Microsoft Defender for Endpoint

This inventory contains data from HKLM\SOFTWARE\Microsoft\Windows Advanced Threat Protection. Last updated: 15 July 2026

ProviderRule bindings
Anaheim-SmartScreen
  • No event ID assigned
    • UriLookup
    • BreakTheGlass
Anti Tampering
  • Event ID 1
    • ETW Provider tampering
  • Event ID 2
    • Process tampering
  • Event ID 3
    • Com tampering
Application Error
AppLocker
AttackSurfaceMonitor
  • No event ID assigned
    • Device creation via AST
    • Device IOCTL called
Audit-CVE
Bits-Client
Bluetooth-Policy
CodeIntegrity
Crypto-DPAPI-Events
Dhcp-Client
DHCPV6-Client-Events
DNS-Client
DotNETRuntime
EDP-Audit-Regular
EDP-Audit-TCB
FilterManager
Generic ETW CreateFile Pattern
  • Event ID 1
    • Remote Non PE Create File Event
    • PE Create File Event
    • SMB create File Event
    • Outlook Create File Event
    • Non PE Create File Event
    • Shell Link Create File Event
    • Shell Link Create File Event (Remote)
    • WDATP Tampering Create File Event
    • WDATP Program Files Create File Event
    • User Create File Event
    • Browsers Create File Event
    • Email Archive Create File Event
IE-SmartScreen
  • Event ID 1100: task_0
    • UrlBlockLookup
Kernel Integrity
  • Event ID 1
    • KernelIntegrityCheck
Kernel-Audit-API-Calls
  • Event ID 3: task_03
    • ObMgrSymlinkCreation
Kernel-Network
Kernel-PnP-Events
Ldap-Client
LiveId
  • Event ID 11008: +.
    • Function token provider
LsaSrv
Machine state
  • Event ID 2
    • WDAV state
  • Event ID 3
    • Firewall state
  • Event ID 4
    • CodeIntegrity state
  • Event ID 5
    • AppGuard state
  • Event ID 6
    • SmartScreen state
  • Event ID 7
    • KernelIntegrity state
  • Event ID 8
    • AntiExploit State
  • Event ID 9
    • HIPS ASR state
  • Event ID 10
    • FolderGuard state
  • Event ID 11
    • Windows Updates state
  • Event ID 12
    • Machine properties state
  • Event ID 13
    • BitLocker state
  • Event ID 16
    • Firmware State
  • Event ID 17
    • KB Item State
  • Event ID 18
    • KB Index State
  • Event ID 19
    • Isolation State
  • Event ID 20
    • Azure Vm Metadata State
  • Event ID 21
    • Effective Configuration
  • Event ID 22
    • Capabilities State
  • Event ID 1000
    • WDAV tamper-protection (Windows Defender configuration)
  • Event ID 1001
    • WDAV tamper-protection (Windows Defender configuration)
  • Event ID 1002
    • Timna - Information Gathering
  • No event slot assigned
    • Timna - OXO HKLM reg keys
    • Onboarding information collection
    • Url Cache Size
    • Timna - VA - .NET Framework
    • Timna - VA - Office click to run
    • Timna - secure configuration - application configuration (compatibility)
    • Timna - Internet Explorer - version information
    • Timna - SCA configurations
    • Timna - KBs
    • AppUsage process list
    • Timna - Firmware - TPM
    • Timna - Internet Explorer Installation Status
    • Timna - Firmware - BaseBoard
    • Timna - Firmware - Bios
    • Timna - Local Users
    • Timna - Computer system information
    • Timna - Add or remove programs
    • Timna - Add or remove programs - WOW6432Node
    • Timna - Add or remove programs (hkey_users)
    • Timna - Add or remove programs - WOW6432Node (hkey_users)
    • Registry collection
    • AppGuard state GP
    • Network protection configuration
