EventSentry
  • System32
  • Sysmon
  • Events
  • Compliance
  • Validator
  • TLS/SSL
  • GeoIP
  • Tools


Windows Security Events



Audit Category
  • Policy Change (10)
Operating Systems
  • Windows 10 (10)
  • Windows 2008 R2 (10)
  • Windows 2012 (10)
  • Windows 2012 R2 (10)
  • Windows 2016 (10)
  • Windows 2019 (10)
  • Windows 2022 (10)
  • Windows 7 (10)
  • Windows 8 (10)
  • Windows 8.1 (10)
  • Windows 2008 (9)
  • Windows Vista (9)
  • Windows 11 (8)
Tags
  • Audit Success (9)
Auditing
  • Always (4)
Volume
  • Low (4)
Audit Subcategory
  • Audit Policy Change (10)

AppLocker
  • All AppLocker events
EventSentry
  • All EventSentry events
Security
  • All Windows Security events
Sysmon
  • All Sysmon events
ID Event Description
4715 The audit policy (SACL) on an object was changed
Audit Success
4719 System audit policy was changed
Audit Success
4817 Auditing settings on object were changed
Audit Success
4902 The Per-user audit policy table was created
Audit Success
4904 An attempt was made to register a security event source
Audit Success
4905 An attempt was made to unregister a security event source
Audit Success
4906 The CrashOnAuditFail value has changed
Audit Success
4907 Auditing settings on object were changed
4908 Special Groups Logon table modified
Audit Success
4912 Per User Audit Policy was changed
Audit Success



© netikus.net ltd 2002-2025 | EventSentry | Event Log Messages | Codes | Sysmon | STIG | AppLocker | Privacy Policy