Active Directory security event IDs: a DC reference
Every AD security event ID worth collecting on domain controllers: logon, Kerberos, NTLM, account, group, directory and AD CS events, with fields to hunt.
The Security log on a domain controller can record a few hundred distinct event IDs. Maybe forty of them tell you something useful about an Active Directory attack, and a much smaller number tell you what happened when read on their own. This reference lists the events that matter on DCs and AD CS servers. For each one it gives the audit subcategory that produces it, what it records, and the fields to filter on when hunting.
The auditing and detection pillar guide covers enabling Advanced Audit Policy and SACLs. This page assumes that work is done and focuses on reading the output. All subcategories live under Computer Configuration > Policies > Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies.
How to read this reference
Three rules save time:
- Where the event is logged matters. Kerberos (4768, 4769, 4771) and NTLM validation (4776) for domain accounts are logged on the DC that handled the request. Logon events (4624, 4625) are logged on the machine the user logged on to. A logon to a file server produces 4769 on a DC and 4624 on the file server.
- Nothing is logged unless the subcategory is enabled. Directory events also need a SACL on the object.
- Filter on fields, not on message text. Event messages are localized and change over time, but the XML field names (
TargetUserName,TicketEncryptionType,Status) are stable.
Querying by ID and field on a DC:
# Last 50 failed Kerberos pre-authentications on this DC
Get-WinEvent -FilterHashtable @{ LogName = 'Security'; Id = 4771 } -MaxEvents 50 |
ForEach-Object {
$x = [xml]$_.ToXml()
[pscustomobject]@{
Time = $_.TimeCreated
Account = ($x.Event.EventData.Data | Where-Object Name -eq 'TargetUserName').'#text'
Client = ($x.Event.EventData.Data | Where-Object Name -eq 'IpAddress').'#text'
Code = ($x.Event.EventData.Data | Where-Object Name -eq 'Status').'#text'
}
}Logon and session events
Subcategories: Logon/Logoff > Audit Logon, Audit Special Logon, Audit Logoff, Audit Other Logon/Logoff Events.
| Event ID | Records | What to hunt |
|---|---|---|
| 4624 | Successful logon | LogonType, IpAddress, AuthenticationPackageName, LogonProcessName. Privileged accounts logging on to non-Tier 0 hosts. |
| 4625 | Failed logon | Status / SubStatus codes (see below). Many accounts failing from one source points to spraying. |
| 4634 / 4647 | Logoff / user-initiated logoff | Session duration. Low value on its own. |
| 4648 | Logon with explicit credentials | runas, scheduled tasks, and tools that pass alternate credentials. Admin credentials typed on workstations. |
| 4672 | Special privileges assigned to new logon | Identifies admin-equivalent sessions. Correlate its SubjectLogonId with the TargetLogonId of the matching 4624. |
| 4964 | Special groups assigned to a new logon | Only fires for groups you configure in the SpecialGroups registry value. A cheap way to flag Tier 0 group logons. |
Logon types you will filter on: 2 interactive, 3 network, 4 batch, 5 service, 7 unlock, 8 network cleartext, 9 NewCredentials (runas /netonly, also produced by some credential-injection tools), 10 RemoteInteractive (RDP), 11 cached interactive.
Common 4625 sub-status codes:
| Code | Meaning |
|---|---|
| 0xC0000064 | User name does not exist |
| 0xC000006A | Correct user, wrong password |
| 0xC0000234 | Account locked out |
| 0xC0000072 | Account disabled |
| 0xC000006F | Logon outside allowed hours |
| 0xC0000070 | Workstation restriction |
| 0xC0000071 | Password expired |
| 0xC0000193 | Account expired |
| 0xC000015B | Logon type not granted (user rights assignment) |
A burst of 0xC000015B for Tier 0 accounts on workstations is often your tiering deny-logon rights working as intended, and it is worth trending.
Kerberos events
Subcategories: Account Logon > Audit Kerberos Authentication Service (4768, 4771, 4772) and Audit Kerberos Service Ticket Operations (4769, 4770, 4773).
| Event ID | Records | What to hunt |
|---|---|---|
| 4768 | TGT requested (AS-REQ) | PreAuthType 0 means no pre-authentication, so the account is AS-REP roastable. TicketEncryptionType 0x17 means RC4. Status 0x6 means the account is unknown (user enumeration). |
| 4769 | Service ticket requested (TGS-REQ) | TicketEncryptionType 0x17 for user-account SPNs. One account requesting many distinct ServiceName values quickly points to Kerberoasting. |
| 4770 | Service ticket renewed | Low value. Useful for session timelines. |
| 4771 | Pre-authentication failed | Status 0x18 is a bad password, 0x12 is disabled, expired or locked, 0x25 is clock skew. |
| 4772 / 4773 | TGT / service ticket request failed | Rarely seen. Investigate spikes. |
Encryption type values: 0x11 AES128, 0x12 AES256, 0x17 RC4-HMAC, 0x18 RC4-HMAC-EXP, 0x1 / 0x3 DES (should never appear). Tracking 0x17 in 4768 and 4769 is how you measure progress toward disabling RC4. Newer builds add fields such as the account's available keys and the session key encryption type. They make that measurement much easier, so update your parsers to use them.
