Microsoft-Windows-SEC

61 events across 1 channel

Event IDTitleChannel
1Operational
2Operational
3Operational
4Operational
5Operational
6Operational
7Operational
8Operational
9Operational
10Operational
11Operational
12Operational
13Operational
14Operational
15Operational
16Operational
17Operational
18Operational
19Operational
20Operational
21Operational
22Operational
23Operational
24Operational
25Operational
26Operational
27Operational
28Operational
29Operational
30Operational
31Operational
32Operational
33Operational
34Operational
35Operational
36Operational
37Operational
38Operational
39Operational
40Operational
41Operational
42Operational
43Operational
44Operational
45Operational
46Operational
47Operational
48Operational
49Operational
50Operational
51Operational
52Operational
53Operational
54Operational
55Operational
56Operational
57Operational
58Operational
59Operational
60Operational
61Operational

Event ID 1 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
CreatorProcessId
CreatorProcessTime
CreatorProcessName
ProcessName
CommandLine
ImageSHA256
ImageSHA1
ImageMD5
PartialCRC1
PartialCRC2
PartialCRC3
MotW
IntegrityLevel
TokenElevationType
Elevated
Impersonation
SubjectLogonId
ProcessStartKey
CreatorProcessStartKey
CommandLineTruncated
CommandLineSize
ImageLSH
MitigationPolicy
ProtectionLevel
EnterprisePolicy
InferredParentProcessId
InferredParentProcessTime
InferredParentProcessName
InferredParentProcessStartKey
CiIsSigningChainValid
CiIsMicrosoftRoot
CiIsMicrosoftApplicationRoot
CiSigningLevel
ImageOriginalName
CreationAnomalies
InitialThreadId
InitialThreadStartAddress
WindowFlags
ShowWindowFlags
StandardInputDeviceType
StandardOutputDeviceType
StandardErrorDeviceType
DesktopInfo

Event ID 2 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
DriverUnloadTime

Event ID 3 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
DriverLoadTime

Event ID 4 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
FileName
FileAttributes
Dispositon
ProcessStartKey
RequestSource
ShareName
RemoteIpAddressLength
RemoteIpAddress

Event ID 5 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
FileName
NewFileName
FileAttributes
ProcessStartKey
RequestSource
ShareName
RemoteIpAddressLength
RemoteIpAddress

Event ID 6 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
FileName
FileAttributes
ProcessStartKey
IsSensitive
RequestSource
ShareName
RemoteIpAddressLength
RemoteIpAddress

Event ID 7 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
FileName
FileAttributes
ProcessStartKey
IsSensitive
RequestSource
ShareName
RemoteIpAddressLength
RemoteIpAddress

Event ID 8 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
Key
ProcessStartKey

Event ID 9 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
Key
ProcessStartKey

Event ID 10 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
Key
NewKey
ProcessStartKey

Event ID 11 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
Key
Hive
RestoreFlags
ProcessStartKey

Event ID 12 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
Key
Hive
NewHive
ProcessStartKey

Event ID 13 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
Key
Value
OldValueDataType
OldValueDataSize
OldValueCopiedSize
OldValueData
NewValueDataType
NewValueDataSize
NewValueCopiedSize
NewValueData
ProcessStartKey

Event ID 14 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
VolumeName
VolReadOffset
VolReadSize
SystemVolume
ProcessStartKey
VolumeShadowCopy

Event ID 15 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
VolumeName
AccessMask
SystemVolume
ProcessStartKey
VolumeShadowCopy

Event ID 16 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
Key
Value
DataType
ValueDataSize
ValueCopiedSize
ValueData
ProcessStartKey

Event ID 17 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
PipeName
RemoteClientsAccess
NamedPipeEnd
DesiredAccess
FileOperation
ProcessStartKey
ShareName
RemoteIpAddressLength
RemoteIpAddress

Event ID 18 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
TargetProcessId
TargetProcessTime
TargetProcessName
TargetThreadId
TargetThreadStartAddress
StartAddressVadQueryResult
StartAddressVadAllocationBase
StartAddressVadAllocationProtect
StartAddressVadRegionType
StartAddressVadRegionSize
StartAddressVadProtect
SourceProcessStartKey
TargetProcessStartKey
MappedModuleName

