Daily Blog #746: Solving the windows hello challenge part 2
这篇文章总结了对Windows Hello PIN登录功能的测试过程和结果。作者通过设置PIN并解锁工作站观察到安全日志中的事件ID 4624(类型11和7),但未找到明确指示使用PIN的日志条目。接下来将测试指纹扫描仪。 2025-2-12 04:16:0 Author: www.hecfblog.com(查看原文) 阅读量:6 收藏

By February 11, 2025


 

Hello Reader,

Continuing from yesterday’s entry—where we explored the logs for biometric face-scanning authentication in Windows Hello—today we’re taking a closer look at PIN-based authentication. With a PIN, you can sign in using a simple number sequence instead of a full password.

To test this out, I ensured my PIN was already set up, locked my workstation, and then unlocked it using the PIN. Here’s what I observed in the security logs:

  • Event ID 4624: I found two entries related to my sign-in. One of these events is marked as type 11, which indicates:

    CachedInteractive: A user logged on to this computer with network credentials that were stored locally on the computer. The domain controller wasn't contacted to verify the credentials.

  • The other was a Type 7: Which indicated that my workstation was unlocked.

Additionally, the logon process is recorded as “Negotiat,” and the authentication package is listed as “Negotiate” as well.

Interestingly, I didn’t come across any specific logs that would clearly indicate a PIN was used. I was hoping to find entries in either the Windows Hello for Business or User Device Registration logs—similar to what we see with biometric logins—but neither those logs nor the biometric logs provided any details related to the PIN-based login.

Next on my list is testing a Windows Hello–approved fingerprint scanner. Stay tuned for more updates on that front!


文章来源: https://www.hecfblog.com/2025/02/daily-blog-746-solving-windows-hello.html
如有侵权请联系:admin#unsafe.sh