| A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V | W | X | Y | Z | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | Category | Setting | EventID | Message Description | URL | |||||||||||||||||||||
2 | Account Logon | Audit Credential Validation | 4774 | An account was mapped for logon. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4774 | |||||||||||||||||||||
3 | Account Logon | Audit Credential Validation | 4775 | An account could not be mapped for logon. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4775 | |||||||||||||||||||||
4 | Account Logon | Audit Credential Validation | 4776 | The domain controller attempted to validate the credentials for an account (NTLM) | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4776 | |||||||||||||||||||||
5 | Account Logon | Audit Credential Validation | 4777 | The domain controller failed to validate the credentials for an account. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4777 | |||||||||||||||||||||
6 | Account Logon | Audit Kerberos Authentication Service | 4768 | A Kerberos authentication ticket (TGT) was requested | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4768 | |||||||||||||||||||||
7 | Account Logon | Audit Kerberos Authentication Service | 4771 | Kerberos pre-authentication failed. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4771 | |||||||||||||||||||||
8 | Account Logon | Audit Kerberos Authentication Service | 4772 | A Kerberos authentication ticket request failed. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4772 | |||||||||||||||||||||
9 | Account Logon | Audit Kerberos Service Ticket Operations | 4769 | A Kerberos service ticket was requested. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4769 | |||||||||||||||||||||
10 | Account Logon | Audit Kerberos Service Ticket Operations | 4770 | A Kerberos service ticket was renewed. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4770 | |||||||||||||||||||||
11 | Account Logon | Audit Kerberos Service Ticket Operations | 4773 | A Kerberos service ticket request failed. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4773 | |||||||||||||||||||||
12 | Account Management | Audit Application Group Management | 4783 | A basic application group was created. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-application-group-management | |||||||||||||||||||||
13 | Account Management | Audit Application Group Management | 4784 | A basic application group was changed. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-application-group-management | |||||||||||||||||||||
14 | Account Management | Audit Application Group Management | 4785 | A member was added to a basic application group. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-application-group-management | |||||||||||||||||||||
15 | Account Management | Audit Application Group Management | 4786 | A member was removed from a basic application group. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-application-group-management | |||||||||||||||||||||
16 | Account Management | Audit Application Group Management | 4787 | A non-member was added to a basic application group. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-application-group-management | |||||||||||||||||||||
17 | Account Management | Audit Application Group Management | 4788 | A non-member was removed from a basic application group. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-application-group-management | |||||||||||||||||||||
18 | Account Management | Audit Application Group Management | 4789 | A basic application group was deleted. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-application-group-management | |||||||||||||||||||||
19 | Account Management | Audit Application Group Management | 4790 | An LDAP query group was created. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-application-group-management | |||||||||||||||||||||
20 | Account Management | Audit Application Group Management | 4791 | An LDAP query group was changed. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-application-group-management | |||||||||||||||||||||
21 | Account Management | Audit Application Group Management | 4792 | An LDAP query group was deleted. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-application-group-management | |||||||||||||||||||||
22 | Account Management | Audit Computer Account Management | 4741 | A computer account was created. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4741 | |||||||||||||||||||||
23 | Account Management | Audit Computer Account Management | 4742 | A computer account was changed. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4742 | |||||||||||||||||||||
24 | Account Management | Audit Computer Account Management | 4743 | A computer account was deleted. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4743 | |||||||||||||||||||||
25 | Account Management | Audit Distribution Group Management | 4749 | A security-disabled global group was created. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4749 | |||||||||||||||||||||
26 | Account Management | Audit Distribution Group Management | 4750 | A security-disabled global group was changed. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4750 | |||||||||||||||||||||
27 | Account Management | Audit Distribution Group Management | 4751 | A member was added to a security-disabled global group. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4751 | |||||||||||||||||||||
28 | Account Management | Audit Distribution Group Management | 4752 | A member was removed from a security-disabled global group. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4752 | |||||||||||||||||||||
29 | Account Management | Audit Distribution Group Management | 4753 | A security-disabled global group was deleted. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4753 | |||||||||||||||||||||
30 | Account Management | Audit Distribution Group Management | 4759 | A security-disabled universal group was created. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-distribution-group-management | |||||||||||||||||||||
31 | Account Management | Audit Distribution Group Management | 4760 | A security-disabled universal group was changed. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-distribution-group-management | |||||||||||||||||||||
32 | Account Management | Audit Distribution Group Management | 4761 | A member was added to a security-disabled universal group. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-distribution-group-management | |||||||||||||||||||||
