System Event ID 5827: Vulnerable Netlogon channel denied
- Event ID
- 5827
- Channel
- System
- Provider
- NETLOGON
- Log file
- System.evtx
- Category
- Active Directory
- Default logging
- Logged by default
What event 5827 means
Event 5827 is logged by the NETLOGON service on domain controllers that have the CVE-2020-1472 (Zerologon) updates. It means a client authenticating as a machine account attempted a Netlogon secure channel connection that does not use secure RPC, and the DC refused it.
After the enforcement phase (February 2021 updates) DCs deny these connections by default, so 5827 is what remains of both legacy devices that were never fixed and Zerologon exploitation attempts. The event names the machine account, its domain, account type and the operating system it reported. Related events: 5828 (same, for a trust account), 5829 (vulnerable connection allowed, pre-enforcement), and 5830/5831 (allowed by the "Allow vulnerable Netlogon secure channel connections" policy).
Zerologon tooling typically targets the DC's own computer account, so a 5827 naming a domain controller account, or coming from a system that claims an odd or empty operating system, deserves immediate attention.
When it is logged
Logged to the System log of domain controllers with the CVE-2020-1472 updates installed (August 2020 and later).
The event data is a set of unnamed insertion strings; this viewer shows them joined in Data1. The Netlogon debug log (%windir%\debug\netlogon.log) can add the client IP address.
Key fields
| Field | What it tells you |
|---|---|
| Data1 | Insertion strings in message order — machine SamAccountName, domain, account type, machine operating system, OS build and service pack. |
Common benign sources
- Old or third-party devices (NAS appliances, legacy Samba, embedded systems) that do not support secure RPC.
What attackers do that produces it
- Zerologon exploitation attempts (Mimikatz
lsadump::zerologon, public PoC scripts) against a patched DC, usually targeting a domain controller's machine account.
Investigation tips
- Identify the machine account and check whether it belongs to a real, known device.
- Treat a DC machine account in 5827 as an attack until proven otherwise; hunt for DCSync (4662) and DC account password changes (4742) on all DCs.
- Find the source IP in the Netlogon debug log or in network telemetry for the same second.
- On unpatched DCs there is no 5827; look for 4742 on a DC account followed by replication-based credential theft instead.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1210 Exploitation of Remote Services | Lateral Movement |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.