# Windows Event ID Lookup Tool: Search and Get Explanation

:root{--lm-accent:rgb(15,15,215);--lm-bg:#f5f5f5;--lm-text:#041c35;--lm-muted:#6b7280;--lm-line:#e5e7eb;--lm-info:#0f0fd7;--lm-warn:#b45309;--lm-crit:#b91c1c}
*{box-sizing:border-box}.lm-estimator{font-family:Inter,system-ui,-apple-system,BlinkMacSystemFont,"Segoe UI",sans-serif;padding:64px 16px 80px;background:var(--lm-bg);color:var(--lm-text)}
.lm-inner{max-width:1200px;margin:0 auto}.lm-header{text-align:center;margin-bottom:28px}.lm-eyebrow{font-size:.875rem;font-weight:700;text-transform:uppercase;color:var(--lm-accent);margin-bottom:8px}.lm-title{font-family:Sora,sans-serif;font-size:clamp(1.75rem,4vw,3rem);line-height:1.12;margin:0 0 16px}.lm-subtitle{max-width:820px;margin:0 auto;font-size:1.05rem;line-height:1.65}
.lm-search-card{background:#fff;border-radius:28px;padding:22px 24px;box-shadow:0 18px 45px rgba(15,23,42,.08);margin-bottom:22px}
.lm-search-row{display:flex;gap:12px;flex-wrap:wrap}
.lm-search-input-wrap{flex:1 1 320px;position:relative}
#lm-search{width:100%;border:1px solid var(--lm-line);border-radius:999px;padding:14px 18px;font-size:15px;outline:0}
#lm-search:focus{border-color:var(--lm-accent);box-shadow:0 0 0 2px rgba(15,15,215,.12)}
.lm-log-select{border:1px solid var(--lm-line);border-radius:999px;padding:14px 34px 14px 18px;font-size:14px;background:#fff url("data:image/svg+xml;charset=UTF-8,%3Csvg xmlns='http://www.w3.org/2000/svg' viewBox='0 0 20 20'%3E%3Cpath fill='%236b7280' d='M5.5 7.5l4.5 4.5 4.5-4.5z'/%3E%3C/svg%3E") no-repeat right 12px center;-webkit-appearance:none;appearance:none;cursor:pointer}
.lm-chips{display:flex;flex-wrap:wrap;gap:8px;margin-top:14px}
.lm-chip{border:1px solid var(--lm-line);background:#fff;border-radius:999px;padding:7px 14px;font-size:12.5px;font-weight:600;cursor:pointer;color:#3f4650}
.lm-chip.is-active{background:var(--lm-accent);border-color:var(--lm-accent);color:#fff}
.lm-meta-row{display:flex;justify-content:space-between;align-items:center;margin:18px 0 10px;flex-wrap:wrap;gap:10px}
.lm-count{font-size:13px;color:var(--lm-muted)}
.lm-btn{display:inline-flex;justify-content:center;align-items:center;border:0;border-radius:999px;padding:10px 18px;background:var(--lm-accent);color:#fff;font-weight:700;cursor:pointer;box-shadow:0 12px 30px rgba(15,15,215,.3);font-size:13px}
.lm-btn:hover{transform:translateY(-1px)}
.lm-results{display:flex;flex-direction:column;gap:12px}
.lm-card{background:#fff;border-radius:22px;padding:20px 22px;box-shadow:0 10px 30px rgba(15,23,42,.06);display:grid;grid-template-columns:96px 1fr;gap:18px}
.lm-id-col{display:flex;flex-direction:column;align-items:center;gap:8px}
.lm-id{font-family:Sora,sans-serif;font-size:1.6rem;font-weight:800;color:var(--lm-accent)}
.lm-sev{font-size:10.5px;font-weight:700;text-transform:uppercase;letter-spacing:.04em;padding:3px 9px;border-radius:999px}
.lm-sev-info{background:rgba(15,15,215,.1);color:var(--lm-info)}
.lm-sev-warn{background:rgba(180,83,9,.12);color:var(--lm-warn)}
.lm-sev-crit{background:rgba(185,28,28,.12);color:var(--lm-crit)}
.lm-body h4{margin:0 0 4px;font-size:1.02rem}
.lm-tags{display:flex;gap:6px;flex-wrap:wrap;margin-bottom:8px}
.lm-tag{font-size:11px;color:var(--lm-muted);background:#f9fafb;border:1px solid var(--lm-line);border-radius:999px;padding:2px 9px}
.lm-desc{font-size:13.5px;line-height:1.6;margin:0 0 8px}
.lm-risk-label{font-size:11px;font-weight:700;text-transform:uppercase;color:#9ca3af;margin:2px 0 4px}
.lm-risk{font-size:13px;line-height:1.55;margin:0 0 8px;padding:9px 12px;border-radius:12px;background:rgba(15,15,215,.05);border:1px solid rgba(15,15,215,.1);color:#2b3648}
.lm-causes{font-size:12.5px;line-height:1.55;color:#4b5563;margin:0;padding-left:18px}
.lm-causes li{margin-bottom:2px}
.lm-causes-label{font-size:11px;font-weight:700;text-transform:uppercase;color:#9ca3af;margin:8px 0 4px}
.lm-footnote{max-width:900px;margin:26px auto 0;font-size:11px;color:#8a919d;line-height:1.6;text-align:center}
@media(max-width:620px){.lm-estimator{padding:44px 12px 60px}.lm-search-card{padding:18px}.lm-card{grid-template-columns:1fr;text-align:left}.lm-id-col{flex-direction:row;justify-content:flex-start}}
Windows Event ID lookup

# Windows Event ID Lookup Tool

Search Windows Security, System, Application, Active Directory, DNS/DHCP Server, Sysmon and PowerShell event IDs by number or keyword. Get a plain-language explanation, why it matters for monitoring, and what typically causes it.

Windows logs thousands of distinct event IDs across its many components — this isn’t a complete catalog. It’s a curated reference of the IDs most frequently searched for and relied on in security and IT monitoring.



All logsSecurity logSystem logApplication logPowerShell logsSysmonDNS ServerDHCP Server











Descriptions, severity guidance, and common causes on this page are original summaries written for quick triage, not reproductions of Microsoft’s official event documentation. They cover commonly encountered IDs across Windows Server and Windows 10/11 Security, System, and Application logs, Active Directory trust/AD DS events, DNS and DHCP Server audit logging, Sysmon, and PowerShell logging — not every event ID Windows or these components can ever emit. DHCP Server entries reference the DHCP audit-log codes written to its own CSV log file, not standard Event Viewer IDs. Exact IDs, fields, and behavior can vary by OS version, audit policy, and provider version. For authoritative field-level detail, refer to Microsoft’s own Windows Security documentation.




