<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there a good list of Windows Event IDs pertaining to security out there? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-good-list-of-Windows-Event-IDs-pertaining-to-security/m-p/92759#M19285</link>
    <description>&lt;P&gt;While it hasn't been updated since 2013 there haven't been too many changes to the Windows event logs to make it significant enough to be outdated but this NSA document does help a lot: (Page 8 for Overall list; Page 24-34 for in depth info in each category)&lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.nsa.gov/ia/_files/app/spotting_the_adversary_with_windows_event_log_monitoring.pdf"&gt;https://www.nsa.gov/ia/_files/app/spotting_the_adversary_with_windows_event_log_monitoring.pdf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Then with the various types of Logon Types for a login event; e.g. Logon Type 7 is Unlock, 10 Interactive, etc...  Try this SANS white paper:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.sans.org/reading-room/whitepapers/forensics/windows-logon-forensics-34132"&gt;https://www.sans.org/reading-room/whitepapers/forensics/windows-logon-forensics-34132&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 26 Apr 2016 01:41:22 GMT</pubDate>
    <dc:creator>lmaclean</dc:creator>
    <dc:date>2016-04-26T01:41:22Z</dc:date>
    <item>
      <title>Is there a good list of Windows Event IDs pertaining to security out there?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-good-list-of-Windows-Event-IDs-pertaining-to-security/m-p/92755#M19281</link>
      <description>&lt;P&gt;I am looking to create searches that follow a "User \ Group" lifecycle, and want to know if anyone has a good list of Windows Security Event IDs.  I want to create searches for:&lt;/P&gt;

&lt;P&gt;New User Created&lt;BR /&gt;
New Group Created&lt;BR /&gt;
User Added to Group&lt;BR /&gt;
User Deleted from Group&lt;BR /&gt;
Share Rights Assigned to Group&lt;BR /&gt;
Share Rights Assigned to User&lt;BR /&gt;
User Deleted&lt;BR /&gt;
Group Deleted&lt;BR /&gt;
User Locked Out&lt;BR /&gt;
User Unlocked&lt;/P&gt;

&lt;P&gt;etc.&lt;/P&gt;

