Customise
Text colour: Panel colour:

Matrix text: Matrix background:

Background image:

Matrix Code:

Reset




FW Admin Tech Tool Pro

FW Admin Tech Tool Pro

Windows Store FW Admin Tech Tool Pro Art


Tech Tools

Backup & Developer Tools
Cleanup & File Management
Conversion Tools
Email Tools
Information & Discovery
Monitoring & Automation
Network & Internet Tools
Office & Document Tools
Printer & Device Tools
Search Tools
Security & Privacy
System Information & Optimization
Visual & Creative Tools
Web & SEO Tools


Event Guard - Monitor your system for signs of compromise (Updated Jul 2026)


Description:
Event Guard watches the Windows Security event log for the events that most often signal an attack or tampering — failed logons, new accounts, privilege changes, service and scheduled-task installs, cleared audit logs, PowerShell script blocks, Defender detections and more. It can run in Live Monitor mode, showing events the moment they happen, or in History mode to review a chosen date range. Events are grouped into categories, colour-coded by severity, searchable, and shown with full details, and high-severity events can raise a desktop tray alert. You can watch the local machine or a remote computer, and export the filtered results to text or CSV for auditing and incident response.

Note: Event Guard reads the Windows Security log, so it should be run as Administrator. If it isn’t, a status message warns that Security-log access may be limited. Monitoring a remote computer requires administrator rights on that machine.

How to use:
FW Admin Tech Tool Pro - Event Guard


1. Choose an event category. The Event Categories tree on the left lists All plus groups such as Account Mgmt, Logon / Logoff, Privilege & SID, Process & Service, Scheduled Tasks, Object & Registry, Network & Share, Firewall, Audit & Policy, PowerShell and Antivirus. Selecting one filters the log to that group.

2. Pick Live or History mode. Click Live Monitor to watch events in real time as they are written, or History Mode to load past events. In History mode, set the From and To date/time range in the Filters panel (the date range applies to History only).

3. Apply filters. Use the Severity dropdown (All, High, Medium, Low), type in the Search box to match on description, user, event ID or category, and tick Auto-scroll to keep the newest event in view. Tick Tray alerts to be notified of high-severity events.

4. (Optional) Monitor a remote computer. Enter a machine name in the Computer field to watch that computer’s Security log instead of the local one (administrator rights on that machine are required).

5. Choose which events are reported. Click Select Events to open the event picker, tick or untick individual events, and save — your selection is remembered for next time and applies in both Live and History modes.

6. Read the Event Log grid. Each row shows Time, Event ID, Severity, Category, User and Description. High-severity rows are shaded red and medium rows yellow, and a counter shows how many events are displayed of the total.

7. Inspect an event. Click any row to see the full breakdown — time, event ID, severity, category, source, user, description and the raw event message — in the Event Details pane.

8. Keep a record. Use Refresh to reload, Clear Log to empty the current view, Copy Event to copy the selected event’s details, or Export to TXT / Export to CSV to save the filtered events for analysis or record-keeping.



Select Events Review the list of events that can be reported or monitored and choose what appears by checking or unchecking each one. Each event has a brief description of what it is and its severity. Click the "Save" button to store your selection — it will be remembered for next time and used in both Live and History modes.

FW Admin Tech Tool Pro - Event Guard


Live Monitoring reports monitored events as they happen. High-severity events also raise a desktop tray notification (with a sound) when Tray alerts is enabled, so you stay aware of what is happening on your system even when the window isn’t in focus.

FW Admin Tech Tool Pro - Event Guard


Potential Uses for Event Guard Tool
  • Real-time Security Monitoring: Instantly surface suspicious activity by watching the Windows Security log live, with tray alerts on high-severity events.

  • Audit and Compliance Reporting: Gather detailed event data for compliance reviews, audits, or security investigations.

  • Incident Response: Quickly assess the scope and timeline of a security incident by filtering and analysing critical events by category, severity and date.

  • User Activity Tracking: Monitor logons, failed access attempts, account changes and privilege escalations for accountability.

  • Historical Analysis: Search through past events to discover patterns, recurring issues, or the sequence of actions around an event of interest.

  • Remote Machine Checks: Point the tool at another computer's Security log to review its recent security events from one place.

  • Export for Forensics: Export the filtered events to CSV or text for off-machine analysis and record-keeping.



Event Guard Monitored Events
Event Guard classifies each monitored event as High, Medium or Low severity. High-severity rows are highlighted red, medium rows yellow, and high-severity events can raise a tray alert. The events currently recognised are listed below.

