How to Analyze Windows Event Logs
What’s in a Windows Security event
Each Windows Security event carries an EventID, a TimeCreated SystemTime, the Computer it came from, and an EventData block of named <Data> fields. For authentication events the fields that matter most are TargetUserName, IpAddress, LogonType, and — on failures — Status and SubStatus. LogTriage’s parser reads both the XML export and binary .evtx, mapping each recognized EventID to a normalized event: 4625 becomes a failed POST /windows/logon, 4624 a successful one, and 4688 a process event whose path includes the executable name.
What to look at first
- 4625 failed logons grouped by
IpAddress. One source failing against manyTargetUserNamevalues is password spraying; one source hammering one account is brute force. Both are LogonType 3 in the common remote case. - The
SubStatuson each 4625.0xC000006A(bad password) versus0xC0000064(no such account) tells you whether the attacker already has valid usernames. - A 4624 success from an attacker
IpAddressafter a run of failures. This is the compromise moment. Note theWorkstationNameandAuthenticationPackageName— an NTLM logon from a name likeATTACKER-VMis a red flag. - 4672 special privileges assigned to the account that just logged on — an early sign the compromised identity is privileged.
- 4688 process creation with a suspicious
CommandLine(for examplenet group "Domain Admins" /domain), and 4720 / 4728 for account creation and Domain Admins membership — the persistence stage.
Common patterns and what they mean
| Pattern | Likely meaning |
|---|---|
Many 4625 from one IP across many usernames, SubStatus 0xC000006A | Password spraying |
| Many 4625 against one username from one IP | Brute force |
4625 with SubStatus 0xC0000064 across many names | Username enumeration |
| 4625 failures then a 4624 success, same IP | Successful compromise after guessing |
| 4720 then 4728 (add to Domain Admins) | Backdoor account + privilege escalation |
| 4698 scheduled task creation with encoded PowerShell | Persistence |
Where manual log review breaks down
The Security log on a domain controller can produce thousands of 4625 events an hour from ordinary mistyped passwords and stale cached credentials, so the campaign that matters — one source, many accounts, one eventual success — is genuinely hard to see by scrolling. LogTriage groups failed logons by source IP inside a session window and raises a credential-stuffing pattern when the volume and failure rate cross the threshold, escalating to critical when a successful logon appears in the same session. The attacker IP is also checked against confirmed-malicious CIDR ranges, so a logon attempt from a known Tor exit is flagged even before the pattern completes. There is a published, sample-validated Sigma rule for the 4625 spraying case, LTR-0012, and a companion use case on Windows credential stuffing.
Frequently Asked Questions
- Do I need to convert .evtx to XML before analysis?
- Not necessarily. LogTriage reads binary .evtx directly when the optional python-evtx dependency is installed, and reads Event Viewer / wevtutil XML exports natively. If you cannot install python-evtx, export first with wevtutil qe Security /f:xml > events.xml (or Event Viewer's Save All Events As, choosing XML) and upload that.
- What does the SubStatus code on a 4625 event tell me?
- The SubStatus refines the top-level Status. 0xC000006A means the account exists but the password was wrong (brute force / spraying). 0xC0000064 means the account name does not exist (username enumeration). 0xC0000234 means the account is locked out, and 0xC0000072 means it is disabled. Reading SubStatus is how you tell what phase of an attack you are looking at.
- Which LogonType values matter for intrusion detection?
- LogonType 3 is a network logon (SMB, remote auth) — the type most brute force and lateral movement produces. LogonType 10 is RemoteInteractive (RDP). LogonType 2 is a physical console logon. LogonType 3 failures in volume from one source, or a LogonType 10 success from an unfamiliar address, are the ones worth chasing.
- Which Event IDs should I export for a compromise investigation?
- At minimum 4625 (failed logon), 4624 (success), 4648 (explicit-credential logon), 4672 (special privileges assigned), 4688 (process creation with command line), 4720 (account created), 4728/4732/4756 (group membership added), and the Kerberos 4768/4769/4771 events. Together they cover the arc from initial guessing through privilege escalation and persistence.
Related Resources
See this detection run on a real report
Try the live demo with a pre-loaded malicious log set — no signup required — or upload your own log file and get a full AI-reviewed threat report in minutes.