| (any) | Defender event | | Y | Y |
| AccountCheckedForBlankPassword | Account checked for blank password | | N | N |
| AmsiScriptContent | AMSI script content captured | | N | Y |
| AmsiScriptDetection | AMSI script detection | | Y | N |
| AntivirusDefinitionsUpdated | Antivirus definitions updated | | N | N |
| AntivirusDefinitionsUpdateFailed | Antivirus definitions update failed | | N | N |
| AntivirusDetection | Antivirus detection | | Y | N |
| AntivirusEmergencyUpdatesInstalled | Antivirus emergency updates installed | | N | N |
| AntivirusError | Antivirus error | | N | N |
| AntivirusMalwareActionFailed | Antivirus malware action failed | | N | N |
| AntivirusMalwareBlocked | Antivirus malware blocked | | N | N |
| AntivirusReport | Antivirus report | | Y | N |
| AntivirusScanCancelled | Antivirus scan cancelled | | Y | N |
| AntivirusScanCompleted | Antivirus scan completed | | Y | N |
| AntivirusScanFailed | Antivirus scan failed | | N | N |
| AntivirusTroubleshootModeEvent | Antivirus troubleshoot mode state change | | N | N |
| AppControlAppInstallationAudited | AppControl app installation (audited) | | N | N |
| AppControlAppInstallationBlocked | AppControl app installation (blocked) | | N | N |
| AppControlCIScriptAudited | AppControl Config CI script (audited) | | N | N |
| AppControlCIScriptBlocked | AppControl Config CI script (blocked) | | N | N |
| AppControlCodeIntegrityDriverRevoked | AppControl Code Integrity driver revoked | | N | N |
| AppControlCodeIntegrityImageAudited | AppControl Code Integrity image (audited) | | N | N |
| AppControlCodeIntegrityImageRevoked | AppControl Code Integrity image revoked | | N | N |
| AppControlCodeIntegrityOriginAllowed | AppControl Code Integrity origin allowed | | N | N |
| AppControlCodeIntegrityOriginAudited | AppControl Code Integrity origin (audited) | | N | N |
| AppControlCodeIntegrityOriginBlocked | AppControl Code Integrity origin (blocked) | | N | N |
| AppControlCodeIntegrityPolicyAudited | AppControl Code Integrity policy (audited) | | N | N |
| AppControlCodeIntegrityPolicyBlocked | AppControl Code Integrity policy (blocked) | | N | N |
| AppControlCodeIntegrityPolicyLoaded | AppControl Code Integrity policy loaded | | N | N |
| AppControlCodeIntegritySigningInformation | AppControl Code Integrity signing information | | Y | N |
| AppControlExecutableAudited | AppControl executable (audited) | | N | N |
| AppControlExecutableBlocked | AppControl executable (blocked) | | N | N |
| AppControlPackagedAppAudited | AppControl packaged app (audited) | | N | N |
| AppControlPackagedAppBlocked | AppControl packaged app (blocked) | | N | N |
| AppControlPolicyApplied | AppControl policy applied | | Y | N |
| AppControlScriptAudited | AppControl script (audited) | | N | N |
| AppControlScriptBlocked | AppControl script (blocked) | | N | N |
| AppGuardBrowseToUrl | Application Guard browse to URL | | N | N |
| AppGuardCreateContainer | Application Guard container created | | N | N |
| AppGuardLaunchedWithUrl | Application Guard launched with URL | | N | N |
| AppGuardResumeContainer | Application Guard container resumed | | N | N |
| AppGuardStopContainer | Application Guard container stopped | | N | N |
| AppGuardSuspendContainer | Application Guard container suspended | | N | N |
| AppLockerBlockExecutable | AppLocker blocked executable | | N | N |
| AppLockerBlockPackagedApp | AppLocker blocked packaged app | | N | N |
| AppLockerBlockPackagedAppInstallation | AppLocker blocked packaged app installation | | N | N |
| AppLockerBlockScript | AppLocker blocked script | | N | N |
| AsrAbusedSystemToolAudited | ASR copied or impersonated system tool (audited) | Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator. | Y | N |
| AsrAbusedSystemToolBlocked | ASR copied or impersonated system tool (blocked) | Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator. | Y | N |
| AsrAbusedSystemToolWarnBypassed | ASR copied or impersonated system tool (warn bypassed) | Windows-Defender Event ID 1129: A user has allowed a blocked Microsoft Defender Exploit Guard operation. | N | N |
