Unable to hunt down the user/process that failes to authenticate on DC

0

I monitor for failed authentications on DC’s.

labels: Authentication | Fail | Kerberos | User

My top failed authentications is on one client/one account that I can’t hunt down. I have looked at all process’es and their “credential’s” + installed sysmon on the client. But I can’t find the process or user. Any ideas how I could hunt this down?

Share This Post:

8 comments

Date Votes
0
Avatar
Gustav Elkjær Rødsgaard

Hi Henrik,

I am unsure i understand your question properly. What do you mean excatly when you say you can’t hunt down the account?

Best Regards,
Gustav

0
Avatar
Network Team

I mean that I can’t find which process on the target is doing the logons. There is nothing in the security or sysmon eventlog on the target, no scheduled tasks, processes, config files with that account. The failed logins accour once a minute.

0
Avatar
Gustav Elkjær Rødsgaard

Hi,

Alirght, that makes more sense.

Can you tell me which event id you get from the failed login events?

Best Regards,
Gustav

0
Avatar
Network Team

Hi!

SID is mapped to a valid user account in AD, 0x18 is the the status_code.

Please sign in to leave a comment.