← Event ID reference
4648

A logon was attempted using explicit credentials

  • Log: Security
  • Source: Microsoft-Windows-Security-Auditing
  • Logons
  • Info

What it means

A process used credentials different from the signed-in user, for example "Run as", a mapped drive with another account, or a scheduled task.

Why it matters

Normal for admins and some apps, but attackers moving between machines also generate it.

What to do

  • Check which process (Process Name) used the credentials.
  • Investigate unusual accounts or target servers.

Find it with PowerShell

Get-WinEvent -MaxEvents 20 -FilterHashtable @{
  LogName = 'Security'; Id = 4648
} | Select-Object TimeCreated, ProviderName, Message

Add -ComputerName SERVER to query another machine. Other event sources can reuse the same ID number, so check the ProviderName column.

Source

Seeing a lot of these? We can investigate, or alert you automatically through our monitoring.

Talk to us