26/08/2026
Windows Event IDs and Sysmon Event IDs are essential for every SOC Analyst.
In this video, we explore the most important Windows Security Event IDs and Sysmon Event IDs used during SOC monitoring, threat detection, incident investigation, and threat hunting.
You will learn how Windows Event Logs and Sysmon provide visibility into attacker activity and how SOC analysts can use these events to investigate suspicious behavior.
π Windows Event IDs Covered
4624 β Successful Logon
4625 β Failed Logon
4634 β Logoff
4672 β Special Privileges Assigned
4688 β Process Creation
4697 β Service Installed
1102 β Audit Log Cleared
π‘οΈ Important Sysmon Event IDs
Event ID 1 β Process Creation
Event ID 3 β Network Connection
Event ID 7 β Image Loaded
Event ID 8 β CreateRemoteThread
Event ID 10 β Process Access
Event ID 11 β File Created
Event ID 13 β Registry Value Set
Event ID 22 β DNS Query
Event ID 23 β File Delete
Event ID 24 β Clipboard Change
Event ID 25 β Process Tampering
π SOC Investigation Perspective
We also discuss how analysts can correlate these events to identify:
β
Brute-force attacks
β
Suspicious logons
β
Malicious process ex*****on
β
PowerShell activity
β
Network connections
β
Malware ex*****on
β
Persistence
β
Registry modifications
β
DNS-based suspicious activity
β
File creation and deletion
β
Process injection/tampering
The goal is not simply to memorize Event IDs β learn what the event means, why it matters, and how a SOC analyst investigates it.
π― Who Should Watch?
This video is useful for:
SOC Analysts
Cybersecurity Beginners
Blue Team Analysts
Incident Responders
Threat Hunters
SIEM Analysts
Cybersecurity Students
Anyone preparing for SOC interviews
π If you're learning SOC
Subscribe to SOC SIVA for practical cybersecurity training, SOC investigations, SIEM use cases, Windows logs, Sysmon, threat hunting, incident response and hands-on attack simulations.
LEARN | ANALYZE | DEFEND π‘οΈ