You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
60 KiB
60 KiB
| 1 | action | category | os | signature | signature_id | subcategory | status | object | object_category |
|---|---|---|---|---|---|---|---|---|---|
| 2 | deleted | Object Access | Windows 7, Windows Server 2008 R2 | The audit log was cleared | 1102 | Log clear | success | Microsoft-Windows-Eventlog | auditlog |
| 3 | success | System | Windows Vista, Windows Server 2008 | Windows is starting up. | 4608 | Security State Change | |||
| 4 | unknown | System | Windows Vista, Windows Server 2008 | Windows is shutting down. | 4609 | Security State Change | |||
| 5 | unknown | System | Windows Vista, Windows Server 2008 | An authentication package has been loaded by the Local Security Authority. | 4610 | Security System Extension | |||
| 6 | success | System | Windows Vista, Windows Server 2008 | A trusted logon process has been registered with the Local Security Authority. | 4611 | Security System Extension | |||
| 7 | unknown | System | Windows Vista, Windows Server 2008 | Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits. | 4612 | System Integrity | |||
| 8 | unknown | System | Windows Vista, Windows Server 2008 | A notification package has been loaded by the Security Account Manager. | 4614 | Security System Extension | |||
| 9 | unknown | System | Windows Vista, Windows Server 2008 | Invalid use of LPC port. | 4615 | System Integrity | |||
| 10 | success | System | Windows Vista, Windows Server 2008 | The system time was changed. | 4616 | Security State Change | |||
| 11 | unknown | System | Windows Vista, Windows Server 2008 | A monitored security event pattern has occurred. | 4618 | System Integrity | |||
| 12 | unknown | System | Windows Vista, Windows Server 2008 | Administrator recovered system from CrashOnAuditFail. Users who are not administrators will now be allowed to log on. Some auditable activity might not have been recorded. | 4621 | Security State Change | |||
| 13 | unknown | System | Windows Vista, Windows Server 2008 | A security package has been loaded by the Local Security Authority. | 4622 | Security System Extension | |||
| 14 | success | Logon/Logoff | Windows Vista, Windows Server 2008 | An account was successfully logged on. | 4624 | Logon | |||
| 15 | failure | Logon/Logoff | Windows Vista, Windows Server 2008 | An account failed to log on. | 4625 | Logon | |||
| 16 | unknown | Logon/Logoff | Windows 8, Windows Server 2012 | User/Device claims information. | 4626 | Logon | |||
| 17 | success | Logon/Logoff | Windows Vista, Windows Server 2008 | An account was logged off. | 4634 | Logoff | |||
| 18 | unknown | Logon/Logoff | Windows Vista, Windows Server 2008 | IKE DoS-prevention mode started. | 4646 | IPsec Main Mode | |||
| 19 | success | Logon/Logoff | Windows Vista, Windows Server 2008 | User initiated logoff. | 4647 | Logoff | |||
| 20 | success | Logon/Logoff | Windows Vista, Windows Server 2008 | A logon was attempted using explicit credentials. | 4648 | Logon | |||
| 21 | unknown | Logon/Logoff | Windows Vista, Windows Server 2008 | A replay attack was detected. | 4649 | Other Logon/Logoff Events | |||
| 22 | unknown | Logon/Logoff | Windows Vista, Windows Server 2008 | An IPsec Main Mode security association was established. Extended Mode was not enabled. Certificate authentication was not used. | 4650 | IPsec Main Mode | |||
| 23 | unknown | Logon/Logoff | Windows Vista, Windows Server 2008 | An IPsec Main Mode security association was established. Extended Mode was not enabled. A certificate was used for authentication. | 4651 | IPsec Main Mode | |||
| 24 | unknown | Logon/Logoff | Windows Vista, Windows Server 2008 | An IPsec Main Mode negotiation failed. | 4652 | IPsec Main Mode | |||
| 25 | failure | Logon/Logoff | Windows Vista, Windows Server 2008 | An IPsec Main Mode negotiation failed. | 4653 | IPsec Main Mode | |||
| 26 | unknown | Logon/Logoff | Windows Vista, Windows Server 2008 | An IPsec Quick Mode negotiation failed. | 4654 | IPsec Quick Mode | |||
| 27 | unknown | Logon/Logoff | Windows Vista, Windows Server 2008 | An IPsec Main Mode security association ended. | 4655 | IPsec Main Mode | |||
| 28 | failure | Object Access | Windows Vista, Windows Server 2008 | A handle to an object was requested. | 4656 | Handle Manipulation | |||
| 29 | unknown | Object Access | Windows Vista, Windows Server 2008 | A registry value was modified. | 4657 | Registry | |||
| 30 | success | Object Access | Windows Vista, Windows Server 2008 | The handle to an object was closed. | 4658 | Handle Manipulation | |||
| 31 | unknown | Object Access | Windows Vista, Windows Server 2008 | A handle to an object was requested with intent to delete. | 4659 | Special | |||
| 32 | unknown | Object Access | Windows Vista, Windows Server 2008 | An object was deleted. | 4660 | Special | |||
| 33 | success | Object Access | Windows Vista, Windows Server 2008 | A handle to an object was requested. | 4661 | Special | |||
| 34 | success | DS Access | Windows Vista, Windows Server 2008 | An operation was performed on an object. | 4662 | Directory Service Access | |||
| 35 | success | Object Access | Windows Vista, Windows Server 2008 | An attempt was made to access an object. | 4663 | Special | |||
| 36 | success | Object Access | Windows Vista, Windows Server 2008 | An attempt was made to create a hard link. | 4664 | File System | |||
| 37 | unknown | Object Access | Windows Vista, Windows Server 2008 | An attempt was made to create an application client context. | 4665 | Application Generated | |||
| 38 | unknown | Object Access | Windows Vista, Windows Server 2008 | An application attempted an operation: | 4666 | Application Generated | |||
| 39 | unknown | Object Access | Windows Vista, Windows Server 2008 | An application client context was deleted. | 4667 | Application Generated | |||
| 40 | unknown | Object Access | Windows Vista, Windows Server 2008 | An application was initialized. | 4668 | Application Generated | |||
| 41 | success | Policy Change | Windows Vista, Windows Server 2008 | Permissions on an object were changed. | 4670 | Subcategory (special) | |||
| 42 | unknown | Object Access | Windows Vista, Windows Server 2008 | An application attempted to access a blocked ordinal through the TBS. | 4671 | Other Object Access Events | |||
| 43 | success | Privilege Use | Windows Vista, Windows Server 2008 | Special privileges assigned to new logon. | 4672 | Sensitive Privilege Use / Non Sensitive Privilege Use | |||
| 44 | failure | Privilege Use | Windows Vista, Windows Server 2008 | A privileged service was called. | 4673 | Sensitive Privilege Use / Non Sensitive Privilege Use | |||
| 45 | success | Privilege Use | Windows Vista, Windows Server 2008 | An operation was attempted on a privileged object. | 4674 | Sensitive Privilege Use / Non Sensitive Privilege Use | |||
| 46 | unknown | Logon/Logoff | Windows Vista, Windows Server 2008 | SIDs were filtered. | 4675 | Logon | |||
| 47 | success | Detailed Tracking | Windows Vista, Windows Server 2008 | A new process has been created. | 4688 | Process Creation | |||
| 48 | success | Detailed Tracking | Windows Vista, Windows Server 2008 | A process has exited. | 4689 | Process Termination | |||
| 49 | success | Object Access | Windows Vista, Windows Server 2008 | An attempt was made to duplicate a handle to an object. | 4690 | Handle Manipulation | |||
| 50 | unknown | Object Access | Windows Vista, Windows Server 2008 | Indirect access to an object was requested. | 4691 | Other Object Access Events | |||
| 51 | unknown | Detailed Tracking | Windows Vista, Windows Server 2008 | Backup of data protection master key was attempted. | 4692 | DPAPI Activity | |||
| 52 | unknown | Detailed Tracking | Windows Vista, Windows Server 2008 | Recovery of data protection master key was attempted. | 4693 | DPAPI Activity | |||
| 53 | unknown | Detailed Tracking | Windows Vista, Windows Server 2008 | Protection of auditable protected data was attempted. | 4694 | DPAPI Activity | |||
| 54 | unknown | Detailed Tracking | Windows Vista, Windows Server 2008 | Unprotection of auditable protected data was attempted. | 4695 | DPAPI Activity | |||
