Defender-DeviceEvents

216 ActionTypes

ActionTypeTitle
anyDefender event (any)
PowerShellCommandPowerShell command executed
AmsiScriptDetectedAMSI script detected
AmsiScriptContentAMSI script content captured
CreateRemoteThreadApiCallCreateRemoteThread API call
ProcessInjectionDetectedProcess injection detected
NamedPipeEventNamed pipe event
UserAccountAddedToLocalGroupUser account added to local group
UserAccountRemovedFromLocalGroupUser account removed from local group
AsrAuditEventASR audit event
AsrLsassCredentialTheftAuditedASR: LSASS credential theft (audited)
AsrOfficeChildProcessAuditedASR: Office child process (audited)
AntivirusReportAntivirus report
ScheduledTaskCreatedScheduled task created
ScheduledTaskDeletedScheduled task deleted
ScheduledTaskUpdatedScheduled task updated
OpenProcessApiCallProcess opened (OpenProcess API call)
ProcessPrimaryTokenModifiedProcess primary token modified
LdapSearchLDAP search
ClrUnbackedModuleLoadedCLR unbacked module loaded
AsrUntrustedExecutableAuditedASR untrusted executable (audited)
DriverLoadDriver loaded
NtAllocateVirtualMemoryRemoteApiCallRemote virtual memory allocation (NtAllocateVirtualMemory)
MemoryRemoteProtectRemote virtual memory protection change
NtMapViewOfSectionRemoteApiCallRemote section map (NtMapViewOfSection)
QueueUserApcRemoteApiCallRemote APC queued (QueueUserApc)
SetThreadContextRemoteApiCallRemote thread context change (SetThreadContext)
AsrAbusedSystemToolAuditedASR copied or impersonated system tool (audited)
AsrAbusedSystemToolBlockedASR copied or impersonated system tool (blocked)
AsrAbusedSystemToolWarnBypassedASR copied or impersonated system tool (warn bypassed)
AsrAdobeReaderChildProcessAuditedASR Adobe Reader child process (audited)
AsrAdobeReaderChildProcessBlockedASR Adobe Reader child process (blocked)
AsrAdobeReaderChildProcessWarnBypassedASR Adobe Reader child process (warn bypassed)
AsrExecutableEmailContentAuditedASR executable from email client (audited)
AsrExecutableEmailContentBlockedASR executable from email client (blocked)
AsrExecutableEmailContentWarnBypassedASR executable from email client (warn bypassed)
AsrExecutableOfficeContentAuditedASR Office app creating executable content (audited)
AsrExecutableOfficeContentBlockedASR Office app creating executable content (blocked)
AsrExecutableOfficeContentWarnBypassedASR Office app creating executable content (warn bypassed)
AsrLsassCredentialTheftBlockedASR LSASS credential theft (blocked)
AsrLsassCredentialTheftWarnBypassedASR LSASS credential theft (warn bypassed)
AsrObfuscatedScriptAuditedASR obfuscated script execution (audited)
AsrObfuscatedScriptBlockedASR obfuscated script execution (blocked)
AsrObfuscatedScriptWarnBypassedASR obfuscated script execution (warn bypassed)
AsrOfficeChildProcessBlockedASR Office app child process (blocked)
AsrOfficeChildProcessWarnBypassedASR Office app child process (warn bypassed)
AsrOfficeCommAppChildProcessAuditedASR Office communication app child process (audited)
AsrOfficeCommAppChildProcessBlockedASR Office communication app child process (blocked)
AsrOfficeCommAppChildProcessWarnBypassedASR Office communication app child process (warn bypassed)
AsrOfficeMacroWin32ApiCallsAuditedASR Win32 API calls from Office macros (audited)
AsrOfficeMacroWin32ApiCallsBlockedASR Win32 API calls from Office macros (blocked)
AsrOfficeMacroWin32ApiCallsWarnBypassedASR Win32 API calls from Office macros (warn bypassed)
AsrOfficeProcessInjectionAuditedASR Office app code injection (audited)
AsrOfficeProcessInjectionBlockedASR Office app code injection (blocked)
AsrOfficeProcessInjectionWarnBypassedASR Office app code injection (warn bypassed)
AsrPersistenceThroughWmiAuditedASR WMI event subscription persistence (audited)
AsrPersistenceThroughWmiBlockedASR WMI event subscription persistence (blocked)
AsrPersistenceThroughWmiWarnBypassedASR WMI event subscription persistence (warn bypassed)
AsrPsexecWmiChildProcessAuditedASR PsExec or WMI child process (audited)
AsrPsexecWmiChildProcessBlockedASR PsExec or WMI child process (blocked)
AsrPsexecWmiChildProcessWarnBypassedASR PsExec or WMI child process (warn bypassed)
AsrRansomwareAuditedASR ransomware activity (audited)
AsrRansomwareBlockedASR ransomware activity (blocked)
AsrRansomwareWarnBypassedASR ransomware activity (warn bypassed)
AsrSafeModeRebootAuditedASR Safe mode reboot configuration (audited)
AsrSafeModeRebootBlockedASR Safe mode reboot configuration (blocked)
AsrSafeModeRebootWarnBypassedASR Safe mode reboot configuration (warn bypassed)
AsrScriptExecutableDownloadAuditedASR script launching downloaded executable (audited)
AsrScriptExecutableDownloadBlockedASR script launching downloaded executable (blocked)
AsrScriptExecutableDownloadWarnBypassedASR script launching downloaded executable (warn bypassed)
AsrUntrustedExecutableBlockedASR untrusted executable (blocked)
AsrUntrustedExecutableWarnBypassedASR untrusted executable (warn bypassed)
AsrUntrustedUsbProcessAuditedASR untrusted process from USB (audited)
AsrUntrustedUsbProcessBlockedASR untrusted process from USB (blocked)
AsrUntrustedUsbProcessWarnBypassedASR untrusted process from USB (warn bypassed)
AsrVulnerableSignedDriverAuditedASR vulnerable signed driver (audited)
AsrVulnerableSignedDriverBlockedASR vulnerable signed driver (blocked)
AsrVulnerableSignedDriverWarnBypassedASR vulnerable signed driver (warn bypassed)
AsrWebShellOnServerAuditedASR webshell creation on Windows Server (audited)
AsrWebShellOnServerBlockedASR webshell creation on Windows Server (blocked)
AsrWebShellWarnBypassedASR webshell creation (warn bypassed)
AppControlAppInstallationAuditedAppControl app installation (audited)
AppControlAppInstallationBlockedAppControl app installation (blocked)
AppControlCIScriptAuditedAppControl Config CI script (audited)
AppControlCIScriptBlockedAppControl Config CI script (blocked)
AppControlCodeIntegrityDriverRevokedAppControl Code Integrity driver revoked
AppControlCodeIntegrityImageAuditedAppControl Code Integrity image (audited)
AppControlCodeIntegrityImageRevokedAppControl Code Integrity image revoked
AppControlCodeIntegrityOriginAllowedAppControl Code Integrity origin allowed
AppControlCodeIntegrityOriginAuditedAppControl Code Integrity origin (audited)
AppControlCodeIntegrityOriginBlockedAppControl Code Integrity origin (blocked)
AppControlCodeIntegrityPolicyAuditedAppControl Code Integrity policy (audited)
AppControlCodeIntegrityPolicyBlockedAppControl Code Integrity policy (blocked)
AppControlCodeIntegrityPolicyLoadedAppControl Code Integrity policy loaded
AppControlCodeIntegritySigningInformationAppControl Code Integrity signing information
AppControlExecutableAuditedAppControl executable (audited)
AppControlExecutableBlockedAppControl executable (blocked)
AppControlPackagedAppAuditedAppControl packaged app (audited)
AppControlPackagedAppBlockedAppControl packaged app (blocked)
AppControlPolicyAppliedAppControl policy applied
AppControlScriptAuditedAppControl script (audited)
AppControlScriptBlockedAppControl script (blocked)
AppGuardBrowseToUrlApplication Guard browse to URL
AppGuardCreateContainerApplication Guard container created
AppGuardLaunchedWithUrlApplication Guard launched with URL
AppGuardResumeContainerApplication Guard container resumed
AppGuardStopContainerApplication Guard container stopped
AppGuardSuspendContainerApplication Guard container suspended
AppLockerBlockExecutableAppLocker blocked executable
AppLockerBlockPackagedAppAppLocker blocked packaged app
AppLockerBlockPackagedAppInstallationAppLocker blocked packaged app installation
AppLockerBlockScriptAppLocker blocked script
ControlFlowGuardViolationControl Flow Guard violation
ExploitGuardAcgAuditedExploit Guard ACG (audited)
ExploitGuardAcgEnforcedExploit Guard ACG (blocked)
ExploitGuardChildProcessAuditedExploit Guard child process (audited)
ExploitGuardChildProcessBlockedExploit Guard child process (blocked)
ExploitGuardEafViolationAuditedExploit Guard EAF violation (audited)
ExploitGuardEafViolationBlockedExploit Guard EAF violation (blocked)
ExploitGuardIafViolationAuditedExploit Guard IAF violation (audited)
ExploitGuardIafViolationBlockedExploit Guard IAF violation (blocked)
ExploitGuardLowIntegrityImageAuditedExploit Guard low-integrity image (audited)
ExploitGuardLowIntegrityImageBlockedExploit Guard low-integrity image (blocked)
ExploitGuardNetworkProtectionAuditedExploit Guard Network Protection (audited)
ExploitGuardNetworkProtectionBlockedExploit Guard Network Protection (blocked)
ExploitGuardNonMicrosoftSignedAuditedExploit Guard non-Microsoft signed image (audited)
ExploitGuardNonMicrosoftSignedBlockedExploit Guard non-Microsoft signed image (blocked)
ExploitGuardRopExploitAuditedExploit Guard ROP exploit (audited)
ExploitGuardRopExploitBlockedExploit Guard ROP exploit (blocked)
ExploitGuardSharedBinaryAuditedExploit Guard shared binary load (audited)
ExploitGuardSharedBinaryBlockedExploit Guard shared binary load (blocked)
ExploitGuardWin32SystemCallAuditedExploit Guard Win32k system-call (audited)
ExploitGuardWin32SystemCallBlockedExploit Guard Win32k system-call (blocked)
AntivirusDefinitionsUpdateFailedAntivirus definitions update failed
AntivirusDefinitionsUpdatedAntivirus definitions updated
AntivirusDetectionAntivirus detection
AntivirusEmergencyUpdatesInstalledAntivirus emergency updates installed
AntivirusErrorAntivirus error
AntivirusMalwareActionFailedAntivirus malware action failed
AntivirusMalwareBlockedAntivirus malware blocked
AntivirusScanCancelledAntivirus scan cancelled
AntivirusScanCompletedAntivirus scan completed
AntivirusScanFailedAntivirus scan failed
AntivirusTroubleshootModeEventAntivirus troubleshoot mode state change
ControlledFolderAccessViolationAuditedControlled folder access violation (audited)
ControlledFolderAccessViolationBlockedControlled folder access violation (blocked)
FirewallInboundConnectionBlockedFirewall inbound connection blocked
FirewallInboundConnectionToAppBlockedFirewall inbound connection to app blocked
FirewallOutboundConnectionBlockedFirewall outbound connection blocked
FirewallServiceStoppedFirewall service stopped
NetworkProtectionUserBypassEventNetwork protection user bypass
NetworkShareObjectAccessCheckedNetwork share object access checked
NetworkShareObjectAddedNetwork share object added
NetworkShareObjectDeletedNetwork share object deleted
NetworkShareObjectModifiedNetwork share object modified
SmartScreenAppWarningSmartScreen app warning
SmartScreenExploitWarningSmartScreen exploit warning
SmartScreenUrlWarningSmartScreen URL warning
SmartScreenUserOverrideSmartScreen user override
AccountCheckedForBlankPasswordAccount checked for blank password
AuditPolicyModificationAudit policy modified
BitLockerAuditCompletedBitLocker audit completed
BluetoothPolicyTriggeredBluetooth policy triggered
BrowserLaunchedToOpenUrlBrowser launched to open URL
BruteForceActivityDetectedBrute force activity detected
CertificateServicesApprovedCertificateRequestCertificate Services approved certificate request
CertificateServicesLoadedTemplateCertificate Services loaded template
CertificateServicesReceivedCertificateRequestCertificate Services received certificate request
CredentialsBackupCredentials backed up
DeviceBootAttestationInfoDevice boot attestation info
DirectoryServiceObjectCreatedDirectory Service object created
DirectoryServiceObjectModifiedDirectory Service object modified
DnsQueryResponseDNS query response
DpapiAccessedDPAPI accessed
ExternalDeviceConnectedExternal device connected
ExternalDeviceDisconnectedExternal device disconnected
FileTimestampModificationEventFile timestamp modified
GetAsyncKeyStateApiCallGetAsyncKeyState API call
GetClipboardDataGetClipboardData API call
LogonRightsSettingEnabledLogon rights setting enabled
NtAllocateVirtualMemoryApiCallNtAllocateVirtualMemory API call
NtProtectVirtualMemoryApiCallNtProtectVirtualMemory API call
PTraceDetectedPTrace detected
PasswordChangeAttemptPassword change attempt
PlistPropertyModifiedPlist property modified
PnpDeviceAllowedPnP device allowed
PnpDeviceBlockedPnP device blocked
PnpDeviceConnectedPnP device connected
PrintJobBlockedPrint job blocked
ProcessCreatedUsingWmiQueryProcess created using WMI query
ReadProcessMemoryApiCallReadProcessMemory API call
RemoteDesktopConnectionRemote Desktop connection
RemoteWmiOperationRemote WMI operation
RemovableStorageFileEventRemovable storage file event
RemovableStoragePolicyTriggeredRemovable storage policy triggered
SafeDocFileScanSafe Documents file scanned
ScheduledTaskDisabledScheduled task disabled
ScheduledTaskEnabledScheduled task enabled
ScreenshotTakenScreenshot taken
SecurityGroupCreatedSecurity group created
SecurityGroupDeletedSecurity group deleted
SecurityLogClearedSecurity log cleared
SensitiveFileReadSensitive file read
ServiceInstalledService installed
ShellLinkCreateFileEventShell link (LNK) file created
TamperingAttemptTampering attempt
UntrustedWifiConnectionUntrusted Wi-Fi connection
UsbDriveDriveLetterChangedUSB drive letter changed
UsbDriveMountedUSB drive mounted
UsbDriveUnmountedUSB drive unmounted
UserAccountCreatedUser account created
UserAccountDeletedUser account deleted
UserAccountModifiedUser account modified
UserAccountPasswordResetAttemptUser account password reset attempt
WmiBindEventFilterToConsumerWMI EventFilter bound to consumer
WriteToLsassProcessMemoryWrite to LSASS process memory

any: Defender event (any)

#
Table
DeviceEvents

Description

Defender event (any). DeviceEvents is a catch-all; bridges only apply per-ActionType.

Fields #

NameDescription
DeviceId
Timestamp
ActionType
AdditionalFields
InitiatingProcessFileName
InitiatingProcessCommandLine

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventTypeeqConnectionSuccess2 ruleskusto
EventTypestarts_withAppControl5 ruleskusto
file_nameeqncrypt.dll4 ruleskusto
DestinationHostnameeqlogin.microsoftonline.com3 ruleskusto
GlobalPrevalencelt2503 ruleskusto
DestinationPorteq33892 ruleselastic, kusto, sigma, splunk
NodeLabeleqdevice2 ruleskusto
OnboardingStatusneOnboarded2 ruleskusto
TpmActivatednetrue2 ruleskusto
TpmEnablednetrue2 ruleskusto
TpmSupportednetrue2 ruleskusto
parent_process_namecontainspowershell2 ruleskusto
parent_process_namecontainspython2 ruleskusto
parent_process_namenemicrosoft.tri.sensor.exe2 ruleskusto
typeeqDeviceInventoryId2 ruleskusto

Detection Rules #

View all rules referencing this event →

Kusto #

Show 7 more (10 total)

References #

PowerShellCommand: PowerShell command executed

#
Table
DeviceEvents

Description

PowerShell command executed. PowerShell ScriptBlockLogging captures the same surface.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName
InitiatingProcessCommandLine

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventTypeeqPowerShellCommand1 rulekusto

Detection Rules #

View all rules referencing this event →

Kusto #

  • Suspicious Powershell Commandlet Executed source medium: This analytic rule detects when a suspicious PowerShell commandlet is executed on a host. Threat actors often use PowerShell to execute commands and scripts to move laterally, escalate privileges, and exfiltrate data.

References #

AmsiScriptDetected: AMSI script detected

#
Table
DeviceEvents

Description

AMSI script detected. Defender-only; no Windows-native equivalent.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

AmsiScriptContent: AMSI script content captured

#
Table
DeviceEvents

Description

AMSI script content captured. Defender-only; no Windows-native equivalent.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
parent_process_nameeqpowershell.exe1 ruleelastic, kusto, splunk

Detection Rules #

View all rules referencing this event →

Kusto #

  • Deimos Component Execution source high: Jupyter, otherwise known as SolarMarker, is a malware family and cluster of components known for its info-stealing and backdoor capabilities that mainly proliferates through search engine optimization manipulation and malicious advertising in order to successfully encourage users to download malicious templates and documents. This malware has been popular since 2020 and currently is still active as of 2021.

References #

CreateRemoteThreadApiCall: CreateRemoteThread API call

#
Table
DeviceEvents

Description

CreateRemoteThread API call

Fields #

NameDescription
DeviceId
Timestamp
ProcessId
InitiatingProcessFileName

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventTypeeqConnectionSuccess1 rulekusto
EventTypeinCreateRemoteThreadApiCall3 ruleskusto
EventTypeinQueueUserApcRemoteApiCall3 ruleskusto
EventTypeinSetThreadContextRemoteApiCall3 ruleskusto
EventTypeinNtAllocateVirtualMemoryRemoteApiCall2 ruleskusto
EventTypeinNtMapViewOfSectionRemoteApiCall2 ruleskusto
DestinationPorteq93891 ruleelastic, kusto, sigma, splunk
parent_process_nameeqmmc.exe1 ruleelastic, kusto, splunk
parent_process_nameinexcel.exe1 rulekusto, splunk
parent_process_nameinpowerpnt.exe1 rulekusto, splunk
parent_process_nameinwinword.exe1 rulekusto, splunk

Detection Rules #

View all rules referencing this event →

Kusto #

Show 1 more (4 total)

References #

ProcessInjectionDetected: Process injection detected

#
Table
DeviceEvents

Description

Process injection detected. Defender-only; no Windows-native equivalent.

