Windows Security & Sysmon event reference
Look up any Windows Security or Sysmon event ID.
Definitions, trigger scenarios, key fields, false positives, related events, and SIEM starter queries, sourced and reviewed.
Windows EventsSecurity log event IDsSysmon EventsSysmon operational log eventsToolsTimestamp, Sigma, CVSS
- Indexed IDs
- 108
- Full guides
- 108
- Sources
- 2
- Official-source first
- Every full page is built around source links, review dates, and explicit version context.
- Machine-readable by design
- Schema-backed JSON, JSON-LD, stable canonical URLs, and predictable routing.
- Detection oriented
- Entries include KQL, SPL, key fields, false positives, and related event pivots.