Windows has thousands of events, and most learners drown in them. In practice, an analyst works with a short list of Event IDs — they cover most investigations.
Authentication and accounts: 4624 successful logon with logon type (2 local, 3 network, 10 RDP), 4625 failed logon — a burst means brute force or password spraying, 4720 user created, 4728 and 4732 added to a protected group such as Domain Admins, 4768 and 4769 Kerberos tickets where 4769 with RC4 hints at Kerberoasting, 4740 account lockout. Processes: 4688 or Sysmon 1 for process creation — read the parent-to-child chain, Sysmon 3 for network connections, Sysmon 11 and 13 for file and registry activity, 7045 and 4698 for new services and scheduled tasks. WINWORD.EXE spawning powershell.exe is the classic indicator of compromise.
Authentication and Accounts
- 4624 — Successful Logon. The most important is Logon Type: 2 local, 3 network, 10 RDP, 4 Batch, 5 Service.
- 4625 — Failed Logon. Dozens of events for one account = Brute Force; a single event for each account across hundreds of accounts = Password Spraying.
- 4720 — New user created. If there was no proper request — this is Persistence.
- 4728 / 4732 / 4756 — User added to a protected group ( Admins, Administrators). Almost always a critical event.
- 4768 / 4769 — tickets. 4769 with Encryption Type 0x17 (RC4) against a service account = suspicion of .
- 4740 — Account lockout, usually a result of Spraying or an old password in a service.
- 1102 — The security log was cleared. There is almost no legitimate reason for this.
Processes — 4688 and Sysmon
- 4688 / Sysmon Event ID 1 — Process execution. The gold is in the Parent Process field.
- WINWORD.EXE or EXCEL.EXE running cmd.exe or powershell.exe — a classic indicator of successful phishing.
- Sysmon 3 — Network connection from a process. powershell.exe reaching out is a red flag.
- Sysmon 11 / 13 — File write and Registry modification, this is where Run Keys for persistence are caught.
- 7045 / 4698 — New service or new scheduled task, the two most common persistence methods.