Encyclopédie des Event ID Windows
237 événements Windows expliqués pour les analystes DFIR et SOC : leur signification, la stratégie d’audit qui les produit, les champs utiles, comment les attaquants les déclenchent et quelles règles SigmaHQ les détectent.
237 événements
- 1100Event logging service shut downSecurityAnglaisSecurity event 1100 marks the Windows Event Log service stopping, normally at shutdown. Outside a reboot it can mean logging was stopped on purpose.
- 1102Journal Sécurité effacéSecurityL'événement 1102 est écrit quand le journal Sécurité est effacé et nomme le compte responsable. Rare en exploitation, c'est un signe classique d'anti-forensic.
- 1104Security log fullSecurityAnglaisSecurity event 1104 means the Security log reached its maximum size and is set not to overwrite, so new audit events can no longer be written.
- 4608Windows starting upSecurityAnglaisSecurity event 4608 is logged when LSASS starts and auditing initializes during boot. Use it to mark system startups on the Security log timeline.
- 4616System time changedSecurityAnglaisSecurity event 4616 records a system clock change with old and new time, account and process. Routine time sync is normal; manual jumps skew timelines.
- 4624Ouverture de session réussieSecurityL'événement 4624 consigne chaque ouverture de session réussie : qui, comment (LogonType), d'où (IpAddress) et avec quel package. Le socle de l'analyse.
- 4625Échec d'ouverture de sessionSecurityL'événement 4625 consigne une tentative d'ouverture de session en échec. Status et SubStatus donnent la cause : mot de passe erroné, compte inconnu, verrouillé.
- 4634Fermeture de sessionSecurityL'événement 4634 marque la fin d'une session. Associez son TargetLogonId à un 4624 pour mesurer la durée de la session.
- 4647User-initiated logoffSecurityAnglaisEvent 4647 is logged when a user actively signs out of an interactive or RDP session, before the session teardown event 4634.
- 4648Identifiants explicitesSecurityL'événement 4648 est consigné sur l'hôte source quand un processus utilise des identifiants fournis explicitement : runas, net use /user ou PsExec -u.
- 4656Object handle requestedSecurityAnglaisSecurity event 4656 logs a request for a handle to an audited file, registry key or kernel object, with the access asked for and whether it was granted.
- 4657Registry value modifiedSecurityAnglaisSecurity event 4657 records a created, changed or deleted registry value on an audited key, with old and new data and the process that made the change.
- 4658Object handle closedSecurityAnglaisSecurity event 4658 marks the closing of a handle to an audited object. Pair it with 4656 by HandleId to measure how long the object was open.
- 4660Object deletedSecurityAnglaisSecurity event 4660 confirms that an audited file, registry key or kernel object was deleted. It has no object name, so join it to 4663 by HandleId.
- 4661SAM or AD handle requestedSecurityAnglaisSecurity event 4661 logs a handle request on a SAM or Active Directory object. On DCs it exposes SAMR enumeration of users and groups such as Domain Admins.
- 4662AD object operationSecurityAnglaisSecurity event 4662 logs an operation on an Active Directory object. With the replication rights GUIDs in Properties, it is the classic DCSync detection.
- 4663Accès à un objetSecurityL'événement 4663 consigne un droit d'accès réellement utilisé sur un fichier, dossier, clé de registre ou objet noyau audité : qui, quel processus, quel accès.
- 4670Object permissions changedSecurityAnglaisSecurity event 4670 records a change to an object's permissions (DACL or owner), with old and new security descriptors in SDDL and the process responsible.
- 4672Privilèges spéciaux attribuésSecurityL'événement 4672 suit un 4624 lorsque la nouvelle session détient des privilèges sensibles comme SeDebug ou SeTcb — marqueur des sessions administrateur.
- 4673Privileged service calledSecurityAnglaisSecurity event 4673 logs a call to a privileged system service, such as registering a logon process with SeTcbPrivilege, and whether the call succeeded.
- 4688Création de processusSecurityL'événement 4688 consigne chaque nouveau processus : exécutable, parent, compte, élévation et, si activée, la ligne de commande complète. Désactivé par défaut.
- 4689Process exitedSecurityAnglaisSecurity event 4689 logs a process exit with its PID, path, account and exit code. Pair it with 4688 to get how long a process ran. Off by default.
- 4697Service installéSecurityL'événement 4697 consigne un nouveau service Windows : nom, binaire, type de démarrage et compte. Clé pour le mouvement latéral type PsExec et la persistance.
- 4698Tâche planifiée crééeSecurityL'événement 4698 consigne une nouvelle tâche planifiée et son XML complet : commande, compte, déclencheurs. Signal clé de persistance et d'exécution distante.
- 4699Scheduled task deletedSecurityAnglaisSecurity event 4699 records a deleted scheduled task, including its last XML definition. Quick create-then-delete pairs point to remote execution.
- 4700Scheduled task enabledSecurityAnglaisSecurity event 4700 records a scheduled task being enabled, with its XML definition. Watch for dormant or attacker-created tasks switched back on.
- 4701Scheduled task disabledSecurityAnglaisSecurity event 4701 records a scheduled task being disabled, with its XML. Disabling security, backup or update tasks can be part of defense evasion.
- 4702Scheduled task updatedSecurityAnglaisSecurity event 4702 records a modified scheduled task with its new XML definition. Look for changed actions or run-as accounts on existing tasks.