33 | Account Management | Audit Distribution Group Management | 4762 | A member was removed from a security-disabled universal group. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-distribution-group-management | |||||||||||||||||||||
34 | Account Management | Audit Distribution Group Management | 4763 | A security-disabled universal group was deleted. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-distribution-group-management | |||||||||||||||||||||
35 | Account Management | Audit Distribution Group Management | 4744 | A security-disabled local group was created. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-distribution-group-management | |||||||||||||||||||||
36 | Account Management | Audit Distribution Group Management | 4745 | A security-disabled local group was changed. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-distribution-group-management | |||||||||||||||||||||
37 | Account Management | Audit Distribution Group Management | 4746 | A member was added to a security-disabled local group. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-distribution-group-management | |||||||||||||||||||||
38 | Account Management | Audit Distribution Group Management | 4747 | A member was removed from a security-disabled local group. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-distribution-group-management | |||||||||||||||||||||
39 | Account Management | Audit Distribution Group Management | 4748 | A security-disabled local group was deleted. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-distribution-group-management | |||||||||||||||||||||
40 | Account Management | Audit Other Account Management Events | 4782 | The password hash of an account was accessed. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4782 | |||||||||||||||||||||
41 | Account Management | Audit Other Account Management Events | 4793 | The Password Policy Checking API was called. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4793 | |||||||||||||||||||||
42 | Account Management | Audit Security Group Management | 4731 | A security-enabled local group was created. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4731 | |||||||||||||||||||||
43 | Account Management | Audit Security Group Management | 4732 | A member was added to a security-enabled local group | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4732 | |||||||||||||||||||||
44 | Account Management | Audit Security Group Management | 4733 | A member was removed from a security-enabled local group. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4733 | |||||||||||||||||||||
45 | Account Management | Audit Security Group Management | 4734 | A security-enabled local group was deleted. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4734 | |||||||||||||||||||||
46 | Account Management | Audit Security Group Management | 4735 | A security-enabled local group was changed. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4735 | |||||||||||||||||||||
47 | Account Management | Audit Security Group Management | 4764 | A group's type was changed. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4764 | |||||||||||||||||||||
48 | Account Management | Audit Security Group Management | 4799 | A security-enabled local group or account membership was enumerated | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4799 | |||||||||||||||||||||
49 | Account Management | Audit Security Group Management | 4727 | A security-enabled global group was created. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-security-group-management | |||||||||||||||||||||
50 | Account Management | Audit Security Group Management | 4737 | A security-enabled global group was changed. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-security-group-management | |||||||||||||||||||||
51 | Account Management | Audit Security Group Management | 4728 | A member was added to a security-enabled global group | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-security-group-management | |||||||||||||||||||||
52 | Account Management | Audit Security Group Management | 4729 | A member was removed from a security-enabled global group. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-security-group-management | |||||||||||||||||||||
53 | Account Management | Audit Security Group Management | 4730 | A security-enabled global group was deleted. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-security-group-management | |||||||||||||||||||||
54 | Account Management | Audit Security Group Management | 4754 | A security-enabled universal group was created. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-security-group-management | |||||||||||||||||||||
55 | Account Management | Audit Security Group Management | 4755 | A security-enabled universal group was changed. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-security-group-management | |||||||||||||||||||||
56 | Account Management | Audit Security Group Management | 4756 | A member was added to a security-enabled universal group. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-security-group-management | |||||||||||||||||||||
57 | Account Management | Audit Security Group Management | 4757 | A member was removed from a security-enabled universal group. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-security-group-management | |||||||||||||||||||||
58 | Account Management | Audit Security Group Management | 4758 | A security-enabled universal group was deleted. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-security-group-management | |||||||||||||||||||||
59 | Account Management | Audit User Account Management | 4720 | A (local) user account was created | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4720 | |||||||||||||||||||||
60 | Account Management | Audit User Account Management | 4722 | A user account was enabled | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4722 | |||||||||||||||||||||
61 | Account Management | Audit User Account Management | 4723 | An attempt was made to change an account's password. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4723 | |||||||||||||||||||||
62 | Account Management | Audit User Account Management | 4724 | An attempt was made to reset an account's password. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4724 | |||||||||||||||||||||
63 | Account Management | Audit User Account Management | 4725 | A user account was disabled. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4725 | |||||||||||||||||||||
64 | Account Management | Audit User Account Management | 4726 | A user account was deleted. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4726 | |||||||||||||||||||||