    • Timna - secure configuration
    • LDAP Security Configuration
    • Disable Remote Registry Service
    • Disable NTLM authentication for Windows workstations
    • Exchange OwaVersion Collection
    • SCA WMI Defender configurations
    • XSPM - TPM Status
    • XSPM - RDP Status
    • XSPM - HKLM PowerShell Execution Status
Microsoft-Antimalware-Engine
Microsoft-Antimalware-RTP
  • Event ID 25: DCEvent
    • DC_RemovableStorageRWE
  • Event ID 26: DCEvent26
    • DC_DataDuplicationEvent
  • Event ID 28: DCEvent28
    • DC_DevicePresenceEvent
  • Event ID 29: DCEvent29
    • DC_HealthReportEvent
Microsoft-Antimalware-Scan-Interface
  • Event ID 1101: AmsiScanBuffer
    • AMSIScan
    • AMSIContent
    • AMSIContentForIIS
    • AMSIContentForDotNet
    • VssAmsiContent
Microsoft-Antimalware-Service
Microsoft-Antimalware-UacScan
  • Event ID 1201: UacScan
    • UacScanExe
    • UacScanCom
    • UacScanPackagedApp
    • UacScanOther
Microsoft-ThreatProtectionService
  • No event ID assigned
    • SqliStatelessDetector
microsoft-windows-grouppolicy
Microsoft.Office.Security
  • No event ID assigned
    • Office SafeDocs file scanning
Microsoft.Windows.ComOleAut32
  • No event ID assigned
    • Com OleAut32 - TypeLibVerifyTrust
    • Com OleAut32 - TypeLibMonikerFallback
    • Com OleAut32 - TypeLibRegister
    • Com OleAut32 - TypeLibLoad
    • Com OleAut32 - TypeLibMonikerLoad
    • Com OleAut32 - GetDocumentationDllLoad
Microsoft.Windows.Console.Host
  • No event ID assigned
    • conhost cooked read buffer
Microsoft.Windows.Defender
  • No event ID assigned
    • Legacy Process Creation
    • Elam bypass
Microsoft.Windows.FileSystem.CloudFiles
  • No event ID assigned
    • CfRegisterSyncRoot_Success
Microsoft.Windows.HVSI.ContainerService
  • No event ID assigned
    • CreateVMEnd
    • SuspendComputeSystemEnd
    • ResumeComputeSystemEnd
Microsoft.Windows.HVSI.Manager
  • No event ID assigned
    • LaunchDocumentInContainer
Microsoft.Windows.HyperV.Compute
  • No event ID assigned
    • ContainerStopped
Microsoft.Windows.NdrCollector
  • No event ID assigned
    • ModelCollectorNdrScanner
    • NdrCollectorHyperVVmDiscovery
    • NdrCollectorAdUserComputer
    • NdrCollectorAdUserComputerV2
    • NdrCollectorAdUserComputerV3
    • NdrCollectorLdapExchangeServerV3
    • NdrCollectorVirtualMachineInfo
    • NdrCollectorHyperVVmDiscoveryV2
    • NdrCollectorDomainTrust
    • NdrCollectorDomainController
    • NdrCollectorAdcaInfo
    • NdrCollectorAadConnectInfo
    • NdrCollectorAadConnectInfoV2
    • NdrCollectorDiscoveredAadConnectInfo
    • NdrCollectorSccmInfo
    • NdrCollectorSccmAgentInfo
    • NdrCollectorAdfsInfoV2
    • NdrCollectorDefaultGatewayDiscovery
    • NdrCollectorVeritasBackupExecInfo
Microsoft.Windows.NdrScanner
  • No event ID assigned
    • NdrScannerDefaultGatewayDiscovery
    • NdrScannerSsh
    • SipDiscoveryNdrScanner
    • SnmpDiscoveryNdrScanner
    • WsDiscoveryNdrScanner
    • mDnsNdrScanner
    • UPnPNdrScanner
    • NdrScannerTelemetry
    • NdrCveLocalScanner
    • NdrScannerBannerGrab
    • NdrScannerFtpBannerGrab
    • NdrScannerHostDiscovery
    • NdrScannerPortScan
    • NdrScannerHttpProbe
    • NdrScannerIcmp
    • NdrScannerIpp
    • NdrScannerWsdExtension
    • NdrScannerNetBios
    • NdrScannerSmb
    • NdrScannerSmbV1
    • NdrScannerPjl
    • NdrScannerCrestronIP
