Enciclopedia de Event ID de Windows
237 eventos de Windows explicados para analistas DFIR y SOC: qué significa cada uno, qué directiva de auditoría lo genera, los campos importantes, cómo lo provocan los atacantes y qué reglas SigmaHQ lo detectan.
237 eventos
- 1100Event logging service shut downSecurityInglésSecurity event 1100 marks the Windows Event Log service stopping, normally at shutdown. Outside a reboot it can mean logging was stopped on purpose.
- 1102Registro de Seguridad borradoSecurityEl evento 1102 se genera cuando se borra el registro de Seguridad e indica la cuenta que lo hizo. Raro en operación normal y señal clásica de antiforense.
- 1104Security log fullSecurityInglésSecurity event 1104 means the Security log reached its maximum size and is set not to overwrite, so new audit events can no longer be written.
- 4608Windows starting upSecurityInglésSecurity event 4608 is logged when LSASS starts and auditing initializes during boot. Use it to mark system startups on the Security log timeline.
- 4616System time changedSecurityInglésSecurity event 4616 records a system clock change with old and new time, account and process. Routine time sync is normal; manual jumps skew timelines.
- 4624Inicio de sesión correctoSecurityEl evento 4624 registra cada inicio de sesión correcto: quién, cómo (LogonType), desde dónde (IpAddress) y con qué paquete. La base del análisis.
- 4625Inicio de sesión fallidoSecurityEl evento 4625 se registra al fallar un inicio de sesión. Status y SubStatus dan el motivo: contraseña errónea, usuario inexistente o cuenta bloqueada.
- 4634Cierre de sesiónSecurityEl evento 4634 marca el fin de una sesión. Relacione su TargetLogonId con un 4624 para medir cuánto duró la sesión.
- 4647User-initiated logoffSecurityInglésEvent 4647 is logged when a user actively signs out of an interactive or RDP session, before the session teardown event 4634.
- 4648Inicio con credenciales explícitasSecurityEl evento 4648 se registra en el host de origen cuando un proceso usa credenciales proporcionadas explícitamente, como runas, net use /user o PsExec -u.
- 4656Object handle requestedSecurityInglésSecurity event 4656 logs a request for a handle to an audited file, registry key or kernel object, with the access asked for and whether it was granted.
- 4657Registry value modifiedSecurityInglésSecurity event 4657 records a created, changed or deleted registry value on an audited key, with old and new data and the process that made the change.
- 4658Object handle closedSecurityInglésSecurity event 4658 marks the closing of a handle to an audited object. Pair it with 4656 by HandleId to measure how long the object was open.
- 4660Object deletedSecurityInglésSecurity event 4660 confirms that an audited file, registry key or kernel object was deleted. It has no object name, so join it to 4663 by HandleId.
- 4661SAM or AD handle requestedSecurityInglésSecurity event 4661 logs a handle request on a SAM or Active Directory object. On DCs it exposes SAMR enumeration of users and groups such as Domain Admins.
- 4662AD object operationSecurityInglésSecurity event 4662 logs an operation on an Active Directory object. With the replication rights GUIDs in Properties, it is the classic DCSync detection.
- 4663Acceso a objetoSecurityEl evento 4663 registra un derecho de acceso realmente usado sobre un archivo, carpeta, clave de registro u objeto auditado: quién, qué proceso y qué acceso.
- 4670Object permissions changedSecurityInglésSecurity event 4670 records a change to an object's permissions (DACL or owner), with old and new security descriptors in SDDL and the process responsible.
- 4672Privilegios especiales asignadosSecurityEl evento 4672 sigue a un 4624 cuando la nueva sesión tiene privilegios sensibles como SeDebug o SeTcb; marca los inicios de sesión de administrador.
- 4673Privileged service calledSecurityInglésSecurity event 4673 logs a call to a privileged system service, such as registering a logon process with SeTcbPrivilege, and whether the call succeeded.
- 4688Creación de procesoSecurityEl evento 4688 registra cada nuevo proceso: ejecutable, padre, cuenta, elevación y, si se habilita, la línea de comandos completa. Desactivado por defecto.
- 4689Process exitedSecurityInglésSecurity event 4689 logs a process exit with its PID, path, account and exit code. Pair it with 4688 to get how long a process ran. Off by default.
- 4697Servicio instaladoSecurityEl evento 4697 registra un nuevo servicio con su nombre, ruta del binario, tipo de inicio y cuenta. Clave para movimiento lateral tipo PsExec y persistencia.
- 4698Tarea programada creadaSecurityEl evento 4698 registra una nueva tarea programada con su XML completo: comando, argumentos, cuenta y desencadenadores. Señal clave de persistencia.
- 4699Scheduled task deletedSecurityInglésSecurity event 4699 records a deleted scheduled task, including its last XML definition. Quick create-then-delete pairs point to remote execution.
- 4700Scheduled task enabledSecurityInglésSecurity event 4700 records a scheduled task being enabled, with its XML definition. Watch for dormant or attacker-created tasks switched back on.
- 4701Scheduled task disabledSecurityInglésSecurity event 4701 records a scheduled task being disabled, with its XML. Disabling security, backup or update tasks can be part of defense evasion.
- 4702Scheduled task updatedSecurityInglésSecurity event 4702 records a modified scheduled task with its new XML definition. Look for changed actions or run-as accounts on existing tasks.
