deserves immediate attention.

When it is logged

Audit policy / configuration

Logged to the System log of domain controllers with the CVE-2020-1472 updates installed (August 2020 and later).

The event data is a set of unnamed insertion strings; this viewer shows them joined in Data1. The Netlogon debug log (%windir%\debug\netlogon.log) can add the client IP address.

Key fields

FieldWhat it tells you
Data1Insertion strings in message order — machine SamAccountName, domain, account type, machine operating system, OS build and service pack.

Common benign sources

  • Old or third-party devices (NAS appliances, legacy Samba, embedded systems) that do not support secure RPC.

What attackers do that produces it

  • Zerologon exploitation attempts (Mimikatz lsadump::zerologon, public PoC scripts) against a patched DC, usually targeting a domain controller's machine account.

Investigation tips

  • Identify the machine account and check whether it belongs to a real, known device.
  • Treat a DC machine account in 5827 as an attack until proven otherwise; hunt for DCSync (4662) and DC account password changes (4742) on all DCs.
  • Find the source IP in the Netlogon debug log or in network telemetry for the same second.
  • On unpatched DCs there is no 5827; look for 4742 on a DC account followed by replication-based credential theft instead.

MITRE ATT&CK techniques

TechniqueTactics
T1210 Exploitation of Remote ServicesLateral Movement

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading