Loading...
Knowledge Base

Windows Events

Title Event ID Channel Primary Fields Audit Policy
Decrypt call failed 1015 Microsoft-Windows-SMBServer/Security ClientName ClientAddress Status IP Computer ProcessID ThreadID -
Pipe Connected 18 Microsoft-Windows-Sysmon/Operational RuleName EventType ProcessGuid ProcessId PipeName Image User IP Computer ProcessID ThreadID Sysmon/Pipe Connected
Network connection 3 Microsoft-Windows-Sysmon/Operational DestinationHostname DestinationIp DestinationIsIpv6 DestinationPort DestinationPortName Image Initiated ProcessGuid ProcessId Protocol RuleName SourceHostname SourceIp SourceIsIpv6 SourcePort SourcePortName User UtcTime IP Computer ProcessID ThreadID Sysmon/Network connection
The SMB redirector selected the connection initiated with the following parameters 30830 Microsoft-Windows-SmbClient/Connectivity ServerName ConnectionType RemoteAddress LocalAddress InstanceName PortSelectionOrigin Status ConnectionId ClientCertSha1Hash IP Computer ProcessID ThreadID -
Attempt to get credential key by call package blocked by Credential Guard 4014 Microsoft-Windows-NTLM/Operational ImageName SvcHostTag IP Computer ProcessID ThreadID -
An account was successfully logged on 4624 Security SubjectUserSid SubjectUserName SubjectDomainName SubjectLogonId LogonType RestrictedAdminMode RemoteCredentialGuard ImpersonationLevel TargetUserSid TargetUserName TargetDomainName TargetLogonId LogonGuid ProcessId ProcessName WorkstationName IpAddress IpPort LogonProcessName AuthenticationPackageName IP Computer ProcessID ThreadID Audit Logon
Group membership information 4627 Security SubjectUserSid SubjectUserName SubjectDomainName SubjectLogonId LogonType TargetUserSid TargetUserName TargetDomainName TargetLogonId GroupMembership IP Computer ProcessID ThreadID Audit Group Membership
An account was logged off 4634 Security TargetUserSid TargetUserName TargetDomainName TargetLogonId LogonType IP Computer ProcessID ThreadID Audit Logoff
A logon was attempted using explicit credentials 4648 Security SubjectUserSid SubjectUserName SubjectDomainName SubjectLogonId LogonGuid TargetUserName TargetDomainName TargetLogonGuid TargetServerName TargetInfo ProcessId ProcessName IpAddress IpPort IP Computer ProcessID ThreadID Audit Logon
Special privileges assigned to new logon 4672 Security SubjectUserSid SubjectUserName SubjectDomainName SubjectLogonId PrivilegeList Computer ProcessID IP ThreadID Audit Special Logon
An attempt was made to reset an account's password 4724 Security SubjectUserSid SubjectUserName SubjectDomainName SubjectLogonId TargetSid TargetUserName TargetDomainName IP Computer ProcessID ThreadID Audit User Account Management
A computer account was created 4741 Security SubjectUserSid SubjectUserName SubjectDomainName SubjectLogonId TargetSid TargetUserName TargetDomainName SamAccountName DisplayName UserPrincipalName HomeDirectory HomePath ScriptPath ProfilePath UserWorkstations PasswordLastSet AccountExpires PrimaryGroupId AllowedToDelegateTo OldUacValue NewUacValue UserAccountControl UserParameters SidHistory LogonHours DnsHostName ServicePrincipalNames PrivilegeList IP Computer ProcessID ThreadID Audit Computer Account Management
A computer account was changed 4742 Security SubjectUserSid SubjectUserName SubjectDomainName SubjectLogonId TargetSid TargetUserName TargetDomainName SamAccountName DisplayName UserPrincipalName HomeDirectory HomePath ScriptPath ProfilePath UserWorkstations PasswordLastSet AccountExpires PrimaryGroupId AllowedToDelegateTo OldUacValue NewUacValue UserAccountControl UserParameters SidHistory LogonHours DnsHostName ServicePrincipalNames PrivilegeList IP Computer ProcessID ThreadID Audit Computer Account Management
A Kerberos authentication ticket (TGT) was requested 4768 Security TargetUserName TargetDomainName TargetSid ServiceName ServiceSid TicketOptions Status TicketEncryptionType PreAuthType IpAddress IpPort CertIssuerName CertSerialNumber CertThumbprint ResponseTicket IP Computer ProcessID ThreadID Audit Kerberos Authentication Service
A Kerberos service ticket was requested 4769 Security TargetUserName TargetDomainName LogonGuid ServiceName ServiceSid IpAddress IpPort TicketOptions TicketEncryptionType Status TransmittedServices RequestTicketHash ResponseTicketHash IP Computer ProcessID ThreadID Audit Kerberos Service Ticket Operations
The computer attempted to validate the credentials for an account 4776 Security PackageName TargetUserName Workstation Status IP Computer ProcessID ThreadID Audit Credential Validation
Certificate Services received a certificate request 4886 Security RequestId Requester Attributes Subject SubjectAlternativeName CertificateTemplate RequestOSVersion RequestCSPProvider RequestClientInfo AuthenticationService AuthenticationLevel DCOMorRPC IP Computer ProcessID ThreadID Audit Certification Services
Certificate Services approved a certificate request and issued a certificate 4887 Security RequestId Requester Attributes Subject SubjectAlternativeName CertificateTemplate CertSerialNumber AuthenticationService AuthenticationLevel DCOMorRPC IP Computer ProcessID ThreadID Audit Certification Services
Certificate Services received a certificate request 4889 Security RequestId Requester Attributes Subject SubjectAlternativeName CertificateTemplate RequestOSVersion RequestCSPProvider RequestClientInfo AuthenticationService AuthenticationLevel DCOMorRPC IP Computer ProcessID ThreadID Audit Certification Services
A network share object was accessed 5140 Security SubjectUserSid SubjectUserName SubjectDomainName SubjectLogonId ObjectType IpAddress IpPort ShareName ShareLocalPath AccessMask AccessList IP Computer ProcessID ThreadID Audit File Share
The Netlogon service created a secure channel with a client with RC4 5840 System param1 param2 param3 param4 param5 IP Computer ProcessID ThreadID -
NTLM server blocked audit: Audit Incoming NTLM Traffic that would be blocked 8002 Microsoft-Windows-NTLM/Operational ProcessName CallerPID ClientUserName ClientDomainName MechanismOID IP Computer ProcessID ThreadID Network security: Restrict NTLM: Audit Incoming NTLM Traffic
NTLM server blocked in the domain audit: Audit NTLM authentication in this domain 8003 Microsoft-Windows-NTLM/Operational UserName DomainName Workstation CallerPID ProcessName LogonType MechanismOID IP Computer ProcessID ThreadID Network security: Restrict NTLM: Audit NTLM authentication in this domain
Domain Controller Blocked Audit: Audit NTLM authentication to this domain controller 8004 Microsoft-Windows-NTLM/Operational UserName DomainName IP Computer ProcessID ThreadID Network security: Restrict NTLM: Audit NTLM authentication in this domain

SOCpedia - knowledge platform

This section contains materials on SOC and Blue Team practices: articles, news, books, and translations.