Fields #

NameDescription
DeviceId
Timestamp
ProcessId
InitiatingProcessFileName

References #

NamedPipeEvent: Named pipe event

#
Table
DeviceEvents

Description

Named pipe event

Fields #

NameDescription
DeviceId
Timestamp
FileName
InitiatingProcessFileName

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventTypeeqNamedPipeEvent2 ruleskusto

Detection Rules #

View all rules referencing this event →

Kusto #

References #

UserAccountAddedToLocalGroup: User account added to local group

#
Table
DeviceEvents

Description

User account added to local group

Fields #

NameDescription
DeviceId
Timestamp
AccountName
AdditionalFields

Detection Rules #

View all rules referencing this event →

Kusto #

References #

UserAccountRemovedFromLocalGroup: User account removed from local group

#
Table
DeviceEvents

Description

User account removed from local group

Fields #

NameDescription
DeviceId
Timestamp
AccountName
AdditionalFields

References #

AsrAuditEvent: ASR audit event

#
Table
DeviceEvents

Description

ASR audit event. Defender ASR audit; loosely maps to Defender-1121 channel events.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

AsrLsassCredentialTheftAudited: ASR: LSASS credential theft (audited)

#
Table
DeviceEvents

Description

ASR: LSASS credential theft (audited). Defender ASR; no native equivalent.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName

References #

AsrOfficeChildProcessAudited: ASR: Office child process (audited)

#
Table
DeviceEvents

Description

ASR: Office child process (audited). Defender ASR; no native equivalent.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName

References #

AntivirusReport: Antivirus report

#
Table
DeviceEvents

Description

Antivirus report. Defender AV; loosely maps to Defender-1116/1117 detected/quarantined events.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
AdditionalFields

References #

ScheduledTaskCreated: Scheduled task created

#
Table
DeviceEvents

Description

Scheduled task created

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

ScheduledTaskDeleted: Scheduled task deleted

#
Table
DeviceEvents

Description

Scheduled task deleted

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

ScheduledTaskUpdated: Scheduled task updated

#
Table
DeviceEvents

Description

Scheduled task updated

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

OpenProcessApiCall: Process opened (OpenProcess API call)

#
Table
DeviceEvents

Description

Process opened (OpenProcess API call). Sysmon-10 is ProcessAccess; Kernel-Audit-API-Calls-5 (TargetProcessId / DesiredAccess / ReturnCode) is the same kernel audit hook MDE consumes and any admin ETW session can collect.

Fields #

NameDescription
DeviceId
Timestamp
FileName
ProcessId
InitiatingProcessFileName
InitiatingProcessCommandLine

Detection Patterns #

References #

ProcessPrimaryTokenModified: Process primary token modified

#
Table
DeviceEvents

Description

Process primary token modified. Security-4696 candidate closed (lab-verified 2026-06-05, Win11 26200): 4696 is emitted on current builds but only for kernel-level token assignments at boot (SYSTEM assigning token to Registry and other early kernel processes). User-space CreateProcessAsUser paths (Task Scheduler, scheduled task with explicit credentials) do not emit 4696. Semantics mismatch: 4696 fires on token assignment at process creation; ProcessPrimaryTokenModified fires on in-place token replacement (NtSetInformationProcess with ProcessAccessToken). Different kernel codepaths; no bridge.

Fields #

NameDescription
DeviceId
Timestamp
ProcessId
AccountName
InitiatingProcessFileName

Detection Patterns #

References #

LdapSearch: LDAP search

#
Table
DeviceEvents

Description

LDAP search. Client-side LDAP query telemetry (search filter in AdditionalFields). ETW bridge verified by live capture on Win11 26200 (2026-06-05): Microsoft-Windows-LDAP-Client event 30 (ScopeOfSearch, SearchFilter, DistinguishedName, AttributeList, ProcessId) fires for every wldap32.dll search call including rootDSE probes and paged result sets. Bridge is derivable-from, not one-to-one: event 30 fires for all client-side searches regardless of whether MDE would surface them as LdapSearch ActionType events.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
InitiatingProcessCommandLine
AdditionalFields

Detection Patterns #

References #

ClrUnbackedModuleLoaded: CLR unbacked module loaded

#
Table
DeviceEvents

Description

CLR unbacked module loaded. Derivable-from, not one-to-one: DotNETRuntime-152 (ModuleLoad) fires for every CLR module; 'unbacked' (no disk-backed image) is a filter over the module-flags payload. CLR ETW is emitted inside the (potentially attacker-controlled) process and can be patched out; the MDE sensor copy is the tamper-resistant variant.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
parent_process_nameincscript.exe1 ruleelastic, kusto, splunk
parent_process_nameinmmc.exe1 rulekusto, splunk
parent_process_nameinmshta.exe1 ruleelastic, kusto
parent_process_nameinwscript.exe1 ruleelastic, kusto, splunk

Detection Rules #

View all rules referencing this event →

Kusto #

  • Script Interpreter Loading DotNet Assembly From Memory source: The query searches for script interpreters (mmc.exe, mshta.exe, wscript.exe, and cscript.exe) loading .NET assemblies from memory. In the case of the MMC executable, the query also checks for the MSC file that was loaded, as some legitimate MSC files are known to load .NET assemblies via MMC.

References #

AsrUntrustedExecutableAudited: ASR untrusted executable (audited)

#
Table
DeviceEvents

Description

ASR untrusted executable (audited). Block-mode ASR siblings map to Defender-1121.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
InitiatingProcessFileName

Detection Rules #

View all rules referencing this event →

Kusto #

References #

DriverLoad: Driver loaded

#
Table
DeviceEvents

Description

Driver loaded. ETW-TI requires a PPL/ELAM-signed consumer; Sysmon-6 is the collectible equivalent for non-MDE environments.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
SHA1
SHA256

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventTypeeqDriverLoad2 ruleskusto
dcount_DeviceIdle51 rulekusto

Detection Rules #

View all rules referencing this event →

Kusto #

References #

NtAllocateVirtualMemoryRemoteApiCall: Remote virtual memory allocation (NtAllocateVirtualMemory)

#
Table
DeviceEvents

Description

Remote virtual memory allocation (NtAllocateVirtualMemory)

Fields #

NameDescription
DeviceId
Timestamp
ProcessId
InitiatingProcessFileName

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventTypeeqConnectionSuccess1 rulekusto
EventTypeinCreateRemoteThreadApiCall2 ruleskusto
EventTypeinNtAllocateVirtualMemoryRemoteApiCall2 ruleskusto
EventTypeinNtMapViewOfSectionRemoteApiCall2 ruleskusto
EventTypeinQueueUserApcRemoteApiCall2 ruleskusto
EventTypeinSetThreadContextRemoteApiCall2 ruleskusto
DestinationPorteq93891 ruleelastic, kusto, sigma, splunk
parent_process_nameeqmmc.exe1 ruleelastic, kusto, splunk

Detection Rules #

View all rules referencing this event →

Kusto #

References #

MemoryRemoteProtect: Remote virtual memory protection change

#
Table
DeviceEvents

Description

Remote virtual memory protection change

Fields #

NameDescription
DeviceId
Timestamp
ProcessId
InitiatingProcessFileName

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
DestinationPorteq93891 ruleelastic, kusto, sigma, splunk
EventTypeeqConnectionSuccess1 rulekusto
parent_process_nameeqmmc.exe1 ruleelastic, kusto, splunk

Detection Rules #

View all rules referencing this event →

Kusto #

References #

NtMapViewOfSectionRemoteApiCall: Remote section map (NtMapViewOfSection)

#
Table
DeviceEvents

Description

Remote section map (NtMapViewOfSection)

Fields #

NameDescription
DeviceId
Timestamp
ProcessId
InitiatingProcessFileName

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventTypeeqConnectionSuccess1 rulekusto
EventTypeinCreateRemoteThreadApiCall2 ruleskusto
EventTypeinNtAllocateVirtualMemoryRemoteApiCall2 ruleskusto
EventTypeinNtMapViewOfSectionRemoteApiCall2 ruleskusto
EventTypeinQueueUserApcRemoteApiCall2 ruleskusto
EventTypeinSetThreadContextRemoteApiCall2 ruleskusto
DestinationPorteq93891 ruleelastic, kusto, sigma, splunk
parent_process_nameeqmmc.exe1 ruleelastic, kusto, splunk

Detection Rules #

View all rules referencing this event →

Kusto #

References #

QueueUserApcRemoteApiCall: Remote APC queued (QueueUserApc)

#
Table
DeviceEvents

Description

Remote APC queued (QueueUserApc)

Fields #

NameDescription
DeviceId
Timestamp
ProcessId
InitiatingProcessFileName

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventTypeinCreateRemoteThreadApiCall2 ruleskusto
EventTypeinNtAllocateVirtualMemoryRemoteApiCall2 ruleskusto
EventTypeinNtMapViewOfSectionRemoteApiCall2 ruleskusto
EventTypeinQueueUserApcRemoteApiCall2 ruleskusto
EventTypeinSetThreadContextRemoteApiCall2 ruleskusto
parent_process_nameeqmmc.exe1 ruleelastic, kusto, splunk

Detection Rules #

View all rules referencing this event →

Kusto #

References #

SetThreadContextRemoteApiCall: Remote thread context change (SetThreadContext)

#
Table
DeviceEvents

Description

Remote thread context change (SetThreadContext)

Fields #

NameDescription
DeviceId
Timestamp
ProcessId
InitiatingProcessFileName

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventTypeinCreateRemoteThreadApiCall2 ruleskusto
EventTypeinNtAllocateVirtualMemoryRemoteApiCall2 ruleskusto
EventTypeinNtMapViewOfSectionRemoteApiCall2 ruleskusto
EventTypeinQueueUserApcRemoteApiCall2 ruleskusto
EventTypeinSetThreadContextRemoteApiCall2 ruleskusto

Detection Rules #

View all rules referencing this event →

Kusto #

References #

AsrAbusedSystemToolAudited: ASR copied or impersonated system tool (audited)

#
Table
DeviceEvents

Description

ASR copied or impersonated system tool (audited). Block-mode ASR sibling maps to Defender-1121.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

