NETLOGON

Event ID 3210

#
Channel
System
Level
Error

Fields #

NameDescription
Data_0
Data_1
Binary

Example Event #

{
  "system": {
    "provider": "NETLOGON",
    "guid": "",
    "event_source_name": "",
    "event_id": 3210,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-03-13T16:35:16.146153+00:00",
    "event_record_id": 1731,
    "correlation": {},
    "execution": {
      "process_id": 780,
      "thread_id": 0
    },
    "channel": "System",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "ludus",
    "Data_1": "\\\\LAB-DC01.ludus.domain",
    "Binary": "220000C0"
  },
  "message": ""
}

Event ID 5719: This computer was not able to set up a secure session with a domain controller in domain ludus due to the following: An internal error occurred.

#
Channel
System
Level
2

Fields #

NameDescription
Data_0
Binary

Example Event #

{
  "system": {
    "provider": "NETLOGON",
    "guid": "",
    "event_source_name": "",
    "event_id": 5719,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-08 00:26:19.683004+00:00",
    "event_record_id": 911,
    "correlation": {
      "ActivityID": "",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 992,
      "thread_id": 0
    },
    "channel": "System",
    "computer": "tel2-WIN11-25H2-1",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "<string>ludus</string>\n<string>%%1359</string>\n",
    "Binary": "5QAAwA=="
  },
  "message": "This computer was not able to set up a secure session with a domain controller in domain ludus due to the following: \r\nAn internal error occurred. \r\nThis may lead to authentication problems. Make sure that this computer is connected to the network. If the problem persists, please contact your domain administrator.  \r\n\r\nADDITIONAL INFO \r\nIf this computer is a domain controller for the specified domain, it sets up the secure session to the primary domain controller emulator in the specified domain. Otherwise, this computer sets up the secure session to any domain controller in the specified domain."
}

Event ID 5723

#
Channel
System
Level
Error

Fields #

NameDescription
Data_0
Data_1
Binary

Example Event #

{
  "system": {
    "provider": "NETLOGON",
    "guid": "",
    "event_source_name": "",
    "event_id": 5723,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-03-13T05:12:11.679917+00:00",
    "event_record_id": 10597,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "System",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "LAB-WIN11",
    "Data_1": "LAB-WIN11$",
    "Binary": "8B0100C0"
  },
  "message": ""
}

Detection Patterns #

Lateral Movement: Exploitation of Remote Services

1 rule

Sigma

Demyan Sokolin @_drd0c, Teymur Kheirkhabarov @HeirhabarovT, oscd.community

Event ID 5774

#
Channel
System
Level
Error

Fields #

NameDescription
Data_0
Data_1
Data_2
Data_3
Data_4
Binary

Example Event #

{
  "system": {
    "provider": "NETLOGON",
    "guid": "",
    "event_source_name": "",
    "event_id": 5774,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-29T01:34:08.4639056+00:00",
    "event_record_id": 6575,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "System",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "cell-a.ludus.domain. 600 IN A 10.1.20.11",
    "Data_1": "%%9502",
    "Data_2": "10.1.20.11",
    "Data_3": "0",
    "Data_4": "9502"
  },
  "message": "The dynamic registration of the DNS record 'cell-a.ludus.domain. 600 IN A 10.1.20.11' failed on the following DNS server:  \r\n\r\nDNS server IP address: 10.1.20.11 \r\nReturned Response Code (RCODE): 0 \r\nReturned Status Code: 9502  \r\n\r\nFor computers and users to locate this domain controller, this record must be registered in DNS.  \r\n\r\nUSER ACTION  \r\nDetermine what might have caused this failure, resolve the problem, and initiate registration of the DNS records by the domain controller. To determine what might have caused this failure, run DCDiag.exe. To learn more about DCDiag.exe, see Help and Support Center. To initiate registration of the DNS records by this domain  controller, run 'nltest.exe /dsregdns' from the command prompt on the domain controller or restart Net Logon service. \r\n  Or, you can manually add this record to DNS, but it is not recommended.  \r\n\r\nADDITIONAL DATA \r\nError Value: Bad DNS packet."
}

