Skip to main content
AD Academy
Back to all recipes
Level: JuniorLast updated:

Spot a spike of failed logons (4625) on a DC

Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625; StartTime=(Get-Date).AddHours(-24)} |
  ForEach-Object { $_.Properties[5].Value } |
  Group-Object | Sort-Object Count -Descending | Select-Object -First 15

Why it works this way

Grouping 4625 by account and source separates a forgotten password from an intrusion attempt.

Watch out

  • Run it on the DC itself, or add -ComputerName DC01.
  • One account across many hosts is password spraying, not forgetfulness.

Related events