Enciclopedia degli Event ID di Windows
237 eventi Windows spiegati per analisti DFIR e SOC: significato, criterio di controllo che li genera, campi utili, come li attivano gli attaccanti e quali regole SigmaHQ li rilevano. Le schede sono in inglese.
237 eventi
- 1100Event logging service shut downSecurityIngleseSecurity event 1100 marks the Windows Event Log service stopping, normally at shutdown. Outside a reboot it can mean logging was stopped on purpose.
- 1102Security log clearedSecurityIngleseSecurity event 1102 is written when the Security log is cleared, naming the account that did it. Rare in normal operations and a classic anti-forensics sign.
- 1104Security log fullSecurityIngleseSecurity event 1104 means the Security log reached its maximum size and is set not to overwrite, so new audit events can no longer be written.
- 4608Windows starting upSecurityIngleseSecurity event 4608 is logged when LSASS starts and auditing initializes during boot. Use it to mark system startups on the Security log timeline.
- 4616System time changedSecurityIngleseSecurity event 4616 records a system clock change with old and new time, account and process. Routine time sync is normal; manual jumps skew timelines.
- 4624Successful logonSecurityIngleseSecurity event 4624 records every successful logon: who, how (LogonType), from where (IpAddress) and with which package. The core of logon forensics.
- 4625Failed logonSecurityIngleseEvent 4625 is logged when a logon attempt fails. Status and SubStatus say why: bad password, unknown user, locked or disabled account.
- 4634LogoffSecurityIngleseEvent 4634 marks the end of a logon session. Match its TargetLogonId to a 4624 to measure how long a session lasted.
- 4647User-initiated logoffSecurityIngleseEvent 4647 is logged when a user actively signs out of an interactive or RDP session, before the session teardown event 4634.
- 4648Logon with explicit credentialsSecurityIngleseEvent 4648 is logged on the source host when a process uses explicitly supplied credentials, such as runas, net use /user or PsExec -u.
- 4656Object handle requestedSecurityIngleseSecurity event 4656 logs a request for a handle to an audited file, registry key or kernel object, with the access asked for and whether it was granted.
- 4657Registry value modifiedSecurityIngleseSecurity event 4657 records a created, changed or deleted registry value on an audited key, with old and new data and the process that made the change.
- 4658Object handle closedSecurityIngleseSecurity event 4658 marks the closing of a handle to an audited object. Pair it with 4656 by HandleId to measure how long the object was open.
- 4660Object deletedSecurityIngleseSecurity event 4660 confirms that an audited file, registry key or kernel object was deleted. It has no object name, so join it to 4663 by HandleId.
- 4661SAM or AD handle requestedSecurityIngleseSecurity event 4661 logs a handle request on a SAM or Active Directory object. On DCs it exposes SAMR enumeration of users and groups such as Domain Admins.
- 4662AD object operationSecurityIngleseSecurity event 4662 logs an operation on an Active Directory object. With the replication rights GUIDs in Properties, it is the classic DCSync detection.
- 4663Object accessSecurityIngleseSecurity event 4663 records an access right actually used on an audited file, folder, registry key or kernel object: who, which process, and what access.
- 4670Object permissions changedSecurityIngleseSecurity event 4670 records a change to an object's permissions (DACL or owner), with old and new security descriptors in SDDL and the process responsible.
- 4672Special privileges assignedSecurityIngleseEvent 4672 follows a 4624 when the new session holds sensitive privileges such as SeDebug or SeTcb — a marker of administrator logons.
- 4673Privileged service calledSecurityIngleseSecurity event 4673 logs a call to a privileged system service, such as registering a logon process with SeTcbPrivilege, and whether the call succeeded.
- 4688Process creationSecurityIngleseSecurity event 4688 logs every new process: executable, parent, account, elevation and, if enabled, the full command line. Off by default.
- 4689Process exitedSecurityIngleseSecurity event 4689 logs a process exit with its PID, path, account and exit code. Pair it with 4688 to get how long a process ran. Off by default.
- 4697Service installedSecurityIngleseSecurity event 4697 records a new Windows service with its name, binary path, start type and account. Key for PsExec-style lateral movement and persistence.
- 4698Scheduled task createdSecurityIngleseSecurity event 4698 records a new scheduled task with its full XML: command, arguments, run-as account and triggers. A key persistence and remote exec signal.
- 4699Scheduled task deletedSecurityIngleseSecurity event 4699 records a deleted scheduled task, including its last XML definition. Quick create-then-delete pairs point to remote execution.
- 4700Scheduled task enabledSecurityIngleseSecurity event 4700 records a scheduled task being enabled, with its XML definition. Watch for dormant or attacker-created tasks switched back on.
- 4701Scheduled task disabledSecurityIngleseSecurity event 4701 records a scheduled task being disabled, with its XML. Disabling security, backup or update tasks can be part of defense evasion.
- 4702Scheduled task updatedSecurityIngleseSecurity event 4702 records a modified scheduled task with its new XML definition. Look for changed actions or run-as accounts on existing tasks.
- 4703Token right adjustedSecurityIngleseSecurity event 4703 logs privileges being enabled or disabled in an access token, such as a process turning on SeDebugPrivilege before touching LSASS.
