Transitive Network Logon attack - Account lockout

Lrok 1 Reputation point
2020-08-20T01:25:45.977+00:00

Hi all,

I see a transitive Network Logon attack on my AD netlogon logs, however, the computer name that attacks are coming from not pingable or searchable internally. Is there any way to find this puzzle?

Thanks,

Lrok

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,150 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,774 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Fan Fan 15,321 Reputation points Microsoft Vendor
    2020-08-20T06:05:01.017+00:00

    Hi,
    I would recommend you use Netmon/wireshark tool to monitor if there are any brute/dictionary attack coming from the outside.
    For more advice , you can refer to the following link, hope it would be helpful.
    https://social.technet.microsoft.com/Forums/ie/en-US/8dd4375a-48c4-43d7-8e33-87324de9ecf5/transitive-network-logon-attack?forum=winserverDS

    Best Regards,