Operator On The Wire
Join
← Back to Knowledge Base
BLUE TEAM / THREAT HUNT / ACTIVE DIRECTORY

Events Matrix

Authentication Events

LogEvent IDMeaningDetection UseTypical Attacks
Security4624Successful logonIdentify lateral movementPass the Hash / Relay
Security4625Failed logonDetect brute force / sprayingPassword Spraying
Security4634LogoffSession trackingLateral movement
Security4647User initiated logoffSession terminationInvestigation pivot
Security4648Explicit credentials usedRunAs / alternate credsLateral movement
Security4672Special privileges assignedAdmin logonPrivilege escalation
Security4776NTLM authenticationNTLM usage trackingNTLM Relay

Kerberos Authentication

LogEvent IDMeaningDetection UseTypical Attacks
Security4768Kerberos TGT requestAuthentication baselineOverpass the Hash
Security4769Kerberos service ticketService access monitoringKerberoasting
Security4770Kerberos ticket renewalLong sessionsPersistence tracking
Security4771Kerberos pre-auth failurePassword attacksPassword spraying
Security4772Kerberos TGT failureAuthentication failureKerberos attacks

Directory Object Access

LogEvent IDMeaningDetection UseTypical Attacks
Security4662Directory object accessReplication / LDAP activityDCSync / LDAP relay
Security4661Handle to object requestedObject access monitoringRecon / enumeration
Security4663Object accessFile / registry accessCredential dumping

Active Directory Changes

LogEvent IDMeaningDetection UseTypical Attacks
Security5136Directory object modifiedACL changesShadow Credentials
Security5137Object createdRogue objectsDCShadow / GPO abuse
Security5138Object undeletedPersistence artifactAD abuse
Security5139Object movedPrivilege abuseAD manipulation
Security5141Object deletedEvidence removalCovering tracks

Group Membership Changes

LogEvent IDMeaningDetection UseTypical Attacks
Security4728Member added to security groupPrivilege escalationAddMember abuse
Security4729Member removed from security groupGroup changeCleanup
Security4732Member added to local groupAdmin escalationLateral movement
Security4733Member removed from local groupPrivilege removalCleanup
Security4756Member added to universal groupDomain privilege escalationPersistence

Account Changes

LogEvent IDMeaningDetection UseTypical Attacks
Security4720User account createdPersistenceRogue account
Security4722Account enabledAccount activationPersistence
Security4723Password change attemptCredential modificationPrivilege abuse
Security4724Password resetForced password changeForceChangePassword
Security4725Account disabledIncident response actionContainment
Security4726Account deletedCleanupCover tracks

Service Creation / Execution

LogEvent IDMeaningDetection UseTypical Attacks
Security7045Service installedRemote command executionPsExec / SMBExec
System7036Service startedExecution trackingLateral movement

Process Execution

LogEvent IDMeaningDetection UseTypical Attacks
Security4688Process creationCommand executionWMIExec / WinRM
Sysmon1Process creationParent-child analysisMalware / shells
Sysmon5Process terminationProcess lifecycleIR timeline

Network Activity

LogEvent IDMeaningDetection UseTypical Attacks
Security5140Network share accessedSMB lateral movementSMB relay
Security5145Detailed share accessFile access trackingCredential theft
Sysmon3Network connectionCommand and controlLateral movement

Credential Access

LogEvent IDMeaningDetection UseTypical Attacks
Sysmon10Process accessed another processLSASS handle accessMimikatz
Security4663File accessRegistry hive accessSAM dumping

PowerShell

LogEvent IDMeaningDetection UseTypical Attacks
PowerShell4103Module loggingScript activityRecon
PowerShell4104Script block loggingMalicious scriptsAttack tooling

Windows Remote Management

LogEvent IDMeaningDetection UseTypical Attacks
WinRM91Remote shell createdWinRM lateral movementEvil-WinRM

Certificate Services (ADCS)

LogEvent IDMeaningDetection UseTypical Attacks
Security4886Certificate issuedCertificate abuseGolden Certificate
Security4887Certificate request approvedTemplate abuseADCS ESC attacks
Security4888Certificate request deniedSuspicious enrollmentADCS abuse

DNS Activity

LogEvent IDMeaningDetection UseTypical Attacks
DNS257DNS update requestADIDNS abuseDNS poisoning
DNS258DNS zone transferUnauthorized replicationDNS recon