- 4704User right assignedSecurityIngleseSecurity event 4704 logs a user right (privilege) being assigned to an account or group in local security policy, such as SeDebugPrivilege or SeBackupPrivilege.
- 4705User right removedSecurityIngleseSecurity event 4705 logs a user right (privilege) being removed from an account or group in local security policy. Mirror of event 4704.
- 4713Kerberos policy changedSecurityIngleseSecurity event 4713 is logged on domain controllers when the domain Kerberos policy (ticket lifetimes, renewal, clock skew) is changed.
- 4717Logon right grantedSecurityIngleseSecurity event 4717 logs a logon right (e.g. SeRemoteInteractiveLogonRight, SeServiceLogonRight) being granted to an account or group in local security policy.
- 4718Logon right removedSecurityIngleseSecurity event 4718 logs a logon right (such as a Deny logon right or RDP logon right) being removed from an account or group in local security policy.
- 4719Audit policy changedSecurityIngleseSecurity event 4719 logs a change to the system audit policy, such as Success or Failure auditing being removed for a subcategory with auditpol.
- 4720User account createdSecurityIngleseSecurity event 4720 records the creation of a local or domain user account: who created it, the new name and SID, and its initial attributes.
- 4722User account enabledSecurityIngleseSecurity event 4722 is logged when a user or computer account is enabled. It shows who enabled it and which account, identified by name and SID.
- 4723Password change attemptSecurityIngleseSecurity event 4723 is logged when an account attempts to change its own password (knowing the old one). Failure means the new password was rejected.
- 4724Password reset attemptSecurityIngleseSecurity event 4724 is logged when one account resets another account's password without knowing the old one — an administrative action worth reviewing.
- 4725User account disabledSecurityIngleseSecurity event 4725 is logged when a user or computer account is disabled, recording who disabled it and which account was affected.
- 4726User account deletedSecurityIngleseSecurity event 4726 is logged when a local or domain user account is deleted, with the subject who deleted it and the removed account's name and SID.
- 4727Global group createdSecurityIngleseSecurity event 4727 is logged on a domain controller when a new security-enabled global group is created in Active Directory.
- 4728Member added to global groupSecurityIngleseSecurity event 4728 is logged on a domain controller when a member is added to a security-enabled global group, such as Domain Admins.
- 4729Member removed from global groupSecurityIngleseSecurity event 4729 is logged on a domain controller when a member is removed from a security-enabled global group, such as Domain Admins.
- 4730Global group deletedSecurityIngleseSecurity event 4730 is logged on a domain controller when a security-enabled global group is deleted from Active Directory.
- 4731Local group createdSecurityIngleseSecurity event 4731 is logged when a security-enabled local group is created — a local SAM group on a host, or a domain local group on a domain controller.
- 4732Member added to local groupSecurityIngleseSecurity event 4732 is logged when a member is added to a security-enabled local group, such as the local Administrators group or a domain local group.
- 4733Member removed from local groupSecurityIngleseSecurity event 4733 is logged when a member is removed from a security-enabled local group, such as the local Administrators group or a domain local group.
- 4734Local group deletedSecurityIngleseSecurity event 4734 is logged when a security-enabled local group is deleted — a local SAM group on a host, or a domain local group on a domain controller.
- 4735Local group changedSecurityIngleseSecurity event 4735 is logged when a security-enabled local group is changed. It shows name or SID history changes; most instances accompany membership changes.
- 4737Global group changedSecurityIngleseSecurity event 4737 is logged on a domain controller when a security-enabled global group is changed; most instances accompany membership changes.
- 4738User account changedSecurityIngleseSecurity event 4738 is logged when a user account is modified. Changed attributes carry new values, including account flags such as delegation or pre-auth.
- 4739Domain policy changedSecurityIngleseSecurity event 4739 logs a change to domain password, lockout or logoff policy, or to ms-DS-MachineAccountQuota. Only the changed values are filled in.
- 4740Account locked outSecurityIngleseSecurity event 4740 is logged when an account is locked out after too many bad passwords. It names the account and the caller computer that triggered it.
- 4741Computer account createdSecurityIngleseSecurity event 4741 is logged on a domain controller when a computer account is created in Active Directory, e.g. by a domain join or a manual pre-creation.
- 4742Computer account changedSecurityIngleseSecurity event 4742 is logged on a domain controller when a computer account is changed: password, SPNs, DNS name, delegation or account flags.
- 4743Computer account deletedSecurityIngleseSecurity event 4743 is logged on a domain controller when a computer account is deleted from Active Directory, with who deleted it and the account's SID.
- 4754Universal group createdSecurityIngleseSecurity event 4754 is logged on a domain controller when a new security-enabled universal group is created in Active Directory.
- 4755Universal group changedSecurityIngleseSecurity event 4755 is logged on a domain controller when a security-enabled universal group is changed; most instances accompany membership changes.
- 4756Member added to universal groupSecurityIngleseSecurity event 4756 is logged on a domain controller when a member is added to a security-enabled universal group, such as Enterprise Admins or Schema Admins.
