Real-World Attack Examples Using Windows Event IDs

1. Event ID 4625 – Failed Logon (Brute-Force Attack)

Scenario: Password Spraying via RDP

What happens:

  • Attacker targets exposed RDP
  • Tries one password against many users

Logs observed:

  • Many 4625 events
  • Same source IP
  • Status: 0xC000006A (bad password)

Red flags:

  • Multiple usernames
  • Same password pattern
  • Short time window

Real case:
Seen frequently in ransomware attacks (e.g., LockBit) before initial access.


2. Event ID 4624 – Successful Logon (Compromised Account)

Scenario: Attacker Gains Valid Credentials

What happens:

  • After brute force or phishing, attacker logs in

Logs observed:

  • 4624
  • Logon Type 10 (RDP)
  • Source IP from foreign country or VPN

Red flags:

  • Login outside business hours
  • New geographic location
  • Followed by admin activity

3. Event ID 4672 – Special Privileges Assigned (Privilege Escalation)

Scenario: Attacker Becomes Administrator

What happens:

  • Attacker adds account to Administrators group
  • Logs in again

Logs observed:

  • 4672 immediately after 4624
  • Privileges like SeDebugPrivilege

Red flags:

  • Non-admin user suddenly gets admin rights
  • Followed by service or process creation

4. Event ID 4688 – Process Creation (Malware Execution)

Scenario: Living-Off-the-Land (LOLBins)

What happens:

  • Attacker runs built-in tools to avoid detection

Logs observed:

  • 4688
  • Suspicious commands:
    • powershell -enc ...
    • cmd.exe /c whoami
    • rundll32.exe

Real malware:
Emotet, TrickBot, Cobalt Strike

Red flags:

  • Encoded PowerShell
  • Unusual parent processes (Word → PowerShell)

5. Event ID 4697 – Service Installed (Persistence)

Scenario: Malware Installs as a Service

What happens:

  • Attacker ensures malware runs on reboot

Logs observed:

  • 4697
  • Service path pointing to temp or user directory

Red flags:

  • Service names mimicking Windows
  • Non-system paths

Real example:
Ryuk ransomware installs backdoor services.


6. Event ID 4648 – Logon with Explicit Credentials (Lateral Movement)

Scenario: Pass-the-Hash / RunAs

What happens:

  • Attacker uses stolen credentials to access another system

Logs observed:

  • 4648
  • One user authenticates as another

Red flags:

  • Helpdesk or service accounts used interactively
  • Happens after privilege escalation

Common tools:
PsExec, WMIC, Cobalt Strike


7. Event ID 4719 – Audit Policy Changed (Defense Evasion)

Scenario: Attacker Disables Logging

What happens:

  • Attacker tries to hide their tracks

Logs observed:

  • 4719
  • Audit policies set to “No Auditing”

Red flags:

  • Logging disabled shortly after admin login
  • Followed by gaps in logs

Real attacks:
APT groups often disable auditing early.


8. Event ID 4720 – New User Account Created (Persistence Backdoor)

Scenario: Hidden Admin Account

What happens:

  • Attacker creates a new account
  • Adds it to Administrators

Logs observed:

  • 4720
  • Followed by group modification events

Red flags:

  • Account created outside change window
  • Generic names (backupadmin, sys_support)

9. Event ID 4740 – Account Lockout (Attack Detection)

Scenario: Aggressive Brute Force

What happens:

  • Attacker keeps guessing passwords

Logs observed:

  • 4740
  • Multiple lockouts across users

Red flags:

  • Same source computer
  • Service accounts locking out

10. Event ID 4634 – Logoff (Covering Tracks)

Scenario: Attacker Ends Session Quickly

What happens:

  • Attacker finishes actions
  • Logs off to avoid attention

Logs observed:

  • 4634
  • Short session duration

Red flags:

  • Logon → admin → malware → logoff in minutes

🔗 Full Attack Kill Chain Using Event IDs

Attack StageEvent IDs
Initial Access4625 → 4624
Privilege Escalation4672
Execution4688
Persistence4697, 4720
Lateral Movement4648
Defense Evasion4719
Impact4634, 4740

🛡️ SOC Detection Tip

High-confidence compromise alert:

4624 (Logon)
→ 4672 (Admin Privileges)
→ 4688 (PowerShell)
→ 4697 (Service Installed)
within 10 minutes