LogonTracer – Investigate Malicious Windows Logon by Visualizing and Analyzing Windows event log

LogonTracer Logo Investigate malicious Windows logon

Many computer infect with Trojan or RAT, attacker can spy victim computer, grab any data, put keylogger and do something horrible on your computer. LogonTracer maybe can help a little bit, this tool will analyze/detect windows logon and automatically create a visual report, and if malicious logon detect you can see the report.

Concept

LogonTracer is a tool to investigate malicious logon by visualizing and analyzing Windows Active Directory event logs. This tool associates a host name (or an IP address) and account name found in logon-related events and displays it as a graph. This way, it is possible to see in which account login attempt occurs and which host is used.
This tool can visualize the following event id related to Windows logon based on this research.

  • 4624: Successful logon
  • 4625: Logon failure
  • 4768: Kerberos Authentication (TGT Request)
  • 4769: Kerberos Service Ticket (ST Request)
  • 4776: NTLM Authentication
  • 4672: Assign special privileges

More details are described in the following documents :

LogonTracer Report Investigate malicious Windows logon by visualizing and analyzing Windows event log

Additional Analysis

LogonTracer uses PageRankHidden Markov model and ChangeFinder to detect malicious hosts and accounts from event log.

LogonTracer Users Investigate malicious Windows logon by visualizing and analyzing Windows event log

With LogonTracer, it is also possible to display event logs in a chronological order.

LogonTracer Timeline Investigate malicious Windows logon by visualizing and analyzing Windows event log

Use LogonTracer

To use LogonTracer, you can :

Documentation

If you want to know more details, please check the LogonTracer wiki.

Demonstration

Following YouTube’s video shows how to use LogonTracer.

Architecture

LogonTracer is written in Python and uses Neo4j for database. The following tools are used.


You May Also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

seventeen + 5 =