Windows Security Log Events
All Sources
Windows Audit
SharePoint Audit
(
LOGbinder for SharePoint
)
SQL Server Audit
(
LOGbinder for SQL Server
)
Exchange Audit
(
LOGbinder for Exchange
)
Sysmon
(
MS Sysinternals Sysmon
)
Windows Audit Categories:
All categories
Account Logon
Account Management
Directory Service
Logon/Logoff
Non Audit (Event Log)
Object Access
Policy Change
Privilege Use
Process Tracking
System
Uncategorized
Subcategories:
All subcategories
Application Generated
Central Policy Staging
Certification Services
Detailed File Share
File Share
File System
Filtering Platform Connection
Filtering Platform Packet Drop
Handle Manipulation
Kernel Object
Other Object Access Events
Registry
SAM
Windows Versions:
All events
Win2000, XP and Win2003 only
Win2008, Win2012R2, Win2016 and Win10+, Win2019
Required when sub-category selected.
Category:
Object Access
Subcategory:
Other Object Access Events
Windows
4656
A handle to an object was requested
Windows
4658
The handle to an object was closed
Windows
4659
A handle to an object was requested with intent to delete
Windows
4660
An object was deleted
Windows
4663
An attempt was made to access an object
Windows
4671
An application attempted to access a blocked ordinal through the TBS
Windows
4691
Indirect access to an object was requested
Windows
4698
A scheduled task was created
Windows
4699
A scheduled task was deleted
Windows
4700
A scheduled task was enabled
Windows
4701
A scheduled task was disabled
Windows
4702
A scheduled task was updated
Windows
5148
The Windows Filtering Platform has detected a DoS attack and entered a defensive mode; packets associated with this attack will be discarded.
Windows
5149
The DoS attack has subsided and normal processing is being resumed.
Windows
5888
An object in the COM+ Catalog was modified
Windows
5889
An object was deleted from the COM+ Catalog
Stay up-to-date on the Latest in Cybersecurity
Sign up for the Ultimate IT Security newsletter to hear about the latest webinars, patches, CVEs, attacks, and more.
Work Email:
Upcoming Webinars
Windows Event Forwarding: 4 Silent Killers that Stop the Flow of Events without You Knowing
Additional Resources
Encyclopedia
•
Event IDs
•
All Event IDs
•
Audit Policy
Go To Event ID:
Security Log
Quick Reference
Chart
Download now!
Tweet
User name:
Password:
/
Forgot?
Register
March 2026
Patch Tuesday
"Patch Tuesday - Two Zero-Days for the Month " - sponsored by LOGbinder
Home
Cookies help us deliver the best experience on our website. By using our website, you agree to the use of cookies.