A failed 4769 with Status 0x1F (integrity check on decrypted field failed) can point to forged or tampered tickets. Expect false positives from clock and trust issues, so treat these as leads to investigate, not verdicts.
NTLM events
Subcategory: Account Logon > Audit Credential Validation.
| Event ID | Records | What to hunt |
|---|---|---|
| 4776 | DC attempted to validate an account's credentials (NTLM) | Status 0xC000006A bad password, 0xC0000064 unknown user. Workstation field shows the claimed client name. Volume of NTLM by privileged accounts. |
| 4774 / 4775 | Account mapped / could not be mapped for logon | Rare. Investigate if present. |
For NTLM usage by protocol version and target server, enable Network security: Restrict NTLM: Audit NTLM authentication in this domain and read the Microsoft-Windows-NTLM/Operational log (8001 to 8004). That process is covered in auditing and restricting NTLM.
Account management events
Subcategories: Account Management > Audit User Account Management, Audit Computer Account Management, Audit Security Group Management.
Users
| Event ID | Records | What to hunt |
|---|---|---|
| 4720 | User account created | Accounts created outside your provisioning workflow or by unexpected admins. |
| 4722 / 4725 | Account enabled / disabled | Dormant accounts re-enabled. |
| 4723 / 4724 | Password change / reset attempt | 4724 performed by a non-helpdesk principal on a privileged account. |
| 4726 | Account deleted | Cleanup of evidence. |
| 4738 | User account changed | UserAccountControl changes (for example "Don't require preauth" or "Trusted for delegation"), SidHistory, AllowedToDelegateTo. |
| 4740 | Account locked out | Logged on the PDC emulator. CallerComputerName gives the source. |
| 4765 / 4766 | SID History added / add failed | Outside a migration, any 4765 is critical. See SID History cleanup. |
| 4780 | ACL set on accounts that are members of administrators groups | SDProp activity. See AdminSDHolder and SDProp. |
| 4794 | Attempt to set the DSRM administrator password | Should match change tickets. |
Groups
| Event ID | Records | Scope |
|---|---|---|
| 4727 / 4730 / 4737 | Security group created / deleted / changed | Global |
| 4728 / 4729 | Member added / removed | Global (Domain Admins) |
| 4731 / 4734 / 4735 | Security group created / deleted / changed | Domain local |
| 4732 / 4733 | Member added / removed | Domain local (Administrators, Backup Operators) |
| 4754 / 4758 / 4755 | Security group created / deleted / changed | Universal |
| 4756 / 4757 | Member added / removed | Universal (Enterprise Admins, Schema Admins) |
| 4764 | Group type changed | Distribution to security conversions |
| 4799 | Local group membership enumerated | Reconnaissance against built-in groups |
Alert in real time on 4728, 4732 and 4756 where the target is any Tier 0 group. Filter on TargetSid rather than name, so renamed or localized groups are still matched.
Computers
| Event ID | Records | What to hunt |
|---|---|---|
| 4741 | Computer account created | Creations by non-admin users (the machine account quota at work). |
| 4742 | Computer account changed | ServicePrincipalNames, UserAccountControl delegation flags, DNS host name changes. |
| 4743 | Computer account deleted | Unexpected deletions. |
Directory service events
Subcategories: DS Access > Audit Directory Service Access (4662) and Audit Directory Service Changes (5136 to 5141). SACLs required.
| Event ID | Records | What to hunt |
|---|---|---|
| 4662 | Operation performed on an object | Properties containing 1131f6aa-9c07-11d1-f79f-00c04fc2dcd2 or 1131f6ad-9c07-11d1-f79f-00c04fc2dcd2 from a non-DC is DCSync. Also reads of decoy objects. |
| 5136 | Object modified | AttributeLDAPDisplayName such as member, nTSecurityDescriptor, gPLink, msDS-AllowedToActOnBehalfOfOtherIdentity, msDS-KeyCredentialLink, servicePrincipalName. |
| 5137 | Object created | New objects in Tier 0 OUs, new GPOs (groupPolicyContainer). |
| 5138 | Object undeleted | Reanimation of previously privileged accounts. |
| 5139 | Object moved | Accounts moved out of OUs covered by your GPOs or SACLs. |
| 5141 | Object deleted | Deleted GPOs, OUs or users. |
5136 logs one event per attribute value added or removed, with OperationType %%14674 (value added) or %%14675 (value deleted). A single ACL change produces a delete event for the old descriptor and an add event for the new one. Correlate the pair on OpCorrelationID.
