Searchable reference for Windows Security, Sysmon, PowerShell, Defender, AppLocker, WMI and more — with MITRE ATT&CK mappings, attack context, detection notes, fields to pivot on, and ready-to-run Sigma, KQL and Splunk queries.
Open any event for its meaning, MITRE ATT&CK mapping, detection guidance and a Sigma rule.
A Windows Event ID is a numeric code that identifies a specific type of logged event in the Windows Event Log — for example, 4624 (successful logon), 4625 (failed logon), or 4688 (process creation). Analysts use them to detect and investigate suspicious activity.
It indexes 235+ event IDs across the Security, Sysmon, PowerShell, System, Application, Defender, AppLocker, WMI-Activity and Terminal Services channels — the sources most relevant to threat detection and incident response.
Yes. Each event includes relevant MITRE ATT&CK techniques along with attack context, detection notes, the fields to pivot on, and ready-to-run Sigma, Sentinel KQL and Splunk SPL queries you can adapt for your SIEM.
No. The entire dataset loads into your browser and all searching happens locally — nothing is sent to any server.