AsrAbusedSystemToolBlocked: ASR copied or impersonated system tool (blocked)

#
Table
DeviceEvents

Description

ASR copied or impersonated system tool (blocked). Audit-mode ASR sibling maps to Defender-1122.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

AsrAbusedSystemToolWarnBypassed: ASR copied or impersonated system tool (warn bypassed)

#
Table
DeviceEvents

Description

ASR copied or impersonated system tool (warn bypassed). Defender ASR user-override event; no ETW-channel equivalent.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

AsrAdobeReaderChildProcessAudited: ASR Adobe Reader child process (audited)

#
Table
DeviceEvents

Description

ASR Adobe Reader child process (audited). Block-mode ASR sibling maps to Defender-1121.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrAdobeReaderChildProcessBlocked: ASR Adobe Reader child process (blocked)

#
Table
DeviceEvents

Description

ASR Adobe Reader child process (blocked). Audit-mode ASR sibling maps to Defender-1122.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrAdobeReaderChildProcessWarnBypassed: ASR Adobe Reader child process (warn bypassed)

#
Table
DeviceEvents

Description

ASR Adobe Reader child process (warn bypassed). Defender ASR user-override event; no ETW-channel equivalent.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrExecutableEmailContentAudited: ASR executable from email client (audited)

#
Table
DeviceEvents

Description

ASR executable from email client (audited). Block-mode ASR sibling maps to Defender-1121.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

AsrExecutableEmailContentBlocked: ASR executable from email client (blocked)

#
Table
DeviceEvents

Description

ASR executable from email client (blocked). Audit-mode ASR sibling maps to Defender-1122.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

AsrExecutableEmailContentWarnBypassed: ASR executable from email client (warn bypassed)

#
Table
DeviceEvents

Description

ASR executable from email client (warn bypassed). Defender ASR user-override event; no ETW-channel equivalent.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

AsrExecutableOfficeContentAudited: ASR Office app creating executable content (audited)

#
Table
DeviceEvents

Description

ASR Office app creating executable content (audited). Block-mode ASR sibling maps to Defender-1121.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

AsrExecutableOfficeContentBlocked: ASR Office app creating executable content (blocked)

#
Table
DeviceEvents

Description

ASR Office app creating executable content (blocked). Audit-mode ASR sibling maps to Defender-1122.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

AsrExecutableOfficeContentWarnBypassed: ASR Office app creating executable content (warn bypassed)

#
Table
DeviceEvents

Description

ASR Office app creating executable content (warn bypassed). Defender ASR user-override event; no ETW-channel equivalent.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

AsrLsassCredentialTheftBlocked: ASR LSASS credential theft (blocked)

#
Table
DeviceEvents

Description

ASR LSASS credential theft (blocked). Audit-mode ASR sibling maps to Defender-1122.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrLsassCredentialTheftWarnBypassed: ASR LSASS credential theft (warn bypassed)

#
Table
DeviceEvents

Description

ASR LSASS credential theft (warn bypassed). Defender ASR user-override event; no ETW-channel equivalent.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrObfuscatedScriptAudited: ASR obfuscated script execution (audited)

#
Table
DeviceEvents

Description

ASR obfuscated script execution (audited). Block-mode ASR sibling maps to Defender-1121.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrObfuscatedScriptBlocked: ASR obfuscated script execution (blocked)

#
Table
DeviceEvents

Description

ASR obfuscated script execution (blocked). Audit-mode ASR sibling maps to Defender-1122.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrObfuscatedScriptWarnBypassed: ASR obfuscated script execution (warn bypassed)

#
Table
DeviceEvents

Description

ASR obfuscated script execution (warn bypassed). Defender ASR user-override event; no ETW-channel equivalent.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrOfficeChildProcessBlocked: ASR Office app child process (blocked)

#
Table
DeviceEvents

Description

ASR Office app child process (blocked). Audit-mode ASR sibling maps to Defender-1122.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrOfficeChildProcessWarnBypassed: ASR Office app child process (warn bypassed)

#
Table
DeviceEvents

Description

ASR Office app child process (warn bypassed). Defender ASR user-override event; no ETW-channel equivalent.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrOfficeCommAppChildProcessAudited: ASR Office communication app child process (audited)

#
Table
DeviceEvents

Description

ASR Office communication app child process (audited). Block-mode ASR sibling maps to Defender-1121.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrOfficeCommAppChildProcessBlocked: ASR Office communication app child process (blocked)

#
Table
DeviceEvents

Description

ASR Office communication app child process (blocked). Audit-mode ASR sibling maps to Defender-1122.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrOfficeCommAppChildProcessWarnBypassed: ASR Office communication app child process (warn bypassed)

#
Table
DeviceEvents

Description

ASR Office communication app child process (warn bypassed). Defender ASR user-override event; no ETW-channel equivalent.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrOfficeMacroWin32ApiCallsAudited: ASR Win32 API calls from Office macros (audited)

#
Table
DeviceEvents

Description

ASR Win32 API calls from Office macros (audited). Block-mode ASR sibling maps to Defender-1121.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrOfficeMacroWin32ApiCallsBlocked: ASR Win32 API calls from Office macros (blocked)

#
Table
DeviceEvents

Description

ASR Win32 API calls from Office macros (blocked). Audit-mode ASR sibling maps to Defender-1122.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrOfficeMacroWin32ApiCallsWarnBypassed: ASR Win32 API calls from Office macros (warn bypassed)

#
Table
DeviceEvents

Description

ASR Win32 API calls from Office macros (warn bypassed). Defender ASR user-override event; no ETW-channel equivalent.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrOfficeProcessInjectionAudited: ASR Office app code injection (audited)

#
Table
DeviceEvents

Description

ASR Office app code injection (audited). Block-mode ASR sibling maps to Defender-1121.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrOfficeProcessInjectionBlocked: ASR Office app code injection (blocked)

#
Table
DeviceEvents

Description

ASR Office app code injection (blocked). Audit-mode ASR sibling maps to Defender-1122.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrOfficeProcessInjectionWarnBypassed: ASR Office app code injection (warn bypassed)

#
Table
DeviceEvents

Description

ASR Office app code injection (warn bypassed). Defender ASR user-override event; no ETW-channel equivalent.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrPersistenceThroughWmiAudited: ASR WMI event subscription persistence (audited)

#
Table
DeviceEvents

Description

ASR WMI event subscription persistence (audited). Block-mode ASR sibling maps to Defender-1121.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrPersistenceThroughWmiBlocked: ASR WMI event subscription persistence (blocked)

#
Table
DeviceEvents

Description

ASR WMI event subscription persistence (blocked). Audit-mode ASR sibling maps to Defender-1122.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrPersistenceThroughWmiWarnBypassed: ASR WMI event subscription persistence (warn bypassed)

#
Table
DeviceEvents

Description

ASR WMI event subscription persistence (warn bypassed). Defender ASR user-override event; no ETW-channel equivalent.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrPsexecWmiChildProcessAudited: ASR PsExec or WMI child process (audited)

#
Table
DeviceEvents

Description

ASR PsExec or WMI child process (audited). Block-mode ASR sibling maps to Defender-1121.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrPsexecWmiChildProcessBlocked: ASR PsExec or WMI child process (blocked)

#
Table
DeviceEvents

Description

ASR PsExec or WMI child process (blocked). Audit-mode ASR sibling maps to Defender-1122.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrPsexecWmiChildProcessWarnBypassed: ASR PsExec or WMI child process (warn bypassed)

#
Table
DeviceEvents

Description

ASR PsExec or WMI child process (warn bypassed). Defender ASR user-override event; no ETW-channel equivalent.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrRansomwareAudited: ASR ransomware activity (audited)

#
Table
DeviceEvents

Description

ASR ransomware activity (audited). Block-mode ASR sibling maps to Defender-1121.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrRansomwareBlocked: ASR ransomware activity (blocked)

#
Table
DeviceEvents

Description

ASR ransomware activity (blocked). Audit-mode ASR sibling maps to Defender-1122.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrRansomwareWarnBypassed: ASR ransomware activity (warn bypassed)

#
Table
DeviceEvents

Description

ASR ransomware activity (warn bypassed). Defender ASR user-override event; no ETW-channel equivalent.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrSafeModeRebootAudited: ASR Safe mode reboot configuration (audited)

#
Table
DeviceEvents

Description

ASR Safe mode reboot configuration (audited). Block-mode ASR sibling maps to Defender-1121.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrSafeModeRebootBlocked: ASR Safe mode reboot configuration (blocked)

#
Table
DeviceEvents

Description

ASR Safe mode reboot configuration (blocked). Audit-mode ASR sibling maps to Defender-1122.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrSafeModeRebootWarnBypassed: ASR Safe mode reboot configuration (warn bypassed)

#
Table
DeviceEvents

Description

ASR Safe mode reboot configuration (warn bypassed). Defender ASR user-override event; no ETW-channel equivalent.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrScriptExecutableDownloadAudited: ASR script launching downloaded executable (audited)

#
Table
DeviceEvents

Description

ASR script launching downloaded executable (audited). Block-mode ASR sibling maps to Defender-1121.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

AsrScriptExecutableDownloadBlocked: ASR script launching downloaded executable (blocked)

#
Table
DeviceEvents

Description

ASR script launching downloaded executable (blocked). Audit-mode ASR sibling maps to Defender-1122.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

AsrScriptExecutableDownloadWarnBypassed: ASR script launching downloaded executable (warn bypassed)

#
Table
DeviceEvents

Description

ASR script launching downloaded executable (warn bypassed). Defender ASR user-override event; no ETW-channel equivalent.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

AsrUntrustedExecutableBlocked: ASR untrusted executable (blocked)

