Splunk Correlation Rules for Windows Event ID 4624 and 4625

Monitoring and analyzing Windows Event Logs is a critical element of any organization’s security strategy. Of the many events recorded, Windows Event ID 4624 (successful first logon session) and 4625 (failed new logon session) can be particularly helpful for detecting potential security threats.
In this blog post, we’ll walk you through creating a Splunk correlation rule that utilizes these two Event IDs to help detect suspicious logon activity in real time.
Overview of Windows Security Logs and Auditing
Windows Security Logs and Auditing are essential tools for system administrators and security professionals to monitor, manage, and maintain the security posture of their Windows-based systems. They offer a comprehensive record of system events and user activities that provide valuable insights into potential security threats and vulnerabilities.
Windows Security Logs are generated by the operating system and contain information related to various security events, such as logon attempts, file access, and policy changes.
These logs can be viewed, filtered, and analyzed using Event Viewer–an integral Windows utility that enables viewing, filtering, and analyzing recorded activities. Security auditing, on the other hand, involves configuring your system so it tracks specific types of activities and generates log entries accordingly. This includes the authentication information field and source machine details.
Auditing allows you to keep an eye on the critical events within your environment and take proactive measures for system security. This process is highly customizable, allowing you to select only those events which are most pertinent to your organization’s security requirements.
Windows Security Log Event ID 4624: An Account was successfully logged on
Event ID 4624 is generated when a successful user logon occurs on a Windows device. This event is essential in monitoring user logs and activity, ensuring only authorized personnel have access to your system. Analyzing event ID 4624 allows you to monitor successful logons, monitor your computer account credentials and maintain system security. The Security Identifier (SID) plays a key role in this.
Windows Security Log Event ID 4625: An Account failed to log on
Windows Event ID 4625 is an essential security log event that records failed logon attempts. This occurs when a user attempts to log on with an incorrect username or password on the Windows system. It may also include a bad password or workstation restriction.
It also records the source IP address from which the user or computer logged-on attempt was made, as well as other details related to the failed attempt, such as hexadecimal codes. Organizations can utilize this event for detecting potential malicious activity and taking appropriate action; additionally, auditing purposes are undertaken in order to guarantee compliance with security policies.
Why Windows Event ID 4624 and 4625 Matter for Security?
Windows Event ID 4624 and 4625 are essential security and logon failed events that any system administrator or security professional should be familiar with. These events provide valuable data regarding behalf of a user’s password logon attempts, both successful and unsuccessful. They also can include textual explanation and unhashed form information.
- Event ID 4624: Represents a successful logon attempt and can be used to monitor user activity, identify unauthorized access points and track access patterns.
- Event ID 4625: Signals a failed logon attempt, which may indicate potential brute force attacks, password guessing attempts, or attempts to gain unauthorized access.
The Benefits of Using Windows Event ID for Security Monitoring
Utilizing Windows Event IDs for security monitoring provides organizations with numerous advantages, enabling them to strengthen their defenses and safeguard Windows operating systems against potential threats.
By correlating these two events in Splunk, you can gain valuable insights into your environment and local system’s security posture and quickly detect and address potential threats. This could involve security database or security package analysis.
Components of Event ID 4624 and 4625
In the constantly evolving world of cybersecurity, vigilance is paramount. Within the vast labyrinth of logs and alerts lies vital information that can shield an organization from potential cyber threats. Let’s focus our lens on two critical events, ID 4624 and 4625, and dissect the nuances they carry. Understanding these elements is akin to knowing the pulse of your system, allowing prompt and precise action.
A Closer Look at Logon Information: The Account Domain
Imagine the logon information as the fingerprints of a user’s identity. For event IDs 4624 and 4625, these fingerprints contain intricate details:
- Who: The person initiating the logon request.
- Account Name and Domain: The username and domain involved in the request.
- Security Identifier (SID): A unique token representing the user’s credentials.
These fragments piece together the puzzle of a user’s logon attempt. Was it a legitimate entry, or did it bear the signs of malevolent intent? Such inquiries can be answered, bringing clarity to the shadowy recesses of unauthorized access attempts.
The Significance of Logon Type
Logon types, while appearing simple, narrate a story of how a user entered the digital kingdom. Event IDs 4624 and 4625 bring forth a tapestry of methods:
- Interactive Logon: Direct access to the system.
- Network Logon: Through network protocols.
- Remote Desktop Logon: Via remote desktop services.
Each type unfolds a context, providing invaluable insights into the nature of the logon attempt. It’s like opening different doors, and understanding these doors helps in identifying if any are left ajar, becoming vulnerabilities.
Impersonation Level
Within the Windows environment lies a carefully orchestrated dance of trust. Impersonation levels in event ID 4624 and logon ID 4625 reveal how a trusted logon process can wear the mask of another user.
- Access and Actions: It uncovers what the user can touch and transform within the system.