- 4757Member removed from universal groupSecurityIngleseSecurity event 4757 is logged on a domain controller when a member is removed from a security-enabled universal group, such as Enterprise Admins.
- 4765SID History addedSecurityIngleseSecurity event 4765 is logged on a domain controller when SID History is added to an account — normal in migrations, a privilege escalation path otherwise.
- 4766SID History add failedSecurityIngleseSecurity event 4766 is logged on a domain controller when an attempt to add SID History to an account fails — worth checking outside a migration project.
- 4767Account unlockedSecurityIngleseSecurity event 4767 is logged when a locked-out user account is unlocked, recording who unlocked it and which account.
- 4768Kerberos TGT requestedSecurityIngleseDomain controller event 4768 records every Kerberos TGT request: the account, client IP, encryption type, pre-authentication type and result.
- 4769Kerberos service ticket requestedSecurityIngleseEvent 4769 is logged on domain controllers for every Kerberos service ticket (TGS) request — the key record for spotting Kerberoasting.
- 4770Kerberos service ticket renewedSecurityIngleseEvent 4770 is logged on domain controllers when a client renews an existing Kerberos service ticket instead of requesting a new one.
- 4771Kerberos pre-authentication failedSecurityIngleseEvent 4771 is logged on domain controllers when Kerberos pre-authentication fails, most often because of a wrong password (Status 0x18).
- 4776NTLM credential validationSecurityIngleseEvent 4776 records an NTLM credential check: on the domain controller for domain accounts, on the local machine for local accounts.
- 4778Session reconnectedSecurityIngleseEvent 4778 is logged when a user reconnects to an existing interactive session, typically an RDP reconnect or fast user switching.
- 4779Session disconnectedSecurityIngleseEvent 4779 is logged when an interactive session is disconnected without logging off — an RDP window closed or a user switch.
- 4780AdminSDHolder ACL appliedSecurityIngleseSecurity event 4780 is logged when SDProp resets the ACL of a protected admin account to match AdminSDHolder, revealing ACL changes on privileged accounts.
- 4781Account renamedSecurityIngleseSecurity event 4781 is logged when the sAMAccountName of a user, computer or group is changed. It gives the old and new names with the account's SID.
- 4794DSRM password set attemptSecurityIngleseSecurity event 4794 is logged on a domain controller when someone sets the DSRM administrator password. Rare, and abused for DC persistence.
- 4798User's local groups enumeratedSecurityIngleseSecurity event 4798 logs a process listing which local groups a user belongs to, with the calling process. Mostly noise, but useful for spotting discovery.
- 4799Local group members enumeratedSecurityIngleseSecurity event 4799 logs a process listing the members of a local group such as Administrators, with the caller process. Good signal for local admin discovery.
- 4800Workstation lockedSecurityIngleseSecurity event 4800 records a user locking their workstation, with the account and logon session. Useful to tell when a user was really at the keyboard.
- 4801Workstation unlockedSecurityIngleseSecurity event 4801 records a user unlocking their workstation, with the account and logon session. Pairs with 4800 to show when the user was present.
- 4826Boot configuration loadedSecurityIngleseSecurity event 4826 records the Boot Configuration Data settings loaded at startup, such as test signing, integrity checks and kernel debugging.
- 4886Certificate request receivedSecurityIngleseSecurity event 4886 is logged on an AD CS certification authority when it receives a certificate request, with the request ID and the requesting account.
- 4887Certificate issuedSecurityIngleseSecurity event 4887 is logged on an AD CS certification authority when a certificate is issued: request ID, requester, subject and subject key identifier.
- 4907Object SACL changedSecurityIngleseSecurity event 4907 logs a change to an object's auditing settings (SACL) on a file or registry key, with the old and new security descriptors.
- 4946Firewall rule addedSecurityIngleseSecurity event 4946 records a Windows Firewall rule added locally, with its name, ID and profiles. Useful to catch attackers opening ports or allowing tools.
- 4947Firewall rule modifiedSecurityIngleseSecurity event 4947 logs a local change to an existing Windows Firewall rule. Watch for rules enabled, widened or switched from block to allow.
- 4948Firewall rule deletedSecurityIngleseSecurity event 4948 records the local deletion of a Windows Firewall rule. Useful to spot attackers removing block rules or cleaning up rules they added.
- 4964Special group logonSecurityIngleseSecurity event 4964 flags a logon by a member of a group listed in the SpecialGroups registry value, e.g. Domain Admins. Only works once configured.
- 5136AD object modifiedSecurityIngleseSecurity event 5136 logs an attribute change on an Active Directory object, with the attribute and value — GPO edits, SPNs, ACLs, shadow credentials.
- 5137AD object createdSecurityIngleseSecurity event 5137 logs the creation of an Active Directory object — user, computer, group, GPO or any other class — with its DN, class and creator.
- 5140Network share accessedSecurityIngleseSecurity event 5140 logs the first access to a network share in an SMB session: account, source IP and share name. Key for tracking C$, ADMIN$ and IPC$ use.
- 5141AD object deletedSecurityIngleseSecurity event 5141 logs the deletion of an Active Directory object, with its DN, class, the account responsible and whether a subtree delete was used.
