Windows Security: Outgoing Logon (LogonType 9) Using New Credentials (4624)

Flags Windows 4624 LogonType 9 events where new credentials are used for authentication.

FreeReviewedSigma · Low · v2
Product
windows
Service
security
Author
Max Altgelt (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-04-06
Updated
2026-07-31

ATT&CK techniques

Defense Evasion → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Windows Security logon events (EventID 4624) with LogonType 9, indicating an outgoing logon that uses new credentials. Such activity matters because attackers and administrators can leverage credential-based access to move laterally or access remote resources. The detection relies on Windows Security audit telemetry capturing the logon event details, specifically the event ID and logon type fields.

Related detections4 linkedT1550 — drag to rearrange
Suspicious High-Privilege Microsoft Graph Application Role Grant via Azure Audit (via azure)
AWS CloudTrail Alert for Suspicious SAML Role Assumption and SAML Provider Updates
AWS CloudTrail: Suspicious STS AssumeRole sessions from Role-issued principals
AWS CloudTrail: IAMUser STS GetSessionToken Use
Windows Security: Outgoing Logon (LogonType 9) Using New Credentials (4624)
Pivot detection · T1550 · 4 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.