← All cheat sheets

WINDOWS-EVENTS

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Critical Windows Event IDs for security monitoring.
Essential reference for SOC analysts and incident responders.

AUTHENTICATION EVENTS#


    

LOGON EVENTS#

4624    Successful logon
4625    Failed logon
4634    Logoff
4647    User initiated logoff
4648    Logon with explicit credentials
4672    Special privileges assigned (admin logon)
4776    Credential validation (NTLM)
4768    Kerberos TGT requested
4769    Kerberos service ticket requested
4771    Kerberos pre-auth failed

LOGON TYPES (4624/4625)#

Type 2:  Interactive (local console)
Type 3:  Network (SMB, RPC)
Type 4:  Batch (scheduled task)
Type 5:  Service
Type 7:  Unlock
Type 8:  NetworkCleartext
Type 9:  NewCredentials (runas)
Type 10: RemoteInteractive (RDP)
Type 11: CachedInteractive

ACCOUNT MANAGEMENT#


    

USER ACCOUNTS#

4720    User account created
4722    User account enabled
4723    Password change attempted
4724    Password reset attempted
4725    User account disabled
4726    User account deleted
4738    User account changed
4740    Account locked out
4767    Account unlocked
4781    Account name changed

GROUP CHANGES#

4727    Security-enabled global group created
4728    Member added to global group
4729    Member removed from global group
4730    Security-enabled global group deleted
4731    Security-enabled local group created
4732    Member added to local group
4733    Member removed from local group
4734    Security-enabled local group deleted
4735    Local group changed
4737    Global group changed
4755    Universal group changed
4756    Member added to universal group
4757    Member removed from universal group

DOMAIN CONTROLLERS#

4742    Computer account changed
4743    Computer account deleted

PRIVILEGE USE#

4673    Privileged service called
4674    Operation attempted on privileged object
4688    New process created
4689    Process exited

OBJECT ACCESS#


    

FILE/FOLDER ACCESS#

4656    Handle requested to object
4658    Handle closed
4660    Object deleted
4663    Attempt to access object
4670    Permissions changed
4985    State of transaction changed

REGISTRY#

4657    Registry value modified
4660    Registry key deleted

SAM DATABASE#

4661    Handle requested to SAM

AUDIT POLICY#

4719    System audit policy changed
4902    Per-user audit policy table created
4906    CrashOnAuditFail value changed
4907    Auditing settings on object changed
4912    Per User Audit Policy changed

PROCESS TRACKING#

4688    Process creation
4689    Process termination
4696    Primary token assigned to process

SCHEDULED TASKS#

4698    Scheduled task created
4699    Scheduled task deleted
4700    Scheduled task enabled
4701    Scheduled task disabled
4702    Scheduled task updated

SERVICES#

7034    Service crashed unexpectedly
7035    Service control sent
7036    Service state change
7040    Service start type changed
7045    Service installed

FIREWALL#

4946    Rule added
4947    Rule modified
4948    Rule deleted
4950    Setting changed
5025    Firewall service stopped
5031    Application blocked
5152    Packet dropped
5154    Listen allowed
5156    Connection allowed
5157    Connection blocked

REMOTE ACCESS#


    

RDP#

4624    (Type 10) RDP logon
4625    (Type 10) RDP failed logon
4778    Session reconnected
4779    Session disconnected

POWERSHELL#

4103    Module logging
4104    Script block logging
4105    Script start
4106    Script stop

KERBEROS ATTACKS#


    

GOLDEN TICKET#

4624    Logon with no corresponding 4768
4672    High privileges without expected source

PASS-THE-TICKET#

4624    Logon from unexpected source
4648    Explicit credentials from unexpected host

KERBEROASTING#

4769    Multiple TGS requests (etype 0x17 RC4)
        Look for: service accounts, unusual requesting users

AS-REP ROASTING#

4768    TGT request without pre-auth
        Look for: users with DONT_REQ_PREAUTH

DCSYNC#

4662    DS-Replication-Get-Changes(-All)
        Object: Domain NC
        Properties: GUID for replication

LATERAL MOVEMENT#


    

PSEXEC#

4624    Type 3 logon
7045    Service installed (PSEXESVC)
4688    Process: PSEXESVC

WMI#

4624    Type 3 logon
4688    Process: wmiprvse.exe spawning child

WINRM#

4624    Type 3 logon
4688    Process: wsmprovhost.exe

DCOM#

4624    Type 3 logon
4688    Process: mmc.exe spawning child

SMB#

5140    Network share accessed
5145    Share object accessed

PERSISTENCE#


    

REGISTRY RUN KEYS#

4657    Registry value modified
        Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Run

SCHEDULED TASKS#

4698    Task created
4702    Task updated

SERVICES#

7045    Service installed
4697    Service installed (requires audit)

WMI#

5857    WMI activity
5858    WMI errors
5859    WMI subscription
5860    WMI filter registration
5861    WMI consumer registration

CREDENTIAL ACCESS#


    

LSASS#

4688    Process accessing lsass.exe
        Tools: mimikatz, procdump
4663    Read access to lsass

SAM#

4661    SAM handle requested
4663    SAM access

NTDS.DIT#

4663    Access to ntds.dit
4662    DS object accessed

SUSPICIOUS COMBINATIONS#


    

BRUTE FORCE#

Multiple 4625 (failed logon)
Same target, different accounts
Or same account, multiple sources

PASS THE HASH#

4624 Type 3 logon
NTLM authentication
No corresponding 4648

PRIVILEGE ESCALATION#

4672 immediately after 4624
Unexpected admin privileges

DATA EXFILTRATION#

5145 Large file access
4663 Multiple file reads

LOG LOCATIONS#

Security Log
- Authentication
- Account management
- Audit policy

System Log
- Services
- Drivers

Application Log
- Application specific

PowerShell Log
- Microsoft-Windows-PowerShell/Operational

Sysmon Log
- Microsoft-Windows-Sysmon/Operational

QUICK REFERENCE#

4624/4625: Logon success/failure
4720/4726: User created/deleted
4728/4729: Group member added/removed
4740: Account lockout
4688: Process created
4698: Scheduled task created
7045: Service installed
4672: Admin logon
4768/4769: Kerberos TGT/TGS
5140/5145: Share access