> For the complete documentation index, see [llms.txt](https://docs.blusapphire.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.blusapphire.io/older-releases/16_best-practices/windows-logging-recommendations/windows-general-log-recommendations.md).

# Windows General Log Recommendations

<table data-header-hidden><thead><tr><th></th><th width="269">Category </th><th>Name </th><th>ID </th><th>Level </th><th>Event Log </th><th>Event Source </th></tr></thead><tbody><tr><td>1 </td><td>Boot Events </td><td>Shutdown Initiate Failed </td><td>1074 </td><td>Warning </td><td>User32 </td><td>User32 </td></tr><tr><td>2 </td><td>Application Crashes </td><td>BSOD </td><td>1001 </td><td>Error </td><td>System </td><td>Microsoft-Windows-WER-SystemErrorReporting </td></tr><tr><td>3 </td><td>Boot Events </td><td>Windows Shutdown </td><td>13 </td><td>Information </td><td>System </td><td>Microsoft-Windows-Kernel-General </td></tr><tr><td>4 </td><td>Boot Events </td><td>Windows Startup </td><td>12 </td><td>Information </td><td>System </td><td>Microsoft-Windows-Kernel-General </td></tr><tr><td>5 </td><td>Clearing Event Logs </td><td>Event Log was Cleared </td><td>104 </td><td>Information </td><td>System </td><td>Microsoft-Windows-Eventlog </td></tr><tr><td>6 </td><td>Group Policy Errors </td><td>Generic Internal Error </td><td>1126 </td><td>Error </td><td>System </td><td>Microsoft-Windows-GroupPolicy </td></tr><tr><td>7 </td><td>Group Policy Errors </td><td>Group Policy Application Failed due to Connectivity </td><td>1129 </td><td>Error </td><td>System </td><td>Microsoft-Windows-GroupPolicy </td></tr><tr><td>8 </td><td>Group Policy Errors </td><td>Internal Error </td><td>1125 </td><td>Error </td><td>System </td><td>Microsoft-Windows-GroupPolicy </td></tr><tr><td>9 </td><td>Kernel Driver Signing </td><td>Failed Kernel Driver Loading </td><td>219 </td><td>Warning </td><td>System </td><td>Microsoft-Windows-Kernel-PnP </td></tr><tr><td>10 </td><td>Software and Service Installation </td><td>New Kernel Filter Driver </td><td>6 </td><td>Information </td><td>System </td><td>Microsoft-Windows-FilterManager </td></tr><tr><td>11 </td><td>Software and Service Installation </td><td>New Windows Service </td><td>7045 </td><td>Information </td><td>System </td><td>Microsoft-Windows-FilterManager </td></tr><tr><td>12 </td><td>Software and Service Installation </td><td>Service Start Failure </td><td>7000 </td><td>Error </td><td>System </td><td>Service Control Manager </td></tr><tr><td>13 </td><td>Software and Service Installation </td><td>Windows Update Installed </td><td>19 </td><td>Information </td><td>System </td><td>Microsoft-Windows-WindowsUpdateClient </td></tr><tr><td>14 </td><td>System Integrity </td><td>System Time Changed </td><td>1 </td><td>Information </td><td>System </td><td>Microsoft-Windows-Kernel-General </td></tr><tr><td>15 </td><td>System or Service Failures </td><td>Windows Service Fails or Crashes </td><td>7022, 7023, 7024, 7026, 7031, 7032, 7034 </td><td>Error </td><td>System </td><td>Service Control Manager </td></tr><tr><td>16 </td><td>Software and Service Installation </td><td>Update Packages Installed </td><td>2 </td><td>Information </td><td>Setup </td><td>Microsoft-Windows-Servicing </td></tr><tr><td>17 </td><td>Windows Update Errors </td><td>Hotpatching Failed </td><td>1009 </td><td>Information </td><td>Setup </td><td>Microsoft-Windows-Servicing </td></tr><tr><td>18 </td><td>Account Usage </td><td>Account Lockouts </td><td>4740 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>19 </td><td>Account Usage </td><td>Account Login with Explicit Credentials </td><td>4648 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>20 </td><td>Account Usage </td><td>Account Name Changed </td><td>4781 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>21 </td><td>Account Usage </td><td>Account removed from Local Sec. Grp. </td><td>4733 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>22 </td><td>Account Usage </td><td>Credential Authentication </td><td>4776 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>23 </td><td>Account Usage </td><td>Credentials backed up </td><td>5376 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>24 </td><td>Account Usage </td><td>Credentials restored </td><td>5377 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>25 </td><td>Account Usage </td><td>Failed User Account Login </td><td>4625 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>26 </td><td>Account Usage </td><td>Logoff Event </td><td>4634 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>27 </td><td>Account Usage </td><td>Logon with Special Privs </td><td>4672 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>28 </td><td>Account Usage </td><td>New User Account Created </td><td>4720 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>29 </td><td>Account Usage </td><td>New User Account Enabled </td><td>4722 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>30 </td><td>Account Usage </td><td>Password Hash Accessed </td><td>4782 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>31 </td><td>Account Usage </td><td>Password Policy Checking API called </td><td>4793 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>32 </td><td>Account Usage </td><td>Security-enabled Group Created </td><td>4731 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>33 </td><td>Account Usage </td><td>Security-Enabled group Modification </td><td>4735 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>34 </td><td>Account Usage </td><td>SID History add attempted on Account </td><td>4766 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>35 </td><td>Account Usage </td><td>SID History added to Account </td><td>4765 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>36 </td><td>Account Usage </td><td>Successful User Account Login </td><td>4624 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>37 </td><td>Account Usage </td><td>User Account Deleted </td><td>4726 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>38 </td><td>Account Usage </td><td>User Account Disabled </td><td>4725 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>39 </td><td>Account Usage </td><td>User Account Unlocked </td><td>4767 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>40 </td><td>Account Usage </td><td>User Added to Privileged Group </td><td>4728, 4732, 4756 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>41 </td><td>Account Usage </td><td>User Right Assigned </td><td>4704 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>42 </td><td>Application Whitelisting </td><td>Process Created </td><td>4688 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>43 </td><td>Application Whitelisting </td><td>Process Terminated </td><td>4689 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>44 </td><td>Certificate Services </td><td>CA Services Request </td><td>4886 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>45 </td><td>Certificate Services </td><td>Certificate Manager Settings Changed </td><td>4890 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>46 </td><td>Certificate Services </td><td>Certificate Request Attributes Changed </td><td>4874 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>47 </td><td>Certificate Services </td><td>Certificate Request Extension Changed </td><td>4873 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>48 </td><td>Certificate Services </td><td>Certificate Revoked </td><td>4870 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>49 </td><td>Certificate Services </td><td>Certificate Services approved request </td><td>4887 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>50 </td><td>Certificate Services </td><td>Certificate Services Audit Filter Changed </td><td>4885 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>51 </td><td>Certificate Services </td><td>Certificate Services Configuration Changed </td><td>4891 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>52 </td><td>Certificate Services </td><td>Certificate Services denied request </td><td>4888 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>53 </td><td>Certificate Services </td><td>Certificate Services Loaded Template </td><td>4898 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>54 </td><td>Certificate Services </td><td>Certificate Services Permissions Changed </td><td>4882 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>55 </td><td>Certificate Services </td><td>Certificate Services Property Changed </td><td>4892 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>56 </td><td>Certificate Services </td><td>Certificate Services Started </td><td>4880 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>57 </td><td>Certificate Services </td><td>Certificate Services Stopped </td><td>4881 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>58 </td><td>Certificate Services </td><td>Certificate Services Template Security Updated </td><td>4900 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>59 </td><td>Certificate Services </td><td>Certificate Services Template Updated </td><td>4899 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>60 </td><td>Certificate Services </td><td>Entries Removed from Certificate Database </td><td>4896 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>61 </td><td>Clearing Event Logs </td><td>Event Log Service Shutdown </td><td>1100 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-EventLog </td></tr><tr><td>62 </td><td>Clearing Event Logs </td><td>Event Log was Cleared </td><td>1102 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Eventlog </td></tr><tr><td>63 </td><td>DNS/Directory Services </td><td>Directory service created </td><td>5137 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>64 </td><td>DNS/Directory Services </td><td>Directory service deleted </td><td>5141 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>65 </td><td>DNS/Directory Services </td><td>Directory service modified </td><td>5136 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>66 </td><td>DNS/Directory Services </td><td>Directory service moved </td><td>5139 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>67 </td><td>DNS/Directory Services </td><td>Directory service recovered </td><td>5138 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>68 </td><td>Kernel Driver Signing </td><td>Detected an invalid image hash of a file </td><td>5038 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>69 </td><td>Kernel Driver Signing </td><td>Detected an invalid page hash of an image file </td><td>6281 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>70 </td><td>Network Policy </td><td>Encrypted Data Recovery Policy Changed </td><td>4714 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>71 </td><td>Network Policy </td><td>Kerberos Policy Changed </td><td>4713 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>72 </td><td>Network Policy </td><td>Kerberos Service Ticket Req. Failed </td><td>4769 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>73 </td><td>Network Policy </td><td>Network Policy Server Denied Access </td><td>6273 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>74 </td><td>Network Policy </td><td>Network Policy Server Discarded Accounting Request </td><td>6275 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>75 </td><td>Network Policy </td><td>Network Policy Server Discarded Request </td><td>6274 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>76 </td><td>Network Policy </td><td>Network Policy Server Granted Access </td><td>6272 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>77 </td><td>Network Policy </td><td>Network Policy Server Granted Full Access </td><td>6278 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>78 </td><td>Network Policy </td><td>Network Policy Server Granted Probationary Access </td><td>6277 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>79 </td><td>Network Policy </td><td>Network Policy Server Locked Account </td><td>6279 