HIDS 59230
Rule 59222 | |
---|---|
Status | Active |
Alert Message | Account locked out |
Contents |
Description
Windows is reporting that the account the user has attempted to access has been locked out.
Associated Windows Event IDs
- 529
- 530
- 531
- 532
- 533
- 534
- 535
- 536
- 537
- 539
- 4625
What you should do
This means that the account has been locked out by Windows, typically because of too many authentication failures. This may indicate that the account is under attack, and the source(s) of the logon failures should be investigated to determine if this is an attack against other accounts. Search the GUI for additional events from the source IPs for these events.
The platform will track this logon, and if multiple events occur will issue a higher level alert that a brute force attack may be occurring.
Troubleshooting
False Positives
There are no false positives with this rule.
Tuning Guidance
There is no guidance for tuning this rule, and the rule should not be disabled.
Additional Information
Support
If you are unsure about how to respond to this alert, please contact Atomicorp support. We're here to help you!
Similar Rules
HIDS_59222 Windows: Remote Logon Failure - Unknown user or bad password
HIDS_59223 Logon Failure - Account logon time restriction violation
HIDS_59224 Logon Failure - Account currently disabled
HIDS_59225 Logon Failure - Specified account expired
HIDS_59226 Logon Failure - User not allowed to login at this computer
HIDS_59227 Logon Failure - User not granted logon type
HIDS_59228 Logon Failure - Account's password expired
HIDS_59229 Logon Failure - Internal error
Knowledge Base Articles
None.
Outside References
None.