WINDOWS-IR-EVENTS
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Critical Windows Event IDs for security monitoring, threat hunting, and incident response investigations.
EVENT LOG LOCATIONS#
Security Log: %SystemRoot%\System32\Winevt\Logs\Security.evtx System Log: %SystemRoot%\System32\Winevt\Logs\System.evtx Application Log: %SystemRoot%\System32\Winevt\Logs\Application.evtx PowerShell Log: Microsoft-Windows-PowerShell/Operational Sysmon Log: Microsoft-Windows-Sysmon/Operational TaskScheduler: Microsoft-Windows-TaskScheduler/Operational WMI Log: Microsoft-Windows-WMI-Activity/Operational Terminal Services: Microsoft-Windows-TerminalServices-LocalSessionManager/Operational Defender: Microsoft-Windows-Windows Defender/Operational Firewall: Microsoft-Windows-Windows Firewall With Advanced Security/Firewall
AUTHENTICATION EVENTS#
Event ID | Description | Log ---------|------------------------------------------|---------- 4624 | Successful logon | Security 4625 | Failed logon | Security 4634 | Logon session terminated (logoff) | Security 4647 | User initiated logoff | Security 4648 | Logon using explicit credentials (runas) | Security 4672 | Special privileges assigned (admin logon) | Security 4776 | NTLM authentication (success/failure) | Security 4768 | Kerberos TGT requested (AS-REQ) | Security 4769 | Kerberos service ticket requested (TGS) | Security 4771 | Kerberos pre-auth failed | Security 4624 LOGON TYPES (Critical for IR): Type 2: Interactive (local keyboard/console) Type 3: Network (SMB, net use, WMI) Type 4: Batch (scheduled tasks) Type 5: Service (service startup) Type 7: Unlock (workstation unlock) Type 8: NetworkCleartext (IIS basic auth) Type 9: NewCredentials (runas /netonly) Type 10: RemoteInteractive (RDP) Type 11: CachedInteractive (cached domain creds) Key fields in 4624: - Subject (who initiated) - Target (who logged on) - LogonType - WorkstationName (source machine) - IpAddress (source IP) - LogonProcessName (Negotiate, NTLM, Kerberos) - AuthenticationPackageName 4625 FAILURE STATUS CODES: 0xC000006A: Bad password 0xC0000064: User does not exist 0xC0000072: Account disabled 0xC0000234: Account locked out 0xC0000193: Account expired 0xC000006D: Bad username or auth info 0xC000015B: Logon type not granted 0xC0000071: Password expired 0xC0000224: Password must change at next logon
ACCOUNT MANAGEMENT EVENTS#
Event ID | Description | Log ---------|------------------------------------------|---------- 4720 | User account created | Security 4722 | User account enabled | Security 4723 | Password change attempted | Security 4724 | Password reset attempted | Security 4725 | User account disabled | Security 4726 | User account deleted | Security 4728 | Member added to security-enabled global group | Security 4732 | Member added to security-enabled local group | Security 4735 | Security-enabled local group changed | Security 4738 | User account changed | Security 4740 | User account locked out | Security 4756 | Member added to universal security group | Security 4767 | User account unlocked | Security HIGH-PRIORITY ALERTS: - 4720 followed by 4732 (new account added to admin group) - 4724 on privileged accounts (password reset) - 4738 changes to AdminCount or UAC flags - Multiple 4740 events (brute force lockouts)
POLICY AND AUDIT CHANGES#
Event ID | Description | Log ---------|------------------------------------------|---------- 4670 | Permissions on object changed | Security 4703 | Token right adjusted | Security 4704 | User right assigned | Security 4706 | Trust to domain created | Security 4713 | Kerberos policy changed | Security 4719 | System audit policy changed | Security 4739 | Domain policy changed | Security 4907 | Auditing settings on object changed | Security 1102 | Audit log cleared | Security 104 | Event log cleared | System RED FLAGS: - 1102/104: Log clearing is a strong indicator of cover-up - 4719: Audit policy changes may indicate attacker disabling logging - 4706: Unexpected domain trusts could indicate persistence
PROCESS CREATION AND EXECUTION#
