An event ID is not an incident. This is a starter list for Security and nearby channels.
| ID | Meaning | L1 question |
|---|---|---|
| 4624 | Successful logon | Logon type? Account? Source? |
| 4625 | Failed logon | Status / substatus? Burst or once? |
| 4634 / 4647 | Logoff | Did a session even exist? |
| 4648 | Explicit credentials | Who launched it? Toward what? |
| 4672 | Privileged logon | Expected admin account? |
| 4688 | Process create | Parent, command line (if enabled) |
| 4720 | Account created | Who created it? Local or domain? |
| 4732 | Group membership | Which group? |
| 4740 | Lockout | How many 4625 before? |
| 1102 | Security log cleared | Who, from which host? |
| 7045 | New service (System) | Binary, service account |
PowerShell: 4104 (script) needs logging enabled — otherwise this sheet lies.
Pattern: ID → host → account → time → neighbouring events → hypothesis.