- 4703Token right adjustedSecurityAnglaisSecurity event 4703 logs privileges being enabled or disabled in an access token, such as a process turning on SeDebugPrivilege before touching LSASS.
- 4704User right assignedSecurityAnglaisSecurity event 4704 logs a user right (privilege) being assigned to an account or group in local security policy, such as SeDebugPrivilege or SeBackupPrivilege.
- 4705User right removedSecurityAnglaisSecurity event 4705 logs a user right (privilege) being removed from an account or group in local security policy. Mirror of event 4704.
- 4713Kerberos policy changedSecurityAnglaisSecurity event 4713 is logged on domain controllers when the domain Kerberos policy (ticket lifetimes, renewal, clock skew) is changed.
- 4717Logon right grantedSecurityAnglaisSecurity event 4717 logs a logon right (e.g. SeRemoteInteractiveLogonRight, SeServiceLogonRight) being granted to an account or group in local security policy.
- 4718Logon right removedSecurityAnglaisSecurity event 4718 logs a logon right (such as a Deny logon right or RDP logon right) being removed from an account or group in local security policy.
- 4719Stratégie d'audit modifiéeSecurityL'événement 4719 consigne une modification de la stratégie d'audit système, par exemple l'audit des succès ou échecs retiré d'une sous-catégorie via auditpol.
- 4720Compte utilisateur crééSecurityL'événement 4720 consigne la création d'un compte utilisateur local ou de domaine : auteur, nom et SID du nouveau compte, et ses attributs initiaux.
- 4722Compte utilisateur activéSecurityL'événement 4722 est consigné quand un compte utilisateur ou ordinateur est activé. Il indique l'auteur et le compte concerné, par nom et SID.
- 4723Password change attemptSecurityAnglaisSecurity event 4723 is logged when an account attempts to change its own password (knowing the old one). Failure means the new password was rejected.
- 4724Réinitialisation de mot de passeSecurityL'événement 4724 est consigné quand un compte réinitialise le mot de passe d'un autre sans connaître l'ancien — une action d'administration à vérifier.
- 4725User account disabledSecurityAnglaisSecurity event 4725 is logged when a user or computer account is disabled, recording who disabled it and which account was affected.
- 4726Compte utilisateur suppriméSecurityL'événement 4726 est consigné à la suppression d'un compte utilisateur local ou de domaine, avec l'auteur de la suppression et le nom et SID du compte.
- 4727Global group createdSecurityAnglaisSecurity event 4727 is logged on a domain controller when a new security-enabled global group is created in Active Directory.
- 4728Ajout à un groupe globalSecurityL'événement 4728 est consigné sur un contrôleur de domaine quand un membre est ajouté à un groupe global de sécurité, comme Domain Admins.
- 4729Member removed from global groupSecurityAnglaisSecurity event 4729 is logged on a domain controller when a member is removed from a security-enabled global group, such as Domain Admins.
- 4730Global group deletedSecurityAnglaisSecurity event 4730 is logged on a domain controller when a security-enabled global group is deleted from Active Directory.
- 4731Local group createdSecurityAnglaisSecurity event 4731 is logged when a security-enabled local group is created — a local SAM group on a host, or a domain local group on a domain controller.
- 4732Ajout à un groupe localSecurityL'événement 4732 est consigné quand un membre est ajouté à un groupe local de sécurité, comme le groupe Administrateurs local ou un groupe local de domaine.
- 4733Member removed from local groupSecurityAnglaisSecurity event 4733 is logged when a member is removed from a security-enabled local group, such as the local Administrators group or a domain local group.
- 4734Local group deletedSecurityAnglaisSecurity event 4734 is logged when a security-enabled local group is deleted — a local SAM group on a host, or a domain local group on a domain controller.
- 4735Local group changedSecurityAnglaisSecurity event 4735 is logged when a security-enabled local group is changed. It shows name or SID history changes; most instances accompany membership changes.
- 4737Global group changedSecurityAnglaisSecurity event 4737 is logged on a domain controller when a security-enabled global group is changed; most instances accompany membership changes.
- 4738Compte utilisateur modifiéSecurityL'événement 4738 est consigné à la modification d'un compte utilisateur. Les attributs modifiés portent leur nouvelle valeur, y compris délégation ou pré-auth.
- 4739Domain policy changedSecurityAnglaisSecurity event 4739 logs a change to domain password, lockout or logoff policy, or to ms-DS-MachineAccountQuota. Only the changed values are filled in.
- 4740Compte verrouilléSecurityL'événement 4740 est consigné quand un compte est verrouillé après trop de mots de passe erronés. Il nomme le compte et l'ordinateur appelant à l'origine.
- 4741Computer account createdSecurityAnglaisSecurity event 4741 is logged on a domain controller when a computer account is created in Active Directory, e.g. by a domain join or a manual pre-creation.
- 4742Computer account changedSecurityAnglaisSecurity event 4742 is logged on a domain controller when a computer account is changed: password, SPNs, DNS name, delegation or account flags.
- 4743Computer account deletedSecurityAnglaisSecurity event 4743 is logged on a domain controller when a computer account is deleted from Active Directory, with who deleted it and the account's SID.
- 4754Universal group createdSecurityAnglaisSecurity event 4754 is logged on a domain controller when a new security-enabled universal group is created in Active Directory.
- 4755Universal group changedSecurityAnglaisSecurity event 4755 is logged on a domain controller when a security-enabled universal group is changed; most instances accompany membership changes.
