Skip to content

Active Directory security event IDs: a DC reference

Every AD security event ID worth collecting on domain controllers: logon, Kerberos, NTLM, account, group, directory and AD CS events, with fields to hunt.

Florian Amette11 min read

The Security log on a domain controller can record a few hundred distinct event IDs. Maybe forty of them tell you something useful about an Active Directory attack, and a much smaller number tell you what happened when read on their own. This reference lists the events that matter on DCs and AD CS servers. For each one it gives the audit subcategory that produces it, what it records, and the fields to filter on when hunting.

The auditing and detection pillar guide covers enabling Advanced Audit Policy and SACLs. This page assumes that work is done and focuses on reading the output. All subcategories live under Computer Configuration > Policies > Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies.

How to read this reference

Three rules save time:

  • Where the event is logged matters. Kerberos (4768, 4769, 4771) and NTLM validation (4776) for domain accounts are logged on the DC that handled the request. Logon events (4624, 4625) are logged on the machine the user logged on to. A logon to a file server produces 4769 on a DC and 4624 on the file server.
  • Nothing is logged unless the subcategory is enabled. Directory events also need a SACL on the object.
  • Filter on fields, not on message text. Event messages are localized and change over time, but the XML field names (TargetUserName, TicketEncryptionType, Status) are stable.

Querying by ID and field on a DC:

PowerShell
# Last 50 failed Kerberos pre-authentications on this DC
Get-WinEvent -FilterHashtable @{ LogName = 'Security'; Id = 4771 } -MaxEvents 50 |
  ForEach-Object {
    $x = [xml]$_.ToXml()
    [pscustomobject]@{
      Time    = $_.TimeCreated
      Account = ($x.Event.EventData.Data | Where-Object Name -eq 'TargetUserName').'#text'
      Client  = ($x.Event.EventData.Data | Where-Object Name -eq 'IpAddress').'#text'
      Code    = ($x.Event.EventData.Data | Where-Object Name -eq 'Status').'#text'
    }
  }

Logon and session events

Subcategories: Logon/Logoff > Audit Logon, Audit Special Logon, Audit Logoff, Audit Other Logon/Logoff Events.

Event IDRecordsWhat to hunt
4624Successful logonLogonType, IpAddress, AuthenticationPackageName, LogonProcessName. Privileged accounts logging on to non-Tier 0 hosts.
4625Failed logonStatus / SubStatus codes (see below). Many accounts failing from one source points to spraying.
4634 / 4647Logoff / user-initiated logoffSession duration. Low value on its own.
4648Logon with explicit credentialsrunas, scheduled tasks, and tools that pass alternate credentials. Admin credentials typed on workstations.
4672Special privileges assigned to new logonIdentifies admin-equivalent sessions. Correlate its SubjectLogonId with the TargetLogonId of the matching 4624.
4964Special groups assigned to a new logonOnly fires for groups you configure in the SpecialGroups registry value. A cheap way to flag Tier 0 group logons.

Logon types you will filter on: 2 interactive, 3 network, 4 batch, 5 service, 7 unlock, 8 network cleartext, 9 NewCredentials (runas /netonly, also produced by some credential-injection tools), 10 RemoteInteractive (RDP), 11 cached interactive.

Common 4625 sub-status codes:

CodeMeaning
0xC0000064User name does not exist
0xC000006ACorrect user, wrong password
0xC0000234Account locked out
0xC0000072Account disabled
0xC000006FLogon outside allowed hours
0xC0000070Workstation restriction
0xC0000071Password expired
0xC0000193Account expired
0xC000015BLogon type not granted (user rights assignment)

A burst of 0xC000015B for Tier 0 accounts on workstations is often your tiering deny-logon rights working as intended, and it is worth trending.

Kerberos events

Subcategories: Account Logon > Audit Kerberos Authentication Service (4768, 4771, 4772) and Audit Kerberos Service Ticket Operations (4769, 4770, 4773).

Event IDRecordsWhat to hunt
4768TGT requested (AS-REQ)PreAuthType 0 means no pre-authentication, so the account is AS-REP roastable. TicketEncryptionType 0x17 means RC4. Status 0x6 means the account is unknown (user enumeration).
4769Service ticket requested (TGS-REQ)TicketEncryptionType 0x17 for user-account SPNs. One account requesting many distinct ServiceName values quickly points to Kerberoasting.
4770Service ticket renewedLow value. Useful for session timelines.
4771Pre-authentication failedStatus 0x18 is a bad password, 0x12 is disabled, expired or locked, 0x25 is clock skew.
4772 / 4773TGT / service ticket request failedRarely seen. Investigate spikes.

