Microsoft Defender XDR

DeviceProcessEvents (3)

ActionTypeDescriptionSampleRule
(any)Process activityYY
OpenProcessProcess handle openedNN
ProcessCreatedProcess createdYY

DeviceNetworkEvents (20)

ActionTypeDescriptionSampleRule
(any)Network activityYY
ConnectionAcknowledgedConnection acknowledgedYN
ConnectionAttemptConnection attemptYY
ConnectionFailedConnection failedYY
ConnectionFoundConnection foundYN
ConnectionRequestConnection requestNY
ConnectionSuccessConnection succeededYY
DnsConnectionInspectedDNS connection inspectedYN
FtpConnectionInspectedFTP connection inspectedNN
HttpConnectionInspectedHTTP connection inspectedYN
IcmpConnectionInspectedICMP connection inspectedYN
InboundConnectionAcceptedInbound connection acceptedYY
InboundInternetScanInspectedInbound internet scan inspectedNN
KerberosConnectionInspectedKerberos connection inspectedYN
ListeningConnectionCreatedListening connection createdYY
NetworkSignatureInspectedNetwork signature inspectedYY
NtlmAuthenticationInspectedNTLM authentication inspectedYN
SmtpConnectionInspectedSMTP connection inspectedNN
SshConnectionInspectedSSH connection inspectedNN
SslConnectionInspectedSSL connection inspectedYN

DeviceFileEvents (5)

ActionTypeDescriptionSampleRule
(any)File activityYY
FileCreatedFile createdYY
FileDeletedFile deletedYN
FileModifiedFile modifiedYY
FileRenamedFile renamedYY

DeviceRegistryEvents (6)

ActionTypeDescriptionSampleRule
(any)Registry activityYY
RegistryKeyCreatedRegistry key createdYN
RegistryKeyDeletedRegistry key deletedYY
RegistryKeyRenamedRegistry key renamedNY
RegistryValueDeletedRegistry value deletedYY
RegistryValueSetRegistry value setYY

DeviceImageLoadEvents (2)

ActionTypeDescriptionSampleRule
(any)Image loadYY
ImageLoadedImage loadedYY

DeviceLogonEvents (4)

ActionTypeDescriptionSampleRule
(any)Logon activityYY
LogonAttemptedLogon attempt outcome (derived)YN
LogonFailedLogon failedYY
LogonSuccessLogon succeededYY

DeviceEvents (219)