Useful events outside the Security log:
- Directory Service log 2889: LDAP binds without signing. See LDAP signing and channel binding.
- Directory Service log 2089: partition not backed up within the backup latency interval.
- System log 7045: new service installed on a DC.
Policy, trust and system integrity events
| Event ID | Subcategory | Records |
|---|---|---|
| 4719 | Audit Audit Policy Change | System audit policy changed |
| 1102 | (always logged) | Security log cleared |
| 4713 | Audit Authentication Policy Change | Kerberos policy changed |
| 4739 | Audit Authentication Policy Change | Domain policy changed (password or lockout) |
| 4706 / 4707 | Audit Authentication Policy Change | Trust to a domain created / removed |
| 4716 | Audit Authentication Policy Change | Trusted domain information modified (SID filtering, attributes) |
| 4697 | Audit Security System Extension | Service installed |
| 4698 / 4702 | Audit Other Object Access Events | Scheduled task created / updated |
| 4688 | Audit Process Creation | Process created (enable command line capture) |
| 5145 | Audit Detailed File Share | Access to SYSVOL and NETLOGON files |
Treat 1102, 4719 and any 4706 as page-someone events on DCs. Legitimate occurrences are rare and should always match a change ticket.
AD CS events
Subcategory: Object Access > Audit Certification Services. The CA also needs its own audit filter, which you set on the CA server:
certutil -setreg CA\AuditFilter 127
Restart-Service certsvc| Event ID | Records | What to hunt |
|---|---|---|
| 4886 | Certificate request received | Volume per requester. |
| 4887 | Certificate request approved and issued | Requester differing from the subject name or SAN in the issued certificate (ESC1 abuse). |
| 4888 | Request denied | Probing of templates. |
| 4898 / 4899 / 4900 | Template loaded / updated / template security updated | Template edits outside change control. |
| 4882 | CA security permissions changed | Changes to CA ACLs. |
On DCs, the System log events 39, 40 and 41 (Kerberos-Key-Distribution-Center) report weak certificate mappings. They are covered in strong certificate mapping. The wider template picture is in AD CS hardening.
Pitfalls
- Volume surprises. 4624 type 3, 4634, 4769 and 4662 dominate DC log volume. Forward them anyway, but set Security log sizes large enough (several GB on busy DCs) that local logs cover at least a few days if the forwarding pipeline stalls.
- 4771 versus 4625 confusion. Kerberos failures do not produce 4625 on the DC. A spraying detection built only on 4625 misses most domain-wide attacks.
- Localized names. Group names in events are localized on non-English DCs. Match on SIDs: well-known domain RIDs (512 Domain Admins, 519 Enterprise Admins, 518 Schema Admins) and the builtin SID
S-1-5-32-544(Administrators), which has no domain prefix. - Mixed audit policy. If legacy category settings are applied alongside Advanced Audit Policy without Audit: Force audit policy subcategory settings enabled, events silently stop.
- SACL scope creep. A SACL for Everyone reading all properties on the domain root will flood the log. Scope read auditing to decoys and write auditing to Tier 0 objects.
- Clock skew. Correlating 4768 on one DC with 4624 on a server only works if time sync is healthy across the domain.
Related reading: get these events off the DCs with Windows Event Forwarding, turn a handful of them into near-zero-false-positive alerts with honeytokens, and browse the rest of the auditing, logging and detection area.
Frequently asked questions
Why do I not see event 4662 or 5136 even though auditing is enabled?
Both events need two things: the Directory Service Access or Directory Service Changes subcategory enabled on the domain controllers, and a SACL on the object being accessed or modified. Audit policy alone decides which categories are logged; the SACL decides which objects and operations generate events. If either is missing you get nothing. Check the effective policy with auditpol /get /category:* and the object's Auditing tab or its Get-Acl Audit property.
Which log records a failed Kerberos logon with a wrong password?
The domain controller that handled the request logs event 4771 with failure code 0x18 when Kerberos pre-authentication fails because of a bad password. NTLM failures appear instead as event 4776 with error 0xC000006A. The workstation or server where the user tried to log on records 4625 locally. To see password spraying across the domain you need the 4771 and 4776 events from every DC, not just the PDC emulator.
Are event IDs the same on Windows Server 2016, 2019, 2022 and 2025?
The IDs and their meaning are stable across these versions, which is why SIEM content written years ago still works. What changes is the set of fields inside some events. Recent cumulative updates added fields to Kerberos events 4768 and 4769, such as the account's available keys and the session key encryption type, to help find RC4 usage. Parse events by field name rather than position so new fields do not break detections.
Active Directory security event IDs: a DC reference