My friend Mahmoud has great notes on Windows Event IDs and other topics check them out!
https://mahmoud-shaker.gitbook.io/dfir-notes/incident-response-eventhoods