- 5142Network share addedSecurityIngleseSecurity event 5142 records a new network share: who created it, its name and local path. Watch for shares exposing drives or staging folders.
- 5144Network share deletedSecurityIngleseSecurity event 5144 records the removal of a network share, with the account that deleted it and the share's name and path. Often a cleanup step.
- 5145Share object access checkSecurityIngleseSecurity event 5145 logs each file, folder or named pipe accessed through a share, with account, source IP and requested rights. Detailed and noisy.
- 5156WFP connection allowedSecurityIngleseSecurity event 5156 logs each connection allowed by the Windows Filtering Platform: process, direction, addresses, ports and protocol.
- 5157WFP connection blockedSecurityIngleseSecurity event 5157 logs each connection blocked by the Windows Filtering Platform, with process, direction, addresses and ports. Reveals scans and blocked C2.
- 5376Credential Manager backupSecurityIngleseSecurity event 5376 records a backup of a user's Credential Manager vault. Rarely used by real users, so worth checking every time.
- 5377Credential Manager restoreSecurityIngleseSecurity event 5377 records Credential Manager credentials restored from a backup file into a user's vault. Rare; confirm each one.
- 6416External device recognizedSecurityIngleseSecurity event 6416 records a new device recognized by Windows, such as a USB drive, with device ID, class and vendor IDs. Needs Audit PNP Activity.
- 12Operating system startedSystemIngleseSystem event 12 (Kernel-General) marks an operating system boot and records the exact kernel start time and OS build. The anchor for every boot timeline.
- 13Operating system shutdownSystemIngleseSystem event 13 (Kernel-General) is written on a clean shutdown with the exact stop time. No 13 before a boot means a crash or power loss.
- 41Unclean reboot (Kernel-Power)SystemIngleseSystem event 41 (Kernel-Power) is logged at boot when the previous session ended without a clean shutdown: crash, hang, power loss or forced reset.
- 104Event log clearedSystemIngleseSystem event 104 records that an event log (System, Application, Sysmon, PowerShell...) was cleared, and by whom. Security log clears are event 1102 instead.
- 1014DNS resolution timeoutSystemIngleseSystem event 1014 (DNS Client) is logged when a name lookup timed out because none of the configured DNS servers answered. Mostly network noise.
- 1074Shutdown or restart requestedSystemIngleseSystem event 1074 (User32) records who requested a shutdown or restart: the process, the user, the reason code and the comment. Answers "who rebooted this box?"
- 5827Vulnerable Netlogon channel deniedSystemIngleseSystem event 5827: a DC denied a machine account's Netlogon secure channel without secure RPC. Key Zerologon (CVE-2020-1472) signal.
- 6005Event Log service startedSystemIngleseSystem event 6005 is written when the Event Log service starts, which in practice means at every boot. A simple, reliable startup marker next to event 12.
- 6006Event Log service stoppedSystemIngleseSystem event 6006 is written when the Event Log service stops, normally at clean shutdown. Missing before a boot means a crash.
- 6008Unexpected shutdownSystemIngleseSystem event 6008 is logged at boot when the previous shutdown was unexpected, with the approximate local time the system went down. Pairs with Kernel-Power 41.
- 6013Uptime reportSystemIngleseSystem event 6013 reports the system uptime in seconds and the time zone, at boot and once a day. Helps spot reboots and log gaps.
- 7000Service failed to startSystemIngleseSystem event 7000 is logged when a service fails to start, with the error. Often follows a malicious 7045 whose payload is not a real service binary.
- 7009Service start timeoutSystemIngleseSystem event 7009: a service did not report to the SCM within the timeout (30 s by default). Common with command-based malicious services.
- 7031Service crashed (recovery action)SystemIngleseSystem event 7031: a service terminated unexpectedly and the SCM will apply a recovery action. Can reveal security tools being killed.
- 7034Service crashedSystemIngleseSystem event 7034: a service process ended unexpectedly with no recovery action configured. Crashes, or security services being killed.
- 7036Service state changedSystemIngleseSystem event 7036 logs each time a service enters the running or stopped state. Shows when services ran and when security tools or logging were stopped.
- 7040Service start type changedSystemIngleseSystem event 7040 records a change to a service start type (auto, demand, disabled). Reveals security tools being disabled and services turned into persistence.
- 7045Service installedSystemIngleseSystem event 7045 records every new service or driver: name, binary path, start type and account. A top lateral movement signal.
- 20001Device driver installedSystemIngleseSystem event 20001 (UserPnp) records a device driver install with the device instance ID. First-connection evidence for USB storage.
- 1000Application crashApplicationIngleseApplication event 1000 records a process crash: application, faulting module, exception code and offset. Exposes exploits and killed tools.
- 1001Windows Error Reporting reportApplicationIngleseApplication event 1001 records a Windows Error Reporting report (APPCRASH, BEX, BlueScreen...) and its report folder. Complements 1000.
- 1033MSI product installedApplicationIngleseApplication event 1033 (MsiInstaller) records an MSI package installation: product name, version, manufacturer and result, with the installing user's SID.