- 4703Token right adjustedSecurityInglésSecurity event 4703 logs privileges being enabled or disabled in an access token, such as a process turning on SeDebugPrivilege before touching LSASS.
- 4704User right assignedSecurityInglésSecurity event 4704 logs a user right (privilege) being assigned to an account or group in local security policy, such as SeDebugPrivilege or SeBackupPrivilege.
- 4705User right removedSecurityInglésSecurity event 4705 logs a user right (privilege) being removed from an account or group in local security policy. Mirror of event 4704.
- 4713Kerberos policy changedSecurityInglésSecurity event 4713 is logged on domain controllers when the domain Kerberos policy (ticket lifetimes, renewal, clock skew) is changed.
- 4717Logon right grantedSecurityInglésSecurity event 4717 logs a logon right (e.g. SeRemoteInteractiveLogonRight, SeServiceLogonRight) being granted to an account or group in local security policy.
- 4718Logon right removedSecurityInglésSecurity event 4718 logs a logon right (such as a Deny logon right or RDP logon right) being removed from an account or group in local security policy.
- 4719Directiva de auditoría cambiadaSecurityEl evento 4719 registra un cambio en la directiva de auditoría del sistema, como quitar con auditpol la auditoría de éxito o error de una subcategoría.
- 4720Cuenta de usuario creadaSecurityEl evento 4720 registra la creación de una cuenta de usuario local o de dominio: quién la creó, el nuevo nombre y SID, y sus atributos iniciales.
- 4722Cuenta de usuario habilitadaSecurityEl evento 4722 se registra cuando se habilita una cuenta de usuario o de equipo. Indica quién la habilitó y qué cuenta, identificada por nombre y SID.
- 4723Password change attemptSecurityInglésSecurity event 4723 is logged when an account attempts to change its own password (knowing the old one). Failure means the new password was rejected.
- 4724Intento de restablecer contraseñaSecurityEl evento 4724 se registra cuando una cuenta restablece la contraseña de otra sin conocer la anterior; una acción administrativa que conviene revisar.
- 4725User account disabledSecurityInglésSecurity event 4725 is logged when a user or computer account is disabled, recording who disabled it and which account was affected.
- 4726Cuenta de usuario eliminadaSecurityEl evento 4726 se registra cuando se elimina una cuenta de usuario local o de dominio, con el sujeto que la eliminó y el nombre y SID de la cuenta.
- 4727Global group createdSecurityInglésSecurity event 4727 is logged on a domain controller when a new security-enabled global group is created in Active Directory.
- 4728Miembro añadido a grupo globalSecurityEl evento 4728 se registra en un controlador de dominio cuando se añade un miembro a un grupo global de seguridad, como Domain Admins.
- 4729Member removed from global groupSecurityInglésSecurity event 4729 is logged on a domain controller when a member is removed from a security-enabled global group, such as Domain Admins.
- 4730Global group deletedSecurityInglésSecurity event 4730 is logged on a domain controller when a security-enabled global group is deleted from Active Directory.
- 4731Local group createdSecurityInglésSecurity event 4731 is logged when a security-enabled local group is created — a local SAM group on a host, or a domain local group on a domain controller.
- 4732Miembro añadido a grupo localSecurityEl evento 4732 se registra cuando se añade un miembro a un grupo local de seguridad, como el grupo local Administradores o un grupo local de dominio.
- 4733Member removed from local groupSecurityInglésSecurity event 4733 is logged when a member is removed from a security-enabled local group, such as the local Administrators group or a domain local group.
- 4734Local group deletedSecurityInglésSecurity event 4734 is logged when a security-enabled local group is deleted — a local SAM group on a host, or a domain local group on a domain controller.
- 4735Local group changedSecurityInglésSecurity event 4735 is logged when a security-enabled local group is changed. It shows name or SID history changes; most instances accompany membership changes.
- 4737Global group changedSecurityInglésSecurity event 4737 is logged on a domain controller when a security-enabled global group is changed; most instances accompany membership changes.
- 4738Cuenta de usuario modificadaSecurityEl evento 4738 se registra al modificar una cuenta de usuario. Los atributos cambiados llevan su nuevo valor, incluidos indicadores como delegación o preauth.
- 4739Domain policy changedSecurityInglésSecurity event 4739 logs a change to domain password, lockout or logoff policy, or to ms-DS-MachineAccountQuota. Only the changed values are filled in.
- 4740Cuenta bloqueadaSecurityEl evento 4740 se registra cuando una cuenta se bloquea tras demasiadas contraseñas erróneas. Indica la cuenta y el equipo llamador que lo provocó.
- 4741Computer account createdSecurityInglésSecurity event 4741 is logged on a domain controller when a computer account is created in Active Directory, e.g. by a domain join or a manual pre-creation.
- 4742Computer account changedSecurityInglésSecurity event 4742 is logged on a domain controller when a computer account is changed: password, SPNs, DNS name, delegation or account flags.
- 4743Computer account deletedSecurityInglésSecurity event 4743 is logged on a domain controller when a computer account is deleted from Active Directory, with who deleted it and the account's SID.
- 4754Universal group createdSecurityInglésSecurity event 4754 is logged on a domain controller when a new security-enabled universal group is created in Active Directory.
