Resources

April 2, 2026 ยท View on GitHub

Notable Event IDs to record to build up risk with. Exlcudes those already included in existing Sigma rules.

Table of Contents

Application

EventIDDescriptionFilter
1002Application Hang
1003Application Error
11707Product: [1] -- Installation operation completed successfully.
11724Product: [1] -- Removal completed successfully.

Microsoft-Windows-AppLocker/EXE and DLL

EventIDDescriptionFilter
8003... would have been prevented from running.

Microsoft-Windows-AppLocker/MSI and Script

EventIDDescriptionFilter
EventIDDescription
:-----:-------------------------------------------
8006... would have been prevented from running.
8007... was prevented from running.

Microsoft-Windows-AppLocker/Packaged app-Execution

EventIDDescription
8022... was prevented from running.

Microsoft-Windows-AppLocker/Packaged app-Deployment

EventIDDescription
8025... was prevented from running.

Security

EventIDDescriptionFilter
1100The event logging service has shut down.
4618A monitored security event pattern has occurred.
4664An attempt was made to create a hard link
4693Recovery of data protection master key was attempted.
4695Unprotection of auditable protected data was attempted.
4717System security access was granted to an account.
4718System security access was removed from an account.
4722A user account was enabled.
4723An attempt was made to change an account's password.
4724An attempt was made to reset an account's password.
4725A user account was disabled.
4726A user account was deleted.
4731A security-enabled local group was created.
4733A member was removed from a security-enabled local group.
4734A security-enabled local group was deleted.
4735A security-enabled local group was changed.
4738A user account was changed.
4739Domain Policy was changed.
4740A user account was locked out.
4767A user account was unlocked.
4782The password hash an account was accessed.
4798A user's local group membership was enumerated.
4816RPC detected an integrity violation while decrypting an incoming message.
4882The security permissions for Certificate Services changed.
4946A change has been made to Windows Firewall exception list. A rule was added.
4947A change has been made to Windows Firewall exception list. A rule was modified.
4948A change has been made to Windows Firewall exception list. A rule was deleted.
4950A Windows Firewall setting has changed (local only)
5025Windows Firewall Service has been stopped
5030Windows Firewall Service failed to start
5031The Windows Firewall Service blocked an application from accepting incoming connections on the network.
5034The Windows Firewall Driver was stopped
5035Windows Firewall Driver failed to start
5037Windows Firewall Driver detected critical runtime error Terminating
5142Network share object added
5143Network share object changed
5144Network share object deleted
5376Credential Manager credentials were backed up
5377Credential Manager credentials were restored from a backup.
5378The requested credentials delegation was disallowed by policy.
6273Network Policy Server denied access to a user
6276Network Policy Server quarantined a user
6277Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy
6278Network Policy Server granted full access to a user because the host met the defined health policy
6279Network Policy Server locked the user account due to repeated failed authentication attempts
6280Network Policy Server unlocked the user account
6281Code Integrity determined that the page hashes of an image file are not valid.Level 0 or 4
6410Code integrity determined that a file does not meet the security requirements to load into a process.Level 0 or 4
6419A request was made to disable a device.
6420A device was disabled.
6421A request was made to enable a device.
6422A device was enabled.
6424The installation of this device was allowed after having previously been forbidden by policy.

Security (Domain Controller Specific)

EventIDDescriptionFilter
4707A trust to a domain was removed.
4713Kerberos policy was changed.
4714Encrypted data recovery policy was changed
4716Trusted domain information was modified.
4729A member was removed from a security-enabled global group.
4731A security-enabled local group was created.
4733A member was removed to a security-enabled local group.
4735A security-enabled local group was changed.
4734A security-enabled local group was deleted.
4737A security-enabled global group was changed.
4743A computer account was deleted.
4744A security-disabled local group was created
4745A security-disabled local group was changed
4746A member was added to a security-disabled local group
4747A member was removed from a security-disabled local group
4748A security-disabled local group was deleted
4749A security-disabled global group was created
4750A security-disabled global group was changed
4751A member was added to a security-disabled global group
4752A member was removed from a security-disabled global group
4753A security-disabled global group was deleted
4754A security-enabled universal group was created.
4755A security-enabled universal group was changed.
4756A member was added to a security-enabled universal group.
4757A member was removed from a security-enabled universal group.
4758A security-enabled universal group was deleted.
4759A security-disabled universal group was created
4760A security-disabled universal group was changed
4761A member was added to a security-disabled universal group
4762A member was removed from a security-disabled universal group
4763A security-disabled universal group was deleted
4764A group's type was changed.
4766An attempt to add SID History to an account failed.
4767A user account was unlocked.
4865A trusted forest information entry was added.
4866A trusted forest information entry was removed.
4867A trusted forest information entry was added.
5137A directory service object was created.
5138A directory service object was undeleted
5139A directory service object was moved.
5141A directory service object was deleted

