|Alert Message||Logon Failure - User not granted logon type|
Windows has detected that a system has attempted to log an account where they have not been granted the logon type.
Associated Windows Event IDs
What you should do
This may indicate an attack, and the source should be investigated. Check the GUI for other events from the sources IP.
The platform will track this logon, and if multiple events occur will issue a higher level alert that a brute force attack may be occurring.
There are no false positives with this rule.
There is no guidance for tuning this rule, this is a generic Windows error and the rule should not be disabled.
If you are unsure about how to respond to this alert, please contact Atomicorp support. We're here to help you!
HIDS_59222 Windows: Remote Logon Failure - Unknown user or bad password
HIDS_59223 Logon Failure - Account logon time restriction violation
HIDS_59224 Logon Failure - Account currently disabled
HIDS_59225 Logon Failure - Specified account expired
HIDS_59226 Logon Failure - User not allowed to login at this computer
HIDS_59228 Logon Failure - Account's password expired
HIDS_59229 Logon Failure - Internal error
HIDS_59230 Logon Failure - Account locked out
Knowledge Base Articles