- 4756Ajout à un groupe universelSecurityL'événement 4756 est consigné sur un contrôleur de domaine lors de l'ajout d'un membre à un groupe universel de sécurité (Enterprise Admins, Schema Admins).
- 4757Member removed from universal groupSecurityAnglaisSecurity event 4757 is logged on a domain controller when a member is removed from a security-enabled universal group, such as Enterprise Admins.
- 4765SID History addedSecurityAnglaisSecurity event 4765 is logged on a domain controller when SID History is added to an account — normal in migrations, a privilege escalation path otherwise.
- 4766SID History add failedSecurityAnglaisSecurity event 4766 is logged on a domain controller when an attempt to add SID History to an account fails — worth checking outside a migration project.
- 4767Account unlockedSecurityAnglaisSecurity event 4767 is logged when a locked-out user account is unlocked, recording who unlocked it and which account.
- 4768Demande de TGT KerberosSecurityL'événement 4768 consigne sur le contrôleur de domaine chaque demande de TGT Kerberos : compte, IP client, chiffrement, type de pré-authentification, résultat.
- 4769Ticket de service Kerberos demandéSecurityL'événement 4769 est consigné sur les contrôleurs de domaine à chaque demande de ticket de service Kerberos (TGS) — la trace clé du Kerberoasting.
- 4770Kerberos service ticket renewedSecurityAnglaisEvent 4770 is logged on domain controllers when a client renews an existing Kerberos service ticket instead of requesting a new one.
- 4771Échec de pré-auth KerberosSecurityL'événement 4771 est consigné sur les contrôleurs de domaine en cas d'échec de pré-authentification Kerberos, le plus souvent un mauvais mot de passe (0x18).
- 4776Validation d'identifiants NTLMSecurityL'événement 4776 consigne une vérification d'identifiants NTLM : sur le DC pour les comptes de domaine, sur la machine locale pour les comptes locaux.
- 4778Session reconnectéeSecurityL'événement 4778 est consigné lors d'une reconnexion à une session interactive existante, typiquement une reconnexion RDP ou un changement rapide d'utilisateur.
- 4779Session disconnectedSecurityAnglaisEvent 4779 is logged when an interactive session is disconnected without logging off — an RDP window closed or a user switch.
- 4780AdminSDHolder ACL appliedSecurityAnglaisSecurity event 4780 is logged when SDProp resets the ACL of a protected admin account to match AdminSDHolder, revealing ACL changes on privileged accounts.
- 4781Account renamedSecurityAnglaisSecurity event 4781 is logged when the sAMAccountName of a user, computer or group is changed. It gives the old and new names with the account's SID.
- 4794DSRM password set attemptSecurityAnglaisSecurity event 4794 is logged on a domain controller when someone sets the DSRM administrator password. Rare, and abused for DC persistence.
- 4798User's local groups enumeratedSecurityAnglaisSecurity event 4798 logs a process listing which local groups a user belongs to, with the calling process. Mostly noise, but useful for spotting discovery.
- 4799Local group members enumeratedSecurityAnglaisSecurity event 4799 logs a process listing the members of a local group such as Administrators, with the caller process. Good signal for local admin discovery.
- 4800Workstation lockedSecurityAnglaisSecurity event 4800 records a user locking their workstation, with the account and logon session. Useful to tell when a user was really at the keyboard.
- 4801Workstation unlockedSecurityAnglaisSecurity event 4801 records a user unlocking their workstation, with the account and logon session. Pairs with 4800 to show when the user was present.
- 4826Boot configuration loadedSecurityAnglaisSecurity event 4826 records the Boot Configuration Data settings loaded at startup, such as test signing, integrity checks and kernel debugging.
- 4886Certificate request receivedSecurityAnglaisSecurity event 4886 is logged on an AD CS certification authority when it receives a certificate request, with the request ID and the requesting account.
- 4887Certificate issuedSecurityAnglaisSecurity event 4887 is logged on an AD CS certification authority when a certificate is issued: request ID, requester, subject and subject key identifier.
- 4907Object SACL changedSecurityAnglaisSecurity event 4907 logs a change to an object's auditing settings (SACL) on a file or registry key, with the old and new security descriptors.
- 4946Firewall rule addedSecurityAnglaisSecurity event 4946 records a Windows Firewall rule added locally, with its name, ID and profiles. Useful to catch attackers opening ports or allowing tools.
- 4947Firewall rule modifiedSecurityAnglaisSecurity event 4947 logs a local change to an existing Windows Firewall rule. Watch for rules enabled, widened or switched from block to allow.
- 4948Firewall rule deletedSecurityAnglaisSecurity event 4948 records the local deletion of a Windows Firewall rule. Useful to spot attackers removing block rules or cleaning up rules they added.
- 4964Special group logonSecurityAnglaisSecurity event 4964 flags a logon by a member of a group listed in the SpecialGroups registry value, e.g. Domain Admins. Only works once configured.
- 5136AD object modifiedSecurityAnglaisSecurity event 5136 logs an attribute change on an Active Directory object, with the attribute and value — GPO edits, SPNs, ACLs, shadow credentials.
- 5137AD object createdSecurityAnglaisSecurity event 5137 logs the creation of an Active Directory object — user, computer, group, GPO or any other class — with its DN, class and creator.