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>80 </td><td>Network Policy </td><td>Network Policy Server Quarantined User </td><td>6276 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>81 </td><td>Network Policy </td><td>Network Policy Server Unlocked Account </td><td>6280 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>82 </td><td>Network Policy </td><td>Network share accessed </td><td>5140 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>83 </td><td>Network Policy </td><td>Network Share Checked </td><td>5145 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>84 </td><td>Network Policy </td><td>Network Share Created </td><td>5142 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>85 </td><td>Network Policy </td><td>Network Share Deleted </td><td>5144 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>86 </td><td>Network Policy </td><td>New Trust for Domain </td><td>4706 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>87 </td><td>Network Policy </td><td>Role Separation Enabled </td><td>4897 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>88 </td><td>Network Policy </td><td>System Audit Policy Changed </td><td>4719 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>89 </td><td>Network Policy </td><td>Trusted Domain Information Modified </td><td>4716 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>90 </td><td>Network Policy </td><td>TS Session Disconnect </td><td>4779 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>91 </td><td>Network Policy </td><td>TS Session Reconnect </td><td>4778 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>92 </td><td>Network Policy </td><td>Wireless 802.1X Auth </td><td>5632 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>93 </td><td>System Integrity </td><td>Registry Modification </td><td>4657 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>94 </td><td>Network Policy </td><td>RADIUS User assigned IP </td><td>20250 </td><td>Success </td><td>RemoteAccess </td><td>Microsoft-Windows-MPRMSG </td></tr><tr><td>95 </td><td>Network Policy </td><td>RADIUS User Authenticated </td><td>20274 </td><td>Success </td><td>RemoteAccess </td><td>Microsoft-Windows-MPRMSG </td></tr><tr><td>96 </td><td>Network Policy </td><td>RADIUS User Disconnected </td><td>20275 </td><td>Success </td><td>RemoteAccess </td><td>Microsoft-Windows-MPRMSG </td></tr><tr><td>97 </td><td>PowerShell Activities </td><td>Get-MessageTrackingLog cmdlet </td><td>800 </td><td>Information </td><td>Powershell </td><td>Microsoft-Windows-Powershell </td></tr><tr><td>98 </td><td>PowerShell Activities </td><td>Remote Connection </td><td>169 </td><td>Information </td><td>Powershell </td><td>Microsoft-Windows-Powershell </td></tr><tr><td>99 </td><td>Mobile Device Activities </td><td>Disconnect from Wireless connection </td><td>8003 </td><td>Information </td><td>Microsoft-Windows-WLAN-AutoConfig/Operational </td><td>Microsoft-Windows-WLAN-AutoConfig </td></tr><tr><td>100 </td><td>Mobile Device Activities </td><td>Starting a Wireless connection </td><td>8000, 8011 </td><td>Information </td><td>Microsoft-Windows-WLAN-AutoConfig/Operational </td><td>Microsoft-Windows-WLAN-AutoConfig </td></tr><tr><td>101 </td><td>Mobile Device Activities </td><td>Successfully connected to a Wireless connection </td><td>8001 </td><td>Information </td><td>Microsoft-Windows-WLAN-AutoConfig/Operational </td><td>Microsoft-Windows-WLAN-AutoConfig </td></tr><tr><td>102 </td><td>Mobile Device Activities </td><td>Wireless Association Status </td><td>11000, 11001 </td><td>Information </td><td>Microsoft-Windows-WLAN-AutoConfig/Operational </td><td>Microsoft-Windows-WLAN-AutoConfig </td></tr><tr><td>103 </td><td>Mobile Device Activities </td><td>Wireless Association Status </td><td>11002 </td><td>Error </td><td>Microsoft-Windows-WLAN-AutoConfig/Operational </td><td>Microsoft-Windows-WLAN-AutoConfig </td></tr><tr><td>104 </td><td>Mobile Device Activities </td><td>Wireless Authentication Started and Failed </td><td>12011, 12012 </td><td>Information </td><td>Microsoft-Windows-WLAN-AutoConfig/Operational </td><td>Microsoft-Windows-WLAN-AutoConfig </td></tr><tr><td>105 </td><td>Mobile Device Activities </td><td>Wireless Authentication Started and Failed </td><td>12013 </td><td>Error </td><td>Microsoft-Windows-WLAN-AutoConfig/Operational </td><td>Microsoft-Windows-WLAN-AutoConfig </td></tr><tr><td>106 </td><td>Mobile Device Activities </td><td>Wireless Connection Failed </td><td>8002 </td><td>Error </td><td>Microsoft-Windows-WLAN-AutoConfig/Operational </td><td>Microsoft-Windows-WLAN-AutoConfig </td></tr><tr><td>107 </td><td>Mobile Device Activities </td><td>Wireless Security Started, Stopped, Successful, or Failed </td><td>11004, 11005 </td><td>Information </td><td>Microsoft-Windows-WLAN-AutoConfig/Operational </td><td>Microsoft-Windows-WLAN-AutoConfig </td></tr><tr><td>108 </td><td>Mobile Device Activities </td><td>Wireless Security Started, Stopped, Successful, or Failed </td><td>11010, 11006 </td><td>Error </td><td>Microsoft-Windows-WLAN-AutoConfig/Operational </td><td>Microsoft-Windows-WLAN-AutoConfig </td></tr><tr><td>109 </td><td>Windows Update Errors </td><td>Windows Update Failed </td><td>20, 24, 25, 31, 34, 35 </td><td>Error </td><td>Microsoft-Windows-WindowsUpdateClient/Operational </td><td>Microsoft-Windows-WindowsUpdateClient </td></tr><tr><td>110 </td><td>Windows Firewall </td><td>Firewall Failed to load Group Policy </td><td>2009 </td><td>Error </td><td>Microsoft-Windows-Windows Firewall With Advanced Security/Firewall </td><td>Microsoft-Windows-Windows Firewall With Advanced Security </td></tr><tr><td>111 </td><td>Windows Firewall </td><td>Firewall Rule Add </td><td>2004 </td><td>Information </td><td>Microsoft-Windows-Windows Firewall With Advanced Security/Firewall </td><td>Microsoft-Windows-Windows Firewall With Advanced Security </td></tr><tr><td>112 </td><td>Windows Firewall </td><td>Firewall Rule Change </td><td>2005 </td><td>Information </td><td>Microsoft-Windows-Windows