Windows-Event-ID-Enzyklopädie
237 Windows-Ereignisse für DFIR- und SOC-Analysten erklärt: was sie bedeuten, welche Überwachungsrichtlinie sie erzeugt, welche Felder zählen, wie Angreifer sie auslösen und welche SigmaHQ-Regeln sie erkennen.
237 Ereignisse
- 1100Event logging service shut downSecurityEnglischSecurity event 1100 marks the Windows Event Log service stopping, normally at shutdown. Outside a reboot it can mean logging was stopped on purpose.
- 1102Sicherheitsprotokoll gelöschtSecurityEvent-ID 1102 wird geschrieben, wenn das Sicherheitsprotokoll gelöscht wird, samt Konto. Im Normalbetrieb selten, klassisches Anti-Forensik-Indiz.
- 1104Security log fullSecurityEnglischSecurity event 1104 means the Security log reached its maximum size and is set not to overwrite, so new audit events can no longer be written.
- 4608Windows starting upSecurityEnglischSecurity event 4608 is logged when LSASS starts and auditing initializes during boot. Use it to mark system startups on the Security log timeline.
- 4616System time changedSecurityEnglischSecurity event 4616 records a system clock change with old and new time, account and process. Routine time sync is normal; manual jumps skew timelines.
- 4624Erfolgreiche AnmeldungSecurityEvent-ID 4624 protokolliert jede erfolgreiche Anmeldung: wer, wie (LogonType), von wo (IpAddress) und mit welchem Paket. Kern der Anmeldeforensik.
- 4625Fehlgeschlagene AnmeldungSecurityEvent-ID 4625 protokolliert fehlgeschlagene Anmeldeversuche. Status und SubStatus nennen den Grund: falsches Kennwort, unbekannter Benutzer, Sperre.
- 4634AbmeldungSecurityEvent-ID 4634 markiert das Ende einer Anmeldesitzung. Über die TargetLogonId mit einem 4624 verknüpfen, um die Sitzungsdauer zu messen.
- 4647User-initiated logoffSecurityEnglischEvent 4647 is logged when a user actively signs out of an interactive or RDP session, before the session teardown event 4634.
- 4648Anmeldung mit expliziten CredentialsSecurityEvent-ID 4648 wird auf dem Quellhost protokolliert, wenn ein Prozess explizit angegebene Anmeldeinformationen nutzt, etwa runas, net use /user oder PsExec -u.
- 4656Object handle requestedSecurityEnglischSecurity event 4656 logs a request for a handle to an audited file, registry key or kernel object, with the access asked for and whether it was granted.
- 4657Registry value modifiedSecurityEnglischSecurity event 4657 records a created, changed or deleted registry value on an audited key, with old and new data and the process that made the change.
- 4658Object handle closedSecurityEnglischSecurity event 4658 marks the closing of a handle to an audited object. Pair it with 4656 by HandleId to measure how long the object was open.
- 4660Object deletedSecurityEnglischSecurity event 4660 confirms that an audited file, registry key or kernel object was deleted. It has no object name, so join it to 4663 by HandleId.
- 4661SAM or AD handle requestedSecurityEnglischSecurity event 4661 logs a handle request on a SAM or Active Directory object. On DCs it exposes SAMR enumeration of users and groups such as Domain Admins.
- 4662AD object operationSecurityEnglischSecurity event 4662 logs an operation on an Active Directory object. With the replication rights GUIDs in Properties, it is the classic DCSync detection.
- 4663ObjektzugriffSecurityEvent-ID 4663 protokolliert ein genutztes Zugriffsrecht auf eine überwachte Datei, einen Registry-Schlüssel oder ein Kernelobjekt: wer, welcher Prozess, was.
- 4670Object permissions changedSecurityEnglischSecurity event 4670 records a change to an object's permissions (DACL or owner), with old and new security descriptors in SDDL and the process responsible.
- 4672Besondere Rechte zugewiesenSecurityEvent-ID 4672 folgt auf ein 4624, wenn die neue Sitzung sensible Privilegien wie SeDebug oder SeTcb besitzt — ein Marker für Administratoranmeldungen.
- 4673Privileged service calledSecurityEnglischSecurity event 4673 logs a call to a privileged system service, such as registering a logon process with SeTcbPrivilege, and whether the call succeeded.
- 4688ProzesserstellungSecurityEvent-ID 4688 protokolliert jeden neuen Prozess: Programm, Elternprozess, Konto, Erhöhung und optional die vollständige Befehlszeile. Standardmäßig aus.
- 4689Process exitedSecurityEnglischSecurity event 4689 logs a process exit with its PID, path, account and exit code. Pair it with 4688 to get how long a process ran. Off by default.
- 4697Dienst installiertSecurityEvent-ID 4697 protokolliert einen neuen Windows-Dienst mit Name, Binärpfad, Starttyp und Konto. Zentral für Lateral Movement à la PsExec und Persistenz.
- 4698Geplante Aufgabe erstelltSecurityEvent-ID 4698 protokolliert eine neue geplante Aufgabe samt XML: Befehl, Argumente, Konto, Trigger. Wichtig für Persistenz und Remote-Ausführung.
- 4699Scheduled task deletedSecurityEnglischSecurity event 4699 records a deleted scheduled task, including its last XML definition. Quick create-then-delete pairs point to remote execution.
- 4700Scheduled task enabledSecurityEnglischSecurity event 4700 records a scheduled task being enabled, with its XML definition. Watch for dormant or attacker-created tasks switched back on.