Event ID 19 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
TargetProcessId
TargetProcessTime
TargetProcess
Access
SourceProcessStartKey
TargetProcessStartKey

Event ID 20 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
Desktop
Access
Duplicate
Kernel
ProcessStartKey

Event ID 21 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
VolumeName
VolWriteOffset
VolWriteSize
SystemVolume
ProcessStartKey
VolumeShadowCopy

Event ID 22 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
ProcessName
CommandLine
ProcessStartKey
CommandLineTruncated
CommandLineSize

Event ID 23 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
ImageName
MotW
ImageSHA256
ImageSHA1
ImageMD5
PartialCRC1
PartialCRC2
PartialCRC3
SystemModeImage
LoadImageAddress
ProcessStartKey
LoadImageSize
ImageLSH
CiIsSigningChainValid
CiIsMicrosoftRoot
CiIsMicrosoftApplicationRoot
CiSigningLevel
ImageOriginalName
ImageSignatureLevel
ImageDeviceType
ImageDeviceCharacteristics
ImageDeviceFlags

Event ID 24 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
ImageName
MotW
ImageSHA256
ImageSHA1
ImageMD5
PartialCRC1
PartialCRC2
PartialCRC3
ImageSignatureLevel
ImageSignatureType
CurrentCodeIntegrityOptions
OriginalCodeIntegrityOptions
ProcessStartKey
ImageBase
ImageSize
ImageLSH

Event ID 25 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
AffectedProcessId
AffectedProcessTime
CurrentTokenPointer
CurrentTokenSource
CurrentTokenPrivPresent
CurrentTokenPrivEnabled
CurrentTokenPrivEnabledByDefault
CurrentTokenIntegrityLevel
CurrentTokenUserSid
PreviousTokenPointer
PreviousTokenSource
PreviousTokenPrivPresent
PreviousTokenPrivEnabled
PreviousTokenPrivEnabledByDefault
PreviousTokenIntegrityLevel
PreviousTokenUserSid
OriginalTokenPointer
OriginalTokenSource
OriginalTokenPrivPresent
OriginalTokenPrivEnabled
OriginalTokenPrivEnabledByDefault
OriginalTokenIntegrityLevel
OriginalTokenUserSid
SystemTokenPointer
InlineCheck
AffectedProcessStartKey
PrimaryTokenFrozen
ParentTokenIntegrityLevel

Event ID 26 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ProcessStartKey
ThreadId
UserSid
SessionId
NormalizedSharePath
ShareName
SocketAddress
OpenDirection

Event ID 27 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
AffectedProcessId
AffectedProcessStartKey
AffectedProcessTime
InlineCheck
CurrentDaclPointer
CurrentDaclValidAceList
CurrentDaclAceCount
CurrentDaclSids
CurrentDaclAccessMaskBlobSize
CurrentDaclAccessMasks
PreviousDaclPointer
PreviousDaclValidAceList
PreviousDaclAceCount
PreviousDaclSids
PreviousDaclAccessMaskBlobSize
PreviousDaclAccessMasks
OriginalDaclPointer
OriginalDaclValidAceList
OriginalDaclAceCount
OriginalDaclSids
OriginalDaclAccessMaskBlobSize
OriginalDaclAccessMasks

Event ID 28 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessStartKey
Flags
ThreadId
CallerAddress
StartAddress
BackTraceSize
BackTrace
TargetCodeSize
TargetCode
CallerCodeSize
CallerCode

Event ID 29 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
CurrentValue
OriginalValue
IsSynchronous

Event ID 30 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
CurrentValue
PreviousValue
OriginalValue
IsSynchronous

Event ID 31 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ProcessStartKey
ThreadId
UserSid
RequestSource
ShareName
RemoteIpAddressLength
RemoteIpAddress

Event ID 32 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
SuspiciousPointerIndex
TableSize
Table
CodeSize
Code

Event ID 33 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
SuspiciousPointerIndex
TableSize
Table
CodeSize
Code

Event ID 34 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
TargetProcessId
TargetProcessTime
TargetProcess
Access
SourceProcessStartKey
TargetProcessStartKey

Event ID 35 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
FileName
OriginalCreationTime
OriginalLastAccessTime
OriginalLastWriteTime
OriginalChangeTime
ModifiedCreationTime
ModifiedLastAccessTime
ModifiedLastWriteTime
ModifiedChangeTime
FileAttributes
ProcessStartKey

