Windows Sign-In Evidence: Investigating Authentication Across Hosts
About this course
This course teaches SOC analysts, Windows administrators, and incident responders how Windows authentication becomes evidence across several systems. Learners build a mental model of credentials, authentication, logon sessions, tokens, and resource access; interpret common Security log events; reconstruct Kerberos and NTLM activity; and correlate host, domain-controller, network, and identity telemetry. The course treats event IDs as records with placement, fields, and collection limits rather than universal verdicts. Completion means the learner can investigate a suspicious sign-in, explain where supporting events should exist, distinguish common administrative and service behavior from meaningful anomalies, and hand off a scoped, time-aligned assessment.
What you'll learn
- ✓ Explain the difference between credential validation, authentication, a Windows logon session, and later resource access.
- ✓ Locate and interpret common logon and account-logon events on endpoints, servers, and domain controllers.
- ✓ Reconstruct Kerberos and NTLM activity while accounting for protocol, logging, and field limitations.
- ✓ Build a corroborated sign-in timeline and write a disposition based on expected behavior, impact, and confidence.
Course Content
Module 1: 1. Build the Sign-In Evidence Model
Understand what Windows creates during sign-in and why related records appear on different computers with different identifiers.
From Credentials to a Windows Logon Session
Trace the path from an authentication attempt to a local session and avoid equating every credential event with an interactive desktop sign-in.
Place Events on the Computer That Knows the Fact
Map endpoint, resource-server, and domain-controller records so absence on one system is not mistaken for absence everywhere.
Module 2: 2. Interpret Kerberos and NTLM Evidence
Reconstruct the two dominant Active Directory authentication paths and recognize what ticket and credential-validation events cannot reveal alone.
Reconstruct Kerberos Ticket Activity
Connect ticket-granting ticket requests, service tickets, and target-host logons without claiming a ticket request equals successful resource use.
Interpret NTLM Validation and Fallback
Read NTLM credential-validation evidence, identify its missing destination context, and investigate why NTLM was used before assigning intent.
Module 3: 3. Investigate and Make the Decision
Turn distributed audit records into a bounded timeline, then use baselines and counter-evidence to decide whether access was expected, suspicious, or confirmed unauthorized.
Build a Cross-Host Authentication Timeline
Join failures, tickets, successes, privileges, processes, and resource access while preserving source-specific time and identifier limits.
Baseline, Escalate, and Document the Finding
Measure deviations against peer and historical behavior, assess impact separately, and write a sign-in disposition that another analyst can reproduce.