Firewall With Advanced Security/Firewall </td><td>Microsoft-Windows-Windows Firewall With Advanced Security </td></tr><tr><td>113 </td><td>Windows Firewall </td><td>Firewall Rules Deleted </td><td>2006, 2033 </td><td>Information </td><td>Microsoft-Windows-Windows Firewall With Advanced Security/Firewall </td><td>Microsoft-Windows-Windows Firewall With Advanced Security </td></tr><tr><td>114 </td><td>Windows Defender Activities </td><td>Action on Malware Failed </td><td>1008 </td><td>Error </td><td>Microsoft-Windows-Windows Defender/Operational </td><td>Microsoft-Windows-Windows Defender </td></tr><tr><td>115 </td><td>Windows Defender Activities </td><td>Detected Malware </td><td>1006, 1116 </td><td>Warning </td><td>Microsoft-Windows-Windows Defender/Operational </td><td>Microsoft-Windows-Windows Defender </td></tr><tr><td>116 </td><td>Windows Defender Activities </td><td>Failed to remove item from quarantine </td><td>1010 </td><td>Error </td><td>Microsoft-Windows-Windows Defender/Operational </td><td>Microsoft-Windows-Windows Defender </td></tr><tr><td>117 </td><td>Windows Defender Activities </td><td>Failed to update engine </td><td>2003 </td><td>Error </td><td>Microsoft-Windows-Windows Defender/Operational </td><td>Microsoft-Windows-Windows Defender </td></tr><tr><td>118 </td><td>Windows Defender Activities </td><td>Failed to update signatures </td><td>2001 </td><td>Error </td><td>Microsoft-Windows-Windows Defender/Operational </td><td>Microsoft-Windows-Windows Defender </td></tr><tr><td>119 </td><td>Windows Defender Activities </td><td>File Restored from Quarantine </td><td>1009 </td><td>Information </td><td>Microsoft-Windows-Windows Defender/Operational </td><td>Microsoft-Windows-Windows Defender </td></tr><tr><td>120 </td><td>Windows Defender Activities </td><td>Malware Removal Error </td><td>1118 </td><td>Information </td><td>Microsoft-Windows-Windows Defender/Operational </td><td>Microsoft-Windows-Windows Defender </td></tr><tr><td>121 </td><td>Windows Defender Activities </td><td>Malware Removal Fatal Error </td><td>1119 </td><td>Error </td><td>Microsoft-Windows-Windows Defender/Operational </td><td>Microsoft-Windows-Windows Defender </td></tr><tr><td>122 </td><td>Windows Defender Activities </td><td>Malware Removed </td><td>1007, 1117 </td><td>Information </td><td>Microsoft-Windows-Windows Defender/Operational </td><td>Microsoft-Windows-Windows Defender </td></tr><tr><td>123 </td><td>Windows Defender Activities </td><td>Real-Time Protection failed </td><td>3002 </td><td>Error </td><td>Microsoft-Windows-Windows Defender/Operational </td><td>Microsoft-Windows-Windows Defender </td></tr><tr><td>124 </td><td>Windows Defender Activities </td><td>Reverting to last known good set of signatures </td><td>2004 </td><td>Warning </td><td>Microsoft-Windows-Windows Defender/Operational </td><td>Microsoft-Windows-Windows Defender </td></tr><tr><td>125 </td><td>Windows Defender Activities </td><td>Scan Failed </td><td>1005 </td><td>Error </td><td>Microsoft-Windows-Windows Defender/Operational </td><td>Microsoft-Windows-Windows Defender </td></tr><tr><td>126 </td><td>Windows Defender Activities </td><td>Unexpected Error </td><td>5008 </td><td>Error </td><td>Microsoft-Windows-Windows Defender/Operational </td><td>Microsoft-Windows-Windows Defender </td></tr><tr><td>127 </td><td>External Media Detection </td><td>New Device Information </td><td>43 </td><td>Information </td><td>Microsoft-Windows-USB-USBHUB3-Analytic </td><td>Microsoft-Windows-USB-USBHUB3 </td></tr><tr><td>128 </td><td>Network Policy </td><td>Outbound TS Connect Attempt </td><td>1024 </td><td>Information </td><td>Microsoft-Windows-TerminalServices-RDPClient/Operational </td><td>Microsoft-Windows-TerminalServices-ClientActiveXCore </td></tr><tr><td>129 </td><td>Task Scheduler Activities </td><td>New Task Registered </td><td>106 </td><td>Information </td><td>Microsoft-Windows-TaskScheduler/Operational </td><td>Microsoft-Windows-TaskScheduler </td></tr><tr><td>130 </td><td>Task Scheduler Activities </td><td>Task Deleted </td><td>141 </td><td>Information </td><td>Microsoft-Windows-TaskScheduler/Operational </td><td>Microsoft-Windows-TaskScheduler </td></tr><tr><td>131 </td><td>Task Scheduler Activities </td><td>Task Disabled </td><td>142 </td><td>Information </td><td>Microsoft-Windows-TaskScheduler/Operational </td><td>Microsoft-Windows-TaskScheduler </td></tr><tr><td>132 </td><td>Task Scheduler Activities </td><td>Task Launched </td><td>200 </td><td>Information </td><td>Microsoft-Windows-TaskScheduler/Operational </td><td>Microsoft-Windows-TaskScheduler </td></tr><tr><td>133 </td><td>Printing Services </td><td>Printing Document </td><td>307 </td><td>Information </td><td>Microsoft-Windows-PrintService/Operational </td><td>Microsoft-Windows-PrintService </td></tr><tr><td>134 </td><td>PowerShell Activities </td><td>Exception Raised </td><td>4103 </td><td>Information </td><td>Microsoft-Windows-Powershell/Operational </td><td>Microsoft-Windows-Powershell </td></tr><tr><td>135 </td><td>PowerShell Activities </td><td>Exception Raised </td><td>4104 </td><td>Information </td><td>Microsoft-Windows-Powershell/Operational </td><td>Microsoft-Windows-Powershell </td></tr><tr><td>136 </td><td>PowerShell Activities </td><td>Exception Raised </td><td>4105 </td><td>Information </td><td>Microsoft-Windows-Powershell/Operational </td><td>Microsoft-Windows-Powershell </td></tr><tr><td>137 </td><td>PowerShell Activities </td><td>Exception Raised </td><td>4106 </td><td>Information </td><td>Microsoft-Windows-Powershell/Operational </td><td>Microsoft-Windows-Powershell </td></tr><tr><td>138 </td><td>Mobile Device Activities </td><td>Network Connection and Disconnection Status (Wired and Wireless) </td><td>10000, 10001 </td><td>Information </td><td>Microsoft-Windows-NetworkProfile/Operational </td><td>Microsoft-Windows-NetworkProfile </td></tr><tr><td>139 </td><td>Account Usage </td><td>Group Assigned to new Session </td><td>300 </td><td>Information </td><td>Microsoft-Windows-LSA/Operational </td><td>LsaSrv </td></tr><tr><td>140 </td><td>External Media Detection </td><td>New Mass Storage Installation </td><td>400, 410 </td><td>Information </td><td>Microsoft-Windows-Kernel-PnP/Device Configuration </td><td>Microsoft-Windows-Kernel-PnP </td></tr><tr><td>141 </td><td>DNS/Directory Services </td><td>DNS Request/Response </td><td>256, 257 </td><td>Information </td><td>Microsoft-Windows-DNSServer/Analytical </td><td>Microsoft-Windows-DNSServer </td></tr><tr><td>142 </td><td>DNS/Directory Services </td><td>DNS Query Complete </td><td>3008 </td><td>Information </td><td>Microsoft-Windows-DNS-Client/Operational </td><td>Microsoft-Windows-DNS-Client </td></tr><tr><td>143 </td><td>DNS/Directory Services </td><td>DNS Response Complete </td><td>3020 </td><td>Information </td><td>Microsoft-Windows-DNS-Client/Operational </td><td>Microsoft-Windows-DNS-Client </td></tr><tr><td>144 </td><td>Kernel Driver Signing </td><td>Code Integrity Check </td><td>3001, 3002, 3003, 3004, 3010, 3023 </td><td>Warning, Error </td><td>Microsoft-Windows-CodeIntegrity/Operational </td><td>Microsoft-Windows-CodeIntegrity </td></tr><tr><td>145 </td><td>Certificate Services </td><td>CA Permissions Corrupted or Missing </td><td>90 </td><td>Information </td><td>Microsoft-Windows-CertificationAuthority </td><td>Microsoft-Windows-CertificationAuthority </td></tr><tr><td>146 </td><td>Microsoft Cryptography API </td><td>Cert Trust Chain Build Failed </td><td>11 </td><td>Information </td><td>Microsoft-Windows-CAPI2/Operational </td><td>Microsoft-Windows-CAPI2 </td></tr><tr><td>147 </td><td>Microsoft Cryptography API </td><td>Private Key Accessed </td><td>70 </td><td>Information </td><td>Microsoft-Windows-CAPI2/Operational </td><td>Microsoft-Windows-CAPI2 </td></tr><tr><td>148 </td><td>Microsoft Cryptography API </td><td>X.509 Object </td><td>90 </td><td>Information </td><td>Microsoft-Windows-CAPI2/Operational </td><td>Microsoft-Windows-CAPI2 </td></tr><tr><td>149 </td><td>Application Whitelisting </td><td>Application Ran </td><td>8020 </td><td>Information </td><td>Microsoft-Windows-AppLocker/Packaged app-Execution </td><td>Microsoft-Windows-AppLocker </td></tr><tr><td>150 </td><td>Application Whitelisting </td><td>Application Installed </td><td>8023 </td><td>Information </td><td>Microsoft-Windows-AppLocker/Packaged app-Deployment </td><td>Microsoft-Windows-AppLocker </td></tr><tr><td>151 </td><td>Application Whitelisting </td><td>AppLocker Warning </td><td>8006 </td><td>Error </td><td>Microsoft-Windows-AppLocker/MSI and Script </td><td>Microsoft-Windows-AppLocker </td></tr><tr><td>152 </td><td>Application Whitelisting </td><td>AppLocker Warning </td><td>8007 </td><td>Warning </td><td>Microsoft-Windows-AppLocker/MSI and Script </td><td>Microsoft-Windows-AppLocker </td></tr><tr><td>153 </td><td>Application Whitelisting </td><td>Script or Installer ran </td><td>8005 </td><td>Information </td><td>Microsoft-Windows-AppLocker/MSI and Script </td><td>Microsoft-Windows-AppLocker </td></tr><tr><td>154 </td><td>Application Whitelisting </td><td>AppLocker Block </td><td>8002 </td><td>Information </td><td>Microsoft-Windows-AppLocker/EXE and DLL </td><td>Microsoft-Windows-AppLocker </td></tr><tr><td>155 </td><td>Application Whitelisting </td><td>AppLocker Block </td><td>8003 </td><td>Error </td><td>Microsoft-Windows-AppLocker/EXE and DLL </td><td>Microsoft-Windows-AppLocker </td></tr><tr><td>156 </td><td>Application Whitelisting </td><td>AppLocker Block </td><td>8004 </td><td>Warning </td><td>Microsoft-Windows-AppLocker/EXE and DLL </td><td>Microsoft-Windows-AppLocker </td></tr><tr><td>157 </td><td>Software and Service Installation </td><td>New Application Installation </td><td>903, 904 </td><td>Information </td><td>Microsoft-Windows-Application-Experience/Program-Inventory </td><td>Microsoft-Windows-Application-Experience </td></tr><tr><td>158 </td><td>Software and Service Installation </td><td>Removed Application </td><td>907, 908 </td><td>Information </td><td>Microsoft-Windows-Application-Experience/Program-Inventory </td><td>Microsoft-Windows-Application-Experience </td></tr><tr><td>159 </td><td>Software and Service Installation </td><td>Summary of Software Activities </td><td>800 </td><td>Information </td><td>Microsoft-Windows-Application-Experience/Program-Inventory </td><td>Microsoft-Windows-Application-Experience </td></tr><tr><td>160 </td><td>Software and Service Installation </td><td>Updated Application </td><td>905, 906 </td><td>Information </td><td>Microsoft-Windows-Application-Experience/Program-Inventory </td><td>Microsoft-Windows-Application-Experience </td></tr><tr><td>161 </td><td>Account Usage </td><td>Create Profile failed </td><td>1518 </td><td>Error </td><td>Application </td><td>Microsoft-Windows-User Profiles Service </td></tr><tr><td>162 </td><td>Account Usage </td><td>Temp Profile Logon </td><td>1511 </td><td>Error </td><td>Application </td><td>Microsoft-Windows-User Profiles Service </td></tr><tr><td>163 </td><td>Application Crashes </td><td>App Crash </td><td>1000 </td><td>Error </td><td>Application </td><td>Application Error </td></tr><tr><td>164 </td><td>Application Crashes </td><td>App Error </td><td>1000 </td><td>Error </td><td>Application </td><td>Application Error </td></tr><tr><td>165 </td><td>Application Crashes </td><td>App Hang </td><td>1002 </td><td>Error </td><td>Application </td><td>Application Hang </td></tr><tr><td>166 </td><td>Application Crashes </td><td>WER </td><td>1001 </td><td>Information </td><td>Application </td><td>Windows Error Reporting </td></tr><tr><td>167 </td><td>Application Whitelisting </td><td>SRP Block </td><td>865, 866, 867, 868, 882 </td><td>Warning </td><td>Application </td><td>Microsoft-Windows-SoftwareRestrictionPolicies </td></tr><tr><td>168 </td><td>Software and Service Installation </td><td>New MSI File Installed </td><td>1022, 1033 </td><td>Information </td><td>Application </td><td>MsiInstaller </td></tr></tbody></table>

