Audit Logon Events

Audit Logon Events

One-liner: Windows audit policy that records account logon/logoff activities and related authentication events.

🎯 What Is It?

Controls whether Windows logs successful and/or failed logon attempts. Events surface in the Security log (e.g., 4624, 4625) and are critical for identity-related investigations.

🤔 Why It Matters

🔬 How It Works

Core Principles

  1. Configure Success and Failure auditing via Local/Group Policy.
  2. Tune to reduce noise while retaining security value.
  3. Forward to SIEM for correlation.

Technical Deep-Dive

🛡️ Detection & Prevention

How to Detect

How to Prevent / Mitigate