| 55 | unknown | Detailed Tracking | Windows Vista, Windows Server 2008 | A primary token was assigned to process. | 4696 | Process Creation | |||
| 56 | unknown | System | Windows Vista, Windows Server 2008 | A service was installed in the system. | 4697 | Security System Extension | |||
| 57 | unknown | Object Access | Windows Vista, Windows Server 2008 | A scheduled task was created. | 4698 | Other Object Access Events | |||
| 58 | unknown | Object Access | Windows Vista, Windows Server 2008 | A scheduled task was deleted. | 4699 | Other Object Access Events | |||
| 59 | unknown | Object Access | Windows Vista, Windows Server 2008 | A scheduled task was enabled. | 4700 | Other Object Access Events | |||
| 60 | unknown | Object Access | Windows Vista, Windows Server 2008 | A scheduled task was disabled. | 4701 | Other Object Access Events | |||
| 61 | success | Object Access | Windows Vista, Windows Server 2008 | A scheduled task was updated. | 4702 | Other Object Access Events | |||
| 62 | success | Policy Change | Windows Vista, Windows Server 2008 | A user right was assigned. | 4704 | Authorization Policy Change | |||
| 63 | unknown | Policy Change | Windows Vista, Windows Server 2008 | A user right was removed. | 4705 | Authorization Policy Change | |||
| 64 | unknown | Policy Change | Windows Vista, Windows Server 2008 | A new trust was created to a domain. | 4706 | Authorization Policy Change | |||
| 65 | unknown | Policy Change | Windows Vista, Windows Server 2008 | A trust to a domain was removed. | 4707 | Authorization Policy Change | |||
| 66 | unknown | Policy Change | Windows Vista, Windows Server 2008 | IPsec Services was started. | 4709 | Filtering Platform Policy Change | |||
| 67 | unknown | Policy Change | Windows Vista, Windows Server 2008 | IPsec Services was disabled. | 4710 | Filtering Platform Policy Change | |||
| 68 | unknown | Policy Change | Windows Vista, Windows Server 2008 | May contain any one of the following: PAStore Engine applied locally cached copy of Active Directory storage IPsec policy on the computer.^MPAStore Engine applied Active Directory storage IPsec policy on the computer.^MPAStore Engine applied local registry storage IPsec policy on the computer.^MPAStore Engine failed to apply locally cached copy of Active Directory storage IPsec policy on the computer.^MPAStore Engine failed to apply Active Directory storage IPsec policy on the computer.^MPAStore Engine failed to apply local registry storage IPsec policy on the computer.^MPAStore Engine failed to apply some rules of the active IPsec policy on the computer.^MPAStore Engine failed to load directory storage IPsec policy on the computer.^MPAStore Engine loaded directory storage IPsec policy on the computer.^MPAStore Engine failed to load local storage IPsec policy on the computer.^MPAStore Engine loaded local storage IPsec policy on the computer.^MPAStore Engine polled for changes to the active IPsec policy and detected no changes. | 4711 | Filtering Platform Policy Change | |||
| 69 | unknown | Policy Change | Windows Vista, Windows Server 2008 | IPsec Services encountered a potentially serious failure. | 4712 | Filtering Platform Policy Change | |||
| 70 | unknown | Policy Change | Windows Vista, Windows Server 2008 | Kerberos policy was changed. | 4713 | Authentication Policy Change | |||
| 71 | unknown | Policy Change | Windows Vista, Windows Server 2008 | Encrypted data recovery policy was changed. | 4714 | Authorization Policy Change | |||
| 72 | acl_modified | Policy Change | Windows Vista, Windows Server 2008 | The audit policy (SACL) on an object was changed. | 4715 | Audit Policy Change | success | Audit Policy | policy |
| 73 | unknown | Policy Change | Windows Vista, Windows Server 2008 | Trusted domain information was modified. | 4716 | Authentication Policy Change | |||
| 74 | success | Policy Change | Windows Vista, Windows Server 2008 | System security access was granted to an account. | 4717 | Authentication Policy Change | |||
| 75 | unknown | Policy Change | Windows Vista, Windows Server 2008 | System security access was removed from an account. | 4718 | Authentication Policy Change | |||
| 76 | acl_modified | Policy Change | Windows Vista, Windows Server 2008 | System audit policy was changed. | 4719 | Audit Policy Change | success | Audit Policy | policy |
| 77 | created | Account Management | Windows Vista, Windows Server 2008 | A user account was created. | 4720 | User Account Management | success | Account Management | user |
| 78 | modified | Account Management | Windows Vista, Windows Server 2008 | A user account was enabled. | 4722 | User Account Management | success | Account Management | user |
| 79 | modified | Account Management | Windows Vista, Windows Server 2008 | An attempt was made to change an account's password. | 4723 | User Account Management | success | Account Management | user |
| 80 | modified | Account Management | Windows Vista, Windows Server 2008 | An attempt was made to reset an account's password. | 4724 | User Account Management | success | Account Management | user |
| 81 | modified | Account Management | Windows Vista, Windows Server 2008 | A user account was disabled. | 4725 | User Account Management | success | Account Management | user |
| 82 | deleted | Account Management | Windows Vista, Windows Server 2008 | A user account was deleted. | 4726 | User Account Management | Account Management | user | |
| 83 | success | Account Management | Windows Vista, Windows Server 2008 | A security-enabled global group was created. | 4727 | Security Group Management | |||
| 84 | success | Account Management | Windows Vista, Windows Server 2008 | A member was added to a security-enabled global group. | 4728 | Security Group Management | |||
| 85 | success | Account Management | Windows Vista, Windows Server 2008 | A member was removed from a security-enabled global group. | 4729 | Security Group Management | |||
| 86 | unknown | Account Management | Windows Vista, Windows Server 2008 | A security-enabled global group was deleted. | 4730 | Security Group Management | |||
| 87 | unknown | Account Management | Windows Vista, Windows Server 2008 | A security-enabled local group was created. | 4731 | Security Group Management | |||
| 88 | success | Account Management | Windows Vista, Windows Server 2008 | A member was added to a security-enabled local group. | 4732 | Security Group Management | |||
| 89 | success | Account Management | Windows Vista, Windows Server 2008 | A member was removed from a security-enabled local group. | 4733 | Security Group Management | |||
| 90 | unknown | Account Management | Windows Vista, Windows Server 2008 | A security-enabled local group was deleted. | 4734 | Security Group Management | |||
| 91 | success | Account Management | Windows Vista, Windows Server 2008 | A security-enabled local group was changed. | 4735 | Security Group Management | |||
| 92 | success | Account Management | Windows Vista, Windows Server 2008 | A security-enabled global group was changed. | 4737 | Security Group Management | |||
| 93 | modified | Account Management | Windows Vista, Windows Server 2008 | A user account was changed. | 4738 | User Account Management | success | Account Management | user |
| 94 | unknown | Policy Change | Windows Vista, Windows Server 2008 | Domain Policy was changed. | 4739 | Authentication Policy Change | |||
| 95 | modified | Account Management | Windows Vista, Windows Server 2008 | A user account was locked out. | 4740 | User Account Management | success | Account Management | user |
| 96 | modified | Account Management | Windows Vista, Windows Server 2008 | A computer account was changed. | 4742 | Computer Account Management | success | Account Management | computer |
| 97 | deleted | Account Management | Windows Vista, Windows Server 2008 | A computer account was deleted. | 4743 | Computer Account Management | success | Account Management | computer |
| 98 | unknown | Account Management | Windows Vista, Windows Server 2008 | A security-disabled local group was created. | 4744 | Distribution Group Management | |||
