Skip to main content
AD Academy
SOC Analyst — Read traffic, logs, and attacks
Intermediate15 minLast updated: Topic 2 of 3

Windows Event ID Map for the Analyst

The events that really matter: logins, user creation, protected groups, and process execution.

Not read

What you will learn here

  • Authentication and Accounts
  • Processes — 4688 and Sysmon
  • The events that really matter: logins, user creation, protected groups, and process execution.

Worth reading first:Network Packet Anatomy — Where to look for an attacker

Windows has thousands of events, and most learners drown in them. In practice, an analyst works with a short list of Event IDs — they cover most investigations.

Authentication and accounts: 4624 successful logon with logon type (2 local, 3 network, 10 RDP), 4625 failed logon — a burst means brute force or password spraying, 4720 user created, 4728 and 4732 added to a protected group such as Domain Admins, 4768 and 4769 Kerberos tickets where 4769 with RC4 hints at Kerberoasting, 4740 account lockout. Processes: 4688 or Sysmon 1 for process creation — read the parent-to-child chain, Sysmon 3 for network connections, Sysmon 11 and 13 for file and registry activity, 7045 and 4698 for new services and scheduled tasks. WINWORD.EXE spawning powershell.exe is the classic indicator of compromise.

Authentication and Accounts

  • 4624 — Successful Logon. The most important is Logon Type: 2 local, 3 network, 10 RDP, 4 Batch, 5 Service.
  • 4625 — Failed Logon. Dozens of events for one account = Brute Force; a single event for each account across hundreds of accounts = Password Spraying.
  • 4720 — New user created. If there was no proper request — this is Persistence.
  • 4728 / 4732 / 4756 — User added to a protected group ( Admins, Administrators). Almost always a critical event.
  • 4768 / 4769 — tickets. 4769 with Encryption Type 0x17 (RC4) against a service account = suspicion of .
  • 4740 — Account lockout, usually a result of Spraying or an old password in a service.
  • 1102 — The security log was cleared. There is almost no legitimate reason for this.

Processes — 4688 and Sysmon

  • 4688 / Sysmon Event ID 1 — Process execution. The gold is in the Parent Process field.
  • WINWORD.EXE or EXCEL.EXE running cmd.exe or powershell.exe — a classic indicator of successful phishing.
  • Sysmon 3 — Network connection from a process. powershell.exe reaching out is a red flag.
  • Sysmon 11 / 13 — File write and Registry modification, this is where Run Keys for persistence are caught.
  • 7045 / 4698 — New service or new scheduled task, the two most common persistence methods.
# All failed login attempts in the last 24 hours
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625; StartTime=(Get-Date).AddDays(-1)} |
  Group-Object { $_.Properties[5].Value } | Sort-Object Count -Descending | Select -First 10

# Who was added to protected groups
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4728,4732,4756} |
  Select TimeCreated, Message -First 20

# Process execution chain (Sysmon)
Get-WinEvent -LogName 'Microsoft-Windows-Sysmon/Operational' -MaxEvents 200 |
  Where-Object { $_.Id -eq 1 -and $_.Message -match 'powershell' }
powershell
Architecture and Theory — Under the Hood

Windows writes every security event to the Security Log with a numeric Event ID. A SOC analyst has a 'mental map' of the critical IDs — this allows them to quickly move from event to action. Raw logs reside in %SystemRoot%\System32\winevt\Logs.

  • Logon Events: 4624 (Success), 4625 (Failure), 4634 (Logoff), 4648 (Explicit Logon).
  • : 4768 (), 4769 (), 4771 (Pre-auth failed).
  • Account Management: 4720 (User Created), 4726 (Deleted), 4728/4732 (Added to Group).
  • Process: 4688 (Process Created — with Command Line if enabled).
  • PowerShell: 4103/4104 (Script Block Logging).
Practical Configuration (PowerShell / GUI)
# Search for Logon Failures in PowerShell
Get-WinEvent -FilterHashtable @{LogName='Security';ID=4625;StartTime=(Get-Date).AddHours(-1)} |
  Select TimeCreated,@{n='User';e={$_.Properties[5].Value}},@{n='Source';e={$_.Properties[19].Value}}

# Search for multiple TGS from the same source - Kerberoasting
Get-WinEvent -FilterHashtable @{LogName='Security';ID=4769} |
  Group-Object {$_.Properties[0].Value} | Sort Count -Desc

# Enable command line logging for 4688
# GPO: Computer > Policies > Admin Templates > System > Audit Process Creation > Include command line = Enabled
powershell
Real-world Scenarios in an Organization
  • Brute Force — dozens of 4625 from the same IP within a minute.
  • — multiple 4769 for different SPNs in a short time with RC4 (Ticket Encryption 0x17).
  • — 4624 Type 3 without prior 4768, with a non-existent username.
  • Persistence — 4720 (new account) + 4732 (added to Administrators) in sequence.
Diagnosis and Troubleshooting
  • Log fills up too quickly → Increase log size (Limit-EventLog / ) and transfer to /Sysmon.
  • Event 1102 = Security Log cleared — sign of attacker hiding tracks.
  • 4625 missing Source Network Address → Local source (Interactive) or NLA before 4625.
Glossary and Quick Command Line
  • 4624 Type 10 = RDP.
  • 4672 = Special privileges (Admin).
  • 4740 = Account locked out (PDCe only).
  • Sysmon = Mandatory extension — Process, Network, DNS, Registry.

Check yourself

Hundreds of 4625 events for different accounts, one for each account — what is this?

Which pair of processes raises immediate suspicion in 4688?

Was this page helpful?