N
N
naruto_hokagi2020-11-07 09:05:18
Active Directory
naruto_hokagi, 2020-11-07 09:05:18

How to find out who is breaking under the UZ guest?

Good afternoon! There is a CD, local KMs of the type Guest and administrator are disabled, but the event is constantly observed in the log files: Use of the standard KU Guest/administrator has been detected.
With what it can be connected?

Answer the question

In order to leave comments, you need to log in

1 answer(s)
H
hint000, 2020-11-07
@hint000

Logon failure: account currently disabled
Event Class ID = 4776
there in details of event there is an initial workstation . This is the name of the computer that is breaking into the server over the network. Identify the computer by name - deal with it further.
5fa67db835904191739387.png

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question