| ID | Event Description |
|---|
| 4611 | A trusted logon process has been registered with the Local Security Authority
Audit Success |
| 4624 | An account was successfully logged on
CJIS, Audit Success, ISO 27001:2013, HIPAA, NIST SP 800-53, CMMC L1, NIST 800-171, PCI-DSS |
| 4625 | An account failed to log on
Audit Failure, CJIS, ISO 27001:2013, PCI-DSS, HIPAA, NIST SP 800-53, NIST 800-171, CMMC L1 |
| 4626 | User / Device claims information
Audit Success |
| 4627 | Group membership information
Audit Success |
| 4634 | An account was logged off
Audit Success |
| 4647 | User initiated logoff
Audit Success |
| 4648 | A logon was attempted using explicit credentials
Audit Success |
| 4649 | A replay attack was detected
Domain Controller, Audit Success, Audit Failure, PCI-DSS, HIPAA, CJIS, ISO 27001:2013 |
| 4650 | An IPsec main mode security association was established
Audit Success |
| 4651 | An IPsec main mode security association was established
Audit Success |
| 4652 | An IPsec main mode negotiation failed
Audit Failure |
| 4653 | An IPsec main mode negotiation failed
Audit Failure |
| 4654 | An IPsec quick mode negotiation failed
Audit Failure |
| 4655 | An IPsec main mode security association ended
Audit Success |
| 4688 | A new process has been created
NIST 800-171, NIST SP 800-53, Audit Success, ISO 27001:2013, CMMC L3 |
| 4739 | Domain Policy was changed
Domain Controller, NIST 800-171, NIST SP 800-53, ISO 27001:2013, Audit Success, CMMC L3 |
| 4768 | This event generates every time Key Distribution Center issues a Kerberos Ticket Granting Ticket (TGT).
Domain Controller, Audit Success, Audit Failure, CJIS, ISO 27001:2013, PCI-DSS, NIST 800-171, NIST SP 800-53 |
| 4769 | A Kerberos service ticket was requested
Domain Controller, Audit Success, Audit Failure, CJIS, ISO 27001:2013, HIPAA, NIST 800-171, NIST SP 800-53, CMMC L1 |
| 4770 | A Kerberos service ticket was renewed
Domain Controller, Audit Success |
| 4771 | Kerberos pre-authentication failed
Domain Controller, Audit Failure, CJIS, ISO 27001:2013, PCI-DSS, HIPAA, NIST 800-171, NIST SP 800-53, CMMC-L2 |
| 4772 | A Kerberos authentication ticket request failed
Domain Controller, Audit Failure, Not Implemented |
| 4773 | A Kerberos service ticket request failed
Domain Controller, Audit Failure, Not Implemented |
| 4778 | A session was reconnected to a Window Station
Audit Success, NIST 800-171, NIST SP 800-53, CMMC L3 |
| 4779 | A session was disconnected from a Window Station
Audit Success, NIST 800-171, NIST SP 800-53, CMMC L3 |
| 4820 | A Kerberos Ticket-granting-ticket (TGT) was denied because the device does not meet the access control restrictions
Domain Controller |
| 4821 | A Kerberos service ticket was denied because the user, device, or both does not meet the access control restrictions
Domain Controller |
| 4824 | Kerberos preauthentication by using DES or RC4 failed because the account was a member of the Protected User group
Domain Controller |
| 4825 | A user was denied the access to Remote Desktop. By default, users are allowed to connect only if they are members of the Remote Desktop Users group or Administrators group
|
| 4928 | An Active Directory replica source naming context was established
Domain Controller, Audit Success, Audit Failure |
| 4929 | An Active Directory replica source naming context was removed
Domain Controller, Audit Success, Audit Failure |
| 4930 | An Active Directory replica source naming context was modified
Domain Controller, Audit Success, Audit Failure |
| 4931 | An Active Directory replica destination naming context was modified
Domain Controller, Audit Success, Audit Failure |
| 4960 | IPsec dropped an inbound packet that failed an integrity check
|
| 4961 | IPsec dropped an inbound packet that failed a replay check
|
| 4962 | IPsec dropped an inbound packet that failed a replay check
|
| 4963 | IPsec dropped an inbound clear text packet that should have been secured
|
| 4965 | IPsec received a packet from a remote computer with an incorrect Security Parameter Index (SPI)
|
| 4976 | During main mode negotiation, IPsec received an invalid negotiation packet
Audit Success |
| 4977 | During quick mode negotiation, IPsec received an invalid negotiation packet
|
| 4978 | During extended mode negotiation, IPsec received an invalid negotiation packet
|
| 4979 | IPsec main mode and extended mode security associations were established
|
| 4980 | IPsec main mode and extended mode security associations were established
|
| 4981 | IPsec main mode and extended mode security associations were established
|
| 4982 | IPsec main mode and extended mode security associations were established
|
| 4983 | An IPsec extended mode negotiation failed
|
| 4984 | An IPsec extended mode negotiation failed
|
| 5031 | Windows Firewall blocked an application from accepting incoming connections on the network.