| AsrAdobeReaderChildProcessAudited | ASR Adobe Reader child process (audited) | Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator. | N | N |
| AsrAdobeReaderChildProcessBlocked | ASR Adobe Reader child process (blocked) | Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator. | N | N |
| AsrAdobeReaderChildProcessWarnBypassed | ASR Adobe Reader child process (warn bypassed) | | N | N |
| AsrExecutableEmailContentAudited | ASR executable from email client (audited) | Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator. | N | N |
| AsrExecutableEmailContentBlocked | ASR executable from email client (blocked) | Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator. | N | N |
| AsrExecutableEmailContentWarnBypassed | ASR executable from email client (warn bypassed) | | N | N |
| AsrExecutableOfficeContentAudited | ASR Office app creating executable content (audited) | Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator. | N | N |
| AsrExecutableOfficeContentBlocked | ASR Office app creating executable content (blocked) | Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator. | N | N |
| AsrExecutableOfficeContentWarnBypassed | ASR Office app creating executable content (warn bypassed) | | N | N |
| AsrLsassCredentialTheftAudited | ASR: LSASS credential theft (audited) | Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator. | N | N |
| AsrLsassCredentialTheftBlocked | ASR LSASS credential theft (blocked) | Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator. | N | N |
| AsrLsassCredentialTheftWarnBypassed | ASR LSASS credential theft warn bypassed | | N | N |
| AsrObfuscatedScriptAudited | ASR obfuscated script execution (audited) | Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator. | N | N |
| AsrObfuscatedScriptBlocked | ASR obfuscated script execution (blocked) | Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator. | N | N |
| AsrObfuscatedScriptWarnBypassed | ASR obfuscated script execution (warn bypassed) | | N | N |
| AsrOfficeChildProcessAudited | ASR: Office child process (audited) | Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator. | N | N |
| AsrOfficeChildProcessBlocked | ASR Office app child process (blocked) | Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator. | N | N |
| AsrOfficeChildProcessWarnBypassed | ASR Office app child process (warn bypassed) | | N | N |
| AsrOfficeCommAppChildProcessAudited | ASR Office communication app child process (audited) | Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator. | N | N |
| AsrOfficeCommAppChildProcessBlocked | ASR Office communication app child process (blocked) | Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator. | N | N |
| AsrOfficeCommAppChildProcessWarnBypassed | ASR Office communication app child process (warn bypassed) | | N | N |
| AsrOfficeMacroWin32ApiCallsAudited | ASR Win32 API calls from Office macros (audited) | Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator. | N | N |
| AsrOfficeMacroWin32ApiCallsBlocked | ASR Win32 API calls from Office macros (blocked) | Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator. | N | N |
| AsrOfficeMacroWin32ApiCallsWarnBypassed | ASR Win32 API calls from Office macros (warn bypassed) | | N | N |
| AsrOfficeProcessInjectionAudited | ASR Office app code injection (audited) | Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator. | N | N |
| AsrOfficeProcessInjectionBlocked | ASR Office app code injection (blocked) | Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator. | N | N |
| AsrOfficeProcessInjectionWarnBypassed | ASR Office process injection warn bypassed | | N | N |
| AsrPersistenceThroughWmiAudited | ASR WMI event subscription persistence (audited) | Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator. | Y | N |
| AsrPersistenceThroughWmiBlocked | ASR WMI event subscription persistence (blocked) | Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator. | Y | N |
