Skip to content

Instantly share code, notes, and snippets.

@philiprobinson95
philiprobinson95 / eventIDtable.csv
Created March 12, 2020 11:56
Event IDs Table
Event Code Description To find (Tactic: Technique)
4624 (4672) Successful logon (Administrator logon) Credential access: Valid accounts
4625 Unsuccessful logon Credential access: Brute force
4732 Member added to security-enabled group Privilege Escalation: Account manipulation
1102 Logs cleared Defense evasion: Indicator removal on host
4688 Process creation Execution: Command-Line Interference