Windows Failed Logon (Event ID 4625) From Non-Private Public IP
Alerts on Windows failed logons (4625) originating from IPs outside private/local ranges.
- Product
- windows
- Service
- security
- Author
- NVISO (SigmaHQ), DRL 1.1
- Published
- 2020-05-06
- Updated
- 2026-07-31
ATT&CK techniques
Initial Access → Defense EvasionRecon
Resource Dev
Execution
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Windows Security Event ID 4625 failed logon attempts where the source IP is not within common local/private IP ranges. Failed authentication attempts from public IPs can indicate probing or unauthorized access attempts over the network boundary. It relies on Windows Security auditing telemetry for Event ID 4625 and the reported IpAddress field to determine whether the IP is public versus local.
Reporting behind it
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Failed Logon (Event ID 4625) From Non-Private Public IP
id: a8bf0054-cf4b-4933-b169-c3b52e5b46a2
status: test
description: This rule flags Windows Security Event ID 4625 failed logon attempts where the source IP is not within common local/private IP ranges. Failed authentication attempts from public IPs can indicate probing or unauthorized access attempts over the network boundary. It relies on Windows Security auditing telemetry for Event ID 4625 and the reported IpAddress field to determine whether the IP is public versus local.
references:
- https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4625
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/security/account_management/win_security_susp_failed_logon_source.yml
author: NVISO, Huntrule Team
date: 2020-05-06
modified: 2024-03-11
tags:
- attack.privilege-escalation
- attack.initial-access
- attack.persistence
- attack.stealth
- attack.t1078
- attack.t1190
- attack.t1133
logsource:
product: windows
service: security
detection:
selection:
EventID: 4625
filter_main_ip_unknown:
IpAddress|contains: "-"
filter_main_local_ranges:
IpAddress|cidr:
- ::1/128
- 10.0.0.0/8
- 127.0.0.0/8
- 172.16.0.0/12
- 192.168.0.0/16
- 169.254.0.0/16
- fc00::/7
- fe80::/10
condition: selection and not 1 of filter_main_*
falsepositives:
- Legitimate logon attempts over the internet
- IPv4-to-IPv6 mapped IPs
level: medium
license: DRL-1.1
related:
- id: f88e112a-21aa-44bd-9b01-6ee2a2bbbed1
type: derived