- 4701Scheduled task disabledSecurityEnglischSecurity event 4701 records a scheduled task being disabled, with its XML. Disabling security, backup or update tasks can be part of defense evasion.
- 4702Scheduled task updatedSecurityEnglischSecurity event 4702 records a modified scheduled task with its new XML definition. Look for changed actions or run-as accounts on existing tasks.
- 4703Token right adjustedSecurityEnglischSecurity event 4703 logs privileges being enabled or disabled in an access token, such as a process turning on SeDebugPrivilege before touching LSASS.
- 4704User right assignedSecurityEnglischSecurity event 4704 logs a user right (privilege) being assigned to an account or group in local security policy, such as SeDebugPrivilege or SeBackupPrivilege.
- 4705User right removedSecurityEnglischSecurity event 4705 logs a user right (privilege) being removed from an account or group in local security policy. Mirror of event 4704.
- 4713Kerberos policy changedSecurityEnglischSecurity event 4713 is logged on domain controllers when the domain Kerberos policy (ticket lifetimes, renewal, clock skew) is changed.
- 4717Logon right grantedSecurityEnglischSecurity event 4717 logs a logon right (e.g. SeRemoteInteractiveLogonRight, SeServiceLogonRight) being granted to an account or group in local security policy.
- 4718Logon right removedSecurityEnglischSecurity event 4718 logs a logon right (such as a Deny logon right or RDP logon right) being removed from an account or group in local security policy.
- 4719Überwachungsrichtlinie geändertSecurityEvent-ID 4719 protokolliert eine Änderung der Überwachungsrichtlinie, etwa wenn per auditpol die Erfolgs- oder Fehlerüberwachung entfernt wird.
- 4720Benutzerkonto erstelltSecurityEvent-ID 4720 protokolliert das Anlegen eines lokalen oder Domänen-Benutzerkontos: wer es anlegte, Name und SID des Kontos, Anfangsattribute.
- 4722Benutzerkonto aktiviertSecurityEvent-ID 4722 wird protokolliert, wenn ein Benutzer- oder Computerkonto aktiviert wird. Es zeigt, wer es aktiviert hat und welches Konto, per Name und SID.
- 4723Password change attemptSecurityEnglischSecurity event 4723 is logged when an account attempts to change its own password (knowing the old one). Failure means the new password was rejected.
- 4724Versuch der KennwortzurücksetzungSecurityEvent-ID 4724: Ein Konto setzt das Kennwort eines anderen zurück, ohne das alte zu kennen — eine administrative Aktion, die geprüft werden sollte.
- 4725User account disabledSecurityEnglischSecurity event 4725 is logged when a user or computer account is disabled, recording who disabled it and which account was affected.
- 4726Benutzerkonto gelöschtSecurityEvent-ID 4726 wird beim Löschen eines lokalen oder Domänen-Benutzerkontos protokolliert, mit Ausführendem sowie Name und SID des Kontos.
- 4727Global group createdSecurityEnglischSecurity event 4727 is logged on a domain controller when a new security-enabled global group is created in Active Directory.
- 4728Neues Mitglied in globaler GruppeSecurityEvent-ID 4728 wird auf einem Domänencontroller protokolliert, wenn ein Mitglied einer sicherheitsaktivierten globalen Gruppe wie Domain Admins hinzugefügt wird.
- 4729Member removed from global groupSecurityEnglischSecurity event 4729 is logged on a domain controller when a member is removed from a security-enabled global group, such as Domain Admins.
- 4730Global group deletedSecurityEnglischSecurity event 4730 is logged on a domain controller when a security-enabled global group is deleted from Active Directory.
- 4731Local group createdSecurityEnglischSecurity event 4731 is logged when a security-enabled local group is created — a local SAM group on a host, or a domain local group on a domain controller.
- 4732Neues Mitglied in lokaler GruppeSecurityEvent-ID 4732 wird protokolliert, wenn ein Mitglied einer lokalen Sicherheitsgruppe wie Administratoren oder einer domänenlokalen Gruppe beitritt.
- 4733Member removed from local groupSecurityEnglischSecurity event 4733 is logged when a member is removed from a security-enabled local group, such as the local Administrators group or a domain local group.
- 4734Local group deletedSecurityEnglischSecurity event 4734 is logged when a security-enabled local group is deleted — a local SAM group on a host, or a domain local group on a domain controller.
- 4735Local group changedSecurityEnglischSecurity event 4735 is logged when a security-enabled local group is changed. It shows name or SID history changes; most instances accompany membership changes.
- 4737Global group changedSecurityEnglischSecurity event 4737 is logged on a domain controller when a security-enabled global group is changed; most instances accompany membership changes.
- 4738Benutzerkonto geändertSecurityEvent-ID 4738 wird bei Änderungen an einem Benutzerkonto protokolliert: neue Attributwerte, inklusive Kontoflags wie Delegierung oder Preauth.
- 4739Domain policy changedSecurityEnglischSecurity event 4739 logs a change to domain password, lockout or logoff policy, or to ms-DS-MachineAccountQuota. Only the changed values are filled in.
- 4740Konto gesperrtSecurityEvent-ID 4740 wird protokolliert, wenn ein Konto nach zu vielen falschen Kennwörtern gesperrt wird. Es nennt das Konto und den aufrufenden Computer.
- 4741Computer account createdSecurityEnglischSecurity event 4741 is logged on a domain controller when a computer account is created in Active Directory, e.g. by a domain join or a manual pre-creation.
- 4742Computer account changedSecurityEnglischSecurity event 4742 is logged on a domain controller when a computer account is changed: password, SPNs, DNS name, delegation or account flags.
