EventSentry
  • System32
  • Sysmon
  • Events
  • Compliance
  • Validator
  • TLS/SSL
  • GeoIP
  • Tools


Windows Security Events



Audit Category
  • Object Access (7)
  • Logon/Logoff (4)
  • Policy Change (3)
  • Privilege Use (2)
  • DS Access (1)
  • Detailed Tracking (1)
  • System (1)
Operating Systems
  • Windows 2016 (19)
  • Windows 2019 (19)
  • Windows 2022 (19)
  • Windows 10 (18)
  • Windows 2008 (18)
  • Windows 2008 R2 (18)
  • Windows 2012 (18)
  • Windows 2012 R2 (18)
  • Windows 7 (17)
  • Windows 8 (17)
  • Windows 8.1 (17)
  • Windows Vista (17)
  • Windows 11 (3)
Tags
  • Audit Success (18)
  • Audit Failure (5)
  • CJIS (5)
  • HIPAA (3)
  • ISO 27001:2013 (3)
  • CMMC L1 (2)
  • Domain Controller (2)
  • NIST 800-171 (2)
  • NIST SP 800-53 (2)
  • PCI-DSS (2)
Auditing
  • Always (6)
  • Conditional (4)
  • Rarely (2)
  • Off (1)
Volume
  • High (5)
  • Low (5)
  • Medium (5)
  • Very high (4)
Audit Subcategory
  • File System (6)
  • Registry (6)
  • Kernel Object (4)
  • Logon (3)
  • Removable Storage (3)
  • Audit Policy Change (2)
  • Authorization Policy Change (2)
  • Sensitive Privilege Use (2)
  • Account Lockout (1)
  • Authentication Policy Change (1)
  • Directory Service Access (1)
  • Handle Manipulation (1)
  • Non Sensitive Privilege Use (1)
  • Other Logon/Logoff Events (1)
  • Process Termination (1)
  • SAM (1)
  • Security State Change (1)

AppLocker
  • All AppLocker events
EventSentry
  • All EventSentry events
Security
  • All Windows Security events
Sysmon
  • All Sysmon events
ID Event Description
4616 The system time was changed
Audit Success
4624 An account was successfully logged on
CJIS, Audit Success, ISO 27001:2013, HIPAA, NIST SP 800-53, CMMC L1, NIST 800-171
4625 An account failed to log on
Audit Failure, CJIS, ISO 27001:2013, PCI-DSS, HIPAA, NIST SP 800-53, NIST 800-171, CMMC L1
4648 A logon was attempted using explicit credentials
Audit Success
4649 A replay attack was detected
Domain Controller, Audit Success, Audit Failure, PCI-DSS, HIPAA, CJIS, ISO 27001:2013
4656 A handle to an object was requested
Audit Failure, Audit Success, CJIS
4657 A registry value was modified
Audit Success
4658 The handle to an object was closed
Audit Success
4660 An object was deleted
Audit Success
4661 A handle to an object was requested
Domain Controller, Audit Success, Audit Failure
4663 An attempt was made to access an object
Audit Success, CJIS
4670 Permissions on an object were changed
Audit Success
4673 A privileged service was called
Audit Success
4674 An operation was attempted on a privileged object
Audit Failure, Audit Success
4689 A process has exited
Audit Success
4703 A token right was adjusted
Audit Success
4904 An attempt was made to register a security event source
Audit Success
4905 An attempt was made to unregister a security event source
Audit Success
4985 The state of a transaction has changed
Audit Success



© netikus.net ltd 2002-2025 | EventSentry | Event Log Messages | Codes | Sysmon | STIG | AppLocker | Privacy Policy