You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

1.6 KiB

1event_idsourcedescription
2104Microsoft-Windows-EventlogAttackers tend to clear logs in order to hide previous activity.
3104EventlogAttackers tend to clear logs in order to hide previous activity.
4517SecurityAttackers tend to clear logs in order to hide previous activity.
51000Application ErrorCritical application error
61001Microsoft-Windows-WER-SystemErrorReportingBlue Screen of Death
71002Application HangApplication hang
81076USER32An admin provided a reason for an unexpected restart
91102EventlogAttackers tend to clear logs in order to hide previous activity.
102004Microsoft-Windows-Windows Firewall with Advanced SecurityFirewall rule added
112006Microsoft-Windows-Windows Firewall with Advanced SecurityFirewall rule deleted
122033Microsoft-Windows-Windows Firewall with Advanced SecurityFirewall rule deleted
134608Microsoft Windows security auditingThe computer has been restarted - not an usual event.
144625Microsoft Windows security auditingA user failed to logon
154663Microsoft-Windows-Security-AuditingAn audited object has been accessed.
164719Microsoft-Windows-Security-AuditingSystem audit policy was changed
174728Microsoft-Windows-Security-AuditingUser Added to Privileged Group
184732Microsoft-Windows-Security-AuditingUser Added to Privileged Group
194735Microsoft-Windows-Security-AuditingSecurity-Enabled Group Modification
204740Microsoft-Windows-Security-AuditingAccount lockout
214756Microsoft-Windows-Security-AuditingUser Added to Privileged Group
227045Service Control ManagerInstallation of new services are not typical events.