Windows Security: DiagTrackEoP POC Default UserName Login Attempt (LogonType 9)

Alerts on Windows 4624 LogonType 9 events targeting a known DiagTrackEoP default username.

FreeReviewedSigma · Critical · v2
Product
windows
Service
security
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-08-03
Updated
2026-07-31

What it detects

This rule flags Windows Security events (EventID 4624) with LogonType 9 where the TargetOutboundUserName matches the specific placeholder value used by the DiagTrackEoP proof-of-concept. Attackers may use this non-real default username during exploitation attempts, making it a high-signal indicator of suspicious authentication activity. It relies on Security log telemetry capturing successful logon events and the TargetOutboundUserName field.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.