Windows Failed Logon (Event ID 4625) From Non-Private Public IP

Alerts on Windows failed logons (4625) originating from IPs outside private/local ranges.

FreeReviewedSigma · Medium · v2
Product
windows
Service
security
Author
NVISO (SigmaHQ), DRL 1.1
Published
2020-05-06
Updated
2026-07-31

ATT&CK techniques

Initial Access → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Execution

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule flags Windows Security Event ID 4625 failed logon attempts where the source IP is not within common local/private IP ranges. Failed authentication attempts from public IPs can indicate probing or unauthorized access attempts over the network boundary. It relies on Windows Security auditing telemetry for Event ID 4625 and the reported IpAddress field to determine whether the IP is public versus local.

Related detections9 linkedT1133 — drag to rearrange
Possible Next.js Middleware Auth Bypass via X-Middleware-Subrequest Header (CVE-2025-29927)
Windows Process Creation: GoAnywhere child command execution indicating possible MFT exploitation
OpenCanary Telnet Login Attempt Recorded in Application Logs
OpenCanary application logs: SSH new connection attempt on monitored node
OpenCanary Application Logs: SSH Login Attempt on Monitoring Node
Windows RDP Successful Logon (4624 LogonType 10) from Public IP
Windows Successful SMB Logon (Event ID 4624 Logon Type 3) From Public IPs
Suspicious Security Group Ingress Rule Opened to the Internet via CloudTrail
Malicious SharePoint ToolShell Exploitation via ToolPane Endpoint
Windows Failed Logon (Event ID 4625) From Non-Private Public IP
Pivot detection · T1133 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.