SOC Tools · Detection Engineering

Windows Event ID Lookup

Searchable reference for Windows Security, Sysmon, PowerShell, Defender, AppLocker, WMI and more — with MITRE ATT&CK mappings, attack context, detection notes, fields to pivot on, and ready-to-run Sigma, KQL and Splunk queries.

Loading dataset… · Press / to focus search

Source
Severity
Tactic
Loading…
Export filtered

All 235 Windows Event IDs

Open any event for its meaning, MITRE ATT&CK mapping, detection guidance and a Sigma rule.

AppLocker log (2)

8003 AppLocker would have blocked a file (audit) 8004 AppLocker blocked a file (enforce)

Application log (3)

1000 Application error 1001 Application fault bucket 1002 Application hang

Defender log (4)

1116 Microsoft Defender detected malware or PUA 1117 Microsoft Defender took action on malware 5001 Microsoft Defender real-time protection disabled 5007 Microsoft Defender configuration changed

PowerShell log (9)

400 PowerShell engine started 403 PowerShell engine stopped 600 PowerShell provider started 800 Pipeline execution details 4100 PowerShell script execution error 4103 Module logging — pipeline execution details 4104 Script block logging — script block recorded 4105 Script block start (first execution) 4106 Script block end (final execution)

Security log (162)

1102 The audit log was cleared 4608 Windows is starting up 4616 The system time was changed 4621 Administrator recovered system from CrashOnAuditFail 4624 An account was successfully logged on 4625 An account failed to log on 4626 User/Device claims information 4627 Group membership information 4634 An account was logged off 4647 User initiated logoff 4648 A logon was attempted using explicit credentials 4649 A replay attack was detected 4656 A handle to an object was requested 4657 A registry value was modified 4658 The handle to an object was closed 4660 An object was deleted 4662 An operation was performed on an object 4663 An attempt was made to access an object 4665 An attempt was made to create an application client context 4670 Permissions on an object were changed 4672 Special privileges assigned to new logon 4673 A privileged service was called 4674 An operation was attempted on a privileged object 4675 SIDs were filtered 4688 A new process has been created 4689 A process has exited 4690 An attempt was made to duplicate a handle to an object 4697 A service was installed in the system 4698 A scheduled task was created 4699 A scheduled task was deleted 4700 A scheduled task was enabled 4701 A scheduled task was disabled 4702 A scheduled task was updated 4703 A token right was adjusted 4704 A user right was assigned 4705 A user right was removed 4706 A new trust was created to a domain 4707 A trust to a domain was removed 4713 Kerberos policy was changed 4714 Encrypted data recovery policy was changed 4715 The audit policy (SACL) on an object was changed 4716 Trusted domain information was changed 4717 System security access was granted to an account 4718 System security access was removed from an account 4719 System audit policy was changed 4720 A user account was created 4722 A user account was enabled 4723 An attempt was made to change an account's password 4724 An attempt was made to reset an account's password 4725 A user account was disabled 4726 A user account was deleted 4728 A member was added to a security-enabled global group 4729 A member was removed from a security-enabled global group 4730 A security-enabled global group was deleted 4731 A security-enabled local group was created 4732 A member was added to a security-enabled local group 4733 A member was removed from a security-enabled local group 4734 A security-enabled local group was deleted 4735 A security-enabled local group was changed 4737 A security-enabled global group was changed 4738 A user account was changed 4740 A user account was locked out 4741 A computer account was created 4742 A computer account was changed 4743 A computer account was deleted 4756 A member was added to a security-enabled universal group 4757 A member was removed from a security-enabled universal group 4764 A group's type was changed 4767 A user account was unlocked 4768 A Kerberos authentication ticket (TGT) was requested 4769 A Kerberos service ticket was requested 4770 A Kerberos service ticket was renewed 4771 Kerberos pre-authentication failed 4772 A Kerberos authentication ticket request failed 4773 A Kerberos service ticket request failed 4774 An account was mapped for logon 4775 An account could not be mapped for logon 4776 The domain controller attempted to validate the credentials for an account (NTLM) 4777 The domain controller failed to validate the credentials for an account 4778 A session was reconnected to a Window Station 4779 A session was disconnected from a Window Station 4780 The ACL was set on accounts which are members of administrators groups 4781 The name of an account was changed 4782 The password hash an account was accessed 4793 The Password Policy Checking API was called 4797 An attempt was made to query the existence of a blank password 4798 A user's local group membership was enumerated 4799 A security-enabled local group membership was enumerated 4800 The workstation was locked 4801 The workstation was unlocked 4802 The screen saver was invoked 4803 The screen saver was dismissed 4820 A Kerberos Ticket-Granting-Ticket (TGT) was denied because the device does not meet the access control restrictions 4821 A Kerberos service ticket was denied because the user, device, or both do not meet the access control restrictions 4822 NTLM authentication failed because the account was a member of the Protected Users group 4824 An attempt to use DES encryption for Kerberos failed 4825 A user was denied the access to Remote Desktop 4886 Certificate Services received a certificate request 4887 Certificate Services approved a certificate request and issued a certificate 4888 Certificate Services denied a certificate request 4890 The settings for Certificate Services changed 4896 One or more rows have been deleted from the certificate database 4907 Auditing settings on object were changed 4928 An Active Directory replica source naming context was established 4929 An Active Directory replica source naming context was removed 4930 An Active Directory replica source naming context was modified 4932 Synchronization of a replica of an Active Directory naming context has begun 4933 Synchronization of a replica of an Active Directory naming context has ended 4934 Attributes of an Active Directory object were replicated 4935 Replication failure begins 4936 Replication failure ends 4937 A lingering object was removed from the replica 4944 The following policy was active when the Windows Firewall started 4946 A change has been made to Windows Firewall exception list — a rule was added 4947 A change has been made to Windows Firewall exception list — a rule was modified 4948 A change has been made to Windows Firewall exception list — a rule was deleted 4950 A Windows Firewall setting has changed 4957 Windows Firewall did not apply the following rule 4964 Special groups have been assigned to a new logon 4985 The state of a transaction has changed 5024 The Windows Firewall Service has started successfully 5025 The Windows Firewall Service has been stopped 5031 Windows Firewall blocked an application from accepting incoming connections 5038 Code integrity determined that the image hash of a file is not valid 5136 A directory service object was modified 5137 A directory service object was created 5138 A directory service object was undeleted 5139 A directory service object was moved 5140 A network share object was accessed 5141 A directory service object was deleted 5142 A network share object was added 5143 A network share object was modified 5144 A network share object was deleted 5145 A network share object was checked to see whether client can be granted desired access 5152 The Windows Filtering Platform has blocked a packet 5154 The Windows Filtering Platform has permitted an application to listen on a port 5155 The Windows Filtering Platform has blocked an application from listening on a port 5156 The Windows Filtering Platform has permitted a connection 5157 The Windows Filtering Platform has blocked a connection 5158 The Windows Filtering Platform has permitted a bind to a local port 5168 SPN check for SMB/SMB2 failed 5376 Credential Manager credentials were backed up 5377 Credential Manager credentials were restored from a backup 5378 The requested credentials delegation was disallowed by policy 5379 Credential Manager credentials were read 5380 Vault credentials were found 5381 Vault credentials were listed 5382 Vault credentials were read 6272 Network Policy Server granted access to a user 6273 Network Policy Server denied access to a user 6274 Network Policy Server discarded the request for a user 6278 Network Policy Server granted full access to a user because the host met the defined health policy 6279 Network Policy Server locked the user account due to repeated failed authentication attempts 6280 Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy 6416 A new external device was recognized by the system 6419 A request was made to disable a device 6420 A device was disabled 6421 A request was made to enable a device 6422 A device was enabled 6423 The installation of this device is forbidden by system policy 6424 The installation of this device was allowed after a policy override 4661 A handle to an object was requested (SAM / DS object)