## What log events should I collect/send to my SIEM?

### Account Management

&#x20;           4740: Account Lockouts

&#x20;           4627: Group Membership Information

&#x20;           4703: A user right was adjusted.

&#x20;           4704: A user right (privilege) was assigned.

&#x20;           4704: A user right (privilege) was removed.

&#x20;           4720: A user account was created.

&#x20;           4722: A user account was enabled.

&#x20;           4723: Attempt was made to change account's password.

&#x20;           4724: An attempt was made to reset an account's password.

&#x20;           4725: A user account was disabled.

&#x20;           4726: A user account was deleted.

&#x20;           4727: A security-enabled global group was created.

&#x20;           4728: A member was added to a security-enabled global group.

&#x20;           4729: A member was removed to a security-enabled global group.

&#x20;           4730: A security-enabled global group was deleted.

&#x20;           4731: A security-enabled local group was created.

&#x20;           4732: A member was added to a security-enabled local group.

&#x20;           4733: A member was removed from a security-enabled local group.

&#x20;           4734: A security-enabled local group was deleted.

&#x20;           4735: Modification of Security-enabled groups

&#x20;           4737: A security-enabled global group was changed.

&#x20;           4738: A user account was changed.

&#x20;           4739: Domain Policy was changed.

&#x20;           4741: A computer account was created.

&#x20;           4742: A computer account was changed.

&#x20;           4743: A computer account was deleted.

&#x20;           4744: A security-disabled local group was created.

&#x20;           4745: A security-disabled local group was changed.

&#x20;           4746: A member was added to a security-disabled local group.

&#x20;           4747: A member was removed from a security-disabled local group.

&#x20;           4748: A security-disabled local group was deleted.

&#x20;           4749: A security-disabled global group was created.

&#x20;           4750: A security-disabled global group was changed.

&#x20;           4751: A member was added to a security-disabled global group.

&#x20;           4752: A member was removed from a security-disabled global group.

&#x20;           4753: A security-disabled global group was deleted.

&#x20;           4754: A security-enabled universal group was created.

&#x20;           4755: A security-enabled universal group was changed.

&#x20;           4756: A security-enabled universal group was changed.

&#x20;           4757: A security-enabled universal group was changed.

&#x20;           4758: A security-enabled universal group was created.

&#x20;           4759: A security-disabled universal group was created.

&#x20;           4760: A security-disabled universal group was changed.

&#x20;           4761: A member was added to a security-disabled universal group.

&#x20;           4762: A member was removed from a security-disabled universal group.

&#x20;           4763: A security-disabled universal group was deleted.

&#x20;           4764: A group's type was changed.

&#x20;           4765: SID History was added to an account.

&#x20;           4766: An attempt to add SID History to an account failed.

&#x20;           4767: A user account was unlocked.

&#x20;           4780: The ACL was set on accounts which are members of administrators group.

&#x20;           4781: The name of an account was changed.

&#x20;           4782: The password hash an account was accessed.

&#x20;           4793: The Password Policy Checking API was called.

&#x20;           4794: An attempt was made to set the Directory Services Restore Mode administrator password.

&#x20;           4798: A user's local group membership was enumerated.

&#x20;           4799: A security-enabled local group membership was enumerated.

&#x20;           5376: Credential Manager credentials were backed up.

&#x20;           5377: Credential Manager credentials were restored from a backup.

### Active Directory

&#x20;           4662: Directory Service Access Operation Performed On An Object

&#x20;           5136: A directory service object was modified.

&#x20;           5137: A directory service object was created.

&#x20;           5138: A directory service object was undeleted.

&#x20;           5139: A directory service object was moved.

&#x20;           5141: A directory service object was deleted.

&#x20;           4713: Kerberos Policy was changed.

&#x20;           4706: A new trust was created to a domain.

&#x20;           4707: A trust to a domain was removed.

&#x20;           4716: Trusted domain information was modified.

&#x20;           4717: System security access was granted to an account.

&#x20;           4718: System security access was removed from an account.

&#x20;           4739: Domain Policy was changed.

&#x20;           4864: A namespace collision was detected.

&#x20;           4865: A trusted forest information entry was added.

&#x20;           4866: A trusted forest information entry was removed.

&#x20;           4867: A trusted forest information entry was modified.

### Application Error and Hang

&#x20;           EventID=1000

&#x20;           EventID=1002

&#x20;           WER Application Crashes Reports

&#x20;           EventID=1001

### Applocker

&#x20;           Microsoft-Windows-AppLocker/EXE and DLL

&#x20;           Rules that look for Applocker EXE or Script events

&#x20;           Applocker Packaged app execution

&#x20;           Applocker Packaged app installation

### Authentication Events

&#x20; 4624: An account was successfully logged on.

&#x20; 4625: An account failed to log on.

&#x20; 4626: User/Device claims information.

&#x20; 4634: An account was successfully logged off.

&#x20; 4647: User initiated logoff.

&#x20; 4649: A replay attack was detected.

&#x20; 4672: Special privileges assigned to a new logon, administrative logins -sa, -ada, etc.

&#x20; 4675: SIDs were filtered.

&#x20; 4774: An account was mapped for logon.

&#x20; 4775: An account could not be mapped for logon.

&#x20; 4776: The computer attempted to validate the credentials for an account.

&#x20; 4777: The domain controller failed to validate the credentials for an account.

&#x20; 4778: A session was reconnected to a Window Station.

&#x20; 4779: A session was disconnected from a Window Station.

&#x20; 4800 The workstation was locked.

&#x20; 4801 The workstation was unlocked.

&#x20; 4802 The screen saver was invoked.

&#x20; 4803 The screen saver was dismissed.

&#x20; 4964: Special groups have been assigned a new logon.

&#x20; 5378 The requested credentials delegation was disallowed by policy.

&#x20; \*\*\*\* Suppress \[EventData\[Data\[1]="S-1-5-18"]] to avoid SECURITY\_LOCAL\_SYSTEM\_RID\*\*\*\*\*\*\*

### BITS

&#x20; Microsoft-Windows-Bits-Client/Operational

### Certificate Authority

&#x20;           Security

&#x20;           4886: Certificate Services received certificate request

&#x20;           4887: Approved and Certificate issued

&#x20;           4888: Denied request

### Code Integrity

&#x20; Windows Code Integrity Checks (Kernel-mode Driver and User-mode Protected Media Validation)

&#x20; Level = 2 or 3

&#x20; and Event ID is

&#x20; EventID=3001 or

&#x20; EventID=3002 or

&#x20; EventID=3003 or

&#x20; EventID=3004 or

&#x20; EventID=3010 or

&#x20; EventID=3023)

&#x20; Windows Code Integrity Checks (Invalid hashes)

&#x20; Level=0 or Level=4 and

&#x20; EventID=5038 or

&#x20; EventID=6281 or

&#x20; EventID=6410

### DNS Logs

&#x20; 3008: DNS Client events Query Completed

&#x20; Suppress EventData\[Data\[@Name="QueryOptions"]="140737488355328"

&#x20; Suppress EventData\[Data\[@Name="QueryResults"]=""

&#x20; 150: DNS Server could not load or initialize the plug-in DLL

&#x20; 770: DNS Server plugin DLL has been loaded

&#x20; 541: The setting serverlevelplugindll on scope . has been set to $dll\_path

### Drivers Logs

&#x20; Microsoft-Windows-Kernel-PnP

&#x20; Level=3 and EventID=219

&#x20; Microsoft-Windows-DriverFrameworks-UserMode/Operational

&#x20; Detect User-Mode drivers loaded - for potential BadUSB detection.

