The Domain Controller Attempted To Validate The Credentials For An Account

The domain controller attempted to validate the credentials for an account.

Configuration

query

EventID:4776 OR EventID:680

config

Key | Value — | — type | aggregation-v1 query | EventID:4776 OR EventID:680 streams | [5f74fe0891d2ba1b645adb8d] conditions | {expression:null} search_within_ms | 3600000 execute_every_ms | 3600000

SIEM Microsoft Events to Monitor
notes
SIEM Microsoft Events to Monitor
notes

Last modified December 31, 1969