| Anaheim-SmartScreen | |
| Anti Tampering | Event ID 1 Event ID 2 Event ID 3
|
| Application Error | |
| AppLocker | -
-
-
-
-
-
- AppLocker Appx Process Audit
-
- AppLocker Appx Process Block
-
- AppLocker Appx script Audit
-
- AppLocker Appx script Block
-
-
- Wldp Script File Disabled
|
| AttackSurfaceMonitor | No event ID assigned - Device creation via AST
- Device IOCTL called
|
| Audit-CVE | |
| Bits-Client | -
-
-
-
- BITS_EV_JOB_TAKE_OWNERSHIP
-
|
| Bluetooth-Policy | -
- Bluetooth_PolicyServiceBlockAudit
|
| CodeIntegrity | -
-
-
- DeviceGuard policy failure audit
-
- DeviceGuard policy failure
-
- Code Integrity signature information
-
- Smartlocker Operational Success
-
- Smartlocker Operational Audit
-
- Smartlocker Operational Failure
-
|
| Crypto-DPAPI-Events | |
| Dhcp-Client | |
| DHCPV6-Client-Events | |
| DNS-Client | -
- Send query to DNS server
- Send query to DNS server Aggregation
-
|
| DotNETRuntime | |
| EDP-Audit-Regular | -
- WIP Sensitive Data Copied
-
- WIP Application Generated
|
| EDP-Audit-TCB | -
- WIP File Protection Removed
|
| FilterManager | |
| Generic ETW CreateFile Pattern | Event ID 1 - Remote Non PE Create File Event
- PE Create File Event
- SMB create File Event
- Outlook Create File Event
- Non PE Create File Event
- Shell Link Create File Event
- Shell Link Create File Event (Remote)
- WDATP Tampering Create File Event
- WDATP Program Files Create File Event
- User Create File Event
- Browsers Create File Event
- Email Archive Create File Event
|
| IE-SmartScreen | |
| Kernel Integrity | |
| Kernel-Audit-API-Calls | |
| Kernel-Network | -
- Kernel network bytes sent TCP IPv4 non Filtered
- Kernel Network Byte Send IPv4 Filtered
-
- Kernel network bytes received TCP IPv4 non Filtered
-
- Kernel network bytes sent TCP IPv6 non Filtered
-
- Kernel network bytes received TCP IPv6 non Filtered
|
| Kernel-PnP-Events | -
- Device Config Success by policy
-
- configuration blocked by policy
|
| Ldap-Client | |
| LiveId | |
| LsaSrv | -
- LsaSrv UI user
- LsaSrv UI computer account
-
- Encryption oracle remediation
|
| Machine state | Event ID 2 Event ID 3 Event ID 4 Event ID 5 Event ID 6 Event ID 7 Event ID 8 Event ID 9 Event ID 10 Event ID 11 Event ID 12 Event ID 13 Event ID 16 Event ID 17 Event ID 18 Event ID 19 Event ID 20 Event ID 21 Event ID 22 Event ID 1000 - WDAV tamper-protection (Windows Defender configuration)
Event ID 1001 - WDAV tamper-protection (Windows Defender configuration)
Event ID 1002 - Timna - Information Gathering
No event slot assigned - Timna - OXO HKLM reg keys
- Onboarding information collection
- Url Cache Size
- Timna - VA - .NET Framework
- Timna - VA - Office click to run
- Timna - secure configuration - application configuration (compatibility)
- Timna - Internet Explorer - version information
- Timna - SCA configurations
- Timna - KBs
- AppUsage process list
- Timna - Firmware - TPM
- Timna - Internet Explorer Installation Status
- Timna - Firmware - BaseBoard
- Timna - Firmware - Bios
- Timna - Local Users
- Timna - Computer system information
- Timna - Add or remove programs
- Timna - Add or remove programs - WOW6432Node
- Timna - Add or remove programs (hkey_users)
- Timna - Add or remove programs - WOW6432Node (hkey_users)
- Registry collection
- AppGuard state GP
- Network protection configuration
- Timna - secure configuration
- LDAP Security Configuration
- Disable Remote Registry Service