| AsrPersistenceThroughWmiWarnBypassed | ASR WMI event subscription persistence (warn bypassed) | | N | N |
| AsrPsexecWmiChildProcessAudited | ASR PsExec or WMI child process (audited) | Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator. | Y | N |
| AsrPsexecWmiChildProcessBlocked | ASR PsExec or WMI child process (blocked) | Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator. | Y | N |
| AsrPsexecWmiChildProcessWarnBypassed | ASR PsExec or WMI child process (warn bypassed) | | N | N |
| AsrRansomwareAudited | ASR ransomware activity (audited) | Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator. | N | N |
| AsrRansomwareBlocked | ASR ransomware activity (blocked) | Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator. | N | N |
| AsrRansomwareWarnBypassed | ASR ransomware activity (warn bypassed) | | N | N |
| AsrSafeModeRebootBlocked | ASR Safe mode reboot configuration (blocked) | Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator. | N | N |
| AsrSafeModeRebootedAudited | ASR Safe mode reboot configuration (audited) | Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator. | N | N |
| AsrSafeModeRebootWarnBypassed | ASR Safe mode reboot configuration (warn bypassed) | Windows-Defender Event ID 1129: A user has allowed a blocked Microsoft Defender Exploit Guard operation. | N | N |
| AsrScriptExecutableDownloadAudited | ASR script launching downloaded executable (audited) | Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator. | N | N |
| AsrScriptExecutableDownloadBlocked | ASR script launching downloaded executable (blocked) | Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator. | N | N |
| AsrScriptExecutableDownloadWarnBypassed | ASR script launching downloaded executable (warn bypassed) | | N | N |
| AsrUntrustedExecutableAudited | ASR untrusted executable (audited) | Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator. | N | Y |
| AsrUntrustedExecutableBlocked | ASR untrusted executable (blocked) | Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator. | N | Y |
| AsrUntrustedExecutableWarnBypassed | ASR untrusted executable (warn bypassed) | | N | N |
| AsrUntrustedUsbProcessAudited | ASR untrusted process from USB (audited) | Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator. | N | N |
| AsrUntrustedUsbProcessBlocked | ASR untrusted process from USB (blocked) | Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator. | N | N |
| AsrUntrustedUsbProcessWarnBypassed | ASR untrusted process from USB (warn bypassed) | | N | N |
| AsrVulnerableSignedDriverAudited | ASR vulnerable signed driver (audited) | Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator. | N | N |
| AsrVulnerableSignedDriverBlocked | ASR vulnerable signed driver (blocked) | Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator. | N | N |
| AsrVulnerableSignedDriverWarnBypassed | ASR vulnerable signed driver (warn bypassed) | | N | N |
| AsrWebShellOnServerAudited | ASR webshell creation on Windows Server (audited) | Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator. | N | N |
| AsrWebShellOnServerBlocked | ASR webshell creation on Windows Server (blocked) | Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator. | N | N |
| AsrWebShellWarnBypassed | ASR webshell creation (warn bypassed) | | N | N |
| AuditPolicyModification | Audit policy modified | | Y | N |
| BitLockerAuditCompleted | BitLocker audit completed | | N | N |
| BluetoothPolicyTriggered | Bluetooth policy triggered | | N | N |
| BrowserLaunchedToOpenUrl | Browser launched to open URL | | Y | Y |
| BruteForceActivityDetected | Brute force activity detected | | N | N |
| CertificateServicesApprovedCertificateRequest | Certificate Services approved certificate request | | Y | N |
| CertificateServicesLoadedTemplate | Certificate Services loaded template | | Y | N |
| CertificateServicesReceivedCertificateRequest | Certificate Services received certificate request | | Y | N |
| ClrUnbackedModuleLoaded | CLR unbacked module loaded | | Y | Y |
| ContainedUserLogonBlocked | Contained user logon blocked | | Y | N |
