Oh great OSSEC oracles,
Has anyone created a decoder that extracts the source IP addresses from
authentitation failures under Windows? I have OSSEC monitoring our
Windows AD domain controllers, but I only wish to be alerted if there
are multiple password failures that originate from a single IP address.
So before I try and tackle this, has anyone resolved it yet?
Thanks for any help,
Trey Valenta
--- cut here ---
Received From: (domaincontroller) 10.1.1.1->WinEvtLog
Rule: 18152 fired (level 10) -> "Multiple Windows Logon Failures."
Portion of the log(s):
WinEvtLog: Security: AUDIT_FAILURE(675): Security: SYSTEM: NT AUTHORITY:
DC1: Pre-authentication failed: User Name: User1
User ID: %{S-1-5-21-1078081533-1614895754-1801674531-1208}
Service Name: krbtgt/DOMAINNAME Pre-Authentication Type: 0x0
Failure Code: 0x19 Client Address: 10.6.11.41
WinEvtLog: Security: AUDIT_FAILURE(675): Security: SYSTEM: NT AUTHORITY:
DC1: Pre-authentication failed: User Name: User1
User ID: %{S-1-5-21-1078081533-1614895754-1801674531-1208}
Service Name: krbtgt/DOMAINNAME Pre-Authentication Type: 0x0
Failure Code: 0x19 Client Address: 10.6.11.41
WinEvtLog: Security: AUDIT_FAILURE(675): Security: SYSTEM: NT AUTHORITY:
DC1: Pre-authentication failed: User Name: User2
User ID: %{S-1-5-21-1078081533-1614895754-1801674531-2231}
Service Name: krbtgt/DOMAINNAME.LOCAL Pre-Authentication Type: 0x0
Failure Code: 0x19 Client Address: 10.6.11.51
WinEvtLog: Security: AUDIT_FAILURE(675): Security: SYSTEM: NT AUTHORITY:
DC1: Pre-authentication failed: User Name: User1
User ID: %{S-1-5-21-1078081533-1614895754-1801674531-1208}
Service Name: krbtgt/DOMAINNAME.LOCAL Pre-Authentication Type: 0x0
Failure Code: 0x19 Client Address: 10.6.11.41
WinEvtLog: Security: AUDIT_FAILURE(675): Security: SYSTEM: NT AUTHORITY:
DC1: Pre-authentication failed: User Name: WINPC1$
User ID: %{S-1-5-21-1078081533-1614895754-1801674531-2800}
Service Name: krbtgt/DOMAINNAME.LOCAL Pre-Authentication Type: 0x0
Failure Code: 0x19 Client Address: 10.4.1.100
WinEvtLog: Security: AUDIT_FAILURE(675): Security: SYSTEM: NT AUTHORITY:
DC1: Pre-authentication failed: User Name: WINPC2$
User ID: %{S-1-5-21-1078081533-1614895754-1801674531-2744}
Service Name: krbtgt/DOMAINNAME.LOCAL Pre-Authentication Type: 0x0
Failure Code: 0x19 Client Address: 10.4.1.5
WinEvtLog: Security: AUDIT_FAILURE(675): Security: SYSTEM: NT AUTHORITY:
DC1: Pre-authentication failed: User Name: User3
User ID: %{S-1-5-21-1078081533-1614895754-1801674531-2648}
Service Name: krbtgt/DOMAINNAME.LOCAL Pre-Authentication Type: 0x0
Failure Code: 0x19 Client Address: 10.4.1.8
--- cut here ---
--
<t(Trey)@(Valenta)trey.net> Seattle, Wash.
Something's rotten in the state of Denmark.
-- Shakespeare