Saturday, November 2, 2019

Windows Event Log - Audit Policy Change Management


Event IdDescription
4670Permissions on an object were changed.
4715The audit policy, SACL, on an object was changed.
4719System audit policy was changed.
4817Auditing settings on object were changed.
4902The Per-user audit policy table was created.
4906The CrashOnAuditFail value has changed.
4907Auditing settings on object were changed.
4908Special Groups Logon table modified.
4912Per User Audit Policy was changed.
4904An attempt was made to register a security event source.
4905An attempt was made to unregister a security event source.

No comments:

Post a Comment