[Samba] [SamLogon, network] vs [Kerberos KDC, ENC-TS Pre-authentication]


This is just curiosity.

We are monitoring failed logons, and there seem to be three types:

- LDAP,simple bind/TLS
(obious, failed ldap logons)

and these two:
- SamLogon,network
- Kerberos KDC,ENC-TS Pre-authentication

Could someone explain what (the difference between) these two types is?

Google doesn't really seem to help.