Event ID | Description | Log ---------|------------------------------------------|---------- 4688 | New process created | Security 4689 | Process exited | Security 1 | Process creation (Sysmon) | Sysmon 4688 KEY FIELDS: - NewProcessName: full path of executable - CommandLine: full command line (requires audit policy) - ParentProcessName: parent process (requires Win10+) - SubjectUserName: user who started the process - TokenElevationType: %%1936=full token (elevated), %%1937=limited ENABLE COMMAND LINE AUDITING: GPO: Computer Configuration > Administrative Templates > System > Audit Process Creation > Include command line in process creation events = Enabled SUSPICIOUS PROCESS PATTERNS: - cmd.exe spawned by Office applications (Word, Excel) - powershell.exe with encoded commands (-enc, -e, -encodedcommand) - wscript.exe or cscript.exe spawned by browser - rundll32.exe with unusual DLL paths - mshta.exe executing remote content - certutil.exe downloading files (-urlcache) - bitsadmin.exe transferring files - regsvr32.exe /s /n /u (Squiblydoo)
POWERSHELL LOGGING#
Event ID | Description | Log
---------|------------------------------------------|----------
4103 | Module logging (pipeline execution) | PowerShell Operational
4104 | Script block logging (code content) | PowerShell Operational
4105 | Script block execution start | PowerShell Operational
4106 | Script block execution complete | PowerShell Operational
400 | Engine lifecycle (start) | PowerShell
403 | Engine lifecycle (stop) | PowerShell
800 | Pipeline execution details | PowerShell
ENABLE POWERSHELL LOGGING:
Script Block Logging:
GPO: Administrative Templates > Windows Components > Windows PowerShell
> Turn on PowerShell Script Block Logging = Enabled
> Log script block invocation start/stop events = Enabled
Module Logging:
> Turn on Module Logging = Enabled
Module Names: *
Transcription:
> Turn on PowerShell Transcription = Enabled
> Include invocation headers = Enabled
Output Directory: \\server\share\pslogs
SUSPICIOUS POWERSHELL INDICATORS (4104):
- Invoke-Expression (IEX)
- Invoke-WebRequest / Invoke-RestMethod
- System.Net.WebClient (DownloadString, DownloadFile)
- [System.Convert]::FromBase64String
- -EncodedCommand / -enc
- New-Object System.Net.Sockets.TCPClient (reverse shell)
- Invoke-Mimikatz / Invoke-Kerberoast
- Set-MpPreference -DisableRealtimeMonitoring (Defender off)
- Add-MpPreference -ExclusionPath (Defender exclusions)
- AMSI bypass patterns (AmsiUtils, amsiInitFailed)
SCHEDULED TASKS#
Event ID | Description | Log ---------|------------------------------------------|---------- 4698 | Scheduled task created | Security 4699 | Scheduled task deleted | Security 4700 | Scheduled task enabled | Security 4701 | Scheduled task disabled | Security 4702 | Scheduled task updated | Security 106 | Task registered | TaskScheduler 140 | Task updated | TaskScheduler 141 | Task removed | TaskScheduler 200 | Task executed | TaskScheduler 201 | Task completed | TaskScheduler PERSISTENCE INDICATORS: - Tasks created via command line (schtasks.exe) - Tasks running as SYSTEM - Tasks executing from unusual paths (\Temp, \AppData, \ProgramData) - Tasks with encoded PowerShell commands - Tasks triggered at logon or system start
SERVICE INSTALLATION#
Event ID | Description | Log ---------|------------------------------------------|---------- 4697 | Service installed | Security 7034 | Service crashed unexpectedly | System 7035 | Service control manager sent start/stop | System 7036 | Service started or stopped | System 7040 | Service start type changed | System 7045 | New service installed | System RED FLAGS: - Services with binary paths in temp/user directories - Services running as LocalSystem from unusual locations - Service names mimicking legitimate services (one char off) - Services with command-line executable paths (cmd.exe /c ...) - 7045 with ServiceType = kernel mode driver (rootkit)
SYSMON EVENTS (ESSENTIAL FOR IR)#