- 4755Universal group changedSecurityInglésSecurity event 4755 is logged on a domain controller when a security-enabled universal group is changed; most instances accompany membership changes.
- 4756Miembro añadido a grupo universalSecurityEl evento 4756 se registra en un controlador de dominio cuando se añade un miembro a un grupo universal de seguridad, como Enterprise Admins o Schema Admins.
- 4757Member removed from universal groupSecurityInglésSecurity event 4757 is logged on a domain controller when a member is removed from a security-enabled universal group, such as Enterprise Admins.
- 4765SID History addedSecurityInglésSecurity event 4765 is logged on a domain controller when SID History is added to an account — normal in migrations, a privilege escalation path otherwise.
- 4766SID History add failedSecurityInglésSecurity event 4766 is logged on a domain controller when an attempt to add SID History to an account fails — worth checking outside a migration project.
- 4767Account unlockedSecurityInglésSecurity event 4767 is logged when a locked-out user account is unlocked, recording who unlocked it and which account.
- 4768TGT de Kerberos solicitadoSecurityEl evento 4768 de controlador de dominio registra cada solicitud de TGT Kerberos: cuenta, IP del cliente, cifrado, tipo de preautenticación y resultado.
- 4769Ticket de servicio Kerberos pedidoSecurityEl evento 4769 se registra en los controladores de dominio por cada solicitud de ticket de servicio Kerberos (TGS); clave para detectar Kerberoasting.
- 4770Kerberos service ticket renewedSecurityInglésEvent 4770 is logged on domain controllers when a client renews an existing Kerberos service ticket instead of requesting a new one.
- 4771Fallo de preautenticación KerberosSecurityEl evento 4771 se registra en los controladores de dominio cuando falla la preautenticación Kerberos, casi siempre por una contraseña incorrecta (Status 0x18).
- 4776Validación de credenciales NTLMSecurityEl evento 4776 registra una comprobación de credenciales NTLM: en el controlador de dominio para cuentas de dominio y en la máquina local para cuentas locales.
- 4778Sesión reconectadaSecurityEl evento 4778 se registra cuando un usuario se reconecta a una sesión interactiva existente, normalmente una reconexión RDP o un cambio rápido de usuario.
- 4779Session disconnectedSecurityInglésEvent 4779 is logged when an interactive session is disconnected without logging off — an RDP window closed or a user switch.
- 4780AdminSDHolder ACL appliedSecurityInglésSecurity event 4780 is logged when SDProp resets the ACL of a protected admin account to match AdminSDHolder, revealing ACL changes on privileged accounts.
- 4781Account renamedSecurityInglésSecurity event 4781 is logged when the sAMAccountName of a user, computer or group is changed. It gives the old and new names with the account's SID.
- 4794DSRM password set attemptSecurityInglésSecurity event 4794 is logged on a domain controller when someone sets the DSRM administrator password. Rare, and abused for DC persistence.
- 4798User's local groups enumeratedSecurityInglésSecurity event 4798 logs a process listing which local groups a user belongs to, with the calling process. Mostly noise, but useful for spotting discovery.
- 4799Local group members enumeratedSecurityInglésSecurity event 4799 logs a process listing the members of a local group such as Administrators, with the caller process. Good signal for local admin discovery.
- 4800Workstation lockedSecurityInglésSecurity event 4800 records a user locking their workstation, with the account and logon session. Useful to tell when a user was really at the keyboard.
- 4801Workstation unlockedSecurityInglésSecurity event 4801 records a user unlocking their workstation, with the account and logon session. Pairs with 4800 to show when the user was present.
- 4826Boot configuration loadedSecurityInglésSecurity event 4826 records the Boot Configuration Data settings loaded at startup, such as test signing, integrity checks and kernel debugging.
- 4886Certificate request receivedSecurityInglésSecurity event 4886 is logged on an AD CS certification authority when it receives a certificate request, with the request ID and the requesting account.
- 4887Certificate issuedSecurityInglésSecurity event 4887 is logged on an AD CS certification authority when a certificate is issued: request ID, requester, subject and subject key identifier.
- 4907Object SACL changedSecurityInglésSecurity event 4907 logs a change to an object's auditing settings (SACL) on a file or registry key, with the old and new security descriptors.
- 4946Firewall rule addedSecurityInglésSecurity event 4946 records a Windows Firewall rule added locally, with its name, ID and profiles. Useful to catch attackers opening ports or allowing tools.
- 4947Firewall rule modifiedSecurityInglésSecurity event 4947 logs a local change to an existing Windows Firewall rule. Watch for rules enabled, widened or switched from block to allow.
- 4948Firewall rule deletedSecurityInglésSecurity event 4948 records the local deletion of a Windows Firewall rule. Useful to spot attackers removing block rules or cleaning up rules they added.
- 4964Special group logonSecurityInglésSecurity event 4964 flags a logon by a member of a group listed in the SpecialGroups registry value, e.g. Domain Admins. Only works once configured.
- 5136AD object modifiedSecurityInglésSecurity event 5136 logs an attribute change on an Active Directory object, with the attribute and value — GPO edits, SPNs, ACLs, shadow credentials.
- 5137AD object createdSecurityInglésSecurity event 5137 logs the creation of an Active Directory object — user, computer, group, GPO or any other class — with its DN, class and creator.
