Windows Security: Detects RULER workstation using NTLM and login events (Event IDs 4776, 4624/4625)

Alerts when RULER-labeled Windows Security events show NTLM auth (4776) plus 4624/4625 logons.

FreeReviewedSigma · High · v2
Product
windows
Service
security
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2017-05-31
Updated
2026-07-31

ATT&CK techniques

Execution → Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Lateral Movement

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule flags Windows Security audit activity associated with the RULER workstation, combining NTLM authentication processing (Event ID 4776) with subsequent logon success/failure events (Event IDs 4624 and 4625) that also reference RULER. Such activity can indicate use of an offensive NTLM-focused tooling workflow for authentication testing or credential interaction. It relies on Windows Security logs containing Event IDs 4776, 4624, and/or 4625 and matching the workstation/workstation name fields to RULER.

Related detections9 linkedT1059 — drag to rearrange
AutoIt Script Execution via A3X Payload
Suspicious Python Execution via Renamed Synaptics Binary
MSBuild Executing Non-Project File or Remote Payload
Possible Ivanti Pulse Connect Secure Command Injection via License Keys-Status Endpoint (via webserver)
Possible Craft CMS RCE via Query-String CLI Option Injection
Possible Aspera Faspex Pre-Auth RCE via YAML Deserialization in package_relay (via webserver)
Possible Sitecore Pre-Auth RCE via Report.ashx Insecure Deserialization (via webserver)
Possible WatchGuard Pre-Auth RCE via agent login XML-RPC CVE-2022-26318
Possible Oracle Opera CGI Webshell Command Execution via operabin
Windows Security: Detects RULER workstation using NTLM and login events (Event IDs 4776, 4624/4625)
Pivot detection · T1059 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.