Oh great OSSEC oracles,

Has anyone created a decoder that extracts the source IP addresses from
authentitation failures under Windows? I have OSSEC monitoring our
Windows AD domain controllers, but I only wish to be alerted if there
are multiple password failures that originate from a single IP address.

So before I try and tackle this, has anyone resolved it yet?

Thanks for any help,
Trey Valenta


--- cut here ---
Received From: (domaincontroller) 10.1.1.1->WinEvtLog
Rule: 18152 fired (level 10) -> "Multiple Windows Logon Failures."
Portion of the log(s):

WinEvtLog: Security: AUDIT_FAILURE(675): Security: SYSTEM: NT AUTHORITY:
DC1: Pre-authentication failed:            User Name: User1
User ID:        %{S-1-5-21-1078081533-1614895754-1801674531-1208}
Service Name: krbtgt/DOMAINNAME      Pre-Authentication Type: 0x0
Failure Code: 0x19      Client Address: 10.6.11.41    
WinEvtLog: Security: AUDIT_FAILURE(675): Security: SYSTEM: NT AUTHORITY:
DC1: Pre-authentication failed:            User Name: User1
User ID:        %{S-1-5-21-1078081533-1614895754-1801674531-1208}
Service Name: krbtgt/DOMAINNAME      Pre-Authentication Type: 0x0
Failure Code: 0x19      Client Address: 10.6.11.41    
WinEvtLog: Security: AUDIT_FAILURE(675): Security: SYSTEM: NT AUTHORITY:
DC1: Pre-authentication failed:            User Name: User2
User ID:        %{S-1-5-21-1078081533-1614895754-1801674531-2231}
Service Name: krbtgt/DOMAINNAME.LOCAL        Pre-Authentication Type: 0x0
Failure Code: 0x19      Client Address: 10.6.11.51    
WinEvtLog: Security: AUDIT_FAILURE(675): Security: SYSTEM: NT AUTHORITY:
DC1: Pre-authentication failed:            User Name: User1
User ID:        %{S-1-5-21-1078081533-1614895754-1801674531-1208}
Service Name: krbtgt/DOMAINNAME.LOCAL        Pre-Authentication Type: 0x0
Failure Code: 0x19      Client Address: 10.6.11.41    
WinEvtLog: Security: AUDIT_FAILURE(675): Security: SYSTEM: NT AUTHORITY:
DC1: Pre-authentication failed:            User Name: WINPC1$
User ID:        %{S-1-5-21-1078081533-1614895754-1801674531-2800}
Service Name: krbtgt/DOMAINNAME.LOCAL        Pre-Authentication Type: 0x0
Failure Code: 0x19      Client Address: 10.4.1.100    
WinEvtLog: Security: AUDIT_FAILURE(675): Security: SYSTEM: NT AUTHORITY:
DC1: Pre-authentication failed:            User Name: WINPC2$
User ID:        %{S-1-5-21-1078081533-1614895754-1801674531-2744}
Service Name: krbtgt/DOMAINNAME.LOCAL        Pre-Authentication Type: 0x0
Failure Code: 0x19      Client Address: 10.4.1.5    
WinEvtLog: Security: AUDIT_FAILURE(675): Security: SYSTEM: NT AUTHORITY:
DC1: Pre-authentication failed:            User Name: User3
User ID:        %{S-1-5-21-1078081533-1614895754-1801674531-2648}
Service Name: krbtgt/DOMAINNAME.LOCAL        Pre-Authentication Type: 0x0
Failure Code: 0x19      Client Address: 10.4.1.8    

--- cut here ---

-- 
<t(Trey)@(Valenta)trey.net> Seattle, Wash.
Something's rotten in the state of Denmark.
                -- Shakespeare

Reply via email to