- Disable NTLM authentication for Windows workstations
- Exchange OwaVersion Collection
- SCA WMI Defender configurations
- XSPM - TPM Status
- XSPM - RDP Status
- XSPM - HKLM PowerShell Execution Status
|
| Microsoft-Antimalware-Engine | -
-
- AVEngineBASTelemetry
- AVEngineThreatTelemetry
- AVEngineNonThreatTelemetry
-
-
|
| Microsoft-Antimalware-RTP | |
| Microsoft-Antimalware-Scan-Interface | -
- AMSIScan
- AMSIContent
- AMSIContentForIIS
- AMSIContentForDotNet
- VssAmsiContent
|
| Microsoft-Antimalware-Service | -
-
-
-
- NetworkFilterConnectionInfo
-
-
-
- TroubleshootingModeNotification
-
- TamperProtectionNotification
-
- MpPreferenceExclusionsHardening
Event ID 76 - PolicyExclusionsHardening
|
| Microsoft-Antimalware-UacScan | -
- UacScanExe
- UacScanCom
- UacScanPackagedApp
- UacScanOther
|
| Microsoft-ThreatProtectionService | |
| microsoft-windows-grouppolicy | -
- DomainControllerDiscovery
|
Microsoft.Office.SecurityNo event ID assigned - Office SafeDocs file scanning
| Microsoft.Windows.ComOleAut32No event ID assigned - Com OleAut32 - TypeLibVerifyTrust
- Com OleAut32 - TypeLibMonikerFallback
- Com OleAut32 - TypeLibRegister
- Com OleAut32 - TypeLibLoad
- Com OleAut32 - TypeLibMonikerLoad
- Com OleAut32 - GetDocumentationDllLoad
| | Microsoft.Windows.Console.Host | No event ID assigned - conhost cooked read buffer
| | Microsoft.Windows.Defender | No event ID assigned - Legacy Process Creation
- Elam bypass
| Microsoft.Windows.FileSystem.CloudFilesNo event ID assigned - CfRegisterSyncRoot_Success
| Microsoft.Windows.HVSI.ContainerServiceNo event ID assigned - CreateVMEnd
- SuspendComputeSystemEnd
- ResumeComputeSystemEnd
| Microsoft.Windows.HVSI.ManagerNo event ID assigned - LaunchDocumentInContainer
| | Microsoft.Windows.HyperV.Compute | | Microsoft.Windows.NdrCollectorNo event ID assigned - ModelCollectorNdrScanner
- NdrCollectorHyperVVmDiscovery
- NdrCollectorAdUserComputer
- NdrCollectorAdUserComputerV2
- NdrCollectorAdUserComputerV3
- NdrCollectorLdapExchangeServerV3
- NdrCollectorVirtualMachineInfo
- NdrCollectorHyperVVmDiscoveryV2
- NdrCollectorDomainTrust
- NdrCollectorDomainController
- NdrCollectorAdcaInfo
- NdrCollectorAadConnectInfo
- NdrCollectorAadConnectInfoV2
- NdrCollectorDiscoveredAadConnectInfo
- NdrCollectorSccmInfo
- NdrCollectorSccmAgentInfo
- NdrCollectorAdfsInfoV2
- NdrCollectorDefaultGatewayDiscovery
- NdrCollectorVeritasBackupExecInfo
| Microsoft.Windows.NdrScannerNo event ID assigned - NdrScannerDefaultGatewayDiscovery
- NdrScannerSsh
- SipDiscoveryNdrScanner
- SnmpDiscoveryNdrScanner
- WsDiscoveryNdrScanner
- mDnsNdrScanner
- UPnPNdrScanner
- NdrScannerTelemetry
- NdrCveLocalScanner
- NdrScannerBannerGrab
- NdrScannerFtpBannerGrab
- NdrScannerHostDiscovery
- NdrScannerPortScan
- NdrScannerHttpProbe
- NdrScannerIcmp
- NdrScannerIpp
- NdrScannerWsdExtension
- NdrScannerNetBios
- NdrScannerSmb
- NdrScannerSmbV1
- NdrScannerPjl
- NdrScannerCrestronIP
- NdrScannerLdap
- NdrScannerAfp
- NdrScannerRdpNla
- NdrScannerNtlm
- ShieldsUpSetupResults
- NdrScannerIphoneSync
- NdrScannerAirplay
- NdrScannerRpcMapper
- NdrScannerVnc
- NdrScannerSlp
- NdrLdapComputerDiscovery
- NdrScannerSpring4Shell
- SnmpExtendedDiscoveryNdrScanner
| Microsoft.Windows.Oct.Enclave | | Microsoft.Windows.OLE.Clipboard | | | Microsoft.Windows.Print.Winspool | | Microsoft.Windows.Security.WininitNo event ID assigned - lsaIsoStartupCheck
- LsassStarted