ID | Description | Key Fields ---|--------------------------------|---------------------------------- 1 | Process creation | Image, CommandLine, ParentImage, Hashes 2 | File creation time changed | TargetFilename, PreviousCreationUtcTime 3 | Network connection | DestinationIp, DestinationPort, Image 5 | Process terminated | Image 6 | Driver loaded | ImageLoaded, Hashes, Signed 7 | Image loaded (DLL) | ImageLoaded, Image, Signed, Hashes 8 | CreateRemoteThread | SourceImage, TargetImage (injection) 9 | RawAccessRead | Device (disk access bypass filesystem) 10 | ProcessAccess | SourceImage, TargetImage, GrantedAccess 11 | FileCreate | TargetFilename, Image 12 | Registry key/value created/deleted | TargetObject, EventType 13 | Registry value set | TargetObject, Details 14 | Registry key/value renamed | TargetObject, NewName 15 | FileCreateStreamHash | TargetFilename (ADS detection) 17 | PipeCreated | PipeName, Image 18 | PipeConnected | PipeName, Image 20 | WmiEventConsumer | Destination, Name 21 | WmiEventConsumerToFilter | Consumer, Filter 22 | DNSQuery | QueryName, QueryResults, Image 23 | FileDelete (archived) | TargetFilename, Image, Hashes 25 | ProcessTampering | Image, Type (hollowing detection) 26 | FileDeleteDetected | TargetFilename, Image CRITICAL SYSMON DETECTIONS: - Event 1: Look for LOLBins with suspicious parents - Event 3: Outbound connections from unusual processes - Event 8: CreateRemoteThread (process injection indicator) - Event 10: LSASS access (credential dumping) - TargetImage=lsass.exe - Event 11: File drops in \Temp, \AppData, startup folders - Event 22: DNS queries to known malicious domains or DGA patterns
LATERAL MOVEMENT DETECTION#
Event ID | Technique | Log | Indicator ---------|--------------------------|------------|------------------------- 4624(3) | SMB/WMI | Security | Type 3 + admin account 4624(10) | RDP | Security | Type 10 from internal IP 4648 | Pass-the-Hash/Ticket | Security | Explicit credential use 4776 | NTLM relay | Security | Unexpected NTLM auth 5140 | Network share accessed | Security | C$, ADMIN$, IPC$ access 5145 | Detailed file share | Security | Share access details
WINDOWS DEFENDER EVENTS#
Event ID | Description | Log ---------|------------------------------------------|---------- 1006 | Malware or unwanted software detected | Defender 1007 | Action taken against malware | Defender 1008 | Action against malware failed | Defender 1116 | Real-time protection detected malware | Defender 1117 | Real-time protection action taken | Defender 5001 | Real-time protection disabled | Defender 5010 | Scanning for unwanted software disabled | Defender 5012 | Virus scanning disabled | Defender
USEFUL QUERIES (POWERSHELL)#
# Recent failed logons
Get-WinEvent -FilterHashtable @{LogName='Security';Id=4625} -MaxEvents 50 |
Select TimeCreated, @{n='Account';e={$_.Properties[5].Value}},
@{n='Source';e={$_.Properties[19].Value}}
# New accounts created
Get-WinEvent -FilterHashtable @{LogName='Security';Id=4720}
# Cleared event logs
Get-WinEvent -FilterHashtable @{LogName='Security';Id=1102}
Get-WinEvent -FilterHashtable @{LogName='System';Id=104}
# Service installations
Get-WinEvent -FilterHashtable @{LogName='System';Id=7045}
# PowerShell script blocks with suspicious keywords
Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-PowerShell/Operational';Id=4104} |
Where-Object { $_.Message -match 'Invoke-|Download|WebClient|Base64|bypass' }
# Sysmon process creation
Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational';Id=1} -MaxEvents 100
# RDP logins
Get-WinEvent -FilterHashtable @{LogName='Security';Id=4624} |
Where-Object { $_.Properties[8].Value -eq 10 }
AUDIT POLICY RECOMMENDATIONS#
Enable these via: auditpol /set /subcategory:"<name>" /success:enable /failure:enable Logon/Logoff: Logon, Logoff, Special Logon, Other Logon Events Account Logon: Credential Validation, Kerberos Auth, Kerberos Ticket Account Management: User Account Management, Security Group Management Detailed Tracking: Process Creation (with command line) Object Access: File Share, Detailed File Share, SAM, Registry Policy Change: Audit Policy Change, Auth Policy Change Privilege Use: Sensitive Privilege Use System: Security System Extension, System Integrity
REFERENCES#
- Microsoft Security Auditing Documentation - SANS Windows Event Log Cheat Sheet (Jonathan Ham) - Sysmon Configuration: https://github.com/SwiftOnSecurity/sysmon-config - MITRE ATT&CK Data Sources: https://attack.mitre.org/datasources/ - NSA Spotting the Adversary with Windows Event Log Monitoring