Open cardosec

Case 6C4B9D · Blue team / DFIR · L2 Practitioner

Key Windows Event IDs

Practise as: Explain it · Interview

Interview questionWhich Windows event IDs do you rely on most during an investigation?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. 4624 logon success (check Logon Type: 3 network, 10 RDP), 4625 failed logon, 4672 special privileges assigned.
  2. 4688 process creation (enable command-line auditing); Sysmon 1 gives hashes and parent process too.
  3. 4720 user created, 4728/4732 added to privileged group, 4698 scheduled task created, 7045 service installed.
  4. 1102 Security log cleared and 104 (another log cleared, recorded in System) are high-signal anti-forensics indicators.
  5. Kerberos: 4768 TGT request, 4769 service ticket (RC4 0x17 encryption hints at Kerberoasting).

If the interviewer pushes back

  • How would you detect pass-the-hash using logon events, and why is it noisy?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.