← All cheat sheets

WINDOWS-IR-EVENTS

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Critical Windows Event IDs for security monitoring, threat hunting,
and incident response investigations.

EVENT LOG LOCATIONS#

Security Log:      %SystemRoot%\System32\Winevt\Logs\Security.evtx
System Log:        %SystemRoot%\System32\Winevt\Logs\System.evtx
Application Log:   %SystemRoot%\System32\Winevt\Logs\Application.evtx
PowerShell Log:    Microsoft-Windows-PowerShell/Operational
Sysmon Log:        Microsoft-Windows-Sysmon/Operational
TaskScheduler:     Microsoft-Windows-TaskScheduler/Operational
WMI Log:           Microsoft-Windows-WMI-Activity/Operational
Terminal Services: Microsoft-Windows-TerminalServices-LocalSessionManager/Operational
Defender:          Microsoft-Windows-Windows Defender/Operational
Firewall:          Microsoft-Windows-Windows Firewall With Advanced Security/Firewall

AUTHENTICATION EVENTS#

Event ID | Description                              | Log
---------|------------------------------------------|----------
4624     | Successful logon                         | Security
4625     | Failed logon                             | Security
4634     | Logon session terminated (logoff)         | Security
4647     | User initiated logoff                    | Security
4648     | Logon using explicit credentials (runas)  | Security
4672     | Special privileges assigned (admin logon) | Security
4776     | NTLM authentication (success/failure)     | Security
4768     | Kerberos TGT requested (AS-REQ)           | Security
4769     | Kerberos service ticket requested (TGS)   | Security
4771     | Kerberos pre-auth failed                  | Security

4624 LOGON TYPES (Critical for IR):
  Type 2:  Interactive (local keyboard/console)
  Type 3:  Network (SMB, net use, WMI)
  Type 4:  Batch (scheduled tasks)
  Type 5:  Service (service startup)
  Type 7:  Unlock (workstation unlock)
  Type 8:  NetworkCleartext (IIS basic auth)
  Type 9:  NewCredentials (runas /netonly)
  Type 10: RemoteInteractive (RDP)
  Type 11: CachedInteractive (cached domain creds)

Key fields in 4624:
  - Subject (who initiated)
  - Target (who logged on)
  - LogonType
  - WorkstationName (source machine)
  - IpAddress (source IP)
  - LogonProcessName (Negotiate, NTLM, Kerberos)
  - AuthenticationPackageName

4625 FAILURE STATUS CODES:
  0xC000006A: Bad password
  0xC0000064: User does not exist
  0xC0000072: Account disabled
  0xC0000234: Account locked out
  0xC0000193: Account expired
  0xC000006D: Bad username or auth info
  0xC000015B: Logon type not granted
  0xC0000071: Password expired
  0xC0000224: Password must change at next logon

ACCOUNT MANAGEMENT EVENTS#

Event ID | Description                              | Log
---------|------------------------------------------|----------
4720     | User account created                     | Security
4722     | User account enabled                     | Security
4723     | Password change attempted                | Security
4724     | Password reset attempted                 | Security
4725     | User account disabled                    | Security
4726     | User account deleted                     | Security
4728     | Member added to security-enabled global group | Security
4732     | Member added to security-enabled local group  | Security
4735     | Security-enabled local group changed     | Security
4738     | User account changed                     | Security
4740     | User account locked out                  | Security
4756     | Member added to universal security group  | Security
4767     | User account unlocked                    | Security

HIGH-PRIORITY ALERTS:
  - 4720 followed by 4732 (new account added to admin group)
  - 4724 on privileged accounts (password reset)
  - 4738 changes to AdminCount or UAC flags
  - Multiple 4740 events (brute force lockouts)

POLICY AND AUDIT CHANGES#

Event ID | Description                              | Log
---------|------------------------------------------|----------
4670     | Permissions on object changed             | Security
4703     | Token right adjusted                     | Security
4704     | User right assigned                      | Security
4706     | Trust to domain created                  | Security
4713     | Kerberos policy changed                  | Security
4719     | System audit policy changed              | Security
4739     | Domain policy changed                    | Security
4907     | Auditing settings on object changed      | Security
1102     | Audit log cleared                        | Security
104      | Event log cleared                        | System

RED FLAGS:
  - 1102/104: Log clearing is a strong indicator of cover-up
  - 4719: Audit policy changes may indicate attacker disabling logging
  - 4706: Unexpected domain trusts could indicate persistence

PROCESS CREATION AND EXECUTION#

Event ID | Description                              | Log
---------|------------------------------------------|----------
4688     | New process created                      | Security
4689     | Process exited                           | Security
1       | Process creation (Sysmon)                 | Sysmon