- 5140Acceso a recurso compartidoSecurityEl evento 5140 registra el primer acceso a un recurso compartido en una sesión SMB: cuenta, IP de origen y recurso. Clave para seguir C$, ADMIN$ e IPC$.
- 5141AD object deletedSecurityInglésSecurity event 5141 logs the deletion of an Active Directory object, with its DN, class, the account responsible and whether a subtree delete was used.
- 5142Network share addedSecurityInglésSecurity event 5142 records a new network share: who created it, its name and local path. Watch for shares exposing drives or staging folders.
- 5144Network share deletedSecurityInglésSecurity event 5144 records the removal of a network share, with the account that deleted it and the share's name and path. Often a cleanup step.
- 5145Comprobación de acceso a recursoSecurityEl evento 5145 registra cada archivo, carpeta o canalización con nombre abiertos vía recurso compartido, con cuenta, IP y derechos. Detallado y ruidoso.
- 5156WFP connection allowedSecurityInglésSecurity event 5156 logs each connection allowed by the Windows Filtering Platform: process, direction, addresses, ports and protocol.
- 5157WFP connection blockedSecurityInglésSecurity event 5157 logs each connection blocked by the Windows Filtering Platform, with process, direction, addresses and ports. Reveals scans and blocked C2.
- 5376Credential Manager backupSecurityInglésSecurity event 5376 records a backup of a user's Credential Manager vault. Rarely used by real users, so worth checking every time.
- 5377Credential Manager restoreSecurityInglésSecurity event 5377 records Credential Manager credentials restored from a backup file into a user's vault. Rare; confirm each one.
- 6416External device recognizedSecurityInglésSecurity event 6416 records a new device recognized by Windows, such as a USB drive, with device ID, class and vendor IDs. Needs Audit PNP Activity.
- 12Operating system startedSystemInglésSystem event 12 (Kernel-General) marks an operating system boot and records the exact kernel start time and OS build. The anchor for every boot timeline.
- 13Operating system shutdownSystemInglésSystem event 13 (Kernel-General) is written on a clean shutdown with the exact stop time. No 13 before a boot means a crash or power loss.
- 41Unclean reboot (Kernel-Power)SystemInglésSystem event 41 (Kernel-Power) is logged at boot when the previous session ended without a clean shutdown: crash, hang, power loss or forced reset.
- 104Registro de eventos borradoSystemEl evento 104 de System registra que se borró un registro de eventos (System, Application, Sysmon, PowerShell...) y quién lo hizo. Para Seguridad es el 1102.
- 1014DNS resolution timeoutSystemInglésSystem event 1014 (DNS Client) is logged when a name lookup timed out because none of the configured DNS servers answered. Mostly network noise.
- 1074Apagado o reinicio solicitadoSystemEl evento 1074 de System (User32) registra quién pidió un apagado o reinicio: proceso, usuario, código de motivo y comentario. Dice quién reinició el equipo.
- 5827Vulnerable Netlogon channel deniedSystemInglésSystem event 5827: a DC denied a machine account's Netlogon secure channel without secure RPC. Key Zerologon (CVE-2020-1472) signal.
- 6005Event Log service startedSystemInglésSystem event 6005 is written when the Event Log service starts, which in practice means at every boot. A simple, reliable startup marker next to event 12.
- 6006Event Log service stoppedSystemInglésSystem event 6006 is written when the Event Log service stops, normally at clean shutdown. Missing before a boot means a crash.
- 6008Unexpected shutdownSystemInglésSystem event 6008 is logged at boot when the previous shutdown was unexpected, with the approximate local time the system went down. Pairs with Kernel-Power 41.
- 6013Uptime reportSystemInglésSystem event 6013 reports the system uptime in seconds and the time zone, at boot and once a day. Helps spot reboots and log gaps.
- 7000Service failed to startSystemInglésSystem event 7000 is logged when a service fails to start, with the error. Often follows a malicious 7045 whose payload is not a real service binary.
- 7009Service start timeoutSystemInglésSystem event 7009: a service did not report to the SCM within the timeout (30 s by default). Common with command-based malicious services.
- 7031Service crashed (recovery action)SystemInglésSystem event 7031: a service terminated unexpectedly and the SCM will apply a recovery action. Can reveal security tools being killed.
- 7034Service crashedSystemInglésSystem event 7034: a service process ended unexpectedly with no recovery action configured. Crashes, or security services being killed.
- 7036Cambio de estado de servicioSystemEl evento 7036 de System se registra cada vez que un servicio pasa a ejecución o se detiene. Muestra cuándo corrieron servicios y cuándo se pararon defensas.
- 7040Service start type changedSystemInglésSystem event 7040 records a change to a service start type (auto, demand, disabled). Reveals security tools being disabled and services turned into persistence.
- 7045Servicio instaladoSystemEl evento 7045 de System registra cada nuevo servicio o controlador: nombre, ruta del binario, tipo de inicio y cuenta. Gran señal de movimiento lateral.
- 20001Device driver installedSystemInglésSystem event 20001 (UserPnp) records a device driver install with the device instance ID. First-connection evidence for USB storage.
- 1000Application crashApplicationInglésApplication event 1000 records a process crash: application, faulting module, exception code and offset. Exposes exploits and killed tools.