Sysmon log (29)

1 Process creation 2 A process changed a file creation time 3 Network connection detected 4 Sysmon service state changed 5 Process terminated 6 Driver loaded 7 Image loaded 8 CreateRemoteThread detected 9 RawAccessRead detected 10 Process accessed 11 File created 12 Registry object added or deleted 13 Registry value set 14 Registry object renamed 15 File stream created 16 Sysmon configuration state changed 17 Pipe created 18 Pipe connected 19 WmiEventFilter activity detected 20 WmiEventConsumer activity detected 21 WmiEventConsumerToFilter activity detected 22 DNS query 23 File deleted (archived) 24 New content in the clipboard 25 Process image was tampered (Hollowing/Herpaderping) 26 File delete logged (not archived) 27 File block executable 28 File block shredding 29 File executable detected

System log (21)

104 The System event log was cleared 1074 The process has initiated the restart or shutdown of computer 6005 The Event Log service was started 6006 The Event Log service was stopped 6008 The previous system shutdown was unexpected 6009 Microsoft Windows version 6013 The system uptime is 7000 The service failed to start due to the following error 7001 The service depends on another service 7009 A timeout was reached while waiting for service to connect 7022 The service hung on starting 7023 The service terminated with an error 7024 The service terminated with a service-specific error 7026 The following boot-start or system-start driver failed to load 7031 The service terminated unexpectedly 7034 The service terminated unexpectedly and will be restarted 7035 The service was successfully sent a start or stop control 7036 The service entered the stopped/running state 7038 The service was unable to log on as the configured account 7040 The start type of a service was changed 7045 A new service was installed in the system

TerminalServices log (1)

1149 Remote Desktop authentication succeeded

WMI-Activity log (3)

5857 WMI provider started an operation 5860 Temporary WMI event consumer registered 5861 Permanent WMI event consumer registered

WinRM log (1)

169 WinRM remote connection

Frequently asked questions

What is a Windows Event ID?

A Windows Event ID is a numeric code that identifies a specific type of logged event in the Windows Event Log — for example, 4624 (successful logon), 4625 (failed logon), or 4688 (process creation). Analysts use them to detect and investigate suspicious activity.

Which logs does this tool cover?

It indexes 235+ event IDs across the Security, Sysmon, PowerShell, System, Application, Defender, AppLocker, WMI-Activity and Terminal Services channels — the sources most relevant to threat detection and incident response.

Are the events mapped to MITRE ATT&CK?

Yes. Each event includes relevant MITRE ATT&CK techniques along with attack context, detection notes, the fields to pivot on, and ready-to-run Sigma, Sentinel KQL and Splunk SPL queries you can adapt for your SIEM.

Is my search data sent anywhere?

No. The entire dataset loads into your browser and all searching happens locally — nothing is sent to any server.