Microsoft-Windows-Security-Kerberos
86 events across 2 channels
Event ID 3 —
Fields
| Name | Description |
|---|---|
LogonSession | — |
ClientTime | — |
ServerTime | — |
ErrorCode | — |
ErrorMessage | — |
ExtendedError | — |
ClientRealm | — |
ClientName | — |
ServerRealm | — |
ServerName | — |
TargetName | — |
ErrorText | — |
File | — |
Line | — |
__binLength | — |
binary | — |
Event ID 4 —
Fields
| Name | Description |
|---|---|
Server | — |
TargetRealm | — |
Targetname | — |
ClientRealm | — |
__binLength | — |
binary | — |
Event ID 5 —
Fields
| Name | Description |
|---|---|
Error | — |
__binLength | — |
binary | — |
Event ID 6 —
Fields
| Name | Description |
|---|---|
Error | — |
__binLength | — |
binary | — |
Event ID 7 —
Fields
| Name | Description |
|---|---|
Error | — |
__binLength | — |
binary | — |
Event ID 8 —
Fields
| Name | Description |
|---|---|
Error | — |
__binLength | — |
binary | — |
Event ID 9 —
Fields
| Name | Description |
|---|---|
Error | — |
__binLength | — |
binary | — |
Event ID 10 —
Fields
| Name | Description |
|---|---|
Error | — |
__binLength | — |
binary | — |
Event ID 11 —
Fields
| Name | Description |
|---|---|
Error | — |
__binLength | — |
binary | — |
Event ID 12 —
Fields
| Name | Description |
|---|---|
Error | — |
__binLength | — |
binary | — |
Event ID 13 — An error occurred while initializing the smart card logon library.
Message
Fields
| Name | Description |
|---|---|
Error | — |
__binLength | — |
binary | — |
Event ID 14 —
Fields
| Name | Description |
|---|---|
Error | — |
__binLength | — |
binary | — |
Event ID 15 —
Fields
| Name | Description |
|---|---|
Error | — |
__binLength | — |
binary | — |
Event ID 16 —
Fields
| Name | Description |
|---|---|
Error | — |
__binLength | — |
binary | — |
Sigma Rules
- No Suitable Encryption Key Found For Generating Kerberos Ticket
Detects errors when a target server doesn't have suitable keys for generating kerberos tickets. This issue can occur for example when a service uses a user account or a computer account that is configured for only DES encryption on a computer that is running Windows 7 which has DES encryption for Kerberos authentication disabled.
Event ID 17 —
Fields
| Name | Description |
|---|---|
Error | — |
__binLength | — |
binary | — |
Event ID 18 —
Fields
| Name | Description |
|---|---|
Error | — |
__binLength | — |
binary | — |
Event ID 19 —
Fields
| Name | Description |
|---|---|
Error | — |
__binLength | — |
binary | — |
Event ID 20 —
Fields
| Name | Description |
|---|---|
DomainName | — |
ErrorCode | — |
Event ID 100 — The service principal name (SPN) %1 is not registered, which caused Kerberos authentication to fail: %2.
Message
Fields
| Name | Description |
|---|---|
SPN | — |
ErrorCode | — |
Event ID 101 — The service principal name (SPN) %1 is registered on multiple accounts which caused Kerberos authentication to fail: %2.
Message
Fields
| Name | Description |
|---|---|
SPN | — |
ErrorCode | — |
Event ID 102 — Trust validation of the certificate for the Kerberos Key Distribution Center (KDC) %1 failed: %2.
Message
Fields
| Name | Description |
|---|---|
DomainController | — |
ErrorCode | — |
Event ID 103 — Trust validation of the client certificate for %1 failed: %2 on KDC.
Message
Fields
| Name | Description |
|---|---|
ClientUpn | — |
ErrorCode | — |
Event ID 104 — The Kerberos Key Distribution Center (KDC) for the domain %1 does not have a certificate installed or does not support logon using certificates: %2.
Message
Fields
| Name | Description |
|---|---|
TargetDomain | — |
ErrorCode | — |
Event ID 105 — The Kerberos client could not retrieve passwords for the group managed service account.
Message
Fields
| Name | Description |
|---|---|
LogonId | — |
DomainName | — |
UserName | — |
Refresh | — |
Current_File_Time | — |
Error_Code | — |
LuidHighPart | — |
LuidLowPart | — |
CurrentFileTime | — |
ErrorCode | — |
Event ID 106 — The Kerberos client received a KDC certificate that does not have KDC EKU (not based on Kerberos Authentication Template).
Message
Fields
| Name | Description |
|---|---|
Error_Code | — |
ErrorCode | — |
Event ID 107 — The Kerberos client received a KDC certificate that does not have a matched domain name.