- 5140Accès à un partage réseauSecurityL'événement 5140 consigne le premier accès à un partage réseau dans une session SMB : compte, IP source et partage. Clé pour suivre C$, ADMIN$ et IPC$.
- 5141AD object deletedSecurityAnglaisSecurity event 5141 logs the deletion of an Active Directory object, with its DN, class, the account responsible and whether a subtree delete was used.
- 5142Network share addedSecurityAnglaisSecurity event 5142 records a new network share: who created it, its name and local path. Watch for shares exposing drives or staging folders.
- 5144Network share deletedSecurityAnglaisSecurity event 5144 records the removal of a network share, with the account that deleted it and the share's name and path. Often a cleanup step.
- 5145Vérification d'accès à un partageSecurityL'événement 5145 consigne chaque fichier, dossier ou canal nommé accédé via un partage, avec compte, IP source et droits demandés. Détaillé et bruyant.
- 5156WFP connection allowedSecurityAnglaisSecurity event 5156 logs each connection allowed by the Windows Filtering Platform: process, direction, addresses, ports and protocol.
- 5157WFP connection blockedSecurityAnglaisSecurity event 5157 logs each connection blocked by the Windows Filtering Platform, with process, direction, addresses and ports. Reveals scans and blocked C2.
- 5376Credential Manager backupSecurityAnglaisSecurity event 5376 records a backup of a user's Credential Manager vault. Rarely used by real users, so worth checking every time.
- 5377Credential Manager restoreSecurityAnglaisSecurity event 5377 records Credential Manager credentials restored from a backup file into a user's vault. Rare; confirm each one.
- 6416External device recognizedSecurityAnglaisSecurity event 6416 records a new device recognized by Windows, such as a USB drive, with device ID, class and vendor IDs. Needs Audit PNP Activity.
- 12Operating system startedSystemAnglaisSystem event 12 (Kernel-General) marks an operating system boot and records the exact kernel start time and OS build. The anchor for every boot timeline.
- 13Operating system shutdownSystemAnglaisSystem event 13 (Kernel-General) is written on a clean shutdown with the exact stop time. No 13 before a boot means a crash or power loss.
- 41Unclean reboot (Kernel-Power)SystemAnglaisSystem event 41 (Kernel-Power) is logged at boot when the previous session ended without a clean shutdown: crash, hang, power loss or forced reset.
- 104Journal d'événements effacéSystemL'événement System 104 consigne l'effacement d'un journal (System, Application, Sysmon, PowerShell...) et son auteur. Pour le journal Sécurité, c'est le 1102.
- 1014DNS resolution timeoutSystemAnglaisSystem event 1014 (DNS Client) is logged when a name lookup timed out because none of the configured DNS servers answered. Mostly network noise.
- 1074Arrêt ou redémarrage demandéSystemL'événement System 1074 (User32) consigne l'auteur d'un arrêt ou redémarrage : processus, utilisateur, motif, commentaire. Qui a redémarré cette machine ?
- 5827Vulnerable Netlogon channel deniedSystemAnglaisSystem event 5827: a DC denied a machine account's Netlogon secure channel without secure RPC. Key Zerologon (CVE-2020-1472) signal.
- 6005Event Log service startedSystemAnglaisSystem event 6005 is written when the Event Log service starts, which in practice means at every boot. A simple, reliable startup marker next to event 12.
- 6006Event Log service stoppedSystemAnglaisSystem event 6006 is written when the Event Log service stops, normally at clean shutdown. Missing before a boot means a crash.
- 6008Unexpected shutdownSystemAnglaisSystem event 6008 is logged at boot when the previous shutdown was unexpected, with the approximate local time the system went down. Pairs with Kernel-Power 41.
- 6013Uptime reportSystemAnglaisSystem event 6013 reports the system uptime in seconds and the time zone, at boot and once a day. Helps spot reboots and log gaps.
- 7000Service failed to startSystemAnglaisSystem event 7000 is logged when a service fails to start, with the error. Often follows a malicious 7045 whose payload is not a real service binary.
- 7009Service start timeoutSystemAnglaisSystem event 7009: a service did not report to the SCM within the timeout (30 s by default). Common with command-based malicious services.
- 7031Service crashed (recovery action)SystemAnglaisSystem event 7031: a service terminated unexpectedly and the SCM will apply a recovery action. Can reveal security tools being killed.
- 7034Service crashedSystemAnglaisSystem event 7034: a service process ended unexpectedly with no recovery action configured. Crashes, or security services being killed.
- 7036Changement d'état de serviceSystemL'événement System 7036 consigne chaque démarrage ou arrêt de service : quand un service a tourné, quand sécurité ou journalisation ont été coupées.
- 7040Service start type changedSystemAnglaisSystem event 7040 records a change to a service start type (auto, demand, disabled). Reveals security tools being disabled and services turned into persistence.
- 7045Service installéSystemL'événement System 7045 consigne chaque nouveau service ou pilote : nom, binaire, type de démarrage et compte. Un signal majeur de mouvement latéral.
- 20001Device driver installedSystemAnglaisSystem event 20001 (UserPnp) records a device driver install with the device instance ID. First-connection evidence for USB storage.
- 1000Application crashApplicationAnglaisApplication event 1000 records a process crash: application, faulting module, exception code and offset. Exposes exploits and killed tools.
- 1001Windows Error Reporting reportApplicationAnglaisApplication event 1001 records a Windows Error Reporting report (APPCRASH, BEX, BlueScreen...) and its report folder. Complements 1000.