4688 KEY FIELDS:
  - NewProcessName: full path of executable
  - CommandLine: full command line (requires audit policy)
  - ParentProcessName: parent process (requires Win10+)
  - SubjectUserName: user who started the process
  - TokenElevationType: %%1936=full token (elevated), %%1937=limited

ENABLE COMMAND LINE AUDITING:
  GPO: Computer Configuration > Administrative Templates > System > Audit Process Creation
  > Include command line in process creation events = Enabled

SUSPICIOUS PROCESS PATTERNS:
  - cmd.exe spawned by Office applications (Word, Excel)
  - powershell.exe with encoded commands (-enc, -e, -encodedcommand)
  - wscript.exe or cscript.exe spawned by browser
  - rundll32.exe with unusual DLL paths
  - mshta.exe executing remote content
  - certutil.exe downloading files (-urlcache)
  - bitsadmin.exe transferring files
  - regsvr32.exe /s /n /u (Squiblydoo)

POWERSHELL LOGGING#

Event ID | Description                              | Log
---------|------------------------------------------|----------
4103     | Module logging (pipeline execution)       | PowerShell Operational
4104     | Script block logging (code content)       | PowerShell Operational
4105     | Script block execution start              | PowerShell Operational
4106     | Script block execution complete            | PowerShell Operational
400      | Engine lifecycle (start)                  | PowerShell
403      | Engine lifecycle (stop)                   | PowerShell
800      | Pipeline execution details                | PowerShell

ENABLE POWERSHELL LOGGING:
  Script Block Logging:
    GPO: Administrative Templates > Windows Components > Windows PowerShell
    > Turn on PowerShell Script Block Logging = Enabled
    > Log script block invocation start/stop events = Enabled

  Module Logging:
    > Turn on Module Logging = Enabled
    Module Names: *

  Transcription:
    > Turn on PowerShell Transcription = Enabled
    > Include invocation headers = Enabled
    Output Directory: \\server\share\pslogs

SUSPICIOUS POWERSHELL INDICATORS (4104):
  - Invoke-Expression (IEX)
  - Invoke-WebRequest / Invoke-RestMethod
  - System.Net.WebClient (DownloadString, DownloadFile)
  - [System.Convert]::FromBase64String
  - -EncodedCommand / -enc
  - New-Object System.Net.Sockets.TCPClient (reverse shell)
  - Invoke-Mimikatz / Invoke-Kerberoast
  - Set-MpPreference -DisableRealtimeMonitoring (Defender off)
  - Add-MpPreference -ExclusionPath (Defender exclusions)
  - AMSI bypass patterns (AmsiUtils, amsiInitFailed)

SCHEDULED TASKS#

Event ID | Description                              | Log
---------|------------------------------------------|----------
4698     | Scheduled task created                   | Security
4699     | Scheduled task deleted                   | Security
4700     | Scheduled task enabled                   | Security
4701     | Scheduled task disabled                  | Security
4702     | Scheduled task updated                   | Security
106      | Task registered                          | TaskScheduler
140      | Task updated                             | TaskScheduler
141      | Task removed                             | TaskScheduler
200      | Task executed                            | TaskScheduler
201      | Task completed                           | TaskScheduler

PERSISTENCE INDICATORS:
  - Tasks created via command line (schtasks.exe)
  - Tasks running as SYSTEM
  - Tasks executing from unusual paths (\Temp, \AppData, \ProgramData)
  - Tasks with encoded PowerShell commands
  - Tasks triggered at logon or system start

SERVICE INSTALLATION#

Event ID | Description                              | Log
---------|------------------------------------------|----------
4697     | Service installed                        | Security
7034     | Service crashed unexpectedly             | System
7035     | Service control manager sent start/stop  | System
7036     | Service started or stopped               | System
7040     | Service start type changed               | System
7045     | New service installed                    | System

RED FLAGS:
  - Services with binary paths in temp/user directories
  - Services running as LocalSystem from unusual locations
  - Service names mimicking legitimate services (one char off)
  - Services with command-line executable paths (cmd.exe /c ...)
  - 7045 with ServiceType = kernel mode driver (rootkit)