- 1001Windows Error Reporting reportApplicationInglésApplication event 1001 records a Windows Error Reporting report (APPCRASH, BEX, BlueScreen...) and its report folder. Complements 1000.
- 1033MSI product installedApplicationInglésApplication event 1033 (MsiInstaller) records an MSI package installation: product name, version, manufacturer and result, with the installing user's SID.
- 11707MSI installation succeededApplicationInglésApplication event 11707 (MsiInstaller) confirms that an MSI product installation completed successfully, with the product name and the installing user's SID.
- 18456SQL Server login failedApplicationInglésApplication event 18456 from SQL Server logs a failed database login with user, reason and client IP. Brute force against MSSQL.
- 1Creación de procesoSysmonEl evento 1 de Sysmon registra cada nuevo proceso con línea de comandos, hashes, padre y un ProcessGuid para correlacionar. La base del hunting en endpoints.
- 2File creation time changedSysmonInglésSysmon event 2 fires when a process explicitly changes a file's creation timestamp — the classic trace of timestomping, but also common in installers.
- 3Conexión de redSysmonEl evento 3 de Sysmon vincula cada conexión TCP/UDP con el proceso que la hizo: origen, destino, puertos y ProcessGuid. Clave para C2 y movimiento lateral.
- 4Service state changedSysmonInglésSysmon event 4 reports the Sysmon service starting or stopping. An unexpected stop outside maintenance can mean someone is blinding endpoint telemetry.
- 5Process terminatedSysmonInglésSysmon event 5 records a process exiting, with ProcessGuid and image path. Pairs with event 1 to measure lifetime and close out process timelines.
- 6Driver loadedSysmonInglésSysmon event 6 logs a kernel driver being loaded, with hashes and signature details. Rare and high-impact: watch for vulnerable or unsigned drivers.
- 7Image (DLL) loadedSysmonInglésSysmon event 7 logs a DLL or other module loaded into a process, with hashes and signature. Used to catch DLL side-loading and unusual module loads.
- 8Remote thread createdSysmonInglésSysmon event 8 fires when a process creates a thread in another process — a classic code injection technique. Low volume, high signal.
- 9Raw disk access readSysmonInglésSysmon event 9 logs a process reading a drive directly through the \\.\ device path, used to copy locked files such as NTDS.dit or SAM without file APIs.
- 10Acceso a procesoSysmonEl evento 10 de Sysmon registra la apertura de un handle de un proceso a otro, con máscara de acceso y pila de llamadas. El evento clave para LSASS.
- 11Archivo creadoSysmonEl evento 11 de Sysmon registra la creación o sobrescritura de un archivo y el proceso que lo escribió. Clave para payloads, persistencia y volcados.
- 12Registry key created or deletedSysmonInglésSysmon event 12 logs registry keys and values being created or deleted, with the process responsible. Watch autostart keys, services and COM entries.
- 13Valor de registro establecidoSysmonEl evento 13 de Sysmon registra la escritura de un valor del registro, con los datos de los valores DWORD, QWORD y de cadena. El evento clave de persistencia.
- 14Registry key or value renamedSysmonInglésSysmon event 14 logs a registry key or value being renamed, with the old path and the new name. Rare, and occasionally used to hide or stage persistence.
- 15Alternate data stream createdSysmonInglésSysmon event 15 logs a named NTFS stream being created, such as the Zone.Identifier mark of the web on downloads. Reveals download origins and ADS use.
- 16Configuration changedSysmonInglésSysmon event 16 records a change to the Sysmon configuration, with the config file and its hash. An unexpected change may be an attempt to blind monitoring.
- 17Named pipe createdSysmonInglésSysmon event 17 logs a named pipe being created and the process behind it. Known pipe names reveal PsExec, C2 frameworks and other lateral movement tools.
- 18Named pipe connectedSysmonInglésSysmon event 18 logs a client connecting to a named pipe. Paired with event 17 it shows who talks over a pipe — useful for PsExec and C2 pivots.
- 19WMI event filter registeredSysmonInglésSysmon event 19 logs a WMI event filter being registered, with namespace, name and WQL query. The first of three events behind WMI subscription persistence.
- 20WMI event consumer registeredSysmonInglésSysmon event 20 logs a WMI event consumer being registered, including the command or script it runs. The action half of WMI subscription persistence.
- 21WMI consumer bound to filterSysmonInglésSysmon event 21 logs a WMI consumer being bound to a filter, the step that activates a permanent WMI subscription. Completes the WMI persistence trio.
- 22Consulta DNSSysmonEl evento 22 de Sysmon registra una consulta DNS de un proceso, con nombre, estado y respuestas. Vincula dominios y procesos para cazar C2, túneles y phishing.
- 23File deleted (archived)SysmonInglésSysmon event 23 logs a file deletion and saves a copy of the deleted file in the archive folder. Recovers payloads and tools attackers delete after use.
- 24Clipboard content changedSysmonInglésSysmon event 24 records a change to clipboard contents, with process, session and hash; contents can be archived. Useful for RDP copy-paste investigations.
- 25Process tampering detectedSysmonInglésSysmon event 25 fires when a process image is changed in memory or on disk, as in process hollowing or herpaderping. Rare and high-signal.
- 26File deleted (logged)SysmonInglésSysmon event 26 logs a file deletion with the deleting process and hashes but, unlike event 23, does not keep a copy. A low-cost way to track deletions.
