Windows Logon Events (4624 and 4625)
Also called Event ID 4624, Event ID 4625, logon type, failed logon events, Windows security log logon.
- PLATFORM
- Windows
- CATEGORY
- Accounts and Authentication
- INDEX
- 28 of 36
- PROVES
- 5 findings
- CANNOT PROVE
- 5 limits
- QUESTIONS
- 4 answered
Security log records of each logon and failed logon attempt, naming the account, the logon type, the source workstation and address, and the resulting session identifier.
Where it lives
Security event log — 4624 successful logon, 4625 failed logon, 4634 and 4647 logoff, 4648 logon with explicit credentials, 4672 special privileges
Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of windows logon events (4624 and 4625)” is neither.
What it records
A successful logon writes an event naming the account and SID, a logon type distinguishing interactive from network, service, batch, unlock and remote-interactive sessions, the process that performed the logon, and where applicable the source workstation name and network address. A failure writes a parallel event carrying a status code that distinguishes a bad password from a disabled, locked or expired account, or from a logon attempted outside permitted hours. A logon session identifier links a logon to its later logoff.
What it proves — and what it cannot
These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.
What it proves
FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.
- That a named account authenticated to a machine at a recorded time, and by what mechanism
- The nature of the session, from the logon type — the difference between someone sitting at the console, a background share access, and a remote desktop session
- The source address and workstation name a remote logon came from, subject to how those fields are populated
- Failure patterns: repeated bad passwords, attempts against disabled accounts, and the point at which one succeeded
- Session duration, by pairing a logon with the logoff sharing its session identifier
What it cannot prove
INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.
- That the account is the person. A log names a security context; shared credentials, service accounts, delegated and impersonated sessions, and stored credentials in scheduled tasks all break the link, and closing it requires evidence from outside the machine
- That a network logon reflects human activity. Type 3 logons are generated continuously by background processes, print services, and file access, and reading a list of them as a list of sessions produces nonsense
- That the source is where the person was. The workstation name field is supplied by the client and can be set to anything, and an address is frequently a VPN concentrator or a shared network egress point rather than a device
- What the account did once logged on. The logon event marks the start of a session and nothing about its content
- Anything beyond the log's window. Security log retention on a busy server is often measured in hours unless events were forwarded to a collector
How the finding is attacked
An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.
- Attacking the account-to-person inference where credentials were shared, written down, or held in a password manager available to others
- Reclassifying an event by logon type to show it was a background process rather than a person
- Establishing that the source address is a shared egress point that hundreds of people sit behind
- Showing the log rolled or was cleared, so the absence of a logon proves nothing about presence
What survives, and for how long
Events persist until the Security log reaches its configured maximum and rolls, which is frequently hours on a domain controller and days to weeks on a workstation. Forwarding to a collector or SIEM is what makes them available months later, and whether such forwarding existed is a question to raise at the first opportunity in discovery.
More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.
Questions counsel ask
What does Event ID 4624 prove?
It proves that a named account successfully authenticated to a machine at a recorded time, by a recorded mechanism, and it identifies the session that logon created. It does not prove that any particular person was at the keyboard. Attributing a logon to a human requires something outside the machine — badge records, video, a phone in the same place, or an admission.
What do Windows logon types mean?
The logon type field distinguishes how the session was established: interactive at the console, network access to a share or service, batch, service, workstation unlock, and remote-interactive for a remote desktop session, among others. The distinction is decisive in practice, because network logons are generated constantly by background processes and reading them as human sessions inflates activity dramatically.
Can you tell where someone logged in from?
Partly, and less reliably than the fields suggest. A logon event may carry a source workstation name and network address. The workstation name is supplied by the client and can be set to anything. The address is frequently a VPN concentrator, a proxy, or a shared network egress point rather than a device, so it narrows the origin to a network rather than to a machine or a person.
How long does the Windows Security log keep logon events?
Until it reaches its configured maximum size and rolls, which depends entirely on activity and configuration — hours on a busy domain controller, days to weeks on a quiet workstation. Nothing about the default configuration is designed for litigation. Where events were forwarded to a collector or SIEM, they may exist for far longer, and that is worth establishing early.
Terms used on this page
Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.
Related artifacts
No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.
Remote Desktop Artifacts
Server- and client-side records of remote desktop sessions: who connected, from what address, when the session started and ended, and which servers a machine connected out to.
Entra ID Sign-in Logs
Tenant-side records of every authentication to Microsoft 365 and connected applications, with the application, IP address, device state, and conditional-access outcome — retained for days unless exported.
Process Creation Events (4688)
A Security log record written each time a process starts, naming the account, the executable, the parent process and — if separately enabled — the full command line.
BAM and DAM
A registry record, organised by user SID, of the last execution time of individual executables — the rare Windows artifact that attributes execution to an account directly.
Whether the windows logon events (4624 and 4625)evidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.
A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.
- Can This Artifact Prove That?
Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.
- Computer forensics
The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.
- The artifact index
All 36 entries, grouped by what they bear on and filterable by platform.
- Daubert and digital evidence
Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.
Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.