#
Table
DeviceEvents

Description

ASR untrusted executable (blocked). Audit-mode ASR sibling maps to Defender-1122.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

AsrUntrustedExecutableWarnBypassed: ASR untrusted executable (warn bypassed)

#
Table
DeviceEvents

Description

ASR untrusted executable (warn bypassed). Defender ASR user-override event; no ETW-channel equivalent.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

AsrUntrustedUsbProcessAudited: ASR untrusted process from USB (audited)

#
Table
DeviceEvents

Description

ASR untrusted process from USB (audited). Block-mode ASR sibling maps to Defender-1121.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrUntrustedUsbProcessBlocked: ASR untrusted process from USB (blocked)

#
Table
DeviceEvents

Description

ASR untrusted process from USB (blocked). Audit-mode ASR sibling maps to Defender-1122.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrUntrustedUsbProcessWarnBypassed: ASR untrusted process from USB (warn bypassed)

#
Table
DeviceEvents

Description

ASR untrusted process from USB (warn bypassed). Defender ASR user-override event; no ETW-channel equivalent.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrVulnerableSignedDriverAudited: ASR vulnerable signed driver (audited)

#
Table
DeviceEvents

Description

ASR vulnerable signed driver (audited). Block-mode ASR sibling maps to Defender-1121.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrVulnerableSignedDriverBlocked: ASR vulnerable signed driver (blocked)

#
Table
DeviceEvents

Description

ASR vulnerable signed driver (blocked). Audit-mode ASR sibling maps to Defender-1122.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrVulnerableSignedDriverWarnBypassed: ASR vulnerable signed driver (warn bypassed)

#
Table
DeviceEvents

Description

ASR vulnerable signed driver (warn bypassed). Defender ASR user-override event; no ETW-channel equivalent.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

AsrWebShellOnServerAudited: ASR webshell creation on Windows Server (audited)

#
Table
DeviceEvents

Description

ASR webshell creation on Windows Server (audited). Block-mode ASR sibling maps to Defender-1121.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

AsrWebShellOnServerBlocked: ASR webshell creation on Windows Server (blocked)

#
Table
DeviceEvents

Description

ASR webshell creation on Windows Server (blocked). Audit-mode ASR sibling maps to Defender-1122.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

AsrWebShellWarnBypassed: ASR webshell creation (warn bypassed)

#
Table
DeviceEvents

Description

ASR webshell creation (warn bypassed). Defender ASR user-override event; no ETW-channel equivalent.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

AppControlAppInstallationAudited: AppControl app installation (audited)

#
Table
DeviceEvents

Description

AppControl app installation (audited). AppLocker packaged-install audit channel records the same decision.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
SHA1
SHA256
AdditionalFields
InitiatingProcessFileName

References #

AppControlAppInstallationBlocked: AppControl app installation (blocked)

#
Table
DeviceEvents

Description

AppControl app installation (blocked). AppLocker packaged-install block channel records the same decision.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
SHA1
SHA256
AdditionalFields
InitiatingProcessFileName

References #

AppControlCIScriptAudited: AppControl Config CI script (audited)

#
Table
DeviceEvents

Description

AppControl Config CI script (audited). CI here is the Lockdown Policy script enforcement; AppLocker 8028 records the audit-channel sibling.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
SHA1
SHA256
AdditionalFields
InitiatingProcessFileName

References #

AppControlCIScriptBlocked: AppControl Config CI script (blocked)

#
Table
DeviceEvents

Description

AppControl Config CI script (blocked). Lockdown Policy script block surfaces in the AppLocker channel as 8029.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
SHA1
SHA256
AdditionalFields
InitiatingProcessFileName

References #

AppControlCodeIntegrityDriverRevoked: AppControl Code Integrity driver revoked

#
Table
DeviceEvents

Description

AppControl Code Integrity driver revoked. CodeIntegrity 3023 records a revoked driver load on the kernel side.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
SHA1
SHA256
AdditionalFields
InitiatingProcessFileName

References #

AppControlCodeIntegrityImageAudited: AppControl Code Integrity image (audited)

#
Table
DeviceEvents

Description

AppControl Code Integrity image (audited). CodeIntegrity 3076 records the user-image audit decision.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
SHA1
SHA256
AdditionalFields
InitiatingProcessFileName

References #

AppControlCodeIntegrityImageRevoked: AppControl Code Integrity image revoked

#
Table
DeviceEvents

Description

AppControl Code Integrity image revoked. User-image revocations surface as 3077; driver-side revocations surface as 3023.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
SHA1
SHA256
AdditionalFields
InitiatingProcessFileName

References #

AppControlCodeIntegrityOriginAllowed: AppControl Code Integrity origin allowed

#
Table
DeviceEvents

Description

AppControl Code Integrity origin allowed. Intelligent Security Graph reputation lookup; no Windows-native ETW source records a good-reputation allow.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
SHA1
SHA256
AdditionalFields
InitiatingProcessFileName

References #

AppControlCodeIntegrityOriginAudited: AppControl Code Integrity origin (audited)

#
Table
DeviceEvents

Description

AppControl Code Integrity origin (audited). Intelligent Security Graph reputation audit; no Windows-native ETW source.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
SHA1
SHA256
AdditionalFields
InitiatingProcessFileName

References #

AppControlCodeIntegrityOriginBlocked: AppControl Code Integrity origin (blocked)

#
Table
DeviceEvents

Description

AppControl Code Integrity origin (blocked). Derivable-from, not one-to-one: the ISG bad-reputation decision surfaces as a generic CI policy block 3077; the reputation rationale is not in ETW.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
SHA1
SHA256
AdditionalFields
InitiatingProcessFileName

References #

AppControlCodeIntegrityPolicyAudited: AppControl Code Integrity policy (audited)

#
Table
DeviceEvents

Description

AppControl Code Integrity policy (audited). CodeIntegrity 3076 records the user-image policy audit decision.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
SHA1
SHA256
AdditionalFields
InitiatingProcessFileName

References #

AppControlCodeIntegrityPolicyBlocked: AppControl Code Integrity policy (blocked)

#
Table
DeviceEvents

Description

AppControl Code Integrity policy (blocked). CodeIntegrity 3077 records the user-image policy block decision.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
SHA1
SHA256
AdditionalFields
InitiatingProcessFileName

References #

AppControlCodeIntegrityPolicyLoaded: AppControl Code Integrity policy loaded

#
Table
DeviceEvents

Description

AppControl Code Integrity policy loaded. CodeIntegrity 3099 records a successful policy refresh.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

AppControlCodeIntegritySigningInformation: AppControl Code Integrity signing information

#
Table
DeviceEvents

Description

AppControl Code Integrity signing information. 3089 carries signer detail for a paired CodeIntegrity decision event.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
SHA1
SHA256
AdditionalFields
InitiatingProcessFileName

References #

AppControlExecutableAudited: AppControl executable (audited)

#
Table
DeviceEvents

Description

AppControl executable (audited). Smart App Control system execution policy audit surfaces in AppLocker as 8041.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
SHA1
SHA256
AdditionalFields
InitiatingProcessFileName

References #

AppControlExecutableBlocked: AppControl executable (blocked)

#
Table
DeviceEvents

Description

AppControl executable (blocked). 8042 carries the block decision; 8045 carries Smart App Control block detail.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
SHA1
SHA256
AdditionalFields
InitiatingProcessFileName

References #

AppControlPackagedAppAudited: AppControl packaged app (audited)

#
Table
DeviceEvents

Description

AppControl packaged app (audited). AppLocker packaged-install audit 8024 records the same decision.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
SHA1
SHA256
AdditionalFields
InitiatingProcessFileName

References #

AppControlPackagedAppBlocked: AppControl packaged app (blocked)

#
Table
DeviceEvents

Description

AppControl packaged app (blocked). AppLocker packaged-install block 8025 records the same decision.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
SHA1
SHA256
AdditionalFields
InitiatingProcessFileName

References #

AppControlPolicyApplied: AppControl policy applied

#
Table
DeviceEvents

Description

AppControl policy applied. CodeIntegrity 3099 records a successful policy refresh on the host.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

AppControlScriptAudited: AppControl script (audited)

#
Table
DeviceEvents

Description

AppControl script (audited). AppLocker 8028 records the Config CI script audit decision.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
SHA1
SHA256
AdditionalFields
InitiatingProcessFileName

References #

AppControlScriptBlocked: AppControl script (blocked)

#
Table
DeviceEvents

Description

AppControl script (blocked). AppLocker 8029 records the Config CI script block decision.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
SHA1
SHA256
AdditionalFields
InitiatingProcessFileName

References #

AppGuardBrowseToUrl: Application Guard browse to URL

#
Table
DeviceEvents

Description

Application Guard browse to URL. Defender Application Guard isolation telemetry; no Windows-native ETW source in the catalog.

Fields #

NameDescription
DeviceId
Timestamp
AppGuardContainerId
RemoteUrl
InitiatingProcessFileName

References #

AppGuardCreateContainer: Application Guard container created

#
Table
DeviceEvents

Description

Application Guard container created. Defender Application Guard isolation telemetry; no Windows-native ETW source in the catalog.

Fields #

NameDescription
DeviceId
Timestamp
AppGuardContainerId
InitiatingProcessFileName

References #

AppGuardLaunchedWithUrl: Application Guard launched with URL

#
Table
DeviceEvents

Description

Application Guard launched with URL. Defender Application Guard isolation telemetry; no Windows-native ETW source in the catalog.

Fields #

NameDescription
DeviceId
Timestamp
AppGuardContainerId
RemoteUrl
InitiatingProcessFileName

References #

AppGuardResumeContainer: Application Guard container resumed

#
Table
DeviceEvents

Description

Application Guard container resumed. Defender Application Guard isolation telemetry; no Windows-native ETW source in the catalog.

