Active › Module 8 › Lesson 1
Event IDs
Windows security Event IDs named for AD detection — 4769, 4624, 4662, 4776, 4728 literacy on $LAB_AD SIEM exercises.
Visual · t25_event_ids
Event IDs = named detection anchors. 4769 4624 4662. $LAB_AD. Original Cyberlium.
Opening
Blue team lives in the event log — know 4769 before you ever touch a Kerberoast tutorial on an unauthorized forest.
AD detection literacy names key Event IDs: 4769 (Kerberos service ticket requested — Kerberoast context), 4624/4625 (logon success/failure — PtH and spray context), 4662 (directory service object operation — DCSync/replication GUID context), 4776 (NTLM credential validation), 4728/4732 (group membership change), 5136 (directory object modified — RBCD/delegation edits). Analyst maps each ID to technique family and false-positive notes — not full Sigma rule coding unless brief assigns. Cyberlium exercises on YOUR $LAB_AD forwarded logs or instructor-provided synthetic samples — NOT tuning detections using stranger enterprise log exports, NOT disabling logging to 'reduce noise' on unauthorized systems. Ship event ID cheat sheet with technique link and one lab alert hypothesis per ID.
1. Core Event IDs
4769: TGS request — watch unusual encryption types and service names on $LAB_AD.
4662: replication GUIDs — DCSync detection anchor. 4624: logon type 3/10 chains for lateral movement literacy.
Command guide
Try these commands — Core Event IDs
═══ WINDOWS / POWERSHELL (Active Directory Lab) ═══
Check current user, domain context, and security privileges
Command — copy this
whoami /user /groups /priv
Query active Domain Controller and trust relationships
Command — copy this
nltest /dsgetdc:$env:USERDOMAIN nltest /domain_trusts
List password policy across the domain
Command — copy this
net accounts /domain
Check Kerberos ticket cache
Command — copy this
klist
═══ LINUX / BASH (Lab Network) ═══ Test DNS SRV resolution for Active Directory services
Command — copy this
dig _ldap._tcp.dc._msdcs.lab.local SRV +short dig _kerberos._tcp.dc._msdcs.lab.local SRV +short
Primary tools to practice this lesson: curl, grep. Reference sites: Event 4769 (https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4769); Event 4624 (https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4624); Event 4662 (https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4662). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.
2. Detection hygiene
Centralize DC logs, sync time, retain per policy — detection fails without logging.
Baseline normal 4769 volume on lab before declaring anomaly.
3. Scope
Synthetic or $LAB_AD logs only — no importing real breach log dumps from strangers.
Literacy: ID + meaning + alert idea — not live SIEM access to employer without authorization.
4. What you ship: AD event ID cheat sheet
Eight Event IDs + technique family + one lab alert hypothesis each.
5. What you record before the next lesson
Event ID cheat sheet path.
6. Wrong vs right: stranger-domain attacks vs lab AD literacy
Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.
Wrong
Import leaked enterprise EVTX to tune Kerberoast rule without authorization.
Right
Event ID cheat sheet for $LAB_AD detection literacy. Next: ATT&CK Mapping.
Mission: event ID cheat sheet
1) List eight AD Event IDs with one-line meaning. 2) Link 4769 4662 4624 to Module 5/6 concepts. 3) One alert hypothesis per ID on lab. 4) NEVER stranger log imports.
Stuck? Ask Cyberlium AI Mentor
Ask Mentor: “4769 encryption type 0x17 — literacy note?”
Knowledge Check
APPLY: Event 4769 relates to:
Multiple choice
Knowledge Check
APPLY: True or False: 4662 can anchor DCSync detection.
True or False
Knowledge Check
APPLY: Detection literacy uses logs from:
Multiple choice