| Accounts | New Local User | Security | Event ID 4720 | New user created unexpectedly | Group membership, logon activity, profile creation | Persistence / rogue account |
| Accounts | Account Enabled | Security | Event ID 4722 | Previously disabled account enabled | Logon events, actor account, target purpose | Reactivated foothold |
| Accounts | Password Reset | Security | Event ID 4724 | Password reset by another account | 4624 / 4672 around same actor | ForceChangePassword / takeover |
| Accounts | Account Deleted | Security | Event ID 4726 | User removed unexpectedly | Prior 4720/4722/4724 chain | Cleanup / evidence destruction |
| Authentication | Successful Logon | Security | Event ID 4624 | Suspicious LogonType, account, source | 4672, 4648, 4688, workstation | Lateral movement / foothold |
| Authentication | Failed Logon | Security | Event ID 4625 | Burst failures across users or hosts | Source IP, usernames, 4771/4776 | Password spraying / brute force |
| Authentication | Explicit Credentials | Security | Event ID 4648 | Alternate creds used | 4624 target logon, 4688 parent process | RunAs / PsExec / remote exec |
| Authentication | Special Privileges Assigned | Security | Event ID 4672 | Admin-equivalent session established | 4624 logon pair, 4688 child processes | Privileged foothold |
| Authentication | Logoff | Security | Event IDs 4634 / 4647 | Session boundaries | Paired 4624, child process timeline | Investigation scoping |
| Authentication | NTLM Authentication | Security | Event ID 4776 | NTLM validation where Kerberos expected | 4624 LogonType, source host, target account | PtH / relay / legacy auth abuse |
| Authentication | Kerberos TGT Request | Security | Event ID 4768 | Unusual source, volume, or account | 4769, 4771, workstation, IP | Kerberos baseline / OPTH |
| Authentication | Kerberos Service Ticket | Security | Event ID 4769 | High-volume SPN requests or rare service access | SPN name, encryption type, source, account | Kerberoasting / ticket abuse |
| Authentication | Kerberos Renewal | Security | Event ID 4770 | Long-running session / renewal anomalies | Prior 4768/4769, host activity | Persistence / long sessions |
| Authentication | Kerberos Pre-Auth Failure | Security | Event ID 4771 | Many failures across users | Source IP, account selection, timing | Password spray / guessing |
| Authentication | Kerberos TGT Failure | Security | Event ID 4772 | Abnormal TGT failure pattern | Account, host, adjacent 4771/4768 | Kerberos abuse / failure analysis |
| Credentials | LSASS Handle Access | Sysmon | Event ID 10 | Process opening lsass.exe with suspicious access | Sysmon 1 parent/child, signer, user | Mimikatz / credential dumping |
| Credentials | LSASS Process Creation Context | Sysmon / Security | Event ID 1 / 4688 | dumper / comsvcs / rundll32 / procdump near LSASS | Command line, signed status, temp paths | Credential dumping staging |
| Credentials | SAM Hive Access | Security | Event ID 4663 | Access to \Windows\System32\config\SAM | Process, account, nearby 4688 | SAM dumping |
| Credentials | SECURITY Hive Access | Security | Event ID 4663 | Access to SECURITY hive | Actor, process, adjacent file copies | LSA secrets extraction |
| Credentials | SYSTEM Hive Access | Security | Event ID 4663 | SYSTEM hive access with SAM/SECURITY | Copy location, archive staging | Offline credential extraction |
| Credentials | NTDS / Replication Rights Abuse | Security | Event ID 4662 | Replication-related object access | Subject user, rights GUIDs, DC context | DCSync / NTDS replication |
| Credentials | NTDS File Access | Security / File Logs | 4663 or file telemetry | ntds.dit touched or copied | VSS activity, temp copies, archive creation | NTDS dump |
