NETLOGON
| Event | Title | Channel | Sample | Rule |
|---|---|---|---|---|
| 3210 | Event ID 3210 | System | Y | N |
| 5719 | This computer was not able to set up a secure session with a domain controller … | System | Y | N |
| 5723 | Event ID 5723 | System | Y | Y |
| 5774 | Event ID 5774 | System | Y | N |
| 5782 | Event ID 5782 | System | Y | N |
| 5783 | Event ID 5783 | System | Y | N |
| 5805 | Event ID 5805 | System | Y | Y |
| 5823 | Event ID 5823 | System | Y | N |
| 5829 | The Netlogon service allowed a vulnerable Netlogon secure channel connection. | System | N | Y |
| 5836 | The Netlogon service was able to bind to a TCP/IP port with the configured … | System | Y | N |
Event ID 3210
#Fields #
| Name | Description |
|---|---|
Data_0 | |
Data_1 | |
Binary |
Example Event #
{
"system": {
"provider": "NETLOGON",
"guid": "",
"event_source_name": "",
"event_id": 3210,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2026-03-13T16:35:16.146153+00:00",
"event_record_id": 1731,
"correlation": {},
"execution": {
"process_id": 780,
"thread_id": 0
},
"channel": "System",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": ""
}
},
"event_data": {
"Data_0": "ludus",
"Data_1": "\\\\LAB-DC01.ludus.domain",
"Binary": "220000C0"
},
"message": ""
}
Event ID 5719: This computer was not able to set up a secure session with a domain controller in domain ludus due to the following: An internal error occurred.
#Fields #
| Name | Description |
|---|---|
Data_0 | |
Binary |
Example Event #
{
"system": {
"provider": "NETLOGON",
"guid": "",
"event_source_name": "",
"event_id": 5719,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2026-05-08 00:26:19.683004+00:00",
"event_record_id": 911,
"correlation": {
"ActivityID": "",
"RelatedActivityID": ""
},
"execution": {
"process_id": 992,
"thread_id": 0
},
"channel": "System",
"computer": "tel2-WIN11-25H2-1",
"security": {
"user_id": ""
}
},
"event_data": {
"Data_0": "<string>ludus</string>\n<string>%%1359</string>\n",
"Binary": "5QAAwA=="
},
"message": "This computer was not able to set up a secure session with a domain controller in domain ludus due to the following: \r\nAn internal error occurred. \r\nThis may lead to authentication problems. Make sure that this computer is connected to the network. If the problem persists, please contact your domain administrator. \r\n\r\nADDITIONAL INFO \r\nIf this computer is a domain controller for the specified domain, it sets up the secure session to the primary domain controller emulator in the specified domain. Otherwise, this computer sets up the secure session to any domain controller in the specified domain."
}
Event ID 5723
#Fields #
| Name | Description |
|---|---|
Data_0 | |
Data_1 | |
Binary |
Example Event #
{
"system": {
"provider": "NETLOGON",
"guid": "",
"event_source_name": "",
"event_id": 5723,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2026-03-13T05:12:11.679917+00:00",
"event_record_id": 10597,
"correlation": {},
"execution": {
"process_id": 0,
"thread_id": 0
},
"channel": "System",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": ""
}
},
"event_data": {
"Data_0": "LAB-WIN11",
"Data_1": "LAB-WIN11$",
"Binary": "8B0100C0"
},
"message": ""
}
Detection Patterns #
Lateral Movement: Exploitation of Remote Services
Event ID 5774
#Fields #
| Name | Description |
|---|---|
Data_0 | |
Data_1 | |
Data_2 | |
Data_3 | |
Data_4 | |
Binary |
Example Event #
{
"system": {
"provider": "NETLOGON",
"guid": "",
"event_source_name": "",
"event_id": 5774,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2026-05-29T01:34:08.4639056+00:00",
"event_record_id": 6575,
"correlation": {},
"execution": {
"process_id": 0,
"thread_id": 0
},
"channel": "System",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": ""
}
},
"event_data": {
"Data_0": "cell-a.ludus.domain. 600 IN A 10.1.20.11",
"Data_1": "%%9502",
"Data_2": "10.1.20.11",
"Data_3": "0",
"Data_4": "9502"
},
"message": "The dynamic registration of the DNS record 'cell-a.ludus.domain. 600 IN A 10.1.20.11' failed on the following DNS server: \r\n\r\nDNS server IP address: 10.1.20.11 \r\nReturned Response Code (RCODE): 0 \r\nReturned Status Code: 9502 \r\n\r\nFor computers and users to locate this domain controller, this record must be registered in DNS. \r\n\r\nUSER ACTION \r\nDetermine what might have caused this failure, resolve the problem, and initiate registration of the DNS records by the domain controller. To determine what might have caused this failure, run DCDiag.exe. To learn more about DCDiag.exe, see Help and Support Center. To initiate registration of the DNS records by this domain controller, run 'nltest.exe /dsregdns' from the command prompt on the domain controller or restart Net Logon service. \r\n Or, you can manually add this record to DNS, but it is not recommended. \r\n\r\nADDITIONAL DATA \r\nError Value: Bad DNS packet."