(function(){
'use strict';
// Each entry: [id, log, category, title, description, severity('info'|'warn'|'crit'), causes[]]
const DATA=[
[4624,"Security","Logon and Logoff","An account logged on successfully","Recorded whenever any account, human or service, completes a logon. The Logon Type field is what actually matters: 2 is an interactive console logon, 3 is a network logon (e.g. SMB), 4 is batch, 5 is a service logon, 7 is an unlock, 10 is RemoteInteractive (RDP), and 11 is a cached credential logon.","info",["Normal daily user and service activity","RDP or remote admin sessions (Type 10)","Scheduled tasks or services starting (Type 4/5)"],"On its own this is background noise, but logon type combined with source IP/time is central to spotting anomalous access \u2014 e.g. Type 10 (RDP) logons from unfamiliar external addresses, or a service account suddenly logging on interactively."],
[4625,"Security","Logon and Logoff","An account failed to log on","Logged whenever a logon attempt is rejected. The Status/Sub Status codes explain the reason (wrong password, disabled account, expired password, logon-hours restriction, etc.). A high volume from one source is a classic brute-force or password-spray signature.","warn",["Mistyped credentials","Brute-force or password-spraying attempts","An account disabled, locked, or expired"],"A high-frequency stream of 4625s against one or many accounts is the primary signal for brute-force and password-spraying attacks; a wide spread of failures across many accounts with few attempts each is a spraying pattern that evades simple lockout-based defenses."],
[4634,"Security","Logon and Logoff","An account was logged off","Marks the end of a logon session; pair with the corresponding 4624 to compute session duration.","info",["Normal session end","User sign-out or scheduled task completion"],"Low security relevance on its own; mainly useful for building session timelines alongside 4624 and 4648."],
[4647,"Security","Logon and Logoff","User-initiated logoff","Logged when a user explicitly signs out, as opposed to a session simply timing out or being terminated.","info",["Normal user sign-out"],"Low security relevance on its own; helps distinguish a deliberate sign-out from a session that was killed or timed out."],
[4648,"Security","Logon and Logoff","A logon was attempted using explicit credentials","Fires when a process presents a different set of credentials than the one it's running under — RunAs, a scheduled task with stored credentials, or tools used for lateral movement. Frequently one of the first indicators of credential reuse across hosts.","warn",["Legitimate RunAs / admin activity","Scheduled tasks configured with stored credentials","Lateral movement using stolen credentials"],"One of the clearest lateral-movement indicators in the whole log \u2014 attackers commonly use stolen credentials with tools like PsExec or WMI to authenticate to other hosts as a different account than the one they're currently logged in as."],
[4672,"Security","Logon and Logoff","Special privileges assigned to a new logon","Indicates the logon session was granted administrator- or system-equivalent rights (e.g. SeDebugPrivilege). A reliable marker for privileged sessions worth correlating with what that session did next.","warn",["Legitimate administrator logon","Privilege escalation following a compromised account"],"Marks every session that holds administrator- or system-equivalent rights; unexpected 4672 events for accounts that shouldn't be privileged are a strong indicator of privilege escalation or token abuse."],
[4778,"Security","Logon and Logoff","A session was reconnected to a Windows station","Typically an RDP session resuming after a disconnect rather than a fresh logon.","info",["Normal RDP reconnect","Session takeover if the reconnect source is unexpected"],"Worth correlating the reconnect source against the original session \u2014 an RDP session reconnecting from a different, unexpected location can indicate session hijacking."],
[4779,"Security","Logon and Logoff","A session was disconnected from a Windows station","Typically an RDP session going into a disconnected-but-still-running state.","info",["Normal RDP disconnect (user closed the client without logging off)"],"Low risk signal alone; useful context for RDP session timelines."],
[4800,"Security","Logon and Logoff","The workstation was locked","Session locked, either by the user or by policy (screen-lock timeout).","info",["User locked their session","Idle-timeout policy"],"Low security relevance; mainly used to establish user-presence timelines."],
[4801,"Security","Logon and Logoff","The workstation was unlocked","Session unlocked after being locked.","info",["User returned and unlocked their session"],"Low security relevance; can help confirm whether a physical user, rather than a remote session, was active at a given time."],
[4802,"Security","Logon and Logoff","The screen saver was invoked","Screen saver activated after the idle timeout.","info",["Idle timeout reached"],"Low security relevance; a minor supporting signal for idle-time analysis."],
[4803,"Security","Logon and Logoff","The screen saver was dismissed","User returned and dismissed the screen saver.","info",["User activity resumed"],"Low security relevance; supporting signal for user-presence timelines."],
[4964,"Security","Logon and Logoff","Special groups were assigned to a new logon","Logged when a logon's group memberships match a defined 'Special Groups' list used for extra auditing (commonly used to flag admin-equivalent logons).","warn",["Sign-in by an account in a monitored privileged group"],"Purpose-built for security monitoring \u2014 configure the 'Special Groups' list with your privileged groups (Domain Admins, Enterprise Admins, etc.) so any sign-in by a member of those groups is flagged automatically."],

[4720,"Security","Account Management","A user account was created","New local or domain user account created — always worth confirming was expected, especially outside change windows.","warn",["Legitimate onboarding / provisioning","A rogue or backdoor account created after compromise"],"Attackers who gain administrative access frequently create a new account as a backdoor that survives password resets on the compromised account; any 4720 outside a known onboarding process deserves review."],
[4722,"Security","Account Management","A user account was enabled","A previously disabled account was re-enabled.","warn",["Legitimate reactivation","Re-enabling a dormant or compromised account"],"Re-enabling a stale or previously disabled account is a common way to reactivate a dormant backdoor or a compromised account that was thought to be neutralized."],
[4723,"Security","Account Management","An account attempted to change its own password","Self-service password change attempt (success or failure detail is in the event).","info",["Routine password rotation"],"Low risk in isolation; a burst of these across many accounts in a short window can indicate a credential-stuffing or password-spray campaign that also attempts resets."],
[4724,"Security","Account Management","An attempt was made to reset an account's password","Someone else (admin or helpdesk tool) reset the account's password, rather than the user changing it themselves.","warn",["Legitimate helpdesk password reset","Account takeover preparation"],"A password reset performed by someone other than the account owner is a key step in account-takeover playbooks (e.g. a social-engineered helpdesk reset), so unexpected 4724 events for privileged accounts are high-value to review."],
[4725,"Security","Account Management","A user account was disabled","Account disabled by an administrator or automated process.","info",["Offboarding","Security response to a suspected compromise"],"Low-to-moderate risk on its own; a wave of disables outside a change window can indicate a destructive or disruptive action following a compromise."],
[4726,"Security","Account Management","A user account was deleted","Account permanently removed.","warn",["Offboarding cleanup","An attacker covering tracks by deleting an account they created"],"Deleting an account an attacker created is a common way to remove evidence after establishing other persistence; also worth confirming deletions were authorized change requests."],
[4727,"Security","Account Management","A security-enabled global group was created","New domain global group created.","info",["Normal AD administration"],"Low risk alone; worth reviewing if the new group is later granted broad permissions."],
[4728,"Security","Account Management","A member was added to a security-enabled global group","Membership change to a global group — check especially for additions to privileged groups.","warn",["Routine access provisioning","Unauthorized privilege escalation"],"Additions to groups with domain-wide privileges (e.g. Domain Admins) are one of the highest-value events to alert on for detecting privilege escalation."],
[4729,"Security","Account Management","A member was removed from a security-enabled global group","Membership removed from a global group.","info",["Routine access de-provisioning"],"Low risk on its own; useful for confirming legitimate offboarding."],
[4730,"Security","Account Management","A security-enabled global group was deleted","Global group removed from the domain.","info",["Planned AD cleanup"],"Low risk alone, though deleting a group that held security-relevant permissions can have downstream access implications worth reviewing."],
[4731,"Security","Account Management","A security-enabled local group was created","New local group created on a member server or workstation.","info",["Normal local administration"],"Low risk alone; review if the new group is granted administrative rights on the host."],
[4732,"Security","Account Management","A member was added to a security-enabled local group","Local group membership changed — additions to the local Administrators group are especially high-signal.","warn",["Legitimate local admin grant","Privilege escalation on an endpoint"],"Additions to the local Administrators group on any endpoint are a classic local privilege-escalation indicator, especially when performed by a non-admin account or from a remote session."],
[4733,"Security","Account Management","A member was removed from a security-enabled local group","Local group membership removed.","info",["Routine access cleanup"],"Low risk alone; useful for confirming legitimate access changes."],
[4734,"Security","Account Management","A security-enabled local group was deleted","Local group removed.","info",["Planned local administration"],"Low risk alone."],
[4735,"Security","Account Management","A security-enabled local group was changed","Local group's attributes (not membership) were modified.","info",["Administrative change to group settings"],"Low risk alone; review changes to groups with elevated local rights."],
[4737,"Security","Account Management","A security-enabled global group was changed","Global group's attributes were modified.","info",["Administrative change to group settings"],"Low risk alone; review changes to groups with domain-wide elevated rights."],
[4738,"Security","Account Management","A user account was changed","Covers a broad set of attribute changes — flags, expiration date, allowed logon workstations, etc. Correlate with the changed-attribute list in the event for context.","warn",["Routine account maintenance","Attacker weakening account restrictions (e.g. disabling password expiry)"],"Attackers sometimes modify account flags to disable password expiration, remove logon restrictions, or clear the account's 'sensitive' flag to make it easier to abuse long-term \u2014 the changed-attribute list in the event is important to review."],
[4740,"Security","Account Management","A user account was locked out","Account locked after exceeding the failed-logon threshold.","warn",["Legitimate user mistyping their password repeatedly","Brute-force attack against the account"],"A burst of lockouts across the environment, especially timed together, often indicates an automated brute-force or password-spray tool testing many accounts."],
[4741,"Security","Account Management","A computer account was created","New machine account joined to the domain.","info",["Legitimate device provisioning / domain join"],"Low risk alone; unexpected machine joins outside change management can indicate rogue devices being added to the domain."],
[4742,"Security","Account Management","A computer account was changed","Machine account attributes modified.","info",["Routine device management"],"Low risk alone."],
[4743,"Security","Account Management","A computer account was deleted","Machine account removed from the domain.","info",["Planned device decommissioning"],"Low risk alone."],
[4756,"Security","Account Management","A member was added to a security-enabled universal group","Universal group membership changed — relevant in multi-domain forests.","warn",["Routine access provisioning","Cross-domain privilege escalation"],"Additions to forest-wide privileged groups (e.g. Enterprise Admins) are high-value to alert on, since universal group membership applies across the entire forest."],
[4757,"Security","Account Management","A member was removed from a security-enabled universal group","Universal group membership removed.","info",["Routine access cleanup"],"Low risk alone."],
[4767,"Security","Account Management","A user account was unlocked","A previously locked-out account was unlocked, typically by an administrator.","info",["Helpdesk unlocking a legitimate user"],"Low risk alone; confirm the unlock was performed by an authorized helpdesk/admin action rather than the account itself bypassing lockout controls."],
[4780,"Security","Account Management","ACL set on accounts that are members of administrator groups","Logged when Windows resets the security descriptor on accounts belonging to privileged groups.","info",["Automatic AdminSDHolder enforcement in Active Directory"],"Normally an automatic AD housekeeping event (AdminSDHolder); worth noting mainly because unusually frequent occurrences can indicate repeated tampering with permissions on protected accounts."],

