RESOURCE / EN

Windows Event Log cheat sheet

Event IDs worth knowing at L1 — always with host, account and time, never the number alone.

An event ID is not an incident. This is a starter list for Security and nearby channels.

ID Meaning L1 question
4624 Successful logon Logon type? Account? Source?
4625 Failed logon Status / substatus? Burst or once?
4634 / 4647 Logoff Did a session even exist?
4648 Explicit credentials Who launched it? Toward what?
4672 Privileged logon Expected admin account?
4688 Process create Parent, command line (if enabled)
4720 Account created Who created it? Local or domain?
4732 Group membership Which group?
4740 Lockout How many 4625 before?
1102 Security log cleared Who, from which host?
7045 New service (System) Binary, service account

PowerShell: 4104 (script) needs logging enabled — otherwise this sheet lies.

Pattern: ID → host → account → time → neighbouring events → hypothesis.

Want this implemented or scoped?

The resource stays open. The form is for implementation, not an email gate.

The inquiry is stored on the server. The operator is notified on Telegram. There is no email autoresponder.