Fields #

NameDescription
DeviceId
Timestamp
AppGuardContainerId
InitiatingProcessFileName

References #

AppGuardStopContainer: Application Guard container stopped

#
Table
DeviceEvents

Description

Application Guard container stopped. Defender Application Guard isolation telemetry; no Windows-native ETW source in the catalog.

Fields #

NameDescription
DeviceId
Timestamp
AppGuardContainerId
InitiatingProcessFileName

References #

AppGuardSuspendContainer: Application Guard container suspended

#
Table
DeviceEvents

Description

Application Guard container suspended. Defender Application Guard isolation telemetry; no Windows-native ETW source in the catalog.

Fields #

NameDescription
DeviceId
Timestamp
AppGuardContainerId
InitiatingProcessFileName

References #

AppLockerBlockExecutable: AppLocker blocked executable

#
Table
DeviceEvents

Description

AppLocker blocked executable. AppLocker EXE-and-DLL channel 8004 records the same block decision.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
InitiatingProcessFileName

References #

AppLockerBlockPackagedApp: AppLocker blocked packaged app

#
Table
DeviceEvents

Description

AppLocker blocked packaged app. AppLocker packaged-app channel 8022 records the same block decision.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
InitiatingProcessFileName

References #

AppLockerBlockPackagedAppInstallation: AppLocker blocked packaged app installation

#
Table
DeviceEvents

Description

AppLocker blocked packaged app installation. AppLocker packaged-install channel 8025 records the same block decision.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
InitiatingProcessFileName

References #

AppLockerBlockScript: AppLocker blocked script

#
Table
DeviceEvents

Description

AppLocker blocked script. AppLocker writes script blocks to the MSI and Script channel.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
InitiatingProcessFileName

References #

ControlFlowGuardViolation: Control Flow Guard violation

#
Table
DeviceEvents

Description

Control Flow Guard violation. CFG enforcement is in-process and surfaces as process termination; kernel ROP/CFG triggers raise shadow-stack mismatch event 33. Derivable-from, not one-to-one.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
AdditionalFields

References #

ExploitGuardAcgAudited: Exploit Guard ACG (audited)

#
Table
DeviceEvents

Description

Exploit Guard ACG (audited)

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

ExploitGuardAcgEnforced: Exploit Guard ACG (blocked)

#
Table
DeviceEvents

Description

Exploit Guard ACG (blocked)

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

ExploitGuardChildProcessAudited: Exploit Guard child process (audited)

#
Table
DeviceEvents

Description

Exploit Guard child process (audited)

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

ExploitGuardChildProcessBlocked: Exploit Guard child process (blocked)

#
Table
DeviceEvents

Description

Exploit Guard child process (blocked)

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

ExploitGuardEafViolationAudited: Exploit Guard EAF violation (audited)

#
Table
DeviceEvents

Description

Exploit Guard EAF violation (audited). UserMode channel.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

ExploitGuardEafViolationBlocked: Exploit Guard EAF violation (blocked)

#
Table
DeviceEvents

Description

Exploit Guard EAF violation (blocked). UserMode channel.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

ExploitGuardIafViolationAudited: Exploit Guard IAF violation (audited)

#
Table
DeviceEvents

Description

Exploit Guard IAF violation (audited). UserMode channel.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

ExploitGuardIafViolationBlocked: Exploit Guard IAF violation (blocked)

#
Table
DeviceEvents

Description

Exploit Guard IAF violation (blocked). UserMode channel.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

ExploitGuardLowIntegrityImageAudited: Exploit Guard low-integrity image (audited)

#
Table
DeviceEvents

Description

Exploit Guard low-integrity image (audited)

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

ExploitGuardLowIntegrityImageBlocked: Exploit Guard low-integrity image (blocked)

#
Table
DeviceEvents

Description

Exploit Guard low-integrity image (blocked)

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

ExploitGuardNetworkProtectionAudited: Exploit Guard Network Protection (audited)

#
Table
DeviceEvents

Description

Exploit Guard Network Protection (audited). Network Protection engine writes to Defender-1126; URL detail is in Defender-engine logs, not the DeviceEvents action. Derivable-from, not one-to-one.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
RemoteUrl
RemoteIP
AdditionalFields

References #

ExploitGuardNetworkProtectionBlocked: Exploit Guard Network Protection (blocked)

#
Table
DeviceEvents

Description

Exploit Guard Network Protection (blocked). Network Protection engine writes to Defender-1125; URL detail is in Defender-engine logs. Derivable-from, not one-to-one.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
RemoteUrl
RemoteIP
AdditionalFields

References #

ExploitGuardNonMicrosoftSignedAudited: Exploit Guard non-Microsoft signed image (audited)

#
Table
DeviceEvents

Description

Exploit Guard non-Microsoft signed image (audited)

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

ExploitGuardNonMicrosoftSignedBlocked: Exploit Guard non-Microsoft signed image (blocked)

#
Table
DeviceEvents

Description

Exploit Guard non-Microsoft signed image (blocked)

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

ExploitGuardRopExploitAudited: Exploit Guard ROP exploit (audited)

#
Table
DeviceEvents

Description

Exploit Guard ROP exploit (audited). UserMode channel; hooked-API audit covers ROP detection.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

ExploitGuardRopExploitBlocked: Exploit Guard ROP exploit (blocked)

#
Table
DeviceEvents

Description

Exploit Guard ROP exploit (blocked). UserMode channel; hooked-API block covers ROP enforcement.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

ExploitGuardSharedBinaryAudited: Exploit Guard shared binary load (audited)

#
Table
DeviceEvents

Description

Exploit Guard shared binary load (audited). Image-load audit covers UNC and shared-path loads.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

ExploitGuardSharedBinaryBlocked: Exploit Guard shared binary load (blocked)

#
Table
DeviceEvents

Description

Exploit Guard shared binary load (blocked). Image-load block covers UNC and shared-path loads.

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

ExploitGuardWin32SystemCallAudited: Exploit Guard Win32k system-call (audited)

#
Table
DeviceEvents

Description

Exploit Guard Win32k system-call (audited)

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

ExploitGuardWin32SystemCallBlocked: Exploit Guard Win32k system-call (blocked)

#
Table
DeviceEvents

Description

Exploit Guard Win32k system-call (blocked)

Fields #

NameDescription
DeviceId
Timestamp
InitiatingProcessFileName
FileName
FolderPath
AdditionalFields

References #

AntivirusDefinitionsUpdateFailed: Antivirus definitions update failed

#
Table
DeviceEvents

Description

Antivirus definitions update failed

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields

References #

AntivirusDefinitionsUpdated: Antivirus definitions updated

#
Table
DeviceEvents

Description

Antivirus definitions updated

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields

References #

AntivirusDetection: Antivirus detection

#
Table
DeviceEvents

Description

Antivirus detection. Defender-1006 is the legacy ID; 1116 is the modern equivalent.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
SHA1
SHA256
InitiatingProcessFileName
AdditionalFields

References #

AntivirusEmergencyUpdatesInstalled: Antivirus emergency updates installed

#
Table
DeviceEvents

Description

Antivirus emergency updates installed. Emergency updates use the same 2000 event with elevated priority.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields

References #

AntivirusError: Antivirus error

#
Table
DeviceEvents

Description

Antivirus error

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields

References #

AntivirusMalwareActionFailed: Antivirus malware action failed

#
Table
DeviceEvents

Description

Antivirus malware action failed

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
SHA1
SHA256
AdditionalFields

References #

AntivirusMalwareBlocked: Antivirus malware blocked

#
Table
DeviceEvents

Description

Antivirus malware blocked

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
SHA1
SHA256
InitiatingProcessFileName
AdditionalFields

References #

AntivirusScanCancelled: Antivirus scan cancelled

#
Table
DeviceEvents

Description

Antivirus scan cancelled

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields

References #

AntivirusScanCompleted: Antivirus scan completed

#
Table
DeviceEvents

Description

Antivirus scan completed

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields

References #

AntivirusScanFailed: Antivirus scan failed

#
Table
DeviceEvents

Description

Antivirus scan failed

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields

References #

AntivirusTroubleshootModeEvent: Antivirus troubleshoot mode state change

#
Table
DeviceEvents

Description

Antivirus troubleshoot mode state change. Troubleshoot mode is a configuration state change; the closest Defender-Operational event is 5007 (configuration changed). Derivable-from, not one-to-one.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields

References #

ControlledFolderAccessViolationAudited: Controlled folder access violation (audited)

#
Table
DeviceEvents

Description

Controlled folder access violation (audited)

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
InitiatingProcessFileName
InitiatingProcessCommandLine

References #

ControlledFolderAccessViolationBlocked: Controlled folder access violation (blocked)

#
Table
DeviceEvents

Description

Controlled folder access violation (blocked)

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
InitiatingProcessFileName
InitiatingProcessCommandLine

References #

FirewallInboundConnectionBlocked: Firewall inbound connection blocked

#
Table
DeviceEvents

Description

Firewall inbound connection blocked. WFP packet drop; Security-5152 fires for all inbound blocks at the filtering layer.

Fields #

NameDescription
DeviceId
Timestamp
RemoteIP
RemotePort
LocalIP
LocalPort
InitiatingProcessFileName
AdditionalFields

References #

FirewallInboundConnectionToAppBlocked: Firewall inbound connection to app blocked

#
Table
DeviceEvents

Description

Firewall inbound connection to app blocked. Same WFP event as inbound block; app-specific filter target is the differentiator in the action payload.

