Hi HosniAdnan-7274,
EventID 4776 means that the computer(Domain Controller) attempted to validate the credentials for an user logon.
4776(S, F): The computer attempted to validate the credentials for an account
https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4776
According to the information(such as JP1), this event might be recorded not only user logon but also application.
10.2.2 Failure Audit(EventID : 4625 or 4776) is recorded in the Windows security event log
PCM70254.HTM
If you'd like to stop recording ID 4776, you need to set the Advanced Audit Policy configuration at your system as follow.
[Group Policy Management]
Computer Configuration > Policies > Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Account Logon
[Sub Category]
Audit Credential Validation
[Audit Events]
Not Configured
I hope this would help you.
Best regards,
Zaamasu