Skip to main content

Windows Event ID Library

Every reference here is built for detection work, not trivia: the real Microsoft field tables, a simulated log sample you can copy, the status codes decoded, and SIEM queries you can run as written. Each page links to hands-on practice in SOCSimulator Operations.

System

Application

Logon/Logoff

4624

An account was successfully logged on

Event ID 4624 is the Windows Security log entry generated on the destination machine every time a logon session is created successfully, regardless of logon method. It fires for interactive desktop logons, network share access, RDP sessions, scheduled task execution, and service starts alike, so the Logon Type field is what actually tells an analyst what happened.

Read the reference
4625

An account failed to log on

Event ID 4625 is the Windows Security log entry generated on the Audit Logon and Audit Account Lockout subcategories whenever a logon attempt fails, whether from a wrong password, a locked account, or a disabled one. It fires on the machine where the attempt happened and carries a Status/SubStatus code pair that tells you why the logon was rejected.

Read the reference
4648

A logon was attempted using explicit credentials

Event ID 4648 fires when a process explicitly supplies a different account's credentials instead of using the caller's own logon session, most often through runas, scheduled tasks with stored credentials, or net use with /user:. It logs three identities at once: who initiated the action, whose credentials got used, and which server the new process ran on.

Read the reference
4672

Special privileges assigned to new logon

Event ID 4672 (Security log, Audit Special Logon subcategory) records that a new logon session was handed one or more sensitive Windows privileges, such as SeDebugPrivilege or SeBackupPrivilege. It fires immediately after a matching 4624 logon. Most instances come from SYSTEM and service accounts; the ones worth chasing are standard or service accounts receiving privileges they have never held before.

Read the reference

Detailed Tracking

Account Management

Account Logon

Frequently Asked Questions

What are Windows event IDs?
Windows event IDs are numeric codes the operating system assigns to every entry it writes into the Event Log. Each ID identifies one specific occurrence: Event 4625 is a failed logon, 4688 a new process, 7045 a new service. SOC analysts read them as the ground-truth telemetry behind most Windows detections.
Which Windows event IDs matter most for security monitoring?
The Security log auditing events carry most of the signal: 4624/4625 (logons), 4688 (process creation), 4672 (privileged logons), 4720/4740 (account creation and lockout), 1102 (audit log cleared), plus PowerShell 4104 and Service Control Manager 7045. Every entry in this library explains one of them with its fields, codes, and tested detection queries.
Where do I find Windows event IDs?
Open Event Viewer (eventvwr.msc) and browse Windows Logs: Security, System, and Application, or the Applications and Services Logs tree for channels like Sysmon and PowerShell Operational. In a SOC you rarely read Event Viewer directly: endpoints forward these logs to a SIEM, where you query them by event ID at scale.
How do I practice investigating Windows event logs?
Reading references only gets you part of the way. SOCSimulator Operations puts realistic Windows telemetry in front of you inside simulated SIEM, XDR, and Firewall consoles, so you can pivot on event IDs, correlate logons with process activity, and close investigations the way a working analyst does. A free tier is available.