QuestionCONSTRUCTED
Interview prep: logon type 3 against logon type 10
A junior question that is really about containment: which logons leave credentials behind on the host, and so which accounts you have to reset when that host is compromised.
junior levelwindows forensicsa spoken answer of about 3 minutes
The question
“What is the difference between a type 3 and a type 10 logon in event 4624, and why does it matter when a host is compromised?”
Goodcorrect, and where most candidates stop
Type 3 is a network logon: something reached the machine over the network, such as a file share, remote management, or most lateral movement tools. Type 10 is RemoteInteractive, which is Remote Desktop. Both appear in event 4624, the successful logon, and the type is in the Logon Type field.
Betteradds the limits and the second source
The difference that matters is what each leaves behind. A type 10 logon, like a type 2 at the console, gives the user an interactive session on the target, and the credentials to support it are held in LSASS memory there. If that host is compromised, the operator can take them.
A type 3 network logon generally does not leave reusable credentials on the target. The server checked a challenge response or a Kerberos ticket and never held the password or the hash. Dumping LSASS on the compromised host does not yield those accounts.
So on a compromised host, the accounts with type 10 or type 2 sessions are the ones whose credentials I assume are stolen and reset first.
Bestwhat somebody who has done it says
Everything in the better answer, and three qualifications, because this is the field that decides the reset list and getting it wrong in either direction is expensive.
First, Remote Desktop with Network Level Authentication often writes a type 3 logon on the target before the type 10, so seeing both from one address a second apart is one connection, not two.
Second, there are ways to use Remote Desktop without leaving credentials: Restricted Admin mode and Remote Credential Guard both exist for exactly this. If an administrator used either, their session was type 10 but their reusable credentials did not land on the host.
Third, the rule that type 3 leaves nothing has an exception worth knowing: a host trusted for unconstrained delegation keeps a forwardable ticket-granting ticket for accounts that authenticate to it with Kerberos, even over the network. On such a host a network logon does expose the account.
The other types to check are 2 (console), 9 (runas with network-only credentials, and what some pass-the-hash tools produce) and 11 (cached credentials used without a domain controller). For the response, I would pull every 4624 on the host from the first sign of compromise, group by account and logon type, reset the interactive ones first, and then look at where the type 3 accounts went next.
Why the gap between them matters
The good answer knows the numbers. The better answer knows why they matter: credentials in memory. The best answer knows where that rule bends, which is the difference between a reset list that is right and one that either misses an exposed administrator or locks out half the IT team for nothing. The event log cheat sheet has the full table of logon types.
What they are listening for
Whether you connect a field in a log to a decision: which accounts' credentials are sitting in memory on a compromised host and therefore have to be reset.
Where it goes next
- You see a type 3 logon immediately before a type 10 from the same address. What happened?
- An administrator used Remote Desktop to a compromised server with Restricted Admin mode. Do you reset their password?
- Which other logon types leave reusable credentials on the target?
Confident and wrong
- Type 3 is a failed logon. It is a network logon; failures are event 4625.
- Every account that touched the host has to be reset. True of type 10 and type 2, not generally of type 3.
- Knowing the numbers but not what they change about the response.