Encryption type values: 0x11 AES128, 0x12 AES256, 0x17 RC4-HMAC, 0x18 RC4-HMAC-EXP, 0x1 / 0x3 DES (should never appear). Tracking 0x17 in 4768 and 4769 is how you measure progress toward disabling RC4. Newer builds add fields such as the account's available keys and the session key encryption type. They make that measurement much easier, so update your parsers to use them.

A failed 4769 with Status 0x1F (integrity check on decrypted field failed) can point to forged or tampered tickets. Expect false positives from clock and trust issues, so treat these as leads to investigate, not verdicts.

NTLM events

Subcategory: Account Logon > Audit Credential Validation.

Event IDRecordsWhat to hunt
4776DC attempted to validate an account's credentials (NTLM)Status 0xC000006A bad password, 0xC0000064 unknown user. Workstation field shows the claimed client name. Volume of NTLM by privileged accounts.
4774 / 4775Account mapped / could not be mapped for logonRare. Investigate if present.

For NTLM usage by protocol version and target server, enable Network security: Restrict NTLM: Audit NTLM authentication in this domain and read the Microsoft-Windows-NTLM/Operational log (8001 to 8004). That process is covered in auditing and restricting NTLM.

Account management events

Subcategories: Account Management > Audit User Account Management, Audit Computer Account Management, Audit Security Group Management.

Users

Event IDRecordsWhat to hunt
4720User account createdAccounts created outside your provisioning workflow or by unexpected admins.
4722 / 4725Account enabled / disabledDormant accounts re-enabled.
4723 / 4724Password change / reset attempt4724 performed by a non-helpdesk principal on a privileged account.
4726Account deletedCleanup of evidence.
4738User account changedUserAccountControl changes (for example "Don't require preauth" or "Trusted for delegation"), SidHistory, AllowedToDelegateTo.
4740Account locked outLogged on the PDC emulator. CallerComputerName gives the source.
4765 / 4766SID History added / add failedOutside a migration, any 4765 is critical. See SID History cleanup.
4780ACL set on accounts that are members of administrators groupsSDProp activity. See AdminSDHolder and SDProp.
4794Attempt to set the DSRM administrator passwordShould match change tickets.

Groups

Event IDRecordsScope
4727 / 4730 / 4737Security group created / deleted / changedGlobal
4728 / 4729Member added / removedGlobal (Domain Admins)
4731 / 4734 / 4735Security group created / deleted / changedDomain local
4732 / 4733Member added / removedDomain local (Administrators, Backup Operators)
4754 / 4758 / 4755Security group created / deleted / changedUniversal
4756 / 4757Member added / removedUniversal (Enterprise Admins, Schema Admins)
4764Group type changedDistribution to security conversions
4799Local group membership enumeratedReconnaissance against built-in groups

Alert in real time on 4728, 4732 and 4756 where the target is any Tier 0 group. Filter on TargetSid rather than name, so renamed or localized groups are still matched.

Computers

Event IDRecordsWhat to hunt
4741Computer account createdCreations by non-admin users (the machine account quota at work).
4742Computer account changedServicePrincipalNames, UserAccountControl delegation flags, DNS host name changes.
4743Computer account deletedUnexpected deletions.

Directory service events

Subcategories: DS Access > Audit Directory Service Access (4662) and Audit Directory Service Changes (5136 to 5141). SACLs required.

Event IDRecordsWhat to hunt
4662Operation performed on an objectProperties containing 1131f6aa-9c07-11d1-f79f-00c04fc2dcd2 or 1131f6ad-9c07-11d1-f79f-00c04fc2dcd2 from a non-DC is DCSync. Also reads of decoy objects.
5136Object modifiedAttributeLDAPDisplayName such as member, nTSecurityDescriptor, gPLink, msDS-AllowedToActOnBehalfOfOtherIdentity, msDS-KeyCredentialLink, servicePrincipalName.
5137Object createdNew objects in Tier 0 OUs, new GPOs (groupPolicyContainer).
5138Object undeletedReanimation of previously privileged accounts.
5139Object movedAccounts moved out of OUs covered by your GPOs or SACLs.
5141Object deletedDeleted GPOs, OUs or users.

5136 logs one event per attribute value added or removed, with OperationType %%14674 (value added) or %%14675 (value deleted). A single ACL change produces a delete event for the old descriptor and an add event for the new one. Correlate the pair on OpCorrelationID.