- 4743Computer account deletedSecurityEnglischSecurity event 4743 is logged on a domain controller when a computer account is deleted from Active Directory, with who deleted it and the account's SID.
- 4754Universal group createdSecurityEnglischSecurity event 4754 is logged on a domain controller when a new security-enabled universal group is created in Active Directory.
- 4755Universal group changedSecurityEnglischSecurity event 4755 is logged on a domain controller when a security-enabled universal group is changed; most instances accompany membership changes.
- 4756Mitglied in universeller GruppeSecurityEvent-ID 4756 protokolliert auf dem DC das Hinzufügen eines Mitglieds zu einer universellen Gruppe wie Enterprise Admins oder Schema Admins.
- 4757Member removed from universal groupSecurityEnglischSecurity event 4757 is logged on a domain controller when a member is removed from a security-enabled universal group, such as Enterprise Admins.
- 4765SID History addedSecurityEnglischSecurity event 4765 is logged on a domain controller when SID History is added to an account — normal in migrations, a privilege escalation path otherwise.
- 4766SID History add failedSecurityEnglischSecurity event 4766 is logged on a domain controller when an attempt to add SID History to an account fails — worth checking outside a migration project.
- 4767Account unlockedSecurityEnglischSecurity event 4767 is logged when a locked-out user account is unlocked, recording who unlocked it and which account.
- 4768Kerberos-TGT angefordertSecurityEvent-ID 4768 protokolliert auf dem DC jede Kerberos-TGT-Anforderung: Konto, Client-IP, Verschlüsselungs- und Vorauthentifizierungstyp, Ergebnis.
- 4769Kerberos-Dienstticket angefordertSecurityEvent-ID 4769 wird auf Domänencontrollern bei jeder Kerberos-Dienstticket-Anforderung (TGS) protokolliert — der zentrale Eintrag zum Erkennen von Kerberoasting.
- 4770Kerberos service ticket renewedSecurityEnglischEvent 4770 is logged on domain controllers when a client renews an existing Kerberos service ticket instead of requesting a new one.
- 4771Kerberos-Pre-Auth fehlgeschlagenSecurityEvent-ID 4771 wird auf Domänencontrollern protokolliert, wenn die Kerberos-Vorauthentifizierung fehlschlägt, meist wegen eines falschen Kennworts (Status 0x18).
- 4776NTLM-Überprüfung der AnmeldedatenSecurityEvent-ID 4776 protokolliert eine NTLM-Prüfung von Anmeldeinformationen: auf dem DC für Domänenkonten, auf dem lokalen Rechner für lokale Konten.
- 4778Sitzung wiederverbundenSecurityEvent-ID 4778: Ein Benutzer verbindet sich erneut mit einer bestehenden interaktiven Sitzung, meist RDP-Reconnect oder schneller Benutzerwechsel.
- 4779Session disconnectedSecurityEnglischEvent 4779 is logged when an interactive session is disconnected without logging off — an RDP window closed or a user switch.
- 4780AdminSDHolder ACL appliedSecurityEnglischSecurity event 4780 is logged when SDProp resets the ACL of a protected admin account to match AdminSDHolder, revealing ACL changes on privileged accounts.
- 4781Account renamedSecurityEnglischSecurity event 4781 is logged when the sAMAccountName of a user, computer or group is changed. It gives the old and new names with the account's SID.
- 4794DSRM password set attemptSecurityEnglischSecurity event 4794 is logged on a domain controller when someone sets the DSRM administrator password. Rare, and abused for DC persistence.
- 4798User's local groups enumeratedSecurityEnglischSecurity event 4798 logs a process listing which local groups a user belongs to, with the calling process. Mostly noise, but useful for spotting discovery.
- 4799Local group members enumeratedSecurityEnglischSecurity event 4799 logs a process listing the members of a local group such as Administrators, with the caller process. Good signal for local admin discovery.
- 4800Workstation lockedSecurityEnglischSecurity event 4800 records a user locking their workstation, with the account and logon session. Useful to tell when a user was really at the keyboard.
- 4801Workstation unlockedSecurityEnglischSecurity event 4801 records a user unlocking their workstation, with the account and logon session. Pairs with 4800 to show when the user was present.
- 4826Boot configuration loadedSecurityEnglischSecurity event 4826 records the Boot Configuration Data settings loaded at startup, such as test signing, integrity checks and kernel debugging.
- 4886Certificate request receivedSecurityEnglischSecurity event 4886 is logged on an AD CS certification authority when it receives a certificate request, with the request ID and the requesting account.
- 4887Certificate issuedSecurityEnglischSecurity event 4887 is logged on an AD CS certification authority when a certificate is issued: request ID, requester, subject and subject key identifier.
- 4907Object SACL changedSecurityEnglischSecurity event 4907 logs a change to an object's auditing settings (SACL) on a file or registry key, with the old and new security descriptors.
- 4946Firewall rule addedSecurityEnglischSecurity event 4946 records a Windows Firewall rule added locally, with its name, ID and profiles. Useful to catch attackers opening ports or allowing tools.
- 4947Firewall rule modifiedSecurityEnglischSecurity event 4947 logs a local change to an existing Windows Firewall rule. Watch for rules enabled, widened or switched from block to allow.
- 4948Firewall rule deletedSecurityEnglischSecurity event 4948 records the local deletion of a Windows Firewall rule. Useful to spot attackers removing block rules or cleaning up rules they added.
- 4964Special group logonSecurityEnglischSecurity event 4964 flags a logon by a member of a group listed in the SpecialGroups registry value, e.g. Domain Admins. Only works once configured.