Fields #

NameDescription
DeviceId
Timestamp
RemoteIP
RemotePort
LocalIP
LocalPort
InitiatingProcessFileName
AdditionalFields

References #

FirewallOutboundConnectionBlocked: Firewall outbound connection blocked

#
Table
DeviceEvents

Description

Firewall outbound connection blocked

Fields #

NameDescription
DeviceId
Timestamp
RemoteIP
RemotePort
LocalIP
LocalPort
InitiatingProcessFileName
AdditionalFields

References #

FirewallServiceStopped: Firewall service stopped

#
Table
DeviceEvents

Description

Firewall service stopped. Firewall service state change; derivable-from, not one-to-one. The MDE sensor inference also rides the service-control surface.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields

References #

NetworkProtectionUserBypassEvent: Network protection user bypass

#
Table
DeviceEvents

Description

Network protection user bypass. Defender-1129 records user-allowed Exploit Guard bypass and covers the same user-initiated override. Derivable-from, not one-to-one.

Fields #

NameDescription
DeviceId
Timestamp
RemoteUrl
InitiatingProcessFileName
AdditionalFields

References #

NetworkShareObjectAccessChecked: Network share object access checked

#
Table
DeviceEvents

Description

Network share object access checked

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
AccountName
AccountDomain
AdditionalFields

References #

NetworkShareObjectAdded: Network share object added

#
Table
DeviceEvents

Description

Network share object added

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
AccountName
AccountDomain
AdditionalFields

References #

NetworkShareObjectDeleted: Network share object deleted

#
Table
DeviceEvents

Description

Network share object deleted

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
AccountName
AccountDomain
AdditionalFields

References #

NetworkShareObjectModified: Network share object modified

#
Table
DeviceEvents

Description

Network share object modified

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
AccountName
AccountDomain
AdditionalFields

References #

SmartScreenAppWarning: SmartScreen app warning

#
Table
DeviceEvents

Description

SmartScreen app warning. SmartScreen-1000 is the app-warn signal; URL and reputation detail live in the engine, not the ETW payload. Engine-side decision; derivable-from, not one-to-one.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
SHA1
SHA256
InitiatingProcessFileName
AdditionalFields

References #

SmartScreenExploitWarning: SmartScreen exploit warning

#
Table
DeviceEvents

Description

SmartScreen exploit warning. SmartScreen-1001 is the exploit-warn signal; same caveat as SmartScreen-1000. Engine-side decision; derivable-from, not one-to-one.

Fields #

NameDescription
DeviceId
Timestamp
RemoteUrl
InitiatingProcessFileName
AdditionalFields

References #

SmartScreenUrlWarning: SmartScreen URL warning

#
Table
DeviceEvents

Description

SmartScreen URL warning. SmartScreen-1002 is the URL-warn signal; URL string in the action payload, reputation context in the engine. Derivable-from, not one-to-one.

Fields #

NameDescription
DeviceId
Timestamp
RemoteUrl
InitiatingProcessFileName
AdditionalFields

References #

SmartScreenUserOverride: SmartScreen user override

#
Table
DeviceEvents

Description

SmartScreen user override. SmartScreen-1003 records the user-initiated override; engine-side decision context not in the ETW payload.

Fields #

NameDescription
DeviceId
Timestamp
RemoteUrl
FileName
InitiatingProcessFileName
AdditionalFields

References #

AccountCheckedForBlankPassword: Account checked for blank password

#
Table
DeviceEvents

Description

Account checked for blank password. MDE engine inference; no ETW source.

Fields #

NameDescription
DeviceId
Timestamp
AccountName
AccountDomain
AccountSid
AdditionalFields
InitiatingProcessFileName

References #

AuditPolicyModification: Audit policy modified

#
Table
DeviceEvents

Description

Audit policy modified. Security 4719 records system audit policy changes.

Fields #

NameDescription
DeviceId
Timestamp
AccountName
AccountDomain
AccountSid
AdditionalFields
InitiatingProcessFileName

References #

BitLockerAuditCompleted: BitLocker audit completed

#
Table
DeviceEvents

Description

BitLocker audit completed. MDE-side BitLocker audit summary; no native equivalent.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

BluetoothPolicyTriggered: Bluetooth policy triggered

#
Table
DeviceEvents

Description

Bluetooth policy triggered. Device-control policy; MDE engine only.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

BrowserLaunchedToOpenUrl: Browser launched to open URL

#
Table
DeviceEvents

Description

Browser launched to open URL. MDE sensor URL-handler interception; no Windows-native equivalent.

Fields #

NameDescription
DeviceId
Timestamp
RemoteUrl
AdditionalFields
InitiatingProcessFileName

References #

BruteForceActivityDetected: Brute force activity detected

#
Table
DeviceEvents

Description

Brute force activity detected. MDE engine inference over 4625 patterns; no single ETW event.

Fields #

NameDescription
DeviceId
Timestamp
AccountName
AccountDomain
RemoteIP
AdditionalFields

References #

CertificateServicesApprovedCertificateRequest: Certificate Services approved certificate request

#
Table
DeviceEvents

Description

Certificate Services approved certificate request. CA server-side; Security audit captures the same approval on the CA host.

Fields #

NameDescription
DeviceId
Timestamp
AccountName
AccountDomain
AccountSid
AdditionalFields
InitiatingProcessFileName

References #

CertificateServicesLoadedTemplate: Certificate Services loaded template

#
Table
DeviceEvents

Description

Certificate Services loaded template. Security 4898 records template load on the CA host.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

CertificateServicesReceivedCertificateRequest: Certificate Services received certificate request

#
Table
DeviceEvents

Description

Certificate Services received certificate request. Security 4886 records the inbound request on the CA host.

Fields #

NameDescription
DeviceId
Timestamp
AccountName
AccountDomain
AccountSid
AdditionalFields
InitiatingProcessFileName

References #

CredentialsBackup: Credentials backed up

#
Table
DeviceEvents

Description

Credentials backed up. Credential Manager backup UX action; MDE-only.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

DeviceBootAttestationInfo: Device boot attestation info

#
Table
DeviceEvents

Description

Device boot attestation info. Windows Defender System Guard attestation; MDE-only.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

DirectoryServiceObjectCreated: Directory Service object created

#
Table
DeviceEvents

Description

Directory Service object created. Security 5137 records DS object creation on the domain controller.

Fields #

NameDescription
DeviceId
Timestamp
AccountName
AccountDomain
AccountSid
AdditionalFields
InitiatingProcessFileName

References #

DirectoryServiceObjectModified: Directory Service object modified

#
Table
DeviceEvents

Description

Directory Service object modified. Security 5136 records DS object modification on the domain controller.

Fields #

NameDescription
DeviceId
Timestamp
AccountName
AccountDomain
AccountSid
AdditionalFields
InitiatingProcessFileName

References #

DnsQueryResponse: DNS query response

#
Table
DeviceEvents

Description

DNS query response. DeviceEvents covers query/response pairs MDE selects as interesting; Sysmon-22 is the broader client query stream. Microsoft-Windows-DNS-Client trace logging covers the OS view but is not enabled by default.

Fields #

NameDescription
DeviceId
Timestamp
RemoteUrl
RemoteIP
RemotePort
LocalIP
LocalPort
InitiatingProcessFileName

References #

DpapiAccessed: DPAPI accessed

#
Table
DeviceEvents

Description

DPAPI accessed. Defender-only; closest analog is Microsoft-Windows-Crypto-DPAPI ETW but the MDE sensor decision criterion is not surfaced there.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

ExternalDeviceConnected: External device connected

#
Table
DeviceEvents

Description

External device connected. Generic peripheral connect; Kernel-PnP covers the install side. Derivable-from, not one-to-one.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

ExternalDeviceDisconnected: External device disconnected

#
Table
DeviceEvents

Description

External device disconnected. Generic peripheral disconnect; Kernel-PnP-440 covers the removal side. Derivable-from, not one-to-one.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

FileTimestampModificationEvent: File timestamp modified

#
Table
DeviceEvents

Description

File timestamp modified. MDE sensor minifilter; no Windows-native equivalent.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
SHA1
InitiatingProcessFileName

References #

GetAsyncKeyStateApiCall: GetAsyncKeyState API call

#
Table
DeviceEvents

Description

GetAsyncKeyState API call. Win32k-1003 is the kernel-side GetAsyncKeyState audit; the Defender Win32k filter forwards selected invocations. Derivable-from, not one-to-one.

Fields #

NameDescription
DeviceId
Timestamp
ProcessId
InitiatingProcessFileName
InitiatingProcessCommandLine

References #

GetClipboardData: GetClipboardData API call

#
Table
DeviceEvents

Description

GetClipboardData API call. User32 GetClipboardData has no kernel-side ETW audit comparable to the keystate audit; MDE sensor hooks user-mode API.

Fields #

NameDescription
DeviceId
Timestamp
ProcessId
InitiatingProcessFileName
InitiatingProcessCommandLine

References #

LogonRightsSettingEnabled: Logon rights setting enabled

#
Table
DeviceEvents

Description

Logon rights setting enabled. Security 4717 records logon right grant.

Fields #

NameDescription
DeviceId
Timestamp
AccountName
AccountDomain
AccountSid
AdditionalFields
InitiatingProcessFileName

References #

NtAllocateVirtualMemoryApiCall: NtAllocateVirtualMemory API call

#
Table
DeviceEvents

Description

NtAllocateVirtualMemory API call. ETW-TI 6 is KERNEL_THREATINT_TASK_ALLOCVM local-process; PPL-AntiMalware-gated. The remote-process sibling NtAllocateVirtualMemoryRemoteApiCall maps to TI-1.