- 11707MSI installation succeededApplicationIngleseApplication event 11707 (MsiInstaller) confirms that an MSI product installation completed successfully, with the product name and the installing user's SID.
- 18456SQL Server login failedApplicationIngleseApplication event 18456 from SQL Server logs a failed database login with user, reason and client IP. Brute force against MSSQL.
- 1Process creationSysmonIngleseSysmon event 1 logs every new process with full command line, hashes, parent process and a ProcessGuid for correlation. The backbone of endpoint hunting.
- 2File creation time changedSysmonIngleseSysmon event 2 fires when a process explicitly changes a file's creation timestamp — the classic trace of timestomping, but also common in installers.
- 3Network connectionSysmonIngleseSysmon event 3 ties each TCP/UDP connection to the process that made it: source, destination, ports and ProcessGuid. Key for C2 and lateral movement.
- 4Service state changedSysmonIngleseSysmon event 4 reports the Sysmon service starting or stopping. An unexpected stop outside maintenance can mean someone is blinding endpoint telemetry.
- 5Process terminatedSysmonIngleseSysmon event 5 records a process exiting, with ProcessGuid and image path. Pairs with event 1 to measure lifetime and close out process timelines.
- 6Driver loadedSysmonIngleseSysmon event 6 logs a kernel driver being loaded, with hashes and signature details. Rare and high-impact: watch for vulnerable or unsigned drivers.
- 7Image (DLL) loadedSysmonIngleseSysmon event 7 logs a DLL or other module loaded into a process, with hashes and signature. Used to catch DLL side-loading and unusual module loads.
- 8Remote thread createdSysmonIngleseSysmon event 8 fires when a process creates a thread in another process — a classic code injection technique. Low volume, high signal.
- 9Raw disk access readSysmonIngleseSysmon event 9 logs a process reading a drive directly through the \\.\ device path, used to copy locked files such as NTDS.dit or SAM without file APIs.
- 10Process accessedSysmonIngleseSysmon event 10 logs one process opening a handle to another, with the access mask and call stack. The go-to event for LSASS credential dumping.
- 11File createdSysmonIngleseSysmon event 11 logs a file being created or overwritten and the process that wrote it. Key for dropped payloads, persistence folders and dump files.
- 12Registry key created or deletedSysmonIngleseSysmon event 12 logs registry keys and values being created or deleted, with the process responsible. Watch autostart keys, services and COM entries.
- 13Registry value setSysmonIngleseSysmon event 13 logs a registry value being written, with the data for DWORD, QWORD and string values. The main Sysmon event for registry persistence.
- 14Registry key or value renamedSysmonIngleseSysmon event 14 logs a registry key or value being renamed, with the old path and the new name. Rare, and occasionally used to hide or stage persistence.
- 15Alternate data stream createdSysmonIngleseSysmon event 15 logs a named NTFS stream being created, such as the Zone.Identifier mark of the web on downloads. Reveals download origins and ADS use.
- 16Configuration changedSysmonIngleseSysmon event 16 records a change to the Sysmon configuration, with the config file and its hash. An unexpected change may be an attempt to blind monitoring.
- 17Named pipe createdSysmonIngleseSysmon event 17 logs a named pipe being created and the process behind it. Known pipe names reveal PsExec, C2 frameworks and other lateral movement tools.
- 18Named pipe connectedSysmonIngleseSysmon event 18 logs a client connecting to a named pipe. Paired with event 17 it shows who talks over a pipe — useful for PsExec and C2 pivots.
- 19WMI event filter registeredSysmonIngleseSysmon event 19 logs a WMI event filter being registered, with namespace, name and WQL query. The first of three events behind WMI subscription persistence.
- 20WMI event consumer registeredSysmonIngleseSysmon event 20 logs a WMI event consumer being registered, including the command or script it runs. The action half of WMI subscription persistence.
- 21WMI consumer bound to filterSysmonIngleseSysmon event 21 logs a WMI consumer being bound to a filter, the step that activates a permanent WMI subscription. Completes the WMI persistence trio.
- 22DNS querySysmonIngleseSysmon event 22 logs a DNS query made by a process, with the name, status and answers. Links domains to processes for C2, tunneling and phishing hunts.
- 23File deleted (archived)SysmonIngleseSysmon event 23 logs a file deletion and saves a copy of the deleted file in the archive folder. Recovers payloads and tools attackers delete after use.
- 24Clipboard content changedSysmonIngleseSysmon event 24 records a change to clipboard contents, with process, session and hash; contents can be archived. Useful for RDP copy-paste investigations.
- 25Process tampering detectedSysmonIngleseSysmon event 25 fires when a process image is changed in memory or on disk, as in process hollowing or herpaderping. Rare and high-signal.
- 26File deleted (logged)SysmonIngleseSysmon event 26 logs a file deletion with the deleting process and hashes but, unlike event 23, does not keep a copy. A low-cost way to track deletions.
- 27Executable file blockedSysmonIngleseSysmon event 27 fires when Sysmon blocks the creation of an executable (PE) file matching its rules. A preventive control added in Sysmon 14.0.
- 28File shredding blockedSysmonIngleseSysmon event 28 fires when Sysmon blocks a file-shredding attempt, such as SDelete overwriting a file before deleting it. Added in Sysmon 14.1.