| | Microsoft.Windows.Security.Wsc | No event ID assigned - WSC RegisterAntiVirus
- WSC UnregisterAntiVirus
| Microsoft.Windows.Sense.AccountsLockoutProvider | Microsoft.Windows.Sense.BrowserExtensionCollectionNo event ID assigned - CollectedBrowserExtensions
- TvmCollectedBrowserExtensionsIndex
| Microsoft.Windows.Sense.CollectionEtwNo event ID assigned - AWS CLI authentication data
- Azure CLI authentication data
- GCP ADC Authentication Data
- GCP Gcloud CLI Authentication Data
- DangerousWifiProfiles
- LocalServices
- LocalServicesIndex
- Timna - Products files scanning
- Timna - open handles scanning
- Timna - Products files scanning index
- DataCollection - Certificate not installed
- DataCollection - execution policy reduced
- Logon Audit Security Policy
- Browser data logged Azure user
- Browser data logged AWS user
- Browser data logged Azure users unified
- Browser data logged AWS users unified
- Azure CLI Authentication Data Unified
- AWS CLI Authentication Data Unified
- GCP ADC Authentication Data Unified
- GCP Gcloud CLI Authentication Data Unified
- DataCollection - Action response
- DataCollection - Action failure
| Microsoft.Windows.Sense.ConnectivityCheckerNo event ID assigned - ConnectivityCheckerReport
- ConnectivityCheckerFailure
| Microsoft.Windows.Sense.GeneratedETWNo event ID assigned - HangDetection - report a hung component
- HangDetection - looking for hung components
- ResourceManagerEvent
- OfflineCommandStatus
- IsolationAutoRecoveryHandler
- IsolationStartup_IsolationAfterReboot
- PlatformUpdateStatus
- PlatformUpdateStatus_Collector
- Create process using G-ETW
- OsInfo
- OsSettings
- SecurityLogCleared
- LogCleared
- StorageVolumeInformation
- Policy dispatcher critical error
- PSScriptSignatureValidation_Mismatch
- RunPSScript_InvalidSasUrl
- RunPSScript_InvalidValidationConfig
- OnlineActionSampler_InvalidCmd
- FirewallConfiguratorApplyEvent
- FirewallConfiguratorRemoveEvent
- FirewallConfiguratorGeneralEvent
- LMF Policy Applied
- LMF force close SMB session
- LMF force disconnect WTS session
- LMF force logoff WTS session
- SmbBouncerPolicy policy applied
- Geppetto policy applied
- Geppetto policy removal
- SBG policy applied
- SBG policy removed
- SBG mitigation
- RiskAssessment policy applied
- RiskAssessment policy removed
- WDAC policy applied
- WfpConfigurator policy applied
- WfpConfigurator policy removed
- DeviceContain policy applied
- DeviceContain policy did not match
- DeviceContain policy removed
- OffboardingEpochBlock policy applied
- Offboarding blob epoch blocked
- Offboarding blob epoch blocked - audit
- WfpGuard Policy Applied
- DLP Telemetry Event
- DLP Operational Information
- CrashCollector_CrashReport
- CrashCollector_WER
- InternalOpticsEvent
- InternalOpticsCompressedEvent
- Sense Uploaded Size
- PerformanceCounterProcessAndSystem
- PerformanceCounterProcess
- Orchestrator info
- Orchestrator error
- SenseService_ShutdownEvent
- SenseService_StopEvent
- SenseService_RestartEvent
- SenseService_UpdateInfoEvent
- SenseService_UpdateFailedEvent
- LogicResolverTelemetry
| Microsoft.Windows.Sense.ImmuneNo event ID assigned - Driver Collection Event
- ImmuneCodeIntegrity
- ImmuneComTelemetry
- ImmuneComAnalyzer
| Microsoft.Windows.Sense.LocalGroupsUsersCollection | Microsoft.Windows.Sense.OlympusNo event ID assigned - ADFS pre-authentication
- ADFS post-authentication