    • NdrScannerLdap
    • NdrScannerAfp
    • NdrScannerRdpNla
    • NdrScannerNtlm
    • ShieldsUpSetupResults
    • NdrScannerIphoneSync
    • NdrScannerAirplay
    • NdrScannerRpcMapper
    • NdrScannerVnc
    • NdrScannerSlp
    • NdrLdapComputerDiscovery
    • NdrScannerSpring4Shell
    • SnmpExtendedDiscoveryNdrScanner
Microsoft.Windows.Oct.Enclave
  • No event ID assigned
    • SGRM Assertion Event
Microsoft.Windows.OLE.Clipboard
  • No event ID assigned
    • OLE Clipboard Get Data
Microsoft.Windows.Print.Winspool
  • No event ID assigned
    • Print Job Created
Microsoft.Windows.Security.Wininit
  • No event ID assigned
    • lsaIsoStartupCheck
    • LsassStarted
Microsoft.Windows.Security.Wsc
  • No event ID assigned
    • WSC RegisterAntiVirus
    • WSC UnregisterAntiVirus
Microsoft.Windows.Sense.AccountsLockoutProvider
  • No event ID assigned
    • AccountLockoutPolicy
Microsoft.Windows.Sense.BrowserExtensionCollection
  • No event ID assigned
    • CollectedBrowserExtensions
    • TvmCollectedBrowserExtensionsIndex
Microsoft.Windows.Sense.CollectionEtw
  • No event ID assigned
    • AWS CLI authentication data
    • Azure CLI authentication data
    • GCP ADC Authentication Data
    • GCP Gcloud CLI Authentication Data
    • DangerousWifiProfiles
    • LocalServices
    • LocalServicesIndex
    • Timna - Products files scanning
    • Timna - open handles scanning
    • Timna - Products files scanning index
    • DataCollection - Certificate not installed
    • DataCollection - execution policy reduced
    • Logon Audit Security Policy
    • Browser data logged Azure user
    • Browser data logged AWS user
    • Browser data logged Azure users unified
    • Browser data logged AWS users unified
    • Azure CLI Authentication Data Unified
    • AWS CLI Authentication Data Unified
    • GCP ADC Authentication Data Unified
    • GCP Gcloud CLI Authentication Data Unified
    • DataCollection - Action response
    • DataCollection - Action failure
Microsoft.Windows.Sense.ConnectivityChecker
  • No event ID assigned
    • ConnectivityCheckerReport
    • ConnectivityCheckerFailure
Microsoft.Windows.Sense.GeneratedETW
  • No event ID assigned
    • HangDetection - report a hung component
    • HangDetection - looking for hung components
    • ResourceManagerEvent
    • OfflineCommandStatus
    • IsolationAutoRecoveryHandler
    • IsolationStartup_IsolationAfterReboot
    • PlatformUpdateStatus
    • PlatformUpdateStatus_Collector
    • Create process using G-ETW
    • OsInfo
    • OsSettings
    • SecurityLogCleared
    • LogCleared
    • StorageVolumeInformation
    • Policy dispatcher critical error
    • PSScriptSignatureValidation_Mismatch
    • RunPSScript_InvalidSasUrl
    • RunPSScript_InvalidValidationConfig
    • OnlineActionSampler_InvalidCmd
    • FirewallConfiguratorApplyEvent
    • FirewallConfiguratorRemoveEvent
    • FirewallConfiguratorGeneralEvent
    • LMF Policy Applied
    • LMF force close SMB session
    • LMF force disconnect WTS session
    • LMF force logoff WTS session
    • SmbBouncerPolicy policy applied
    • Geppetto policy applied
    • Geppetto policy removal
    • SBG policy applied
    • SBG policy removed
    • SBG mitigation
    • RiskAssessment policy applied
    • RiskAssessment policy removed
    • WDAC policy applied
    • WfpConfigurator policy applied