Fields #

NameDescription
DeviceId
Timestamp
ProcessId
InitiatingProcessFileName
InitiatingProcessCommandLine

Detection Rules #

View all rules referencing this event →

Kusto #

References #

NtProtectVirtualMemoryApiCall: NtProtectVirtualMemory API call

#
Table
DeviceEvents

Description

NtProtectVirtualMemory API call. ETW-TI 7 is KERNEL_THREATINT_TASK_PROTECTVM local-process; PPL-AntiMalware-gated. Remote-process counterpart maps to TI-2.

Fields #

NameDescription
DeviceId
Timestamp
ProcessId
InitiatingProcessFileName
InitiatingProcessCommandLine

References #

PTraceDetected: PTrace detected

#
Table
DeviceEvents

Description

PTrace detected. Linux-context AT; no Windows analog.

Fields #

NameDescription
DeviceId
Timestamp
ProcessId
InitiatingProcessFileName
InitiatingProcessCommandLine

References #

PasswordChangeAttempt: Password change attempt

#
Table
DeviceEvents

Description

Password change attempt. Defender-only; Security 4723/4724 only fire after successful change.

Fields #

NameDescription
DeviceId
Timestamp
AccountName
AccountDomain
AccountSid
AdditionalFields
InitiatingProcessFileName

References #

PlistPropertyModified: Plist property modified

#
Table
DeviceEvents

Description

Plist property modified. macOS/iOS plist; sensor-only on Windows context (no equivalent).

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

PnpDeviceAllowed: PnP device allowed

#
Table
DeviceEvents

Description

PnP device allowed. Kernel-PnP covers driver install; device-control policy allow decisions are visible in the install lifecycle but tagged differently in DeviceEvents. Derivable-from, not one-to-one.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

PnpDeviceBlocked: PnP device blocked

#
Table
DeviceEvents

Description

PnP device blocked. Driver install failures surface here for policy-blocked devices; the policy reason is not in the ETW payload. Derivable-from, not one-to-one.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

PnpDeviceConnected: PnP device connected

#
Table
DeviceEvents

Description

PnP device connected. Kernel-PnP 410 captures all device install activity.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

PrintJobBlocked: Print job blocked

#
Table
DeviceEvents

Description

Print job blocked. Device-control policy; MDE engine only.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

ProcessCreatedUsingWmiQuery: Process created using WMI query

#
Table
DeviceEvents

Description

Process created using WMI query. WMI provider start fires for every consumer; Sysmon-1 with ParentImage=WmiPrvSE.exe is the derivable view of WMI-spawned processes. Derivable-from, not one-to-one.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

ReadProcessMemoryApiCall: ReadProcessMemory API call

#
Table
DeviceEvents

Description

ReadProcessMemory API call. ETW-TI 11 is KERNEL_THREATINT_TASK_READVM local-process; PPL-AntiMalware-gated. Cross-process reads emit TI-13 (READVM remote).

Fields #

NameDescription
DeviceId
Timestamp
ProcessId
InitiatingProcessFileName
InitiatingProcessCommandLine

Detection Rules #

View all rules referencing this event →

Kusto #

References #

RemoteDesktopConnection: Remote Desktop connection

#
Table
DeviceEvents

Description

Remote Desktop connection. RDP session establishment; LogonType=10 in 4624 is the canonical signal. Microsoft-Windows-TerminalServices-RemoteConnectionManager carries the session-broker side.

Fields #

NameDescription
DeviceId
Timestamp
AccountName
AccountDomain
RemoteIP
AdditionalFields

References #

RemoteWmiOperation: Remote WMI operation

#
Table
DeviceEvents

Description

Remote WMI operation. WMI-Activity covers provider start; the MDE sensor adds remote-context attribution via session and authentication state. Derivable-from, not one-to-one.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

RemovableStorageFileEvent: Removable storage file event

#
Table
DeviceEvents

Description

Removable storage file event. Device-control policy decision; MDE engine only.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
SHA1
InitiatingProcessFileName

References #

RemovableStoragePolicyTriggered: Removable storage policy triggered

#
Table
DeviceEvents

Description

Removable storage policy triggered. Device-control policy decision; MDE engine only.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

SafeDocFileScan: Safe Documents file scanned

#
Table
DeviceEvents

Description

Safe Documents file scanned. Office Protected View cloud submission; MDE-only.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
SHA1
InitiatingProcessFileName

References #

ScheduledTaskDisabled: Scheduled task disabled

#
Table
DeviceEvents

Description

Scheduled task disabled. TaskScheduler-142 is the operational-channel record; Security-4701 is the audit-channel sibling.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

ScheduledTaskEnabled: Scheduled task enabled

#
Table
DeviceEvents

Description

Scheduled task enabled. TaskScheduler-140 is the operational-channel record; Security-4700 is the audit-channel sibling.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

ScreenshotTaken: Screenshot taken

#
Table
DeviceEvents

Description

Screenshot taken. DLP/Insider Risk screenshot capture; MDE-only.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

SecurityGroupCreated: Security group created

#
Table
DeviceEvents

Description

Security group created. Security 4727 records security global group creation.

Fields #

NameDescription
DeviceId
Timestamp
AccountName
AccountDomain
AccountSid
AdditionalFields
InitiatingProcessFileName

References #

SecurityGroupDeleted: Security group deleted

#
Table
DeviceEvents

Description

Security group deleted. Security 4730 records security global group deletion.

Fields #

NameDescription
DeviceId
Timestamp
AccountName
AccountDomain
AccountSid
AdditionalFields
InitiatingProcessFileName

References #

SecurityLogCleared: Security log cleared

#
Table
DeviceEvents

Description

Security log cleared. Security 1102 records audit log clearance.

Fields #

NameDescription
DeviceId
Timestamp
AccountName
AccountDomain
AccountSid
AdditionalFields
InitiatingProcessFileName

References #

SensitiveFileRead: Sensitive file read

#
Table
DeviceEvents

Description

Sensitive file read. DLP policy match; MDE-only.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
SHA1
InitiatingProcessFileName

References #

ServiceInstalled: Service installed

#
Table
DeviceEvents

Description

Service installed. Security-4697 requires the Security System Extension subcategory; System-7045 fires unconditionally.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

ShellLinkCreateFileEvent: Shell link (LNK) file created

#
Table
DeviceEvents

Description

Shell link (LNK) file created. Sysmon-11 covers LNK file create as a regular file-create; MDE flags the .lnk subset. Derivable-from, not one-to-one.

Fields #

NameDescription
DeviceId
Timestamp
FileName
FolderPath
SHA1
InitiatingProcessFileName

References #

TamperingAttempt: Tampering attempt

#
Table
DeviceEvents

Description

Tampering attempt. Defender-5013 records Tamper Protection state changes from the engine side. Derivable-from, not one-to-one.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

UntrustedWifiConnection: Untrusted Wi-Fi connection

#
Table
DeviceEvents

Description

Untrusted Wi-Fi connection. MDE-only inference over Wi-Fi profile state; no native event.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

UsbDriveDriveLetterChanged: USB drive letter changed

#
Table
DeviceEvents

Description

USB drive letter changed. MDE-only inference over Kernel-PnP and Mountpoint API; no single ETW event.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

UsbDriveMounted: USB drive mounted

#
Table
DeviceEvents

Description

USB drive mounted. Mount events are derivable from device-install activity; the OS view is in Kernel-PnP, MDE adds drive-letter and policy context. Derivable-from, not one-to-one.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

UsbDriveUnmounted: USB drive unmounted

#
Table
DeviceEvents

Description

USB drive unmounted. Removal events surface via Kernel-PnP 440; same caveat as UsbDriveMounted. Derivable-from, not one-to-one.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

UserAccountCreated: User account created

#
Table
DeviceEvents

Description

User account created. Security 4720 records user account creation.

Fields #

NameDescription
DeviceId
Timestamp
AccountName
AccountDomain
AccountSid
AdditionalFields
InitiatingProcessFileName

References #

UserAccountDeleted: User account deleted

#
Table
DeviceEvents

Description

User account deleted. Security 4726 records user account deletion.

Fields #

NameDescription
DeviceId
Timestamp
AccountName
AccountDomain
AccountSid
AdditionalFields
InitiatingProcessFileName

References #

UserAccountModified: User account modified

#
Table
DeviceEvents

Description

User account modified. Security 4738 records user account changes.

Fields #

NameDescription
DeviceId
Timestamp
AccountName
AccountDomain
AccountSid
AdditionalFields
InitiatingProcessFileName

References #

UserAccountPasswordResetAttempt: User account password reset attempt

#
Table
DeviceEvents

Description

User account password reset attempt. 4723 records self password change; 4724 records admin-initiated reset. Distinct actions, not sensor-equivalent.

Fields #

NameDescription
DeviceId
Timestamp
AccountName
AccountDomain
AccountSid
AdditionalFields
InitiatingProcessFileName

References #

WmiBindEventFilterToConsumer: WMI EventFilter bound to consumer

#
Table
DeviceEvents

Description

WMI EventFilter bound to consumer. Sysmon-21 and WMI-Activity-5861 both record the FilterToConsumerBinding registration.

Fields #

NameDescription
DeviceId
Timestamp
AdditionalFields
InitiatingProcessFileName

References #

WriteToLsassProcessMemory: Write to LSASS process memory

#
Table
DeviceEvents

Description

Write to LSASS process memory. ETW-TI 14 is KERNEL_THREATINT_TASK_WRITEVM remote-process (cross-process write to LSASS); LSASS-target filtering is downstream of the ETW source. PPL-AntiMalware-gated.

Fields #

NameDescription
DeviceId
Timestamp
ProcessId
InitiatingProcessFileName
InitiatingProcessCommandLine

References #