Windows Event ID reference
Code → what it means → first steps. The daily base for helpdesk, NOC and SOC work.
I have a problem — search by symptom44 events
- 1058
Client could not read a GPO file from SYSVOL
System (client) — Group PolicyThe client could not reach \\domain\SYSVOL. Causes: wrong DNS, stalled SYSVOL replication, NTFS permissions.
Open the event card - 1085
A specific GPO extension failed to apply
Most of the policy applied but one part (drive maps, scripts) failed. gpresult shows which.
Open the event card - 1102
Security log was cleared
SecuritySomeone cleared the security log. In a healthy environment this is almost never legitimate.
Open the event card - 1311
KCC cannot build a replication topology
Directory Service (DC)Sites & Services configuration cannot yield a replication path: a site with no Site Link, or an unassigned subnet.
Open the event card - 1388
Lingering object re-created
Directory Service (DC)A DC received an update for an object others already deleted — a sign it was offline past the tombstone lifetime.
Open the event card - 1988
Lingering object — replication halted
Directory Service (DC)A DC tried to replicate an object already deleted elsewhere. AD stops replication with that partner. Usual cause: the DC was offline longer than the tombstone lifetime (180 days).
Open the event card - 2042
It has been too long since this machine replicated
Directory Service (DC)The DC crossed the tombstone lifetime, so replication is blocked entirely.
Open the event card - 2889
Unsigned LDAP bind detected
Directory Service (DC)A client binds to LDAP without signing/encryption — the password crosses the network exposed. Find every such client before enforcing LDAP signing.
Open the event card - 3210
Failed to authenticate to the domain (Netlogon)
System — Netlogon (client)The workstation cannot authenticate to the DC. The familiar wording: "The trust relationship between this workstation and the primary domain failed".
Open the event card - 4624
Successful logon
A successful sign-in. Logon Type tells you how: 2 = local, 3 = network (share), 10 = RDP, 5 = service.
Open the event card - 4625
Failed logon
Security (DC / client)A logon attempt failed. Status/Sub Status explains why: 0xC000006A wrong password, 0xC0000064 no such user, 0xC0000234 account locked.
Open the event card - 4627
Group membership information at logon
Logged together with 4624 and lists the groups the user belonged to at logon. It shows at a glance when someone with Domain Admins rights signs in.
Open the event card - 4634
Logoff
A session ended. Mostly used to measure session length together with 4624 — not every 4624 gets a matching 4634.
Open the event card - 4648
Logon using explicit credentials (RunAs)
SecurityA user ran something as another account. A classic manual lateral-movement signal.
Open the event card - 4662
Operation on an AD object — the DCSync detection point
Security (DC)A detail-rich event. If Properties include the DS-Replication-Get-Changes-All GUID and the account is not a DC, that is DCSync.
Open the event card - 4672
Special privileges assigned to new logon
Security (DC)The logon received sensitive privileges (SeDebug, SeBackup, SeTakeOwnership). Almost always accompanies an admin logon.
Open the event card - 4698
Scheduled task created
SecurityScheduled tasks are a popular persistence trick: they survive reboots and look harmless.
Open the event card - 4719
System audit policy was changed
Security (DC)Someone changed what gets logged. Attackers disable auditing right before the real action — hence critical.
Open the event card - 4720
User account created
Security (DC)A new user was created. After a breach this is a classic persistence step.
Open the event card - 4723
User changed own password
A password change made with knowledge of the old password — unlike 4724, an admin-driven reset.
Open the event card - 4724
Password reset attempt by another user
Security (DC)An admin or helpdesk reset someone's password. Against a privileged account, investigate.
Open the event card - 4726
User account deleted
Security (DC)A user was deleted. Deletion is usually a mistake — disable instead. Recovery needs the AD Recycle Bin enabled beforehand.
Open the event card - 4728
Member added to a global group (e.g. Domain Admins)
Security (DC)Someone gained rights through a global group. For Domain Admins / Enterprise Admins this is a top-priority alert.
Open the event card - 4729
Member removed from a global group
Security (DC)The inverse of 4728. Matters in two cases: an employee leaving, or an attacker cleaning up after abusing a privilege.
Open the event card - 4732
Member added to a local group (e.g. Administrators)
Security (DC / member server)Adding to the local Administrators group on a server or PC — a quiet way to gain control without touching Domain Admins.
Open the event card - 4733
Member removed from a domain local group
Security (DC)Pairs with 4732. Domain Local groups usually hold the actual permissions on resources (shares, printers).
Open the event card - 4738
User account changed
Security (DC)Account attributes changed: UAC flags, SPN, password-never-expires, encryption. A new SPN on a normal user is a red flag (Kerberoasting).
Open the event card - 4739
Domain policy was changed
Security (DC)A domain-wide policy change: password length, lockout policy, password age. It affects everyone.
Open the event card - 4740
Account was locked out
Security (PDC Emulator)The account exceeded the bad-password threshold. The event always lands on the PDC Emulator; Caller Computer Name points at the source.
Open the event card - 4756
Member added to a universal group
Security (DC)Universal groups include Enterprise Admins and Schema Admins — the strongest privileges in the forest.
Open the event card - 4757
Member removed from a universal group
Security (DC)Pairs with 4756. In an attack context: covering tracks after using forest-level privileges.
Open the event card - 4767
Account was unlocked
Someone manually unlocked an account. Worth knowing who — especially for privileged accounts.
Open the event card - 4768
A Kerberos TGT was requested
Start of Kerberos authentication. Watch Ticket Encryption Type: 0x17 (RC4) on a modern account can mean downgrade or AS-REP Roasting.
Open the event card - 4769
Service ticket (TGS) requested — the Kerberoasting signal
Security (DC)A user requested a ticket for a service. Many RC4 (0x17) requests from one user to many services signal Kerberoasting.
Open the event card - 4770
Kerberos service ticket renewed
An existing ticket was extended without re-authentication. Perfectly normal in long sessions.
Open the event card - 4771
Kerberos pre-authentication failed
Security (DC)TGT request rejected. 0x18 wrong password, 0x12 account disabled/locked/expired, 0x25 clock skew over 5 minutes.
Open the event card - 4776
NTLM credential validation
Security (DC)The DC validated a password over NTLM. Microsoft is retiring NTLM — every 4776 today is a question: who still uses it and why.
Open the event card - 4886
Certificate Services received a certificate request
Security (CA)Someone requested a certificate from the CA server (AD CS). Normal by itself — but this is where ESC1 starts: a request carrying another user's name (SAN).
Open the event card - 4887
Certificate Services approved and issued a certificate
Security (CA)The certificate was issued. If it names an admin but went to someone else, the attacker can log in as that admin (ESC1) — even after a password reset.
Open the event card - 4964
Special group member logged on
Security (DC)A mechanism that alerts when a member of a group you defined (e.g. Domain Admins) logs on anywhere.
Open the event card - 5136
A directory service object was modified (including GPOs)
Security (DC)Records an attribute change on an AD object. Editing a GPO changes gPCFileSysPath/versionNumber — that is how you see who changed policy.
Open the event card - 5722
Secure channel setup with a machine account failed
System (DC)The computer account password does not match. Typical after restoring an old snapshot or with a duplicate machine name.
Open the event card - 5723
Secure channel request from a machine account that does not exist
System (DC)A computer talks to the domain but has no AD account — deleted, or never properly joined.
Open the event card - 7045
A new service was installed
SystemA new service was registered. PsExec, Cobalt Strike and many lateral-movement tools leave traces here.
Open the event card