[4768,"Security","Kerberos and NTLM","A Kerberos authentication ticket (TGT) was requested","Logged on the domain controller when a user or service requests an initial Kerberos ticket — effectively the domain-controller-side view of a logon.","info",["Normal domain sign-in","Requests for a non-existent or disabled account (worth investigating)"],"Requests tied to non-existent or disabled accounts, or a sudden spike from one source, can indicate account enumeration or a brute-force attempt against Kerberos pre-authentication."],
[4769,"Security","Kerberos and NTLM","A Kerberos service ticket was requested","Logged whenever a client requests access to a specific service. A useful trail for tracking which resources an account accessed, and central to spotting Kerberoasting attempts (unusual volumes of ticket requests for service accounts).","warn",["Normal access to a file share, SQL instance, or other Kerberos-authenticated service","Kerberoasting reconnaissance"],"An unusually high volume of service-ticket requests for accounts with Service Principal Names (SPNs), especially using weak (RC4) encryption, is the signature of Kerberoasting \u2014 an offline password-cracking attack against service accounts."],
[4770,"Security","Kerberos and NTLM","A Kerberos service ticket was renewed","An existing ticket was renewed rather than reissued from scratch.","info",["Normal ticket lifecycle management"],"Low risk alone."],
[4771,"Security","Kerberos and NTLM","Kerberos pre-authentication failed","Usually indicates a wrong password was supplied during Kerberos authentication; repeated failures for one account suggest brute-forcing.","warn",["User mistyping a password","Brute-force attempt against a specific account"],"Repeated pre-authentication failures against one account are a strong brute-force indicator; a wide spread of failures across many accounts from one source suggests password spraying."],
[4772,"Security","Kerberos and NTLM","A Kerberos authentication ticket request failed","The TGT request itself failed for a reason other than bad password (e.g. clock skew, encryption type mismatch).","warn",["Time sync issues between client and domain controller","Misconfigured or incompatible encryption settings"],"Usually benign (clock skew, encryption mismatch), but worth checking in bulk for signs of tooling probing Kerberos configuration."],
[4773,"Security","Kerberos and NTLM","A Kerberos service ticket request failed","A service ticket request was rejected.","warn",["Access to a service the account is not authorized for","Ticket manipulation attempts"],"Can indicate reconnaissance against services the requesting account isn't authorized for."],
[4776,"Security","Kerberos and NTLM","The domain controller attempted to validate credentials (NTLM)","Logged when NTLM (rather than Kerberos) is used to authenticate — common for local logons, legacy applications, or logons by IP address.","info",["Legacy application authentication","Logons that bypass Kerberos (worth investigating in a hardened environment)"],"Because NTLM authentication is weaker than Kerberos and lacks the same protections, a rise in NTLM logons in an otherwise Kerberos-first environment can indicate a downgrade attack or an NTLM relay attempt."],
[4777,"Security","Kerberos and NTLM","The domain controller failed to validate credentials","NTLM credential validation failed.","warn",["Wrong password on an NTLM-authenticated logon","Credential-stuffing attempts"],"Repeated NTLM validation failures against a single account are a brute-force or credential-stuffing indicator."],

[4673,"Security","Privilege Use","A privileged service was called","An API requiring a sensitive privilege (e.g. backup or debug privilege) was invoked.","warn",["Legitimate backup or system tooling","Privilege abuse by malware or an attacker"],"Because privileges like SeDebugPrivilege can be used to read memory from other processes (including LSASS for credential theft), unexpected use of this event by non-security tooling is worth investigating."],
[4674,"Security","Privilege Use","An operation was attempted on a privileged object","Sensitive object access requiring elevated rights.","warn",["Administrative maintenance","Attempted tampering with a protected object"],"Indicates elevated-rights access to a sensitive object; review in combination with what the object was and who requested access."],

[4688,"Security","Process Tracking","A new process was created","Fires every time a process starts. With command-line auditing enabled via Group Policy, this becomes one of the single most valuable events for spotting malicious scripts, living-off-the-land binaries, and unusual parent-child process chains.","warn",["Normal application and script execution","Malware execution or attacker tooling"],"The backbone of endpoint detection on native Windows logging \u2014 the command line reveals living-off-the-land techniques (encoded PowerShell, LOLBins like certutil or rundll32), and unusual parent-child relationships (e.g. Office spawning cmd.exe) are one of the most reliable signs of a phishing payload executing."],
[4689,"Security","Process Tracking","A process exited","Marks process termination; useful for building process lifetimes when paired with 4688.","info",["Normal process completion"],"Low risk alone; supporting detail for process-lifetime analysis."],
[4696,"Security","Process Tracking","A primary token was assigned to a process","Logged when a process is started with a different security token than its parent, often via RunAs or scheduled tasks.","warn",["Legitimate impersonation for scheduled tasks","Token manipulation for privilege escalation"],"Token manipulation is a documented privilege-escalation and impersonation technique, so unexpected 4696 events outside of scheduled-task or RunAs contexts merit review."],

[4698,"Security","Scheduled Tasks","A scheduled task was created","New Task Scheduler job registered. Attackers commonly use scheduled tasks for persistence, so unexpected creations deserve a look.","warn",["Legitimate automation or maintenance job","Persistence mechanism planted by an attacker"],"Scheduled tasks are one of the most common persistence mechanisms in real intrusions; a new task that runs a script, downloads a payload, or runs under SYSTEM outside of change management is high priority to investigate."],
[4699,"Security","Scheduled Tasks","A scheduled task was deleted","An existing scheduled task was removed.","info",["Routine cleanup", "Attacker removing evidence"],"Can represent an attacker cleaning up a task after it has served its purpose, particularly if it follows shortly after a related 4698."],
[4700,"Security","Scheduled Tasks","A scheduled task was enabled","A disabled task was re-enabled.","info",["Routine administration"],"Re-enabling a previously disabled task can indicate reactivation of a dormant persistence mechanism."],
[4701,"Security","Scheduled Tasks","A scheduled task was disabled","A task was turned off without being deleted.","info",["Routine administration"],"Low risk alone."],
[4702,"Security","Scheduled Tasks","A scheduled task was updated","An existing task's configuration or trigger was changed.","warn",["Legitimate maintenance","An attacker modifying an existing task to run malicious code"],"Modifying an existing, trusted task to run additional or different commands is a stealthier persistence technique than creating a brand-new task, since it doesn't trigger a fresh 4698."],

[4656,"Security","Object and File Access","A handle to an object was requested","Logged when a process requests access to a file, registry key, or other securable object, prior to actually reading or writing it. High-volume; usually filtered to specific sensitive objects.","info",["Normal file/registry access under an active audit policy"],"Low signal in isolation given its volume; becomes valuable when scoped to specific sensitive files, shares, or registry keys via SACLs."],
[4657,"Security","Object and File Access","A registry value was modified","A monitored registry value was changed — useful for tracking persistence keys (Run keys, services, etc.).","warn",["Legitimate software configuration","Registry-based persistence being installed"],"Central to detecting registry-based persistence (Run/RunOnce keys, service ImagePath changes, etc.) when scoped to the keys attackers commonly abuse."],
[4658,"Security","Object and File Access","The handle to an object was closed","Pairs with 4656 to bound how long an object was open.","info",["Normal object lifecycle"],"Low risk alone; supporting detail for 4656 timelines."],
[4660,"Security","Object and File Access","An object was deleted","A monitored file, folder, or object was deleted.","warn",["Routine file management","Data destruction or evidence removal"],"Deletion of monitored files can indicate data destruction, ransomware activity, or evidence removal, depending on what was deleted."],
[4663,"Security","Object and File Access","An attempt was made to access an object","Records the specific access performed (read/write/delete) on an audited file, folder, or registry key — the core event for tracking sensitive-data access.","warn",["Legitimate access to a monitored file share","Unauthorized access to sensitive data"],"The primary event for detecting unauthorized access to sensitive files and folders when File System Access Auditing (SACLs) is configured on data of interest."],
[4670,"Security","Object and File Access","Permissions on an object were changed","An object's ACL/DACL was modified.","warn",["Legitimate permission management","An attacker widening access to a file or folder"],"Widening permissions on a sensitive file, folder, or registry key is a common step to make data accessible for later exfiltration or to plant a persistence artifact accessible by a lower-privileged account."],
[5140,"Security","Object and File Access","A network share object was accessed","Logged when a shared folder is accessed over the network.","info",["Normal file-share usage","Reconnaissance or data-staging activity"],"Baseline share-access activity; unusual access patterns (off-hours, unfamiliar accounts, unusually broad enumeration) can indicate reconnaissance ahead of data staging."],
[5142,"Security","Object and File Access","A network share object was added","A new network share was created.","warn",["Legitimate share provisioning","Attacker creating a share for staging or exfiltration"],"New shares created outside change management can indicate an attacker staging a location to collect or exfiltrate data."],
[5143,"Security","Object and File Access","A network share object was modified","An existing share's settings changed.","info",["Routine share administration"],"Low risk alone; review if permissions were widened."],
[5144,"Security","Object and File Access","A network share object was deleted","A network share was removed.","info",["Routine share administration"],"Low risk alone."],
[5145,"Security","Object and File Access","A network share was checked for access permission","Logged for each file accessed on a share, recording whether the requesting account was granted or denied access — very high volume, usually enabled selectively.","info",["Normal file-share activity, useful for detailed forensic timelines"],"Very high volume, but when correlated with 5140 gives per-file evidence of what was actually read from a share, useful for scoping data-exposure incidents."],