- 29Executable file detectedSysmonIngleseSysmon event 29 logs the creation of a new executable (PE) file, with hashes, without blocking it. Added in Sysmon 15.0; ideal for tracking dropped binaries.
- 255ErrorSysmonIngleseSysmon event 255 reports an internal Sysmon error, such as events dropped under load or a failed operation. Signals gaps in telemetry and possible tampering.
- 4103Module loggingPowerShell OperationalInglesePowerShell event 4103 (module logging) records pipeline execution: each command invoked, with its parameter bindings and the host context.
- 4104Script block loggingPowerShell OperationalInglesePowerShell event 4104 logs the text of executed script blocks, after decoding — the richest record of what PowerShell actually ran.
- 4105Script block invocation startedPowerShell OperationalInglesePowerShell event 4105 marks the start of a script block's execution; with 4106 it gives run times for blocks logged by 4104.
- 4106Script block invocation completedPowerShell OperationalInglesePowerShell event 4106 marks the end of a script block's execution, paired with 4105 by ScriptBlockId when invocation logging is enabled.
- 40961Console startingPowerShell OperationalInglesePowerShell event 40961 is logged when a PowerShell host starts, giving a timestamp for each PowerShell launch even without script logging.
- 40962Console ready for inputPowerShell OperationalInglesePowerShell event 40962 follows 40961 when the PowerShell host is ready for input — another default-logged marker of PowerShell use.
- 400Engine startedWindows PowerShellIngleseWindows PowerShell event 400 logs every engine start with HostApplication (the command line) and EngineVersion — key to spot PowerShell v2 downgrades.
- 403Engine stoppedWindows PowerShellIngleseWindows PowerShell event 403 logs when a PowerShell engine stops; paired with 400 it bounds a PowerShell session in time.
- 600Provider startedWindows PowerShellIngleseWindows PowerShell event 600 is logged as each provider (Registry, FileSystem, Variable…) starts in a new session, repeating HostApplication.
- 800Pipeline execution detailsWindows PowerShellIngleseWindows PowerShell event 800 records pipeline execution details (commands and parameters) when module logging is enabled.
- 100Task startedTask SchedulerIngleseTask Scheduler event 100 marks the start of a task instance: task path, run-as user and an instance GUID that links the launch, actions and completion.
- 102Task completedTask SchedulerIngleseTask Scheduler event 102 marks the end of a task instance. With event 100 it bounds how long a task ran; the action's return code is in event 201.
- 106Task registeredTask SchedulerIngleseTask Scheduler event 106 records that a user registered a new scheduled task: the task path and the account that created it. Key for persistence hunting.
- 129Task process createdTask SchedulerIngleseTask Scheduler event 129 records the process created for a task: task path, image path and process ID — the link to process creation logs.
- 140Task updatedTask SchedulerIngleseTask Scheduler event 140 records that a user updated an existing scheduled task. Watch for built-in or trusted tasks being modified to run a payload.
- 141Task deletedTask SchedulerIngleseTask Scheduler event 141 records that a user deleted a scheduled task. Right after 106 and a run, it points to one-shot remote execution or cleanup.
- 142Task disabledTask SchedulerIngleseTask Scheduler event 142 records that a user disabled a scheduled task — relevant when security, update or backup tasks are switched off.
- 200Action startedTask SchedulerIngleseTask Scheduler event 200 records that a task action was launched: which task, which instance and the action itself — often the program path that ran.
- 201Action completedTask SchedulerIngleseTask Scheduler event 201 records that a task action completed, with the action and its return code — tells you whether the launched program succeeded.
- 21Session logon succeededRDP LocalSessionManagerIngleseRDP event 21 confirms a session logon on the target: user, session ID and source network address ("LOCAL" for console logons).
- 22Shell startRDP LocalSessionManagerIngleseRDP event 22 is logged when the user's shell (Explorer) starts in a new session, right after the session logon event 21.
- 23Session logoffRDP LocalSessionManagerIngleseRDP event 23 is logged when a Remote Desktop or console session is logged off, closing the session opened by event 21.
- 24Session disconnectedRDP LocalSessionManagerIngleseRDP event 24 is logged when a Remote Desktop session is disconnected without logoff, with the user, session ID and client address.
- 25Session reconnectedRDP LocalSessionManagerIngleseRDP event 25 is logged when a user reconnects to an existing disconnected session, with the new client address.
- 39Session disconnected by another sessionRDP LocalSessionManagerIngleseRDP event 39 records that one session was disconnected by another session, as with a session takeover or tscon.
- 40Session disconnect reasonRDP LocalSessionManagerIngleseRDP event 40 gives the reason code for a session disconnect, telling user-initiated disconnects from replaced connections.
- 1149Connection authenticatedRDP RemoteConnectionManagerIngleseRDP event 1149 records an inbound Remote Desktop connection with user, domain and source IP. It means the network connection succeeded, not the logon.
- 1024Outbound connection attemptRDP ClientIngleseRDP client event 1024 is logged on the source host when mstsc starts connecting to a server; the Value field holds the target name or IP.
