Hi @Peter_1985
Description of the Shutdown Event Tracker
which lists these event ids to monitor (quoted but edited and reformatted from article):
Event ID 6005 (alternate): “The event log service was started.” This is synonymous to system startup.
Event ID 6006 (alternate): “The event log service was stopped.” This is synonymous to system shutdown.
Event ID 6008 (alternate): "The previous system shutdown was unexpected." Records that the system started after it was not shut down properly.
Event ID 6009 (alternate): Indicates the Windows product name, version, build number, service pack number, and operating system type detected at boot time.
hacking activity against windows server
Please don’t forget to Accept the answer
and up-vote
wherever the information provided helps you, this can be beneficial to other community members.