    • WfpConfigurator policy removed
    • DeviceContain policy applied
    • DeviceContain policy did not match
    • DeviceContain policy removed
    • OffboardingEpochBlock policy applied
    • Offboarding blob epoch blocked
    • Offboarding blob epoch blocked - audit
    • WfpGuard Policy Applied
    • DLP Telemetry Event
    • DLP Operational Information
    • CrashCollector_CrashReport
    • CrashCollector_WER
    • InternalOpticsEvent
    • InternalOpticsCompressedEvent
    • Sense Uploaded Size
    • PerformanceCounterProcessAndSystem
    • PerformanceCounterProcess
    • Orchestrator info
    • Orchestrator error
    • SenseService_ShutdownEvent
    • SenseService_StopEvent
    • SenseService_RestartEvent
    • SenseService_UpdateInfoEvent
    • SenseService_UpdateFailedEvent
    • LogicResolverTelemetry
Microsoft.Windows.Sense.Immune
  • No event ID assigned
    • Driver Collection Event
    • ImmuneCodeIntegrity
    • ImmuneComTelemetry
    • ImmuneComAnalyzer
Microsoft.Windows.Sense.LocalGroupsUsersCollection
  • No event ID assigned
    • Timna - LocalGroupsUsers
Microsoft.Windows.Sense.Olympus
  • No event ID assigned
    • ADFS pre-authentication
    • ADFS post-authentication
Microsoft.Windows.Sense.PasswordPolicyProvider
  • No event ID assigned
    • PasswordPolicy
Microsoft.Windows.Sense.PendingRebootUpdates
  • No event ID assigned
    • Timna - Pending Reboot Collection
Microsoft.Windows.Sense.RegHeartBeat
  • No event ID assigned
    • Possible ACL Tampering
Microsoft.Windows.Sense.ResearchCollectionEtw
  • No event ID assigned
    • WfpFilterAudit
    • WfpFilterDelete
Microsoft.Windows.Sense.ScheduledTasksCollection
  • No event ID assigned
    • ScheduledTasks
Microsoft.Windows.Sense.SenseCm
  • No event ID assigned
    • SenseCM
    • CheckinScriptResults
Microsoft.Windows.Sense.SenseCm
  • No event ID assigned
    • CheckinScriptResults
Microsoft.Windows.Sense.SharesCollection
  • No event ID assigned
    • Shares
Microsoft.Windows.Sense.SubAuth
  • No event ID assigned
    • SubAuth user logon audited
    • SubAuth user logon blocked
    • SubAuth initialization completion
    • SubAuth package conflict detection
    • SubAuth policy updated
    • SubAuth policy removed
Microsoft.Windows.Sense.TimnaProductsFromRegistry
  • No event ID assigned
    • Timna - Products From Registry 64 PowerShell
    • Timna - Products From Registry 6432 PowerShell
    • Timna - Products From User Registry 64 PowerShell
    • Timna - Products From User Registry 6432 PowerShell
Microsoft.Windows.Sense.Tvm.Axon
  • No event ID assigned
    • Timna - SenseTVM registry programs collection event
    • Timna - SenseTVM windows programs collection event
    • Timna - SenseTVM windows services collection event
    • Timna - SenseTVM browser extensions collection event
    • Timna - SenseTVM certificates collection event
    • Timna - SenseTVM pending updates collection event
    • Timna - SenseTVM ms store appx collection event
    • Timna - SenseTVM windows KBs collection event
    • Timna - SenseTVM PE collection event
    • Timna - SenseTVM dev library collection event
    • Timna - SenseTVM regex file extraction collection event
    • Timna - SenseTVM JSON config collection event
    • Timna - SenseTVM device info event
    • Timna - SenseTVM windows device info event
    • Timna - SenseTVM telemetry event