&#x20; EventID=2004

### EventLog Diagnostics

&#x20; 1100: The event logging service has shut down.

&#x20; 1104: The security log is now full.

&#x20; 1105: Event log automatic backup.

&#x20; 1108: The event logging service encountered an error while processing an incoming event published from %1

### Explicit Login Credentials

&#x20; Microsoft-Windows-Security-Auditing

&#x20; Level=4 or Level=0 and EventID=4648 and ProcessName != 'C:\Windows\System32\taskhost.exe'

### Firewall Events

### &#x20;

&#x20; Microsoft-Windows-Windows Firewall With Advanced Security/Firewall

&#x20; 4944: The following policy was active when the Windows Firewall started.

&#x20; 4945: A rule was listed when the Windows Firewall started.

&#x20; 4946: A change has been made to Windows Firewall exception list. A rule was added.

&#x20; 4947: A change has been made to Windows Firewall exception list. A rule was modified.

&#x20; 4948: A change has been made to Windows Firewall exception list. A rule was deleted.

&#x20; 4949: Windows Firewall settings were restored to the default values.

&#x20; 4950: A Windows Firewall setting has changed.

&#x20; 4951: A rule has been ignored because its major version number was not recognized by Windows Firewall.

&#x20; 4952: Parts of a rule have been ignored because its minor version number was not recognized by Windows Firewall. The other parts of the rule will be enforced.

&#x20; 4953: A rule has been ignored by Windows Firewall because it could not parse the rule.

&#x20; 4954: Windows Firewall Group Policy settings have changed. The new settings have been applied.

&#x20; 4956: Windows Firewall has changed the active profile.

&#x20; 4957: Windows Firewall did not apply the following rule

&#x20; 4958: Windows Firewall did not apply the following rule because the rule referred to items not configured on this computer

&#x20; Security Log

&#x20; 5024: The Windows Firewall Service has started successfully.

&#x20; 5025:  The Windows Firewall Service has been stopped.

&#x20; 5027:  The Windows Firewall Service was unable to retrieve the security policy from local storage. The service will continue enforcing the current policy.

&#x20; 5028:  The Windows Firewall Service was unable to parse the new security policy. The service will continue with currently enforced policy.

&#x20; 5029:  The Windows Firewall Service failed to initialize the driver. The service will continue to enforce the current policy.

&#x20; 5030:  The Windows Firewall Service failed to start.

&#x20; 5032:  Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network.

&#x20; 5033:  The Windows Firewall Driver has started successfully.

&#x20; 5034:  The Windows Firewall Driver was stopped.

&#x20; 5035:  The Windows Firewall Driver failed to start.

&#x20; 5037:  The Windows Firewall Driver detected critical runtime error. Terminating.

### External Devices Log

&#x20; Security

&#x20; 6416: A new external device was recognized by the System.

&#x20; 6419: A request was made to disable a device.

&#x20; 6420: A device was disabled.

&#x20; 6421: A request was made to enable a device.

&#x20; 6422: A device was enabled..

&#x20; 6423: The installation of this device is forbidden by system policy.

&#x20; 6424: The installation of this device was allowed after having previously been forbidden by policy.

&#x20; Microsoft-Windows-USB-USBHUB3-Analytic

&#x20; Level=4 and EventID=43

&#x20; EventData\[Data\[@Name='fid\_DeviceDescription']="USB Mass Storage Device

&#x20; Microsoft-Windows-Kernel-PnP/Configuration

&#x20; 400, 410: New Mass Storage Device Installation

&#x20; Level=4 and

&#x20; EventID=400 or EventID=410

&#x20; and EventData\[Data\[@Name='DriverName']=usbstor.inf

### GPO logs

&#x20; Microsoft-Windows-GroupPolicy

&#x20; Level 2 and

&#x20; 1085: Application of Group Policy failures

&#x20; 1125: Group Policy Service

&#x20; 1127: Group Policy Service

&#x20; 1129: Group Policy Preprocessing Networking

&#x20; Security

&#x20; 6144: Security policy in the group policy objects has been applied successfully.

&#x20; 6145: One or more errors occurred while processing security policy in the group policy object.

### Kerberos

&#x20; Security

&#x20; 4768 - A Kerberos authentication ticket (TGT) was requested

&#x20; 4769 - A Kerberos service ticket was requested

&#x20; 4770 - A Kerberos service ticket was renewed

&#x20; 4771 - A Kerberos pre-authentication failed.

&#x20; 4772 - A Kerberos authentication ticket request failed.

&#x20; 4773 - A Kerberos service ticket request failed.

### LOG Deletion

&#x20; Security

&#x20; 1102: Security Log File Cleared

&#x20; System

&#x20; 104: Log File Cleared

### Object Manipulation

&#x20; Security

&#x20; 4715: The audit policy (SACL) on an object was changed.

&#x20; 4817: Auditing settings on object were changed.

&#x20; 4656: A handle to an object was requested.

&#x20; 4658: The handle to an object was closed.

&#x20; 4660: An object was deleted.

&#x20; 4663: An attempt was made to access an object.

&#x20; 4670: Permissions on an object were changed.

### Operating System

&#x20; System

&#x20; 41: The system has rebooted without cleanly shutting down first

&#x20; 1001: Application crashes, hangs, and generic reports

&#x20; 4621: Administrator recovered system from CrashOnAuditFail.

&#x20; 6008: The previous system shutdown was unexpected.

