I am getting lots of Audit Failure errors on Windows Logs/Security in event viewer. See the image below. Does that mean someone is trying to brute-force to my computer?
Asked
Active
Viewed 80 times
0
-
1It could mean anything. Why don't you read the event log entries and see what it's actually about? - https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4625 – joeqwerty May 19 '23 at 21:56
1 Answers
0
Event ID 4624 is associated with logon events. Multiple instances of this entry is due to Event Viewer recording every logon event (whether from the local user account or system services such as Windows Security) with the same event ID which is 4624
To identify the source of login, right-click on the event record and select Properties.
In the General tab, scroll down and locate the Logon Information Section. Here, the Logon Type field indicates the kind of logon that occurred. For example, Logon Type 5 indicates a service-based login, while Logon Type 2 indicates user-based login.
More Information - 4625(F): An account failed to log on

Basant Mandal
- 41
- 3
-
Thank you for the answer. In my case, the logon type is 3 (Network). – Mohammad Taherian May 23 '23 at 13:30