| 99 | unknown | Account Management | Windows Vista, Windows Server 2008 | A security-disabled local group was changed. | 4745 | Distribution Group Management | |||
| 100 | unknown | Account Management | Windows Vista, Windows Server 2008 | A member was added to a security-disabled local group. | 4746 | Distribution Group Management | |||
| 101 | unknown | Account Management | Windows Vista, Windows Server 2008 | A member was removed from a security-disabled local group. | 4747 | Distribution Group Management | |||
| 102 | unknown | Account Management | Windows Vista, Windows Server 2008 | A security-disabled local group was deleted. | 4748 | Distribution Group Management | |||
| 103 | unknown | Account Management | Windows Vista, Windows Server 2008 | A security-disabled global group was created. | 4749 | Distribution Group Management | |||
| 104 | unknown | Account Management | Windows Vista, Windows Server 2008 | A security-disabled global group was changed. | 4750 | Distribution Group Management | |||
| 105 | unknown | Account Management | Windows Vista, Windows Server 2008 | A member was added to a security-disabled global group. | 4751 | Distribution Group Management | |||
| 106 | unknown | Account Management | Windows Vista, Windows Server 2008 | A member was removed from a security-disabled global group. | 4752 | Distribution Group Management | |||
| 107 | unknown | Account Management | Windows Vista, Windows Server 2008 | A security-disabled global group was deleted. | 4753 | Distribution Group Management | |||
| 108 | success | Account Management | Windows Vista, Windows Server 2008 | A security-enabled universal group was created. | 4754 | Security Group Management | |||
| 109 | success | Account Management | Windows Vista, Windows Server 2008 | A security-enabled universal group was changed. | 4755 | Security Group Management | |||
| 110 | success | Account Management | Windows Vista, Windows Server 2008 | A member was added to a security-enabled universal group. | 4756 | Security Group Management | |||
| 111 | success | Account Management | Windows Vista, Windows Server 2008 | A member was removed from a security-enabled universal group. | 4757 | Security Group Management | |||
| 112 | unknown | Account Management | Windows Vista, Windows Server 2008 | A security-enabled universal group was deleted. | 4758 | Security Group Management | |||
| 113 | unknown | Account Management | Windows Vista, Windows Server 2008 | A security-disabled universal group was created. | 4759 | Distribution Group Management | |||
| 114 | unknown | Account Management | Windows Vista, Windows Server 2008 | A security-disabled universal group was changed. | 4760 | Distribution Group Management | |||
| 115 | unknown | Account Management | Windows Vista, Windows Server 2008 | A member was added to a security-disabled universal group. | 4761 | Distribution Group Management | |||
| 116 | unknown | Account Management | Windows Vista, Windows Server 2008 | A member was removed from a security-disabled universal group. | 4762 | Distribution Group Management | |||
| 117 | unknown | Account Management | Windows Vista, Windows Server 2008 | A group<75>s type was changed. | 4764 | Security Group Management | |||
| 118 | created | Account Management | Windows Vista, Windows Server 2008 | SID History was added to an account. | 4765 | User Account Management | success | Account Management | sid |
| 119 | created | Account Management | Windows Vista, Windows Server 2008 | An attempt to add SID History to an account failed. | 4766 | User Account Management | failure | Account Management | sid |
| 120 | modified | Account Management | Windows Vista, Windows Server 2008 | A user account was unlocked. | 4767 | User Account Management | success | Account Management | user |
| 121 | failure | Account Logon | Windows Vista, Windows Server 2008 | A Kerberos authentication ticket (TGT) was requested. | 4768 | Kerberos Authentication Service | |||
| 122 | failure | Account Logon | Windows Vista, Windows Server 2008 | A Kerberos service ticket was requested. | 4769 | Kerberos Service Ticket Operations | |||
| 123 | success | Account Logon | Windows Vista, Windows Server 2008 | A Kerberos service ticket was renewed. | 4770 | Kerberos Service Ticket Operations | |||
| 124 | failure | Account Logon | Windows Vista, Windows Server 2008 | Kerberos pre-authentication failed. | 4771 | Kerberos Authentication Service | |||
| 125 | unknown | Account Logon | Windows Vista, Windows Server 2008 | A Kerberos authentication ticket request failed. | 4772 | Kerberos Authentication Service | |||
| 126 | unknown | Account Logon | Windows Vista, Windows Server 2008 | An account was mapped for logon. | 4774 | Credential Validation | |||
| 127 | unknown | Account Logon | Windows Vista, Windows Server 2008 | An account could not be mapped for logon. | 4775 | Credential Validation | |||
| 128 | failure | Account Logon | Windows Vista, Windows Server 2008 | The domain controller attempted to validate the credentials for an account. | 4776 | Credential Validation | |||
| 129 | unknown | Account Logon | Windows Vista, Windows Server 2008 | The domain controller failed to validate the credentials for an account. | 4777 | Credential Validation | |||
| 130 | success | Logon/Logoff | Windows Vista, Windows Server 2008 | A session was reconnected to a Window Station. | 4778 | Other Logon/Logoff Events | |||
| 131 | success | Logon/Logoff | Windows Vista, Windows Server 2008 | A session was disconnected from a Window Station. | 4779 | Other Logon/Logoff Events | |||
| 132 | acl_modified | Account Management | Windows Vista, Windows Server 2008 | The ACL was set on accounts which are members of administrators groups. | 4780 | User Account Management | success | Account Management | group |
| 133 | modified | Account Management | Windows Vista, Windows Server 2008 | The name of an account was changed: | 4781 | User Account Management | success | Account Management | user |
| 134 | unknown | Account Management | Windows Vista, Windows Server 2008 | The password hash an account was accessed. | 4782 | Other Account Management Events | |||
| 135 | unknown | Account Management | Windows Vista, Windows Server 2008 | A basic application group was created. | 4783 | Application Group Management | |||
| 136 | unknown | Account Management | Windows Vista, Windows Server 2008 | A basic application group was changed. | 4784 | Application Group Management | |||
| 137 | unknown | Account Management | Windows Vista, Windows Server 2008 | A member was added to a basic application group. | 4785 | Application Group Management | |||
| 138 | unknown | Account Management | Windows Vista, Windows Server 2008 | A member was removed from a basic application group. | 4786 | Application Group Management | |||
| 139 | unknown | Account Management | Windows Vista, Windows Server 2008 | A non-member was added to a basic application group. | 4787 | Application Group Management | |||
| 140 | unknown | Account Management | Windows Vista, Windows Server 2008 | A non-member was removed from a basic application group. | 4788 | Application Group Management | |||
| 141 | unknown | Account Management | Windows Vista, Windows Server 2008 | A basic application group was deleted. | 4789 | Application Group Management | |||
| 142 | unknown | Account Management | Windows Vista, Windows Server 2008 | An LDAP query group was created. | 4790 | Application Group Management | |||
| 143 | unknown | Account Management | Windows Vista, Windows Server 2008 | The Password Policy Checking API was called. | 4793 | Other Account Management Events | |||
| 144 | modified | Account Management | Windows Vista, Windows Server 2008 | An attempt was made to set the Directory Services Restore Mode. | 4794 | User Account Management | success | Account Management | user |
| 145 | success | Logon/Logoff | Windows Vista, Windows Server 2008 | The workstation was locked. | 4800 | Other Logon/Logoff Events | |||
| 146 | unknown | Logon/Logoff | Windows Vista, Windows Server 2008 | The workstation was unlocked. | 4801 | Other Logon/Logoff Events | |||