[4715,"Security","Policy and Audit","The audit policy on an object was changed","A SACL (audit settings) on a specific object was modified.","warn",["Legitimate audit tuning","An attacker disabling auditing on a target object"],"Disabling auditing on a specific sensitive object is a targeted way for an attacker to become invisible on that one resource while leaving broader logging intact."],
[4719,"Security","Policy and Audit","The system audit policy was changed","The domain- or machine-wide audit policy itself was modified — a high-value event since it can silence future detections.","crit",["Legitimate policy tuning by an administrator","An attacker disabling security auditing to operate undetected"],"One of the most consequential events in the whole list \u2014 a change here can silence entire categories of future detections, so it should be tightly restricted and always alerted on."],
[4739,"Security","Policy and Audit","Domain policy was changed","Domain-wide policy settings (e.g. password or lockout policy) were modified.","warn",["Planned policy update","Weakening password/lockout policy to enable brute-forcing"],"Weakening password complexity, minimum length, or account-lockout thresholds directly increases the domain's exposure to brute-force and password-spraying attacks."],
[4907,"Security","Policy and Audit","Auditing settings on an object were changed","Object-level audit settings modified (similar to 4715, broader object types).","warn",["Legitimate audit configuration change"],"Similar risk to 4715 \u2014 an attacker disabling auditing on an object to operate against it without leaving a trail."],
[1102,"Security","Policy and Audit","The audit log was cleared","The Security event log was manually cleared. One of the highest-value alerts in the entire list — legitimate reasons are rare, and it's a common step in covering tracks after an intrusion.","crit",["Planned log maintenance (rare and should be documented)","An attacker erasing evidence of their activity"],"Among the strongest indicators of malicious activity in Windows logging: legitimate reasons to manually clear the Security log are rare, and doing so is a well-known step attackers take to erase evidence after achieving their objectives."],
[1104,"Security","Policy and Audit","The security log is full","The Security event log has reached its maximum size and, depending on retention settings, may start overwriting old events or stop logging.","warn",["Log size configured too small for event volume","A flood of events, possibly from an attack, filling the log quickly"],"Can be entirely benign (undersized log), but if it coincides with a burst of activity, it may indicate an attacker flooding the log to push earlier evidence out via overwrite."],
[1105,"Security","Policy and Audit","Event log was automatically archived","The event log service performed a scheduled backup/rollover of the log file.","info",["Normal log rotation"],"Low security relevance; routine log housekeeping."],
[1108,"Security","Policy and Audit","The event logging service encountered an error","The Windows Event Log service itself hit an internal error while processing events.","warn",["Disk or resource pressure on the logging subsystem","Log corruption"],"Worth investigating if it results in a gap in logging coverage, since an attacker could exploit any resulting blind spot."],

[5136,"Security","Directory Service and GPO","A directory service object was modified","An Active Directory object (including Group Policy Objects) was changed — check the object class and attribute in the event for what actually changed.","warn",["Routine AD or GPO administration","Malicious GPO tampering (e.g. pushing a scheduled task or script to many machines)"],"GPOs are a powerful lateral-movement and persistence vector \u2014 a modified GPO can push a malicious scheduled task, script, or startup item to every computer in its scope, so unexpected GPO changes deserve prompt review."],
[5137,"Security","Directory Service and GPO","A directory service object was created","A new AD object was created.","info",["Normal AD provisioning"],"Low risk alone; review new objects with security-relevant classes (e.g. new GPOs, trusts)."],
[5138,"Security","Directory Service and GPO","A directory service object was undeleted","A previously deleted AD object was restored from the tombstone/recycle bin.","info",["Legitimate object recovery"],"Low risk alone; can be relevant to forensic timelines if the restored object had been deleted maliciously."],
[5139,"Security","Directory Service and GPO","A directory service object was moved","An AD object was moved to a different container or OU.","info",["Routine AD reorganization"],"Low risk alone; moving an object into a less-restricted OU can unintentionally loosen the Group Policy or delegation applied to it."],
[5141,"Security","Directory Service and GPO","A directory service object was deleted","An AD object was deleted.","warn",["Routine cleanup","Deletion of a security-relevant object such as a GPO or trust"],"Deletion of a GPO, trust, or other security-relevant AD object can disrupt security controls or indicate an attacker removing evidence of prior tampering."],
[4662,"Security","Directory Service and GPO","An operation was performed on an Active Directory object","Records a specific operation against an AD object's properties, including replication-related access rights — the event most associated with detecting DCSync-style credential extraction when the accessed properties involve replication.","crit",["Normal AD replication between domain controllers","DCSync-style credential dumping from a non-DC host"],"When the accessed properties include replication-related rights and the requester is not a domain controller, this is one of the clearest available signals of a DCSync attack extracting password hashes from AD."],
[4706,"Security","Directory Service and GPO","A new trust was created to a domain","Logged on a domain controller whenever a new inter-domain or inter-forest trust relationship is established.","warn",["Planned trust setup between domains/forests","An attacker establishing a rogue trust for persistence or access"],"An unexpected trust can open an authentication path from another domain/forest into yours; attackers with domain admin rights have used rogue trusts to maintain long-term access even after their original foothold is remediated."],
[4707,"Security","Directory Service and GPO","A trust to a domain was removed","An existing domain trust relationship was deleted.","warn",["Planned decommissioning of a trust","Disruption of authentication paths, intentional or malicious"],"Low risk alone, though unexpected removal can disrupt intended cross-domain access; also occasionally used to cover tracks after a rogue trust was created and abused."],
[4716,"Security","Directory Service and GPO","Trusted domain information was modified","An existing domain trust's configuration (e.g. direction, attributes) was changed.","warn",["Legitimate trust reconfiguration","Weakening of trust security settings (e.g. enabling SID filtering bypass)"],"Changes to trust attributes (e.g. disabling SID filtering or quarantine) can weaken the security boundary between domains and enable SID-history-based privilege escalation across the trust."],
[4713,"Security","Directory Service and GPO","The Kerberos policy was changed","Domain-wide Kerberos ticket policy settings (lifetimes, renewal, etc.) were modified.","warn",["Planned policy tuning","Extending ticket lifetimes to ease persistence with stolen tickets"],"Extending maximum ticket lifetimes makes stolen Kerberos tickets (e.g. via Pass-the-Ticket) usable by an attacker for longer, so unexpected changes here are worth reviewing."],
[4765,"Security","Directory Service and GPO","SID History was added to an account","An account had a SID History value added — legitimate during domain migrations, but a well-known technique for smuggling in extra group memberships (a 'SID history injection' attack).","crit",["Legitimate domain migration tooling (e.g. ADMT)","SID history injection used to grant hidden privileged access"],"A textbook technique for smuggling in hidden privileged group memberships (a SID history injection attack); outside of an active, documented domain migration, this event deserves immediate investigation."],
[4766,"Security","Directory Service and GPO","An attempt to add SID History to an account failed","A SID History addition was attempted but rejected.","warn",["A failed migration operation","A blocked SID history injection attempt"],"A failed attempt still indicates someone tried the SID history injection technique and should be investigated even though it didn't succeed."],
[4794,"Security","Directory Service and GPO","An attempt was made to set the Directory Services Restore Mode administrator password","Logged when the DSRM local administrator password on a domain controller is set or changed — that password grants full control of AD if DSRM is ever entered.","crit",["Planned DSRM password rotation (a recommended security practice)","An attacker setting a known DSRM password for a backdoor path into the domain"],"The DSRM password grants full local-administrator-equivalent access to a domain controller outside normal AD authentication; an attacker who sets a known DSRM password can use it as a durable backdoor into the domain."],

[4946,"Security","Firewall","A rule was added to the Windows Firewall exception list","New allow rule added to the local firewall.","warn",["Legitimate application installation opening a required port","An attacker opening a port for remote access or exfiltration"],"Attackers commonly open a port or add an exception to enable remote access tooling or command-and-control traffic, so rule additions outside of known software installs are worth reviewing."],
[4947,"Security","Firewall","A rule was modified in the Windows Firewall exception list","An existing firewall rule was changed.","warn",["Legitimate rule tuning","Modification to allow malicious traffic"],"Modifying an existing trusted rule to permit broader traffic is a stealthier way to open access than creating an obviously new rule."],
[4948,"Security","Firewall","A rule was deleted from the Windows Firewall exception list","A firewall rule was removed.","warn",["Legitimate cleanup","Removal of a blocking rule to permit malicious traffic"],"Removing a rule that was blocking traffic can be used to clear the way for malicious network activity."],
[4950,"Security","Firewall","A Windows Firewall setting was changed","A firewall profile setting (not a specific rule) was modified.","warn",["Legitimate configuration change","Weakening of firewall posture"],"Disabling the firewall profile entirely, or loosening default-block behavior, removes a layer of network defense on the host."],
[4954,"Security","Firewall","Group Policy settings for Windows Firewall were changed","GPO-driven firewall policy changed for the machine.","warn",["Planned GPO update","Unauthorized policy change disabling firewall protections"],"A GPO-level change affects every machine in scope at once, so unauthorized changes here have a much larger blast radius than a single-host rule change."],

