Detection rules › By eventMicrosoft-Windows-Security-Auditing event 46575 detection rules reference this event. View event page.Sigma (5)ETW Logging Disabled In .NET Processes - Registry severity high T1112, T1562 NetNTLM Downgrade Attack severity high T1112, T1562.001 Processes Accessing the Microphone and Webcam severity medium T1123 Sysmon Channel Reference Deletion severity high T1112 Windows Defender Exclusion List Modified severity medium T1562.001