These impersonation levels are a double-edged sword; they can aid in authorized actions or become conduits for privilege escalation attacks. Monitoring them is akin to watching the shadows, catching glimpses of potential anomalies.
Network Information: Source Network Address
Finally, the network information paints a picture of the digital highways traversed during a logon attempt. Essential elements for event ID 4624 and 4625 include:
- IP Address & Hostname: Identifying the device at the origin of the request.
- Source Network Address & Port Number: The pathways and doors used in the attempt.
This aspect is like mapping the geographical contours of a cyber expedition, helping to spot unusual patterns or pinpointing sources of potential threats.
Understanding and decoding these events isn’t a task for the uninitiated; it’s the craft of skilled SOC analysts, those guardians at the gates. For those tasked with defending the digital realms, the wisdom encoded in these events is the sword and shield. Carry them with confidence, and let your systems stand tall and unbreached.
Sample Windows Event Logs:
Windows Event ID 4624:
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 4/14/2023 10:15:23 AM
Event ID: 4624
Task Category: Logon
Level: Information
Keywords: Audit Success
User: N/A
Computer: SERVER01.example.com
Description:
An account was successfully logged on.
Subject:
Security ID: SYSTEM
Account Name: SERVER01$
Account Domain: EXAMPLE
Logon ID: 0x3E7
Logon Information:
Logon Type: 10
Restricted Admin Mode: -
Virtual Account: No
Elevated Token: Yes
New Logon:
Security ID: EXAMPLE\jdoe
Account Name: jdoe
Account Domain: EXAMPLE
Logon ID: 0x4A55F
Linked Logon ID: 0x0
Network Account Name: -
Network Account Domain: -
Logon GUID: {12345678-1234-1234-1234-123456789ABC}
Process Information:
Process ID: 0x1f4
Process Name: C:\Windows\System32\winlogon.exe
Network Information:
Workstation Name: LAPTOP01
Source Network Address: 192.168.1.10
Source Port: 55023
Detailed Authentication Information:
Logon Process: User32
Authentication Package: Negotiate
Transited Services: -
Package Name (NTLM only): -
Key Length: 0
Windows Event ID 4625:
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 4/14/2023 10:20:30 AM
Event ID: 4625
Task Category: Logon
Level: Information
Keywords: Audit Failure
User: N/A
Computer: SERVER01.example.com
Description:
An account failed to log on.
Subject:
Security ID: SYSTEM
Account Name: SERVER01$
Account Domain: EXAMPLE
Logon ID: 0x3E7
Logon Type: 10
Account For Which Logon Failed:
Security ID: NULL SID
Account Name: jdoe
Account Domain: EXAMPLE
Failure Information:
Failure Reason: Unknown user name or bad password.
Status: 0xC000006D
Sub Status: 0xC000006A
Process Information:
Process ID: 0x1f4
Process Name: C:\Windows\System32\winlogon.exe
Network Information:
Workstation Name: LAPTOP01
Source Network Address: 192.168.1.10
Source Port: 55100
Detailed Authentication Information:
Logon Process: User32
Authentication Package: Negotiate
Transited Services: -
Package Name (NTLM only): -
Key Length: 0
Creating a Splunk Correlation Rule with Windows Event ID 4624 and 4625
Creating a Splunk correlation rule that monitors both successful and unsuccessful logon attempts using Windows Event ID 4624 and 4625:
1. Collect Windows Event Logs
This step should be done first:
Before you begin, ensure you’re collecting Windows Event Logs from your local system, domain, server service, controllers’ Windows server service account, or other critical systems. You can do this using Splunk’s Universal Forwarder or a third-party log collector and import them into your Splunk environment. This includes applying the correct audit settings and monitoring for network connectivity issues.
2. Filter Events by Event IDs
index=wineventlog (EventCode=4624 OR EventCode=4625)
Create a search query in Splunk that filters events based on Event IDs 4624 and 4625 to isolate pertinent logon events for further analysis. Utilize the filter dialog to create a complex filter if necessary.
3. Extract Relevant Fields
index=wineventlog (EventCode=4624 OR EventCode=4625)
| eval LogonType=case(EventCode=4624, Logon_Type, EventCode=4625, Logon_Type)
| eval AccountName=case(EventCode=4624, Account_Name, EventCode=4625, Account_Name)
| eval WorkstationName=case(EventCode=4624, Workstation_Name, EventCode=4625, Workstation_Name)
| eval LogonStatus=case(EventCode=4624, "Success", EventCode=4625, "Failure")
Create a search query in Splunk that filters events based on Event IDs 4624 and 4625 to isolate pertinent logon events for further analysis. Utilize the filter dialog to create a complex filter if necessary.
