← Back to Explore
sigmamediumHunting
Account Tampering - Suspicious Failed Logon Reasons
This method uses uncommon error codes on failed logons to determine suspicious activity and tampering with accounts that have been disabled or somehow restricted.
Detection Query
selection_eid:
EventID:
- 4625
- 4776
selection_status:
- Status:
- "0xC0000072"
- "0xC000006F"
- "0xC0000070"
- "0xC0000413"
- "0xC000018C"
- "0xC000015B"
- SubStatus:
- "0xC0000072"
- "0xC000006F"
- "0xC0000070"
- "0xC0000413"
- "0xC000018C"
- "0xC000015B"
filter:
SubjectUserSid: S-1-0-0
condition: all of selection_* and not filter
Author
Florian Roth (Nextron Systems)
Created
2017-02-19
Data Sources
windowssecurity
Platforms
windows
References
Tags
attack.persistenceattack.defense-evasionattack.privilege-escalationattack.initial-accessattack.t1078
Raw Content
title: Account Tampering - Suspicious Failed Logon Reasons
id: 9eb99343-d336-4020-a3cd-67f3819e68ee
status: test
description: This method uses uncommon error codes on failed logons to determine suspicious activity and tampering with accounts that have been disabled or somehow restricted.
references:
- https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4625
- https://twitter.com/SBousseaden/status/1101431884540710913
author: Florian Roth (Nextron Systems)
date: 2017-02-19
modified: 2025-10-17
tags:
- attack.persistence
- attack.defense-evasion
- attack.privilege-escalation
- attack.initial-access
- attack.t1078
logsource:
product: windows
service: security
detection:
selection_eid:
EventID:
- 4625
- 4776
selection_status:
- Status:
- '0xC0000072' # User logon to account disabled by administrator
- '0xC000006F' # User logon outside authorized hours
- '0xC0000070' # User logon from unauthorized workstation
- '0xC0000413' # Logon Failure: The machine you are logging onto is protected by an authentication firewall. The specified account is not allowed to authenticate to the machine
- '0xC000018C' # The logon request failed because the trust relationship between the primary domain and the trusted domain failed
- '0xC000015B' # The user has not been granted the requested logon type (aka logon right) at this machine
- SubStatus:
- '0xC0000072' # User logon to account disabled by administrator
- '0xC000006F' # User logon outside authorized hours
- '0xC0000070' # User logon from unauthorized workstation
- '0xC0000413' # Logon Failure: The machine you are logging onto is protected by an authentication firewall. The specified account is not allowed to authenticate to the machine
- '0xC000018C' # The logon request failed because the trust relationship between the primary domain and the trusted domain failed
- '0xC000015B' # The user has not been granted the requested logon type (aka logon right) at this machine
filter:
SubjectUserSid: 'S-1-0-0'
condition: all of selection_* and not filter
falsepositives:
- User using a disabled account
level: medium