EventSentry
  • System32
  • Sysmon
  • Events
  • Compliance
  • Validator
  • TLS/SSL
  • GeoIP
  • Tools


Windows Security Events



Audit Category
  • Object Access (8)
  • Account Logon (2)
  • Logon/Logoff (2)
  • DS Access (1)
  • Detailed Tracking (1)
Operating Systems
  • Windows 2012 (14)
  • Windows 2012 R2 (14)
  • Windows 2016 (14)
  • Windows 2019 (14)
  • Windows 2022 (14)
  • Windows 2008 (13)
  • Windows 2008 R2 (13)
  • Windows 10 (12)
  • Windows 8 (12)
  • Windows 8.1 (12)
  • Windows 7 (11)
  • Windows Vista (11)
  • Windows 11 (9)
Tags
  • Audit Success (12)
  • Audit Failure (4)
  • Domain Controller (3)
  • ISO 27001:2013 (3)
  • NIST 800-171 (3)
  • NIST SP 800-53 (3)
  • CMMC L3 (2)
  • CJIS (1)
  • CMMC L1 (1)
  • HIPAA (1)
Auditing
  • Rarely (14)
Volume
  • High (8)
  • Very high (7)
  • Medium (4)
  • Low (3)
Audit Subcategory
  • Filtering Platform Connection (3)
  • Filtering Platform Packet Drop (2)
  • Kerberos Service Ticket Operations (2)
  • Other Logon/Logoff Events (2)
  • Central Access Policy Staging (1)
  • Directory Service Access (1)
  • File System (1)
  • Handle Manipulation (1)
  • Kernel Object (1)
  • RPC Events (1)
  • Registry (1)
  • SAM (1)

AppLocker
  • All AppLocker events
EventSentry
  • All EventSentry events
Security
  • All Windows Security events
Sysmon
  • All Sysmon events
ID Event Description
4660 An object was deleted
Audit Success
4661 A handle to an object was requested
Domain Controller, Audit Success, Audit Failure
4690 An attempt was made to duplicate a handle to an object
Audit Success
4769 A Kerberos service ticket was requested
Domain Controller, Audit Success, Audit Failure, CJIS, ISO 27001:2013, HIPAA, NIST 800-171, NIST SP 800-53, CMMC L1
4770 A Kerberos service ticket was renewed
Domain Controller, Audit Success
4802 The screen saver was invoked
ISO 27001:2013, Audit Success, NIST 800-171, NIST SP 800-53, CMMC L3
4803 The screen saver was dismissed
ISO 27001:2013, Audit Success, NIST 800-171, NIST SP 800-53, CMMC L3
4818 Proposed Central Access Policy does not grant the same access permissions as the current Central Access Policy
Audit Success
5152 The Windows Filtering Platform has blocked a packet.
Audit Failure
5153 A more restrictive Windows Filtering Platform filter has blocked a packet.
Audit Success
5156 The Windows Filtering Platform has allowed a connection.
Audit Success
5157 The Windows Filtering Platform has blocked a connection.
Audit Failure
5158 The Windows Filtering Platform has permitted a bind to a local port.
Audit Success
5712 A Remote Procedure Call (RPC) was attempted.
Audit Success



© netikus.net ltd 2002-2025 | EventSentry | Event Log Messages | Codes | Sysmon | STIG | AppLocker | Privacy Policy