- 27Executable file blockedSysmonInglésSysmon event 27 fires when Sysmon blocks the creation of an executable (PE) file matching its rules. A preventive control added in Sysmon 14.0.
- 28File shredding blockedSysmonInglésSysmon event 28 fires when Sysmon blocks a file-shredding attempt, such as SDelete overwriting a file before deleting it. Added in Sysmon 14.1.
- 29Executable file detectedSysmonInglésSysmon event 29 logs the creation of a new executable (PE) file, with hashes, without blocking it. Added in Sysmon 15.0; ideal for tracking dropped binaries.
- 255ErrorSysmonInglésSysmon event 255 reports an internal Sysmon error, such as events dropped under load or a failed operation. Signals gaps in telemetry and possible tampering.
- 4103Registro de módulosPowerShell OperationalEl evento 4103 de PowerShell (registro de módulos) registra la ejecución de la canalización: cada comando invocado, con sus parámetros y el contexto del host.
- 4104Registro de bloques de scriptPowerShell OperationalEl evento 4104 de PowerShell registra el texto de los bloques de script ejecutados, ya decodificado: el registro más completo de lo que ejecutó PowerShell.
- 4105Script block invocation startedPowerShell OperationalInglésPowerShell event 4105 marks the start of a script block's execution; with 4106 it gives run times for blocks logged by 4104.
- 4106Script block invocation completedPowerShell OperationalInglésPowerShell event 4106 marks the end of a script block's execution, paired with 4105 by ScriptBlockId when invocation logging is enabled.
- 40961Console startingPowerShell OperationalInglésPowerShell event 40961 is logged when a PowerShell host starts, giving a timestamp for each PowerShell launch even without script logging.
- 40962Console ready for inputPowerShell OperationalInglésPowerShell event 40962 follows 40961 when the PowerShell host is ready for input — another default-logged marker of PowerShell use.
- 400Engine startedWindows PowerShellInglésWindows PowerShell event 400 logs every engine start with HostApplication (the command line) and EngineVersion — key to spot PowerShell v2 downgrades.
- 403Engine stoppedWindows PowerShellInglésWindows PowerShell event 403 logs when a PowerShell engine stops; paired with 400 it bounds a PowerShell session in time.
- 600Provider startedWindows PowerShellInglésWindows PowerShell event 600 is logged as each provider (Registry, FileSystem, Variable…) starts in a new session, repeating HostApplication.
- 800Pipeline execution detailsWindows PowerShellInglésWindows PowerShell event 800 records pipeline execution details (commands and parameters) when module logging is enabled.
- 100Task startedTask SchedulerInglésTask Scheduler event 100 marks the start of a task instance: task path, run-as user and an instance GUID that links the launch, actions and completion.
- 102Task completedTask SchedulerInglésTask Scheduler event 102 marks the end of a task instance. With event 100 it bounds how long a task ran; the action's return code is in event 201.
- 106Task registeredTask SchedulerInglésTask Scheduler event 106 records that a user registered a new scheduled task: the task path and the account that created it. Key for persistence hunting.
- 129Task process createdTask SchedulerInglésTask Scheduler event 129 records the process created for a task: task path, image path and process ID — the link to process creation logs.
- 140Task updatedTask SchedulerInglésTask Scheduler event 140 records that a user updated an existing scheduled task. Watch for built-in or trusted tasks being modified to run a payload.
- 141Task deletedTask SchedulerInglésTask Scheduler event 141 records that a user deleted a scheduled task. Right after 106 and a run, it points to one-shot remote execution or cleanup.
- 142Task disabledTask SchedulerInglésTask Scheduler event 142 records that a user disabled a scheduled task — relevant when security, update or backup tasks are switched off.
- 200Action startedTask SchedulerInglésTask Scheduler event 200 records that a task action was launched: which task, which instance and the action itself — often the program path that ran.
- 201Action completedTask SchedulerInglésTask Scheduler event 201 records that a task action completed, with the action and its return code — tells you whether the launched program succeeded.
- 21Inicio de sesión correctoRDP LocalSessionManagerEl evento RDP 21 confirma un inicio de sesión en el destino: usuario, ID de sesión y dirección de red de origen ("LOCAL" para los inicios de sesión en consola).
- 22Shell startRDP LocalSessionManagerInglésRDP event 22 is logged when the user's shell (Explorer) starts in a new session, right after the session logon event 21.
- 23Session logoffRDP LocalSessionManagerInglésRDP event 23 is logged when a Remote Desktop or console session is logged off, closing the session opened by event 21.
- 24Sesión desconectadaRDP LocalSessionManagerEl evento RDP 24 se registra cuando una sesión de Escritorio remoto se desconecta sin cerrar sesión, con el usuario, el ID de sesión y la dirección del cliente.
- 25Sesión reconectadaRDP LocalSessionManagerEl evento RDP 25 se registra cuando un usuario se reconecta a una sesión desconectada existente, con la nueva dirección del cliente.
- 39Session disconnected by another sessionRDP LocalSessionManagerInglésRDP event 39 records that one session was disconnected by another session, as with a session takeover or tscon.
- 40Session disconnect reasonRDP LocalSessionManagerInglésRDP event 40 gives the reason code for a session disconnect, telling user-initiated disconnects from replaced connections.