[400,"PowerShell","PowerShell","A new PowerShell engine session started","Marks the start of a PowerShell host session (console, ISE, or a script invoking the engine).","info",["Normal administrative or scripted activity"],"Low risk alone; PowerShell is used constantly for legitimate administration, so this event mainly provides session context for the higher-signal 4103/4104 events."],
[403,"PowerShell","PowerShell","A PowerShell engine session stopped","Marks the end of a PowerShell host session.","info",["Normal session completion"],"Low risk alone."],
[4103,"PowerShell","PowerShell","PowerShell module logging recorded a pipeline execution","Captures the parameters and pipeline execution details for cmdlets in logged modules.","warn",["Normal PowerShell administration","Malicious PowerShell activity using logged modules"],"Useful for reconstructing what cmdlets and parameters were used during a session, including ones associated with credential access, discovery, or lateral movement."],
[4104,"PowerShell","PowerShell","PowerShell script block logging captured executed code","Records the actual de-obfuscated script content that PowerShell executed — one of the single highest-value events for detecting malicious or obfuscated PowerShell, including fileless malware.","crit",["Legitimate scripts and automation","Obfuscated or malicious PowerShell payloads"],"Because it logs the actual de-obfuscated script content, this event defeats most obfuscation and encoding tricks used to hide malicious PowerShell \u2014 it's frequently the single most useful event for identifying fileless malware and offensive PowerShell frameworks."],
[4105,"PowerShell","PowerShell","A PowerShell command started","Marks the start of a specific command's execution within a logged session.","info",["Normal command execution"],"Low risk alone; supporting detail for command-level timelines."],
[4106,"PowerShell","PowerShell","A PowerShell command completed","Marks the end of a specific command's execution.","info",["Normal command execution"],"Low risk alone."],

[6005,"System","Boot and Shutdown","The Event Log service started","Logged at every boot, since the Event Log service is one of the first to start. A reliable marker that the system has come up.","info",["Normal system startup"],"Low security relevance; establishes a reliable 'system came up' marker useful for timeline reconstruction."],
[6006,"System","Boot and Shutdown","The Event Log service stopped","Logged during a clean, orderly shutdown or restart.","info",["Normal system shutdown or restart"],"An unexpected 6006 outside of a normal shutdown/restart window can indicate an attempt to interrupt logging, though normal shutdowns are far more common."],
[6008,"System","Boot and Shutdown","The previous system shutdown was unexpected","Windows detected on startup that the prior shutdown wasn't clean — no matching 6006 preceded it. Often paired with Kernel-Power Event 41.","warn",["Power loss","A hard hang or crash","The power button held down"],"Usually a hardware/power issue, but on a server this can also follow a crash caused by exploitation attempts or unstable malware; worth correlating with any 1001 Bug Check events around the same time."],
[6013,"System","Boot and Shutdown","System uptime was reported","A periodic informational event reporting how long the system has been running.","info",["Routine uptime reporting"],"Low security relevance."],
[41,"System","Boot and Shutdown","The system rebooted without a clean shutdown (Kernel-Power)","Logged by the kernel power provider when the system restarts without going through a normal shutdown sequence — the classic “dirty reboot” indicator, frequently seen alongside 6008.","warn",["Power supply failure or outage","System crash or hard hang","Manual hard reset"],"Same considerations as 6008 \u2014 mostly a hardware/power reliability signal, but worth checking for a pattern of crashes that coincides with other suspicious activity."],
[1074,"System","Boot and Shutdown","A shutdown or restart was initiated by a user or application","Records who or what requested the shutdown/restart and the stated reason, if supplied (e.g. Windows Update, a user action, or a remote request).","info",["Planned maintenance or patching reboot","User-initiated restart"],"Low risk alone; an unexpected restart initiated outside a maintenance window is worth checking against who or what triggered it."],
[1076,"System","Boot and Shutdown","The reason for a previous unexpected shutdown was recorded","Lets a user or process retroactively supply/confirm the reason code for an earlier unclean shutdown.","info",["Follow-up documentation after an unexpected shutdown"],"Low security relevance; documentation event."],
[109,"System","Boot and Shutdown","A system power state transition occurred","Logged around sleep, hibernate, resume, or similar power-state changes handled by the kernel.","info",["Normal sleep/resume cycle on laptops and workstations"],"Low security relevance."],
[1001,"System","Boot and Shutdown","A Bug Check (Stop error / BSOD) was recorded","Captures the stop code and parameters after a kernel-level crash, before the subsequent reboot.","crit",["Faulty or incompatible driver","Failing hardware (RAM, storage, GPU)","Kernel-level software bug"],"Most crashes are driver/hardware bugs, but some publicly known exploits (particularly kernel-level vulnerabilities) manifest as crashes during exploitation attempts, so a pattern of crashes on the same machine or driver is worth a closer look."],

[7000,"System","Services","A service failed to start due to a logon failure","The service couldn't start because the account it runs as failed to authenticate.","warn",["Expired or changed service-account password","Misconfigured service credentials"],"Can indicate a legitimate credential or password issue, but is also what you'd see if malware tampered with a service account's credentials or if a security product's service account was deliberately sabotaged."],
[7001,"System","Services","A service failed to start because a dependency failed","A required dependent service wasn't running, so this service couldn't start either.","warn",["A prerequisite service disabled or crashed","Boot-order/dependency misconfiguration"],"Low risk alone, though a security-relevant service (e.g. antivirus) failing to start due to a disabled dependency is worth investigating."],
[7009,"System","Services","A service did not respond in time (start timeout)","The Service Control Manager gave up waiting for the service to report it had started.","warn",["Slow-starting service under heavy load","A hung or deadlocked service"],"Low risk alone."],
[7011,"System","Services","A timeout occurred waiting for a transaction response from a service","The SCM sent a control request (e.g. stop) and didn't get a timely reply.","warn",["An unresponsive or overloaded service"],"Low risk alone."],
[7022,"System","Services","A service hung during startup","The service startup process stalled indefinitely.","warn",["Deadlock or resource contention during initialization"],"Low risk alone, though repeated hangs on a security-relevant service warrant investigation."],
[7023,"System","Services","A service terminated with an error","The service stopped and returned a Windows error code.","warn",["A bug or unhandled exception in the service","Missing files or misconfiguration"],"Worth reviewing if the affected service is security-relevant (antivirus, EDR agent, log forwarder), since its unavailability creates a monitoring gap."],
[7024,"System","Services","A service terminated with a service-specific error","The service stopped and returned an error code defined by the service itself rather than a generic Windows error.","warn",["Application-specific failure condition"],"Same consideration as 7023 \u2014 check whether the affected service is part of your security stack."],
[7026,"System","Services","Boot-start or system-start drivers failed to load","One or more low-level drivers required at boot didn't load.","warn",["Corrupted or missing driver","Driver disabled or incompatible with the current OS build"],"If the affected driver belongs to security software (antivirus, EDR, disk encryption), a failure to load can leave the endpoint unprotected from boot."],
[7031,"System","Services","A service terminated unexpectedly and a recovery action was taken","The service crashed, and Windows carried out its configured recovery action (e.g. automatic restart).","warn",["Software bug causing a crash","Resource exhaustion"],"Repeated crashes of the same service, especially a security tool, can indicate deliberate interference (e.g. malware crashing an antivirus process) rather than a simple bug."],
[7034,"System","Services","A service terminated unexpectedly","The service process crashed without warning; the event usually includes how many times it has crashed recently.","warn",["A bug or unhandled exception in the service","Malware interfering with a legitimate service"],"A crashing security or logging service is a known technique for an attacker to disable defenses; frequency and which service crashed both matter for triage."],
[7035,"System","Services","A start/stop control was successfully sent to a service","Confirms the Service Control Manager successfully delivered a start or stop request; it does not confirm the service finished starting/stopping.","info",["Routine service management"],"Low risk alone, though an unexpected stop request sent to a security service is worth investigating."],
[7036,"System","Services","A service entered the running or stopped state","One of the highest-volume System log events — logged every time any service transitions state. Useful as a baseline, less useful in isolation.","info",["Normal service lifecycle activity"],"Very high volume and low signal alone, but essential for confirming whether a security-relevant service (antivirus, log forwarder, EDR agent) was stopped unexpectedly."],
[7040,"System","Services","The start type of a service was changed","A service's configured start type (Automatic, Manual, Disabled) was modified.","warn",["Legitimate service configuration change","An attacker disabling security software or re-enabling a dormant backdoor service"],"Setting a security service's start type to Disabled, or changing a dormant/backdoor service to Automatic, is a common technique to weaken defenses or ensure persistence survives a reboot."],
[7045,"System","Services","A new service was installed on the system","Fires whenever a new service is registered, whether by an installer, an administrator, or malware. A very common persistence and lateral-movement indicator, and one of the highest-value System log events to alert on.","crit",["Legitimate software installation","A persistence mechanism installed by an attacker"],"One of the highest-value System log events for detecting persistence and lateral movement \u2014 tools like PsExec and many post-exploitation frameworks install a service to execute code remotely, and this event fires every time regardless of whether the install was benign or malicious."],

