alienvault:/# tail -10f /var/ossec/logs/archives/archives.log |grep "4771" 2017 Mar 0210:01:32 (Host-192-168-69-109) 192.168.69.109->WinEvtLog 2017 Mar 0210:01:27 WinEvtLog: Security: AUDIT_FAILURE(4771): Microsoft-Windows-Security-A uditing: (no user): no domain: WIN-P84RKPA31HU.zymtest08.com: Kerberos pre-authentication failed. Account Information: Security ID: S-1-5-21-2947644658-998118976 -1121298578-1117 Account Name: cc Service Information: Service Name: krbtgt/ZYMTEST08 Network Information: Client Address: ::ffff:192.168.69.147 Client Port: 1172 Additional Information: Ticket Options: 0x40810010 Failure Code: 0x18 Pre-Authentication Type: 2 Certificate Information: Certificate Issuer Name: Certificate Serial Number: Certificate Thumbprint: Certificate information is only provided if a certificate was used for pre-authentication. Pre-authentication types, ticket options and failure codes are defined in RFC 4120. If the ticket was malformed or damaged during transit and could not be decrypted, then many fields in this event might not be present.
alienvault:/# tail -10f /var/ossec/logs/alerts/alerts.log |grep "4771" AV - Alert - "1488420926" --> RID: "18105"; RL: "4"; RG: "windows,"; RC: "Windows audit failure event."; USER: "(no user)"; SRCIP: "None"; HOSTNAME: "(Host-192-168-69-109) 192.168.69.109->WinEvtLog"; LOCATION: "(Host-192-168-69-109) 192.168.69.109->WinEvtLog"; EVENT: "[INIT]2017 Mar 0210:15:19 WinEvtLog: Security: AUDIT_FAILURE(4771): Microsoft-Windows-Security-Auditing: (no user): no domain: WIN-P84RKPA31HU.zymtest08.com: Kerberos pre-authentication failed. Account Information: Security ID: S-1-5-21-2947644658-998118976-1121298578-1117 Account Name: cc Service Information: Service Name: krbtgt/ZYMTEST08 Network Information: Client Address: ::ffff:192.168.69.147 Client Port: 1185 Additional Information: Ticket Options: 0x40810010 Failure Code: 0x18 Pre-Authentication Type: 2 Certificate Information: Certificate Issuer Name: Certificate Serial Number: Certificate Thumbprint: Certificate information is only provided if a certificate was used for pre-authentication. Pre-authentication types, ticket options and failure codes are defined in RFC 4120. If the ticket was malformed or damaged during transit and could not be decrypted, then many fields in this event might not be present.[END]";
alienvault:~# tail -10f /var/ossec/logs/alerts/alerts.log |grep "18120" AV - Alert - "1488867475" --> RID: "18120"; RL: "4"; RG: "windows,"; RC: "4771-Windows login fail."; USER: "(no user)"; SRCIP: "None"; HOSTNAME: "(Host-192-168-0-201) 192.168.0.201->WinEvtLog"; LOCATION: "(Host-192-168-0-201) 192.168.0.201->WinEvtLog"; EVENT: "[INIT]2017 Mar 07 14:17:55 WinEvtLog: Security: AUDIT_FAILURE(4771): Microsoft-Windows-Security-Auditing: (no user): no domain: GLODON-DC01.grandsoft.com.cn: Kerberos pre-authentication failed. Account Information: Security ID: S-1-5-21-436374069-1957994488-1801674531-53787 Account Name: AUTOTEST128004$ Service Information: Service Name: krbtgt/grandsoft.com.cn Network Information: Client Address: ::ffff:192.168.128.4 Client Port: 58977 Additional Information: Ticket Options: 0x40810010 Failure Code: 0x18 Pre-Authentication Type: 2 Certificate Information: Certificate Issuer Name: Certificate Serial Number: Certificate Thumbprint: Certificate information is only provided if a certificate was used for pre-authentication. Pre-authentication types, ticket options and failure codes are defined in RFC 4120. If the ticket was malformed or damaged during transit and could not be decrypted, then many fields in this event might not be present.[END]";