| Credentials | Vault / Browser Secret Collection | Sysmon / File / Browser logs | 1 / file touches | Browsers, vault paths, sqlite access | Archive creation, temp staging | Credential theft / data collection |
| Enumeration | Local Account Enumeration | 4688 / Sysmon 1 / PowerShell 4104 | net user, whoami, wmic useraccount, Get-LocalUser | Enumeration immediately after foothold | 4624, 4672, later privilege abuse | Discovery |
| Enumeration | Group Enumeration | 4688 / 4104 | net localgroup, Get-LocalGroupMember, whoami /groups | Privilege-focused enumeration | 4672, later 7045 / 4698 / 5136 | Privilege planning |
| Enumeration | Domain User Enumeration | Security 4662 / 4104 / LDAP | LDAP queries for users/groups | High-volume domain discovery | SPN / trust / ACL follow-up | AD recon |
| Enumeration | Share Enumeration | Security | Event IDs 5140 / 5145 | Many shares accessed without normal workflow | Source host, account, target server | SMB recon / lateral planning |
| Enumeration | SPN Enumeration | Security / 4104 | 4662 or LDAP query telemetry | servicePrincipalName discovery | Subsequent 4769 spikes | Kerberoasting prep |
| Enumeration | Trust Enumeration | Security / 4104 | 4662 / PowerShell telemetry | trustedDomain queries | Cross-domain auth events | Trust mapping |
| Enumeration | DNS Enumeration | DNS logs / 4104 / 4688 | zone transfer, many lookups, nslookup, Resolve-DnsName | Rare zone queries or broad lookup burst | Source host, later network movement | Infra discovery |
| Enumeration | BloodHound / SharpHound Collection | Sysmon / 4688 / 4104 | Sysmon 1 or 4688 | SharpHound execution or zip staging | LDAP volume, temp archives, outbound copy | Graph recon |
| Execution | Process Creation | Security / Sysmon | 4688 / 1 | Suspicious parent-child or command line | Network connections, signer, path | General execution anchor |
| Execution | PowerShell Execution | PowerShell | 4103 / 4104 | Encoded, obfuscated, download cradle, AD recon | 4688, Sysmon 1, network, AMSI gaps | Script-based intrusion |
| Execution | CMD Abuse | 4688 / Sysmon 1 | cmd.exe /c | Short one-liners launching LOLBins or scripts | Parent process, child process, temp files | Staging / execution |
| Execution | WMI Execution | Sysmon / Security / WMI | Sysmon 1, WMI logs | wmiprvse.exe spawning shell / script | 4624 source host, remote account, children | WMIExec / lateral exec |
| Execution | WinRM Remote Shell | WinRM | Event ID 91 | Remote shell established | 4624, PowerShell 4104, source IP | Evil-WinRM / admin shell |
| Execution | PsExec Service Execution | Security / System | 7045 / 7036 | PSEXESVC or odd remote service | 4624, service binary path, ADMIN$ access | PsExec |
| Execution | SMBExec / Service Drop | Security / System | 7045 / 7036 | Random-named service installed remotely | 5140/5145, copied batch / exe, actor logon | Impacket SMBExec |
| Execution | DCOMExec | Sysmon / 4688 | Sysmon 1 | dllhost.exe spawning shell or script | 4624, COM CLSID context, source | DCOM-based lateral exec |
| Execution | Rundll32 Abuse | Sysmon / 4688 | 1 / 4688 | suspicious DLL path, javascript, export abuse | DLL file path, signer, network | LOLBin execution |
| Execution | Regsvr32 Abuse | Sysmon / 4688 | 1 / 4688 | /s /n /u /i: or remote scriptlet | Network, scriptlet URL, parent | LOLBin / Squiblydoo |
| Execution | Mshta Abuse | Sysmon / 4688 | 1 / 4688 | remote HTA / inline JS/VBS | Network, child powershell/cmd | LOLBin execution |
| Execution | InstallUtil Abuse | Sysmon / 4688 | 1 / 4688 | untrusted assembly launched with InstallUtil | File path, signer, parent | LOLBin execution |