- 1033MSI product installedApplicationAnglaisApplication event 1033 (MsiInstaller) records an MSI package installation: product name, version, manufacturer and result, with the installing user's SID.
- 11707MSI installation succeededApplicationAnglaisApplication event 11707 (MsiInstaller) confirms that an MSI product installation completed successfully, with the product name and the installing user's SID.
- 18456SQL Server login failedApplicationAnglaisApplication event 18456 from SQL Server logs a failed database login with user, reason and client IP. Brute force against MSSQL.
- 1Création de processusSysmonL'événement Sysmon 1 consigne chaque nouveau processus : ligne de commande, hashs, parent et ProcessGuid pour la corrélation. La colonne vertébrale du hunting.
- 2File creation time changedSysmonAnglaisSysmon event 2 fires when a process explicitly changes a file's creation timestamp — the classic trace of timestomping, but also common in installers.
- 3Connexion réseauSysmonL'événement Sysmon 3 relie chaque connexion TCP/UDP au processus qui l'a établie : source, destination, ports et ProcessGuid. Clé pour le C2 et le latéral.
- 4Service state changedSysmonAnglaisSysmon event 4 reports the Sysmon service starting or stopping. An unexpected stop outside maintenance can mean someone is blinding endpoint telemetry.
- 5Process terminatedSysmonAnglaisSysmon event 5 records a process exiting, with ProcessGuid and image path. Pairs with event 1 to measure lifetime and close out process timelines.
- 6Driver loadedSysmonAnglaisSysmon event 6 logs a kernel driver being loaded, with hashes and signature details. Rare and high-impact: watch for vulnerable or unsigned drivers.
- 7Image (DLL) loadedSysmonAnglaisSysmon event 7 logs a DLL or other module loaded into a process, with hashes and signature. Used to catch DLL side-loading and unusual module loads.
- 8Remote thread createdSysmonAnglaisSysmon event 8 fires when a process creates a thread in another process — a classic code injection technique. Low volume, high signal.
- 9Raw disk access readSysmonAnglaisSysmon event 9 logs a process reading a drive directly through the \\.\ device path, used to copy locked files such as NTDS.dit or SAM without file APIs.
- 10Accès à un processusSysmonL'événement Sysmon 10 consigne l'ouverture d'un handle vers un autre processus, avec masque d'accès et pile d'appels. La référence pour le dump LSASS.
- 11Fichier crééSysmonL'événement Sysmon 11 consigne la création ou l'écrasement d'un fichier et le processus responsable. Clé pour les charges déposées, la persistance, les dumps.
- 12Registry key created or deletedSysmonAnglaisSysmon event 12 logs registry keys and values being created or deleted, with the process responsible. Watch autostart keys, services and COM entries.
- 13Valeur de registre définieSysmonL'événement Sysmon 13 consigne l'écriture d'une valeur de registre et sa donnée (DWORD, QWORD, chaîne). L'événement clé de la persistance registre.
- 14Registry key or value renamedSysmonAnglaisSysmon event 14 logs a registry key or value being renamed, with the old path and the new name. Rare, and occasionally used to hide or stage persistence.
- 15Alternate data stream createdSysmonAnglaisSysmon event 15 logs a named NTFS stream being created, such as the Zone.Identifier mark of the web on downloads. Reveals download origins and ADS use.
- 16Configuration changedSysmonAnglaisSysmon event 16 records a change to the Sysmon configuration, with the config file and its hash. An unexpected change may be an attempt to blind monitoring.
- 17Named pipe createdSysmonAnglaisSysmon event 17 logs a named pipe being created and the process behind it. Known pipe names reveal PsExec, C2 frameworks and other lateral movement tools.
- 18Named pipe connectedSysmonAnglaisSysmon event 18 logs a client connecting to a named pipe. Paired with event 17 it shows who talks over a pipe — useful for PsExec and C2 pivots.
- 19WMI event filter registeredSysmonAnglaisSysmon event 19 logs a WMI event filter being registered, with namespace, name and WQL query. The first of three events behind WMI subscription persistence.
- 20WMI event consumer registeredSysmonAnglaisSysmon event 20 logs a WMI event consumer being registered, including the command or script it runs. The action half of WMI subscription persistence.
- 21WMI consumer bound to filterSysmonAnglaisSysmon event 21 logs a WMI consumer being bound to a filter, the step that activates a permanent WMI subscription. Completes the WMI persistence trio.
- 22Requête DNSSysmonL'événement Sysmon 22 consigne une requête DNS d'un processus : nom, statut et réponses. Relie domaines et processus pour chasser C2, tunneling et phishing.
- 23File deleted (archived)SysmonAnglaisSysmon event 23 logs a file deletion and saves a copy of the deleted file in the archive folder. Recovers payloads and tools attackers delete after use.
- 24Clipboard content changedSysmonAnglaisSysmon event 24 records a change to clipboard contents, with process, session and hash; contents can be archived. Useful for RDP copy-paste investigations.
- 25Process tampering detectedSysmonAnglaisSysmon event 25 fires when a process image is changed in memory or on disk, as in process hollowing or herpaderping. Rare and high-signal.
- 26File deleted (logged)SysmonAnglaisSysmon event 26 logs a file deletion with the deleting process and hashes but, unlike event 23, does not keep a copy. A low-cost way to track deletions.
