Case 6C4B9D · Blue team / DFIR · L2 Practitioner
Key Windows Event IDs
Practise as: Explain it · Interview
Interview questionWhich Windows event IDs do you rely on most during an investigation?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- 4624 logon success (check Logon Type: 3 network, 10 RDP), 4625 failed logon, 4672 special privileges assigned.
- 4688 process creation (enable command-line auditing); Sysmon 1 gives hashes and parent process too.
- 4720 user created, 4728/4732 added to privileged group, 4698 scheduled task created, 7045 service installed.
- 1102 Security log cleared and 104 (another log cleared, recorded in System) are high-signal anti-forensics indicators.
- Kerberos: 4768 TGT request, 4769 service ticket (RC4 0x17 encryption hints at Kerberoasting).
If the interviewer pushes back
- How would you detect pass-the-hash using logon events, and why is it noisy?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.