&#x20; 1074: Shutdown initiate requests, with user, process and reason (if supplied)

&#x20; 12: System startup (12 - includes OS/SP/Version) and shutdown

&#x20; 16962: A remote call to the SAM database has been denied

&#x20; 16965: Remote calls to the SAM database have been denied in the past 900 seconds throttling window

&#x20; 16968: The following client would have been normally been denied access to the SAM database

&#x20; 16969: Remote calls to the SAM database are being restricted using the default security descriptor

&#x20; 16965: is enabled via a registry key

### &#x20; Security

&#x20; 4719: System audit policy was changed.

&#x20; 4817: A trusted logon process has been registered with the Local Security Authority.

&#x20; 4902: The Per-user audit policy table was created.

&#x20; 4906: The CrashOnAuditFail value has changed.

&#x20; 4908: Special Groups Logon table modified.

&#x20; 4912: Per User Audit Policy was changed.

&#x20; 4904: An attempt was made to register a security event source..

&#x20; 4905: An attempt was made to unregister a security event source.

&#x20; 4610: An authentication package has been loaded by the Local Security Authority.

&#x20; 4611: A trusted logon process has been registered with the Local Security Authority.

&#x20; 4614: A notification package has been loaded by the Security Account Manager.

&#x20; 4622: A security package has been loaded by the Local Security Authority.

&#x20; 4697: A service was installed in the system.

&#x20; 4817: Auditing settings on object were changed.

&#x20; 4826 Boot Configuration Data loaded.

&#x20; 4608: Windows is starting up

&#x20; Microsoft-Windows-SMBServer/Audit

&#x20; 3000: Client attempted to use SMBv1

### Privilege Use

&#x20; Security

&#x20; 4673: A privileged service was called..

&#x20; 4674: An operation was attempted on a privileged object..

&#x20; 4985: The state of a transaction has changed.

### Process execution

&#x20; Security

&#x20; 4688: Process Created

&#x20; 4699: Process Terminated

### Registry

&#x20; Security

&#x20; 4657: Registry modified events for Operations

&#x20; and EventData\[Data\[@Name=OperationType]] =

&#x20; 1904: New Registry Value created OR

&#x20; 1905: Existing Registry Value modified OR

&#x20; 1906: Registry Value Deleted

### Services

&#x20; System

&#x20; Level 0 OR 1 OR 2 OR 3 OR 4

&#x20; 7022: The service hung on starting

&#x20; 7023: The service terminated with the following error

&#x20; 7023: The service terminated with the following error

&#x20; 7024: The service terminated with service-specific error

&#x20; 7026: The following boot-start or system-start driver(s) failed to load

&#x20; 7031: The service terminated unexpectedly. It has done this x time(s).

&#x20; 7040: Service Start Type Changed

&#x20; 7045: Service Installed

### Network Shares

&#x20; Security

&#x20; 5140: Network share object access

&#x20; 5142: Network Share create

&#x20; 5144: Network Share Delete

&#x20; 5145: A network share object was checked to see whether client can be granted desired access

&#x20; 5168: SPN check for SMB/SMB2 failed.

&#x20; Microsoft-Windows-SMBClient/Operational

&#x20; Event ID: 30622 OR

&#x20; Event ID: 30624

&#x20; Microsoft-Windows-SMBClient/Security

&#x20; Microsoft-Windows-SMBServer/Security

### System Time Modification

&#x20; Security

&#x20; 4616: System Time Changed

### Task Scheduler

&#x20; Microsoft-Windows-TaskScheduler/Operational

&#x20; EventID=106 or

&#x20; EventID=129 or

&#x20; EventID=141 or

&#x20; EventID=142 or

&#x20; EventID=200 or

&#x20; EventID=201

&#x20; Security

&#x20; 4698: A scheduled task was created

&#x20; 4699: A scheduled task was deleted

&#x20; 4700: A scheduled task was enabled

&#x20; 4701: A scheduled task was disabled

&#x20; 4702: A scheduled task was updated

### PowerShell

&#x20; Microsoft-Windows-PowerShell/Operational

&#x20; Microsoft-Windows-PowerShell-DesiredStateConfiguration-FileDownloadManager/Operational

&#x20; Windows PowerShell

### Print Jobs

&#x20; Microsoft-Windows-PrintService/Operational

&#x20; Level=4 and EventID=307

### Terminal Services

&#x20; All TSG Admin Events

&#x20; Microsoft-Windows-TerminalServices-Gateway/Admin

&#x20; Microsoft-Windows-TerminalServices-Gateway/Operational

&#x20; All TSG Client USB Device Events

&#x20; Microsoft-Windows-TerminalServices-ClientUSBDevices/Admin

&#x20; All TSG Client USB Device Events

&#x20; Microsoft-Windows-TerminalServices-ClientUSBDevices/Operational

&#x20; All TSG Client USB PNP Events

&#x20; Microsoft-Windows-TerminalServices-PnPDevices/Admin

&#x20; All TSG Client USB PNP Events

&#x20; Microsoft-Windows-TerminalServices-PnPDevices/Operational

&#x20; All TSG Printer Events

&#x20; Microsoft-Windows-TerminalServices-Printers/Admin

&#x20; All TSG Printer Events

&#x20; Microsoft-Windows-TerminalServices-Printers/Operational

&#x20; All TSG Server USB Device Events

&#x20; Microsoft-Windows-TerminalServices-ServerUSBDevices/Admin

&#x20; All TSG Server USB Device Events

&#x20; Microsoft-Windows-TerminalServices-ServerUSBDevices/Operational

### WMI

&#x20; Microsoft-Windows-WMI-Activity/Operational

&#x20; Microsoft-Windows-TPM-WMI

&#x20; 513: TPM Owner Authorization information was backed up successfully to Active Directory Domain Services.

&#x20; 514: Failed to backup TPM Owner Authorization information to Active Directory Domain Services.

### Windows Defender

&#x20; Microsoft-Windows-Windows Defender/Operational

&#x20; Event ID: 1006 OR 1007 OR 1008 OR 1009

&#x20; Event ID: 1116 OR 1117 OR 1118 OR 1119

### Wireless

&#x20; Security

&#x20; 5632: Request made to authenticate to Wireless network.

&#x20; 5633: A request was made to authenticate to a wired network.
