Event Guard - Monitor your system for signs of compromise (Updated Jul 2026)
Description:
Event Guard watches the Windows Security event log for the events that most often signal an attack or tampering — failed logons, new accounts, privilege changes, service and scheduled-task installs, cleared audit logs, PowerShell script blocks, Defender detections and more. It can run in
Live Monitor mode, showing events the moment they happen, or in
History mode to review a chosen date range. Events are grouped into categories, colour-coded by severity, searchable, and shown with full details, and high-severity events can raise a desktop tray alert. You can watch the local machine or a remote computer, and export the filtered results to text or CSV for auditing and incident response.
Note: Event Guard reads the Windows
Security log, so it should be run as Administrator. If it isn’t, a status message warns that Security-log access may be limited. Monitoring a remote computer requires administrator rights on that machine.
How to use:
1. Choose an event category. The
Event Categories tree on the left lists All plus groups such as Account Mgmt, Logon / Logoff, Privilege & SID, Process & Service, Scheduled Tasks, Object & Registry, Network & Share, Firewall, Audit & Policy, PowerShell and Antivirus. Selecting one filters the log to that group.
2. Pick Live or History mode. Click
Live Monitor to watch events in real time as they are written, or
History Mode to load past events. In History mode, set the
From and
To date/time range in the Filters panel (the date range applies to History only).
3. Apply filters. Use the
Severity dropdown (All, High, Medium, Low), type in the
Search box to match on description, user, event ID or category, and tick
Auto-scroll to keep the newest event in view. Tick
Tray alerts to be notified of high-severity events.
4. (Optional) Monitor a remote computer. Enter a machine name in the
Computer field to watch that computer’s Security log instead of the local one (administrator rights on that machine are required).
5. Choose which events are reported. Click
Select Events to open the event picker, tick or untick individual events, and save — your selection is remembered for next time and applies in both Live and History modes.
6. Read the Event Log grid. Each row shows Time, Event ID, Severity, Category, User and Description. High-severity rows are shaded red and medium rows yellow, and a counter shows how many events are displayed of the total.
7. Inspect an event. Click any row to see the full breakdown — time, event ID, severity, category, source, user, description and the raw event message — in the
Event Details pane.
8. Keep a record. Use
Refresh to reload,
Clear Log to empty the current view,
Copy Event to copy the selected event’s details, or
Export to TXT /
Export to CSV to save the filtered events for analysis or record-keeping.
Select Events Review the list of events that can be reported or monitored and choose what appears by checking or unchecking each one. Each event has a brief description of what it is and its severity. Click the "Save" button to store your selection — it will be remembered for next time and used in both Live and History modes.
Live Monitoring reports monitored events as they happen. High-severity events also raise a desktop tray notification (with a sound) when
Tray alerts is enabled, so you stay aware of what is happening on your system even when the window isn’t in focus.
Potential Uses for Event Guard Tool
- Real-time Security Monitoring: Instantly surface suspicious activity by watching the Windows Security log live, with tray alerts on high-severity events.
- Audit and Compliance Reporting: Gather detailed event data for compliance reviews, audits, or security investigations.
- Incident Response: Quickly assess the scope and timeline of a security incident by filtering and analysing critical events by category, severity and date.
- User Activity Tracking: Monitor logons, failed access attempts, account changes and privilege escalations for accountability.
- Historical Analysis: Search through past events to discover patterns, recurring issues, or the sequence of actions around an event of interest.
- Remote Machine Checks: Point the tool at another computer's Security log to review its recent security events from one place.
- Export for Forensics: Export the filtered events to CSV or text for off-machine analysis and record-keeping.
Event Guard Monitored Events
Event Guard classifies each monitored event as
High,
Medium or
Low severity. High-severity rows are highlighted red, medium rows yellow, and high-severity events can raise a tray alert. The events currently recognised are listed below.