- 1149Conexión autenticadaRDP RemoteConnectionManagerEl evento RDP 1149 registra una conexión entrante de Escritorio remoto con usuario, dominio e IP de origen. Prueba la conexión de red, no el inicio de sesión.
- 1024Outbound connection attemptRDP ClientInglésRDP client event 1024 is logged on the source host when mstsc starts connecting to a server; the Value field holds the target name or IP.
- 1102Multi-transport connectionRDP ClientInglésRDP client event 1102 is logged on the source host when the client opens a multi-transport connection; Value holds the server IP address.
- 131TCP connection acceptedRDP RdpCoreTSInglésRdpCoreTS event 131 is logged when the RDP server accepts a TCP connection, with the client IP and port — even for failed or scanner connections.
- 5857Provider startedWMI-ActivityInglésWMI-Activity event 5857 logs a WMI provider being loaded: provider name, DLL path and host process. Useful to spot rogue providers and WMI usage.
- 5858Operation errorWMI-ActivityInglésWMI-Activity event 5858 logs a failed WMI operation with the client machine, user, process ID and the query or method that failed. Noisy but revealing.
- 5860Temporary event consumerWMI-ActivityInglésWMI-Activity event 5860 logs a temporary WMI event subscription: the namespace, the WQL notification query and the client process that registered it.
- 5861Permanent event consumerWMI-ActivityInglésWMI-Activity event 5861 logs a permanent WMI event subscription (filter-to-consumer binding), the classic fileless persistence technique.
- 1006Malware found by scanMicrosoft DefenderInglésDefender event 1006 is logged when the antimalware engine finds malware or unwanted software, with threat name, path and detection source.
- 1007Action taken (engine)Microsoft DefenderInglésDefender event 1007 records that the antimalware platform took action on detected malware, the engine-level counterpart of event 1117.
- 1008Engine action failedMicrosoft DefenderInglésDefender event 1008 means Defender could not complete an action on detected malware (engine level); the item may still be on the system.
- 1013Detection history deletedMicrosoft DefenderInglésDefender event 1013 is logged when Defender's malware detection history is deleted — routine purging, or an attempt to hide past detections.
- 1015Suspicious behavior detectedMicrosoft DefenderInglésDefender event 1015 is logged when behavior monitoring detects suspicious activity rather than a known file, with threat name and process details.
- 1116Malware detectedMicrosoft DefenderInglésDefender event 1116 is logged when Microsoft Defender Antivirus detects malware or unwanted software: threat name, file path, process and user.
- 1117Action taken on malwareMicrosoft DefenderInglésDefender event 1117 confirms Microsoft Defender Antivirus acted on a detection — quarantine, remove, clean or block — with threat, path and action.
- 1118Action on malware failedMicrosoft DefenderInglésDefender event 1118 means Microsoft Defender Antivirus detected a threat but could not remediate it (non-critical failure) — the item may still be present.
- 1119Critical failure acting on malwareMicrosoft DefenderInglésDefender event 1119 records a critical error while acting on a detected threat — remediation failed and the threat may still be active.
- 1121ASR rule blocked an operationMicrosoft DefenderInglésDefender event 1121 is logged when an attack surface reduction (ASR) rule in block mode stops an operation, such as LSASS access or Office child processes.
- 2001Security intelligence update failedMicrosoft DefenderInglésDefender event 2001 is logged when a security intelligence (signature) update fails, with the versions, update source and error.
- 5000Real-time protection enabledMicrosoft DefenderInglésDefender event 5000 is logged when real-time protection is turned on — the counterpart of 5001, useful to measure how long protection was off.
- 5001Real-time protection disabledMicrosoft DefenderInglésDefender event 5001 is logged when real-time protection is turned off — a classic step before attackers drop tools or ransomware.
- 5004Real-time protection config changedMicrosoft DefenderInglésDefender event 5004 is logged when a real-time protection feature (on-access, behavior monitoring, downloads scanning…) changes configuration.
- 5007Configuration changedMicrosoft DefenderInglésDefender event 5007 logs every Defender configuration change with old and new values — including exclusions added by attackers.
- 5010Malware scanning disabledMicrosoft DefenderInglésDefender event 5010 is logged when scanning for malware and potentially unwanted software is disabled — a sign of defense tampering or another AV.
- 5012Virus scanning disabledMicrosoft DefenderInglésDefender event 5012 is logged when Defender virus scanning is disabled — like 5010, a strong tampering signal unless another antivirus took over.
- 5013Tamper protection blocked a changeMicrosoft DefenderInglésDefender event 5013 is logged when tamper protection blocks a change to Defender settings — evidence that something tried to weaken the antivirus.
- 3Job createdBITS ClientInglésBITS event 3 records the creation of a BITS transfer job: job title, job ID, owner and, on newer builds, the process that created it.
- 4Job completedBITS ClientInglésBITS event 4 records that a BITS transfer job completed: job title, ID, owner, file count and bytes transferred. Confirms a download or upload finished.
- 59Transfer startedBITS ClientInglésBITS event 59 records that BITS started transferring a job, with the job name and the remote URL — the event that tells you where BITS was downloading from.
- 60Transfer stoppedBITS ClientInglésBITS event 60 records that BITS stopped transferring a job, with the job name, remote URL and status code — success, failure or interruption.
