Windows event 4625: reading failed logons and finding attacking IPs

3 min read · updated 7 October 2026

Event 4625, “An account failed to log on”, is the main trace of password guessing on Windows. It is written to the Security log for every failed logon, locally or over the network. This page explains the fields that matter and how to turn them into a list of attacking IPs.

Make sure the event is being written

Event 4625 appears only if auditing of failed logons is on. Check the Logon subcategory (the GUID works on any Windows language):

auditpol /get /subcategory:"{0CCE9215-69AE-11D9-BED3-505054503030}"

If “Failure” is missing, enable it:

auditpol /set /subcategory:"{0CCE9215-69AE-11D9-BED3-505054503030}" /failure:enable

Fields that matter

  • Source Network Address: the attacker's IP. It can be empty (-) for RDP with NLA; then use event 140 in the RemoteDesktopServices-RdpCoreTS/Operational log, see RDP brute-force protection.
  • Logon Type: 3 is a network logon (SMB, NLA RDP, many services), 10 is RemoteInteractive (RDP), 8 is network cleartext (often IIS or mail basic auth).
  • Account Name: the username tried. Bots try administrator, admin, sa and similar names.
  • Status / Sub Status: why it failed. 0xC000006A is a known user with a wrong password, 0xC0000064 is a user that does not exist, 0xC0000234 is a locked-out account.

List the attacking IPs

This PowerShell command shows the addresses with the most failures in the last hour. Index 19 of the event properties is the source address:

Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625; StartTime=(Get-Date).AddHours(-1)} |
  ForEach-Object { $_.Properties[19].Value } |
  Where-Object { $_ -match '^\d{1,3}(\.\d{1,3}){3}$' } |
  Group-Object | Sort-Object Count -Descending |
  Select-Object -First 20 Count, Name

From reading events to blocking

Reading the log is the easy half. Turning it into bans needs a threshold, a firewall rule, expiry and a whitelist; a ready script is in the RDP article, and the options are compared in Fail2ban for Windows. KIPBan does this on every server and shares the result across your fleet.

Questions about event 4625

Why is the source address empty in event 4625?

With NLA enabled the client address can be missing from 4625. Take it from event 140 in the RdpCoreTS operational log.

What is the difference between event 4625 and 4771?

4625 is a failed logon on a member server or workstation. 4771 is a failed Kerberos pre-authentication recorded on a domain controller.

Why do I see thousands of 4625 events a day?

If a service is exposed to the internet, bots guess passwords continuously. That is normal noise, and a reason to block the sources automatically.