EventSentry
  • System32
  • Sysmon
  • Events
  • Compliance
  • Validator
  • TLS/SSL
  • GeoIP
  • Tools


Windows Security Events



Audit Category
  • Object Access (7)
Operating Systems
  • Windows 10 (7)
  • Windows 2008 (7)
  • Windows 2008 R2 (7)
  • Windows 2012 (7)
  • Windows 2012 R2 (7)
  • Windows 2016 (7)
  • Windows 2019 (7)
  • Windows 2022 (7)
  • Windows 7 (7)
  • Windows 8 (7)
  • Windows 8.1 (7)
  • Windows Vista (7)
  • Windows 11 (1)
Tags
  • Audit Success (6)
  • CJIS (2)
  • Audit Failure (1)
Auditing
  • Always (1)
  • Off (1)
  • Rarely (1)
Volume
Audit Subcategory
  • Registry (7)
  • File System (5)
  • Kernel Object (4)
  • Removable Storage (3)
  • Authentication Policy Change (1)
  • Authorization Policy Change (1)
  • Handle Manipulation (1)

AppLocker
  • All AppLocker events
EventSentry
  • All EventSentry events
Security
  • All Windows Security events
Sysmon
  • All Sysmon events
ID Event Description
4656 A handle to an object was requested
Audit Failure, Audit Success, CJIS
4657 A registry value was modified
Audit Success
4658 The handle to an object was closed
Audit Success
4660 An object was deleted
Audit Success
4663 An attempt was made to access an object
Audit Success, CJIS
4670 Permissions on an object were changed
Audit Success
5039 A registry key was virtualized.



© netikus.net ltd 2002-2025 | EventSentry | Event Log Messages | Codes | Sysmon | STIG | AppLocker | Privacy Policy