| ContainedUserRpcAccessBlocked | Contained user RPC access blocked | | Y | N |
| ContainedUserSmbFileOpenBlocked | Contained user SMB file open blocked | | Y | N |
| ControlFlowGuardViolation | Control Flow Guard violation | | N | N |
| ControlledFolderAccessViolationAudited | Controlled folder access violation (audited) | Windows-Defender Event ID 1124: ProcessName would have been blocked from modifying Path by Controlled Folder Access. | Y | N |
| ControlledFolderAccessViolationBlocked | Controlled folder access violation (blocked) | Windows-Defender Event ID 1123: ProcessName has been blocked from modifying Path by Controlled Folder Access. | N | N |
| CreateRemoteThreadApiCall | CreateRemoteThread API call | | Y | Y |
| CredentialsBackup | Credentials backed up | | N | N |
| DeviceBootAttestationInfo | Device boot attestation info | | N | N |
| DirectoryServiceObjectCreated | Directory Service object created | | Y | N |
| DirectoryServiceObjectModified | Directory Service object modified | | N | N |
| DnsQueryResponse | DNS query response | | Y | N |
| DpapiAccessed | DPAPI accessed | | Y | N |
| DriverLoad | Driver loaded | | Y | Y |
| ExploitGuardAcgAudited | Exploit Guard ACG (audited) | | Y | N |
| ExploitGuardAcgEnforced | Exploit Guard ACG (blocked) | | N | N |
| ExploitGuardChildProcessAudited | Exploit Guard child process (audited) | | Y | N |
| ExploitGuardChildProcessBlocked | Exploit Guard child process (blocked) | | N | N |
| ExploitGuardEafViolationAudited | Exploit Guard EAF violation (audited) | | N | N |
| ExploitGuardEafViolationBlocked | Exploit Guard EAF violation (blocked) | | N | N |
| ExploitGuardIafViolationAudited | Exploit Guard IAF violation (audited) | | N | N |
| ExploitGuardIafViolationBlocked | Exploit Guard IAF violation (blocked) | | N | N |
| ExploitGuardLowIntegrityImageAudited | Exploit Guard low-integrity image (audited) | | Y | N |
| ExploitGuardLowIntegrityImageBlocked | Exploit Guard low-integrity image (blocked) | | N | N |
| ExploitGuardNetworkProtectionAudited | Exploit Guard Network Protection (audited) | Windows-Defender Event ID 1125: Your IT administrator would have caused Microsoft Defender Exploit Guard to block a potentially dangerous network connection. | N | N |
| ExploitGuardNetworkProtectionBlocked | Exploit Guard Network Protection (blocked) | Windows-Defender Event ID 1126: Your IT administrator has caused Microsoft Defender Exploit Guard to block a potentially dangerous network connection. | N | N |
| ExploitGuardNonMicrosoftSignedAudited | Exploit Guard non-Microsoft signed image (audited) | | N | N |
| ExploitGuardNonMicrosoftSignedBlocked | Exploit Guard non-Microsoft signed image (blocked) | | Y | Y |
| ExploitGuardRopExploitAudited | Exploit Guard ROP exploit (audited) | | N | N |
| ExploitGuardRopExploitBlocked | Exploit Guard ROP exploit (blocked) | | N | N |
| ExploitGuardSharedBinaryAudited | Exploit Guard shared binary load (audited) | | N | N |
| ExploitGuardSharedBinaryBlocked | Exploit Guard shared binary load (blocked) | | N | N |
| ExploitGuardWin32SystemCallAudited | Exploit Guard Win32k system-call (audited) | | Y | N |
| ExploitGuardWin32SystemCallBlocked | Exploit Guard Win32k system-call (blocked) | | N | N |
| ExternalDeviceConnected | External device connected | | N | N |
| ExternalDeviceDisconnected | External device disconnected | | N | N |
| FileTimestampModificationEvent | File timestamp modified | | N | N |
| FirewallInboundConnectionBlocked | Firewall inbound connection blocked | | Y | N |
| FirewallInboundConnectionToAppBlocked | Firewall inbound connection to app blocked | | Y | N |
| FirewallOutboundConnectionBlocked | Firewall outbound connection blocked | | Y | N |
| FirewallServiceStopped | Firewall service stopped | | N | N |
| GetAsyncKeyStateApiCall | GetAsyncKeyState API call | | N | N |
| GetClipboardData | GetClipboardData API call | | N | N |
| LdapSearch | LDAP search | | Y | Y |
| LogonRightsSettingEnabled | Logon rights setting enabled | | N | N |