Message
Fields
| Name | Description |
|---|---|
Expected_Domain_Name | — |
Error_Code | — |
ExpectedDomainName | — |
ErrorCode | — |
Event ID 108 — The Kerberos client could not send a Kerberos proxy request.
Message
Fields
| Name | Description |
|---|---|
ServerName | [ProxyServer] ServerName. |
ServerPort | [ProxyServer] ServerPort. |
ServerVdir | [ProxyServer] ServerVdir. |
Error_Code | [ProxyServer] Error Code. |
Status_Code | [ProxyServer] Status Code. |
ErrorCode | — |
Status | — |
Event ID 109 — The Kerberos client could not find a suitable credential to use with the authentication proxy: AuthProxy: Proxy: %1 ProxyBypass: %2 Epoch: %3 Suppo...
Message
Fields
| Name | Description |
|---|---|
Proxy | [AuthProxy] Proxy. |
ProxyBypass | [AuthProxy] ProxyBypass. |
Epoch | [AuthProxy] Epoch. |
Supported_Schemes | [AuthProxy] Supported Schemes. |
First_Scheme | [AuthProxy] First Scheme. |
Initialized | [Digest Credential] Initialized. |
DomainAndUserName | [Digest Credential] DomainAndUserName. |
Epoch | [Digest Credential] Epoch. |
Initialized | [Basic Credential] Initialized. |
DomainAndUserName | [Basic Credential] DomainAndUserName. |
Epoch | [Basic Credential] Epoch. |
ProxyEpoch | — |
SupportedSchemes | — |
FirstScheme | — |
DigestCredInitialized | — |
DigestCredDomainAndUserName | — |
DigestCredEpoch | — |
BasicCredInitialized | — |
BasicCredDomainAndUserName | — |
BasicCredEpoch | — |
Event ID 200 — The Kerberos client could not locate a domain controller for domain %1: %2.
Message
Fields
| Name | Description |
|---|---|
TargetDomain | — |
ErrorCode | — |
Event ID 201 — Attempt to use Kerberos unconstrained delegation failed.
Message
Fields
| Name | Description |
|---|---|
TargetName | — |
UserName | — |
DomainName | — |
CallerPID | — |
ProcessName | — |
ClientLUID | — |
ClientUserName | — |
ClientDomainName | — |
MechanismOID | — |
Event ID 202 — Attempt to export TGT session key failed.
Message
Fields
| Name | Description |
|---|---|
TargetName | — |
UserName | — |
DomainName | — |
CallerPID | — |
ProcessName | — |
ClientLUID | — |
ClientUserName | — |
ClientDomainName | — |
MechanismOID | — |
Event ID 203 — When Credential Guard is enabled, Kerberos does not accept PKINIT KDC replies using public key encryption to ensure Kerberos tickets cannot be expo...
Message
Event ID 204 — Kerberos does not accept PKINIT KDC replies using public key encryption.
Message
Event ID 205 — The KDC used a hash algorithm for the PKINIT protocol that is being audited.
Message
Fields
| Name | Description |
|---|---|
Algorithm | — |
Event ID 206 — The Kerberos client used a hash algorithm for the PKINIT protocol that is being audited.
Message
Fields
| Name | Description |
|---|---|
Algorithm | — |
Event ID 207 — The KDC used a hash algorithm for the PKINIT protocol that is not supported on the client.
Message
Fields
| Name | Description |
|---|---|
Algorithm | — |
Event ID 208 — The Kerberos client and KDC could not agree on a policy compliant hash algorithm for PKINIT.
Message
Fields
| Name | Description |
|---|---|
ClientAlgorithms | — |
KdcAlgorithms | — |
Event ID 209 — The Kerberos client has an invalid hash algorithm configuration for PKINIT.
Message
Event ID 300 — The Kerberos client discovered domain controller %1 for the domain %2.
Message
Fields
| Name | Description |
|---|---|
DomainController | — |
TargetDomain | — |
Event ID 301 — The Kerberos client used credentials from the Credential Manager for the target: '.
Message
Fields
| Name | Description |
|---|---|
Target | — |
Event ID 302 — The Kerberos client was bound to domain controller %1 for the domain %2 but could not access this domain controller at the time.
Message
Fields
| Name | Description |
|---|---|
DesiredFlags | — |
CacheFlags | — |
ErrorCode | DesiredFlags. |
DomainController | — |
TargetDomain | — |
Event ID 303 — The Kerberos client updated passwords for the group managed service account.
Message
Fields
| Name | Description |
|---|---|
LogonId | — |
DomainName | — |
UserName | — |
Update_Current_Passwords | — |
Update_Old_Passwords | — |
Refresh | — |
Previous_File_Time | — |
Current_File_Time | — |
LuidHighPart | — |
LuidLowPart | — |
UpdateCurrent | — |
UpdateOld | — |
LastFileTime | — |
CurrentFileTime | — |
Event ID 304 — The Kerberos client used the DES algorithm to encrypt data.
