Cheat sheet
Ports, Windows event IDs, email authentication, checklists and starter SIEM queries — everything in one place.
Updated October 2026 · Bookmark this page
A one-page reference for the facts SOC analysts look up most often. Use it while you study, during practice investigations and before interviews.
| Port | Protocol | Why it matters |
|---|---|---|
| 20/21 | FTP | File transfer; credentials sent in clear text |
| 22 | SSH | Remote administration; watch for brute force |
| 23 | Telnet | Legacy remote access; unencrypted |
| 25 | SMTP | Email delivery between servers |
| 53 | DNS | Name resolution; abused for tunneling |
| 67/68 | DHCP | Automatic IP addressing |
| 80 | HTTP | Unencrypted web traffic |
| 88 | Kerberos | Windows domain authentication |
| 110 / 995 | POP3 / POP3S | Email retrieval |
| 123 | NTP | Time synchronisation |
| 135 | RPC | Windows remote procedure calls |
| 137–139 | NetBIOS | Legacy Windows networking |
| 143 / 993 | IMAP / IMAPS | Email retrieval |
| 389 / 636 | LDAP / LDAPS | Directory queries (Active Directory) |
| 443 | HTTPS | Encrypted web traffic; most C2 hides here |
| 445 | SMB | Windows file sharing; lateral movement and ransomware |
| 1433 | MS SQL | Microsoft SQL Server |
| 3306 | MySQL | MySQL database |
| 3389 | RDP | Remote Desktop; never expose to the internet |
| 5985 / 5986 | WinRM | PowerShell remoting; used for lateral movement |
These appear in the Windows Security log (7045 is in the System log). Some require audit policies to be enabled.
| Event ID | Meaning | Investigation tip |
|---|---|---|
| 4624 | Successful logon | Check logon type, source IP and account |
| 4625 | Failed logon | Many in a short time suggests brute force or password spraying |
| 4634 | Logoff | Helps define session length |
| 4648 | Logon with explicit credentials | Can indicate runas or lateral movement |
| 4672 | Special privileges assigned | Admin-level logon |
| 4688 | Process created | Requires auditing; shows command lines if enabled |
| 4697 / 7045 | Service installed | Common persistence and lateral movement technique |
| 4698 | Scheduled task created | Common persistence technique |
| 4720 | User account created | Unexpected accounts are a red flag |
| 4724 | Password reset attempt | Check who reset whose password |
| 4728 / 4732 | Member added to security group | Watch privileged groups such as Domain Admins |
| 4740 | Account locked out | Often follows brute-force attempts |
| 4776 | Credential validation (NTLM) | Useful for spotting password spraying |
| 1102 | Audit log cleared | Highly suspicious: attackers hide their tracks |
| Type | Name | Example |
|---|---|---|
| 2 | Interactive | Keyboard logon at the machine |
| 3 | Network | Access to a share or service over the network |
| 4 | Batch | Scheduled tasks |
| 5 | Service | Service start-up |
| 7 | Unlock | Workstation unlocked |
| 10 | RemoteInteractive | RDP session |
| 11 | CachedInteractive | Logon with cached credentials, e.g. offline laptop |
Sysmon is a free Microsoft Sysinternals tool that adds detailed endpoint logging. These are the IDs analysts use most.
| ID | Event | Why it is useful |
|---|---|---|
| 1 | Process creation | Full command line, hashes and parent process |
| 3 | Network connection | Which process connected where |
| 7 | Image loaded | DLLs loaded by a process |
| 11 | File created | New files, e.g. dropped payloads |
| 13 | Registry value set | Persistence via Run keys |
| 22 | DNS query | Which process looked up which domain |
A pass does not mean an email is safe: attackers can register look-alike domains with perfect SPF, DKIM and DMARC. Always check the actual domain.
Full walkthrough: how to analyze a phishing email.
Field and table names vary between environments, so treat these as patterns to adapt.
SigninLogs
| where TimeGenerated > ago(1h)
| where ResultType != "0"
| summarize Failures = count() by UserPrincipalName, IPAddress
| where Failures > 10
| order by Failures descindex=wineventlog EventCode=4625 earliest=-1h
| stats count by Account_Name, Source_Network_Address
| where count > 10
| sort - countDeviceProcessEvents
| where InitiatingProcessFileName in~ ("winword.exe","excel.exe","outlook.exe")
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine
| Severity | Typical examples |
|---|---|
| Critical | Active ransomware, confirmed domain admin compromise, data exfiltration in progress |
| High | Confirmed account compromise, malware executing on a host, successful phishing with credential entry |
| Medium | Suspicious activity needing investigation, malware blocked but user clicked, policy violations with risk |
| Low | Blocked attempts, informational alerts, clear false positives to tune |
Every organization defines severity differently — always follow your team’s matrix.
Use it on a real case
Investigate realistic alerts where these event IDs, ports and checks actually matter.
Start free. No experience required.