Useful events outside the Security log:

  • Directory Service log 2889: LDAP binds without signing. See LDAP signing and channel binding.
  • Directory Service log 2089: partition not backed up within the backup latency interval.
  • System log 7045: new service installed on a DC.

Policy, trust and system integrity events

Event IDSubcategoryRecords
4719Audit Audit Policy ChangeSystem audit policy changed
1102(always logged)Security log cleared
4713Audit Authentication Policy ChangeKerberos policy changed
4739Audit Authentication Policy ChangeDomain policy changed (password or lockout)
4706 / 4707Audit Authentication Policy ChangeTrust to a domain created / removed
4716Audit Authentication Policy ChangeTrusted domain information modified (SID filtering, attributes)
4697Audit Security System ExtensionService installed
4698 / 4702Audit Other Object Access EventsScheduled task created / updated
4688Audit Process CreationProcess created (enable command line capture)
5145Audit Detailed File ShareAccess to SYSVOL and NETLOGON files

Treat 1102, 4719 and any 4706 as page-someone events on DCs. Legitimate occurrences are rare and should always match a change ticket.

AD CS events

Subcategory: Object Access > Audit Certification Services. The CA also needs its own audit filter, which you set on the CA server:

PowerShell
certutil -setreg CA\AuditFilter 127
Restart-Service certsvc
Event IDRecordsWhat to hunt
4886Certificate request receivedVolume per requester.
4887Certificate request approved and issuedRequester differing from the subject name or SAN in the issued certificate (ESC1 abuse).
4888Request deniedProbing of templates.
4898 / 4899 / 4900Template loaded / updated / template security updatedTemplate edits outside change control.
4882CA security permissions changedChanges to CA ACLs.

On DCs, the System log events 39, 40 and 41 (Kerberos-Key-Distribution-Center) report weak certificate mappings. They are covered in strong certificate mapping. The wider template picture is in AD CS hardening.

Pitfalls

  • Volume surprises. 4624 type 3, 4634, 4769 and 4662 dominate DC log volume. Forward them anyway, but set Security log sizes large enough (several GB on busy DCs) that local logs cover at least a few days if the forwarding pipeline stalls.
  • 4771 versus 4625 confusion. Kerberos failures do not produce 4625 on the DC. A spraying detection built only on 4625 misses most domain-wide attacks.
  • Localized names. Group names in events are localized on non-English DCs. Match on SIDs: well-known domain RIDs (512 Domain Admins, 519 Enterprise Admins, 518 Schema Admins) and the builtin SID S-1-5-32-544 (Administrators), which has no domain prefix.
  • Mixed audit policy. If legacy category settings are applied alongside Advanced Audit Policy without Audit: Force audit policy subcategory settings enabled, events silently stop.
  • SACL scope creep. A SACL for Everyone reading all properties on the domain root will flood the log. Scope read auditing to decoys and write auditing to Tier 0 objects.
  • Clock skew. Correlating 4768 on one DC with 4624 on a server only works if time sync is healthy across the domain.

Related reading: get these events off the DCs with Windows Event Forwarding, turn a handful of them into near-zero-false-positive alerts with honeytokens, and browse the rest of the auditing, logging and detection area.

Frequently asked questions

Why do I not see event 4662 or 5136 even though auditing is enabled?

Both events need two things: the Directory Service Access or Directory Service Changes subcategory enabled on the domain controllers, and a SACL on the object being accessed or modified. Audit policy alone decides which categories are logged; the SACL decides which objects and operations generate events. If either is missing you get nothing. Check the effective policy with auditpol /get /category:* and the object's Auditing tab or its Get-Acl Audit property.

Which log records a failed Kerberos logon with a wrong password?

The domain controller that handled the request logs event 4771 with failure code 0x18 when Kerberos pre-authentication fails because of a bad password. NTLM failures appear instead as event 4776 with error 0xC000006A. The workstation or server where the user tried to log on records 4625 locally. To see password spraying across the domain you need the 4771 and 4776 events from every DC, not just the PDC emulator.

Are event IDs the same on Windows Server 2016, 2019, 2022 and 2025?

The IDs and their meaning are stable across these versions, which is why SIEM content written years ago still works. What changes is the set of fields inside some events. Recent cumulative updates added fields to Kerberos events 4768 and 4769, such as the account's available keys and the session key encryption type, to help find RC4 usage. Parse events by field name rather than position so new fields do not break detections.

Active Directory security event IDs: a DC reference

Related guides