}
Event ID 5782
#Fields #
| Name | Description |
|---|---|
Data_0 | |
Binary |
Example Event #
{
"system": {
"provider": "NETLOGON",
"guid": "",
"event_source_name": "",
"event_id": 5782,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2022-04-07T16:53:49.187430+00:00",
"event_record_id": 1246,
"correlation": {},
"execution": {
"process_id": 0,
"thread_id": 0
},
"channel": "System",
"computer": "WIN-FPV0DSIC9O6.lab.local",
"security": {
"user_id": ""
}
},
"event_data": {
"Data_0": "%%9852",
"Binary": "7C260000"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 5783
#Fields #
| Name | Description |
|---|---|
Data | |
Binary |
Example Event #
{
"system": {
"provider": "NETLOGON",
"guid": "",
"event_source_name": "",
"event_id": 5783,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2012-04-06T18:07:03.000000Z",
"event_record_id": 13508,
"correlation": {},
"execution": {
"process_id": 0,
"thread_id": 0
},
"channel": "System",
"computer": "WKS-WIN764BITB.shieldbase.local",
"security": {
"user_id": ""
}
},
"event_data": {
"Data": [
"\\\\Controller.shieldbase.local",
"SHIELDBASE",
"WKS-WIN764BITB"
],
"Binary": ""
}
}
Event ID 5805
#Fields #
| Name | Description |
|---|---|
Data | |
Binary |
Example Event #
{
"system": {
"provider": "NETLOGON",
"guid": "",
"event_source_name": "",
"event_id": 5805,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2020-09-15T19:28:49.359773+00:00",
"event_record_id": 63221,
"correlation": {},
"execution": {
"process_id": 0,
"thread_id": 0
},
"channel": "System",
"computer": "01566s-win16-ir.threebeesco.com",
"security": {
"user_id": ""
}
},
"event_data": {
"Data": [
"01566S-WIN16-IR",
"%%5"
],
"Binary": "IgAAwA=="
},
"message": ""
}
Detection Patterns #
Lateral Movement: Exploitation of Remote Services
References #
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 5823
#Fields #
| Name | Description |
|---|---|
Data_0 | |
Binary |
Example Event #
{
"system": {
"provider": "NETLOGON",
"guid": "",
"event_source_name": "",
"event_id": 5823,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2022-04-07T08:15:01.574704+00:00",
"event_record_id": 730,
"correlation": {},
"execution": {
"process_id": 0,
"thread_id": 0
},
"channel": "System",
"computer": "WIN-FPV0DSIC9O6.lab.local",
"security": {
"user_id": ""
}
},
"event_data": {
"Data_0": "",
"Binary": ""
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 5829: The Netlogon service allowed a vulnerable Netlogon secure channel connection.
#Description
Logged on a domain controller during the CVE-2020-1472 (Zerologon) initial-deployment phase when it allows a vulnerable Netlogon secure channel connection from a machine account. These connections are denied once the enforcement phase is active.
Message #
Fields #
| Name | Description |
|---|---|
MachineSamAccountName | SAM account name of the machine that made the vulnerable connection. |
Domain | Domain of the machine account. |
AccountType | Account type of the connecting party. |
MachineOperatingSystem | Operating system reported by the connecting machine. |
MachineOperatingSystemBuild | OS build reported by the connecting machine. |
MachineOperatingSystemServicePack | OS service pack reported by the connecting machine. |
Community Notes #
Matched by the SigmaHQ 'Vulnerable Netlogon Secure Channel Connection Allowed' rule. Paired with 5827/5828 (denied) and 5830/5831 (allowed by group policy) from the same Netlogon enforcement change.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma # view in coverage
T1548
References #
Event ID 5836: The Netlogon service was able to bind to a TCP/IP port with the configured backlog size of 10.
#Fields #
| Name | Description |
|---|---|
Data_0 |
Example Event #
{
"system": {
"provider": "NETLOGON",
"guid": "",
"event_source_name": "",
"event_id": 5836,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2026-04-23T08:40:53.3140979+00:00",
"event_record_id": 30512,
"correlation": {},
"execution": {
"process_id": 0,
"thread_id": 0
},
"channel": "System",
"computer": "JD-DC01-2022.ludus.domain",
"security": {
"user_id": ""
}
},
"event_data": {
"Data_0": "10"
},
"message": "The Netlogon service was able to bind to a TCP/IP port with the configured backlog size of 10."
}