数千个 4776 事件

发布于 2025-01-16 00:31:44 字数 224 浏览 0 评论 0原文

我面临一个问题,导致 DC 上发生数千个成功的 4776 事件。我发现某种网络打印机枚举导致了它。例如,每次在word中刷新或打开打印机,都会触发大量4776。即使用户不使用计算机,因此计算机被锁定,也会发生这种情况。知道为什么会这样吗?我怀疑这是由于打开名为管道的打印机引起的,我在 ProcMon 创建、关闭 pipeline\spools 打印机路径上的文件中看到。服务器是W2K8 R2,客户端是W10

提前致谢

I'm facing a problem which causing thousands of successful 4776 events on DCs. I figured out that some kind of network printer enumeration causing it. Every refreshing or opening printers in word for example, triggers a lot of 4776. It takes place even when user doesn't use computer so it is locked. Any idea why it works like that? I suspect that it is caused by opening printer named pipe, I see in ProcMon create, close file on pipe\spools printer path. Server is W2K8 R2 , client W10

Thanks in advance

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。

评论(1

满意归宿 2025-01-23 00:31:44

每次使用 NTLM 身份验证进行凭据验证时,通常都会出现此问题“数千个 4776 事件”。它显示成功和不成功的凭据验证尝试。

只有权威帐户才会出现此错误。对于域
帐户,域控制器具有权威。对于本地帐户,
本地计算机是权威的。当工作站解锁事件发生时,也会生成此事件。

从 4776 事件日志中获取源工作站地址,请检查以下步骤:

  • 尝试检查用户是否输入了错误的凭据来运行计划任务、启动服务等。
  • 尝试检查凭据管理以了解缓存中是否存在任何旧凭据。
  • 挂载网盘时检查是否输入了错误的密码。
  • 检查是否有第三方程序缓存了用户错误的密码。

参考文献

4776 (S, F) 计算机尝试验证帐户的凭据。 (Windows 10) - Windows 安全 |微软文档

事件 ID 4776 / 0xc00006a - Microsoft Q& ;A

This problem "Thousands of 4776 events" usually occurs every time that a credential validation occurs using NTLM authentication. It shows successful and unsuccessful credential validation attempts.

Only for the authoritative accounts this error occurs. For domain
accounts, the domain controller is authoritative. For local accounts,
the local computer is authoritative. This event also generates when a workstation unlock event occurs.

Obtain the source workstation address from 4776 event log and please check below steps:

  • Try checking whether the user is entering wrong credentials to run scheduled tasks, start services etc.
  • Try checking the credential management to know if there are any old credentials present in cache.
  • While mounting the network disk check whether you have entered wrong password.
  • Check if there are any third-party programs that cache the user's wrong password.

References:

4776(S, F) The computer attempted to validate the credentials for an account. (Windows 10) - Windows security | Microsoft Docs.

Event ID 4776 / 0xc00006a - Microsoft Q&A.

~没有更多了~
我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
原文