- 5136AD object modifiedSecurityEnglischSecurity event 5136 logs an attribute change on an Active Directory object, with the attribute and value — GPO edits, SPNs, ACLs, shadow credentials.
- 5137AD object createdSecurityEnglischSecurity event 5137 logs the creation of an Active Directory object — user, computer, group, GPO or any other class — with its DN, class and creator.
- 5140Zugriff auf NetzwerkfreigabeSecurityEvent-ID 5140 protokolliert den ersten Zugriff auf eine Netzwerkfreigabe in einer SMB-Sitzung: Konto, Quell-IP und Freigabe. Zentral für C$, ADMIN$ und IPC$.
- 5141AD object deletedSecurityEnglischSecurity event 5141 logs the deletion of an Active Directory object, with its DN, class, the account responsible and whether a subtree delete was used.
- 5142Network share addedSecurityEnglischSecurity event 5142 records a new network share: who created it, its name and local path. Watch for shares exposing drives or staging folders.
- 5144Network share deletedSecurityEnglischSecurity event 5144 records the removal of a network share, with the account that deleted it and the share's name and path. Often a cleanup step.
- 5145Zugriffsprüfung auf FreigabeobjektSecurityEvent-ID 5145 protokolliert jede Datei, jeden Ordner und jede Named Pipe, die über eine Freigabe geöffnet wird: Konto, Quell-IP, Rechte. Sehr laut.
- 5156WFP connection allowedSecurityEnglischSecurity event 5156 logs each connection allowed by the Windows Filtering Platform: process, direction, addresses, ports and protocol.
- 5157WFP connection blockedSecurityEnglischSecurity event 5157 logs each connection blocked by the Windows Filtering Platform, with process, direction, addresses and ports. Reveals scans and blocked C2.
- 5376Credential Manager backupSecurityEnglischSecurity event 5376 records a backup of a user's Credential Manager vault. Rarely used by real users, so worth checking every time.
- 5377Credential Manager restoreSecurityEnglischSecurity event 5377 records Credential Manager credentials restored from a backup file into a user's vault. Rare; confirm each one.
- 6416External device recognizedSecurityEnglischSecurity event 6416 records a new device recognized by Windows, such as a USB drive, with device ID, class and vendor IDs. Needs Audit PNP Activity.
- 12Operating system startedSystemEnglischSystem event 12 (Kernel-General) marks an operating system boot and records the exact kernel start time and OS build. The anchor for every boot timeline.
- 13Operating system shutdownSystemEnglischSystem event 13 (Kernel-General) is written on a clean shutdown with the exact stop time. No 13 before a boot means a crash or power loss.
- 41Unclean reboot (Kernel-Power)SystemEnglischSystem event 41 (Kernel-Power) is logged at boot when the previous session ended without a clean shutdown: crash, hang, power loss or forced reset.
- 104Ereignisprotokoll gelöschtSystemEvent-ID 104 im System-Log zeigt, dass ein Ereignisprotokoll (System, Application, Sysmon, PowerShell …) gelöscht wurde, und von wem. Security-Log: 1102.
- 1014DNS resolution timeoutSystemEnglischSystem event 1014 (DNS Client) is logged when a name lookup timed out because none of the configured DNS servers answered. Mostly network noise.
- 1074Herunterfahren oder NeustartSystemEvent-ID 1074 (User32) zeigt, wer Herunterfahren oder Neustart angefordert hat: Prozess, Benutzer, Grundcode und Kommentar. Beantwortet „Wer hat neu gestartet?“
- 5827Vulnerable Netlogon channel deniedSystemEnglischSystem event 5827: a DC denied a machine account's Netlogon secure channel without secure RPC. Key Zerologon (CVE-2020-1472) signal.
- 6005Event Log service startedSystemEnglischSystem event 6005 is written when the Event Log service starts, which in practice means at every boot. A simple, reliable startup marker next to event 12.
- 6006Event Log service stoppedSystemEnglischSystem event 6006 is written when the Event Log service stops, normally at clean shutdown. Missing before a boot means a crash.
- 6008Unexpected shutdownSystemEnglischSystem event 6008 is logged at boot when the previous shutdown was unexpected, with the approximate local time the system went down. Pairs with Kernel-Power 41.
- 6013Uptime reportSystemEnglischSystem event 6013 reports the system uptime in seconds and the time zone, at boot and once a day. Helps spot reboots and log gaps.
- 7000Service failed to startSystemEnglischSystem event 7000 is logged when a service fails to start, with the error. Often follows a malicious 7045 whose payload is not a real service binary.
- 7009Service start timeoutSystemEnglischSystem event 7009: a service did not report to the SCM within the timeout (30 s by default). Common with command-based malicious services.
- 7031Service crashed (recovery action)SystemEnglischSystem event 7031: a service terminated unexpectedly and the SCM will apply a recovery action. Can reveal security tools being killed.
- 7034Service crashedSystemEnglischSystem event 7034: a service process ended unexpectedly with no recovery action configured. Crashes, or security services being killed.
- 7036Dienststatus geändertSystemEvent-ID 7036 protokolliert jeden Wechsel eines Dienstes in den Status „läuft“ oder „beendet“. Zeigt, wann Sicherheitstools gestoppt wurden.
- 7040Service start type changedSystemEnglischSystem event 7040 records a change to a service start type (auto, demand, disabled). Reveals security tools being disabled and services turned into persistence.
- 7045Dienst installiertSystemEvent-ID 7045 im System-Log erfasst jeden neuen Dienst oder Treiber: Name, Binärpfad, Starttyp und Konto. Eines der besten Signale für Lateral Movement.
