cybersecurity
education
€ EUR
  • $ USD
  • € EUR

CQURE Hacks #84: Understanding Event ID 4624 in Action

In this episode of CQURE Hacks, we explore Event ID 4624 in a practical lab and demonstrate how different logon scenarios appear in Windows Security logs and how they can be analyzed from a threat hunting perspective.

by Kajetan Porwolik, CQURE

Event ID 4624 is one of the most important Windows events for monitoring successful logons.

We start by enabling detailed logon auditing on the Domain Controller and then generate several different logon scenarios, including:

1. Workstation unlocks, Logon Type 7

2. Local interactive logons, Type 2

3. Network authentication, Type 3

4. New logon session with alternate credentials for network connections, Type 9

5. RDP sessions, Types 7 and 10

6. Service logons, Type 5

We also demonstrate how SMB activity from Kali Linux appears on the Domain Controller and which fields are most useful during analysis, including:

1. Logon Type

2. Logon Process

3. Authentication Package

4. Source Network Address

    The key takeaway is that Event ID 4624 becomes most valuable when you correlate its fields and understand the context behind the logon.

    A single Type 3, Type 7, or Type 9 event may be completely legitimate. But when you combine the logon type with the account used, source IP address, authentication package, and surrounding activity, it becomes much easier to distinguish normal behavior from activity worth investigating. That is why Event ID 4624 is such a valuable source for Windows authentication analysis, threat hunting, and lateral movement investigations.

    After restoring Bob’s original UPN, the certificate is used for authentication and is mapped by the KDC to the real Administrator account. This allows us to obtain an Administrator TGT and recover the Administrator NT hash.

    With Domain Admin privileges, the demonstration concludes with DCSync, retrieving the krbtgt account hash.

    The attack highlights why AD CS configuration, certificate mapping settings, and permissions to modify identity attributes such as userPrincipalName should all be carefully reviewed. A seemingly small certificate configuration issue can become part of a complete domain compromise.

    Want to learn more?

    Join our FREE live webinar:

    Uncovering New Identity Theft Vectors and How to Mitigate Them

    Discover how identity theft no longer begins and ends with a stolen password.

    Paula Januszkiewicz (CEO of CQURE and CQURE Academy, Cybersecurity Expert & Red Teamer, Microsoft Regional Director, MVP, and MCT) will unveil new identity attack paths, including original research from the CQURE Team demonstrating how an attacker can move from endpoint access to cloud identity takeover, compromise sensitive user secrets, gain access to protected resources such as KeePass, and evade traditional EDR/XDR visibility.

    Register for free:
    👉 https://luma.com/TheftVectors

    Want to know more?

    You may also be interested in:

    How can we help you?

    Suggested searches

      Search history

        Popular searches:

        Not sure what course to look for?

        Mobile Newsletter Form