Security Event Collection Guidance¶
Purpose¶
This WASOC guide provides recommendations for collecting security events of Windows systems based on asset criticality.
The objective is to maximise detection opportunities, support incident response activities, and maintain an appropriate balance between security visibility and log volume.
This guidance is vendor-agnostic and can be implemented using any SIEM, log management platform, managed security service, or security operations capability.
What Are Security Event Logs?¶
Security event logs are records generated by operating systems and applications that capture security-relevant activity, including authentication attempts, account changes, privileged actions, process execution, and service installations. These logs are a key source of information for security monitoring, incident response, threat hunting, and compliance activities.
Examples include:
- Successful and failed logons
- User and group management changes
- Privileged account activity
- Kerberos authentication events
- Process creation events
- Service installation events
- Account lockouts
Further information on Windows Security Event logging can be found in the Windows Security Events Reference.
Recommended Logging Model¶
Domain Controllers
Services / Infrastructure
- Active Directory Domain Controllers
- Entra ID Connect Servers
- Authentication Infrastructure
- Privileged Access Management Systems
Recommended Events
- Authentication Events
- Kerberos Events
- Privileged Account Activity
- Account Management Events
- Service Installation Events
- Process Creation Events
Logging Objectives
- User authentication activity
- Kerberos authentication requests
- Privileged account usage
- Account creation and modification
- Service installation and persistence mechanisms
- Suspicious process execution
Key Event IDs
- 4624 Successful Logon
- 4625 Failed Logon
- 4672 Privileged Logon
- 4720 User Account Created
- 4726 User Account Deleted
- 4732 User Added to Privileged Group
- 4740 Account Locked Out
- 4768 Kerberos TGT Request
- 4769 Kerberos Service Ticket Request
- 4776 NTLM Authentication
- 7045 Service Installed
- 4688 Process Creation
Tier 0 Systems
Services / Infrastructure
- Certificate Authorities (CA)
- Privileged Access Workstations (PAW)
- Backup and Recovery Infrastructure
- Security Management Platforms
- SIEM and Log Collection Servers
- VPN and Remote Access Infrastructure
- Privileged Access Management (PAM) Systems
- Critical Operational Technology (OT) Management Systems
Recommended Events
- Authentication Events
- Privileged Account Activity
- Account Management Events
- Service Installation Events
- Process Creation Events
Logging Objectives
- Administrative access and privileged actions
- Changes to critical systems and services
- Malware, ransomware, and attacker tooling execution
- Lateral movement and credential misuse
- Service installation and persistence mechanisms
Key Event IDs
- 4624 Successful Logon
- 4625 Failed Logon
- 4648 Logon with Explicit Credentials
- 4672 Privileged Logon
- 4720 User Account Created
- 4726 User Account Deleted
- 4732 User Added to Privileged Group
- 4733 User Removed from Privileged Group
- 4740 Account Locked Out
- 4768 Kerberos TGT Request
- 4769 Kerberos Service Ticket Request
- 4776 NTLM Authentication
- 7045 Service Installed
- 4688 Process Creation
General Servers
Services / Infrastructure
- Application Servers
- Web Servers
- API Gateways
- File Servers
- Print Servers
- Database Servers
- Middleware Platforms
- Enterprise Business Systems
- Management Servers
Recommended Events
- Authentication Events
- Account Management Events
- Privileged Account Activity
- Service Installation Events
Logging Objectives
- Successful and failed authentication attempts
- Administrative activity
- User and group management changes
- Service installations and configuration changes
- Potential signs of unauthorised access
Key Event IDs
- 4624 Successful Logon
- 4625 Failed Logon
- 4648 Logon with Explicit Credentials
- 4672 Privileged Logon
- 4720 User Account Created
- 4726 User Account Deleted
- 4732 User Added to Privileged Group
- 4733 User Removed from Privileged Group
- 4740 Account Locked Out
- 4768 Kerberos TGT Request
- 4769 Kerberos Service Ticket Request
- 4776 NTLM Authentication
- 7045 Service Installed
Workstations and End User Devices
Services / Infrastructure
- Corporate Laptops
- Desktop Computers
- Shared Workstations
- Kiosk Devices
- Virtual Desktop Infrastructure (VDI)
- Thin Clients
Recommended Events
- Authentication Events
- Account Lockout Events
- Credential Usage Events
Logging Objectives
- User authentication activity
- Password spraying attempts
- Brute force activity
- Credential misuse
- Potential account compromise indicators
Key Event IDs
- 4624 Successful Logon
- 4625 Failed Logon
- 4648 Logon with Explicit Credentials
- 4740 Account Locked Out
Enhanced Monitoring Option - For higher-risk environments or where additional logging capacity is available, consider collecting:
- 4672 Privileged Logon
- 4688 Process Creation
- 7045 Service Installed
Appendix A – Microsoft Sentinel Implementation¶
Organisations using Microsoft Sentinel can implement this guidance using the Windows Security Events via AMA connector.
Guidance on configuring the connector and available event sets can be found in the Windows Security Events via AMA documentation.
Azure Virtual Machines¶
- Deploy the Azure Monitor Agent (AMA) extension to the virtual machine.
- Create or select a Log Analytics Workspace.
- Enable Microsoft Sentinel on the workspace.
- Configure the Windows Security Events via AMA data connector.
- Create or assign a Data Collection Rule (DCR).
- Select Minimal, Common, All Events, or Custom event collection.
- Associate the DCR with the required servers.
Guidance for deploying and managing AMA is available in the Azure Monitor Agent Overview.
On-Premises and Non-Azure Servers¶
For physical servers, VMware environments, AWS, or other cloud platforms:
- Onboard the server to Azure Arc.
- Deploy the Azure Monitor Agent through Azure Arc.
- Configure the Windows Security Events via AMA connector.
- Create and assign the appropriate Data Collection Rule.
- Verify events are being received in the SecurityEvent table.
Microsoft provides onboarding guidance in the Azure Arc-enabled Servers documentation.
Data Flow¶
Additional information on DCRs is available in the Data Collection Rules Overview, while guidance on collecting Windows Event Logs is available in the Collect Windows Events with AMA.