Skip to main content
AD Academy
Tools
Intermediate12 minLast updated: Topic 2 of 4

Important Event IDs in AD

Which events in Event Viewer are worth tracking.

Not read

What you will learn here

  • Which events are worth watching
  • What each Event ID tells you
  • Where to find them in Event Viewer

Worth reading first:Standard Tools for AD Admins

Every significant action on a is recorded in the Security Log. Knowing the key Event IDs is the basis for monitoring and investigation.

Key Event IDs

  • 4624 — Successful Logon.
  • 4625 — a failed logon attempt, useful for identifying Password Spraying.
  • 4768 / 4769 — and Service Ticket requests in ().
  • 4720 / 4726 — creation or deletion of a user account.
  • 4728 / 4732 — adding a user to a privileged group such as Admins.
# Search failed login attempts in the last 24 hours
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625; StartTime=(Get-Date).AddDays(-1)}
powershell
Architecture and Theory — Under the Hood
  • 4624 — Successful logon (Logon Type: 2 local, 3 network, 10 RDP).
  • 4625 — Logon failure. 4740 — Account lockout.
  • 4768/4769 — / request (4769 with RC4 = suspicion of ).
  • 4672 — Special Privileges Logon (Admin).
  • 4720/4726/4728 — Creation/Deletion/Addition to Group.
  • 1102 — Security Log Cleared — almost always a sign of an attacker.
Practical Configuration (PowerShell / GUI)
Get-WinEvent -FilterHashtable @{LogName='Security';Id=4625;StartTime=(Get-Date).AddHours(-24)} |
  Select TimeCreated,@{n='User';e={$_.Properties[5].Value}},@{n='Src';e={$_.Properties[19].Value}}

wevtutil gl Security                  # Log size
auditpol /get /category:*             # Actual audit policy
powershell

Check yourself

Which Event ID indicates a failed logon attempt?

Was this page helpful?