// Investigation

Hunt console

Structured search across the normalised event store. Terms combine with AND; prefix a value with ! to negate it.

hunt.queryREADY
Try

Result profile

8

events match

Severity

  • Critical2
  • High3
  • Medium0
  • Low3
  • Info0

Applied filters

  • user = jsmith

Matches

Newest first.

Timestamp (UTC)SeverityEvent typeUserSource IPMessage
CriticalCredential AccessjsmithProcess memory of lsass.exe dumped to disk via comsvcs.dll MiniDump
HighProcess Executionjsmith185.100.200.50Encoded PowerShell command block executed with hidden window and execution policy bypass
CriticalUser Createdjsmith185.100.200.50Account 'svc_helpdesk_tmp' created by jsmith and added to group 'Domain Admins'
HighMfa Method Removedjsmith185.100.200.50Second-factor method 'Authenticator app' removed from account jsmith
HighAuthentication Successjsmith185.100.200.50Kerberos TGT issued for jsmith from 185.100.200.50 (logon type 10, RDP) — prior successful logon for this account originated in Chicago, USA 41 minutes earlier
LowAuthentication Failurejsmith185.100.200.50Pre-authentication failed for jsmith from 185.100.200.50 (status 0x18: bad password)
LowAuthentication Failurejsmith185.100.200.50Pre-authentication failed for jsmith from 185.100.200.50 (status 0x18: bad password)
LowAuthentication Failurejsmith185.100.200.50Pre-authentication failed for jsmith from 185.100.200.50 (status 0x18: bad password)