The IDs You Should
Already Know By Heart.
The handful of Windows Event IDs that carry most of the weight during triage: logon and account activity, Kerberos ticket abuse, PowerShell script content, and the Sysmon events that expose process and file behavior. Tables, not cards, because the point here is speed, not depth. For the full 105-event catalog with per-event detection guidance, see WIN-EVT.
Authentication & Logon
The events that fire every time someone, or something, proves who they are.
| Event ID | Name | Significance |
|---|---|---|
| 4624 | Successful logon | The logon type field matters more than the ID itself. Type 2 is interactive, type 3 is network, type 10 is RDP. |
| 4625 | Failed logon | One failure means little. A cluster of them against one account from a single source is the classic brute-force signal. |
| 4634 / 4647 | Logoff (system / user initiated) | 4634 fires when the system tears the session down, 4647 when the user logs off directly. Useful for bounding how long a session actually lasted. |
| 4648 | Logon using explicit credentials | Normal for runas and scheduled tasks. Also how lateral movement and credential testing show up, since it means one account authenticated as another. |
| 4672 | Special privileges assigned to new logon | Flags an admin-level logon. Pair it with the matching 4624 to see exactly who just picked up elevated rights. |
| 4776 | NTLM credential validation | Marks an NTLM authentication attempt. Relevant to pass-the-hash and NTLM relay hunting, especially anywhere Kerberos should have been used instead. |
Account & Privilege Changes
Object management events. Individually mundane, and the backbone of privilege escalation and persistence hunting when you look at them in sequence.
| Event ID | Name | Significance |
|---|---|---|
| 4720 | User account created | New accounts outside a known onboarding window deserve a second look, especially ones created and used within minutes of each other. |
| 4722 | User account enabled | Often paired with 4720 when an attacker revives a disabled account instead of creating a new one. |
| 4724 | Password reset attempt | A reset performed by someone who doesn't normally manage that account is a common account-takeover precursor. |
| 4728 / 4732 / 4756 | Member added to a security-enabled group | Global (4728), local (4732), or universal (4756) group. Any of the three landing on Domain Admins or Enterprise Admins is high-signal regardless of which one fired. |
| 4738 | User account changed | Broad event that catches attribute changes on an existing account. Low signal by itself, more useful in correlation with other changes. |
| 4740 | Account locked out | Usually just a mistyped password. A spike across many accounts at once points to password spraying instead. |
Kerberos & Lateral Movement
Ticket-granting events plus the one share-access event that's noisy enough to ignore and useful enough not to.
| Event ID | Name | Significance |
|---|---|---|
| 4768 | Kerberos TGT requested (AS-REQ) | The start of Kerberos authentication. Pair with 4769 to trace a ticket's full lifecycle from request to service use. |
| 4769 | Kerberos service ticket requested (TGS-REQ) | The Kerberoasting indicator. One account requesting service tickets for many different SPNs in a short window is the tell. |
| 4771 | Kerberos pre-authentication failed | Behaves like 4625 for Kerberos. Repeated failures point to brute-force or password-guessing against the KDC. |
| 5145 | Detailed file share access check | Fires constantly on any file server, so it's noisy on its own. Still the event that shows share enumeration and lateral movement over SMB. |
PowerShell Logging
Four event IDs, and one of them is worth more than the other three combined.
| Event ID | Name | Significance |
|---|---|---|
| 4103 | Module logging | Records cmdlet parameters and pipeline execution details, without necessarily showing the full script text. |
| 4104 | Script block logging | The highest-value PowerShell event by a wide margin. Shows the actual script content, including anything deobfuscated at runtime. |
| 4105 / 4106 | Script start / script stop | Bookends a script's execution window. Mostly useful for timing correlation against what 4103 and 4104 captured. |
Sysmon Process & Network
The events that show what ran, what it talked to, and what it reached into.
| Event ID | Name | Significance |
|---|---|---|
| 1 | Process creation | The workhorse Sysmon event. Full command line plus the parent-child chain, the backbone of most process-based hunting. |
| 3 | Network connection | Source and destination IP, port, and the process that opened the connection. Simple, but a constant building block for network detections. |
| 5 | Process terminated | Marks the end of a process's lifetime. Rarely interesting alone, useful for confirming a process actually ran and exited. |
| 7 | Image loaded | DLL load events. Relevant to DLL sideloading and hijacking hunts, where a legitimate process loads a DLL from an unexpected path. |
| 8 | CreateRemoteThread | A classic process injection indicator: one process creating a thread inside another process's address space. |
| 10 | ProcessAccess | Logs one process opening a handle to another. Credential dumping shows up here when something reaches into lsass.exe. |
Sysmon File & Registry
Where persistence, DNS visibility, and cleanup behavior show up on disk and in the hive.
| Event ID | Name | Significance |
|---|---|---|
| 11 | FileCreate | Logs new file writes. Broad by design, usually filtered down to specific paths like startup folders and temp directories for real hunts. |
| 12 / 13 / 14 | Registry object added/deleted, value set, object renamed | The persistence trio. Run keys and service entries created or modified through the registry all land here. |
| 22 | DNS query | Sysmon's own DNS visibility, independent of any DNS server logs. Useful for tying C2 beaconing back to the exact process that made the request. |
| 23 | FileDelete | Anti-forensics and cleanup often shows up here first, especially deletions of logs, tools, or dropped payloads right after use. |
Context Beats The ID
The one thing every row above leaves out, because it doesn't fit in a table cell.
The ID Alone Isn't Enough
winword.exe spawned powershell.exe is a different conversation entirely. A 4104 logging three harmless lines is nothing; one logging a base64 blob that decodes into a reverse shell is the whole incident. That layer, the fields inside the event, is what this cheatsheet skips on purpose, and it's exactly the depth WIN-EVT's full catalog provides, event by event, across all 105 entries.