65 | Account Management | Audit User Account Management | 4738 | A user account was changed | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4738 | |||||||||||||||||||||
66 | Account Management | Audit User Account Management | 4740 | A user account was locked out. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4740 | |||||||||||||||||||||
67 | Account Management | Audit User Account Management | 4765 | SID History was added to an account. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4765 | |||||||||||||||||||||
68 | Account Management | Audit User Account Management | 4766 | An attempt to add SID History to an account failed. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4766 | |||||||||||||||||||||
69 | Account Management | Audit User Account Management | 4767 | A user account was unlocked. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4767 | |||||||||||||||||||||
70 | Account Management | Audit User Account Management | 4780 | The ACL was set on accounts which are members of administrators groups. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4780 | |||||||||||||||||||||
71 | Account Management | Audit User Account Management | 4781 | The name of an account was changed. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4781 | |||||||||||||||||||||
72 | Account Management | Audit User Account Management | 4794 | An attempt was made to set the Directory Services Restore Mode administrator password. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4794 | |||||||||||||||||||||
73 | Account Management | Audit User Account Management | 4798 | A security-enabled local group or account membership was enumerated. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4798 | |||||||||||||||||||||
74 | Account Management | Audit User Account Management | 5376 | Credential Manager credentials were backed up. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-5376 | |||||||||||||||||||||
75 | Account Management | Audit User Account Management | 5377 | Credential Manager credentials were restored from a backup. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-5377 | |||||||||||||||||||||
76 | Built-In | Event Log | 1100 | The event logging service has shut down | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-1100 | |||||||||||||||||||||
77 | Built-In | Event Log | 1102 | The audit log was cleared | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-1102 | |||||||||||||||||||||
78 | Built-In | Event Log | 1104 | The security Log is now full | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-1104 | |||||||||||||||||||||
79 | Built-In | Event Log | 1105 | Event log automatic backup | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-1105 | |||||||||||||||||||||
80 | Built-In | Event Log | 1108 | The event logging service encountered an error | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-1108 | |||||||||||||||||||||
81 | Detailed Tracking | Audit DPAPI Activity | 4692 | Backup of data protection master key was attempted. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4692 | |||||||||||||||||||||
82 | Detailed Tracking | Audit DPAPI Activity | 4693 | Recovery of data protection master key was attempted. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4693 | |||||||||||||||||||||
83 | Detailed Tracking | Audit DPAPI Activity | 4694 | Protection of auditable protected data was attempted. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4694 | |||||||||||||||||||||
84 | Detailed Tracking | Audit DPAPI Activity | 4695 | Unprotection of auditable protected data was attempted. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4695 | |||||||||||||||||||||
85 | Detailed Tracking | Audit PNP Activity | 6416 | A new external device was recognized by the System. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-6416 | |||||||||||||||||||||
86 | Detailed Tracking | Audit PNP Activity | 6419 | A request was made to disable a device | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-6419 | |||||||||||||||||||||
87 | Detailed Tracking | Audit PNP Activity | 6420 | A device was disabled | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-6420 | |||||||||||||||||||||
88 | Detailed Tracking | Audit PNP Activity | 6421 | A request was made to enable a device | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-6421 | |||||||||||||||||||||
89 | Detailed Tracking | Audit PNP Activity | 6422 | A device was enabled | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-6422 | |||||||||||||||||||||
90 | Detailed Tracking | Audit PNP Activity | 6423 | The installation of this device is forbidden by system policy | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-6423 | |||||||||||||||||||||
91 | Detailed Tracking | Audit PNP Activity | 6424 | The installation of this device was allowed, after having previously been forbidden by policy | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-6424 | |||||||||||||||||||||
92 | Detailed Tracking | Audit Process Creation | 4688 | A new process has been created. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4688 | |||||||||||||||||||||
93 | Detailed Tracking | Audit Process Creation | 4696 | A primary token was assigned to process. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4696 | |||||||||||||||||||||
94 | Detailed Tracking | Audit Process Termination | 4689 | A process has exited. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4689 | |||||||||||||||||||||
95 | Detailed Tracking | Audit RPC Events | 5712 | A Remote Procedure Call (RPC) was attempted. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-5712 | |||||||||||||||||||||
96 | DS Access | Audit Detailed Directory Service Replication | 4928 | An Active Directory replica source naming context was established. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4928 | |||||||||||||||||||||
97 | DS Access | Audit Detailed Directory Service Replication | 4929 | An Active Directory replica source naming context was removed. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4929 | |||||||||||||||||||||
98 | DS Access | Audit Detailed Directory Service Replication | 4930 | An Active Directory replica source naming context was modified. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4930 | |||||||||||||||||||||
99 | DS Access | Audit Detailed Directory Service Replication | 4931 | An Active Directory replica destination naming context was modified. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4931 | |||||||||||||||||||||
100 | DS Access | Audit Detailed Directory Service Replication | 4934 | Attributes of an Active Directory object were replicated. | https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4934 |