- 27Executable file blockedSysmonAnglaisSysmon event 27 fires when Sysmon blocks the creation of an executable (PE) file matching its rules. A preventive control added in Sysmon 14.0.
- 28File shredding blockedSysmonAnglaisSysmon event 28 fires when Sysmon blocks a file-shredding attempt, such as SDelete overwriting a file before deleting it. Added in Sysmon 14.1.
- 29Executable file detectedSysmonAnglaisSysmon event 29 logs the creation of a new executable (PE) file, with hashes, without blocking it. Added in Sysmon 15.0; ideal for tracking dropped binaries.
- 255ErrorSysmonAnglaisSysmon event 255 reports an internal Sysmon error, such as events dropped under load or a failed operation. Signals gaps in telemetry and possible tampering.
- 4103Journalisation des modulesPowerShell OperationalL'événement PowerShell 4103 (journalisation des modules) consigne l'exécution du pipeline : chaque commande, ses paramètres liés et le contexte de l'hôte.
- 4104Blocs de script journalisésPowerShell OperationalL'événement PowerShell 4104 consigne le texte des blocs de script exécutés, après décodage — la trace la plus riche de ce que PowerShell a réellement exécuté.
- 4105Script block invocation startedPowerShell OperationalAnglaisPowerShell event 4105 marks the start of a script block's execution; with 4106 it gives run times for blocks logged by 4104.
- 4106Script block invocation completedPowerShell OperationalAnglaisPowerShell event 4106 marks the end of a script block's execution, paired with 4105 by ScriptBlockId when invocation logging is enabled.
- 40961Console startingPowerShell OperationalAnglaisPowerShell event 40961 is logged when a PowerShell host starts, giving a timestamp for each PowerShell launch even without script logging.
- 40962Console ready for inputPowerShell OperationalAnglaisPowerShell event 40962 follows 40961 when the PowerShell host is ready for input — another default-logged marker of PowerShell use.
- 400Engine startedWindows PowerShellAnglaisWindows PowerShell event 400 logs every engine start with HostApplication (the command line) and EngineVersion — key to spot PowerShell v2 downgrades.
- 403Engine stoppedWindows PowerShellAnglaisWindows PowerShell event 403 logs when a PowerShell engine stops; paired with 400 it bounds a PowerShell session in time.
- 600Provider startedWindows PowerShellAnglaisWindows PowerShell event 600 is logged as each provider (Registry, FileSystem, Variable…) starts in a new session, repeating HostApplication.
- 800Pipeline execution detailsWindows PowerShellAnglaisWindows PowerShell event 800 records pipeline execution details (commands and parameters) when module logging is enabled.
- 100Task startedTask SchedulerAnglaisTask Scheduler event 100 marks the start of a task instance: task path, run-as user and an instance GUID that links the launch, actions and completion.
- 102Task completedTask SchedulerAnglaisTask Scheduler event 102 marks the end of a task instance. With event 100 it bounds how long a task ran; the action's return code is in event 201.
- 106Task registeredTask SchedulerAnglaisTask Scheduler event 106 records that a user registered a new scheduled task: the task path and the account that created it. Key for persistence hunting.
- 129Task process createdTask SchedulerAnglaisTask Scheduler event 129 records the process created for a task: task path, image path and process ID — the link to process creation logs.
- 140Task updatedTask SchedulerAnglaisTask Scheduler event 140 records that a user updated an existing scheduled task. Watch for built-in or trusted tasks being modified to run a payload.
- 141Task deletedTask SchedulerAnglaisTask Scheduler event 141 records that a user deleted a scheduled task. Right after 106 and a run, it points to one-shot remote execution or cleanup.
- 142Task disabledTask SchedulerAnglaisTask Scheduler event 142 records that a user disabled a scheduled task — relevant when security, update or backup tasks are switched off.
- 200Action startedTask SchedulerAnglaisTask Scheduler event 200 records that a task action was launched: which task, which instance and the action itself — often the program path that ran.
- 201Action completedTask SchedulerAnglaisTask Scheduler event 201 records that a task action completed, with the action and its return code — tells you whether the launched program succeeded.
- 21Ouverture de session réussieRDP LocalSessionManagerL'événement RDP 21 confirme une ouverture de session sur la cible : utilisateur, ID de session et adresse réseau source (« LOCAL » pour la console).
- 22Shell startRDP LocalSessionManagerAnglaisRDP event 22 is logged when the user's shell (Explorer) starts in a new session, right after the session logon event 21.
- 23Session logoffRDP LocalSessionManagerAnglaisRDP event 23 is logged when a Remote Desktop or console session is logged off, closing the session opened by event 21.
- 24Session déconnectéeRDP LocalSessionManagerL'événement RDP 24 est consigné quand une session Bureau à distance est déconnectée sans être fermée, avec utilisateur, ID de session et adresse du client.
- 25Session reconnectéeRDP LocalSessionManagerL'événement RDP 25 est consigné quand un utilisateur se reconnecte à une session déconnectée existante, avec l'adresse du nouveau client.
- 39Session disconnected by another sessionRDP LocalSessionManagerAnglaisRDP event 39 records that one session was disconnected by another session, as with a session takeover or tscon.
- 40Session disconnect reasonRDP LocalSessionManagerAnglaisRDP event 40 gives the reason code for a session disconnect, telling user-initiated disconnects from replaced connections.
