SOC Event Lookup

Windows Security & Sysmon event reference

Look up any Windows Security or Sysmon event ID.

Definitions, trigger scenarios, key fields, false positives, related events, and SIEM starter queries, sourced and reviewed.

Indexed IDs
108
Full guides
108
Sources
2
Official-source first
Every full page is built around source links, review dates, and explicit version context.
Machine-readable by design
Schema-backed JSON, JSON-LD, stable canonical URLs, and predictable routing.
Detection oriented
Entries include KQL, SPL, key fields, false positives, and related event pivots.