Active Directory audit
About 21,800 normalized Security records per day from a small domain, with Kerberos, NTLM and temporary group membership.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/windows-active-directory/generator.yml \
--id ad \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| 4768 | Kerberos TGT issued | 47% of authentication | authentication |
| 4769 | Service ticket issued | 45% of authentication | authentication |
| 4776 | NTLM validation | 6% of authentication | authentication |
| 4771 | Kerberos pre-authentication failed | 2% of authentication | authentication |
| 4728 | Temporary global-group grant | About 12/day | iam |
| 4729 | Temporary grant removed | Per grant after 20–40 minutes | iam |
| 5136 | Directory attribute replaced | About six pairs/day | configuration |
Realism Features
- Human office hours and twelve continuous monitoring accounts
- Every modeled grant ends after 20–40 minutes in both modes
- Selected ECS projection; version 2 Kerberos profile assumes patched servers and RC4-enabled service accounts
Sample Output
{
"@timestamp": "2026-09-01T07:02:05.777167+00:00",
"agent": {
"ephemeral_id": "943942bd-09ec-48aa-957d-2f12ecb83866",
"id": "a51465f9-72f4-4761-89bb-55de00ec6701",
"name": "dc01.contoso.local",
"type": "filebeat",
"version": "8.17.0"
},
"ecs": {
"version": "8.11.0"
},
"event": {
"action": "added-member-to-group",
"category": [
"iam"
],
"code": "4728",
"kind": "event",
"outcome": "success",
"provider": "Microsoft-Windows-Security-Auditing",
"sequence": 902240,
"type": [
"group",
"change"
]
},
"group": {
"domain": "CONTOSO",
"id": "S-1-5-21-3457937927-2839227994-823803824-2601",
"name": "Maintenance Operators"
},
"host": {
"name": "dc01.contoso.local",
"os": {
"family": "windows",
"type": "windows"
}
},
"log": {
"level": "information"
},
"related": {
"user": [
"olga.sokolova",
"svc_maintenance_2"
]
},
"user": {
"domain": "CONTOSO",
"id": "S-1-5-21-3457937927-2839227994-823803824-1109",
"name": "olga.sokolova",
"target": {
"domain": "CONTOSO",
"group": {
"domain": "CONTOSO",
"id": "S-1-5-21-3457937927-2839227994-823803824-2601",
"name": "Maintenance Operators"
},
"id": "S-1-5-21-3457937927-2839227994-823803824-2202",
"name": "svc_maintenance_2"
}
},
"winlog": {
"channel": "Security",
"computer_name": "dc01.contoso.local",
"event_data": {
"MemberName": "CN=svc_maintenance_2,CN=Users,DC=contoso,DC=local",
"MemberSid": "S-1-5-21-3457937927-2839227994-823803824-2202",
"SubjectDomainName": "CONTOSO",
"SubjectLogonId": "0x91e545",
"SubjectUserName": "olga.sokolova",
"SubjectUserSid": "S-1-5-21-3457937927-2839227994-823803824-1109",
"TargetDomainName": "CONTOSO",
"TargetSid": "S-1-5-21-3457937927-2839227994-823803824-2601",
"TargetUserName": "Maintenance Operators"
},
"event_id": "4728",
"keywords": [
"Audit Success"
],
"level": "information",
"logon": {
"id": "0x91e545"
},
"opcode": "Info",
"outcome": "success",
"process": {
"pid": 516,
"thread": {
"id": 1467
}
},
"provider_guid": "{54849625-5478-4994-a5ba-3e3b0328c30d}",
"provider_name": "Microsoft-Windows-Security-Auditing",
"record_id": "902240",
"task": "Security Group Management",
"time_created": "2026-09-01T07:02:05.777167+00:00",
"version": 0
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| domain | CONTOSO | NetBIOS domain |
| dns_domain | contoso.local | DNS domain and Kerberos realm |
| domain_dn | DC=contoso,DC=local | Distinguished-name suffix |
| domain_sid | S-1-5-21-3457937927-2839227994-823803824 | Domain SID prefix |
| dc_host | dc01.contoso.local | Controller hostname |
| dc_agent_id | a51465f9-72f4-4761-89bb-55de00ec6701 | Stable collector ID |
| dc_ephemeral_id | 943942bd-09ec-48aa-957d-2f12ecb83866 | Collector session ID |
| agent_version | 8.17.0 | Filebeat version |
| anomaly_mode | true | Enable correlated episodes |
| anomaly_interval_hours | 24 | Episode interval in hours, from 6 to 8760 |
Related Generators
Keycloak 26.7.4 Event Log
Keycloak 26.7.4 jboss-logging user and admin event lines for one realm with 1,500 users and 5 administrators, as native text in event.original with keycloak.*, user.*, source.* and url.* fields following the Elastic keycloak.log pipeline. Recurring episodes show one administrator failing five to eight logins from a VPN egress address, then logging in to the admin console and granting a privileged realm role.
ALD Pro domain controller
About 61,200 selected records/day from one domain controller, including native KDC, LDAP access and audit records.
Cisco ISE 3.4 Administrative Audit Syslog
Cisco ISE CISE_Administrative_and_Operational_Audit remote syslog and matching ECS-style JSON for one Policy Administration Node, with the complete syslog record in event.original, for detections on ISE administrator activity. Logins, logoffs and failed logins of five administrators and 120 read-only operators, and logging-configuration changes; not RADIUS or TACACS traffic. Weekly episodes show an administrator account taken over by password guessing and used to switch off log forwarding.