4. Create a Correlation Rule
Now that you have filtered the events and extracted pertinent fields, you can create a correlation rule tailored to your organization’s requirements. For instance, you might want to identify multiple failed logon attempts followed by successful remote logon services or remote desktop requests from the same source network address within a short timeframe.
index=wineventlog (EventCode=4624 OR EventCode=4625)
| eval LogonType=case(EventCode=4624, Logon_Type, EventCode=4625, Logon_Type)
| eval AccountName=case(EventCode=4624, Account_Name, EventCode=4625, Account_Name)
| eval WorkstationName=case(EventCode=4624, Workstation_Name, EventCode=4625, Workstation_Name)
| eval LogonStatus=case(EventCode=4624, "Success", EventCode=4625, "Failure")
| bucket _time span=1h
| stats count(eval(LogonStatus="Failure")) as FailedCount, count(eval(LogonStatus="Success")) as SuccessCount by AccountName, WorkstationName, LogonType, _time
| where FailedCount > 5 AND SuccessCount > 0
These parameters are not etched in stone. Like the adjustable limbs of a spy gadget, you can modify the thresholds and time window to align with your organization’s unique security policies. It’s about crafting a fit that’s just right for your environment.
5. Monitor and Investigate
With the correlation rule set up, the next phase is akin to manning a watchtower:
- Monitor: Keep an eye on the results for hints of lurking dangers, like suspicious logon activity or authentication failure.
- Investigate: Employ saved searches or design alerts to notify when strange logon patterns surface or when malicious actions are detected.
- Visualize: A dashboard isn’t merely aesthetic; it’s a canvas that translates data into insights, streamlining further investigation and highlighting breaches in server event and security option adjustments.
6. Fine-Tune and Optimize
Continual vigilance might reveal a need to calibrate your watchtower’s lenses. This isn’t a one-time set-up but an ongoing commitment to:
- Reduce False Positives: Fine-tuning to avoid unnecessary alarms.
- Align with Policies: Ensuring the authentication process resonates with organizational security measures, and compliance with security policies.
- Iterate & Optimize: Ensuring the correlation rule’s continued potency in detecting unusual logon activities, including those that might involve outbound connections or specific authentication attacks.
Analyzing Windows Logon Events
Traversing the tracks of both triumphs and tribulations in logon attempts is vital in fortifying your digital fortress. From unauthorized access to potential brute-force attacks, the trails are rich with clues. Here’s how you can embark on this essential journey:
- Enable Logon Event Auditing: Before the hunt begins, set the stage:
- Auditing Activation: Through Group Policy or Local Security Policy, switch on the auditing for both successful and failed logons. Think of it as tuning into specific radio frequencies.
- Understand the Event IDs
- Know the language of the logs:
- Event ID 4624: Successful logon.
- Event ID 4625: Failed logon.
- Event ID 4776: Domain controller authentication.
- These codes narrate the saga of logon events.
- Know the language of the logs:
- Tools of the Trade
- The arsenal at your disposal includes:
- Event Viewer: The magnifying glass that lets you delve into the Windows Security Logs.
- The arsenal at your disposal includes:
- SIEM Tools & Log Management Solutions: The heavyweight champions for larger environments.
- Alerts & Notifications: Custom alarms that sing the tunes of potential threats.
- Regular Reviews: Continual analysis to spot trends and anomalies.
Conclusion: The Proactive Stance
By weaving the Splunk correlation rule with Windows Event IDs 4624 and 4625 into your security fabric, you’re not merely monitoring but actively engaging with potential threats. From anomalous user activity to bad username and wrong password usage, the wisdom embedded in these practices ensures that your Windows Security Logs are more than mere records; they’re the living pulse of your security ecosystem.
Remember, in the fluid world of cyber threats, it’s not about building impregnable walls but nurturing an environment that evolves and adapts. The steps laid out are akin to building fortifications, allowing your security team, including database administrators with administrator rights, to be swift and decisive. Continual refinement ensures the walls stay strong and aligned with baseline security templates, advanced audit policy settings, and the overall security posture of the organization.



black text on a navy page is definitely a choice. each of those events contains two instances of “Security ID” and “account anme”.. obviously most of the time i’ll only care abotu one of them, but splunk is going to collect them both. how do i only collect the one i care about?
You need to pick the “Security ID” and “Account Name” under “New Logon:” which is the user account (This is the user logging-in). The one under “Subject” is usually the system that you’re logging into, so the account here refers to the system account.
You can use the mvindex function in Splunk. Index ‘0’ would be the Subject, and Index ‘1’ would be the New Logon. Below is how I would extract the field:
index=wineventlog (EventCode=4624 OR EventCode=4625)
| eval LogonType=case(EventCode=4624, Logon_Type, EventCode=4625, Logon_Type)
| eval AccountName=coalesce(mvindex(Account_Name,1), Account_Name)
| eval WorkstationName=case(EventCode=4624, Workstation_Name, EventCode=4625, Workstation_Name)
| eval LogonStatus=case(EventCode=4624, “Success”, EventCode=4625, “Failure”)