- 1149Connexion authentifiéeRDP RemoteConnectionManagerL'événement RDP 1149 consigne une connexion Bureau à distance entrante : utilisateur, domaine, IP source. Il atteste la connexion, pas l'ouverture de session.
- 1024Outbound connection attemptRDP ClientAnglaisRDP client event 1024 is logged on the source host when mstsc starts connecting to a server; the Value field holds the target name or IP.
- 1102Multi-transport connectionRDP ClientAnglaisRDP client event 1102 is logged on the source host when the client opens a multi-transport connection; Value holds the server IP address.
- 131TCP connection acceptedRDP RdpCoreTSAnglaisRdpCoreTS event 131 is logged when the RDP server accepts a TCP connection, with the client IP and port — even for failed or scanner connections.
- 5857Provider startedWMI-ActivityAnglaisWMI-Activity event 5857 logs a WMI provider being loaded: provider name, DLL path and host process. Useful to spot rogue providers and WMI usage.
- 5858Operation errorWMI-ActivityAnglaisWMI-Activity event 5858 logs a failed WMI operation with the client machine, user, process ID and the query or method that failed. Noisy but revealing.
- 5860Temporary event consumerWMI-ActivityAnglaisWMI-Activity event 5860 logs a temporary WMI event subscription: the namespace, the WQL notification query and the client process that registered it.
- 5861Permanent event consumerWMI-ActivityAnglaisWMI-Activity event 5861 logs a permanent WMI event subscription (filter-to-consumer binding), the classic fileless persistence technique.
- 1006Malware found by scanMicrosoft DefenderAnglaisDefender event 1006 is logged when the antimalware engine finds malware or unwanted software, with threat name, path and detection source.
- 1007Action taken (engine)Microsoft DefenderAnglaisDefender event 1007 records that the antimalware platform took action on detected malware, the engine-level counterpart of event 1117.
- 1008Engine action failedMicrosoft DefenderAnglaisDefender event 1008 means Defender could not complete an action on detected malware (engine level); the item may still be on the system.
- 1013Detection history deletedMicrosoft DefenderAnglaisDefender event 1013 is logged when Defender's malware detection history is deleted — routine purging, or an attempt to hide past detections.
- 1015Suspicious behavior detectedMicrosoft DefenderAnglaisDefender event 1015 is logged when behavior monitoring detects suspicious activity rather than a known file, with threat name and process details.
- 1116Malware detectedMicrosoft DefenderAnglaisDefender event 1116 is logged when Microsoft Defender Antivirus detects malware or unwanted software: threat name, file path, process and user.
- 1117Action taken on malwareMicrosoft DefenderAnglaisDefender event 1117 confirms Microsoft Defender Antivirus acted on a detection — quarantine, remove, clean or block — with threat, path and action.
- 1118Action on malware failedMicrosoft DefenderAnglaisDefender event 1118 means Microsoft Defender Antivirus detected a threat but could not remediate it (non-critical failure) — the item may still be present.
- 1119Critical failure acting on malwareMicrosoft DefenderAnglaisDefender event 1119 records a critical error while acting on a detected threat — remediation failed and the threat may still be active.
- 1121ASR rule blocked an operationMicrosoft DefenderAnglaisDefender event 1121 is logged when an attack surface reduction (ASR) rule in block mode stops an operation, such as LSASS access or Office child processes.
- 2001Security intelligence update failedMicrosoft DefenderAnglaisDefender event 2001 is logged when a security intelligence (signature) update fails, with the versions, update source and error.
- 5000Real-time protection enabledMicrosoft DefenderAnglaisDefender event 5000 is logged when real-time protection is turned on — the counterpart of 5001, useful to measure how long protection was off.
- 5001Real-time protection disabledMicrosoft DefenderAnglaisDefender event 5001 is logged when real-time protection is turned off — a classic step before attackers drop tools or ransomware.
- 5004Real-time protection config changedMicrosoft DefenderAnglaisDefender event 5004 is logged when a real-time protection feature (on-access, behavior monitoring, downloads scanning…) changes configuration.
- 5007Configuration changedMicrosoft DefenderAnglaisDefender event 5007 logs every Defender configuration change with old and new values — including exclusions added by attackers.
- 5010Malware scanning disabledMicrosoft DefenderAnglaisDefender event 5010 is logged when scanning for malware and potentially unwanted software is disabled — a sign of defense tampering or another AV.
- 5012Virus scanning disabledMicrosoft DefenderAnglaisDefender event 5012 is logged when Defender virus scanning is disabled — like 5010, a strong tampering signal unless another antivirus took over.
- 5013Tamper protection blocked a changeMicrosoft DefenderAnglaisDefender event 5013 is logged when tamper protection blocks a change to Defender settings — evidence that something tried to weaken the antivirus.
- 3Job createdBITS ClientAnglaisBITS event 3 records the creation of a BITS transfer job: job title, job ID, owner and, on newer builds, the process that created it.
- 4Job completedBITS ClientAnglaisBITS event 4 records that a BITS transfer job completed: job title, ID, owner, file count and bytes transferred. Confirms a download or upload finished.
- 59Transfer startedBITS ClientAnglaisBITS event 59 records that BITS started transferring a job, with the job name and the remote URL — the event that tells you where BITS was downloading from.
- 60Transfer stoppedBITS ClientAnglaisBITS event 60 records that BITS stopped transferring a job, with the job name, remote URL and status code — success, failure or interruption.