&lt;P&gt;I was hoping there was a good list to start with somewhere, the Splunk for Windows has a few, but it is very light.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Apr 2011 23:14:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-good-list-of-Windows-Event-IDs-pertaining-to-security/m-p/92755#M19281</guid>
      <dc:creator>kgriffen</dc:creator>
      <dc:date>2011-04-29T23:14:50Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a good list of Windows Event IDs pertaining to security out there?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-good-list-of-Windows-Event-IDs-pertaining-to-security/m-p/92756#M19282</link>
      <description>&lt;P&gt;This one seems pretty comprehensive: &lt;A href="http://www.ultimatewindowssecurity.com/securitylog/encyclopedia/Default.aspx"&gt;http://www.ultimatewindowssecurity.com/securitylog/encyclopedia/Default.aspx&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Apr 2011 00:11:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-good-list-of-Windows-Event-IDs-pertaining-to-security/m-p/92756#M19282</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2011-04-30T00:11:32Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a good list of Windows Event IDs pertaining to security out there?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-good-list-of-Windows-Event-IDs-pertaining-to-security/m-p/92757#M19283</link>
      <description>&lt;P&gt;You could install the Windows Event Codes Lookup app to have all your event codes in your Windows Security Logs looked up into a human readable format automatically:&lt;BR /&gt;
&lt;A href="http://splunk-base.splunk.com/apps/22357/windows-event-codes-lookup"&gt;Windows Event Code Lookup App&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2011 13:38:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-good-list-of-Windows-Event-IDs-pertaining-to-security/m-p/92757#M19283</guid>
      <dc:creator>ftk</dc:creator>
      <dc:date>2011-08-11T13:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a good list of Windows Event IDs pertaining to security out there?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-good-list-of-Windows-Event-IDs-pertaining-to-security/m-p/92758#M19284</link>
      <description>&lt;P&gt;I've got two lists for you, one is legible and the other is off Microsoft's site.&lt;BR /&gt;
From WindowsITPro&lt;BR /&gt;
&lt;A href="http://www.windowsitpro.com/article/reporting2/where-are-the-security-event-id-s-listed-"&gt;http://www.windowsitpro.com/article/reporting2/where-are-the-security-event-id-s-listed-&lt;/A&gt;&lt;BR /&gt;
From Microsoft&lt;BR /&gt;
&lt;A href="http://support.microsoft.com/kb/174074"&gt;http://support.microsoft.com/kb/174074&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;The IT Pro link was drafted from Microsoft's page, but they cleaned it up a bit. Hope it helps&lt;/P&gt;</description>
      <pubDate>Tue, 02 Oct 2012 17:38:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-good-list-of-Windows-Event-IDs-pertaining-to-security/m-p/92758#M19284</guid>
      <dc:creator>jcaffero</dc:creator>
      <dc:date>2012-10-02T17:38:30Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a good list of Windows Event IDs pertaining to security out there?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-good-list-of-Windows-Event-IDs-pertaining-to-security/m-p/92759#M19285</link>
      <description>&lt;P&gt;While it hasn't been updated since 2013 there haven't been too many changes to the Windows event logs to make it significant enough to be outdated but this NSA document does help a lot: (Page 8 for Overall list; Page 24-34 for in depth info in each category)&lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.nsa.gov/ia/_files/app/spotting_the_adversary_with_windows_event_log_monitoring.pdf"&gt;https://www.nsa.gov/ia/_files/app/spotting_the_adversary_with_windows_event_log_monitoring.pdf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Then with the various types of Logon Types for a login event; e.g. Logon Type 7 is Unlock, 10 Interactive, etc...  Try this SANS white paper:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.sans.org/reading-room/whitepapers/forensics/windows-logon-forensics-34132"&gt;https://www.sans.org/reading-room/whitepapers/forensics/windows-logon-forensics-34132&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2016 01:41:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-good-list-of-Windows-Event-IDs-pertaining-to-security/m-p/92759#M19285</guid>
      <dc:creator>lmaclean</dc:creator>
      <dc:date>2016-04-26T01:41:22Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a good list of Windows Event IDs pertaining to security out there?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-good-list-of-Windows-Event-IDs-pertaining-to-security/m-p/92760#M19286</link>
      <description>&lt;P&gt;Check out the &lt;STRONG&gt;Windows Security Operations Center&lt;/STRONG&gt; app in the Splunk store.  There are several pre-built panels and you can check the queries you the Event Codes that are monitored to generate them.   This app also may help you from having to "reinvent the wheel."&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2016 18:43:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-good-list-of-Windows-Event-IDs-pertaining-to-security/m-p/92760#M19286</guid>
      <dc:creator>jd0323fhl</dc:creator>
      <dc:date>2016-09-30T18:43:54Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a good list of Windows Event IDs pertaining to security out there?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-good-list-of-Windows-Event-IDs-pertaining-to-security/m-p/92761#M19287</link>
      <description>&lt;P&gt;One of the 2015 conference discussions was &lt;A href="https://conf.splunk.com/session/2015/conf2015_MGough_MalwareArchaelogy_SecurityCompliance_FindingAdvnacedAttacksAnd.pdf"&gt;Finding Advanced Attacks and Malware With Only 6 Windows EventID’s&lt;/A&gt;&lt;BR /&gt;
This presenter provides &lt;A href="http://www.malwarearchaeology.com/cheat-sheets/"&gt;cheat sheets&lt;/A&gt; and here is the &lt;A href="https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/56b36b4d3c44d86cf33341ca/1454598990744/Windows+Splunk+Logging+Cheat+Sheet+v1.1.pdf"&gt;Splunk specific windows cheat sheet&lt;/A&gt; (at the time of writing this was updated in Feb 2016, refer to the cheat sheets link for the main page)&lt;/P&gt;</description>
      <pubDate>Sat, 01 Oct 2016 06:21:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-good-list-of-Windows-Event-IDs-pertaining-to-security/m-p/92761#M19287</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2016-10-01T06:21:43Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a good list of Windows Event IDs pertaining to security out there?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-good-list-of-Windows-Event-IDs-pertaining-to-security/m-p/92762#M19288</link>
      <description>&lt;P&gt;This Quick Reference Cheat Sheet is quite useful. Posting for Reference&lt;BR /&gt;
&lt;A href="https://www.ultimatewindowssecurity.com/securitylog/quickref/downloads/quickref.zip"&gt;https://www.ultimatewindowssecurity.com/securitylog/quickref/downloads/quickref.zip&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Apr 2017 06:19:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-good-list-of-Windows-Event-IDs-pertaining-to-security/m-p/92762#M19288</guid>
      <dc:creator>ssadh</dc:creator>
      <dc:date>2017-04-13T06:19:26Z</dc:date>
    </item>
  </channel>
</rss>

