WINDOWS-EVENTS
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Critical Windows Event IDs for security monitoring. Essential reference for SOC analysts and incident responders.
AUTHENTICATION EVENTS#
LOGON EVENTS#
4624 Successful logon 4625 Failed logon 4634 Logoff 4647 User initiated logoff 4648 Logon with explicit credentials 4672 Special privileges assigned (admin logon) 4776 Credential validation (NTLM) 4768 Kerberos TGT requested 4769 Kerberos service ticket requested 4771 Kerberos pre-auth failed
LOGON TYPES (4624/4625)#
Type 2: Interactive (local console) Type 3: Network (SMB, RPC) Type 4: Batch (scheduled task) Type 5: Service Type 7: Unlock Type 8: NetworkCleartext Type 9: NewCredentials (runas) Type 10: RemoteInteractive (RDP) Type 11: CachedInteractive
ACCOUNT MANAGEMENT#
USER ACCOUNTS#
4720 User account created 4722 User account enabled 4723 Password change attempted 4724 Password reset attempted 4725 User account disabled 4726 User account deleted 4738 User account changed 4740 Account locked out 4767 Account unlocked 4781 Account name changed
GROUP CHANGES#
4727 Security-enabled global group created 4728 Member added to global group 4729 Member removed from global group 4730 Security-enabled global group deleted 4731 Security-enabled local group created 4732 Member added to local group 4733 Member removed from local group 4734 Security-enabled local group deleted 4735 Local group changed 4737 Global group changed 4755 Universal group changed 4756 Member added to universal group 4757 Member removed from universal group
DOMAIN CONTROLLERS#
4742 Computer account changed 4743 Computer account deleted
PRIVILEGE USE#
4673 Privileged service called 4674 Operation attempted on privileged object 4688 New process created 4689 Process exited
OBJECT ACCESS#
FILE/FOLDER ACCESS#
4656 Handle requested to object 4658 Handle closed 4660 Object deleted 4663 Attempt to access object 4670 Permissions changed 4985 State of transaction changed
REGISTRY#
4657 Registry value modified 4660 Registry key deleted
SAM DATABASE#
4661 Handle requested to SAM
AUDIT POLICY#
4719 System audit policy changed 4902 Per-user audit policy table created 4906 CrashOnAuditFail value changed 4907 Auditing settings on object changed 4912 Per User Audit Policy changed
PROCESS TRACKING#
4688 Process creation 4689 Process termination 4696 Primary token assigned to process
SCHEDULED TASKS#
4698 Scheduled task created 4699 Scheduled task deleted 4700 Scheduled task enabled 4701 Scheduled task disabled 4702 Scheduled task updated
SERVICES#
7034 Service crashed unexpectedly 7035 Service control sent 7036 Service state change 7040 Service start type changed 7045 Service installed
FIREWALL#
4946 Rule added 4947 Rule modified 4948 Rule deleted 4950 Setting changed 5025 Firewall service stopped 5031 Application blocked 5152 Packet dropped 5154 Listen allowed 5156 Connection allowed 5157 Connection blocked
REMOTE ACCESS#
RDP#
4624 (Type 10) RDP logon 4625 (Type 10) RDP failed logon 4778 Session reconnected 4779 Session disconnected
POWERSHELL#
4103 Module logging 4104 Script block logging 4105 Script start 4106 Script stop
KERBEROS ATTACKS#
GOLDEN TICKET#
4624 Logon with no corresponding 4768 4672 High privileges without expected source
PASS-THE-TICKET#
4624 Logon from unexpected source 4648 Explicit credentials from unexpected host
KERBEROASTING#
4769 Multiple TGS requests (etype 0x17 RC4)
Look for: service accounts, unusual requesting users
AS-REP ROASTING#
4768 TGT request without pre-auth
Look for: users with DONT_REQ_PREAUTH
DCSYNC#
4662 DS-Replication-Get-Changes(-All)
Object: Domain NC
Properties: GUID for replication
LATERAL MOVEMENT#
PSEXEC#
4624 Type 3 logon 7045 Service installed (PSEXESVC) 4688 Process: PSEXESVC
WMI#
4624 Type 3 logon 4688 Process: wmiprvse.exe spawning child
WINRM#
4624 Type 3 logon 4688 Process: wsmprovhost.exe
DCOM#
4624 Type 3 logon 4688 Process: mmc.exe spawning child
SMB#
5140 Network share accessed 5145 Share object accessed
PERSISTENCE#
REGISTRY RUN KEYS#
4657 Registry value modified
Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Run
SCHEDULED TASKS#
4698 Task created 4702 Task updated
SERVICES#
7045 Service installed 4697 Service installed (requires audit)
WMI#
5857 WMI activity 5858 WMI errors 5859 WMI subscription 5860 WMI filter registration 5861 WMI consumer registration
CREDENTIAL ACCESS#
LSASS#
4688 Process accessing lsass.exe
Tools: mimikatz, procdump
4663 Read access to lsass
SAM#
4661 SAM handle requested 4663 SAM access
NTDS.DIT#
4663 Access to ntds.dit 4662 DS object accessed
SUSPICIOUS COMBINATIONS#
BRUTE FORCE#
Multiple 4625 (failed logon) Same target, different accounts Or same account, multiple sources
PASS THE HASH#
4624 Type 3 logon NTLM authentication No corresponding 4648
PRIVILEGE ESCALATION#
4672 immediately after 4624 Unexpected admin privileges
DATA EXFILTRATION#
5145 Large file access 4663 Multiple file reads
LOG LOCATIONS#
Security Log - Authentication - Account management - Audit policy System Log - Services - Drivers Application Log - Application specific PowerShell Log - Microsoft-Windows-PowerShell/Operational Sysmon Log - Microsoft-Windows-Sysmon/Operational
QUICK REFERENCE#
4624/4625: Logon success/failure 4720/4726: User created/deleted 4728/4729: Group member added/removed 4740: Account lockout 4688: Process created 4698: Scheduled task created 7045: Service installed 4672: Admin logon 4768/4769: Kerberos TGT/TGS 5140/5145: Share access