Skip to content
FirstSIDocs

SI-Tracer: Windows authentication

Who signed in where, failures, Kerberos, NTLM, directory changes, logon graph, accounts at risk and anomalies.

SI-Tracer reads the Security log of your Windows servers: logons, failures, Kerberos, NTLM, and changes made in the directory (accounts, groups, audit policy). It is where you look for the origin of an account lockout, who added an account to the administrators, or whether an account is signing in all over the place.

Prerequisites

Install the agent with SITRACER=true on the domain controllers: that is where every domain authentication and every directory change goes through. On an ordinary member server you only see its local accounts. At startup the agent turns on the audit policies it needs.

Collected events: 4624, 4625, 4768, 4769, 4776 and 4672 for authentication; 4720 to 4781, 5136, 5137, 5141 and 4719 for directory management. Event 4662 is deliberately left out because it is far too verbose.

The screens

ScreenContent
SI-TracerTotal events, success rate, Open Anomalies, Top Risk Accounts
Logon GraphWho signs in to which machine. Default exclusions hides system accounts. Export as PNG, SVG or PDF
TimelineLogons and distinct accounts per hour
RankingsThe most central accounts and machines (PageRank)
AnomaliesTo be handled with Resolve or False +
AD DirectoryCreations, deletions, group changes, audit policy and object changes
Logon EventsThe raw list, filterable by account, machine, source address, status, event ID. Export CSV (50,000 rows by default)
Account profileEverything about an account on one page: logons, failures, lockouts and their real origin, VPN, Microsoft 365. See Account profile

Detected anomalies

The analysis runs every 2 minutes.

TypeConditionSeverity
Brute Force10 or more failures in 5 min, same address and same accounthigh; critical from 20
Lateral MovementOne account signs in to 5 or more machines in 1 hhigh; critical from 10
Volume SpikeA peak compared with the usual activity for that hourhigh; critical if the gap is very large
Time Anomaly3 or more logons between 10 pm and 6 am (UTC) over 24 hmedium

Retention

DataDuration
Successful logonscustomer retention period
Failures (4625)at least 1 year
Directory managementat least 3 years

Frequently asked questions

The AD Directory tab is empty. The agent is not on a domain controller.

The graph is unreadable. Apply the Default exclusions to remove service and machine accounts.

It's a false positive. False + closes the anomaly, and your name is recorded with the action.

Source: · FirstSI Docs · updated 2026-10-10