- 6WSMan session created (client)WinRMInglésWinRM event 6 is logged on the client when a WS-Management session is created, with the connection string naming the remote host. Source-side PS remoting.
- 91WSMan shell created (server)WinRMInglésWinRM event 91 is logged on the target when a remote WSMan shell is created, with the resource URI showing whether it is PowerShell remoting or winrs.
- 169User authenticated (legacy)WinRMInglésWinRM event 169 logs a user authenticating to the WinRM service and the mechanism used. It is defined only in Windows 7 / Server 2008 R2 era manifests.
- 8002EXE or DLL allowedAppLockerInglésAppLocker event 8002 records that an executable or DLL was allowed to run by an AppLocker rule, with the file path, matching rule and user SID.
- 8003EXE or DLL would be blocked (audit)AppLockerInglésAppLocker event 8003 records an executable or DLL that ran but would have been blocked if the policy were enforced. Audit-mode view of unapproved code.
- 8004EXE or DLL blockedAppLockerInglésAppLocker event 8004 records an executable or DLL blocked by an enforced AppLocker policy, with file path, signer, hash and the user who tried to run it.
- 8005MSI or script allowedAppLockerInglésAppLocker event 8005 records that a script or Windows Installer file was allowed to run by an AppLocker rule, with the file path, rule and user SID.
- 8006Script or MSI would be blockedAppLockerInglésAppLocker event 8006 records a script or MSI that ran but would have been blocked if the policy were enforced — audit-mode view of unapproved scripts.
- 8007MSI or script blockedAppLockerInglésAppLocker event 8007 records a script or Windows Installer file blocked by an enforced AppLocker policy, with the path, hash and user who tried to run it.
- 2004Rule addedWindows FirewallInglésFirewall event 2004 records a new Windows Firewall rule with its program, ports, action and the user and process that added it. On by default, richer than 4946.
- 2005Rule modifiedWindows FirewallInglésFirewall event 2005 records a change to an existing Windows Firewall rule, with the rule's new settings and the user and process that changed it. On by default.
- 2006Rule deletedWindows FirewallInglésFirewall event 2006 records the deletion of a Windows Firewall rule, with the rule ID, name, and the user SID and process that removed it. On by default.
- 2033All rules deletedWindows FirewallInglésFirewall event 2033 records that every rule was deleted from a Windows Firewall rule store, with the user SID and process responsible. Rare and worth reviewing.
- 1006Disk connected (partition data)PartitionInglésPartition event 1006 records a disk's vendor, model, serial, capacity and raw MBR/VBR bytes on connection. Rich USB evidence, incl. volume serials.
- 400Device configuredKernel-PnPInglésKernel-PnP event 400 is logged when a device is configured with a driver: instance ID, driver INF and class. Dates USB storage and other device connections.
- 410Device startedKernel-PnPInglésKernel-PnP event 410 is logged when a device is started with its driver and service. Dates USB storage connections, including repeat ones.
- 8001Outgoing authentication auditNTLMInglésNTLM event 8001 logs outgoing NTLM authentication from this computer: target server, supplied user and client process. Shows which apps still use NTLM.
- 8002Incoming authentication auditNTLMInglésNTLM event 8002 logs incoming NTLM authentication processed by this server, with the calling process and its identity. Maps which servers still accept NTLM.
- 8003Domain server authentication auditNTLMInglésNTLM event 8003 logs NTLM authentication of a domain account received by this server: user, domain, client workstation, logon type and process. Audit only.
- 8004Domain controller authentication auditNTLMInglésNTLM event 8004 is logged on domain controllers for each NTLM authentication they validate: user, client workstation and the server that forwarded it.
- 3033Image blocked (signing level)Code IntegrityInglésCode Integrity event 3033: a process tried to load a DLL or driver below its required signing level and was blocked. Seen with LSA protection.
- 3077App Control (WDAC) blockCode IntegrityInglésCode Integrity event 3077 is the main App Control for Business (WDAC) enforcement block: a file failed the active policy and was prevented from loading.
- 31001Logon failureSMB ClientInglésSMB client event 31001 records a failed authentication from this computer to an SMB server, with server name, user name, SPN and error codes. Source-side view.
- 551SMB session auth failureSMB ServerInglésSMB server event 551 records a failed SMB session authentication, with client address, user name and status code. Complements 4625 for SMB brute force.
- 307Document printedPrintServiceInglésPrintService event 307 logs each printed job: document, user, client, printer, size and pages. Off by default; key for insider print exfiltration.
- 808Spooler plug-in load failedPrintServiceInglésPrintService Admin event 808: the spooler failed to load a plug-in or driver DLL. Error 0x45A with an odd DLL path is a PrintNightmare sign.
- 3006DNS query startedDNS ClientInglésDNS Client event 3006 records the start of a DNS query on the host: queried name, record type and DNS servers. Channel is off by default; pair it with 3008.
- 3008DNS query completedDNS ClientInglésDNS Client event 3008 records a completed DNS query: name, type, status code and resolved addresses. Host-level DNS history; channel is off by default.
- 4sshd informational messageOpenSSHInglésOpenSSH event 4 carries informational sshd messages on Windows: accepted and failed logons, invalid users and disconnects, with source IP and port in the text.