High Severity Events (active attack or critical tampering)
  • 104 — Event log cleared (compatibility)  ·  Audit & Policy
  • 1100 — Event logging service shut down  ·  Audit & Policy
  • 1102 — Audit log cleared (covering tracks)  ·  Audit & Policy
  • 1116 — Defender: malware detected  ·  Antivirus
  • 1120 — Defender: remediation failed  ·  Antivirus
  • 4103 — PowerShell module logging  ·  PowerShell
  • 4104 — PowerShell script block execution (fileless attack)  ·  PowerShell
  • 4616 — System time changed (anti-forensics)  ·  Audit & Policy
  • 4621 — Admin recovered from CrashOnAuditFail  ·  Audit & Policy
  • 4625 — Logon failure (brute force / compromise)  ·  Logon / Logoff
  • 4649 — Replay attack detected  ·  Logon / Logoff
  • 4670 — Object permissions changed (privilege escalation)  ·  Object & Registry
  • 4697 — Service installed (persistence / privilege escalation)  ·  Process & Service
  • 4698 — Scheduled task created (persistence)  ·  Scheduled Tasks
  • 4702 — Scheduled task updated (persistence)  ·  Scheduled Tasks
  • 4706 — Domain trust created (AD attack)  ·  Audit & Policy
  • 4719 — System audit policy changed (cover tracks)  ·  Audit & Policy
  • 4720 — User account created (persistence)  ·  Account Mgmt
  • 4735 — Security-enabled group changed  ·  Account Mgmt
  • 4739 — Domain policy changed (password/lockout/audit)  ·  Audit & Policy
  • 4740 — Account locked out (brute force)  ·  Account Mgmt
  • 4928 — SID history added to account (persistence)  ·  Privilege & SID
  • 4964 — Special groups logon table modified (SID priv-esc)  ·  Privilege & SID
  • 5152 — Network packet blocked by firewall  ·  Firewall
  • 7040 — Service configuration changed (hijacking / persistence)  ·  Process & Service
  • 7045 — Service installed — System log (persistence)  ·  Process & Service
Medium Severity Events (suspicious or noteworthy activity)
  • 800 — Windows Firewall settings changed  ·  Firewall
  • 1117 — Defender: action taken / quarantine  ·  Antivirus
  • 1118 — Defender: remediation started  ·  Antivirus
  • 1119 — Defender: remediation succeeded  ·  Antivirus
  • 4624 — Logon successful  ·  Logon / Logoff
  • 4634 — Logoff  ·  Logon / Logoff
  • 4647 — User-initiated logoff  ·  Logon / Logoff
  • 4648 — Logon with explicit credentials (lateral movement)  ·  Logon / Logoff
  • 4656 — Object handle requested (precursor to 4663)  ·  Object & Registry
  • 4657 — Registry value modified (persistence)  ·  Object & Registry
  • 4661 — Object handle requested (operation)  ·  Object & Registry
  • 4662 — Operation performed on object  ·  Object & Registry
  • 4663 — Attempt to access object (sensitive file/folder)  ·  Object & Registry
  • 4672 — Special privileges assigned to new logon  ·  Logon / Logoff
  • 4688 — New process created (watch parent/child)  ·  Process & Service
  • 4689 — Process exited  ·  Process & Service
  • 4699 — Scheduled task deleted (evasion)  ·  Scheduled Tasks
  • 4700 — Scheduled task enabled  ·  Scheduled Tasks
  • 4701 — Scheduled task disabled  ·  Scheduled Tasks
  • 4722 — User account enabled  ·  Account Mgmt
  • 4723 — User password changed  ·  Account Mgmt
  • 4724 — User password reset  ·  Account Mgmt
  • 4725 — User account disabled  ·  Account Mgmt
  • 4726 — User account deleted  ·  Account Mgmt
  • 4728 — Member added to security group  ·  Account Mgmt
  • 4729 — Member removed from security group  ·  Account Mgmt
  • 4732 — Member added to admin / local group (privilege escalation)  ·  Account Mgmt
  • 4733 — Member removed from local group  ·  Account Mgmt
  • 4738 — User account changed  ·  Account Mgmt
  • 4756 — Member added to universal group  ·  Account Mgmt
  • 4757 — Member removed from universal group  ·  Account Mgmt
  • 4771 — Kerberos pre-auth failed (brute force)  ·  Logon / Logoff
  • 4776 — DC authentication attempt (credentials exposed)  ·  Logon / Logoff
  • 4929 — SID history removed from account  ·  Privilege & SID
  • 5140 — Network share accessed (recon / exfil)  ·  Network & Share
  • 5142 — Network share removed  ·  Network & Share
  • 5145 — Network share object checked (file-level auditing)  ·  Network & Share
  • 5154 — Network packet allowed by firewall  ·  Firewall
  • 5156 — Firewall allowed connection  ·  Firewall
Low Severity Events (informational)
  • 4618 — Monitored security event pattern occurred  ·  Audit & Policy

Event Categories
  • Account Mgmt — user lifecycle, group membership and privilege changes
  • Logon / Logoff — authentication, logon/logoff and Kerberos activity
  • Privilege & SID — special-privilege assignment and SID-history changes
  • Process & Service — process creation and service installation or configuration
  • Scheduled Tasks — scheduled-task creation, update, enable, disable and deletion
  • Object & Registry — object access, registry changes and permission changes
  • Network & Share — network share access, addition and removal
  • Firewall — firewall settings and allowed/blocked packets
  • Audit & Policy — audit-log clearing, audit-policy and time changes, domain trusts
  • PowerShell — PowerShell module logging and script-block execution
  • Antivirus — Microsoft Defender detections and remediation