- 20001Device driver installedSystemEnglischSystem event 20001 (UserPnp) records a device driver install with the device instance ID. First-connection evidence for USB storage.
- 1000Application crashApplicationEnglischApplication event 1000 records a process crash: application, faulting module, exception code and offset. Exposes exploits and killed tools.
- 1001Windows Error Reporting reportApplicationEnglischApplication event 1001 records a Windows Error Reporting report (APPCRASH, BEX, BlueScreen...) and its report folder. Complements 1000.
- 1033MSI product installedApplicationEnglischApplication event 1033 (MsiInstaller) records an MSI package installation: product name, version, manufacturer and result, with the installing user's SID.
- 11707MSI installation succeededApplicationEnglischApplication event 11707 (MsiInstaller) confirms that an MSI product installation completed successfully, with the product name and the installing user's SID.
- 18456SQL Server login failedApplicationEnglischApplication event 18456 from SQL Server logs a failed database login with user, reason and client IP. Brute force against MSSQL.
- 1ProzesserstellungSysmonSysmon-Event-ID 1 protokolliert jeden neuen Prozess mit Befehlszeile, Hashes, Elternprozess und ProcessGuid zur Korrelation. Das Rückgrat des Endpoint-Huntings.
- 2File creation time changedSysmonEnglischSysmon event 2 fires when a process explicitly changes a file's creation timestamp — the classic trace of timestomping, but also common in installers.
- 3NetzwerkverbindungSysmonSysmon-Event-ID 3 verknüpft jede TCP-/UDP-Verbindung mit dem auslösenden Prozess: Quelle, Ziel, Ports und ProcessGuid. Zentral für C2 und Lateral Movement.
- 4Service state changedSysmonEnglischSysmon event 4 reports the Sysmon service starting or stopping. An unexpected stop outside maintenance can mean someone is blinding endpoint telemetry.
- 5Process terminatedSysmonEnglischSysmon event 5 records a process exiting, with ProcessGuid and image path. Pairs with event 1 to measure lifetime and close out process timelines.
- 6Driver loadedSysmonEnglischSysmon event 6 logs a kernel driver being loaded, with hashes and signature details. Rare and high-impact: watch for vulnerable or unsigned drivers.
- 7Image (DLL) loadedSysmonEnglischSysmon event 7 logs a DLL or other module loaded into a process, with hashes and signature. Used to catch DLL side-loading and unusual module loads.
- 8Remote thread createdSysmonEnglischSysmon event 8 fires when a process creates a thread in another process — a classic code injection technique. Low volume, high signal.
- 9Raw disk access readSysmonEnglischSysmon event 9 logs a process reading a drive directly through the \\.\ device path, used to copy locked files such as NTDS.dit or SAM without file APIs.
- 10ProzesszugriffSysmonSysmon-Event-ID 10 protokolliert, wenn ein Prozess ein Handle auf einen anderen öffnet, mit Zugriffsmaske und Call Stack. Zentral für LSASS-Dumping.
- 11Datei erstelltSysmonSysmon-Event-ID 11 protokolliert das Erstellen oder Überschreiben einer Datei und den schreibenden Prozess. Zentral für Payloads, Persistenzordner und Dumps.
- 12Registry key created or deletedSysmonEnglischSysmon event 12 logs registry keys and values being created or deleted, with the process responsible. Watch autostart keys, services and COM entries.
- 13Registry-Wert gesetztSysmonSysmon-Event-ID 13 protokolliert das Schreiben eines Registry-Werts, mit den Daten bei DWORD, QWORD und Zeichenfolgen. Das Haupt-Event für Registry-Persistenz.
- 14Registry key or value renamedSysmonEnglischSysmon event 14 logs a registry key or value being renamed, with the old path and the new name. Rare, and occasionally used to hide or stage persistence.
- 15Alternate data stream createdSysmonEnglischSysmon event 15 logs a named NTFS stream being created, such as the Zone.Identifier mark of the web on downloads. Reveals download origins and ADS use.
- 16Configuration changedSysmonEnglischSysmon event 16 records a change to the Sysmon configuration, with the config file and its hash. An unexpected change may be an attempt to blind monitoring.
- 17Named pipe createdSysmonEnglischSysmon event 17 logs a named pipe being created and the process behind it. Known pipe names reveal PsExec, C2 frameworks and other lateral movement tools.
- 18Named pipe connectedSysmonEnglischSysmon event 18 logs a client connecting to a named pipe. Paired with event 17 it shows who talks over a pipe — useful for PsExec and C2 pivots.
- 19WMI event filter registeredSysmonEnglischSysmon event 19 logs a WMI event filter being registered, with namespace, name and WQL query. The first of three events behind WMI subscription persistence.
- 20WMI event consumer registeredSysmonEnglischSysmon event 20 logs a WMI event consumer being registered, including the command or script it runs. The action half of WMI subscription persistence.
- 21WMI consumer bound to filterSysmonEnglischSysmon event 21 logs a WMI consumer being bound to a filter, the step that activates a permanent WMI subscription. Completes the WMI persistence trio.
- 22DNS-AbfrageSysmonSysmon-Event-ID 22 protokolliert DNS-Abfragen eines Prozesses mit Name, Status und Antworten. Verknüpft Domänen mit Prozessen für C2- und Tunneling-Hunts.
- 23File deleted (archived)SysmonEnglischSysmon event 23 logs a file deletion and saves a copy of the deleted file in the archive folder. Recovers payloads and tools attackers delete after use.