    • Timna - SenseTVM scrubbed telemetry event
Microsoft.Windows.Sense.Tvm.Collector
  • No event ID assigned
    • Timna - VA collector event
    • TvmCveLocalScanner
    • Outbound block windows firewall rules that have no exceptions/scoping
    • Collect Local security policy user rights assignments
    • Collect device users roles info and authority
    • Collect device services info
Microsoft.Windows.Sense.Tvm.NetworkScanner
  • No event ID assigned
    • NetworkScanOutput
    • NetworkScanAgentTrace
    • Petra - Scan command status
    • Timna - Internet Explorer Installation Status (Petra4Windows)
    • Timna - KBs (Petra4Windows)
    • Timna - Computer system information (Petra4Windows)
    • Timna - Firmware - BaseBoard (Petra4Windows)
    • Timna - Firmware - Bios (Petra4Windows)
    • Timna - Local Users (Petra4Windows)
    • Timna - Firmware - TPM (Petra4Windows)
    • Timna - VA - .NET Framework (Petra4Windows)
    • Timna - VA - Office click to run (Petra4Windows)
    • Timna - Internet Explorer - version information (Petra4Windows)
    • Timna - Add or remove programs (Petra4Windows)
    • Timna - Add or remove programs - WOW6432Node (Petra4Windows)
    • Timna - Add or remove programs (hkey_users) (Petra4Windows)
    • Timna - Add or remove programs - WOW6432Node (hkey_users) (Petra4Windows)
    • Petra - Operating system data (Petra4Windows)
    • Petra - Computer system data (Petra4Windows)
    • Timna - secure configuration - application configuration (compatibility) (Petra4Windows)
    • Timna - SCA configurations (Petra4Windows)
    • Timna - secure configuration (Petra4Windows)
    • Timna - Information Gathering (Petra4Windows)
Microsoft.Windows.Sense.TvmBaselineAssessorEtw
  • No event ID assigned
    • TvmBaselineAssessor
Microsoft.Windows.Sense.TvmCertificateCollectionEtw
  • No event ID assigned
    • TvmCertificateCollection
    • TvmCertificateIndexCollection
Microsoft.Windows.Sense.TvmInfoGatheringCollectorEtw
  • No event ID assigned
    • TvmInfoGatheringCollector
Microsoft.Windows.Sense.ValidationEtw
  • No event ID assigned
    • DataCollection - Parent Validation
Microsoft.Windows.Sense.WDCollection
  • No event ID assigned
    • MDATP Security Baseline - AntiVirus
Microsoft.Windows.SenseComponent.GeneratedETW
  • No event ID assigned
    • PerformanceCounterProcessAndSystem
    • PerformanceCounterProcess
Microsoft.Windows.SenseNdr
  • No event ID assigned
    • SenseNdrMdns
    • SenseNdrMdnsCveLog4j
    • SenseNdrDhcp
    • SenseNdrDhcpV6
    • SenseNdrLldp
    • SenseNdrLlmnr
    • SenseNdrSsdp
    • SenseNdrCDP
    • SenseNdrArp
    • SenseNdrArpRequest
    • SenseNdrTcpHeader
    • SenseNdrNbns
    • SenseNdrMndp
    • SenseNdrWsd
    • SenseNdrUdpHeader
    • SenseNdrIPHeader
    • SenseNdrTcpHeaderSynPackets
    • SenseNdr Telemetery
    • ZeekSetupStatusEvent
    • SenseNdrInfo
    • SenseNdrError
    • SenseNdrThrottling
    • SenseNdrSignaturePii
    • SenseNdrSignatureNtlm
    • SenseNdrSignatureSmbServerGuid
    • SenseNdrSignatureMsBrowser
    • SenseNdrSignatureHttpServerHeader
    • SenseNdrSignaturePublicIpScan
    • SenseNdrSignaturePublicIpScanUdp
    • SenseNdrSignatureIphoneSync
    • SenseNdrSignatureCveDetection
    • SenseNdrSignatureSpring4Shell
    • SenseNdrSignatureKerberos
    • SenseNdrSignatureLdapRbcdModify
    • SenseNdrSignatureMsMsdt
