🖥️
Windows DFIR
search
⌘Ctrlk
🖥️
Windows DFIR
  • Introduction
  • Windows Artifacts
    • Windows Quick Tips
    • Account Usage
    • Browser Usage
    • Processes
    • Cloud Storage
    • Deleted File or File Knowledge
    • File Download
    • Folder/File Opening/Creation
    • Persistence
    • Physical Location
    • Program Execution
    • Shadow Copies
    • USB Usage
    • Windows Services
    • System Information
    • Event IDs
      • Authentication / Account
        • 4624 - Authentication Success
        • 4625 - Authentication Failure
        • 4634 - Account Logoff
        • 4648 - Explicit Credentials Success
        • 4672 - Special Privileges
        • 4720 - Account Creation
        • 4722 - Account Enabled
        • 4732 - Addition to Local Group
        • 4738 - Account Changed
        • 4776 - Kerberos Authentication Attempt
        • 4771 - Kerberos Failure
        • 4768
      • File System
  • Windows DFIR & MITTR
    • Initial Access
    • Execution
    • Persistence
    • Privilege Escalation
    • Defense Evasion
    • Credential Access
    • Discovery
    • Lateral Movement
    • Collection
    • Command and Control
    • Exfiltration
    • Impact
  • SOC Related
    • Cached Credentials
    • Domain Controller Password Spraying
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. Windows Artifactschevron-right
  2. Event IDs

Authentication / Account

4624 - Authentication Successchevron-right4625 - Authentication Failurechevron-right4634 - Account Logoffchevron-right4648 - Explicit Credentials Successchevron-right4672 - Special Privilegeschevron-right4720 - Account Creationchevron-right4722 - Account Enabledchevron-right4732 - Addition to Local Groupchevron-right4738 - Account Changedchevron-right4776 - Kerberos Authentication Attemptchevron-right4771 - Kerberos Failurechevron-right4768chevron-right
PreviousEvent IDschevron-leftNext4624 - Authentication Successchevron-right

Last updated 1 year ago