| Microsoft.Windows.Sense.PasswordPolicyProvider | Microsoft.Windows.Sense.PendingRebootUpdatesNo event ID assigned - Timna - Pending Reboot Collection
| Microsoft.Windows.Sense.RegHeartBeat | Microsoft.Windows.Sense.ResearchCollectionEtwNo event ID assigned - WfpFilterAudit
- WfpFilterDelete
| Microsoft.Windows.Sense.ScheduledTasksCollection | Microsoft.Windows.Sense.SenseCmNo event ID assigned - SenseCM
- CheckinScriptResults
| Microsoft.Windows.Sense.SenseCm | Microsoft.Windows.Sense.SharesCollection | Microsoft.Windows.Sense.SubAuthNo event ID assigned - SubAuth user logon audited
- SubAuth user logon blocked
- SubAuth initialization completion
- SubAuth package conflict detection
- SubAuth policy updated
- SubAuth policy removed
| Microsoft.Windows.Sense.TimnaProductsFromRegistryNo event ID assigned - Timna - Products From Registry 64 PowerShell
- Timna - Products From Registry 6432 PowerShell
- Timna - Products From User Registry 64 PowerShell
- Timna - Products From User Registry 6432 PowerShell
| Microsoft.Windows.Sense.Tvm.AxonNo event ID assigned - Timna - SenseTVM registry programs collection event
- Timna - SenseTVM windows programs collection event
- Timna - SenseTVM windows services collection event
- Timna - SenseTVM browser extensions collection event
- Timna - SenseTVM certificates collection event
- Timna - SenseTVM pending updates collection event
- Timna - SenseTVM ms store appx collection event
- Timna - SenseTVM windows KBs collection event
- Timna - SenseTVM PE collection event
- Timna - SenseTVM dev library collection event
- Timna - SenseTVM regex file extraction collection event
- Timna - SenseTVM JSON config collection event
- Timna - SenseTVM device info event
- Timna - SenseTVM windows device info event
- Timna - SenseTVM telemetry event
- Timna - SenseTVM scrubbed telemetry event
| Microsoft.Windows.Sense.Tvm.CollectorNo event ID assigned - Timna - VA collector event
- TvmCveLocalScanner
- Outbound block windows firewall rules that have no exceptions/scoping
- Collect Local security policy user rights assignments
- Collect device users roles info and authority
- Collect device services info
| Microsoft.Windows.Sense.Tvm.NetworkScannerNo event ID assigned - NetworkScanOutput
- NetworkScanAgentTrace
- Petra - Scan command status
- Timna - Internet Explorer Installation Status (Petra4Windows)
- Timna - KBs (Petra4Windows)
- Timna - Computer system information (Petra4Windows)
- Timna - Firmware - BaseBoard (Petra4Windows)
- Timna - Firmware - Bios (Petra4Windows)
- Timna - Local Users (Petra4Windows)
- Timna - Firmware - TPM (Petra4Windows)
- Timna - VA - .NET Framework (Petra4Windows)
- Timna - VA - Office click to run (Petra4Windows)
- Timna - Internet Explorer - version information (Petra4Windows)
- Timna - Add or remove programs (Petra4Windows)
- Timna - Add or remove programs - WOW6432Node (Petra4Windows)
- Timna - Add or remove programs (hkey_users) (Petra4Windows)
- Timna - Add or remove programs - WOW6432Node (hkey_users) (Petra4Windows)
- Petra - Operating system data (Petra4Windows)
- Petra - Computer system data (Petra4Windows)
- Timna - secure configuration - application configuration (compatibility) (Petra4Windows)
- Timna - SCA configurations (Petra4Windows)
- Timna - secure configuration (Petra4Windows)
- Timna - Information Gathering (Petra4Windows)
| Microsoft.Windows.Sense.TvmBaselineAssessorEtw | Microsoft.Windows.Sense.TvmCertificateCollectionEtwNo event ID assigned - TvmCertificateCollection