Message
Event ID 305 — Export of TGT attempted through call package.
Message
Fields
| Name | Description |
|---|---|
Process_Name | — |
Service_Host_Tag | — |
ProcessName | — |
SvchostTag | — |
Event ID 306 — Export of supplemental credentials attempted.
Message
Fields
| Name | Description |
|---|---|
Process_Name | — |
Service_Host_Tag | — |
ProcessName | — |
SvchostTag | — |
Event ID 307 — The Kerberos client has discovered a DMSA migration Old Account Name: %1 New Account Name: %2 Domain Name: %3 Status: %4 Migration Complete: %5.
Message
Fields
| Name | Description |
|---|---|
OldAccount | — |
NewAccount | — |
DomainName | — |
Status | — |
MigrationComplete | — |
Event ID 308 — Adding machine to the Principals Allowed Managed Password attribute of a DMSA DC Used: %1 DMSA Distinguished Name: %2 Linked Account: %3 Domain Nam...
Message
Fields
| Name | Description |
|---|---|
DC | — |
DN | — |
Account | — |
Domain | — |
PreviouslyAuthorized | — |
Status | — |
Event ID 309 — Fetching keys for a DMSA using the machine account KDC Used: %1 Domain Name: %2 Account Name: %3 Fetch Time: %4 Expiration Time: %5 Keys Updated: %...
Message
Fields
| Name | Description |
|---|---|
KDC | — |
Domain | — |
Account | — |
Fetch | — |
Expiration | — |
KeyUpdate | — |
NtlmUpdate | — |
Status | — |
Event ID 310 — Machine password migrated from LSA to VBS Enforcement Mode.
Message
Fields
| Name | Description |
|---|---|
EnforcementMode | — |
Event ID 311 — Machine Identity Isolation is currently in enforcement mode.
Message
Event ID 312 — Machine password change failed Status: %1 Migration Needed: %2 Policy: %3 Exit Reason: %4.
Message
Fields
| Name | Description |
|---|---|
Status | — |
MigrationNeeded | — |
EnforcementMode | — |
ExitReason | — |
Event ID 65541 — An error occurred while retrieving a digital certificate from the inserted smart card.
Message
Fields
| Name | Description |
|---|---|
Error | — |
binary | — |
Event ID 65542 — An error occurred in while attempting to verify the inserted smart card.
Message
Fields
| Name | Description |
|---|---|
Error | — |
binary | — |
Event ID 65543 — An error occurred while signing a message using the inserted smart card.
Message
Fields
| Name | Description |
|---|---|
Error | — |
binary | — |
Event ID 65544 — An error occurred while verifying a signed message using the inserted smart card.
Message
Fields
| Name | Description |
|---|---|
Error | — |
binary | — |
Event ID 65545 — An error occurred while verifying the digital certificate retrieved from the inserted smart card.
Message
Fields
| Name | Description |
|---|---|
Error | — |
binary | — |
Event ID 65546 — An error occurred while encrypting a message using the inserted smart card.
Message
Fields
| Name | Description |
|---|---|
Error | — |
binary | — |
Event ID 65547 — An error occurred while decrypting a message using the inserted smart card.
Message
Fields
| Name | Description |
|---|---|
Error | — |
binary | — |
Event ID 65548 — An error occurred while building a certificate context.
Message
Fields
| Name | Description |
|---|---|
Error | — |
binary | — |
Event ID 65550 — An error occurred while signing a message.
Message
Fields
| Name | Description |
|---|---|
Error | — |
binary | — |
Event ID 65551 — An error occurred while verifying a signed message.
Message
Fields
| Name | Description |
|---|---|
Error | — |
binary | — |
Event ID 65552 — An error occurred while encrypting a message.
Message
Fields
| Name | Description |
|---|---|
Error | — |
binary | — |
Event ID 65553 — An error occurred while decrypting a message.
Message
Fields
| Name | Description |
|---|---|
Error | — |
binary | — |
Event ID 65554 — An error occurred while retrieving some provider parameter.
Message
Fields
| Name | Description |
|---|---|
Error | — |
binary | — |
Event ID 65555 — An error occurred while generating a random number.
Message
Fields
| Name | Description |
|---|---|
Error | — |
binary | — |
Event ID 1073741828 — The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server %1.
Message
Fields
| Name | Description |
|---|---|
Server | — |
TargetRealm | — |
Targetname | — |
ClientRealm | — |
binary | — |
Event ID 1073741829 — The Kerberos client received a KRB_AP_ERR_TKT_NYV error from the server %1.
Message
Fields
| Name | Description |
|---|---|
Server | — |
KDCRealm | — |
binary | — |
Event ID 2147483651 — A Kerberos error message was received: on logon session %1 Client Time: %2 Server Time: %3 Error Code: %4 %5 Extended Error: %6 Client Realm: %7 Cl...
