WinRM Event ID 169: User authenticated (legacy)
- Event ID
- 169
- Channel
- Microsoft-Windows-WinRM/Operational
- Provider
- Microsoft-Windows-WinRM
- Log file
- Microsoft-Windows-WinRM%4Operational.evtx
- Category
- Remote access
- Default logging
- Logged by default
What event 169 means
Event 169 is written by the WinRM service on the target when a remote user authenticates successfully. It names the account (username) and the authentication mechanism (authenticationMechanism, such as Negotiate, Kerberos or Basic), which makes it a convenient server-side marker for the start of a remote management session.
The event is tied to older Windows releases. It appears in the WinRM provider manifest of Windows 7 and Windows Server 2008 R2, but not in the manifests of later releases (Windows 8 through Windows 11, Server 2012 through Server 2022), so on modern systems its absence says nothing. There, rely on event 91 plus Security 4624 (type 3) for the account and source.
Where it exists, it pairs with event 91 (shell created) and the network logon to reconstruct who connected and how.
When it is logged
None — the Microsoft-Windows-WinRM/Operational channel is enabled by default, on Windows versions whose WinRM provider defines this event.
Defined in the Windows 7 / Server 2008 R2 WinRM manifest; not defined in the manifests of Windows 8 through Windows 11 or Server 2012 through Server 2022. Treat it as legacy evidence and use 91 and Security 4624 on current systems.
Key fields
| Field | What it tells you |
|---|---|
| username | Account that authenticated to WinRM (DOMAIN\user). |
| authenticationMechanism | Authentication method used, e.g. Negotiate, Kerberos or Basic. Basic authentication sends credentials that are only protected by the transport, so it is worth flagging. |
Common benign sources
- Administrators and management tools connecting to legacy servers with WinRM.
What attackers do that produces it
- Lateral movement through PowerShell remoting or
winrsto older hosts with stolen credentials.
Investigation tips
- Correlate with Security 4624 (type 3) for the source IP and with event 91 for the shell type.
- Flag Basic authentication and accounts that do not normally manage the host.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.