EventSentry
  • System32
  • Sysmon
  • Events
  • Compliance
  • Validator
  • TLS/SSL
  • GeoIP
  • Tools


Windows Security Events



Audit Category
  • Account Management (16)
Operating Systems
  • Windows 2008 (16)
  • Windows 2008 R2 (16)
  • Windows 2012 (16)
  • Windows 2012 R2 (16)
  • Windows 2016 (16)
  • Windows 2022 (15)
  • Windows 2019 (14)
  • Windows 10 (13)
  • Windows 7 (13)
  • Windows 8 (13)
  • Windows 8.1 (13)
  • Windows Vista (12)
  • Windows 11 (3)
Tags
  • Domain Controller (10)
  • Audit Success (8)
  • CMMC L1 (2)
  • ISO 27001:2013 (2)
  • NIST 800-171 (2)
  • NIST SP 800-53 (2)
  • PCI-DSS (1)
Auditing
  • Always (3)
Volume
  • Low (3)
Audit Subcategory
  • Distribution Group Management (6)
  • Security Group Management (6)
  • Computer Account Management (2)
  • User Account Management (2)

AppLocker
  • All AppLocker events
EventSentry
  • All EventSentry events
Security
  • All Windows Security events
Sysmon
  • All Sysmon events
ID Event Description
4720 A user account was created
ISO 27001:2013, NIST SP 800-53, Audit Success, PCI-DSS, NIST 800-171, CMMC L1
4727 A security-enabled global group was created
Domain Controller
4731 A security-enabled local group was created
Audit Success
4735 A security-enabled local group was changed
Audit Success
4737 A security-enabled global group was changed
Domain Controller
4738 A user account was changed
ISO 27001:2013, NIST 800-171, NIST SP 800-53, Audit Success, CMMC L1
4741 A computer account was created
Domain Controller, Audit Success
4742 A computer account was changed
Domain Controller, Audit Success
4744 A security-disabled local group was created
4745 A security-disabled local group was changed
4749 A security-disabled global group was created
Domain Controller, Audit Success
4750 A security-disabled global group was changed
Domain Controller, Audit Success
4754 A security-enabled universal group was created
Domain Controller
4755 A security-enabled universal group was changed
Domain Controller
4759 A security-disabled universal group was created
Domain Controller
4760 A security-disabled universal group was changed
Domain Controller



© netikus.net ltd 2002-2025 | EventSentry | Event Log Messages | Codes | Sysmon | STIG | AppLocker | Privacy Policy