Message
Fields
| Name | Description |
|---|---|
Client_Time | — |
Server_Time | [A Kerberos error message was received] Client Time. |
Error_Code | [A Kerberos error message was received] Server Time. |
Extended_Error | [A Kerberos error message was received] Error Code. |
Client_Realm | — |
Client_Name | [A Kerberos error message was received] Extended Error. |
Server_Realm | [A Kerberos error message was received] Client Realm. |
Server_Name | [A Kerberos error message was received] Client Name. |
Target_Name | [A Kerberos error message was received] Server Realm. |
Error_Text | [A Kerberos error message was received] Server Name. |
File | [A Kerberos error message was received] Target Name. |
Line | [A Kerberos error message was received] Error Text. |
LogonSession | — |
ClientTime | — |
ServerTime | — |
ErrorCode | — |
ErrorMessage | — |
ExtendedError | — |
ClientRealm | — |
ClientName | — |
ServerRealm | — |
ServerName | — |
TargetName | — |
ErrorText | — |
binary | — |
Event ID 2147483654 — The Kerberos SSPI package generated an output token of size %1 bytes, which was too large to fit in the token buffer of size %2 bytes, provided by ...
Message
Fields
| Name | Description |
|---|---|
NeededSize | — |
ActualSize | — |
ClientProcessID | — |
ClientName | — |
binary | — |
Event ID 2147483658 — The Kerberos subsystem currently cannot retrieve tickets from your domain controller using the UDP network protocol.
Message
Event ID 2147483660 — While using your smart card over a VPN connection, the Kerberos subsystem encountered an error.
Message
Event ID 2147483661 — The smart card PIN stored in Credential Manager is missing or invalid.
Message
Fields
| Name | Description |
|---|---|
Username | — |
binary | — |
Event ID 2147483662 — The password stored in Credential Manager is invalid.
Message
Fields
| Name | Description |
|---|---|
Username | — |
binary | — |
Event ID 2147483663 — The Kerberos SSPI package generated an output token of size %1 bytes, which was too large to fit in the token buffer of size %2 bytes, provided by ...
Message
Fields
| Name | Description |
|---|---|
NeededSize | — |
ActualSize | — |
ClientProcessID | — |
RequiredSize | — |
binary | — |
Event ID 2147483666 — The delegated TGT for the user has expired.
Message
Fields
| Name | Description |
|---|---|
Client | — |
Server | [TGT Details] Client. |
Flags | [TGT Details] Server. |
Start_Time | [TGT Details] Flags. |
End_Time | [TGT Details] Start Time. |
Renew_Until | [TGT Details] End Time. |
Luid | — |
ClientPrincipalName | — |
ServicePrincipalName | — |
TicketFlags | — |
StartTime | — |
EndTime | — |
RenewUntil | — |
ErrorCode | — |
Event ID 2147483667 — The KDC certificate for the domain controller does not contain the KDC Extended Key Usage (EKU): 1.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 2147483668 — The KDC certificate for the domain controller does not have the DNS name of domain %1 in the Subject Alternative Name (SAN) attribute: Error Code %2.
Message
Fields
| Name | Description |
|---|---|
DomainName | — |
ErrorCode | — |
Event ID 2147483669 — During Kerberos Network Ticket Logon, the service ticket for Account .
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 2147483670 — During Kerberos Network Ticket Logon, the service ticket for Account .
Fields
| Name | Description |
|---|---|
Reason | — |
ErrorCode | — |
Event ID 2147483671 — During Kerberos Network Ticket Logon, the service ticket for Account .
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221225479 — The digitally signed Privilege Attribute Certificate (PAC) that contains the authorization information for client %1 in realm %2 could not be valid...
Message
Fields
| Name | Description |
|---|---|
ClientName | — |
Realm | — |
binary | — |
Event ID 3221225480 — The domain controller rejected the client certificate of user %2, used for smart card logon.
Message
Fields
| Name | Description |
|---|---|
Name | — |
Message | — |
binary | — |
Event ID 3221225481 — The client has failed to validate the domain controller certificate for %2.
Message
Fields
| Name | Description |
|---|---|
Name | — |
Message | — |
binary | — |
Event ID 3221225483 — The Distinguished Name in the subject field of your smart card logon certificate does not contain enough information to identify the appropriate do...
Message
Event ID 3221225488 — The Kerberos SSPI package failed to find the smart card certificate in the certificate store.
Message
Fields
| Name | Description |
|---|---|
Username | — |
binary | — |
Event ID 3221225489 — The Kerberos SSPI package failed to locate the forest or domain %1 to search.
Message
Fields
| Name | Description |
|---|---|
Forest | — |
binary | — |