// REFERENCE

🪟 Windows Event IDs

A reference to the Windows Event IDs that matter most for security: what they log, which log they live in and what to hunt with them. Jump to the log analyzer or the Sigma rule generator to turn them into detection.

55 results

// Logon & sessions

// Account & group management

// Privileges & processes

// Persistence: services & tasks

// Lateral movement & resource access

// Kerberos & NTLM

// Auditing & log tampering

// PowerShell

// Sysmon

Original descriptions based on Microsoft's public documentation. IDs and fields may vary with the Windows version and the active audit policy.