| 147 | unknown | Logon/Logoff | Windows Vista, Windows Server 2008 | The screen saver was invoked. | 4802 | Other Logon/Logoff Events | |||
| 148 | unknown | Logon/Logoff | Windows Vista, Windows Server 2008 | The screen saver was dismissed. | 4803 | Other Logon/Logoff Events | |||
| 149 | unknown | System | Windows Vista, Windows Server 2008 | RPC detected an integrity violation while decrypting an incoming message. | 4816 | System Integrity | |||
| 150 | unknown | Policy Change | Windows 7, Windows Server 2008 R2 | Auditing settings on an object were changed. | 4817 | Audit Policy Change | |||
| 151 | unknown | Object Access | Windows 8, Windows Server 2012 | Proposed Central Access Policy does not grant the same access permissions as the current Central Access Policy | 4818 | Central Policy Staging | |||
| 152 | unknown | Policy Change | Windows 8, Windows Server 2012 | Central Access Policies on the machine have been changed. | 4819 | Other Policy Change Events | |||
| 153 | unknown | Policy Change | Windows Vista, Windows Server 2008 | A namespace collision was detected. | 4864 | Authentication Policy Change | |||
| 154 | unknown | Policy Change | Windows Vista, Windows Server 2008 | A trusted forest information entry was added. | 4865 | Authentication Policy Change | |||
| 155 | unknown | Policy Change | Windows Vista, Windows Server 2008 | A trusted forest information entry was removed. | 4866 | Authentication Policy Change | |||
| 156 | unknown | Policy Change | Windows Vista, Windows Server 2008 | A trusted forest information entry was modified. | 4867 | Authentication Policy Change | |||
| 157 | unknown | Object Access | Windows Vista, Windows Server 2008 | The certificate manager denied a pending certificate request. | 4868 | Certification Services | |||
| 158 | unknown | Object Access | Windows Vista, Windows Server 2008 | Certificate Services received a resubmitted certificate request. | 4869 | Certification Services | |||
| 159 | unknown | Object Access | Windows Vista, Windows Server 2008 | Certificate Services revoked a certificate. | 4870 | Certification Services | |||
| 160 | unknown | Object Access | Windows Vista, Windows Server 2008 | Certificate Services received a request to publish the certificate revocation list (CRL). | 4871 | Certification Services | |||
| 161 | unknown | Object Access | Windows Vista, Windows Server 2008 | Certificate Services published the certificate revocation list (CRL). | 4872 | Certification Services | |||
| 162 | unknown | Object Access | Windows Vista, Windows Server 2008 | A certificate request extension changed. | 4873 | Certification Services | |||
| 163 | unknown | Object Access | Windows Vista, Windows Server 2008 | One or more certificate request attributes changed. | 4874 | Certification Services | |||
| 164 | unknown | Object Access | Windows Vista, Windows Server 2008 | Certificate Services received a request to shut down. | 4875 | Certification Services | |||
| 165 | unknown | Object Access | Windows Vista, Windows Server 2008 | Certificate Services backup started. | 4876 | Certification Services | |||
| 166 | unknown | Object Access | Windows Vista, Windows Server 2008 | Certificate Services backup completed. | 4877 | Certification Services | |||
| 167 | unknown | Object Access | Windows Vista, Windows Server 2008 | Certificate Services restore started. | 4878 | Certification Services | |||
| 168 | unknown | Object Access | Windows Vista, Windows Server 2008 | Certificate Services restore completed. | 4879 | Certification Services | |||
| 169 | unknown | Object Access | Windows Vista, Windows Server 2008 | Certificate Services started. | 4880 | Certification Services | |||
| 170 | unknown | Object Access | Windows Vista, Windows Server 2008 | Certificate Services stopped. | 4881 | Certification Services | |||
| 171 | unknown | Object Access | Windows Vista, Windows Server 2008 | The security permissions for Certificate Services changed. | 4882 | Certification Services | |||
| 172 | unknown | Object Access | Windows Vista, Windows Server 2008 | Certificate Services retrieved an archived key. | 4883 | Certification Services | |||
| 173 | unknown | Object Access | Windows Vista, Windows Server 2008 | Certificate Services imported a certificate into its database. | 4884 | Certification Services | |||
| 174 | unknown | Object Access | Windows Vista, Windows Server 2008 | The audit filter for Certificate Services changed. | 4885 | Certification Services | |||
| 175 | unknown | Object Access | Windows Vista, Windows Server 2008 | Certificate Services received a certificate request. | 4886 | Certification Services | |||
| 176 | unknown | Object Access | Windows Vista, Windows Server 2008 | Certificate Services approved a certificate request and issued a certificate. | 4887 | Certification Services | |||
| 177 | unknown | Object Access | Windows Vista, Windows Server 2008 | Certificate Services denied a certificate request. | 4888 | Certification Services | |||
| 178 | unknown | Object Access | Windows Vista, Windows Server 2008 | Certificate Services set the status of a certificate request to pending. | 4889 | Certification Services | |||
| 179 | unknown | Object Access | Windows Vista, Windows Server 2008 | The certificate manager settings for Certificate Services changed. | 4890 | Certification Services | |||
| 180 | unknown | Object Access | Windows Vista, Windows Server 2008 | A configuration entry changed in Certificate Services. | 4891 | Certification Services | |||
| 181 | unknown | Object Access | Windows Vista, Windows Server 2008 | A property of Certificate Services changed. | 4892 | Certification Services | |||
| 182 | unknown | Object Access | Windows Vista, Windows Server 2008 | Certificate Services archived a key. | 4893 | Certification Services | |||
| 183 | unknown | Object Access | Windows Vista, Windows Server 2008 | Certificate Services imported and archived a key. | 4894 | Certification Services | |||
| 184 | unknown | Object Access | Windows Vista, Windows Server 2008 | Certificate Services published the CA certificate to Active Directory Domain Services. | 4895 | Certification Services | |||
| 185 | unknown | Object Access | Windows Vista, Windows Server 2008 | One or more rows have been deleted from the certificate database. | 4896 | Certification Services | |||
| 186 | unknown | Object Access | Windows Vista, Windows Server 2008 | Role separation enabled: | 4897 | Certification Services | |||
| 187 | unknown | Object Access | Windows Vista, Windows Server 2008 | Certificate Services loaded a template. | 4898 | Certification Services | |||
| 188 | success | Policy Change | Windows Vista, Windows Server 2008 | The Per-user audit policy table was created. | 4902 | Audit Policy Change | |||
| 189 | success | Policy Change | Windows Vista, Windows Server 2008 | An attempt was made to register a security event source. | 4904 | Audit Policy Change | |||
| 190 | success | Policy Change | Windows Vista, Windows Server 2008 | An attempt was made to unregister a security event source. | 4905 | Audit Policy Change | |||
| 191 | unknown | Policy Change | Windows Vista, Windows Server 2008 | The CrashOnAuditFail value has changed. | 4906 | Audit Policy Change | |||
| 192 | success | Policy Change | Windows Vista, Windows Server 2008 | Auditing settings on object were changed. | 4907 | Audit Policy Change | |||
| 193 | unknown | Policy Change | Windows Vista, Windows Server 2008 | Special Groups Logon table modified. | 4908 | Audit Policy Change | |||
| 194 | unknown | Policy Change | Windows Vista, Windows Server 2008 | The local policy settings for the TBS were changed. | 4909 | Other Policy Change Events | |||
| 195 | unknown | Policy Change | Windows Vista, Windows Server 2008 | The group policy settings for the TBS were changed. | 4910 | Other Policy Change Events | |||
| 196 | unknown | Policy Change | Windows 8, Windows Server 2012 | Resource attributes of the object were changed. | 4911 | Authorization Policy Change | |||
| 197 | modified | Policy Change | Windows Vista, Windows Server 2008 | Per User Audit Policy was changed. | 4912 | Audit Policy Change | success | Policy Change | policy |
