DC validated credentials via NTLM. ErrorCode: 0x0=success, 0xC000006A=wrong password, 0xC000006D=bad creds, 0xC0000064=unknown user, 0xC0000234=locked.
NTLM brute force and spray. Pass-the-Hash generates 4776 with 0x0 — indistinguishable from legit NTLM auth. Monitor Workstation field for source. Impacket and Metasploit generate NTLM auth. In Kerberos-first environments, unexpected NTLM spikes are high signal.
Alert: >10 ErrorCode=0xC000006A from same Workstation in 5 min. Alert: NTLM from non-Windows systems (null or Linux hostnames). Alert: NTLM from internet-facing IPs. Baseline NTLM traffic — deviations are suspicious.
TargetUserNameWorkstationStatus | Tactic | Technique |
|---|---|
| Credential Access | Brute Force (T1110) |
| Lateral Movement | Pass the Hash (T1550.002) |
Starting points — adapt the log source, projected fields and thresholds for your environment.
title: NTLM Auth Failure Spike on DC
status: stable
description: Repeated NTLM failures on DC indicating brute force or spray
author: theadminstack.com
date: 2026/05/16
logsource:
product: windows
service: security
detection:
selection:
EventID: 4776
ErrorCode: '0xC000006A'
condition: selection | count() by Workstation > 10
falsepositives:
- Services with stale credentials
level: medium
tags:
- attack.credential_access
- attack.t1110
- attack.t1550.002
SecurityEvent
| where EventID == 4776 // The domain controller attempted to validate the credentials for an account (NTLM)
| project TimeGenerated, Computer, TargetUserName, Workstation, Status
| sort by TimeGenerated desc
index=* sourcetype="WinEventLog:Security" EventCode=4776
| stats count earliest(_time) as first_seen latest(_time) as last_seen by ComputerName
| sort - count `# The domain controller attempted to validate the credentials for an account (NTLM) — add EventData fields: TargetUserName, Workstation, Status`
The domain controller attempted to validate the credentials for an account (NTLM). DC validated credentials via NTLM. ErrorCode: 0x0=success, 0xC000006A=wrong password, 0xC000006D=bad creds, 0xC0000064=unknown user, 0xC0000234=locked.
Event 4776 is written to the Security channel by Microsoft-Windows-Security-Auditing. Advanced Audit Policy — enable the 'Kerberos Authentication Service' subcategory (Success and/or Failure).
Event 4776 is associated with: Brute Force (T1110), Pass the Hash (T1550.002).
Alert: >10 ErrorCode=0xC000006A from same Workstation in 5 min. Alert: NTLM from non-Windows systems (null or Linux hostnames). Alert: NTLM from internet-facing IPs. Baseline NTLM traffic — deviations are suspicious.