[51,"System","Disk and Hardware","A disk write error occurred","The disk driver reported a failure to complete a write operation.","warn",["Failing or degraded storage hardware","Cabling/connection issues (for physical disks)"],"Primarily a reliability signal; failing storage can also cause data loss that complicates incident response if it affects log or evidence retention."],
[7,"System","Disk and Hardware","A device is not ready for access","Early sign of a storage device not responding properly to I/O requests.","warn",["Impending disk failure","Removable media not properly inserted/mounted"],"Primarily a reliability signal, though a sudden pattern across many devices can indicate a broader storage or connectivity failure rather than a single failing disk."],
[11,"System","Disk and Hardware","A driver detected a controller error on a device","The storage or device controller reported an error during an operation.","warn",["Failing hardware","Driver or firmware bug"],"Primarily a reliability signal for hardware/driver issues."],
[55,"System","Disk and Hardware","File system corruption was detected","NTFS or the file system driver flagged inconsistency on a volume, often prompting a chkdsk on next boot.","crit",["Unclean shutdown mid-write","Failing storage hardware","File system bug"],"Usually a reliability issue from an unclean shutdown or failing disk, but can also result from tampering or a crash triggered mid-attack; correlate with recent unexpected shutdowns or crashes."],
[129,"System","Disk and Hardware","A storage device did not respond within the timeout period","A storage adapter reset a device after it failed to respond quickly enough.","warn",["Overloaded or failing storage (common in SAN/iSCSI environments)","Firmware or driver issues"],"Primarily a performance/reliability signal for storage infrastructure."],
[153,"System","Disk and Hardware","I/O operations were retried due to a slow device response","The storage stack retried requests because the device responded more slowly than expected — an early warning sign rather than an outright failure.","warn",["Storage latency under load","Early indicator of a failing disk or overloaded SAN"],"Primarily a performance signal; sustained retries are an early warning of a storage problem worth addressing before it becomes an outage."],
[219,"System","Disk and Hardware","A driver failed to load for a device","Windows could not load the driver associated with a connected device.","warn",["Missing, corrupted, or incompatible driver"],"If the affected device or driver is part of a security control, its absence can create a monitoring or protection gap."],

[20,"System","Networking","The DNS client failed to register a record dynamically","The machine could not register or update its DNS record with the configured DNS server.","warn",["DNS server unreachable or misconfigured","Permission issue with dynamic updates"],"Primarily an operational issue, though it can also result from an attacker blocking or interfering with dynamic DNS updates to redirect traffic."],
[1014,"System","Networking","The DNS client failed to resolve a name","A DNS lookup failed after the client contacted its configured DNS servers.","warn",["DNS server outage or misconfiguration","Network connectivity issue","The requested name genuinely doesn't exist"],"Usually operational, but persistent failures for specific internal names can indicate DNS tampering or an attacker interfering with name resolution as part of a broader attack."],
[5719,"System","Networking","No domain controller was found (NETLOGON)","The machine could not locate a domain controller to authenticate against.","warn",["Network connectivity issue to the domain","DNS misconfiguration preventing DC discovery","All reachable domain controllers unavailable"],"Can indicate a network outage, but a coordinated pattern across many machines can also result from a denial-of-service condition against domain controllers or DNS."],
[36,"System","Networking","The time service lost synchronization with its time source","Windows Time service could not keep the clock synchronized against its configured source, which can also cause Kerberos authentication failures.","warn",["Unreachable or misconfigured NTP source","Network issues to the time source"],"Beyond the operational impact, significant clock drift breaks Kerberos authentication (which has a strict time-skew tolerance), so persistent time-sync failures can cause authentication outages that look like an attack."],

[1000,"Application","Application Crashes and Installer","An application crashed (Application Error)","Logged whenever a user-mode application crashes, naming the faulting executable and module. Often paired with a 1001 Windows Error Reporting event with additional diagnostic detail.","warn",["A bug in the application or a third-party plugin/driver it loads","Corrupted installation or incompatible update","Occasionally a sign of exploitation attempts against the application"],"Most crashes are ordinary bugs, but repeated crashes in the same application, especially internet-facing software, can indicate active exploitation attempts against a vulnerability in that application."],
[1001,"Application","Application Crashes and Installer","Windows Error Reporting captured crash details","Additional diagnostic information generated by Windows Error Reporting following a crash (often alongside Event ID 1000).","info",["Follow-up detail after an application crash"],"Low risk alone; supporting diagnostic detail for the related 1000 event."],
[1026,"Application","Application Crashes and Installer","An unhandled .NET runtime exception occurred","A managed (.NET) application threw an exception that wasn't caught anywhere in the code.","warn",["A bug in a .NET application","Missing or mismatched .NET runtime dependency"],"Usually a coding bug, though repeated crashes in a specific managed application can also indicate exploitation attempts against it."],
[1033,"Application","Application Crashes and Installer","Windows Installer completed installing a product","Standard MSI install completion event, naming the product.","info",["Routine software installation via Windows Installer"],"Low risk alone; useful as a baseline of what software is being installed, in case unauthorized or unapproved software shows up here."],
[1034,"Application","Application Crashes and Installer","Windows Installer completed removing a product","Standard MSI uninstall completion event.","info",["Routine software removal via Windows Installer"],"Low risk alone."],
[11707,"Application","Application Crashes and Installer","MSI installation completed successfully","Legacy Windows Installer success code (1707) mapped into the Application log by adding 10,000 — a long-standing way to spot newly installed MSI-based software.","info",["Routine software installation"],"Low risk alone; a useful trail of legitimate MSI-based software installs, though many malware droppers don't use MSI and won't appear here."],
[11724,"Application","Application Crashes and Installer","MSI removal completed successfully","Legacy Windows Installer uninstall-success code (1724 + 10,000).","info",["Routine software removal"],"Low risk alone."],
[10005,"Application","Application Crashes and Installer","Windows Installer setup failed to complete","An MSI-based installation did not finish successfully.","warn",["Installer package error","Insufficient permissions or disk space","Conflicting existing installation"],"Usually benign, though it can indicate a corrupted or blocked install \u2014 worth a closer look if it involves security software failing to deploy."],

[2,"DNS Server","DNS Server","The DNS Server service started","Logged when the Windows DNS Server service starts.","info",["Normal service start / server reboot"],"Low risk alone; establishes a service-availability timeline."],
[3,"DNS Server","DNS Server","The DNS Server service stopped","Logged when the Windows DNS Server service stops.","warn",["Planned maintenance","Unexpected service failure or an attacker disrupting name resolution"],"An unplanned DNS outage can be used to disrupt name resolution as a precursor to redirecting traffic, or may simply indicate an availability problem \u2014 either way it warrants investigation if unplanned."],
[4013,"DNS Server","DNS Server","The DNS server could not access Active Directory","An AD-integrated DNS server was unable to reach the directory it depends on for zone data, typically during startup before network connectivity is fully established.","warn",["A domain controller restarting before its WAN link is ready","Underlying Active Directory or replication problems"],"Primarily an operational/availability issue tied to boot ordering or connectivity, though sustained failures can also point to broader AD replication or connectivity problems worth investigating."],
[6527,"DNS Server","DNS Server","A zone expired before it could complete a transfer or update","A secondary/stub zone's refresh interval lapsed without a successful transfer from its master server, so the zone was taken offline.","crit",["Network connectivity issues to the master DNS server","Zone transfer settings misconfigured or blocked by a firewall"],"If exploited deliberately (e.g. by blocking zone transfers), an attacker could cause a secondary DNS server to serve stale or no data; more often this is a connectivity or configuration issue."],
[3150,"DNS Server","DNS Server","The DNS server wrote a new version of a zone to file","Confirms a file-backed zone was successfully saved to disk after an update.","info",["Normal zone update / transfer activity"],"Low risk alone; routine confirmation of successful zone updates."],
[3151,"DNS Server","DNS Server","The DNS server could not write a zone file","A zone file write failed, most often because the server's disk is full.","crit",["Disk space exhaustion on the DNS server","File permission or path issues"],"Primarily an operational/capacity issue, though a DNS server unable to persist zone data is also unable to reliably serve authoritative records, which has downstream security implications for anything relying on that zone."],