| MemoryRemoteProtect | Remote virtual memory protection change | | N | Y |
| NamedPipeEvent | Named pipe event | | Y | Y |
| NetworkProtectionUserBypassEvent | Network protection user bypass | | N | N |
| NetworkShareObjectAccessChecked | Network share object access checked | | N | N |
| NetworkShareObjectAdded | Network share object added | | N | N |
| NetworkShareObjectDeleted | Network share object deleted | | N | N |
| NetworkShareObjectModified | Network share object modified | | N | N |
| NtAllocateVirtualMemoryApiCall | NtAllocateVirtualMemory API call | | Y | Y |
| NtAllocateVirtualMemoryRemoteApiCall | Remote virtual memory allocation (NtAllocateVirtualMemory) | | Y | Y |
| NtMapViewOfSectionRemoteApiCall | Remote section map (NtMapViewOfSection) | | N | Y |
| NtProtectVirtualMemoryApiCall | NtProtectVirtualMemory API call | | Y | Y |
| OpenProcessApiCall | Process opened (OpenProcess API call) | | Y | Y |
| OtherAlertRelatedActivity | Other alert-related activity | | Y | N |
| PasswordChangeAttempt | Password change attempt | | N | N |
| PlistPropertyModified | Plist property modified | | N | N |
| PnpDeviceAllowed | PnP device allowed | | N | N |
| PnpDeviceBlocked | PnP device blocked | | N | N |
| PnpDeviceConnected | PnP device connected | | Y | N |
| PowerShellCommand | PowerShell command executed | | Y | Y |
| PrintJobBlocked | Print job blocked | | N | N |
| ProcessCreatedUsingWmiQuery | Process created using WMI query | | Y | N |
| ProcessPrimaryTokenModified | Process primary token modified | | Y | Y |
| PTraceDetected | PTrace detected | | N | N |
| QueueUserApcRemoteApiCall | Remote APC queued (QueueUserApc) | | N | Y |
| ReadProcessMemoryApiCall | ReadProcessMemory API call | | Y | Y |
| RemoteDesktopConnection | Remote Desktop connection | | N | N |
| RemoteWmiOperation | Remote WMI operation | | N | N |
| RemovableStorageFileEvent | Removable storage file event | | N | N |
| RemovableStoragePolicyTriggered | Removable storage policy triggered | | N | N |
| SafeDocFileScan | Safe Documents file scanned | | N | N |
| ScheduledTaskCreated | Scheduled task created | | Y | N |
| ScheduledTaskDeleted | Scheduled task deleted | | Y | N |
| ScheduledTaskDisabled | Scheduled task disabled | | N | N |
| ScheduledTaskEnabled | Scheduled task enabled | | N | N |
| ScheduledTaskUpdated | Scheduled task updated | | Y | N |
| ScreenshotTaken | Screenshot taken | | N | N |
| SecurityGroupCreated | Security group created | | Y | N |
| SecurityGroupDeleted | Security group deleted | | Y | N |
| SecurityLogCleared | Security log cleared | | Y | N |
| SensitiveFileRead | Sensitive file read | | N | N |
| ServiceInstalled | Service installed | | Y | N |
| SetThreadContextRemoteApiCall | Remote thread context change (SetThreadContext) | | N | Y |
| ShellLinkCreateFileEvent | Shell link (LNK) file created | | Y | N |
| SmartScreenAppWarning | SmartScreen app warning | | N | N |
| SmartScreenExploitWarning | SmartScreen exploit warning | | N | N |
| SmartScreenUrlWarning | SmartScreen URL warning | | N | N |
| SmartScreenUserOverride | SmartScreen user override | | N | N |
| TamperingAttempt | Tampering attempt | | Y | N |
| TvmAxonTelemetryEvent | Threat and vulnerability management telemetry | | Y | N |
| UntrustedWifiConnection | Untrusted Wi-Fi connection | | N | N |
| UsbDriveDriveLetterChanged | USB drive letter changed | | N | N |
| UsbDriveMounted | USB drive mounted | | Y | Y |
| UsbDriveUnmounted | USB drive unmounted | | N | N |
| UserAccountAddedToLocalGroup | User account added to local group | | Y | Y |
| UserAccountCreated | User account created | | Y | Y |
| UserAccountDeleted | User account deleted | | Y | N |
| UserAccountModified | User account modified | | Y | Y |
| UserAccountPasswordResetAttempt | User account password reset attempt | | Y | N |
| UserAccountRemovedFromLocalGroup | User account removed from local group | | Y | N |
| WmiBindEventFilterToConsumer | WMI EventFilter bound to consumer | | Y | N |
| WriteToLsassProcessMemory | Write to LSASS process memory | | N | N |