← Defense and SOC UniCybers Labs
Defense and SOC

Windows Event ID Reference

The Windows Event IDs that matter most for detection and incident response, with what each one means and which ones to watch.

About

Common event IDs grouped by purpose, from logons and account changes to process creation, service installs and PowerShell script block logging. Search by ID or meaning and copy the ID into your SIEM.

Descriptions are summaries. Exact fields and behaviour vary by Windows version and audit policy, and PowerShell, Defender and Sysmon events only appear when those features are enabled. Confirm specifics against Microsoft documentation.

UniCybers Labs ยท Defense and SOC Back to Defense and SOC tools