| 198 | unknown | Policy Change | Windows 8, Windows Server 2012 | Central Access Policy on the object was changed. | 4913 | Authorization Policy Change | |||
| 199 | unknown | DS Access | Windows Vista, Windows Server 2008 | An Active Directory replica source naming context was established. | 4928 | Detailed Directory Service Replication | |||
| 200 | unknown | DS Access | Windows Vista, Windows Server 2008 | An Active Directory replica source naming context was removed. | 4929 | Detailed Directory Service Replication | |||
| 201 | unknown | DS Access | Windows Vista, Windows Server 2008 | An Active Directory replica source naming context was modified. | 4930 | Detailed Directory Service Replication | |||
| 202 | success | DS Access | Windows Vista, Windows Server 2008 | An Active Directory replica destination naming context was modified. | 4931 | Detailed Directory Service Replication | |||
| 203 | success | DS Access | Windows Vista, Windows Server 2008 | Synchronization of a replica of an Active Directory naming context has begun. | 4932 | Directory Service Replication | |||
| 204 | failure | DS Access | Windows Vista, Windows Server 2008 | Synchronization of a replica of an Active Directory naming context has ended. | 4933 | Directory Service Replication | |||
| 205 | unknown | DS Access | Windows Vista, Windows Server 2008 | Attributes of an Active Directory object were replicated. | 4934 | Detailed Directory Service Replication | |||
| 206 | unknown | DS Access | Windows Vista, Windows Server 2008 | Replication failure begins. | 4935 | Detailed Directory Service Replication | |||
| 207 | unknown | DS Access | Windows Vista, Windows Server 2008 | Replication failure ends. | 4936 | Detailed Directory Service Replication | |||
| 208 | unknown | DS Access | Windows Vista, Windows Server 2008 | A lingering object was removed from a replica. | 4937 | Detailed Directory Service Replication | |||
| 209 | success | Policy Change | Windows Vista, Windows Server 2008 | The following policy was active when the Windows Firewall started. | 4944 | MPSSVC Rule-Level Policy Change | |||
| 210 | success | Policy Change | Windows Vista, Windows Server 2008 | A rule was listed when the Windows Firewall started. | 4945 | MPSSVC Rule-Level Policy Change | |||
| 211 | created | Policy Change | Windows Vista, Windows Server 2008 | A change has been made to Windows Firewall exception list. A rule was added. | 4946 | MPSSVC Rule-Level Policy Change | success | Windows Firewall | policy |
| 212 | modified | Policy Change | Windows Vista, Windows Server 2008 | A change has been made to Windows Firewall exception list. A rule was modified. | 4947 | MPSSVC Rule-Level Policy Change | success | Windows Firewall | policy |
| 213 | deleted | Policy Change | Windows Vista, Windows Server 2008 | A change has been made to Windows Firewall exception list. A rule was deleted. | 4948 | MPSSVC Rule-Level Policy Change | success | Windows Firewall | policy |
| 214 | unknown | Policy Change | Windows Vista, Windows Server 2008 | Windows Firewall settings were restored to the default values. | 4949 | MPSSVC Rule-Level Policy Change | |||
| 215 | unknown | Policy Change | Windows Vista, Windows Server 2008 | A Windows Firewall setting has changed. | 4950 | MPSSVC Rule-Level Policy Change | |||
| 216 | failure | Policy Change | Windows Vista, Windows Server 2008 | A rule has been ignored because its major version number was not recognized by Windows Firewall. | 4951 | MPSSVC Rule-Level Policy Change | |||
| 217 | unknown | Policy Change | Windows Vista, Windows Server 2008 | Parts of a rule have been ignored because its minor version number was not recognized by Windows Firewall. The other parts of the rule will be enforced. | 4952 | MPSSVC Rule-Level Policy Change | |||
| 218 | failure | Policy Change | Windows Vista, Windows Server 2008 | A rule has been ignored by Windows Firewall because it could not parse the rule. | 4953 | MPSSVC Rule-Level Policy Change | |||
| 219 | unknown | Policy Change | Windows Vista, Windows Server 2008 | Windows Firewall Group Policy settings have changed. The new settings have been applied. | 4954 | MPSSVC Rule-Level Policy Change | |||
| 220 | success | Policy Change | Windows Vista, Windows Server 2008 | Windows Firewall has changed the active profile. | 4956 | MPSSVC Rule-Level Policy Change | |||
| 221 | unknown | Policy Change | Windows Vista, Windows Server 2008 | Windows Firewall did not apply the following rule: | 4957 | MPSSVC Rule-Level Policy Change | |||
| 222 | unknown | Policy Change | Windows Vista, Windows Server 2008 | Windows Firewall did not apply the following rule because the rule referred to items not configured on this computer: | 4958 | MPSSVC Rule-Level Policy Change | |||
| 223 | unknown | System | Windows Vista, Windows Server 2008 | IPsec dropped an inbound packet that failed an integrity check. If this problem persists, it could indicate a network issue or that packets are being modified in transit to this computer. Verify that the packets sent from the remote computer are the same as those received by this computer. This error might also indicate interoperability problems with other IPsec implementations. | 4960 | IPsec Driver | |||
| 224 | unknown | System | Windows Vista, Windows Server 2008 | IPsec dropped an inbound packet that failed a replay check. If this problem persists, it could indicate a replay attack against this computer. | 4961 | IPsec Driver | |||
| 225 | unknown | System | Windows Vista, Windows Server 2008 | IPsec dropped an inbound packet that failed a replay check. The inbound packet had too low a sequence number to ensure it was not a replay. | 4962 | IPsec Driver | |||
| 226 | unknown | System | Windows Vista, Windows Server 2008 | IPsec dropped an inbound clear text packet that should have been secured. This is usually due to the remote computer changing its IPsec policy without informing this computer. This could also be a spoofing attack attempt. | 4963 | IPsec Driver | |||
| 227 | unknown | Logon/Logoff | Windows Vista, Windows Server 2008 | Special groups have been assigned to a new logon. | 4964 | Special Logon | |||
| 228 | unknown | System | Windows Vista, Windows Server 2008 | IPsec received a packet from a remote computer with an incorrect Security Parameter Index (SPI). This is usually caused by malfunctioning hardware that is corrupting packets. If these errors persist, verify that the packets sent from the remote computer are the same as those received by this computer. This error may also indicate interoperability problems with other IPsec implementations. In that case, if connectivity is not impeded, then these events can be ignored. | 4965 | IPsec Driver | |||
| 229 | unknown | Logon/Logoff | Windows Vista, Windows Server 2008 | During Main Mode negotiation, IPsec received an invalid negotiation packet. If this problem persists, it could indicate a network issue or an attempt to modify or replay this negotiation. | 4976 | IPsec Main Mode | |||
| 230 | unknown | Logon/Logoff | Windows Vista, Windows Server 2008 | During Quick Mode negotiation, IPsec received an invalid negotiation packet. If this problem persists, it could indicate a network issue or an attempt to modify or replay this negotiation. | 4977 | IPsec Quick Mode | |||
| 231 | unknown | Logon/Logoff | Windows Vista, Windows Server 2008 | During Extended Mode negotiation, IPsec received an invalid negotiation packet. If this problem persists, it could indicate a network issue or an attempt to modify or replay this negotiation. | 4978 | IPsec Extended Mode | |||
| 232 | unknown | Logon/Logoff | Windows Vista, Windows Server 2008 | IPsec Main Mode and Extended Mode security associations were established. | 4979 | IPsec Extended Mode | |||
| 233 | unknown | Logon/Logoff | Windows Vista, Windows Server 2008 | IPsec Main Mode and Extended Mode security associations were established. | 4980 | IPsec Extended Mode | |||
| 234 | unknown | Logon/Logoff | Windows Vista, Windows Server 2008 | IPsec Main Mode and Extended Mode security associations were established. | 4981 | IPsec Extended Mode | |||
| 235 | unknown | Logon/Logoff | Windows Vista, Windows Server 2008 | IPsec Main Mode and Extended Mode security associations were established. | 4982 | IPsec Extended Mode | |||
| 236 | unknown | Logon/Logoff | Windows Vista, Windows Server 2008 | An IPsec Extended Mode negotiation failed. The corresponding Main Mode security association has been deleted. | 4983 | IPsec Extended Mode | |||
| 237 | unknown | Logon/Logoff | Windows Vista, Windows Server 2008 | An IPsec Extended Mode negotiation failed. The corresponding Main Mode security association has been deleted. | 4984 | IPsec Extended Mode | |||
| 238 | success | Object Access | Windows Vista, Windows Server 2008 | The state of a transaction has changed. | 4985 | File System | |||
| 239 | success | System | Windows Vista, Windows Server 2008 | The Windows Firewall Service has started successfully. | 5024 | Other System Events | |||
| 240 | unknown | System | Windows Vista, Windows Server 2008 | The Windows Firewall Service has been stopped. | 5025 | Other System Events | |||
| 241 | unknown | System | Windows Vista, Windows Server 2008 | The Windows Firewall Service was unable to retrieve the security policy from the local storage. The service will continue enforcing the current policy. | 5027 | Other System Events | |||
| 242 | unknown | System | Windows Vista, Windows Server 2008 | The Windows Firewall Service was unable to parse the new security policy. The service will continue with currently enforced policy. | 5028 | Other System Events | |||
| 243 | unknown | System | Windows Vista, Windows Server 2008 | The Windows Firewall Service failed to initialize the driver. The service will continue to enforce the current policy. | 5029 | Other System Events | |||
| 244 | unknown | System | Windows Vista, Windows Server 2008 | The Windows Firewall Service failed to start. | 5030 | Other System Events | |||
| 245 | unknown | Object Access | Windows Vista, Windows Server 2008 | The Windows Firewall Service blocked an application from accepting incoming connections on the network. | 5031 | Filtering Platform Connection | |||
| 246 | unknown | System | Windows Vista, Windows Server 2008 | Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network. | 5032 | Other System Events | |||
| 247 | success | System | Windows Vista, Windows Server 2008 | The Windows Firewall Driver has started successfully. | 5033 | Other System Events | |||
| 248 | unknown | System | Windows Vista, Windows Server 2008 | The Windows Firewall Driver has been stopped. | 5034 | Other System Events | |||
| 249 | unknown | System | Windows Vista, Windows Server 2008 | The Windows Firewall Driver failed to start. | 5035 | Other System Events | |||
| 250 | unknown | System | Windows Vista, Windows Server 2008 | The Windows Firewall Driver detected critical runtime error. Terminating. | 5037 | Other System Events | |||
| 251 | unknown | System | Windows Vista, Windows Server 2008 | Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error. | 5038 | System Integrity | |||
| 252 | unknown | Object Access | Windows Vista, Windows Server 2008 | A registry key was virtualized. | 5039 | Registry | |||
| 253 | unknown | Policy Change | Windows Vista, Windows Server 2008 | A change has been made to IPsec settings. An Authentication Set was added. | 5040 | Filtering Platform Policy Change | |||
| 254 | unknown | Policy Change | Windows Vista, Windows Server 2008 | A change has been made to IPsec settings. An Authentication Set was modified. | 5041 | Filtering Platform Policy Change | |||
| 255 | unknown | Policy Change | Windows Vista, Windows Server 2008 | A change has been made to IPsec settings. An Authentication Set was deleted. | 5042 | Filtering Platform Policy Change | |||
| 256 | unknown | Policy Change | Windows Vista, Windows Server 2008 | A change has been made to IPsec settings. A Connection Security Rule was added. | 5043 | Filtering Platform Policy Change | |||
| 257 | unknown | Policy Change | Windows Vista, Windows Server 2008 | A change has been made to IPsec settings. A Connection Security Rule was modified. | 5044 | Filtering Platform Policy Change | |||
| 258 | unknown | Policy Change | Windows Vista, Windows Server 2008 | A change has been made to IPsec settings. A Connection Security Rule was deleted. | 5045 | Filtering Platform Policy Change | |||
| 259 | unknown | Policy Change | Windows Vista, Windows Server 2008 | A change has been made to IPsec settings. A Crypto Set was added. | 5046 | Filtering Platform Policy Change | |||
| 260 | unknown | Policy Change | Windows Vista, Windows Server 2008 | A change has been made to IPsec settings. A Crypto Set was modified. | 5047 | Filtering Platform Policy Change | |||
| 261 | unknown | Policy Change | Windows Vista, Windows Server 2008 | A change has been made to IPsec settings. A Crypto Set was deleted. | 5048 | Filtering Platform Policy Change | |||
| 262 | unknown | Logon/Logoff | Windows Vista, Windows Server 2008 | An IPsec Security Association was deleted. | 5049 | IPsec Main Mode | |||
| 263 | unknown | Object Access | Windows Vista, Windows Server 2008 | A file was virtualized. | 5051 | File System | |||
| 264 | success | System | Windows Vista, Windows Server 2008 | A cryptographic self test was performed. | 5056 | System Integrity | |||
| 265 | unknown | System | Windows Vista, Windows Server 2008 | A cryptographic primitive operation failed. | 5057 | System Integrity | |||
| 266 | success | System | Windows Vista, Windows Server 2008 | Key file operation. | 5058 | Other System Events | |||
| 267 | success | System | Windows Vista, Windows Server 2008 | Key migration operation. | 5059 | Other System Events | |||
| 268 | unknown | System | Windows Vista, Windows Server 2008 | Verification operation failed. | 5060 | System Integrity | |||
| 269 | failure | System | Windows Vista, Windows Server 2008 | Cryptographic operation. | 5061 | System Integrity | |||
| 270 | unknown | System | Windows Vista, Windows Server 2008 | A kernel-mode cryptographic self test was performed. | 5062 | System Integrity | |||
| 271 | unknown | Policy Change | Windows Vista, Windows Server 2008 | A cryptographic provider operation was attempted. | 5063 | Other Policy Change Events | |||
| 272 | unknown | Policy Change | Windows Vista, Windows Server 2008 | A cryptographic context operation was attempted. | 5064 | Other Policy Change Events | |||
| 273 | unknown | Policy Change | Windows Vista, Windows Server 2008 | A cryptographic context modification was attempted. | 5065 | Other Policy Change Events | |||
| 274 | unknown | Policy Change | Windows Vista, Windows Server 2008 | A cryptographic function operation was attempted. | 5066 | Other Policy Change Events | |||
| 275 | unknown | Policy Change | Windows Vista, Windows Server 2008 | A cryptographic function modification was attempted. | 5067 | Other Policy Change Events | |||
| 276 | unknown | Policy Change | Windows Vista, Windows Server 2008 | A cryptographic function provider operation was attempted. | 5068 | Other Policy Change Events | |||
| 277 | unknown | Policy Change | Windows Vista, Windows Server 2008 | A cryptographic function property operation was attempted. | 5069 | Other Policy Change Events | |||
| 278 | unknown | Policy Change | Windows Vista, Windows Server 2008 | A cryptographic function property modification was attempted. | 5070 | Other Policy Change Events | |||
| 279 | success | DS Access | Windows Vista, Windows Server 2008 | A directory service object was modified. | 5136 | Directory Service Changes | |||
| 280 | unknown | DS Access | Windows Vista, Windows Server 2008 | A directory service object was created. | 5137 | Directory Service Changes | |||
| 281 | unknown | DS Access | Windows Vista, Windows Server 2008 | A directory service object was undeleted. | 5138 | Directory Service Changes | |||
| 282 | unknown | DS Access | Windows Vista, Windows Server 2008 | A directory service object was moved. | 5139 | Directory Service Changes | |||
| 283 | failure | Object Access | Windows Vista, Windows Server 2008 | A network share object was accessed. | 5140 | File Share | |||
| 284 | unknown | DS Access | Windows Vista SP1, Windows Server 2008 | A directory service object was deleted. | 5141 | Directory Service Changes | |||
