Windows
Windows Event Logs for security, system, and application events
Log Types
Security Event Log
Authentication, authorization, and security audit events
Windows Event LogEvent ID 4624 - Successful Logon
Successful authentication events with logon type, authentication method, and session details
Windows Event Log > SecurityEvent ID 4625 - Failed Logon
Failed authentication attempts with detailed failure reasons and status codes
Windows Event Log > SecurityEvent ID 4672 - Special Privileges Assigned
Special privileges assigned to new logon, indicating administrative or sensitive access
Windows Event Log > SecurityEvent ID 4688 - Process Creation
New process creation with command line, parent process, and token information
Windows Event Log > SecurityEvent ID 4720 - User Account Created
New user account creation with account details and creator information
Windows Event Log > SecurityEvent ID 4726 - User Account Deleted
User account deletion with account details and who performed the deletion
Windows Event Log > SecurityEvent ID 4740 - Account Lockout
User account locked out after failed logon attempts
Windows Event Log > SecurityEvent ID 4732 - Member Added to Security Group
Member added to a security-enabled local or domain group
Windows Event Log > SecurityEvent ID 4648 - Explicit Credentials Logon
Logon attempt using explicit credentials (RunAs, mapped drives)
Windows Event Log > SecurityEvent ID 4698 - Scheduled Task Created
New scheduled task created, potential persistence mechanism
Windows Event Log > SecurityEvent ID 1102 - Security Log Cleared
Security event log was cleared, potential anti-forensics activity
Windows Event Log > SecurityEvent ID 4663 - Object Access Attempted
Access attempt on an object (file, registry, etc.) with SACL
Windows Event Log > SecuritySystem Event Log
System component events, drivers, and services
Windows Event LogApplication Event Log
Application-specific events
Windows Event LogDefault Paths by Platform
Event Viewer > Windows LogsC:\Windows\System32\winevt\Logs\Categories
Help improve this documentation
Found an error or want to add a new log type? Contributions are welcome!