Event ID 36 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
AffectedProcessId
AffectedProcessTime
AffectedProcessStartKey
InlineCheck

Event ID 37 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ImageName
ImageBase
ImageSize
DriverName
DriverObject
DriverInit
DriverStartIo
DriverUnload
MajorFunctionArraySize
MajorFunctionArray
FastIoDispatchArraySize
FastIoDispatchArray
SuspiciousDispatchBitmap
ContextInfoArraySize
ContextInfoArray

Event ID 38 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ProcessStartKey
OldFlags
NewFlags

Event ID 39 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
SourceThreadId
TargetThreadId
UserSid
TargetProcessId
TargetProcessTime
AccessMask
ProcessStartKey
TargetProcessStartKey

Event ID 40 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
FileName
FileAttributes
ProcessStartKey
IsSensitive
RequestSource
ShareName
RemoteIpAddressLength
RemoteIpAddress

Event ID 41 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
Key
Value
ProcessStartKey

Event ID 42 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
FileName
FileAttributes
DesiredAccess
Dispositon
ProcessStartKey
VolumeShadowCopy
FileOpenSource
ShareAccess
RequestSource
ShareName
RemoteIpAddressLength
RemoteIpAddress

Event ID 43 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
FileName
NewFileName
FileAttributes
ProcessStartKey
RequestSource
ShareName
RemoteIpAddressLength
RemoteIpAddress

Event ID 44 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
Key
FileName
ProcessStartKey

Event ID 45 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
Key
ProcessStartKey
SecurityInformation
OriginalSecurityDescriptor
NewSecurityDescriptor

Event ID 46 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
AffectedProcessId
AffectedProcessTime
AffectedProcessStartKey
InlineCheck
OriginalCommandLine
ModifiedCommandLine
CorruptedCommandLine

Event ID 47 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ProcessStartKey
IoControlCode
DeviceName
VolumeName
MaximumVolumeSpace
ApplicationGuid

Event ID 48 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ProcessStartKey
DriverName
DriverOriginalName
FunctionName
IsEnforced

Event ID 49 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ProcessStartKey
DriverName
DriverOriginalName
TargetDevice
MajorFunction
IoControlCode
IsEnforced

Event ID 50 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ProcessStartKey
FileName
OperationBlocked
UserSid
ShareName
RemoteIpAddressLength
RemoteIpAddress
Tag

Event ID 51 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ProcessStartKey
KeyName
ValueName
RegistryOperations
OperationBlocked

Event ID 52 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ProcessStartKey
FileName
OperationBlocked
UserSid
ShareName
RemoteIpAddressLength
RemoteIpAddress
Tag

Event ID 53 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
TimeBeforeAcquiringLock
TimeAfterAcquiringLock
TimeBeforeReleasingLock
StatusOplockAcquiring
StatusFileOpening
StatusDuplicateHandle
FileName
Access
ShareMode
OpenFlags

Event ID 54 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
TimeBeforeAcquiringLock
TimeAfterAcquiringLock
TimeBeforeReleasingLock
StatusBeforeRetry
StatusOfRetry
StatusAfterRetry
FileName
ProcessId
ProcessStartKey
ProcessCreationTime
IoFunction
Access
ShareMode
OpenFlags

Event ID 55 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
Key
Value
ProcessStartKey

Event ID 56 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ProcessStartKey
FileName
OperationBlocked
UserSid
ShareName
RemoteIpAddressLength
RemoteIpAddress
Tag

Event ID 57 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ProcessStartKey
FileName
OperationBlocked
UserSid
ShareName
RemoteIpAddressLength
RemoteIpAddress
Tag

Event ID 58 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
ProcessId
ProcessTime
ThreadId
UserSid
SessionId
Key
ProcessStartKey

Event ID 59 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
SuspiciousEntryIndex
TableSize
Table
CodeSize
Code

Event ID 60 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
CurrentValue
OriginalValue
IsSynchronous

Event ID 61 —

Provider
Microsoft-Windows-SEC
Channel
Operational

Fields

NameDescription
SequenceNumber
CurrentValue
OriginalValue
IsSynchronous