Active Directory Logs: Key Information Sources for Investigation

Active Directory Logs require reading the full event, not just the Event ID: time, computer, user, Logon ID, Process, network source, and organizational context. The conclusion is formed by correlating multiple sources.
Windows and Identity investigations rely on a combination of authentication events, process creation, permission changes, Sysmon telemetry, and organizational context. A single event almost never provides a complete conclusion. This article focuses on Active Directory Logs and is intended for SOC analysts and Windows Server students. The goal is to provide a working method that can be applied in practice, in a professional interview, and in a work environment, without settling for a dictionary definition.
The main challenge is that data is almost always partial. 4768/4769 Kerberos, 4771 failures, 4740 lockout can indicate a direction, but their meaning depends on time, asset, user, and expected activity. Therefore, we will build the investigation around an investigation question, required evidence, and clear criteria for completion.
The practical scenario in the article is: Use Case table vs. Event IDs and source. All examples are lab data or process descriptions. When it comes to Penetration Testing, Web, or Cloud, work only with explicit authorization, defined scope, and the ability to stop the test.




