EventSentry
  • System32
  • Sysmon
  • Events
  • Compliance
  • Validator
  • TLS/SSL
  • GeoIP
  • Tools


Windows Security Events



Audit Category
  • Object Access (4)
  • DS Access (2)
  • Privilege Use (1)
Operating Systems
  • Windows 10 (7)
  • Windows 2008 (7)
  • Windows 2008 R2 (7)
  • Windows 2012 (7)
  • Windows 2012 R2 (7)
  • Windows 2016 (7)
  • Windows 2019 (7)
  • Windows 2022 (7)
  • Windows 7 (7)
  • Windows 8 (7)
  • Windows 8.1 (7)
  • Windows Vista (6)
  • Windows 11 (1)
Tags
  • Audit Success (6)
  • Audit Failure (5)
  • CJIS (2)
  • Domain Controller (2)
Auditing
  • Conditional (3)
  • Always (1)
  • Off (1)
  • Rarely (1)
Volume
  • High (3)
  • Very high (3)
  • Medium (2)
  • Low (1)
Audit Subcategory
  • File System (3)
  • Directory Service Access (2)
  • Kernel Object (2)
  • Registry (2)
  • Removable Storage (2)
  • File Share (1)
  • SAM (1)
  • Sensitive Privilege Use (1)

AppLocker
  • All AppLocker events
EventSentry
  • All EventSentry events
Security
  • All Windows Security events
Sysmon
  • All Sysmon events
ID Event Description
4656 A handle to an object was requested
Audit Failure, Audit Success, CJIS
4659 A handle to an object was requested with intent to delete
4661 A handle to an object was requested
Domain Controller, Audit Success, Audit Failure
4662 An operation was performed on an object
Domain Controller, Audit Success, Audit Failure
4663 An attempt was made to access an object
Audit Success, CJIS
4674 An operation was attempted on a privileged object
Audit Failure, Audit Success
5140 A network share object was accessed
Audit Success, Audit Failure



© netikus.net ltd 2002-2025 | EventSentry | Event Log Messages | Codes | Sysmon | STIG | AppLocker | Privacy Policy