- TvmCertificateIndexCollection
| Microsoft.Windows.Sense.TvmInfoGatheringCollectorEtwNo event ID assigned - TvmInfoGatheringCollector
| Microsoft.Windows.Sense.ValidationEtwNo event ID assigned - DataCollection - Parent Validation
| Microsoft.Windows.Sense.WDCollectionNo event ID assigned - MDATP Security Baseline - AntiVirus
| Microsoft.Windows.SenseComponent.GeneratedETWNo event ID assigned - PerformanceCounterProcessAndSystem
- PerformanceCounterProcess
| | Microsoft.Windows.SenseNdr | No event ID assigned - SenseNdrMdns
- SenseNdrMdnsCveLog4j
- SenseNdrDhcp
- SenseNdrDhcpV6
- SenseNdrLldp
- SenseNdrLlmnr
- SenseNdrSsdp
- SenseNdrCDP
- SenseNdrArp
- SenseNdrArpRequest
- SenseNdrTcpHeader
- SenseNdrNbns
- SenseNdrMndp
- SenseNdrWsd
- SenseNdrUdpHeader
- SenseNdrIPHeader
- SenseNdrTcpHeaderSynPackets
- SenseNdr Telemetery
- ZeekSetupStatusEvent
- SenseNdrInfo
- SenseNdrError
- SenseNdrThrottling
- SenseNdrSignaturePii
- SenseNdrSignatureNtlm
- SenseNdrSignatureSmbServerGuid
- SenseNdrSignatureMsBrowser
- SenseNdrSignatureHttpServerHeader
- SenseNdrSignaturePublicIpScan
- SenseNdrSignaturePublicIpScanUdp
- SenseNdrSignatureIphoneSync
- SenseNdrSignatureCveDetection
- SenseNdrSignatureSpring4Shell
- SenseNdrSignatureKerberos
- SenseNdrSignatureLdapRbcdModify
- SenseNdrSignatureMsMsdt
- SenseNdrSignatureJavaReferenceOverLdap
- SenseNdrSignatureSkypeSsrf
- SenseNdrZeekSignatureBacnetBroadcastDiscovery
- SenseNdrZeekSignatureBacnetFW
- SenseNdrZeekSignatureBacnetLocation
- SenseNdrZeekSignatureBacnetModel
- SenseNdrZeekSignatureBacnetHostname
- SenseNdrZeekSignatureBacnetVendorCode
- SenseNdrZeekSignatureBacnetVendorName
- SenseNdrSignatureDns
- SenseNdrSignatureDnsCveLog4j
- SenseNdrSignatureJavaRMI
- SenseNdrSignatureSrvSvc
- SenseNdrSignatureWakeOnLan
- SenseNdrSignatureNegoEx
- SenseNdrSignaturePointOfCareTesting
- SenseNDRSignatureProfinetEPM
- SenseNDRSignatureProfinetIMZeroFive
- SenseNDRSignatureProfinetAssetManagement
- SenseNdrZeekDceRpc
- SenseNdrZeekSamr
- SenseNdrZeekSrvSvc
- SenseNdrZeekDns
- SenseNdrZeekFtp
- SenseNdrZeekConnTcp
- SenseNdrZeekConnUdp
- SenseNdrZeekSignature
- SenseNdrZeekDhcpV6Exploit
- SenseNdrZeekSmbGhost
- SenseNdrZeekIcmp
- SenseNdrZeekHttp
- SenseNdrZeekNtlm
- SenseNdrZeekSmbServerGuid
- SenseNdrZeekSsh
- SenseNdrZeekSmtp
- SenseNdrZeekKerberos
- SenseNdrZeekSsl
- SenseNdrZeekSmbFiles
- SenseNdrZeekSmbMapping
- SenseNdrZeekFiles
- SenseNdrZeekWireguard
- SenseNdrZeekNotice
- SenseNdrZeekPrintNightmare
- ZeekNdrRunnerEvent
- SenseNdrZeekStatistics
- SenseNdrZeekHealthLevelSeven
- SenseNdrZeekPointOfCareTesting
- SenseNdrZeekDicom
- SenseNdrZeekModbus
- SenseNdrZeekSnmp
- SenseNdrZeekEnip
- SenseNdrZeekCip
- SenseNDRZeekBacnetProperty
- SenseNDRZeekBacnetIAmVendor
- SenseNdrZeekModbusReadDeviceID
- SenseNdrZeekNicteaming
- SenseNdrZeekBacnetProperty
- SenseNdrZeekS7CommPlus
- SenseNdrZeekSignatureS7Comm
- SenseNdrZeekBoundarySix
- SenseNdrZeekReporterEvent
- SenseNdrZeekKerberosAuthTicketOut
- SenseNdrZeekKerberosAuthTicketIn
- SenseNdrZeekKerberosTgs
- SenseNdrSignatureTCPCIPGetAll
- SenseNdrSignatureUDPCIPGetAll
- SenseNdrSignatureTCPCIPGetSingle
- SenseNdrSignatureUDPCIPGetSingle
- SenseNdrSignatureUDPENIPListCIPIdentity
- SenseNdrSignatureTCPENIPListCIPIdentity
- SenseNdrSignatureBacnetBroadcastDiscovery
- SenseNdrSignatureBacnetProperty
- SenseNdrSignatureSNMPSysDescription
- SenseNdrSignatureSNMPSysName
- SenseNdrSignatureS7CommReadSZL_0111