High Severity Events (active attack or critical tampering)
- 104 — Event log cleared (compatibility) · Audit & Policy
- 1100 — Event logging service shut down · Audit & Policy
- 1102 — Audit log cleared (covering tracks) · Audit & Policy
- 1116 — Defender: malware detected · Antivirus
- 1120 — Defender: remediation failed · Antivirus
- 4103 — PowerShell module logging · PowerShell
- 4104 — PowerShell script block execution (fileless attack) · PowerShell
- 4616 — System time changed (anti-forensics) · Audit & Policy
- 4621 — Admin recovered from CrashOnAuditFail · Audit & Policy
- 4625 — Logon failure (brute force / compromise) · Logon / Logoff
- 4649 — Replay attack detected · Logon / Logoff
- 4670 — Object permissions changed (privilege escalation) · Object & Registry
- 4697 — Service installed (persistence / privilege escalation) · Process & Service
- 4698 — Scheduled task created (persistence) · Scheduled Tasks
- 4702 — Scheduled task updated (persistence) · Scheduled Tasks
- 4706 — Domain trust created (AD attack) · Audit & Policy
- 4719 — System audit policy changed (cover tracks) · Audit & Policy
- 4720 — User account created (persistence) · Account Mgmt
- 4735 — Security-enabled group changed · Account Mgmt
- 4739 — Domain policy changed (password/lockout/audit) · Audit & Policy
- 4740 — Account locked out (brute force) · Account Mgmt
- 4928 — SID history added to account (persistence) · Privilege & SID
- 4964 — Special groups logon table modified (SID priv-esc) · Privilege & SID
- 5152 — Network packet blocked by firewall · Firewall
- 7040 — Service configuration changed (hijacking / persistence) · Process & Service
- 7045 — Service installed — System log (persistence) · Process & Service
Medium Severity Events (suspicious or noteworthy activity)
- 800 — Windows Firewall settings changed · Firewall
- 1117 — Defender: action taken / quarantine · Antivirus
- 1118 — Defender: remediation started · Antivirus
- 1119 — Defender: remediation succeeded · Antivirus
- 4624 — Logon successful · Logon / Logoff
- 4634 — Logoff · Logon / Logoff
- 4647 — User-initiated logoff · Logon / Logoff
- 4648 — Logon with explicit credentials (lateral movement) · Logon / Logoff
- 4656 — Object handle requested (precursor to 4663) · Object & Registry
- 4657 — Registry value modified (persistence) · Object & Registry
- 4661 — Object handle requested (operation) · Object & Registry
- 4662 — Operation performed on object · Object & Registry
- 4663 — Attempt to access object (sensitive file/folder) · Object & Registry
- 4672 — Special privileges assigned to new logon · Logon / Logoff
- 4688 — New process created (watch parent/child) · Process & Service
- 4689 — Process exited · Process & Service
- 4699 — Scheduled task deleted (evasion) · Scheduled Tasks
- 4700 — Scheduled task enabled · Scheduled Tasks
- 4701 — Scheduled task disabled · Scheduled Tasks
- 4722 — User account enabled · Account Mgmt
- 4723 — User password changed · Account Mgmt
- 4724 — User password reset · Account Mgmt
- 4725 — User account disabled · Account Mgmt
- 4726 — User account deleted · Account Mgmt
- 4728 — Member added to security group · Account Mgmt
- 4729 — Member removed from security group · Account Mgmt
- 4732 — Member added to admin / local group (privilege escalation) · Account Mgmt
- 4733 — Member removed from local group · Account Mgmt
- 4738 — User account changed · Account Mgmt
- 4756 — Member added to universal group · Account Mgmt
- 4757 — Member removed from universal group · Account Mgmt
- 4771 — Kerberos pre-auth failed (brute force) · Logon / Logoff
- 4776 — DC authentication attempt (credentials exposed) · Logon / Logoff
- 4929 — SID history removed from account · Privilege & SID
- 5140 — Network share accessed (recon / exfil) · Network & Share
- 5142 — Network share removed · Network & Share
- 5145 — Network share object checked (file-level auditing) · Network & Share
- 5154 — Network packet allowed by firewall · Firewall
- 5156 — Firewall allowed connection · Firewall
Low Severity Events (informational)
- 4618 — Monitored security event pattern occurred · Audit & Policy
Event Categories
- Account Mgmt — user lifecycle, group membership and privilege changes
- Logon / Logoff — authentication, logon/logoff and Kerberos activity
- Privilege & SID — special-privilege assignment and SID-history changes
- Process & Service — process creation and service installation or configuration
- Scheduled Tasks — scheduled-task creation, update, enable, disable and deletion
- Object & Registry — object access, registry changes and permission changes
- Network & Share — network share access, addition and removal
- Firewall — firewall settings and allowed/blocked packets
- Audit & Policy — audit-log clearing, audit-policy and time changes, domain trusts
- PowerShell — PowerShell module logging and script-block execution
- Antivirus — Microsoft Defender detections and remediation