Event 4625, “An account failed to log on”, is the main trace of password guessing on Windows. It is written to the Security log for every failed logon, locally or over the network. This page explains the fields that matter and how to turn them into a list of attacking IPs.
Make sure the event is being written
Event 4625 appears only if auditing of failed logons is on. Check the Logon subcategory (the GUID works on any Windows language):
auditpol /get /subcategory:"{0CCE9215-69AE-11D9-BED3-505054503030}"
If “Failure” is missing, enable it:
auditpol /set /subcategory:"{0CCE9215-69AE-11D9-BED3-505054503030}" /failure:enable
Fields that matter
- Source Network Address: the attacker's IP. It can be empty (
-) for RDP with NLA; then use event 140 in theRemoteDesktopServices-RdpCoreTS/Operationallog, see RDP brute-force protection. - Logon Type: 3 is a network logon (SMB, NLA RDP, many services), 10 is RemoteInteractive (RDP), 8 is network cleartext (often IIS or mail basic auth).
- Account Name: the username tried. Bots try
administrator,admin,saand similar names. - Status / Sub Status: why it failed.
0xC000006Ais a known user with a wrong password,0xC0000064is a user that does not exist,0xC0000234is a locked-out account.
List the attacking IPs
This PowerShell command shows the addresses with the most failures in the last hour. Index 19 of the event properties is the source address:
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625; StartTime=(Get-Date).AddHours(-1)} |
ForEach-Object { $_.Properties[19].Value } |
Where-Object { $_ -match '^\d{1,3}(\.\d{1,3}){3}$' } |
Group-Object | Sort-Object Count -Descending |
Select-Object -First 20 Count, Name
From reading events to blocking
Reading the log is the easy half. Turning it into bans needs a threshold, a firewall rule, expiry and a whitelist; a ready script is in the RDP article, and the options are compared in Fail2ban for Windows. KIPBan does this on every server and shares the result across your fleet.
Questions about event 4625
Why is the source address empty in event 4625?
With NLA enabled the client address can be missing from 4625. Take it from event 140 in the RdpCoreTS operational log.
What is the difference between event 4625 and 4771?
4625 is a failed logon on a member server or workstation. 4771 is a failed Kerberos pre-authentication recorded on a domain controller.
Why do I see thousands of 4625 events a day?
If a service is exposed to the internet, bots guess passwords continuously. That is normal noise, and a reason to block the sources automatically.