H3AD-REF / CHEATSHEETS / WINDOWS EVENT IDS

The IDs You Should
Already Know By Heart.

The handful of Windows Event IDs that carry most of the weight during triage: logon and account activity, Kerberos ticket abuse, PowerShell script content, and the Sysmon events that expose process and file behavior. Tables, not cards, because the point here is speed, not depth. For the full 105-event catalog with per-event detection guidance, see WIN-EVT.

Authentication & Logon

The events that fire every time someone, or something, proves who they are.

Event IDNameSignificance
4624 Successful logon The logon type field matters more than the ID itself. Type 2 is interactive, type 3 is network, type 10 is RDP.
4625 Failed logon One failure means little. A cluster of them against one account from a single source is the classic brute-force signal.
4634 / 4647 Logoff (system / user initiated) 4634 fires when the system tears the session down, 4647 when the user logs off directly. Useful for bounding how long a session actually lasted.
4648 Logon using explicit credentials Normal for runas and scheduled tasks. Also how lateral movement and credential testing show up, since it means one account authenticated as another.
4672 Special privileges assigned to new logon Flags an admin-level logon. Pair it with the matching 4624 to see exactly who just picked up elevated rights.
4776 NTLM credential validation Marks an NTLM authentication attempt. Relevant to pass-the-hash and NTLM relay hunting, especially anywhere Kerberos should have been used instead.

Account & Privilege Changes

Object management events. Individually mundane, and the backbone of privilege escalation and persistence hunting when you look at them in sequence.

Event IDNameSignificance
4720 User account created New accounts outside a known onboarding window deserve a second look, especially ones created and used within minutes of each other.
4722 User account enabled Often paired with 4720 when an attacker revives a disabled account instead of creating a new one.
4724 Password reset attempt A reset performed by someone who doesn't normally manage that account is a common account-takeover precursor.
4728 / 4732 / 4756 Member added to a security-enabled group Global (4728), local (4732), or universal (4756) group. Any of the three landing on Domain Admins or Enterprise Admins is high-signal regardless of which one fired.
4738 User account changed Broad event that catches attribute changes on an existing account. Low signal by itself, more useful in correlation with other changes.
4740 Account locked out Usually just a mistyped password. A spike across many accounts at once points to password spraying instead.

Kerberos & Lateral Movement

Ticket-granting events plus the one share-access event that's noisy enough to ignore and useful enough not to.

Event IDNameSignificance
4768 Kerberos TGT requested (AS-REQ) The start of Kerberos authentication. Pair with 4769 to trace a ticket's full lifecycle from request to service use.
4769 Kerberos service ticket requested (TGS-REQ) The Kerberoasting indicator. One account requesting service tickets for many different SPNs in a short window is the tell.
4771 Kerberos pre-authentication failed Behaves like 4625 for Kerberos. Repeated failures point to brute-force or password-guessing against the KDC.
5145 Detailed file share access check Fires constantly on any file server, so it's noisy on its own. Still the event that shows share enumeration and lateral movement over SMB.

PowerShell Logging

Four event IDs, and one of them is worth more than the other three combined.

Event IDNameSignificance
4103 Module logging Records cmdlet parameters and pipeline execution details, without necessarily showing the full script text.
4104 Script block logging The highest-value PowerShell event by a wide margin. Shows the actual script content, including anything deobfuscated at runtime.
4105 / 4106 Script start / script stop Bookends a script's execution window. Mostly useful for timing correlation against what 4103 and 4104 captured.

Sysmon Process & Network

The events that show what ran, what it talked to, and what it reached into.

Event IDNameSignificance
1 Process creation The workhorse Sysmon event. Full command line plus the parent-child chain, the backbone of most process-based hunting.
3 Network connection Source and destination IP, port, and the process that opened the connection. Simple, but a constant building block for network detections.
5 Process terminated Marks the end of a process's lifetime. Rarely interesting alone, useful for confirming a process actually ran and exited.
7 Image loaded DLL load events. Relevant to DLL sideloading and hijacking hunts, where a legitimate process loads a DLL from an unexpected path.
8 CreateRemoteThread A classic process injection indicator: one process creating a thread inside another process's address space.
10 ProcessAccess Logs one process opening a handle to another. Credential dumping shows up here when something reaches into lsass.exe.

Sysmon File & Registry

Where persistence, DNS visibility, and cleanup behavior show up on disk and in the hive.

Event IDNameSignificance
11 FileCreate Logs new file writes. Broad by design, usually filtered down to specific paths like startup folders and temp directories for real hunts.
12 / 13 / 14 Registry object added/deleted, value set, object renamed The persistence trio. Run keys and service entries created or modified through the registry all land here.
22 DNS query Sysmon's own DNS visibility, independent of any DNS server logs. Useful for tying C2 beaconing back to the exact process that made the request.
23 FileDelete Anti-forensics and cleanup often shows up here first, especially deletions of logs, tools, or dropped payloads right after use.

Context Beats The ID

The one thing every row above leaves out, because it doesn't fit in a table cell.

CONTEXT

The ID Alone Isn't Enough

It tells you what happened. The fields tell you if it matters.
An event ID marks a category of activity, nothing more. A 4624 with logon type 3 from a file server is unremarkable; the same ID with logon type 10 on an account that never touches RDP is not. A Sysmon 1 with an unremarkable parent process is background noise; one where winword.exe spawned powershell.exe is a different conversation entirely. A 4104 logging three harmless lines is nothing; one logging a base64 blob that decodes into a reverse shell is the whole incident. That layer, the fields inside the event, is what this cheatsheet skips on purpose, and it's exactly the depth WIN-EVT's full catalog provides, event by event, across all 105 entries.