Audit Failure |
| 5032 | Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network.
Audit Failure |
| 5140 | A network share object was accessed
Audit Success, Audit Failure |
| 5142 | A network share object was added
Audit Success |
| 5143 | A network share object was modified
Audit Success |
| 5144 | A network share object was deleted
Audit Success |
| 5145 | A network share object was checked to see whether client can be granted desired access.
Audit Success, Audit Failure |
| 5146 | The Windows Filtering Platform has blocked a packet.
|
| 5147 | A more restrictive Windows Filtering Platform filter has blocked a packet.
|
| 5148 | The Windows Filtering Platform has detected a DoS attack.
Audit Failure |
| 5149 | The DoS attack has subsided and normal processing is being resumed.
Audit Failure |
| 5150 | The Windows Filtering Platform has blocked a packet.
|
| 5151 | A more restrictive Windows Filtering Platform filter has blocked a packet.
|
| 5152 | The Windows Filtering Platform has blocked a packet.
Audit Failure |
| 5153 | A more restrictive Windows Filtering Platform filter has blocked a packet.
Audit Success |
| 5154 | The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections.
Audit Success |
| 5155 | The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections.
Audit Failure |
| 5156 | The Windows Filtering Platform has allowed a connection.
Audit Success |
| 5157 | The Windows Filtering Platform has blocked a connection.
Audit Failure |
| 5158 | The Windows Filtering Platform has permitted a bind to a local port.
Audit Success |
| 5442 | The following provider was present when the Windows Filtering Platform Base Filtering Engine started.
|
| 5446 | A Windows Filtering Platform callout has been changed.
|
| 5448 | A Windows Filtering Platform provider has been changed.
|
| 5451 | An IPsec quick mode security association was established.
|
| 5452 | An IPsec quick mode security association ended.
|
| 5479 | The IPsec Policy Agent service was stopped.
|
| 5480 | IPsec Policy Agent failed to get the complete list of network interfaces on the computer.
|
| 5484 | The IPsec Policy Agent service experienced a critical failure and has shut down.
|
| 5485 | IPsec Policy Agent failed to process some IPsec filters on a plug-and-play event for network interfaces.
|
| 5632 | A request was made to authenticate to a wireless network.
Audit Success, Audit Failure |
| 5633 | A request was made to authenticate to a wired network.
Audit Success, Audit Failure |
| 5712 | A Remote Procedure Call (RPC) was attempted.
Audit Success |
| 6272 | Network Policy Server granted access to a user.
Audit Success, Audit Failure |
| 6273 | Network Policy Server denied access to a user.
Audit Success, Audit Failure |
| 6274 | Network Policy Server discarded the request for a user.
Audit Success, Audit Failure |
| 6275 | Network Policy Server discarded the accounting request for a user.
Audit Success, Audit Failure |
| 6276 | Network Policy Server quarantined a user.
Audit Success, Audit Failure |
| 6277 | Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy.
Audit Success, Audit Failure |
| 6278 | Network Policy Server granted full access to a user because the host met the defined health policy.
Audit Success, Audit Failure |
| 6279 | Network Policy Server locked the user account due to repeated failed authentication attempts.
Audit Success, Audit Failure |
| 6280 | Network Policy Server unlocked the user account.
Audit Success, Audit Failure |
| 6400 | BranchCache: Received an incorrectly formatted response while discovering availability of content.
|
| 6401 | BranchCache: Received invalid data from a peer. Data discarded.
|
| 6402 | BranchCache: The message to the hosted cache offering it data is incorrectly formatted.
|
| 528 | Successful Logon
|
| 529 | Logon Failure : Unknown username or bad password
|
| 530 | Logon Failure : Account logon time restriction violation
|
| 531 | Logon Failure : Account currently disabled
|
| 532 | Logon Failure : The specified user account has expired
|
| 533 | Logon Failure : User not allowed to logon at this computer
|
| 534 | Logon Failure : The user has note been granted the requested logon type at this machine
|
| 535 | Logon Failure : The specified account's password has expired
|
| 536 | Logon Failure : The NetLogon component is not active
|
| 537 | The logon attempt failed for other reasons
|
| 538 | The user has logged off
|
| 539 | Logon Failure : Account locked out
|
| 540 | Successful Network Logon
|
| 552 | Logon attempt using explicit credentials
|
| 672 | Authentication Ticket Request
|
| 673 | Service Ticket Request
|
| 674 | Service Ticket Renewed
|
| 675 | Pre-authentication failed
|
| 676 | Authentication Ticket Request Failed
|
| 677 | Service Ticket Request Failed
|
| 682 | Session reconnected to winstation
|
| 683 | Session disconnected from winstation
|