[0,"DHCP Server","DHCP Server","DHCP audit log: logging started","DHCP Server audit-log code 00. Not a standard Event Viewer ID — DHCP Server writes its own numbered audit log to a CSV file rather than the main Windows Event Log. Marks the start of a new audit log file.","info",["Normal DHCP service start / log rollover"],"Low security relevance; service lifecycle marker."],
[1,"DHCP Server","DHCP Server","DHCP audit log: logging stopped","DHCP Server audit-log code 01, logged when the audit log stops writing (e.g. service stop).","warn",["Planned service stop","Unexpected DHCP service failure"],"An unplanned stop interrupts DHCP audit visibility and, if the DHCP service itself stopped, can disrupt address assignment for the network."],
[2,"DHCP Server","DHCP Server","DHCP audit log: logging paused (low disk space)","DHCP Server audit-log code 02 — the server temporarily stopped writing audit entries because free disk space fell below the configured threshold.","warn",["Disk space exhaustion on the DHCP server"],"Creates a gap in DHCP audit coverage \u2014 any lease activity during the pause won't be recorded, which matters if you later need to trace which device held a given IP address."],
[10,"DHCP Server","DHCP Server","DHCP audit log: a new IP address was leased","DHCP Server audit-log code 10, the most common entry in the log — a client successfully obtained a new lease.","info",["Normal client DHCP lease activity"],"Low risk alone; the baseline record used to trace which device held a given IP address at a given time, which matters for attributing other logged network activity to a specific host."],
[11,"DHCP Server","DHCP Server","DHCP audit log: a lease was renewed","DHCP Server audit-log code 11 — a client renewed its existing lease.","info",["Normal client lease renewal"],"Low risk alone; supporting detail for the lease-to-device mapping."],
[12,"DHCP Server","DHCP Server","DHCP audit log: a lease was released","DHCP Server audit-log code 12 — a client explicitly released its lease (e.g. via ipconfig /release).","info",["Normal client shutdown or manual release"],"Low risk alone."],
[13,"DHCP Server","DHCP Server","DHCP audit log: an IP address conflict was detected","DHCP Server audit-log code 13 — the server found the address already in use on the network before offering it.","warn",["A statically configured device using an address from the DHCP pool","Duplicate address misconfiguration"],"Can indicate a rogue or misconfigured device statically claiming an address from the managed pool, which is sometimes used to intercept traffic intended for the legitimate host."],
[14,"DHCP Server","DHCP Server","DHCP audit log: address pool exhausted","DHCP Server audit-log code 14 — a lease request could not be satisfied because the scope ran out of available addresses.","warn",["Scope sized too small for the number of devices","A sudden surge of new devices (or a DHCP-exhaustion attack)"],"A sudden, unexplained exhaustion of the address pool can indicate a DHCP starvation attack, where an attacker floods the server with bogus requests to deny service to legitimate devices."],
[15,"DHCP Server","DHCP Server","DHCP audit log: a lease was denied","DHCP Server audit-log code 15 — the server explicitly declined (NACK) a client's request.","warn",["Client requesting an address outside its allowed scope/reservation","Client roaming to a subnet it isn't authorized for"],"Can indicate a device attempting to obtain an address outside its authorized scope or reservation, which may be reconnaissance or an attempt to bypass network segmentation."],
[16,"DHCP Server","DHCP Server","DHCP audit log: a lease was deleted","DHCP Server audit-log code 16 — a lease record was removed from the server's database.","info",["Administrative cleanup", "Expired lease reclamation"],"Low risk alone; administrative housekeeping."],
[17,"DHCP Server","DHCP Server","DHCP audit log: a lease expired","DHCP Server audit-log code 17 — a client's lease reached its expiration time without being renewed.","info",["Client offline or disconnected past its lease expiry"],"Low risk alone."],
[55,"DHCP Server","DHCP Server","DHCP audit log: server authorized and servicing","DHCP Server audit-log code 55 — the server confirmed it is authorized in Active Directory and began servicing clients.","info",["Normal DHCP server startup in a domain environment"],"Low risk alone; confirms the server passed Active Directory's built-in rogue-DHCP-server protection."],
[56,"DHCP Server","DHCP Server","DHCP audit log: authorization failure, service stopped","DHCP Server audit-log code 56 — the server determined it is not authorized in Active Directory and stopped servicing clients (rogue-server protection).","crit",["A misconfigured or newly promoted DHCP server not yet authorized","An unauthorized/rogue DHCP server being blocked by AD safeguards"],"Directly relevant to detecting a misconfigured or unauthorized DHCP server on the network \u2014 Active Directory's built-in safeguard stopped it from servicing clients, which is exactly the behavior you'd want to see block a rogue server."],
[61,"DHCP Server","DHCP Server","DHCP audit log: another authorized server found","DHCP Server audit-log code 61 — the server detected another DHCP server that belongs to the AD-integrated domain.","info",["Normal multi-server DHCP redundancy"],"Low risk alone; confirms normal multi-server redundancy."],
[62,"DHCP Server","DHCP Server","DHCP audit log: another DHCP server found on the network","DHCP Server audit-log code 62 — an unrecognized DHCP server was detected on the network during rogue-detection checks.","warn",["A legitimate but unregistered DHCP server","A rogue DHCP server, accidental or malicious"],"A key signal for detecting a rogue DHCP server \u2014 an unauthorized DHCP server on the network can hand out malicious gateway/DNS settings to intercept or redirect client traffic."],

