EventSentry
  • System32
  • Sysmon
  • Events
  • Compliance
  • Validator
  • TLS/SSL
  • GeoIP
  • Tools


Windows Security Events



Audit Category
  • Policy Change (6)
  • Object Access (1)
Operating Systems
  • Windows 2016 (7)
  • Windows 2019 (7)
  • Windows 2022 (7)
  • Windows 10 (6)
  • Windows 2012 (6)
  • Windows 2012 R2 (6)
  • Windows 8 (6)
  • Windows 8.1 (6)
  • Windows 2008 (4)
  • Windows 2008 R2 (4)
  • Windows 7 (3)
  • Windows Vista (3)
  • Windows 11 (2)
Tags
  • Audit Success (6)
  • CMMC L1 (2)
  • CMMC L3 (2)
  • ISO 27001:2013 (2)
  • NIST 800-171 (2)
  • NIST SP 800-53 (2)
Auditing
  • Always (1)
Volume
  • Low (1)
Audit Subcategory
  • Authorization Policy Change (7)
  • Authentication Policy Change (1)
  • File System (1)
  • Registry (1)

AppLocker
  • All AppLocker events
EventSentry
  • All EventSentry events
Security
  • All Windows Security events
Sysmon
  • All Sysmon events
ID Event Description
4670 Permissions on an object were changed
Audit Success
4703 A token right was adjusted
Audit Success
4704 A user right was assigned
ISO 27001:2013, NIST 800-171, NIST SP 800-53, Audit Success, CMMC L1, CMMC L3
4705 A user right was removed
ISO 27001:2013, NIST 800-171, NIST SP 800-53, Audit Success, CMMC L1, CMMC L3
4714 Data Recovery Agent group policy for Encrypting File System (EFS) has changed
4911 Resource attributes of the object were changed
Audit Success
4913 Central Access Policy on the object was changed
Audit Success



© netikus.net ltd 2002-2025 | EventSentry | Event Log Messages | Codes | Sysmon | STIG | AppLocker | Privacy Policy