// REFERENCE
🪟 Windows Event IDs
A reference to the Windows Event IDs that matter most for security: what they log, which log they live in and what to hunt with them. Jump to the log analyzer or the Sigma rule generator to turn them into detection.
// Logon & sessions
4624
4624 — Successful logon 4625
4625 — Failed logon 4634
4634 — Logoff 4647
4647 — User-initiated logoff 4800
4800 — Workstation locked 4801
4801 — Workstation unlocked 4778
4778 — Session reconnected (RDP) 4779
4779 — Session disconnected (RDP)
4624 — Successful logon 4625
4625 — Failed logon 4634
4634 — Logoff 4647
4647 — User-initiated logoff 4800
4800 — Workstation locked 4801
4801 — Workstation unlocked 4778
4778 — Session reconnected (RDP) 4779
4779 — Session disconnected (RDP)
// Account & group management
4720
4720 — User account created 4722
4722 — User account enabled 4723
4723 — Password change attempt 4724
4724 — Password reset attempt 4725
4725 — User account disabled 4726
4726 — User account deleted 4728
4728 — Member added to a global security group 4732
4732 — Member added to a local security group 4738
4738 — User account changed 4740
4740 — Account locked out 4756
4756 — Member added to a universal security group
4720 — User account created 4722
4722 — User account enabled 4723
4723 — Password change attempt 4724
4724 — Password reset attempt 4725
4725 — User account disabled 4726
4726 — User account deleted 4728
4728 — Member added to a global security group 4732
4732 — Member added to a local security group 4738
4738 — User account changed 4740
4740 — Account locked out 4756
4756 — Member added to a universal security group
// Privileges & processes
4672
4672 — Special privileges assigned to new logon 4673
4673 — Sensitive privilege use 4688
4688 — A new process was created 4689
4689 — A process has exited
4672 — Special privileges assigned to new logon 4673
4673 — Sensitive privilege use 4688
4688 — A new process was created 4689
4689 — A process has exited
// Persistence: services & tasks
7045
7045 — A service was installed 7040
7040 — Service start type changed 4697
4697 — A service was installed (Security) 4698
4698 — A scheduled task was created 4699
4699 — A scheduled task was deleted 4700
4700 — A scheduled task was enabled 4702
4702 — A scheduled task was updated
7045 — A service was installed 7040
7040 — Service start type changed 4697
4697 — A service was installed (Security) 4698
4698 — A scheduled task was created 4699
4699 — A scheduled task was deleted 4700
4700 — A scheduled task was enabled 4702
4702 — A scheduled task was updated
// Lateral movement & resource access
5140
5140 — A network share was accessed 5145
5145 — Network share access was checked 5142
5142 — A network share was added 5143
5143 — A network share was modified 4648
4648 — Logon using explicit credentials
5140 — A network share was accessed 5145
5145 — Network share access was checked 5142
5142 — A network share was added 5143
5143 — A network share was modified 4648
4648 — Logon using explicit credentials
// Kerberos & NTLM
4768
4768 — Kerberos TGT requested (AS-REQ) 4769
4769 — Kerberos service ticket requested (TGS-REQ) 4770
4770 — Kerberos service ticket renewed 4771
4771 — Kerberos pre-authentication failed 4776
4776 — NTLM credential validation
4768 — Kerberos TGT requested (AS-REQ) 4769
4769 — Kerberos service ticket requested (TGS-REQ) 4770
4770 — Kerberos service ticket renewed 4771
4771 — Kerberos pre-authentication failed 4776
4776 — NTLM credential validation
// Auditing & log tampering
1102
1102 — The audit log was cleared 104
104 — Event log was cleared 4719
4719 — System audit policy was changed
1102 — The audit log was cleared 104
104 — Event log was cleared 4719
4719 — System audit policy was changed
// PowerShell
400
400 — PowerShell engine started 800
800 — PowerShell pipeline execution details 4103
4103 — PowerShell module logging 4104
4104 — PowerShell script block logging
400 — PowerShell engine started 800
800 — PowerShell pipeline execution details 4103
4103 — PowerShell module logging 4104
4104 — PowerShell script block logging
// Sysmon
1
Sysmon 1 — Process creation 3
Sysmon 3 — Network connection 7
Sysmon 7 — Image (DLL) loaded 8
Sysmon 8 — CreateRemoteThread 10
Sysmon 10 — Process access 11
Sysmon 11 — File created 13
Sysmon 13 — Registry value set 22
Sysmon 22 — DNS query
Sysmon 1 — Process creation 3
Sysmon 3 — Network connection 7
Sysmon 7 — Image (DLL) loaded 8
Sysmon 8 — CreateRemoteThread 10
Sysmon 10 — Process access 11
Sysmon 11 — File created 13
Sysmon 13 — Registry value set 22
Sysmon 22 — DNS query
Original descriptions based on Microsoft's public documentation. IDs and fields may vary with the Windows version and the active audit policy.