- 24Clipboard content changedSysmonEnglischSysmon event 24 records a change to clipboard contents, with process, session and hash; contents can be archived. Useful for RDP copy-paste investigations.
- 25Process tampering detectedSysmonEnglischSysmon event 25 fires when a process image is changed in memory or on disk, as in process hollowing or herpaderping. Rare and high-signal.
- 26File deleted (logged)SysmonEnglischSysmon event 26 logs a file deletion with the deleting process and hashes but, unlike event 23, does not keep a copy. A low-cost way to track deletions.
- 27Executable file blockedSysmonEnglischSysmon event 27 fires when Sysmon blocks the creation of an executable (PE) file matching its rules. A preventive control added in Sysmon 14.0.
- 28File shredding blockedSysmonEnglischSysmon event 28 fires when Sysmon blocks a file-shredding attempt, such as SDelete overwriting a file before deleting it. Added in Sysmon 14.1.
- 29Executable file detectedSysmonEnglischSysmon event 29 logs the creation of a new executable (PE) file, with hashes, without blocking it. Added in Sysmon 15.0; ideal for tracking dropped binaries.
- 255ErrorSysmonEnglischSysmon event 255 reports an internal Sysmon error, such as events dropped under load or a failed operation. Signals gaps in telemetry and possible tampering.
- 4103ModulprotokollierungPowerShell OperationalPowerShell-Event-ID 4103 (Modulprotokollierung) erfasst die Pipeline-Ausführung: jeden aufgerufenen Befehl mit Parameterbindungen und Host-Kontext.
- 4104SkriptblockprotokollierungPowerShell OperationalPowerShell-Event-ID 4104 protokolliert den Text ausgeführter Skriptblöcke nach der Dekodierung — der beste Nachweis dessen, was PowerShell ausführte.
- 4105Script block invocation startedPowerShell OperationalEnglischPowerShell event 4105 marks the start of a script block's execution; with 4106 it gives run times for blocks logged by 4104.
- 4106Script block invocation completedPowerShell OperationalEnglischPowerShell event 4106 marks the end of a script block's execution, paired with 4105 by ScriptBlockId when invocation logging is enabled.
- 40961Console startingPowerShell OperationalEnglischPowerShell event 40961 is logged when a PowerShell host starts, giving a timestamp for each PowerShell launch even without script logging.
- 40962Console ready for inputPowerShell OperationalEnglischPowerShell event 40962 follows 40961 when the PowerShell host is ready for input — another default-logged marker of PowerShell use.
- 400Engine startedWindows PowerShellEnglischWindows PowerShell event 400 logs every engine start with HostApplication (the command line) and EngineVersion — key to spot PowerShell v2 downgrades.
- 403Engine stoppedWindows PowerShellEnglischWindows PowerShell event 403 logs when a PowerShell engine stops; paired with 400 it bounds a PowerShell session in time.
- 600Provider startedWindows PowerShellEnglischWindows PowerShell event 600 is logged as each provider (Registry, FileSystem, Variable…) starts in a new session, repeating HostApplication.
- 800Pipeline execution detailsWindows PowerShellEnglischWindows PowerShell event 800 records pipeline execution details (commands and parameters) when module logging is enabled.
- 100Task startedTask SchedulerEnglischTask Scheduler event 100 marks the start of a task instance: task path, run-as user and an instance GUID that links the launch, actions and completion.
- 102Task completedTask SchedulerEnglischTask Scheduler event 102 marks the end of a task instance. With event 100 it bounds how long a task ran; the action's return code is in event 201.
- 106Task registeredTask SchedulerEnglischTask Scheduler event 106 records that a user registered a new scheduled task: the task path and the account that created it. Key for persistence hunting.
- 129Task process createdTask SchedulerEnglischTask Scheduler event 129 records the process created for a task: task path, image path and process ID — the link to process creation logs.
- 140Task updatedTask SchedulerEnglischTask Scheduler event 140 records that a user updated an existing scheduled task. Watch for built-in or trusted tasks being modified to run a payload.
- 141Task deletedTask SchedulerEnglischTask Scheduler event 141 records that a user deleted a scheduled task. Right after 106 and a run, it points to one-shot remote execution or cleanup.
- 142Task disabledTask SchedulerEnglischTask Scheduler event 142 records that a user disabled a scheduled task — relevant when security, update or backup tasks are switched off.
- 200Action startedTask SchedulerEnglischTask Scheduler event 200 records that a task action was launched: which task, which instance and the action itself — often the program path that ran.
- 201Action completedTask SchedulerEnglischTask Scheduler event 201 records that a task action completed, with the action and its return code — tells you whether the launched program succeeded.
- 21Sitzungsanmeldung erfolgreichRDP LocalSessionManagerRDP-Event-ID 21 bestätigt eine Sitzungsanmeldung auf dem Ziel: Benutzer, Sitzungs-ID und Quell-Netzwerkadresse („LOCAL“ bei Konsolenanmeldungen).
- 22Shell startRDP LocalSessionManagerEnglischRDP event 22 is logged when the user's shell (Explorer) starts in a new session, right after the session logon event 21.
- 23Session logoffRDP LocalSessionManagerEnglischRDP event 23 is logged when a Remote Desktop or console session is logged off, closing the session opened by event 21.
- 24Sitzung getrenntRDP LocalSessionManagerRDP-Event-ID 24 wird protokolliert, wenn eine Remotedesktopsitzung ohne Abmeldung getrennt wird, mit Benutzer, Sitzungs-ID und Client-Adresse.
