EventSentry
  • System32
  • Sysmon
  • Events
  • Compliance
  • Validator
  • TLS/SSL
  • GeoIP
  • Tools


Windows Security Events



Audit Category
  • Privilege Use (2)
  • Logon/Logoff (1)
  • Policy Change (1)
Operating Systems
  • Windows 10 (4)
  • Windows 2016 (4)
  • Windows 2019 (4)
  • Windows 2022 (4)
  • Windows 2008 (3)
  • Windows 2008 R2 (3)
  • Windows 2012 (3)
  • Windows 2012 R2 (3)
  • Windows 2025 (3)
  • Windows 7 (3)
  • Windows 8 (3)
  • Windows 8.1 (3)
  • Windows Vista (3)
Tags
  • Audit Success (4)
  • CMMC L2 (4)
  • NIST800-171 (4)
  • NIST800-53 (4)
  • Audit Failure (1)
Auditing
  • Conditional (3)
Volume
  • High (2)
  • Very high (2)
  • Low (1)
  • Medium (1)
Audit Subcategory
  • Sensitive Privilege Use (2)
  • Authorization Policy Change (1)
  • Non Sensitive Privilege Use (1)
  • Special Logon (1)

AppLocker
  • All AppLocker events
EventSentry
  • All EventSentry events
Security
  • All Windows Security events
Sysmon
  • All Sysmon events
ID Event Description
4672 Special privileges assigned to new logon
Audit Success, CMMC L2, NIST800-171, NIST800-53
4673 A privileged service was called
Audit Success, CMMC L2, NIST800-171, NIST800-53
4674 An operation was attempted on a privileged object
Audit Failure, Audit Success, CMMC L2, NIST800-171, NIST800-53
4703 A token right was adjusted
Audit Success, CMMC L2, NIST800-171, NIST800-53



© netikus.net ltd 2002-2026 | EventSentry Events | Codes | Sysmon | STIG | AppLocker | Privacy Policy