Events Codes For Fun & Profit
Events Codes For Fun & Profit
IO
RedTeamRecipe
Red Team Recipe for Fun & Profit.
Share
Follow
profit(RTC0020)
Event Codes for fun & profit
Event ID Event Name
4720 A user account was created
4722 A user account was enabled
4723 An attempt was made to change an account’s password
4724 An attempt was made to reset an account’s password
4725 A user account was disabled
4726 A user account was deleted
4738 A user account was changed
4740 A user account was locked out
4767 A user account was unlocked
4727 A security-enabled global group was created
4730 A security-enabled global group was deleted
4731 A security-enabled local group was created
4734 A security-enabled local group was deleted
4754 A security-enabled universal group was created
4758 A security-enabled universal group was deleted
4727 A security-enabled global group was created
4730 A security-enabled global group was deleted
4728 A member was added to a security-enabled global group
4729 A member was removed from a security-enabled global group
4732 A member was added to a security-enabled local group
4733 A member was removed from a security-enabled local group
4728 A member was added to a security-enabled global group
4729 A member was removed from a security-enabled global group
4732 A member was added to a security-enabled local group
4733 A member was removed from a security-enabled local group
4756 A member was added to a security-enabled universal group
4757 A member was removed from a security-enabled universal group
4625 FAILED_LOGON
4104 POWERSHELL_SCRIPT_EXECUTION
5145 FILE_SHARE_ACCESS
5145 FILE_SHARE_ACCESS
4674 PRIVILEGE_ELEVATION
1102 LOG_CLEAR
4648 EXPLICIT_CREDENTIAL_LOGON
4663 FILE_DELETED
7045 SERVICE_INSTALLED
4104 POWERSHELL_SCRIPT_EXECUTION
4688 PROCESS_CREATED
4697 SERVICE_CREATED
4104 POWERSHELL_SCRIPT_EXECUTION
4698 SCHEDULED_TASK_CREATED
4672 SPECIAL_PRIVILEGES_ASSIGNED
4688 PROCESS_CREATED
1102 DUPLICATE_TOKEN
4673 TOKEN_PRIVILEGES_MODIFIED
4672 SPECIAL_PRIVILEGES_ASSIGNED
4104 SCRIPT_BLOCK_LOGGING
4103 ENGINE_LIFECYCLE
4104 SCRIPT_BLOCK_LOGGING
Event ID Event Name
5859 WMI_EVENT_FILTER_TO_CONSUMER_BINDING
5858 WMI_ACTIVITY_EXECQUERY
5157 FIREWALL_BLOCK
4104 SCRIPT_BLOCK_LOGGING
7045 SERVICE_INSTALLED
1102 LOG_CLEARED
4673 SENSITIVE_PRIVILEGE_USE
7000 SERVICE_START_FAILED
4660 OBJECT_DELETED
4689 PROCESS_TERMINATED
7034 SERVICE_CRASHED
4226 TCP/IP_CONNECTION_LIMIT_REACHED
Malware Execution:
ID: 002
Data Exfiltration:
ID: 003
Lateral Movement:
ID: 004
Privilege Escalation:
ID: 005
MITRE Tactic & Techniques: Command and Control Commonly Used Port [T1043]
Event ID & Code: 3 NETWORK_CONNECTION
Status Code: N/A
Credential Dumping:
ID: 007
Network Scanning:
ID: 009
System Reconfiguration:
ID: 011
Scripting:
ID: 012
MITRE Tactic & Techniques:** Lateral Movement Remote File Copy [T1021.002]
Event ID & Code:** 4697 SERVICE_CREATED
Status Code: N/A
Process Injection:
ID: 016
Token Impersonation:
ID: 018
Token Duplication:
ID: 020
Token Theft:
ID: 022
evasion or persistence.
WMI Persistence:
ID: 033
MITRE Tactic & Techniques:** Initial Access External Remote Services [T1133]
Event ID & Code:** 5157 FIREWALL_BLOCK
Status Code:** N/A
MITRE Tactic & Techniques:** Command and Control Web Service [T1102]
Event ID & Code:** 5157 FIREWALL_BLOCK
Status Code:** N/A
MITRE Tactic & Techniques:** Command and Control Non-Standard Port [T1571]
Event ID & Code:** 5157 FIREWALL_BLOCK
Status Code:** N/A
Commands and Code:** netsh advfirewall firewall add rule name="Block Non-
Standard Port" dir=out remoteport=1337 action=block
Code Obfuscation:
ID: 043
Rootkit Installation:**
ID: 047
Data Destruction:
ID: 048
Resource Hijacking:
ID:** 050
Service Stop:**
ID:** 051
Description:** Flooding the target system with network requests to cause denial
of service.
Windows logon failure events are captured in the Security log, and each logon
failure event provides a Status and Sub Status code that can help in identifying the
reason for the failure. Here are 20 examples of such codes:
wrongpassword
2. Status: 0xC000006D
3. Status: 0xC000006D
4. Status: 0xC000006D
5. Status: 0xC000006D
6. Status: 0xC000006D
7. Status: 0xC000006D
8. Status: 0xC000006D
Sub Status: 0xC0000193
Description: The account’s password must be changed before logging on
the first time.
9. Status: 0xC000006E
Failure
Description
Code
0x6 The user doesn’t exist
Failure
Description
Code
0x9 Password must be reset
Account disabled, account expired, account locked out, or out of
0x12
logon hours
0x17 Password expired
0x18 Wrong password
0x20 Ticket expired