EventSentry
  • System32
  • Sysmon
  • Events
  • Compliance
  • Validator
  • TLS/SSL
  • GeoIP
  • Tools


Windows Security Events



Audit Category
  • Detailed Tracking (7)
Operating Systems
  • Windows 10 (7)
  • Windows 11 (7)
  • Windows 2012 (7)
  • Windows 2016 (7)
  • Windows 2019 (7)
  • Windows 2022 (7)
  • Windows 2025 (7)
  • Windows 8 (7)
  • Windows 2012 R2 (6)
  • Windows 8.1 (6)
Tags
  • Audit Success (7)
Auditing
    Volume
    • Low (7)
    Audit Subcategory
    • Plug and Play Events (7)
    • PnP Activity (7)

    AppLocker
    • All AppLocker events
    EventSentry
    • All EventSentry events
    Security
    • All Windows Security events
    Sysmon
    • All Sysmon events
    IDEvent Description
    6416 A new external device was recognized by the system.
    Audit Success
    6419 A request was made to disable a device.
    Audit Success
    6420 A device was disabled.
    Audit Success
    6421 A request was made to enable a device.
    Audit Success
    6422 A device was enabled.
    Audit Success
    6423 The installation of this device is forbidden by system policy.
    Audit Success
    6424 The installation of this device was allowed, after having previously been forbidden by policy.
    Audit Success



    © netikus.net ltd 2002-2026 | EventSentry Events | Codes | Sysmon | STIG | AppLocker | Privacy Policy