| 285 | unknown | Object Access | Windows 7, Windows Server 2008 R2 | A network share object was added. | 5142 | File Share | |||
| 286 | success | Object Access | Windows 7, Windows Server 2008 R2 | A network share object was modified. | 5143 | File Share | |||
| 287 | unknown | Object Access | Windows 7, Windows Server 2008 R2 | A network share object was deleted. | 5144 | File Share | |||
| 288 | unknown | Object Access | Windows 7, Windows Server 2008 R2 | A network share object was checked to see whether the client can be granted desired access. | 5145 | Detailed File Share | |||
| 289 | unknown | Object Access | Windows 7, Windows Server 2008 R2 | The Windows Filtering Platform has detected a DoS attack and entered a defensive mode; packets associated with this attack will be discarded. | 5148 | Other Object Access Events | |||
| 290 | unknown | Object Access | Windows 7, Windows Server 2008 R2 | The DoS attack has subsided and normal processing is being resumed. | 5149 | Other Object Access Events | |||
| 291 | unknown | Object Access | Windows 7, Windows Server 2008 R2 | The Windows Filtering Platform has blocked a packet. | 5150 | Filtering Platform Connection | |||
| 292 | unknown | Object Access | Windows 7, Windows Server 2008 R2 | A more restrictive Windows Filtering Platform filter has blocked a packet. | 5151 | Filtering Platform Connection | |||
| 293 | failure | Object Access | Windows Vista, Windows Server 2008 | The Windows Filtering Platform blocked a packet. | 5152 | Filtering Platform Packet Drop | |||
| 294 | unknown | Object Access | Windows Vista, Windows Server 2008 | A more restrictive Windows Filtering Platform filter has blocked a packet. | 5153 | Filtering Platform Packet Drop | |||
| 295 | success | Object Access | Windows Vista, Windows Server 2008 | The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections. | 5154 | Filtering Platform Connection | |||
| 296 | unknown | Object Access | Windows Vista, Windows Server 2008 | The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections. | 5155 | Filtering Platform Connection | |||
| 297 | success | Object Access | Windows Vista, Windows Server 2008 | The Windows Filtering Platform has allowed a connection. | 5156 | Filtering Platform Connection | |||
| 298 | failure | Object Access | Windows Vista, Windows Server 2008 | The Windows Filtering Platform has blocked a connection. | 5157 | Filtering Platform Connection | |||
| 299 | success | Object Access | Windows Vista, Windows Server 2008 | The Windows Filtering Platform has permitted a bind to a local port. | 5158 | Filtering Platform Connection | |||
| 300 | unknown | Object Access | Windows Vista, Windows Server 2008 | The Windows Filtering Platform has blocked a bind to a local port. | 5159 | Filtering Platform Connection | |||
| 301 | unknown | Object Access | Windows 7, Windows Server 2008 R2 | Spn check for SMB/SMB2 failed. | 5168 | File Share | |||
| 302 | read | Account Management | Windows Vista, Windows Server 2008 | Credential Manager credentials were backed up. | 5376 | User Account Management | success | Account Management | user |
| 303 | modified | Account Management | Windows Vista, Windows Server 2008 | Credential Manager credentials were restored from a backup. | 5377 | User Account Management | success | Account Management | user |
| 304 | unknown | Logon/Logoff | Windows Vista, Windows Server 2008 | The requested credentials delegation was disallowed by policy. | 5378 | Other Logon/Logoff Events | |||
| 305 | success | Policy Change | Windows Vista, Windows Server 2008 | The following callout was present when the Windows Filtering Platform Base Filtering Engine started. | 5440 | Filtering Platform Policy Change | |||
| 306 | success | Policy Change | Windows Vista, Windows Server 2008 | The following filter was present when the Windows Filtering Platform Base Filtering Engine started. | 5441 | Filtering Platform Policy Change | |||
| 307 | success | Policy Change | Windows Vista, Windows Server 2008 | The following provider was present when the Windows Filtering Platform Base Filtering Engine started. | 5442 | Filtering Platform Policy Change | |||
| 308 | unknown | Policy Change | Windows Vista, Windows Server 2008 | The following provider context was present when the Windows Filtering Platform Base Filtering Engine started. | 5443 | Filtering Platform Policy Change | |||
| 309 | success | Policy Change | Windows Vista, Windows Server 2008 | The following sub-layer was present when the Windows Filtering Platform Base Filtering Engine started. | 5444 | Filtering Platform Policy Change | |||
| 310 | success | Policy Change | Windows Vista, Windows Server 2008 | A Windows Filtering Platform callout has been changed. | 5446 | Filtering Platform Policy Change | |||
| 311 | success | Policy Change | Windows Vista, Windows Server 2008 | A Windows Filtering Platform filter has been changed. | 5447 | Other Policy Change Events | |||
| 312 | success | Policy Change | Windows Vista, Windows Server 2008 | A Windows Filtering Platform provider has been changed. | 5448 | Filtering Platform Policy Change | |||
| 313 | success | Policy Change | Windows Vista, Windows Server 2008 | A Windows Filtering Platform provider context has been changed. | 5449 | Filtering Platform Policy Change | |||
| 314 | success | Policy Change | Windows Vista, Windows Server 2008 | A Windows Filtering Platform sub-layer has been changed. | 5450 | Filtering Platform Policy Change | |||
| 315 | unknown | Logon/Logoff | Windows Vista, Windows Server 2008 | An IPsec Quick Mode security association was established. | 5451 | IPsec Quick Mode | |||
| 316 | unknown | Logon/Logoff | Windows Vista, Windows Server 2008 | An IPsec Quick Mode security association ended. | 5452 | IPsec Quick Mode | |||
| 317 | unknown | Logon/Logoff | Windows Vista, Windows Server 2008 | An IPsec negotiation with a remote computer failed because the IKE and AuthIP IPsec Keying Modules (IKEEXT) service is not started. | 5453 | IPsec Main Mode | |||
| 318 | unknown | Policy Change | Windows Vista, Windows Server 2008 | PAStore Engine applied Active Directory storage IPsec policy on the computer. | 5456 | Filtering Platform Policy Change | |||
| 319 | unknown | Policy Change | Windows Vista, Windows Server 2008 | PAStore Engine failed to apply Active Directory storage IPsec policy on the computer. | 5457 | Filtering Platform Policy Change | |||
| 320 | unknown | Policy Change | Windows Vista, Windows Server 2008 | PAStore Engine applied locally cached copy of Active Directory storage IPsec policy on the computer. | 5458 | Filtering Platform Policy Change | |||
| 321 | unknown | Policy Change | Windows Vista, Windows Server 2008 | PAStore Engine failed to apply locally cached copy of Active Directory storage IPsec policy on the computer. | 5459 | Filtering Platform Policy Change | |||
| 322 | unknown | Policy Change | Windows Vista, Windows Server 2008 | PAStore Engine applied local registry storage IPsec policy on the computer. | 5460 | Filtering Platform Policy Change | |||
| 323 | unknown | Policy Change | Windows Vista, Windows Server 2008 | PAStore Engine failed to apply local registry storage IPsec policy on the computer. | 5461 | Filtering Platform Policy Change | |||
| 324 | unknown | Policy Change | Windows Vista, Windows Server 2008 | PAStore Engine failed to apply some rules of the active IPsec policy on the computer. Use the IP Security Monitor snap-in to diagnose the problem. | 5462 | Filtering Platform Policy Change | |||
| 325 | unknown | Policy Change | Windows Vista, Windows Server 2008 | PAStore Engine polled for changes to the active IPsec policy and detected no changes. | 5463 | Filtering Platform Policy Change | |||
| 326 | unknown | Policy Change | Windows Vista, Windows Server 2008 | PAStore Engine polled for changes to the active IPsec policy, detected changes, and applied them to IPsec Services. | 5464 | Filtering Platform Policy Change | |||
| 327 | unknown | Policy Change | Windows Vista, Windows Server 2008 | PAStore Engine received a control for forced reloading of IPsec policy and processed the control successfully. | 5465 | Filtering Platform Policy Change | |||