- 25Sitzung wiederverbundenRDP LocalSessionManagerRDP-Event-ID 25 wird protokolliert, wenn sich ein Benutzer erneut mit einer bestehenden, getrennten Sitzung verbindet, mit der neuen Client-Adresse.
- 39Session disconnected by another sessionRDP LocalSessionManagerEnglischRDP event 39 records that one session was disconnected by another session, as with a session takeover or tscon.
- 40Session disconnect reasonRDP LocalSessionManagerEnglischRDP event 40 gives the reason code for a session disconnect, telling user-initiated disconnects from replaced connections.
- 1149Verbindung authentifiziertRDP RemoteConnectionManagerRDP-Event-ID 1149 protokolliert eine eingehende Remotedesktopverbindung mit Benutzer, Domäne und Quell-IP. Belegt die Verbindung, nicht die Anmeldung.
- 1024Outbound connection attemptRDP ClientEnglischRDP client event 1024 is logged on the source host when mstsc starts connecting to a server; the Value field holds the target name or IP.
- 1102Multi-transport connectionRDP ClientEnglischRDP client event 1102 is logged on the source host when the client opens a multi-transport connection; Value holds the server IP address.
- 131TCP connection acceptedRDP RdpCoreTSEnglischRdpCoreTS event 131 is logged when the RDP server accepts a TCP connection, with the client IP and port — even for failed or scanner connections.
- 5857Provider startedWMI-ActivityEnglischWMI-Activity event 5857 logs a WMI provider being loaded: provider name, DLL path and host process. Useful to spot rogue providers and WMI usage.
- 5858Operation errorWMI-ActivityEnglischWMI-Activity event 5858 logs a failed WMI operation with the client machine, user, process ID and the query or method that failed. Noisy but revealing.
- 5860Temporary event consumerWMI-ActivityEnglischWMI-Activity event 5860 logs a temporary WMI event subscription: the namespace, the WQL notification query and the client process that registered it.
- 5861Permanent event consumerWMI-ActivityEnglischWMI-Activity event 5861 logs a permanent WMI event subscription (filter-to-consumer binding), the classic fileless persistence technique.
- 1006Malware found by scanMicrosoft DefenderEnglischDefender event 1006 is logged when the antimalware engine finds malware or unwanted software, with threat name, path and detection source.
- 1007Action taken (engine)Microsoft DefenderEnglischDefender event 1007 records that the antimalware platform took action on detected malware, the engine-level counterpart of event 1117.
- 1008Engine action failedMicrosoft DefenderEnglischDefender event 1008 means Defender could not complete an action on detected malware (engine level); the item may still be on the system.
- 1013Detection history deletedMicrosoft DefenderEnglischDefender event 1013 is logged when Defender's malware detection history is deleted — routine purging, or an attempt to hide past detections.
- 1015Suspicious behavior detectedMicrosoft DefenderEnglischDefender event 1015 is logged when behavior monitoring detects suspicious activity rather than a known file, with threat name and process details.
- 1116Malware detectedMicrosoft DefenderEnglischDefender event 1116 is logged when Microsoft Defender Antivirus detects malware or unwanted software: threat name, file path, process and user.
- 1117Action taken on malwareMicrosoft DefenderEnglischDefender event 1117 confirms Microsoft Defender Antivirus acted on a detection — quarantine, remove, clean or block — with threat, path and action.
- 1118Action on malware failedMicrosoft DefenderEnglischDefender event 1118 means Microsoft Defender Antivirus detected a threat but could not remediate it (non-critical failure) — the item may still be present.
- 1119Critical failure acting on malwareMicrosoft DefenderEnglischDefender event 1119 records a critical error while acting on a detected threat — remediation failed and the threat may still be active.
- 1121ASR rule blocked an operationMicrosoft DefenderEnglischDefender event 1121 is logged when an attack surface reduction (ASR) rule in block mode stops an operation, such as LSASS access or Office child processes.
- 2001Security intelligence update failedMicrosoft DefenderEnglischDefender event 2001 is logged when a security intelligence (signature) update fails, with the versions, update source and error.
- 5000Real-time protection enabledMicrosoft DefenderEnglischDefender event 5000 is logged when real-time protection is turned on — the counterpart of 5001, useful to measure how long protection was off.
- 5001Real-time protection disabledMicrosoft DefenderEnglischDefender event 5001 is logged when real-time protection is turned off — a classic step before attackers drop tools or ransomware.
- 5004Real-time protection config changedMicrosoft DefenderEnglischDefender event 5004 is logged when a real-time protection feature (on-access, behavior monitoring, downloads scanning…) changes configuration.
- 5007Configuration changedMicrosoft DefenderEnglischDefender event 5007 logs every Defender configuration change with old and new values — including exclusions added by attackers.
- 5010Malware scanning disabledMicrosoft DefenderEnglischDefender event 5010 is logged when scanning for malware and potentially unwanted software is disabled — a sign of defense tampering or another AV.
- 5012Virus scanning disabledMicrosoft DefenderEnglischDefender event 5012 is logged when Defender virus scanning is disabled — like 5010, a strong tampering signal unless another antivirus took over.
- 5013Tamper protection blocked a changeMicrosoft DefenderEnglischDefender event 5013 is logged when tamper protection blocks a change to Defender settings — evidence that something tried to weaken the antivirus.
- 3Job createdBITS ClientEnglischBITS event 3 records the creation of a BITS transfer job: job title, job ID, owner and, on newer builds, the process that created it.
- 4Job completedBITS ClientEnglischBITS event 4 records that a BITS transfer job completed: job title, ID, owner, file count and bytes transferred. Confirms a download or upload finished.
