Identify anomalous logon behavior

Prev Next

Logon Tracker helps you identify user activity that deviates from normal patterns, such as logins from strange locations or at odd hours, which could indicate a compromised account.

  • To find logons from outside your network: Set the Category filter to RDP or SSH and review the Src/Tgt Addr column in the grid view. Look for public IP addresses that are not part of your organization's known IP ranges.

  • To check for activity at unusual times: Use the Graph Filter to narrow the currently displayed results to a specific time window, such as overnight or on weekends (for example, 02:00 - 05:59 UTC), to see if any successful logons occurred.

  • To monitor for privilege escalation: Use the Privilege level search filter and select Privileged. This filter shows all logon events that the operating system flagged as using elevated privileges (Windows Event ID 4672), helping you identify unexpected administrative activity.