- 6WSMan session created (client)WinRMAnglaisWinRM event 6 is logged on the client when a WS-Management session is created, with the connection string naming the remote host. Source-side PS remoting.
- 91WSMan shell created (server)WinRMAnglaisWinRM event 91 is logged on the target when a remote WSMan shell is created, with the resource URI showing whether it is PowerShell remoting or winrs.
- 169User authenticated (legacy)WinRMAnglaisWinRM event 169 logs a user authenticating to the WinRM service and the mechanism used. It is defined only in Windows 7 / Server 2008 R2 era manifests.
- 8002EXE or DLL allowedAppLockerAnglaisAppLocker event 8002 records that an executable or DLL was allowed to run by an AppLocker rule, with the file path, matching rule and user SID.
- 8003EXE or DLL would be blocked (audit)AppLockerAnglaisAppLocker event 8003 records an executable or DLL that ran but would have been blocked if the policy were enforced. Audit-mode view of unapproved code.
- 8004EXE or DLL blockedAppLockerAnglaisAppLocker event 8004 records an executable or DLL blocked by an enforced AppLocker policy, with file path, signer, hash and the user who tried to run it.
- 8005MSI or script allowedAppLockerAnglaisAppLocker event 8005 records that a script or Windows Installer file was allowed to run by an AppLocker rule, with the file path, rule and user SID.
- 8006Script or MSI would be blockedAppLockerAnglaisAppLocker event 8006 records a script or MSI that ran but would have been blocked if the policy were enforced — audit-mode view of unapproved scripts.
- 8007MSI or script blockedAppLockerAnglaisAppLocker event 8007 records a script or Windows Installer file blocked by an enforced AppLocker policy, with the path, hash and user who tried to run it.
- 2004Rule addedWindows FirewallAnglaisFirewall event 2004 records a new Windows Firewall rule with its program, ports, action and the user and process that added it. On by default, richer than 4946.
- 2005Rule modifiedWindows FirewallAnglaisFirewall event 2005 records a change to an existing Windows Firewall rule, with the rule's new settings and the user and process that changed it. On by default.
- 2006Rule deletedWindows FirewallAnglaisFirewall event 2006 records the deletion of a Windows Firewall rule, with the rule ID, name, and the user SID and process that removed it. On by default.
- 2033All rules deletedWindows FirewallAnglaisFirewall event 2033 records that every rule was deleted from a Windows Firewall rule store, with the user SID and process responsible. Rare and worth reviewing.
- 1006Disk connected (partition data)PartitionAnglaisPartition event 1006 records a disk's vendor, model, serial, capacity and raw MBR/VBR bytes on connection. Rich USB evidence, incl. volume serials.
- 400Device configuredKernel-PnPAnglaisKernel-PnP event 400 is logged when a device is configured with a driver: instance ID, driver INF and class. Dates USB storage and other device connections.
- 410Device startedKernel-PnPAnglaisKernel-PnP event 410 is logged when a device is started with its driver and service. Dates USB storage connections, including repeat ones.
- 8001Outgoing authentication auditNTLMAnglaisNTLM event 8001 logs outgoing NTLM authentication from this computer: target server, supplied user and client process. Shows which apps still use NTLM.
- 8002Incoming authentication auditNTLMAnglaisNTLM event 8002 logs incoming NTLM authentication processed by this server, with the calling process and its identity. Maps which servers still accept NTLM.
- 8003Domain server authentication auditNTLMAnglaisNTLM event 8003 logs NTLM authentication of a domain account received by this server: user, domain, client workstation, logon type and process. Audit only.
- 8004Domain controller authentication auditNTLMAnglaisNTLM event 8004 is logged on domain controllers for each NTLM authentication they validate: user, client workstation and the server that forwarded it.
- 3033Image blocked (signing level)Code IntegrityAnglaisCode Integrity event 3033: a process tried to load a DLL or driver below its required signing level and was blocked. Seen with LSA protection.
- 3077App Control (WDAC) blockCode IntegrityAnglaisCode Integrity event 3077 is the main App Control for Business (WDAC) enforcement block: a file failed the active policy and was prevented from loading.
- 31001Logon failureSMB ClientAnglaisSMB client event 31001 records a failed authentication from this computer to an SMB server, with server name, user name, SPN and error codes. Source-side view.
- 551SMB session auth failureSMB ServerAnglaisSMB server event 551 records a failed SMB session authentication, with client address, user name and status code. Complements 4625 for SMB brute force.
- 307Document printedPrintServiceAnglaisPrintService event 307 logs each printed job: document, user, client, printer, size and pages. Off by default; key for insider print exfiltration.
- 808Spooler plug-in load failedPrintServiceAnglaisPrintService Admin event 808: the spooler failed to load a plug-in or driver DLL. Error 0x45A with an odd DLL path is a PrintNightmare sign.
- 3006DNS query startedDNS ClientAnglaisDNS Client event 3006 records the start of a DNS query on the host: queried name, record type and DNS servers. Channel is off by default; pair it with 3008.
- 3008DNS query completedDNS ClientAnglaisDNS Client event 3008 records a completed DNS query: name, type, status code and resolved addresses. Host-level DNS history; channel is off by default.
- 4sshd informational messageOpenSSHAnglaisOpenSSH event 4 carries informational sshd messages on Windows: accepted and failed logons, invalid users and disconnects, with source IP and port in the text.