| 328 | unknown | Policy Change | Windows Vista, Windows Server 2008 | PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory cannot be reached, and will use the cached copy of the Active Directory IPsec policy instead. Any changes made to the Active Directory IPsec policy since the last poll could not be applied. | 5466 | Filtering Platform Policy Change | |||
| 329 | unknown | Policy Change | Windows Vista, Windows Server 2008 | PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, and found no changes to the policy. The cached copy of the Active Directory IPsec policy is no longer being used. | 5467 | Filtering Platform Policy Change | |||
| 330 | unknown | Policy Change | Windows Vista, Windows Server 2008 | PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, found changes to the policy, and applied those changes. The cached copy of the Active Directory IPsec policy is no longer being used. | 5468 | Filtering Platform Policy Change | |||
| 331 | unknown | Policy Change | Windows Vista, Windows Server 2008 | PAStore Engine loaded local storage IPsec policy on the computer. | 5471 | Filtering Platform Policy Change | |||
| 332 | unknown | Policy Change | Windows Vista, Windows Server 2008 | PAStore Engine failed to load local storage IPsec policy on the computer. | 5472 | Filtering Platform Policy Change | |||
| 333 | unknown | Policy Change | Windows Vista, Windows Server 2008 | PAStore Engine loaded directory storage IPsec policy on the computer. | 5473 | Filtering Platform Policy Change | |||
| 334 | unknown | Policy Change | Windows Vista, Windows Server 2008 | PAStore Engine failed to load directory storage IPsec policy on the computer. | 5474 | Filtering Platform Policy Change | |||
| 335 | unknown | Policy Change | Windows Vista, Windows Server 2008 | PAStore Engine failed to add quick mode filter. | 5477 | Filtering Platform Policy Change | |||
| 336 | unknown | System | Windows Vista, Windows Server 2008 | IPsec Services has started successfully. | 5478 | IPsec Driver | |||
| 337 | unknown | System | Windows Vista, Windows Server 2008 | IPsec Services has been shut down successfully. The shutdown of IPsec Services can put the computer at greater risk of network attack or expose the computer to potential security risks. | 5479 | IPsec Driver | |||
| 338 | unknown | System | Windows Vista, Windows Server 2008 | IPsec Services failed to get the complete list of network interfaces on the computer. This poses a potential security risk because some of the network interfaces may not get the protection provided by the applied IPsec filters. Use the IP Security Monitor snap-in to diagnose the problem. | 5480 | IPsec Driver | |||
| 339 | unknown | System | Windows Vista, Windows Server 2008 | IPsec Services failed to initialize RPC server. IPsec Services could not be started. | 5483 | IPsec Driver | |||
| 340 | unknown | System | Windows Vista, Windows Server 2008 | IPsec Services has experienced a critical failure and has been shut down. The shutdown of IPsec Services can put the computer at greater risk of network attack or expose the computer to potential security risks. | 5484 | IPsec Driver | |||
| 341 | unknown | System | Windows Vista, Windows Server 2008 | IPsec Services failed to process some IPsec filters on a plug-and-play event for network interfaces. This poses a potential security risk because some of the network interfaces may not get the protection provided by the applied IPsec filters. Use the IP Security Monitor snap-in to diagnose the problem. | 5485 | IPsec Driver | |||
| 342 | unknown | Logon/Logoff | Windows Vista, Windows Server 2008 | A request was made to authenticate to a wireless network. | 5632 | Other Logon/Logoff Events | |||
| 343 | unknown | Logon/Logoff | Windows Vista, Windows Server 2008 | A request was made to authenticate to a wired network. | 5633 | Other Logon/Logoff Events | |||
| 344 | unknown | Detailed Tracking | Windows Vista, Windows Server 2008 | A Remote Procedure Call (RPC) was attempted. | 5712 | RPC Events | |||
| 345 | unknown | Object Access | Windows Vista, Windows Server 2008 | An object in the COM+ Catalog was modified. | 5888 | Other Object Access Events | |||
| 346 | unknown | Object Access | Windows Vista, Windows Server 2008 | An object was deleted from the COM+ Catalog. | 5889 | Other Object Access Events | |||
| 347 | unknown | Object Access | Windows Vista, Windows Server 2008 | An object was added to the COM+ Catalog. | 5890 | Other Object Access Events | |||
| 348 | success | Policy Change | Windows Vista, Windows Server 2008 | Security policy in the group policy objects has been applied successfully. | 6144 | Other Policy Change Events | |||
| 349 | unknown | Policy Change | Windows Vista, Windows Server 2008 | One or more errors occurred while processing security policy in the group policy objects. | 6145 | Other Policy Change Events | |||
| 350 | unknown | Logon/Logoff | Windows Vista SP1, Windows Server 2008 | Network Policy Server granted access to a user. | 6272 | Network Policy Server | |||
| 351 | unknown | Logon/Logoff | Windows Vista SP1, Windows Server 2008 | Network Policy Server denied access to a user. | 6273 | Network Policy Server | |||
| 352 | unknown | Logon/Logoff | Windows Vista SP1, Windows Server 2008 | Network Policy Server discarded the request for a user. | 6274 | Network Policy Server | |||
| 353 | unknown | Logon/Logoff | Windows Vista SP1, Windows Server 2008 | Network Policy Server discarded the accounting request for a user. | 6275 | Network Policy Server | |||
| 354 | unknown | Logon/Logoff | Windows Vista SP1, Windows Server 2008 | Network Policy Server quarantined a user. | 6276 | Network Policy Server | |||
| 355 | unknown | Logon/Logoff | Windows Vista SP1, Windows Server 2008 | Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy. | 6277 | Network Policy Server | |||
| 356 | unknown | Logon/Logoff | Windows Vista SP1, Windows Server 2008 | Network Policy Server granted full access to a user because the host met the defined health policy. | 6278 | Network Policy Server | |||
| 357 | unknown | Logon/Logoff | Windows Vista SP1, Windows Server 2008 | Network Policy Server locked the user account due to repeated failed authentication attempts. | 6279 | Network Policy Server | |||
| 358 | unknown | Logon/Logoff | Windows Vista SP1, Windows Server 2008 | Network Policy Server unlocked the user account. | 6280 | Network Policy Server | |||
| 359 | unknown | System | Windows 7, Windows Server 2008 R2 | Code Integrity determined that the page hashes of an image file are not valid. The file could be improperly signed without page hashes or corrupt due to unauthorized modification. The invalid hashes could indicate a potential disk device error | 6281 | System Integrity | |||
| 360 | unknown | System | Windows 7, Windows Server 2008 R2 | BranchCache: Received an incorrectly formatted response while discovering availability of content. | 6400 | Other System Events | |||
| 361 | unknown | System | Windows 7, Windows Server 2008 R2 | BranchCache: Received invalid data from a peer. Data discarded. | 6401 | Other System Events | |||
| 362 | unknown | System | Windows 7, Windows Server 2008 R2 | BranchCache: The message to the hosted cache offering it data is incorrectly formatted. | 6402 | Other System Events | |||
| 363 | unknown | System | Windows 7, Windows Server 2008 R2 | BranchCache: The hosted cache sent an incorrectly formatted response to the client. | 6403 | Other System Events | |||
| 364 | unknown | System | Windows 7, Windows Server 2008 R2 | BranchCache: Hosted cache could not be authenticated using the provisioned SSL certificate. | 6404 | Other System Events | |||
| 365 | unknown | System | Windows 7, Windows Server 2008 R2 | BranchCache: %2 instance(s) of event id %1 occurred. | 6405 | Other System Events | |||
| 366 | unknown | System | Windows 7, Windows Server 2008 R2 | %1 registered to Windows Firewall to control filtering for the following: %2 | 6406 | Other System Events | |||
| 367 | unknown | System | Windows 7, Windows Server 2008 R2 | 1% | 6407 | Other System Events |