Event ID 5782

#
Channel
System
Level
Warning

Fields #

NameDescription
Data_0
Binary

Example Event #

{
  "system": {
    "provider": "NETLOGON",
    "guid": "",
    "event_source_name": "",
    "event_id": 5782,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2022-04-07T16:53:49.187430+00:00",
    "event_record_id": 1246,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "System",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "%%9852",
    "Binary": "7C260000"
  },
  "message": ""
}

References #

Event ID 5783

#
Channel
System
Level
Error

Fields #

NameDescription
Data
Binary

Example Event #

{
  "system": {
    "provider": "NETLOGON",
    "guid": "",
    "event_source_name": "",
    "event_id": 5783,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2012-04-06T18:07:03.000000Z",
    "event_record_id": 13508,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "System",
    "computer": "WKS-WIN764BITB.shieldbase.local",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "\\\\Controller.shieldbase.local",
      "SHIELDBASE",
      "WKS-WIN764BITB"
    ],
    "Binary": ""
  }
}

Event ID 5805

#
Channel
System
Level
Error

Fields #

NameDescription
Data
Binary

Example Event #

{
  "system": {
    "provider": "NETLOGON",
    "guid": "",
    "event_source_name": "",
    "event_id": 5805,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2020-09-15T19:28:49.359773+00:00",
    "event_record_id": 63221,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "System",
    "computer": "01566s-win16-ir.threebeesco.com",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "01566S-WIN16-IR",
      "%%5"
    ],
    "Binary": "IgAAwA=="
  },
  "message": ""
}

Detection Patterns #

Lateral Movement: Exploitation of Remote Services

1 rule

Sigma

Demyan Sokolin @_drd0c, Teymur Kheirkhabarov @HeirhabarovT, oscd.community

References #

Event ID 5823

#
Channel
System
Level
Informational

Fields #

NameDescription
Data_0
Binary

Example Event #

{
  "system": {
    "provider": "NETLOGON",
    "guid": "",
    "event_source_name": "",
    "event_id": 5823,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2022-04-07T08:15:01.574704+00:00",
    "event_record_id": 730,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "System",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "",
    "Binary": ""
  },
  "message": ""
}

References #

Event ID 5829: The Netlogon service allowed a vulnerable Netlogon secure channel connection.

#
Channel
System

Description

Logged on a domain controller during the CVE-2020-1472 (Zerologon) initial-deployment phase when it allows a vulnerable Netlogon secure channel connection from a machine account. These connections are denied once the enforcement phase is active.

Message #

The Netlogon service allowed a vulnerable Netlogon secure channel connection. Warning: This connection will be denied once the enforcement phase is released.

Fields #

NameDescription
MachineSamAccountNameSAM account name of the machine that made the vulnerable connection.
DomainDomain of the machine account.
AccountTypeAccount type of the connecting party.
MachineOperatingSystemOperating system reported by the connecting machine.
MachineOperatingSystemBuildOS build reported by the connecting machine.
MachineOperatingSystemServicePackOS service pack reported by the connecting machine.

Community Notes #

Matched by the SigmaHQ 'Vulnerable Netlogon Secure Channel Connection Allowed' rule. Paired with 5827/5828 (denied) and 5830/5831 (allowed by group policy) from the same Netlogon enforcement change.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

References #

Event ID 5836: The Netlogon service was able to bind to a TCP/IP port with the configured backlog size of 10.

#
Channel
System
Level
4

Fields #

NameDescription
Data_0

Example Event #

{
  "system": {
    "provider": "NETLOGON",
    "guid": "",
    "event_source_name": "",
    "event_id": 5836,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-04-23T08:40:53.3140979+00:00",
    "event_record_id": 30512,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "System",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "10"
  },
  "message": "The Netlogon service was able to bind to a TCP/IP port with the configured backlog size of 10."
}