Skip to content

Instantly share code, notes, and snippets.

@philiprobinson95
Created March 12, 2020 11:56
Show Gist options
  • Save philiprobinson95/2dad038ab295b957eed1cea9d0aaeac8 to your computer and use it in GitHub Desktop.
Save philiprobinson95/2dad038ab295b957eed1cea9d0aaeac8 to your computer and use it in GitHub Desktop.
Event IDs Table
Event Code Description To find (Tactic: Technique)
4624 (4672) Successful logon (Administrator logon) Credential access: Valid accounts
4625 Unsuccessful logon Credential access: Brute force
4732 Member added to security-enabled group Privilege Escalation: Account manipulation
1102 Logs cleared Defense evasion: Indicator removal on host
4688 Process creation Execution: Command-Line Interference
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment