EventSentry
  • System32
  • Sysmon
  • Events
  • Compliance
  • Validator
  • TLS/SSL
  • GeoIP
  • Tools


Windows Security Events



Audit Category
  • Object Access (9)
Operating Systems
  • Windows 10 (9)
  • Windows 2008 (9)
  • Windows 2008 R2 (9)
  • Windows 2012 (9)
  • Windows 2012 R2 (9)
  • Windows 2016 (9)
  • Windows 2019 (9)
  • Windows 2022 (9)
  • Windows 2025 (9)
  • Windows 7 (9)
  • Windows 8 (9)
  • Windows 8.1 (9)
  • Windows Vista (9)
  • Windows 11 (5)
Tags
  • Audit Success (7)
  • CJIS (2)
  • Audit Failure (1)
Auditing
  • Always (1)
  • Conditional (1)
  • Off (1)
  • Rarely (1)
Volume
    Audit Subcategory
    • File System (9)
    • Registry (5)
    • Kernel Object (4)
    • Removable Storage (3)
    • Authentication Policy Change (1)
    • Authorization Policy Change (1)
    • Handle Manipulation (1)

    AppLocker
    • All AppLocker events
    EventSentry
    • All EventSentry events
    Security
    • All Windows Security events
    Sysmon
    • All Sysmon events
    IDEvent Description
    4656 A handle to an object was requested
    Audit Failure, Audit Success, CJIS
    4658 The handle to an object was closed
    Audit Success
    4659 A handle to an object was requested with intent to delete
    4660 An object was deleted
    Audit Success
    4663 An attempt was made to access an object
    Audit Success, CJIS
    4664 An attempt was made to create a hard link
    Audit Success
    4670 Permissions on an object were changed
    Audit Success
    4985 The state of a transaction has changed
    Audit Success
    5051 A file was virtualized.



    © netikus.net ltd 2002-2026 | EventSentry Events | Codes | Sysmon | STIG | AppLocker | Privacy Policy