SYSMON EVENTS (ESSENTIAL FOR IR)#

ID | Description                    | Key Fields
---|--------------------------------|----------------------------------
1  | Process creation               | Image, CommandLine, ParentImage, Hashes
2  | File creation time changed     | TargetFilename, PreviousCreationUtcTime
3  | Network connection             | DestinationIp, DestinationPort, Image
5  | Process terminated             | Image
6  | Driver loaded                  | ImageLoaded, Hashes, Signed
7  | Image loaded (DLL)             | ImageLoaded, Image, Signed, Hashes
8  | CreateRemoteThread             | SourceImage, TargetImage (injection)
9  | RawAccessRead                  | Device (disk access bypass filesystem)
10 | ProcessAccess                  | SourceImage, TargetImage, GrantedAccess
11 | FileCreate                     | TargetFilename, Image
12 | Registry key/value created/deleted | TargetObject, EventType
13 | Registry value set             | TargetObject, Details
14 | Registry key/value renamed     | TargetObject, NewName
15 | FileCreateStreamHash           | TargetFilename (ADS detection)
17 | PipeCreated                    | PipeName, Image
18 | PipeConnected                  | PipeName, Image
20 | WmiEventConsumer               | Destination, Name
21 | WmiEventConsumerToFilter       | Consumer, Filter
22 | DNSQuery                       | QueryName, QueryResults, Image
23 | FileDelete (archived)          | TargetFilename, Image, Hashes
25 | ProcessTampering               | Image, Type (hollowing detection)
26 | FileDeleteDetected             | TargetFilename, Image

CRITICAL SYSMON DETECTIONS:
  - Event 1: Look for LOLBins with suspicious parents
  - Event 3: Outbound connections from unusual processes
  - Event 8: CreateRemoteThread (process injection indicator)
  - Event 10: LSASS access (credential dumping) - TargetImage=lsass.exe
  - Event 11: File drops in \Temp, \AppData, startup folders
  - Event 22: DNS queries to known malicious domains or DGA patterns

LATERAL MOVEMENT DETECTION#

Event ID | Technique               | Log        | Indicator
---------|--------------------------|------------|-------------------------
4624(3)  | SMB/WMI                  | Security   | Type 3 + admin account
4624(10) | RDP                      | Security   | Type 10 from internal IP
4648     | Pass-the-Hash/Ticket     | Security   | Explicit credential use
4776     | NTLM relay               | Security   | Unexpected NTLM auth
5140     | Network share accessed   | Security   | C$, ADMIN$, IPC$ access
5145     | Detailed file share      | Security   | Share access details

WINDOWS DEFENDER EVENTS#

Event ID | Description                              | Log
---------|------------------------------------------|----------
1006     | Malware or unwanted software detected     | Defender
1007     | Action taken against malware              | Defender
1008     | Action against malware failed             | Defender
1116     | Real-time protection detected malware     | Defender
1117     | Real-time protection action taken         | Defender
5001     | Real-time protection disabled             | Defender
5010     | Scanning for unwanted software disabled   | Defender
5012     | Virus scanning disabled                   | Defender

USEFUL QUERIES (POWERSHELL)#

# Recent failed logons
Get-WinEvent -FilterHashtable @{LogName='Security';Id=4625} -MaxEvents 50 |
  Select TimeCreated, @{n='Account';e={$_.Properties[5].Value}},
  @{n='Source';e={$_.Properties[19].Value}}

# New accounts created
Get-WinEvent -FilterHashtable @{LogName='Security';Id=4720}

# Cleared event logs
Get-WinEvent -FilterHashtable @{LogName='Security';Id=1102}
Get-WinEvent -FilterHashtable @{LogName='System';Id=104}

# Service installations
Get-WinEvent -FilterHashtable @{LogName='System';Id=7045}

# PowerShell script blocks with suspicious keywords
Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-PowerShell/Operational';Id=4104} |
  Where-Object { $_.Message -match 'Invoke-|Download|WebClient|Base64|bypass' }

# Sysmon process creation
Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational';Id=1} -MaxEvents 100

# RDP logins
Get-WinEvent -FilterHashtable @{LogName='Security';Id=4624} |
  Where-Object { $_.Properties[8].Value -eq 10 }

AUDIT POLICY RECOMMENDATIONS#

Enable these via: auditpol /set /subcategory:"<name>" /success:enable /failure:enable

  Logon/Logoff:        Logon, Logoff, Special Logon, Other Logon Events
  Account Logon:       Credential Validation, Kerberos Auth, Kerberos Ticket
  Account Management:  User Account Management, Security Group Management
  Detailed Tracking:   Process Creation (with command line)
  Object Access:       File Share, Detailed File Share, SAM, Registry
  Policy Change:       Audit Policy Change, Auth Policy Change
  Privilege Use:       Sensitive Privilege Use
  System:              Security System Extension, System Integrity

REFERENCES#

- Microsoft Security Auditing Documentation
- SANS Windows Event Log Cheat Sheet (Jonathan Ham)
- Sysmon Configuration: https://github.com/SwiftOnSecurity/sysmon-config
- MITRE ATT&CK Data Sources: https://attack.mitre.org/datasources/
- NSA Spotting the Adversary with Windows Event Log Monitoring