- 1102Multi-transport connectionRDP ClientIngleseRDP client event 1102 is logged on the source host when the client opens a multi-transport connection; Value holds the server IP address.
- 131TCP connection acceptedRDP RdpCoreTSIngleseRdpCoreTS event 131 is logged when the RDP server accepts a TCP connection, with the client IP and port — even for failed or scanner connections.
- 5857Provider startedWMI-ActivityIngleseWMI-Activity event 5857 logs a WMI provider being loaded: provider name, DLL path and host process. Useful to spot rogue providers and WMI usage.
- 5858Operation errorWMI-ActivityIngleseWMI-Activity event 5858 logs a failed WMI operation with the client machine, user, process ID and the query or method that failed. Noisy but revealing.
- 5860Temporary event consumerWMI-ActivityIngleseWMI-Activity event 5860 logs a temporary WMI event subscription: the namespace, the WQL notification query and the client process that registered it.
- 5861Permanent event consumerWMI-ActivityIngleseWMI-Activity event 5861 logs a permanent WMI event subscription (filter-to-consumer binding), the classic fileless persistence technique.
- 1006Malware found by scanMicrosoft DefenderIngleseDefender event 1006 is logged when the antimalware engine finds malware or unwanted software, with threat name, path and detection source.
- 1007Action taken (engine)Microsoft DefenderIngleseDefender event 1007 records that the antimalware platform took action on detected malware, the engine-level counterpart of event 1117.
- 1008Engine action failedMicrosoft DefenderIngleseDefender event 1008 means Defender could not complete an action on detected malware (engine level); the item may still be on the system.
- 1013Detection history deletedMicrosoft DefenderIngleseDefender event 1013 is logged when Defender's malware detection history is deleted — routine purging, or an attempt to hide past detections.
- 1015Suspicious behavior detectedMicrosoft DefenderIngleseDefender event 1015 is logged when behavior monitoring detects suspicious activity rather than a known file, with threat name and process details.
- 1116Malware detectedMicrosoft DefenderIngleseDefender event 1116 is logged when Microsoft Defender Antivirus detects malware or unwanted software: threat name, file path, process and user.
- 1117Action taken on malwareMicrosoft DefenderIngleseDefender event 1117 confirms Microsoft Defender Antivirus acted on a detection — quarantine, remove, clean or block — with threat, path and action.
- 1118Action on malware failedMicrosoft DefenderIngleseDefender event 1118 means Microsoft Defender Antivirus detected a threat but could not remediate it (non-critical failure) — the item may still be present.
- 1119Critical failure acting on malwareMicrosoft DefenderIngleseDefender event 1119 records a critical error while acting on a detected threat — remediation failed and the threat may still be active.
- 1121ASR rule blocked an operationMicrosoft DefenderIngleseDefender event 1121 is logged when an attack surface reduction (ASR) rule in block mode stops an operation, such as LSASS access or Office child processes.
- 2001Security intelligence update failedMicrosoft DefenderIngleseDefender event 2001 is logged when a security intelligence (signature) update fails, with the versions, update source and error.
- 5000Real-time protection enabledMicrosoft DefenderIngleseDefender event 5000 is logged when real-time protection is turned on — the counterpart of 5001, useful to measure how long protection was off.
- 5001Real-time protection disabledMicrosoft DefenderIngleseDefender event 5001 is logged when real-time protection is turned off — a classic step before attackers drop tools or ransomware.
- 5004Real-time protection config changedMicrosoft DefenderIngleseDefender event 5004 is logged when a real-time protection feature (on-access, behavior monitoring, downloads scanning…) changes configuration.
- 5007Configuration changedMicrosoft DefenderIngleseDefender event 5007 logs every Defender configuration change with old and new values — including exclusions added by attackers.
- 5010Malware scanning disabledMicrosoft DefenderIngleseDefender event 5010 is logged when scanning for malware and potentially unwanted software is disabled — a sign of defense tampering or another AV.
- 5012Virus scanning disabledMicrosoft DefenderIngleseDefender event 5012 is logged when Defender virus scanning is disabled — like 5010, a strong tampering signal unless another antivirus took over.
- 5013Tamper protection blocked a changeMicrosoft DefenderIngleseDefender event 5013 is logged when tamper protection blocks a change to Defender settings — evidence that something tried to weaken the antivirus.
- 3Job createdBITS ClientIngleseBITS event 3 records the creation of a BITS transfer job: job title, job ID, owner and, on newer builds, the process that created it.
- 4Job completedBITS ClientIngleseBITS event 4 records that a BITS transfer job completed: job title, ID, owner, file count and bytes transferred. Confirms a download or upload finished.
- 59Transfer startedBITS ClientIngleseBITS event 59 records that BITS started transferring a job, with the job name and the remote URL — the event that tells you where BITS was downloading from.
- 60Transfer stoppedBITS ClientIngleseBITS event 60 records that BITS stopped transferring a job, with the job name, remote URL and status code — success, failure or interruption.
- 6WSMan session created (client)WinRMIngleseWinRM event 6 is logged on the client when a WS-Management session is created, with the connection string naming the remote host. Source-side PS remoting.
