Course

Windows Sign-In Evidence: Investigating Authentication Across Hosts

About this learning content: Courses, lessons, assessments, explanations and illustrations may be created with the help of artificial intelligence. We review and check the material and do our best to avoid incorrect or outdated information, but mistakes, omissions or ambiguous questions may remain. Please verify information before relying on it for professional, security, legal or operational decisions. Read the full notice or report an issue.
Difficulty Intermediate
Modules 3
Lessons 6
Time 5 hr
Language en
Created by Threat Intelligence Lab
Updated 11 September 2026
Windows Sign-In EvidenceAccount, host, domain controller, protocol, session, and resource evidence combine into an authentication investigation.PRACTICAL SECURITY OPERATIONSWindows Sign-In EvidenceAccountEndpointDomain controllerSessionEVIDENCE → REASONING → DEFENSIBLE ACTION

About this course

This course teaches SOC analysts, Windows administrators, and incident responders how Windows authentication becomes evidence across several systems. Learners build a mental model of credentials, authentication, logon sessions, tokens, and resource access; interpret common Security log events; reconstruct Kerberos and NTLM activity; and correlate host, domain-controller, network, and identity telemetry. The course treats event IDs as records with placement, fields, and collection limits rather than universal verdicts. Completion means the learner can investigate a suspicious sign-in, explain where supporting events should exist, distinguish common administrative and service behavior from meaningful anomalies, and hand off a scoped, time-aligned assessment.

What you'll learn

  • ✓ Explain the difference between credential validation, authentication, a Windows logon session, and later resource access.
  • ✓ Locate and interpret common logon and account-logon events on endpoints, servers, and domain controllers.
  • ✓ Reconstruct Kerberos and NTLM activity while accounting for protocol, logging, and field limitations.
  • ✓ Build a corroborated sign-in timeline and write a disposition based on expected behavior, impact, and confidence.

Before you begin

You will get more from this course if these foundations are already familiar.

  • Windows and Active Directory basics — Learners should recognize users, computers, domain controllers, and Security event logs. Packet-level protocol expertise and domain-administrator access are not required.

Course content

Keep building