- SenseNdrSignatureS7CommReadSZL_001C
- SenseNdrSignatureS7CommReadSZL_0011
- SenseNdrSignatureModbusReadDeviceID
- SenseNDRSignatureSiemensSICAM
- SenseNDRSignatureS7CommPlusCreateObject
- SenseNDRSignatureS7CommPlusGetVarSubStreamed
- SenseNDRSignatureS7CommPlusGeneric
- SenseNDRSignatureCSP2DiagnosticStatusResponseLocal
- SenseNDRSignatureCSP2DiagnosticStatusResponseRemote
- SenseNDRSignatureCSP2Generic
- SenseNdrSignatureHoneywellDiscovery
- SenseNdrZeekGhostCat
- SenseNdrZeekProfinetIoCm
- SenseNdrZeekProfinetHandshakeEPM
- SenseNdrZeekJA4SSH
- SenseNDRSignatureEmersonCpcE2SignOn
- SenseNDRSignatureEmersonCpcE2CtrlList
- SenseNdrZeekEmersonCpcE2
| | Microsoft.Windows.ServiceControlManager | | Microsoft.Windows.User32 | Microsoft.Windows.WebDefense.SenseLoggingNo event ID assigned - ThreatAssessmentSenseEvent
| Microsoft.Windows.WSL.DefenderPlugin | | NTLM | -
- NTLM Client Blocked Audit
| | Powershell cmdlets | | | PrintService | -
- Device Control Print Failed due to Restrictions
| | RemoteDesktopServices-RdpCoreTS | -
- RdpCoreTS Accept Connection
-
- RdpCoreTS MST120 Virtual channel
| | RPC | -
- RPC Interface Registration
-
- RPC Interface Unregistration
| | RPC-Audit | | | SEC | -
-
- File create aggregation
- File create extension aggregation
-
- System rename extension aggregation
- File rename aggregation
- File rename extension aggregation
-
- Delete file
- File delete aggregation
- File delete extension aggregation
-
-
-
-
- Filter Process Termination
- Process Termination Aggregation
-
- LoadImage_ForProtectedProcess
- Event23
- Event23_ForSense
- Event23_ForAmsiDetector
- [FirstNSeen] LoadImage
-
-
-
- Open network share
- Admin share opened remotely
- Outgoing admin share access, parent folder only
- Outgoing admin share access, raw events
-
-
-
-
-
- Unauthorized file access attempts
-
-
-
-
-
-
-
-
- High value file read
- High value file read aggregation
- Script read from network share
-
-
- File Open
- File Open By Process
-
-
- Process Commandline Assertion Violation
-
-
- LMF File Open Blocked Audit
- LMF File Open Blocked Audit Aggregation
-
- Atomic Open Remote File And Acquire Oplock
-
-
- LMF network share access blocked
-
- LMF sysvol access blocked
-
| | SEC-WFP | -
- Contain connection blocked callout (legacy)
- ManualDeviceContainBlock
- DisruptionContainBlock
- OutgoingTrafficBlockerBlock
-
-
- DisruptionContainHvaAudit
- OutgoingTrafficBlockerAudit
-
| | SecureETW | -
-
- An account failed to log on
- SE_AUDITID_ETW_LOGON_FAILURE
- LMF network logon enforcement
-
- Logon using explicit credentials
-
- Hardlink Create Audit Event
-
- File permissions change
- Taking Ownership on File from TrustedInstaller
- Taking Ownership on MDE Key
-
- SE_AUDITID_ETW_PROCESS_CREATED
-
-
- A scheduled task was created
-
- A scheduled task was deleted
-
- A scheduled task was updated
-
- System Audit Policy was changed
-
- A user account was created
-
- An Attempt was made to reset an account password
-
- A user account was deleted
- A user account was deleted
-
-
- A member was added to a security-enabled local group
- A member was added to a security-enabled local group
-
-
-
- A user account was changed
-
- User's local group membership was enumerated
-
- Security-enabled local group membership was enumerated
-
- Sense tampering through object sacl change
-
-
-
- Firewall app blocked from listening
-
- Persistent cryptographic key operation.
