Windows Event ID Library
Every reference here is built for detection work, not trivia: the real Microsoft field tables, a simulated log sample you can copy, the status codes decoded, and SIEM queries you can run as written. Each page links to hands-on practice in SOCSimulator Operations.
System
The audit log was cleared
Event ID 1102 records that someone cleared the Windows Security event log. Microsoft's own guidance is blunt: you should almost never see this event, and every occurrence deserves investigation. The event names the account (SubjectUserName, SubjectDomainName) and the SubjectLogonId that performed the clear, which is your starting point for tracing who did it and why.
Read the reference 7045A service was installed in the system
Event ID 7045 is logged by the Service Control Manager to the System log every time a new service is registered on a Windows host, whether by an installer, an admin using sc.exe, or an attacker using PsExec-style remote execution. It records the service name, image path, start mode, and account.
Read the referenceApplication
Logon/Logoff
An account was successfully logged on
Event ID 4624 is the Windows Security log entry generated on the destination machine every time a logon session is created successfully, regardless of logon method. It fires for interactive desktop logons, network share access, RDP sessions, scheduled task execution, and service starts alike, so the Logon Type field is what actually tells an analyst what happened.
Read the reference 4625An account failed to log on
Event ID 4625 is the Windows Security log entry generated on the Audit Logon and Audit Account Lockout subcategories whenever a logon attempt fails, whether from a wrong password, a locked account, or a disabled one. It fires on the machine where the attempt happened and carries a Status/SubStatus code pair that tells you why the logon was rejected.
Read the reference 4648A logon was attempted using explicit credentials
Event ID 4648 fires when a process explicitly supplies a different account's credentials instead of using the caller's own logon session, most often through runas, scheduled tasks with stored credentials, or net use with /user:. It logs three identities at once: who initiated the action, whose credentials got used, and which server the new process ran on.
Read the reference 4672Special privileges assigned to new logon
Event ID 4672 (Security log, Audit Special Logon subcategory) records that a new logon session was handed one or more sensitive Windows privileges, such as SeDebugPrivilege or SeBackupPrivilege. It fires immediately after a matching 4624 logon. Most instances come from SYSTEM and service accounts; the ones worth chasing are standard or service accounts receiving privileges they have never held before.
Read the referenceDetailed Tracking
Account Management
A user account was created
Event ID 4720 fires on Windows Server and workstations every time a new local or domain user account is created, logged to the Security channel under Audit User Account Management. It records who created the account (SubjectUserName) and who was created (TargetUserName), plus initial account attributes analysts use to spot backdoor accounts fast.
Read the reference 4740A user account was locked out
Event ID 4740 fires in the Security log when a user account gets locked out after exceeding the domain's bad-password threshold. Windows itself (SYSTEM) performs the lockout, so the event names the locked account, not an attacker. The CallerComputerName field is the pivot: it names the machine that generated the failed attempts.
Read the referenceAccount Logon
A Kerberos authentication ticket (TGT) was requested
Event ID 4768 records a Kerberos TGT request, the first authentication step of any domain logon. Only domain controllers write it, which makes it the authoritative record of where a logon began even when the client is not onboarded. Read the Result Code, the Pre-Authentication Type and the Client Address together.
Read the reference 4769A Kerberos service ticket was requested
Event ID 4769 is the Windows Security event a domain controller writes every time the Key Distribution Center receives a Kerberos service ticket (TGS) request. It records who asked, which service principal they asked for, the encryption type of the issued ticket, and the client address. RC4 (0x17) tickets for user-account SPNs are the Kerberoasting signal.
Read the reference 4776The computer attempted to validate the credentials for an account
Event ID 4776 is the Windows Security log entry written every time a computer validates an account's credentials over NTLM, under the Audit Credential Validation subcategory. It fires on the machine that owns the account (the domain controller for domain accounts, the local box for local accounts) and reports success or failure through its Error Code field.
Read the referenceFrequently Asked Questions
- What are Windows event IDs?
- Windows event IDs are numeric codes the operating system assigns to every entry it writes into the Event Log. Each ID identifies one specific occurrence: Event 4625 is a failed logon, 4688 a new process, 7045 a new service. SOC analysts read them as the ground-truth telemetry behind most Windows detections.
- Which Windows event IDs matter most for security monitoring?
- The Security log auditing events carry most of the signal: 4624/4625 (logons), 4688 (process creation), 4672 (privileged logons), 4720/4740 (account creation and lockout), 1102 (audit log cleared), plus PowerShell 4104 and Service Control Manager 7045. Every entry in this library explains one of them with its fields, codes, and tested detection queries.
- Where do I find Windows event IDs?
- Open Event Viewer (eventvwr.msc) and browse Windows Logs: Security, System, and Application, or the Applications and Services Logs tree for channels like Sysmon and PowerShell Operational. In a SOC you rarely read Event Viewer directly: endpoints forward these logs to a SIEM, where you query them by event ID at scale.
- How do I practice investigating Windows event logs?
- Reading references only gets you part of the way. SOCSimulator Operations puts realistic Windows telemetry in front of you inside simulated SIEM, XDR, and Firewall consoles, so you can pivot on event IDs, correlate logons with process activity, and close investigations the way a working analyst does. A free tier is available.