This would make my life easier as well!!

>
> Oh great OSSEC oracles,
>
> Has anyone created a decoder that extracts the source IP addresses from
> authentitation failures under Windows? I have OSSEC monitoring our
> Windows AD domain controllers, but I only wish to be alerted if there
> are multiple password failures that originate from a single IP address.
>
> So before I try and tackle this, has anyone resolved it yet?
>
> Thanks for any help,
> Trey Valenta
>
>
> --- cut here ---
> Received From: (domaincontroller) 10.1.1.1->WinEvtLog
> Rule: 18152 fired (level 10) -> "Multiple Windows Logon Failures."
> Portion of the log(s):
>
> WinEvtLog: Security: AUDIT_FAILURE(675): Security: SYSTEM: NT AUTHORITY:
> DC1: Pre-authentication failed:            User Name: User1
> User ID:        %{S-1-5-21-1078081533-1614895754-1801674531-1208}
> Service Name: krbtgt/DOMAINNAME      Pre-Authentication Type: 0x0
> Failure Code: 0x19      Client Address: 10.6.11.41
> WinEvtLog: Security: AUDIT_FAILURE(675): Security: SYSTEM: NT AUTHORITY:
> DC1: Pre-authentication failed:            User Name: User1
> User ID:        %{S-1-5-21-1078081533-1614895754-1801674531-1208}
> Service Name: krbtgt/DOMAINNAME      Pre-Authentication Type: 0x0
> Failure Code: 0x19      Client Address: 10.6.11.41
> WinEvtLog: Security: AUDIT_FAILURE(675): Security: SYSTEM: NT AUTHORITY:
> DC1: Pre-authentication failed:            User Name: User2
> User ID:        %{S-1-5-21-1078081533-1614895754-1801674531-2231}
> Service Name: krbtgt/DOMAINNAME.LOCAL        Pre-Authentication Type: 0x0
> Failure Code: 0x19      Client Address: 10.6.11.51
> WinEvtLog: Security: AUDIT_FAILURE(675): Security: SYSTEM: NT AUTHORITY:
> DC1: Pre-authentication failed:            User Name: User1
> User ID:        %{S-1-5-21-1078081533-1614895754-1801674531-1208}
> Service Name: krbtgt/DOMAINNAME.LOCAL        Pre-Authentication Type: 0x0
> Failure Code: 0x19      Client Address: 10.6.11.41
> WinEvtLog: Security: AUDIT_FAILURE(675): Security: SYSTEM: NT AUTHORITY:
> DC1: Pre-authentication failed:            User Name: WINPC1$
> User ID:        %{S-1-5-21-1078081533-1614895754-1801674531-2800}
> Service Name: krbtgt/DOMAINNAME.LOCAL        Pre-Authentication Type: 0x0
> Failure Code: 0x19      Client Address: 10.4.1.100
> WinEvtLog: Security: AUDIT_FAILURE(675): Security: SYSTEM: NT AUTHORITY:
> DC1: Pre-authentication failed:            User Name: WINPC2$
> User ID:        %{S-1-5-21-1078081533-1614895754-1801674531-2744}
> Service Name: krbtgt/DOMAINNAME.LOCAL        Pre-Authentication Type: 0x0
> Failure Code: 0x19      Client Address: 10.4.1.5
> WinEvtLog: Security: AUDIT_FAILURE(675): Security: SYSTEM: NT AUTHORITY:
> DC1: Pre-authentication failed:            User Name: User3
> User ID:        %{S-1-5-21-1078081533-1614895754-1801674531-2648}
> Service Name: krbtgt/DOMAINNAME.LOCAL        Pre-Authentication Type: 0x0
> Failure Code: 0x19      Client Address: 10.4.1.8
>
> --- cut here ---
>
> --
> <t(Trey)@(Valenta)trey.net> Seattle, Wash.
> Something's rotten in the state of Denmark.
>               -- Shakespeare
>

Reply via email to