-
- Persistent cryptographic key export.
-
- Firewall has blocked a connection outbound
- Firewall has blocked a connection inbound
-
- Credman - Credentials Backup
-
- Credman - Read Credentials
-
- Vault Credential - Find Credential
-
- Vault Credential - Enumerate Credentials
-
- Vault Credential - Get Unique Credential
-
- SE_AUDITID_ETW_RPC_INBOUND_CALL
- LMF RPC Inbound enforcement
-
| | Security-Mitigations | -
- AuditProcessProcessBlockGeneratingDynamicCode
-
- EnforceProcessProcessBlockGeneratingDynamicCode
-
- AuditProcessProcessBlockCreatingChildProcess
-
- EnforceProcessProcessBlockCreatingChildProcess
-
- AuditProcessLoadLowILImage
-
- EnforceProcessLoadLowILImage
-
- AuditProcessLoadBinaryFromRemoteShare
-
- EnforceProcessLoadBinaryFromRemoteShare
-
-
-
- AuditProcessLoadNonMicrosoftSignedBinary
-
- EnforceProcessLoadNonMicrosoftSignedBinary
-
-
- EnforceExportAddressFilter
-
- AuditExportAddressFilterPlus
-
- EnforceExportAddressFilterPlus
-
-
- EnforceInputAddressFilter
-
-
-
-
-
-
| | Services | -
-
- ServiceConfigChangeStartType
-
- ServiceConfigChangeBinaryPathName
-
- ServiceConfigChangeAccountInfo
| | SGRM Report | | | Shell-Core | -
- Explorer_ExecutingFromRunKey
-
- Open http link
- Open .lnk file
| | SmartScreen | | | TCPIP | | | TerminalServices-LocalSessionManager | -
-
- TerminalServices-RECONNECT
| | ThreatIntelligence | -
-
-
-
-
-
- MemAllocForHighRisk
- MemAllocForMeterpreter
-
- Image region local vmprotect
-
- MapViewForHighRiskProcesses
-
- ReadVMRemote
- ReadVMRemote clone
-
-
-
-
-
-
-
-
- AllocVmKernelCallerRemote
-
- ProtectVmKernelCallerRemote
-
- QueueUserApcKernelCallerRemote
-
-
-
| | User32 | | | VHDMP | | | WER-Diag | | | Win32k | -
- UpdateEvent
- BitBlt API call Aggregation
-
- KLRegRawInput (20H1+)
- KLRegRawInput
-
-
| | Windows Defender | -
-
-
-
-
-
- MALWAREPROTECTION_RTP_ENABLED
-
- MALWAREPROTECTION_RTP_DISABLED
-
- MALWAREPROTECTION_CONFIG_CHANGED
-
- Attempted Defender AV Tampering
| | WMI-Activity | -
- WMI remote query
- WMI local query
- WMI Class Creation and Usage
-
- Remote WMI Repository Update
-
- Remote Win32_Process:Create
- Remote WMI execution
- Local Win32_Process:Create
-
- Remote WMI Process Creation (RS5+)
- Local WMI Process Creation (RS5+)
-
- WMI bind filter to consumer
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |