EventSentry
  • System32
  • Sysmon
  • Events
  • Compliance
  • Validator
  • TLS/SSL
  • GeoIP
  • Tools


Windows Security Events



Audit Category
  • Object Access (4)
  • DS Access (1)
Operating Systems
  • Windows 10 (5)
  • Windows 2008 (5)
  • Windows 2008 R2 (5)
  • Windows 2012 (5)
  • Windows 2012 R2 (5)
  • Windows 2016 (5)
  • Windows 2019 (5)
  • Windows 2022 (5)
  • Windows 7 (5)
  • Windows 8 (5)
  • Windows 8.1 (5)
  • Windows Vista (5)
  • Windows 11 (1)
Tags
  • Audit Success (5)
  • Audit Failure (2)
  • CJIS (1)
  • Domain Controller (1)
Auditing
  • Rarely (2)
  • Conditional (1)
  • Off (1)
Volume
  • High (1)
  • Very high (1)
Audit Subcategory
  • File System (4)
  • Kernel Object (2)
  • Registry (2)
  • Directory Service Access (1)
  • Removable Storage (1)
  • SAM (1)

AppLocker
  • All AppLocker events
EventSentry
  • All EventSentry events
Security
  • All Windows Security events
Sysmon
  • All Sysmon events
ID Event Description
4656 A handle to an object was requested
Audit Failure, Audit Success, CJIS
4660 An object was deleted
Audit Success
4661 A handle to an object was requested
Domain Controller, Audit Success, Audit Failure
4664 An attempt was made to create a hard link
Audit Success
4985 The state of a transaction has changed
Audit Success



© netikus.net ltd 2002-2025 | EventSentry | Event Log Messages | Codes | Sysmon | STIG | AppLocker | Privacy Policy