ANAVEM
Languagefr

#security-monitoring

5 articles

Windows Events5

Windows security monitoring dashboard displaying Event ID 5139 registry deletion events in Event Viewer
Event 5139
Microsoft-Windows-Security-Auditing
Windows EventInformation

Windows Event ID 5139 – Microsoft-Windows-Security-Auditing: Registry Value Deleted

Event ID 5139 logs when a registry value is deleted on Windows systems with object access auditing enabled. Critical for security monitoring and compliance tracking.

March 1812 min
Windows security monitoring dashboard showing registry audit events and system logs
Event 5138
Microsoft-Windows-Security-Auditing
Windows EventInformation

Windows Event ID 5138 – Microsoft-Windows-Security-Auditing: Registry Value Deleted

Event ID 5138 records when a registry value is deleted on Windows systems with audit policies enabled. This security audit event helps track registry modifications for compliance and security monitoring.

March 189 min
Security analyst monitoring Windows Event ID 4657 registry audit logs on multiple screens in a SOC environment
Event 4657
Microsoft-Windows-Security-Auditing
Windows EventInformation

Windows Event ID 4657 – Microsoft-Windows-Security-Auditing: Registry Value Modified

Event ID 4657 logs when a registry value is modified on Windows systems with object access auditing enabled. Critical for security monitoring and compliance tracking.

March 1812 min
Windows security monitoring dashboard showing Event Viewer with process creation audit logs
Event 4111
Microsoft-Windows-Kernel-Process
Windows EventInformation

Windows Event ID 4111 – Microsoft-Windows-Kernel-Process: Process Creation Auditing Event

Event ID 4111 tracks process creation events in Windows when advanced auditing is enabled. This security-focused event provides detailed information about new processes, including parent process details and command line arguments.

March 1812 min
Windows security operations center showing Event Viewer with service installation monitoring and PowerShell security analysis
Event 7045
Service Control Manager
Windows EventInformation

Windows Event ID 7045 – Service Control Manager: New Service Installation

Event ID 7045 fires when a new Windows service is installed on the system. This informational event logs service creation details including name, path, and startup type for security monitoring.

March 1812 min