| Execution | Regasm / Regsvcs Abuse | Sysmon / 4688 | 1 / 4688 | unmanaged registration of suspicious assembly | File path, persistence changes | LOLBin execution |
| Execution | Odbcconf Abuse | Sysmon / 4688 | 1 / 4688 | odbcconf.exe spawning payload | Parent, registry, child process | LOLBin execution |
| Execution | Cscript / Wscript Abuse | Sysmon / 4688 | 1 / 4688 | script host launching encoded or temp scripts | Script path, MOTW, parent | Script execution |
| Execution | Office Child Process | Sysmon / 4688 | 1 / 4688 | Office spawning shell / script / LOLBin | Command line, document source, MOTW | Macro / phishing execution |
| Execution | Browser Child Process | Sysmon / 4688 | 1 / 4688 | browser spawning powershell, mshta, cmd | Download path, MOTW, user | Browser exploit / click-through |
| Execution | Scheduled Task Execution | Security / Task Scheduler | 4698 / 4702 / Operational | suspicious task action path or creator | 4624 actor, file path, persistence chain | Task-based execution |
| Staging | Temp Payload Drop | Sysmon / File telemetry | 11 / file logs | Executable/script in Temp, ProgramData, AppData | Prefetch, Amcache, 4688 | Staging |
| Staging | Archive Creation | 4688 / File logs | 4688 or file telemetry | 7z/rar/zip created near sensitive files | 5145, HTTP upload, temp paths | Staging / exfil prep |
| Staging | ADS Usage | Sysmon / file / cmdline | Sysmon 1 / file logs | alternate data stream write / execute | Parent, hidden execution, path | Concealment / staging |
| Staging | Download Cradle | PowerShell / Sysmon | 4104 / Sysmon 1 | IEX, DownloadString, WebClient, Invoke-WebRequest | Network, child payload, temp file | Staging / memory load |
| Staging | BITS Abuse | BITS logs / Sysmon / 4688 | BITS operational + process | suspicious BITS job to external source | Downloaded file, job persistence | Staging / persistence |
| Staging | Certutil Download / Decode | Sysmon / 4688 | 1 / 4688 | certutil -urlcache, -decode | File output, later execution | LOLBin staging |
| Staging | Copy to ADMIN$ / IPC$ | 5140 / 5145 | Share access | Remote copy preceding service/task creation | 7045 / 4698 / 4624 | Lateral staging |
| Persistence | Run Keys | Sysmon / Registry / Security | Sysmon 12/13/14 or registry logs | HKCU/HKLM Run modified | Target binary, signer, user logon | User/system persistence |
| Persistence | Startup Folder | File telemetry | file create in Startup path | executable/link/script dropped | User profile, recent execution | User persistence |
| Persistence | Service Install | Security / System | 7045 / 7036 | New service created with suspicious binary | File path, signer, actor, 4624 | Persistence / remote exec |
| Persistence | Scheduled Task Create / Modify | Security / Task Scheduler | 4698 / 4702 | hidden task, odd action, encoded command | Creator account, path, repetition | Persistence |
| Persistence | WMI Subscription | WMI-Activity / Sysmon / PowerShell | WMI logs / 4104 | Event filter / consumer / binding creation | PowerShell, repository artifacts | Fileless persistence |
| Persistence | AppInit / IFEO / SilentProcessExit | Registry | Registry telemetry | debugger / monitor process added | Parent-child chain, target image | Execution hijack |
| Persistence | COM Hijack | Registry / Sysmon | registry mods / 1 | CLSID points to rogue DLL | Load path, target process | Hijack persistence |
| Persistence | LNK Persistence | File telemetry / 4688 | file create + later process | suspicious shortcut in Startup / Public | Target binary, MOTW, recent docs | Persistence / lure |
| Persistence | Print Processor / Port Monitor | Registry / 7045 / DLL loads | registry/service telemetry | new print DLL / driver path | DLL path, signer, spoolsv loads | Privileged persistence |