    • SenseNdrSignatureJavaReferenceOverLdap
    • SenseNdrSignatureSkypeSsrf
    • SenseNdrZeekSignatureBacnetBroadcastDiscovery
    • SenseNdrZeekSignatureBacnetFW
    • SenseNdrZeekSignatureBacnetLocation
    • SenseNdrZeekSignatureBacnetModel
    • SenseNdrZeekSignatureBacnetHostname
    • SenseNdrZeekSignatureBacnetVendorCode
    • SenseNdrZeekSignatureBacnetVendorName
    • SenseNdrSignatureDns
    • SenseNdrSignatureDnsCveLog4j
    • SenseNdrSignatureJavaRMI
    • SenseNdrSignatureSrvSvc
    • SenseNdrSignatureWakeOnLan
    • SenseNdrSignatureNegoEx
    • SenseNdrSignaturePointOfCareTesting
    • SenseNDRSignatureProfinetEPM
    • SenseNDRSignatureProfinetIMZeroFive
    • SenseNDRSignatureProfinetAssetManagement
    • SenseNdrZeekDceRpc
    • SenseNdrZeekSamr
    • SenseNdrZeekSrvSvc
    • SenseNdrZeekDns
    • SenseNdrZeekFtp
    • SenseNdrZeekConnTcp
    • SenseNdrZeekConnUdp
    • SenseNdrZeekSignature
    • SenseNdrZeekDhcpV6Exploit
    • SenseNdrZeekSmbGhost
    • SenseNdrZeekIcmp
    • SenseNdrZeekHttp
    • SenseNdrZeekNtlm
    • SenseNdrZeekSmbServerGuid
    • SenseNdrZeekSsh
    • SenseNdrZeekSmtp
    • SenseNdrZeekKerberos
    • SenseNdrZeekSsl
    • SenseNdrZeekSmbFiles
    • SenseNdrZeekSmbMapping
    • SenseNdrZeekFiles
    • SenseNdrZeekWireguard
    • SenseNdrZeekNotice
    • SenseNdrZeekPrintNightmare
    • ZeekNdrRunnerEvent
    • SenseNdrZeekStatistics
    • SenseNdrZeekHealthLevelSeven
    • SenseNdrZeekPointOfCareTesting
    • SenseNdrZeekDicom
    • SenseNdrZeekModbus
    • SenseNdrZeekSnmp
    • SenseNdrZeekEnip
    • SenseNdrZeekCip
    • SenseNDRZeekBacnetProperty
    • SenseNDRZeekBacnetIAmVendor
    • SenseNdrZeekModbusReadDeviceID
    • SenseNdrZeekNicteaming
    • SenseNdrZeekBacnetProperty
    • SenseNdrZeekS7CommPlus
    • SenseNdrZeekSignatureS7Comm
    • SenseNdrZeekBoundarySix
    • SenseNdrZeekReporterEvent
    • SenseNdrZeekKerberosAuthTicketOut
    • SenseNdrZeekKerberosAuthTicketIn
    • SenseNdrZeekKerberosTgs
    • SenseNdrSignatureTCPCIPGetAll
    • SenseNdrSignatureUDPCIPGetAll
    • SenseNdrSignatureTCPCIPGetSingle
    • SenseNdrSignatureUDPCIPGetSingle
    • SenseNdrSignatureUDPENIPListCIPIdentity
    • SenseNdrSignatureTCPENIPListCIPIdentity
    • SenseNdrSignatureBacnetBroadcastDiscovery
    • SenseNdrSignatureBacnetProperty
    • SenseNdrSignatureSNMPSysDescription
    • SenseNdrSignatureSNMPSysName
    • SenseNdrSignatureS7CommReadSZL_0111
    • SenseNdrSignatureS7CommReadSZL_001C
    • SenseNdrSignatureS7CommReadSZL_0011
    • SenseNdrSignatureModbusReadDeviceID
    • SenseNDRSignatureSiemensSICAM
    • SenseNDRSignatureS7CommPlusCreateObject
    • SenseNDRSignatureS7CommPlusGetVarSubStreamed
    • SenseNDRSignatureS7CommPlusGeneric
    • SenseNDRSignatureCSP2DiagnosticStatusResponseLocal
    • SenseNDRSignatureCSP2DiagnosticStatusResponseRemote
    • SenseNDRSignatureCSP2Generic
    • SenseNdrSignatureHoneywellDiscovery
    • SenseNdrZeekGhostCat
    • SenseNdrZeekProfinetIoCm
    • SenseNdrZeekProfinetHandshakeEPM
    • SenseNdrZeekJA4SSH
    • SenseNDRSignatureEmersonCpcE2SignOn
    • SenseNDRSignatureEmersonCpcE2CtrlList
    • SenseNdrZeekEmersonCpcE2
Microsoft.Windows.ServiceControlManager
  • No event ID assigned
    • ServiceStarted
Microsoft.Windows.User32
  • No event ID assigned
    • System shutdown (CSRSS)
Microsoft.Windows.WebDefense.SenseLogging
