Server Attacks

Expanded Windows Event IDs, password attack signatures, and risk documentation  ·  Approx. 2–3 class days

StarringEvent 1102 · Event 4688 · Event 4672

Use this as a quick reference for the expanded Event ID vocabulary, spraying vs. stuffing signatures, and risk documentation levels.

Server Attacks: Event IDs and Risk Documentation infographic

🧭 Plot Summary

Back in 2.2.3, you learned Event 4624 and 4625. This activity expands that vocabulary with four more Event IDs — including one that should immediately grab your attention any time you see it in a real log.

4740
Account lockout
4688
Process created
4672
Privileged logon
1102
Audit log cleared

You'll also learn to tell password spraying apart from credential stuffing purely from log patterns, and assess whether a device vulnerability represents high, moderate, or low risk — then document that assessment the way a real analyst would.

What you will do in this lesson

  • Expand your Event ID vocabulary: 4740 (lockout), 4688 (process created), 4672 (privileged logon), 1102 (audit log cleared).
  • Distinguish password spraying from credential stuffing using real log patterns.
  • Learn why offline password attacks are undetectable in logs — no exceptions.
  • Assess device vulnerability risk as high, moderate, or low, with real illustrative examples.
  • Document risk findings for a compromised server.

Why it matters

Event 1102 and an unusual-path 4688 entry are the exact indicators tested directly in the AP FRQ log analysis scenario. This is one of the highest-yield activities in the entire course for exam points.

Self-Check Before You Roll On

Check off each item as you get there. These are not grades — they are your own signal.