|
Decrypt call failed
|
1015 |
Microsoft-Windows-SMBServer/Security |
ClientName
ClientAddress
Status
IP
Computer
ProcessID
ThreadID
|
- |
|
Pipe Connected
|
18 |
Microsoft-Windows-Sysmon/Operational |
RuleName
EventType
ProcessGuid
ProcessId
PipeName
Image
User
IP
Computer
ProcessID
ThreadID
|
Sysmon/Pipe Connected |
|
Network connection
|
3 |
Microsoft-Windows-Sysmon/Operational |
DestinationHostname
DestinationIp
DestinationIsIpv6
DestinationPort
DestinationPortName
Image
Initiated
ProcessGuid
ProcessId
Protocol
RuleName
SourceHostname
SourceIp
SourceIsIpv6
SourcePort
SourcePortName
User
UtcTime
IP
Computer
ProcessID
ThreadID
|
Sysmon/Network connection |
|
The SMB redirector selected the connection initiated with the following parameters
|
30830 |
Microsoft-Windows-SmbClient/Connectivity |
ServerName
ConnectionType
RemoteAddress
LocalAddress
InstanceName
PortSelectionOrigin
Status
ConnectionId
ClientCertSha1Hash
IP
Computer
ProcessID
ThreadID
|
- |
|
Attempt to get credential key by call package blocked by Credential Guard
|
4014 |
Microsoft-Windows-NTLM/Operational |
ImageName
SvcHostTag
IP
Computer
ProcessID
ThreadID
|
- |
|
An account was successfully logged on
|
4624 |
Security |
SubjectUserSid
SubjectUserName
SubjectDomainName
SubjectLogonId
LogonType
RestrictedAdminMode
RemoteCredentialGuard
ImpersonationLevel
TargetUserSid
TargetUserName
TargetDomainName
TargetLogonId
LogonGuid
ProcessId
ProcessName
WorkstationName
IpAddress
IpPort
LogonProcessName
AuthenticationPackageName
IP
Computer
ProcessID
ThreadID
|
Audit Logon |
|
Group membership information
|
4627 |
Security |
SubjectUserSid
SubjectUserName
SubjectDomainName
SubjectLogonId
LogonType
TargetUserSid
TargetUserName
TargetDomainName
TargetLogonId
GroupMembership
IP
Computer
ProcessID
ThreadID
|
Audit Group Membership |
|
An account was logged off
|
4634 |
Security |
TargetUserSid
TargetUserName
TargetDomainName
TargetLogonId
LogonType
IP
Computer
ProcessID
ThreadID
|
Audit Logoff |
|
A logon was attempted using explicit credentials
|
4648 |
Security |
SubjectUserSid
SubjectUserName
SubjectDomainName
SubjectLogonId
LogonGuid
TargetUserName
TargetDomainName
TargetLogonGuid
TargetServerName
TargetInfo
ProcessId
ProcessName
IpAddress
IpPort
IP
Computer
ProcessID
ThreadID
|
Audit Logon |
|
Special privileges assigned to new logon
|
4672 |
Security |
SubjectUserSid
SubjectUserName
SubjectDomainName
SubjectLogonId
PrivilegeList
Computer
ProcessID
IP
ThreadID
|
Audit Special Logon |
|
An attempt was made to reset an account's password
|
4724 |
Security |
SubjectUserSid
SubjectUserName
SubjectDomainName
SubjectLogonId
TargetSid
TargetUserName
TargetDomainName
IP
Computer
ProcessID
ThreadID
|
Audit User Account Management |
|
A computer account was created
|
4741 |
Security |
SubjectUserSid
SubjectUserName
SubjectDomainName
SubjectLogonId
TargetSid
TargetUserName
TargetDomainName
SamAccountName
DisplayName
UserPrincipalName
HomeDirectory
HomePath
ScriptPath
ProfilePath
UserWorkstations
PasswordLastSet
AccountExpires
PrimaryGroupId
AllowedToDelegateTo
OldUacValue
NewUacValue
UserAccountControl
UserParameters
SidHistory
LogonHours
DnsHostName
ServicePrincipalNames
PrivilegeList
IP
Computer
ProcessID
ThreadID
|
Audit Computer Account Management |
|
A computer account was changed
|
4742 |
Security |
SubjectUserSid
SubjectUserName
SubjectDomainName
SubjectLogonId
TargetSid
TargetUserName
TargetDomainName
SamAccountName
DisplayName
UserPrincipalName
HomeDirectory
HomePath
ScriptPath
ProfilePath
UserWorkstations
PasswordLastSet
AccountExpires
PrimaryGroupId
AllowedToDelegateTo
OldUacValue
NewUacValue
UserAccountControl
UserParameters
SidHistory
LogonHours
DnsHostName
ServicePrincipalNames
PrivilegeList
IP
Computer
ProcessID
ThreadID
|
Audit Computer Account Management |
|
A Kerberos authentication ticket (TGT) was requested
|
4768 |
Security |
TargetUserName
TargetDomainName
TargetSid
ServiceName
ServiceSid
TicketOptions
Status
TicketEncryptionType
PreAuthType
IpAddress
IpPort
CertIssuerName
CertSerialNumber
CertThumbprint
ResponseTicket
IP
Computer
ProcessID
ThreadID
|
Audit Kerberos Authentication Service |
|
A Kerberos service ticket was requested
|
4769 |
Security |
TargetUserName
TargetDomainName
LogonGuid
ServiceName
ServiceSid
IpAddress
IpPort
TicketOptions
TicketEncryptionType
Status
TransmittedServices
RequestTicketHash
ResponseTicketHash
IP
Computer
ProcessID
ThreadID
|
Audit Kerberos Service Ticket Operations |
|
The computer attempted to validate the credentials for an account
|
4776 |
Security |
PackageName
TargetUserName
Workstation
Status
IP
Computer
ProcessID
ThreadID
|
Audit Credential Validation |
|
Certificate Services received a certificate request
|
4886 |
Security |
RequestId
Requester
Attributes
Subject
SubjectAlternativeName
CertificateTemplate
RequestOSVersion
RequestCSPProvider
RequestClientInfo
AuthenticationService
AuthenticationLevel
DCOMorRPC
IP
Computer
ProcessID
ThreadID
|
Audit Certification Services |
|
Certificate Services approved a certificate request and issued a certificate
|
4887 |
Security |
RequestId
Requester
Attributes
Subject
SubjectAlternativeName
CertificateTemplate
CertSerialNumber
AuthenticationService
AuthenticationLevel
DCOMorRPC
IP
Computer
ProcessID
ThreadID
|
Audit Certification Services |
|
Certificate Services received a certificate request
|
4889 |
Security |
RequestId
Requester
Attributes
Subject
SubjectAlternativeName
CertificateTemplate
RequestOSVersion
RequestCSPProvider
RequestClientInfo
AuthenticationService
AuthenticationLevel
DCOMorRPC
IP
Computer
ProcessID
ThreadID
|
Audit Certification Services |
|
A network share object was accessed
|
5140 |
Security |
SubjectUserSid
SubjectUserName
SubjectDomainName
SubjectLogonId
ObjectType
IpAddress
IpPort
ShareName
ShareLocalPath
AccessMask
AccessList
IP
Computer
ProcessID
ThreadID
|
Audit File Share |
|
The Netlogon service created a secure channel with a client with RC4
|
5840 |
System |
param1
param2
param3
param4
param5
IP
Computer
ProcessID
ThreadID
|
- |
|
NTLM server blocked audit: Audit Incoming NTLM Traffic that would be blocked
|
8002 |
Microsoft-Windows-NTLM/Operational |
ProcessName
CallerPID
ClientUserName
ClientDomainName
MechanismOID
IP
Computer
ProcessID
ThreadID
|
Network security: Restrict NTLM: Audit Incoming NTLM Traffic |
|
NTLM server blocked in the domain audit: Audit NTLM authentication in this domain
|
8003 |
Microsoft-Windows-NTLM/Operational |
UserName
DomainName
Workstation
CallerPID
ProcessName
LogonType
MechanismOID
IP
Computer
ProcessID
ThreadID
|
Network security: Restrict NTLM: Audit NTLM authentication in this domain |
|
Domain Controller Blocked Audit: Audit NTLM authentication to this domain controller
|
8004 |
Microsoft-Windows-NTLM/Operational |
UserName
DomainName
IP
Computer
ProcessID
ThreadID
|
Network security: Restrict NTLM: Audit NTLM authentication in this domain |