1. Event ID 4625 – Failed Logon (Brute-Force Attack)
Scenario: Password Spraying via RDP
What happens:
- Attacker targets exposed RDP
- Tries one password against many users
Logs observed:
- Many 4625 events
- Same source IP
- Status:
0xC000006A(bad password)
Red flags:
- Multiple usernames
- Same password pattern
- Short time window
Real case:
Seen frequently in ransomware attacks (e.g., LockBit) before initial access.
2. Event ID 4624 – Successful Logon (Compromised Account)
Scenario: Attacker Gains Valid Credentials
What happens:
- After brute force or phishing, attacker logs in
Logs observed:
- 4624
- Logon Type
10(RDP) - Source IP from foreign country or VPN
Red flags:
- Login outside business hours
- New geographic location
- Followed by admin activity
3. Event ID 4672 – Special Privileges Assigned (Privilege Escalation)
Scenario: Attacker Becomes Administrator
What happens:
- Attacker adds account to Administrators group
- Logs in again
Logs observed:
- 4672 immediately after 4624
- Privileges like
SeDebugPrivilege
Red flags:
- Non-admin user suddenly gets admin rights
- Followed by service or process creation
4. Event ID 4688 – Process Creation (Malware Execution)
Scenario: Living-Off-the-Land (LOLBins)
What happens:
- Attacker runs built-in tools to avoid detection
Logs observed:
- 4688
- Suspicious commands:
powershell -enc ...cmd.exe /c whoamirundll32.exe
Real malware:
Emotet, TrickBot, Cobalt Strike
Red flags:
- Encoded PowerShell
- Unusual parent processes (Word → PowerShell)
5. Event ID 4697 – Service Installed (Persistence)
Scenario: Malware Installs as a Service
What happens:
- Attacker ensures malware runs on reboot
Logs observed:
- 4697
- Service path pointing to temp or user directory
Red flags:
- Service names mimicking Windows
- Non-system paths
Real example:
Ryuk ransomware installs backdoor services.
6. Event ID 4648 – Logon with Explicit Credentials (Lateral Movement)
Scenario: Pass-the-Hash / RunAs
What happens:
- Attacker uses stolen credentials to access another system
Logs observed:
- 4648
- One user authenticates as another
Red flags:
- Helpdesk or service accounts used interactively
- Happens after privilege escalation
Common tools:
PsExec, WMIC, Cobalt Strike
7. Event ID 4719 – Audit Policy Changed (Defense Evasion)
Scenario: Attacker Disables Logging
What happens:
- Attacker tries to hide their tracks
Logs observed:
- 4719
- Audit policies set to “No Auditing”
Red flags:
- Logging disabled shortly after admin login
- Followed by gaps in logs
Real attacks:
APT groups often disable auditing early.
8. Event ID 4720 – New User Account Created (Persistence Backdoor)
Scenario: Hidden Admin Account
What happens:
- Attacker creates a new account
- Adds it to Administrators
Logs observed:
- 4720
- Followed by group modification events
Red flags:
- Account created outside change window
- Generic names (backupadmin, sys_support)
9. Event ID 4740 – Account Lockout (Attack Detection)
Scenario: Aggressive Brute Force
What happens:
- Attacker keeps guessing passwords
Logs observed:
- 4740
- Multiple lockouts across users
Red flags:
- Same source computer
- Service accounts locking out
10. Event ID 4634 – Logoff (Covering Tracks)
Scenario: Attacker Ends Session Quickly
What happens:
- Attacker finishes actions
- Logs off to avoid attention
Logs observed:
- 4634
- Short session duration
Red flags:
- Logon → admin → malware → logoff in minutes
🔗 Full Attack Kill Chain Using Event IDs
| Attack Stage | Event IDs |
|---|---|
| Initial Access | 4625 → 4624 |
| Privilege Escalation | 4672 |
| Execution | 4688 |
| Persistence | 4697, 4720 |
| Lateral Movement | 4648 |
| Defense Evasion | 4719 |
| Impact | 4634, 4740 |
🛡️ SOC Detection Tip
High-confidence compromise alert:
4624 (Logon)
→ 4672 (Admin Privileges)
→ 4688 (PowerShell)
→ 4697 (Service Installed)
within 10 minutes