| Persistence | SSP / LSA Package | Registry / 4688 / service | registry value change | auth package modified | reboot/logon sequence, lsass load | Credential interception persistence |
| Privilege Escalation | UAC Bypass | Sysmon / 4688 / Registry | 1 / registry changes | auto-elevate LOLBin with child payload | Integrity level jump, HKCU hijack | Local priv esc |
| Privilege Escalation | SeDebug / Sensitive Privilege Use | 4672 / 4688 / Sysmon 10 | privilege session + LSASS/process access | same logon session, parent chain | Credential dumping / token abuse | |
| Privilege Escalation | Token Manipulation / Impersonation | 4688 / Sysmon / 4624 | unusual token context / process lineage | child as SYSTEM after user process | source logon, services, handles | Token abuse |
| Privilege Escalation | Service BinPath / Config Abuse | Service registry / 7040 / 7045 | service path change to attacker binary | actor account, restart event | Service abuse | |
| Privilege Escalation | DLL Search Order Hijack | Sysmon 7 / file create | unsigned DLL in app dir loaded by high-priv process | image load, path, signer | Priv esc / persistence | |
| Privilege Escalation | Unquoted Service Path | Service config / 4688 | binary created in exploitable path | service start, process creation | Priv esc | |
| Privilege Escalation | AlwaysInstallElevated | Registry / MSI logs | policy enabled + msiexec execution | parent process, package source | MSI priv esc | |
| Network | Inbound SMB Access | Security | 5140 / 5145 | unusual ADMIN$, C$, IPC$ access | 4624 source, copied files, 7045 | Lateral movement |
| Network | Outbound Connection | Sysmon | Event ID 3 | suspicious destination, rare port, parent process | DNS, process creation, user | C2 / staging / exfil |
| Network | Non-Standard Port Listener | Sysmon / netstat / EDR | process + port telemetry | unexpected service or user process listening | binary path, signer, task/service | C2 / tunnel |
| Network | RDP Logon | Security / TerminalServices | 4624 LogonType 10 + TS logs | unusual source or account | 4672, clipboard/drive use, follow-on exec | Interactive lateral movement |
| Network | WinRM Session | WinRM / 4624 | 91 + 4624 | remote management where unusual | PowerShell, source IP, parent chain | Lateral movement |
| Network | DNS Query Abuse | DNS / Sysmon 22 / ETW | rare domain, TXT bursts, beacon cadence | process, destination, timing | DNS C2 / staging | |
| Network | Proxy / Tunneling | Sysmon 3 / process logs | long-lived SSH/chisel/ncat-like pattern | child process, listening ports, remote endpoint | Pivot / tunnel | |
| Parent-Child | Office → Script Host | Sysmon 1 | Office parent of wscript/cscript/powershell | macro-driven execution | document path, user, MOTW | Phishing |
| Parent-Child | Browser → LOLBin | Sysmon 1 | browser spawns mshta/rundll32/powershell | download/drive-by chain | file path, URL, network | User execution |
| Parent-Child | wmiprvse → Shell | Sysmon 1 | wmiprvse spawning cmd/powershell | remote WMI execution | 4624 source, account | WMI lateral exec |
| Parent-Child | dllhost → Shell | Sysmon 1 | dllhost child cmd/powershell | DCOM abuse | remote source, CLSID | DCOM lateral exec |
| Parent-Child | services.exe → Odd Binary | Sysmon 1 | service launching unusual payload | 7045/7036, binary path | service execution / persistence | |
| Parent-Child | taskeng/taskhostw → Payload | Sysmon 1 | task engine launching suspicious binary | 4698/4702, task XML | Task persistence | |
| Parent-Child | winword/excel → cmd/powershell | Sysmon 1 | direct macro shell launch | document source, child chain | Malicious Office document | |
| Parent-Child | explorer → LOLBin from Temp | Sysmon 1 | user-click execution from temp/downloads | MOTW, file hash, recent docs | User execution | |
| Evasion | Event Log Cleared | Security / System | 1102 / 104 | log cleared | actor account, adjacent activity | Cover tracks |
| Evasion | Timestomp | Sysmon / MFT / file metadata | file time anomalies | ctime/mtime mismatch or backdated PE | creation path, Prefetch/Amcache mismatch | Anti-forensics |
| Evasion | Prefetch Missing but Execution Evidence Present | Prefetch / Amcache / 4688 | expected PF absent | Amcache/4688/Sysmon prove run but PF absent | service / one-shot / cleanup | Evasion / unusual execution context |
| Evasion | Amcache / Shimcache Mismatch | Amcache / Shimcache / Prefetch | artifact disagreement | one artifact proves presence not execution / vice versa | timeline, path, compile time | Anti-forensics / uncertainty handling |
| Evasion | Security Tool Disable | 4688 / service / registry | sc stop, tamper settings, policy disable | actor, child actions, subsequent payload | Defense evasion | |
| Evasion | Script Block Logging Disabled | 4104 gaps / registry / GPO | expected PowerShell telemetry missing | registry/GPO changes, module logs | Evasion | |
| Evasion | History / Recent Items Cleanup | user artifacts / 4688 | MRU gaps, deleted LNKs, cleanup commands | shellbags, jumplists, recycle bin | Cover tracks | |
| Exfiltration | SMB Copy Out | 5145 / 3 / file logs | bulk file access then remote share writes | source process, archive creation, target share | Exfil / staging | |
| Exfiltration | HTTP Upload / Web Exfil | Sysmon 3 / proxy logs / 4104 | upload to rare external domain or endpoint | process, archive, command line | Exfiltration | |
| Exfiltration | Cloud Sync / WebDAV Abuse | process / network / file logs | rclone, OneDrive abuse, WebDAV mapping | file set, auth, rare destinations | Data theft | |
| Exfiltration | Archive + Delete | file logs / 4688 | archive created then source deleted / moved | process, destination, timing | Exfil prep + cleanup | |
| Impact | Shadow Copy Delete | 4688 / VSS logs | vssadmin delete shadows, wmic shadowcopy delete | actor, ransomware indicators, file encryption | Ransomware prep | |
| Impact | Backup Disable / Recovery Inhibit | 4688 / service / registry | wbadmin / bcdedit / recovery changes | shadow delete, service stops | Destructive prep | |
| Impact | Mass File Rename / Encrypt | file telemetry / Sysmon / EDR | high-volume file modifications | process, extension pattern, notes | Ransomware / destruction | |
| Impact | Logon Script / GPO Impact Abuse | 5136 / file logs / 4104 | broad script deployment or malicious GPO push | changed GPO, SYSVOL writes, affected hosts | Domain-wide impact | |
| AD Bridge | LDAP Object Read Burst | Security | 4662 | broad object access from unusual host | actor, process, later AD abuse | AD recon |
| AD Bridge | AD Object Modified | Security | 5136 | ACL / attribute change | actor, object DN, follow-up auth | ACL abuse / RBCD / shadow creds |
| AD Bridge | Object Created / Deleted | Security | 5137 / 5141 | rogue objects or cleanup | actor, object DN, later auth/persistence | DCShadow / GPO / cleanup |
| AD Bridge | Group Membership Change | Security | 4728 / 4732 / 4756 | privileged group addition | actor, new privileges, later logons | Priv esc / persistence |
| AD Bridge | Certificate Issued / Approved | Security | 4886 / 4887 | unusual cert enrollment | template, requester, SAN, later auth | ADCS abuse |
| AD Bridge | Coerced Authentication | Security | 4624 / 4776 / 4769 | machine auth to odd host / relay chain | source, relay target, service | PrinterBug / PetitPotam / relay |