[1,"Sysmon","Sysmon","Process creation","Sysmon's richer equivalent of Security 4688 — captures the full command line, hashes, and parent process for every new process. The single most-used Sysmon event in detection engineering.","warn",["Normal application and script execution","Malicious tooling or living-off-the-land execution"],"The richest process-execution telemetry available on Windows \u2014 combined with command-line, hash, and parent-process data, it underpins the majority of endpoint detection rules for malware execution and living-off-the-land techniques."],
[2,"Sysmon","Sysmon","A process changed a file creation time","Flags file creation-timestamp manipulation ('timestomping'), a common anti-forensics technique.","warn",["Legitimate archive/backup tools that preserve timestamps","Timestomping to hide when a malicious file was dropped"],"Timestomping is a well-documented anti-forensic technique used to make a malicious file blend in with legitimate, older files and evade time-based triage."],
[3,"Sysmon","Sysmon","Network connection","Logs outbound (and some inbound) TCP/UDP connections with source/destination process, IP, and port — key for spotting command-and-control traffic.","warn",["Normal application network activity","Command-and-control beaconing or data exfiltration"],"Central to detecting command-and-control beaconing, especially when correlated with process reputation and destination IP/domain reputation."],
[4,"Sysmon","Sysmon","Sysmon service state changed","Sysmon itself started or stopped — worth alerting on, since disabling Sysmon blinds every other detection built on it.","crit",["Planned Sysmon upgrade or config reload","An attacker disabling Sysmon to evade detection"],"If Sysmon itself is stopped or reconfigured to log less, every downstream detection built on it goes blind \u2014 this event should always be alerted on."],
[5,"Sysmon","Sysmon","Process terminated","Marks process exit, pairing with Event ID 1 to bound a process's lifetime.","info",["Normal process completion"],"Low risk alone; supporting detail for process-lifetime correlation with Event ID 1."],
[6,"Sysmon","Sysmon","Driver loaded","A kernel driver was loaded, including its signature/hash information.","warn",["Legitimate hardware or security-product drivers","Loading of a malicious or vulnerable ('BYOVD') driver"],"Loading a legitimately signed but vulnerable driver ('Bring Your Own Vulnerable Driver') is a known technique to gain kernel-level code execution or disable security tooling, so unusual or newly-seen drivers deserve scrutiny."],
[7,"Sysmon","Sysmon","Image loaded","A DLL or executable module was loaded into a process. Very high volume; typically filtered to specific paths or unsigned modules.","info",["Normal application module loading","DLL sideloading/hijacking by malware"],"DLL sideloading and hijacking (getting a legitimate application to load a malicious DLL in place of the expected one) is a common way to run malicious code under a trusted process's identity."],
[8,"Sysmon","Sysmon","CreateRemoteThread","A process created a thread inside another process — a classic process-injection primitive.","crit",["Legitimate debugging or monitoring tools","Process injection used to hide malicious code inside a trusted process"],"A core building block of classic process-injection techniques used to run malicious code inside a trusted process (such as explorer.exe) to blend in and evade detection."],
[9,"Sysmon","Sysmon","RawAccessRead","A process read directly from a disk using low-level \\\\.\\ access, bypassing the normal file system APIs.","warn",["Backup, forensic, or disk-imaging tools","Malware reading raw disk sectors to steal credentials or evade file-level monitoring"],"Malware and credential-theft tools sometimes read raw disk sectors directly to bypass file-level access controls or extract data (such as registry hives) that's normally locked while Windows is running."],
[10,"Sysmon","Sysmon","ProcessAccess","One process opened a handle to another with specific access rights — the event most associated with credential-dumping tools reading LSASS memory.","crit",["Legitimate security tooling inspecting a process (e.g. antivirus)","Credential dumping from LSASS"],"The definitive event for spotting credential-dumping tools (such as those that read LSASS process memory) that extract cached passwords and Kerberos tickets from a running system."],
[11,"Sysmon","Sysmon","FileCreate","A file was created or overwritten, including its full path — useful for catching malware drops and persistence artifacts as they land on disk.","warn",["Normal application and user file activity","Malware payloads being written to disk"],"Catches malware payloads and dropped tools the moment they're written to disk, often before they've even executed."],
[12,"Sysmon","Sysmon","RegistryEvent: object create/delete","A registry key was created or deleted.","info",["Normal application configuration changes","Registry-based persistence setup or cleanup"],"Registry key creation is frequently part of installing persistence mechanisms; deletion can indicate an attacker cleaning up after themselves."],
[13,"Sysmon","Sysmon","RegistryEvent: value set","A registry value was set — especially high-signal for common persistence locations like Run keys.","warn",["Legitimate software configuration","Registry Run-key or similar persistence being installed"],"One of the highest-value Sysmon events for catching registry-based persistence, since most autorun/Run-key techniques ultimately show up as a value being set."],
[14,"Sysmon","Sysmon","RegistryEvent: key/value rename","A registry key or value was renamed.","info",["Normal application maintenance"],"Less common than value changes, but renames of security-relevant keys can indicate an attempt to hide or relocate a persistence mechanism."],
[15,"Sysmon","Sysmon","FileCreateStreamHash","A file was created with an alternate data stream, and Sysmon hashed the stream contents — commonly seen with the 'Mark of the Web' zone-identifier stream on downloaded files.","info",["Files downloaded via a browser or email client (normal)","Payloads hidden in alternate data streams"],"The Mark-of-the-Web zone-identifier stream is exactly what protects users from macros and executables downloaded from the internet \u2014 tracking this event also helps identify files where that protection may have been stripped or is missing."],
[16,"Sysmon","Sysmon","Sysmon configuration change","Sysmon's own configuration was reloaded or changed.","warn",["Planned configuration tuning","An attacker weakening Sysmon's logging coverage"],"An attacker or malicious insider narrowing Sysmon's logging rules is functionally similar to disabling parts of your detection coverage without fully stopping the service, which can be harder to notice."],
[17,"Sysmon","Sysmon","PipeEvent: pipe created","A named pipe was created, commonly used for inter-process and C2-framework communication.","warn",["Normal inter-process communication","Command-and-control frameworks (e.g. Cobalt Strike-style named pipes)"],"Several well-known command-and-control frameworks communicate over named pipes with recognizable naming patterns, making this a useful, if noisy, C2 detection signal."],
[18,"Sysmon","Sysmon","PipeEvent: pipe connected","A process connected to an existing named pipe.","warn",["Normal inter-process communication","C2 framework or lateral-movement tooling communicating over a named pipe"],"Pairs with pipe creation to reveal C2 framework or lateral-movement communication between processes or hosts."],
[19,"Sysmon","Sysmon","WmiEvent: WmiEventFilter activity","A new WMI event filter was registered — a common building block of WMI-based persistence.","crit",["Legitimate systems-management tooling","WMI persistence mechanism being installed"],"The first stage of WMI-based persistence, a technique that survives reboots and doesn't rely on a scheduled task or service, making it popular with more sophisticated attackers."],
[20,"Sysmon","Sysmon","WmiEvent: WmiEventConsumer activity","A new WMI event consumer (the action side of WMI persistence) was registered.","crit",["Legitimate systems-management tooling","WMI persistence mechanism being installed"],"The second stage of WMI persistence \u2014 the consumer defines the actual malicious action (e.g. running a script) that fires when the filter's condition is met."],
[21,"Sysmon","Sysmon","WmiEvent: WmiEventConsumerToFilter activity","A WMI consumer was bound to a filter, completing a WMI subscription — together with Event IDs 19/20, this is the full WMI persistence chain.","crit",["Legitimate systems-management tooling","Completion of a WMI-based persistence mechanism"],"Completes the WMI persistence chain; seeing Event IDs 19, 20, and 21 together for the same subscription is close to definitive evidence of WMI-based persistence being installed."],
[22,"Sysmon","Sysmon","DNSEvent: DNS query","Logs DNS queries made by processes on the host, including the queried name and requesting process — valuable for spotting DNS-based command-and-control or data exfiltration.","warn",["Normal application DNS lookups","DNS tunneling or C2 domain resolution"],"DNS tunneling and DNS-based C2 are designed to blend into normal-looking traffic, so process-level DNS query logging (rather than just network-layer DNS logs) is valuable for tying suspicious lookups back to the process that made them."],
[23,"Sysmon","Sysmon","FileDelete (archived)","A file matching the configured rules was deleted, and Sysmon retained a copy in its archive directory for later analysis.","warn",["Normal cleanup of monitored file types","Anti-forensic cleanup after malware execution (the archived copy preserves evidence)"],"Because Sysmon retains a copy of the deleted file, this event can preserve the actual malicious file for later analysis even after the attacker tries to delete it \u2014 one of Sysmon's most forensically valuable features."],
[24,"Sysmon","Sysmon","ClipboardChange","The system clipboard contents changed.","info",["Normal copy/paste activity","Credential or data theft via clipboard-monitoring malware"],"Clipboard-monitoring malware (used to steal cryptocurrency addresses or credentials copied by a user) is a documented technique this event can help surface."],
[25,"Sysmon","Sysmon","ProcessTampering","Detects process-hollowing or 'herpaderping' style techniques where a process's image doesn't match what was originally launched.","crit",["Rare in legitimate software","Process hollowing/herpaderping used to hide malicious code inside a legitimate-looking process"],"Directly targets process hollowing and herpaderping, sophisticated techniques specifically designed to evade both antivirus and manual process inspection by making malicious code appear to run under a legitimate process's identity."],
[26,"Sysmon","Sysmon","FileDeleteDetected","A file matching the configured rules was deleted (logged without retaining a copy, unlike Event ID 23).","warn",["Normal cleanup of monitored file types","Evidence deletion after malicious activity"],"Can indicate an attacker or malware deleting its own artifacts to cover tracks, though unlike Event ID 23 no copy is preserved for later analysis."],
[27,"Sysmon","Sysmon","FileBlockExecutable","Sysmon detected and blocked the creation of an executable file matching its blocking rules.","crit",["A blocked, legitimate software installation (check the rule)","A blocked attempt to drop a malicious executable"],"A successful block is good news, but it also confirms an attempt was made to drop an executable matching your blocking rules in a monitored location \u2014 worth investigating the source."],
[28,"Sysmon","Sysmon","FileBlockShredding","Sysmon detected and blocked an attempt to shred/wipe a file using secure-deletion tools.","warn",["Blocked legitimate use of a secure-deletion tool","Blocked anti-forensic file shredding by an attacker"],"A blocked shredding attempt can indicate an adversary trying to securely wipe evidence of their activity from disk."],
[29,"Sysmon","Sysmon","FileExecutableDetected","Sysmon detected the creation of a new executable file matching its monitoring rules (detection-only counterpart to Event ID 27).","warn",["Normal software installation","A newly dropped malicious executable"],"Detection-only counterpart to FileBlockExecutable; useful for visibility into new executables landing in monitored locations even where blocking isn't enabled."]
];

const $=id=>document.getElementById(id);
const CATS=[...new Set(DATA.map(d=>d[2]))];
let activeCat='all', activeLog='all', query='';

function buildChips(){
 const chipsEl=$('lm-chips');
 chipsEl.innerHTML='';
 const all=document.createElement('button');
 all.type='button';all.className='lm-chip is-active';all.textContent='All categories';all.dataset.cat='all';
 chipsEl.appendChild(all);
 CATS.forEach(c=>{
  const b=document.createElement('button');
  b.type='button';b.className='lm-chip';b.textContent=c;b.dataset.cat=c;
  chipsEl.appendChild(b);
 });
 chipsEl.addEventListener('click',e=>{
  const b=e.target.closest('.lm-chip');if(!b)return;
  activeCat=b.dataset.cat;
  [...chipsEl.children].forEach(el=>el.classList.toggle('is-active',el===b));
  render();
 });
}

function sevClass(s){return s==='crit'?'lm-sev-crit':s==='warn'?'lm-sev-warn':'lm-sev-info'}
function sevLabel(s){return s==='crit'?'High signal':s==='warn'?'Investigate':'Informational'}

function matches(entry){
 const [id,log,cat,title,desc]=entry;
 if(activeLog!=='all'){ if(log!==activeLog) return false; }
 if(activeCat!=='all'){ if(cat!==activeCat) return false; }
 if(!query)return true;
 const q=query.toLowerCase();
 return String(id).includes(q) || title.toLowerCase().includes(q) || desc.toLowerCase().includes(q) || cat.toLowerCase().includes(q) || log.toLowerCase().includes(q);
}

function render(){
 const results=DATA.filter(matches).sort((a,b)=>a[0]-b[0]);
 $('lm-count').textContent=results.length+(results.length===1?' Event ID found':' Event IDs found');
 const container=$('lm-results');
 container.innerHTML='';
 results.forEach(([id,log,cat,title,desc,sev,causes,risk])=>{
  const card=document.createElement('div');card.className='lm-card';
  card.innerHTML=`
   <div class="lm-id-col"><div class="lm-id">${id}<span class="lm-sev ${sevClass(sev)}">${sevLabel(sev)}
   <div class="lm-body">
    <div class="lm-tags"><span class="lm-tag">${log} log<span class="lm-tag">${cat}
    <h4>${title}
    <p class="lm-desc">${desc}
    <div class="lm-risk-label">Security relevance
    <p class="lm-risk">${risk}
    <div class="lm-causes-label">Commonly seen with
    <ul class="lm-causes">${causes.map(c=>`<li>${c}`).join('')}
   `;
  container.appendChild(card);
 });
}

$('lm-search').addEventListener('input',e=>{query=e.target.value.trim();render()});
$('lm-log-filter').addEventListener('change',e=>{activeLog=e.target.value;render()});
buildChips();render();
})();
