SI-Tracer: Windows authentication
Who signed in where, failures, Kerberos, NTLM, directory changes, logon graph, accounts at risk and anomalies.
SI-Tracer reads the Security log of your Windows servers: logons, failures, Kerberos, NTLM, and changes made in the directory (accounts, groups, audit policy). It is where you look for the origin of an account lockout, who added an account to the administrators, or whether an account is signing in all over the place.
Prerequisites
Install the agent with SITRACER=true on the domain controllers: that is where every domain authentication and every directory change goes through. On an ordinary member server you only see its local accounts. At startup the agent turns on the audit policies it needs.
Collected events: 4624, 4625, 4768, 4769, 4776 and 4672 for authentication; 4720 to 4781, 5136, 5137, 5141 and 4719 for directory management. Event 4662 is deliberately left out because it is far too verbose.
The screens
| Screen | Content |
|---|---|
| SI-Tracer | Total events, success rate, Open Anomalies, Top Risk Accounts |
| Logon Graph | Who signs in to which machine. Default exclusions hides system accounts. Export as PNG, SVG or PDF |
| Timeline | Logons and distinct accounts per hour |
| Rankings | The most central accounts and machines (PageRank) |
| Anomalies | To be handled with Resolve or False + |
| AD Directory | Creations, deletions, group changes, audit policy and object changes |
| Logon Events | The raw list, filterable by account, machine, source address, status, event ID. Export CSV (50,000 rows by default) |
| Account profile | Everything about an account on one page: logons, failures, lockouts and their real origin, VPN, Microsoft 365. See Account profile |
Detected anomalies
The analysis runs every 2 minutes.
| Type | Condition | Severity |
|---|---|---|
| Brute Force | 10 or more failures in 5 min, same address and same account | high; critical from 20 |
| Lateral Movement | One account signs in to 5 or more machines in 1 h | high; critical from 10 |
| Volume Spike | A peak compared with the usual activity for that hour | high; critical if the gap is very large |
| Time Anomaly | 3 or more logons between 10 pm and 6 am (UTC) over 24 h | medium |
Retention
| Data | Duration |
|---|---|
| Successful logons | customer retention period |
| Failures (4625) | at least 1 year |
| Directory management | at least 3 years |
Frequently asked questions
The AD Directory tab is empty. The agent is not on a domain controller.
The graph is unreadable. Apply the Default exclusions to remove service and machine accounts.
It's a false positive. False + closes the anomaly, and your name is recorded with the action.
Source: · FirstSI Docs · updated 2026-10-10