- 59Transfer startedBITS ClientEnglischBITS event 59 records that BITS started transferring a job, with the job name and the remote URL — the event that tells you where BITS was downloading from.
- 60Transfer stoppedBITS ClientEnglischBITS event 60 records that BITS stopped transferring a job, with the job name, remote URL and status code — success, failure or interruption.
- 6WSMan session created (client)WinRMEnglischWinRM event 6 is logged on the client when a WS-Management session is created, with the connection string naming the remote host. Source-side PS remoting.
- 91WSMan shell created (server)WinRMEnglischWinRM event 91 is logged on the target when a remote WSMan shell is created, with the resource URI showing whether it is PowerShell remoting or winrs.
- 169User authenticated (legacy)WinRMEnglischWinRM event 169 logs a user authenticating to the WinRM service and the mechanism used. It is defined only in Windows 7 / Server 2008 R2 era manifests.
- 8002EXE or DLL allowedAppLockerEnglischAppLocker event 8002 records that an executable or DLL was allowed to run by an AppLocker rule, with the file path, matching rule and user SID.
- 8003EXE or DLL would be blocked (audit)AppLockerEnglischAppLocker event 8003 records an executable or DLL that ran but would have been blocked if the policy were enforced. Audit-mode view of unapproved code.
- 8004EXE or DLL blockedAppLockerEnglischAppLocker event 8004 records an executable or DLL blocked by an enforced AppLocker policy, with file path, signer, hash and the user who tried to run it.
- 8005MSI or script allowedAppLockerEnglischAppLocker event 8005 records that a script or Windows Installer file was allowed to run by an AppLocker rule, with the file path, rule and user SID.
- 8006Script or MSI would be blockedAppLockerEnglischAppLocker event 8006 records a script or MSI that ran but would have been blocked if the policy were enforced — audit-mode view of unapproved scripts.
- 8007MSI or script blockedAppLockerEnglischAppLocker event 8007 records a script or Windows Installer file blocked by an enforced AppLocker policy, with the path, hash and user who tried to run it.
- 2004Rule addedWindows FirewallEnglischFirewall event 2004 records a new Windows Firewall rule with its program, ports, action and the user and process that added it. On by default, richer than 4946.
- 2005Rule modifiedWindows FirewallEnglischFirewall event 2005 records a change to an existing Windows Firewall rule, with the rule's new settings and the user and process that changed it. On by default.
- 2006Rule deletedWindows FirewallEnglischFirewall event 2006 records the deletion of a Windows Firewall rule, with the rule ID, name, and the user SID and process that removed it. On by default.
- 2033All rules deletedWindows FirewallEnglischFirewall event 2033 records that every rule was deleted from a Windows Firewall rule store, with the user SID and process responsible. Rare and worth reviewing.
- 1006Disk connected (partition data)PartitionEnglischPartition event 1006 records a disk's vendor, model, serial, capacity and raw MBR/VBR bytes on connection. Rich USB evidence, incl. volume serials.
- 400Device configuredKernel-PnPEnglischKernel-PnP event 400 is logged when a device is configured with a driver: instance ID, driver INF and class. Dates USB storage and other device connections.
- 410Device startedKernel-PnPEnglischKernel-PnP event 410 is logged when a device is started with its driver and service. Dates USB storage connections, including repeat ones.
- 8001Outgoing authentication auditNTLMEnglischNTLM event 8001 logs outgoing NTLM authentication from this computer: target server, supplied user and client process. Shows which apps still use NTLM.
- 8002Incoming authentication auditNTLMEnglischNTLM event 8002 logs incoming NTLM authentication processed by this server, with the calling process and its identity. Maps which servers still accept NTLM.
- 8003Domain server authentication auditNTLMEnglischNTLM event 8003 logs NTLM authentication of a domain account received by this server: user, domain, client workstation, logon type and process. Audit only.
- 8004Domain controller authentication auditNTLMEnglischNTLM event 8004 is logged on domain controllers for each NTLM authentication they validate: user, client workstation and the server that forwarded it.
- 3033Image blocked (signing level)Code IntegrityEnglischCode Integrity event 3033: a process tried to load a DLL or driver below its required signing level and was blocked. Seen with LSA protection.
- 3077App Control (WDAC) blockCode IntegrityEnglischCode Integrity event 3077 is the main App Control for Business (WDAC) enforcement block: a file failed the active policy and was prevented from loading.
- 31001Logon failureSMB ClientEnglischSMB client event 31001 records a failed authentication from this computer to an SMB server, with server name, user name, SPN and error codes. Source-side view.
- 551SMB session auth failureSMB ServerEnglischSMB server event 551 records a failed SMB session authentication, with client address, user name and status code. Complements 4625 for SMB brute force.
- 307Document printedPrintServiceEnglischPrintService event 307 logs each printed job: document, user, client, printer, size and pages. Off by default; key for insider print exfiltration.
- 808Spooler plug-in load failedPrintServiceEnglischPrintService Admin event 808: the spooler failed to load a plug-in or driver DLL. Error 0x45A with an odd DLL path is a PrintNightmare sign.
- 3006DNS query startedDNS ClientEnglischDNS Client event 3006 records the start of a DNS query on the host: queried name, record type and DNS servers. Channel is off by default; pair it with 3008.
- 3008DNS query completedDNS ClientEnglischDNS Client event 3008 records a completed DNS query: name, type, status code and resolved addresses. Host-level DNS history; channel is off by default.
- 4sshd informational messageOpenSSHEnglischOpenSSH event 4 carries informational sshd messages on Windows: accepted and failed logons, invalid users and disconnects, with source IP and port in the text.