  • No event ID assigned
    • ThreatAssessmentSenseEvent
Microsoft.Windows.WSL.DefenderPlugin
  • No event ID assigned
    • WSLDefenderPlugin
NTLM
Powershell cmdlets
PrintService
RemoteDesktopServices-RdpCoreTS
RPC
RPC-Audit
  • Event ID 1: task_0
    • Remote RPC inbound audit
  • Event ID 2: task_02
    • Remote RPC inbound block
SEC
  • Event ID 2: task_02
    • SEC unload
  • Event ID 4: task_04
    • File create aggregation
    • File create extension aggregation
  • Event ID 5: task_05_V1
    • System rename extension aggregation
    • File rename aggregation
    • File rename extension aggregation
  • Event ID 6: task_06_V1
    • Delete file
    • File delete aggregation
    • File delete extension aggregation
  • Event ID 17: task_017
    • Named Pipe
  • Event ID 18: task_018
    • Event18
  • Event ID 19: task_019
    • Event19
  • Event ID 22: task_022
    • Filter Process Termination
    • Process Termination Aggregation
  • Event ID 23: task_023
    • LoadImage_ForProtectedProcess
    • Event23
    • Event23_ForSense
    • Event23_ForAmsiDetector
    • [FirstNSeen] LoadImage
  • Event ID 24: task_024
    • Event24
  • Event ID 25: task_025
    • Event25
  • Event ID 26: task_026
    • Open network share
    • Admin share opened remotely
    • Outgoing admin share access, parent folder only
    • Outgoing admin share access, raw events
  • Event ID 27: task_027
    • Event27
  • Event ID 28: task_028
    • Event28
  • Event ID 29: task_029
    • Event29
  • Event ID 30: task_030
    • Event30
  • Event ID 31: task_031
    • Unauthorized file access attempts
  • Event ID 32: task_032
    • Event32
  • Event ID 33: task_033
    • Event33
  • Event ID 34: task_034
    • Open process for read
  • Event ID 35: task_035
    • Event35
  • Event ID 36: task_036
    • Event36
  • Event ID 37: task_037
    • Event37
  • Event ID 38: task_038
    • Event38
  • Event ID 40: task_040
    • High value file read
    • High value file read aggregation
    • Script read from network share
  • Event ID 41: task_041
    • RegistryQueryValue
  • Event ID 42: task_042_V2
    • File Open
    • File Open By Process
  • Event ID 44: task_044
    • Registry Save Key
  • Event ID 46: task_046
    • Process Commandline Assertion Violation
  • Event ID 47: task_047
    • DeviceIoControl volsnap
  • Event ID 52: task_052_V2
    • LMF File Open Blocked Audit
    • LMF File Open Blocked Audit Aggregation
  • Event ID 53: task_053
    • Atomic Open Remote File And Acquire Oplock
  • Event ID 54: task_054
    • Retry Failed IO
  • Event ID 56: task_056_V2
    • LMF network share access blocked
  • Event ID 57: task_057_V2
    • LMF sysvol access blocked
  • Event ID 58: task_058
    • Registry Query Info Key
SEC-WFP
  • Event ID 1: task_01_V1
    • Contain connection blocked callout (legacy)
    • ManualDeviceContainBlock
    • DisruptionContainBlock
    • OutgoingTrafficBlockerBlock
  • Event ID 2: task_02_V1
    • ContainExclusions
  • Event ID 3: task_03_V1
    • DisruptionContainHvaAudit
    • OutgoingTrafficBlockerAudit
  • Event ID 4: task_0
    • WfpGuard Block Event
SecureETW
Security-Mitigations
Services
SGRM Report
  • Event ID 1
    • SGRM Report
  • Event ID 2
    • SGRM Error
Shell-Core
SmartScreen
TCPIP
TerminalServices-LocalSessionManager
ThreatIntelligence
User32
VHDMP
WER-Diag
Win32k
Windows Defender
WMI-Activity