🖥️
Windows DFIR
⌘Ctrlk
🖥️
Windows DFIR
  • Introduction
    • Windows Quick Tips
    • Account Usage
    • Browser Usage
    • Processes
    • Cloud Storage
    • Deleted File or File Knowledge
    • File Download
    • Folder/File Opening/Creation
    • Persistence
    • Physical Location
    • Program Execution
    • Shadow Copies
    • USB Usage
    • Windows Services
    • System Information
    • Event IDs
      • Security
        • Authentication / Account
          • 4624 - Authentication Success
          • 4625 - Authentication Failure
          • 4634 - Account Logoff
          • 4648 - Explicit Credentials Success
          • 4672 - Special Privileges
          • 4720 - Account Creation
          • 4722 - Account Enabled
          • 4732 - Addition to Local Group
          • 4738 - Account Changed
          • 4776 - Kerberos Authentication Attempt
          • 4771 - Kerberos Failure
          • 4768
        • File System
    • Initial Access
    • Execution
    • Persistence
    • Privilege Escalation
    • Defense Evasion
    • Credential Access
    • Discovery
    • Lateral Movement
    • Collection
    • Command and Control
    • Exfiltration
    • Impact
    • Cached Credentials
    • Domain Controller Password Spraying
Powered by GitBook
For the complete documentation index, see llms.txt. This page is also available as Markdown.
  1. Windows Artifacts
  2. Event IDs
  3. Security

Authentication / Account

4624 - Authentication Success4625 - Authentication Failure4634 - Account Logoff4648 - Explicit Credentials Success4672 - Special Privileges4720 - Account Creation4722 - Account Enabled4732 - Addition to Local Group4738 - Account Changed4776 - Kerberos Authentication Attempt4771 - Kerberos Failure4768
PreviousSecurityNext4624 - Authentication Success

Last updated 2 years ago