System

EventIDDescriptionFilter
41The system has rebooted without cleanly shutting down first
219Failed Kernel Driver LoadingLevel 3
7022Service hung on startingLevel 0, 1, 2, 3, or 4
7024Service terminated with the following service-specific errorLevel 0, 1, 2, 3, or 4
7026The boot-start or system-start driver(s) [did not/failed to] loadLevel 0, 1, 2, 3, or 4
7030Service Creation Errors
7031Service terminated unexpectedlyLevel 0, 1, 2, 3, or 4
7032Service tried to take a corrective action (1) after the unexpected termination of the % serviceLevel 0, 1, 2, 3, or 4
7035The [Service Name] service was successfully sent a [start/stop] control
7040The service state has changedLevel 0, 1, 2, 3, or 4

Microsoft-Windows-Authentication/AuthenticationPolicyFailures-DomainController

EventIDDescription
105Kerberos authentication from a particular device was not permitted.
106The user or device was not allowed to authenticate to the server.
305Kerberos TGT request did not meet access control restrictions.
306User, device or both do not meet the access control restrictions.

Microsoft-Windows-Authentication/ProtectedUserFailures-DomainController

EventIDDescription
100An NTLM sign-in failure occurs for an account that is in the Protected Users security group.
102An account tried to authenticate using DES or RC4. Protected Users are restricted to AES encryption.
104The security package on the client does not contain the credentials.
303A Kerberos ticket-granting-ticket (TGT) was successfully issued for a member of the Protected User group.

Microsoft-Windows-CodeIntegrity/Operational

EventIDDescriptionFilter
3002Code Integrity is unable to verify the image integrity of the file %2 because the set of per-page image hashes could not be found on the system.Level 2 or 3
3003Code Integrity is unable to verify the image integrity of the file %2 because the set of per-page image hashes could not be found on the system. The image is allowed to load because kernel mode debugger is attached.Level 2 or 3
3004Windows is unable to verify the image integrity of the file %2 because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.Level 2 or 3
3010Code Integrity was unable to load the %2 catalog.Level 2 or 3

Microsoft-Windows-GroupPolicy

EventIDDescriptionFilter
1085Windows failed to apply the ... settingsLevel 2
1125The processing of Group Policy failed because of an internal system error.Level 2
1127The processing of Group Policy failed due to an internal error.Level 2
1129The processing of Group Policy failed because of lack of network connectivity to a domain controller.Level 2

Microsoft-Windows-NTLM/Operational

EventIDDescriptionFilter
8003NTLM server blocked in the domain audit: Audit NTLM authentication in this domain.

Microsoft-Windows-PowerShell/Analytic

EventIDDescription
32850Creating a server remote session

Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational

EventIDDescription
131Accepted new TCP connection
140Connection failed; bad username or password

Microsoft-Windows-Security-Mitigations/KernelMode

EventIDDescription
*This event log contains log about the "Exploit Protection" feature.

Microsoft-Windows-Sysmon/Operational

EventIDDescription
2A process changed a file creation time

Microsoft-Windows-TaskScheduler/Operational

EventIDDescription
140Task Updated

Microsoft-Windows-TerminalServices-RDPClient/Operational

EventIDDescription
1024RDP connection attempt
1025RDP connection made
1102multi-transport connection attempt
1103multi-transport connection made

Microsoft-Windows-Windows Defender/Operational

EventIDDescriptionFilter
1002An antimalware scan was stopped before it finished.Level 2
1003malware scan paused
1005An antimalware scan failed.
1007The antimalware platform performed an action to protect your system from malware or other potentially unwanted software.
1008The antimalware platform attempted to perform an action to protect your system from malware or other potentially unwanted software, but the action failed.
1012unable to delete item in quarantine
1014The antimalware platform could not delete history of malware and other potentially unwanted software.
1015The antimalware platform detected suspicious behavior.
1117The antimalware platform performed an action to protect your system from malware or other potentially unwanted software.
1118The antimalware platform attempted to perform an action to protect your system from malware or other potentially unwanted software, but the action failed.
1119The antimalware platform encountered a critical error when trying to take action on malware or other potentially unwanted software. There are more details in the event message.
2001The antimalware definition update failed.
2003The antimalware engine update failed.
2006The platform update failed.
2042The antimalware engine no longer supports this operating system, and is no longer protecting your system from malware.
5008The antimalware engine encountered an error and failed.

Microsoft-Windows-WinINet-Config/ProxyConfigChanged

EventIDDescription
5600Indicates change in the proxy configuration. For example if i change my proxy configuration from the "Internet Option" menu. The event will get generated.

Microsoft-Windows-WMI-Activity/Operational

EventIDDescription
5860Registration of Temporary Event Consumer

Resources