- 91WSMan shell created (server)WinRMIngleseWinRM event 91 is logged on the target when a remote WSMan shell is created, with the resource URI showing whether it is PowerShell remoting or winrs.
- 169User authenticated (legacy)WinRMIngleseWinRM event 169 logs a user authenticating to the WinRM service and the mechanism used. It is defined only in Windows 7 / Server 2008 R2 era manifests.
- 8002EXE or DLL allowedAppLockerIngleseAppLocker event 8002 records that an executable or DLL was allowed to run by an AppLocker rule, with the file path, matching rule and user SID.
- 8003EXE or DLL would be blocked (audit)AppLockerIngleseAppLocker event 8003 records an executable or DLL that ran but would have been blocked if the policy were enforced. Audit-mode view of unapproved code.
- 8004EXE or DLL blockedAppLockerIngleseAppLocker event 8004 records an executable or DLL blocked by an enforced AppLocker policy, with file path, signer, hash and the user who tried to run it.
- 8005MSI or script allowedAppLockerIngleseAppLocker event 8005 records that a script or Windows Installer file was allowed to run by an AppLocker rule, with the file path, rule and user SID.
- 8006Script or MSI would be blockedAppLockerIngleseAppLocker event 8006 records a script or MSI that ran but would have been blocked if the policy were enforced — audit-mode view of unapproved scripts.
- 8007MSI or script blockedAppLockerIngleseAppLocker event 8007 records a script or Windows Installer file blocked by an enforced AppLocker policy, with the path, hash and user who tried to run it.
- 2004Rule addedWindows FirewallIngleseFirewall event 2004 records a new Windows Firewall rule with its program, ports, action and the user and process that added it. On by default, richer than 4946.
- 2005Rule modifiedWindows FirewallIngleseFirewall event 2005 records a change to an existing Windows Firewall rule, with the rule's new settings and the user and process that changed it. On by default.
- 2006Rule deletedWindows FirewallIngleseFirewall event 2006 records the deletion of a Windows Firewall rule, with the rule ID, name, and the user SID and process that removed it. On by default.
- 2033All rules deletedWindows FirewallIngleseFirewall event 2033 records that every rule was deleted from a Windows Firewall rule store, with the user SID and process responsible. Rare and worth reviewing.
- 1006Disk connected (partition data)PartitionInglesePartition event 1006 records a disk's vendor, model, serial, capacity and raw MBR/VBR bytes on connection. Rich USB evidence, incl. volume serials.
- 400Device configuredKernel-PnPIngleseKernel-PnP event 400 is logged when a device is configured with a driver: instance ID, driver INF and class. Dates USB storage and other device connections.
- 410Device startedKernel-PnPIngleseKernel-PnP event 410 is logged when a device is started with its driver and service. Dates USB storage connections, including repeat ones.
- 8001Outgoing authentication auditNTLMIngleseNTLM event 8001 logs outgoing NTLM authentication from this computer: target server, supplied user and client process. Shows which apps still use NTLM.
- 8002Incoming authentication auditNTLMIngleseNTLM event 8002 logs incoming NTLM authentication processed by this server, with the calling process and its identity. Maps which servers still accept NTLM.
- 8003Domain server authentication auditNTLMIngleseNTLM event 8003 logs NTLM authentication of a domain account received by this server: user, domain, client workstation, logon type and process. Audit only.
- 8004Domain controller authentication auditNTLMIngleseNTLM event 8004 is logged on domain controllers for each NTLM authentication they validate: user, client workstation and the server that forwarded it.
- 3033Image blocked (signing level)Code IntegrityIngleseCode Integrity event 3033: a process tried to load a DLL or driver below its required signing level and was blocked. Seen with LSA protection.
- 3077App Control (WDAC) blockCode IntegrityIngleseCode Integrity event 3077 is the main App Control for Business (WDAC) enforcement block: a file failed the active policy and was prevented from loading.
- 31001Logon failureSMB ClientIngleseSMB client event 31001 records a failed authentication from this computer to an SMB server, with server name, user name, SPN and error codes. Source-side view.
- 551SMB session auth failureSMB ServerIngleseSMB server event 551 records a failed SMB session authentication, with client address, user name and status code. Complements 4625 for SMB brute force.
- 307Document printedPrintServiceInglesePrintService event 307 logs each printed job: document, user, client, printer, size and pages. Off by default; key for insider print exfiltration.
- 808Spooler plug-in load failedPrintServiceInglesePrintService Admin event 808: the spooler failed to load a plug-in or driver DLL. Error 0x45A with an odd DLL path is a PrintNightmare sign.
- 3006DNS query startedDNS ClientIngleseDNS Client event 3006 records the start of a DNS query on the host: queried name, record type and DNS servers. Channel is off by default; pair it with 3008.
- 3008DNS query completedDNS ClientIngleseDNS Client event 3008 records a completed DNS query: name, type, status code and resolved addresses. Host-level DNS history; channel is off by default.
- 4sshd informational messageOpenSSHIngleseOpenSSH event 4 carries informational sshd messages on Windows: accepted and failed logons, invalid users and disconnects, with source IP and port in the text.