ActionTypeDescriptionEventSampleRule
(any)Defender eventYY
AccountCheckedForBlankPasswordAccount checked for blank passwordNN
AmsiScriptContentAMSI script content capturedNY
AmsiScriptDetectionAMSI script detectionYN
AntivirusDefinitionsUpdatedAntivirus definitions updatedNN
AntivirusDefinitionsUpdateFailedAntivirus definitions update failedNN
AntivirusDetectionAntivirus detectionYN
AntivirusEmergencyUpdatesInstalledAntivirus emergency updates installedNN
AntivirusErrorAntivirus errorNN
AntivirusMalwareActionFailedAntivirus malware action failedNN
AntivirusMalwareBlockedAntivirus malware blockedNN
AntivirusReportAntivirus reportYN
AntivirusScanCancelledAntivirus scan cancelledYN
AntivirusScanCompletedAntivirus scan completedYN
AntivirusScanFailedAntivirus scan failedNN
AntivirusTroubleshootModeEventAntivirus troubleshoot mode state changeNN
AppControlAppInstallationAuditedAppControl app installation (audited)NN
AppControlAppInstallationBlockedAppControl app installation (blocked)NN
AppControlCIScriptAuditedAppControl Config CI script (audited)NN
AppControlCIScriptBlockedAppControl Config CI script (blocked)NN
AppControlCodeIntegrityDriverRevokedAppControl Code Integrity driver revokedNN
AppControlCodeIntegrityImageAuditedAppControl Code Integrity image (audited)NN
AppControlCodeIntegrityImageRevokedAppControl Code Integrity image revokedNN
AppControlCodeIntegrityOriginAllowedAppControl Code Integrity origin allowedNN
AppControlCodeIntegrityOriginAuditedAppControl Code Integrity origin (audited)NN
AppControlCodeIntegrityOriginBlockedAppControl Code Integrity origin (blocked)NN
AppControlCodeIntegrityPolicyAuditedAppControl Code Integrity policy (audited)NN
AppControlCodeIntegrityPolicyBlockedAppControl Code Integrity policy (blocked)NN
AppControlCodeIntegrityPolicyLoadedAppControl Code Integrity policy loadedNN
AppControlCodeIntegritySigningInformationAppControl Code Integrity signing informationYN
AppControlExecutableAuditedAppControl executable (audited)NN
AppControlExecutableBlockedAppControl executable (blocked)NN
AppControlPackagedAppAuditedAppControl packaged app (audited)NN
AppControlPackagedAppBlockedAppControl packaged app (blocked)NN
AppControlPolicyAppliedAppControl policy appliedYN
AppControlScriptAuditedAppControl script (audited)NN
AppControlScriptBlockedAppControl script (blocked)NN
AppGuardBrowseToUrlApplication Guard browse to URLNN
AppGuardCreateContainerApplication Guard container createdNN
AppGuardLaunchedWithUrlApplication Guard launched with URLNN
AppGuardResumeContainerApplication Guard container resumedNN
AppGuardStopContainerApplication Guard container stoppedNN
AppGuardSuspendContainerApplication Guard container suspendedNN
AppLockerBlockExecutableAppLocker blocked executableNN
AppLockerBlockPackagedAppAppLocker blocked packaged appNN
AppLockerBlockPackagedAppInstallationAppLocker blocked packaged app installationNN
AppLockerBlockScriptAppLocker blocked scriptNN
AsrAbusedSystemToolAuditedASR copied or impersonated system tool (audited)Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator.YN
AsrAbusedSystemToolBlockedASR copied or impersonated system tool (blocked)Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.YN
AsrAbusedSystemToolWarnBypassedASR copied or impersonated system tool (warn bypassed)Windows-Defender Event ID 1129: A user has allowed a blocked Microsoft Defender Exploit Guard operation.NN
AsrAdobeReaderChildProcessAuditedASR Adobe Reader child process (audited)Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator.NN
AsrAdobeReaderChildProcessBlockedASR Adobe Reader child process (blocked)Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.NN
AsrAdobeReaderChildProcessWarnBypassedASR Adobe Reader child process (warn bypassed)NN
AsrExecutableEmailContentAuditedASR executable from email client (audited)Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator.NN
AsrExecutableEmailContentBlockedASR executable from email client (blocked)Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.NN
AsrExecutableEmailContentWarnBypassedASR executable from email client (warn bypassed)NN
AsrExecutableOfficeContentAuditedASR Office app creating executable content (audited)Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator.NN
AsrExecutableOfficeContentBlockedASR Office app creating executable content (blocked)Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.NN
AsrExecutableOfficeContentWarnBypassedASR Office app creating executable content (warn bypassed)NN
AsrLsassCredentialTheftAuditedASR: LSASS credential theft (audited)Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator.NN
AsrLsassCredentialTheftBlockedASR LSASS credential theft (blocked)Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.NN
AsrLsassCredentialTheftWarnBypassedASR LSASS credential theft warn bypassedNN
AsrObfuscatedScriptAuditedASR obfuscated script execution (audited)Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator.NN
AsrObfuscatedScriptBlockedASR obfuscated script execution (blocked)Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.NN
AsrObfuscatedScriptWarnBypassedASR obfuscated script execution (warn bypassed)NN
AsrOfficeChildProcessAuditedASR: Office child process (audited)Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator.NN
AsrOfficeChildProcessBlockedASR Office app child process (blocked)Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.NN
AsrOfficeChildProcessWarnBypassedASR Office app child process (warn bypassed)NN
AsrOfficeCommAppChildProcessAuditedASR Office communication app child process (audited)Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator.NN
AsrOfficeCommAppChildProcessBlockedASR Office communication app child process (blocked)Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.NN
AsrOfficeCommAppChildProcessWarnBypassedASR Office communication app child process (warn bypassed)NN
AsrOfficeMacroWin32ApiCallsAuditedASR Win32 API calls from Office macros (audited)Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator.NN
AsrOfficeMacroWin32ApiCallsBlockedASR Win32 API calls from Office macros (blocked)Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.NN
AsrOfficeMacroWin32ApiCallsWarnBypassedASR Win32 API calls from Office macros (warn bypassed)NN
AsrOfficeProcessInjectionAuditedASR Office app code injection (audited)Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator.NN
AsrOfficeProcessInjectionBlockedASR Office app code injection (blocked)Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.NN
AsrOfficeProcessInjectionWarnBypassedASR Office process injection warn bypassedNN
AsrPersistenceThroughWmiAuditedASR WMI event subscription persistence (audited)Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator.YN
AsrPersistenceThroughWmiBlockedASR WMI event subscription persistence (blocked)Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.YN
AsrPersistenceThroughWmiWarnBypassedASR WMI event subscription persistence (warn bypassed)NN
AsrPsexecWmiChildProcessAuditedASR PsExec or WMI child process (audited)Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator.YN
AsrPsexecWmiChildProcessBlockedASR PsExec or WMI child process (blocked)Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.YN
AsrPsexecWmiChildProcessWarnBypassedASR PsExec or WMI child process (warn bypassed)NN
AsrRansomwareAuditedASR ransomware activity (audited)Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator.NN
AsrRansomwareBlockedASR ransomware activity (blocked)Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.NN
AsrRansomwareWarnBypassedASR ransomware activity (warn bypassed)NN
AsrSafeModeRebootBlockedASR Safe mode reboot configuration (blocked)Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.NN
AsrSafeModeRebootedAuditedASR Safe mode reboot configuration (audited)Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator.NN
AsrSafeModeRebootWarnBypassedASR Safe mode reboot configuration (warn bypassed)Windows-Defender Event ID 1129: A user has allowed a blocked Microsoft Defender Exploit Guard operation.NN
AsrScriptExecutableDownloadAuditedASR script launching downloaded executable (audited)Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator.NN
AsrScriptExecutableDownloadBlockedASR script launching downloaded executable (blocked)Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.NN
AsrScriptExecutableDownloadWarnBypassedASR script launching downloaded executable (warn bypassed)NN
AsrUntrustedExecutableAuditedASR untrusted executable (audited)Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator.NY
AsrUntrustedExecutableBlockedASR untrusted executable (blocked)Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.NY
AsrUntrustedExecutableWarnBypassedASR untrusted executable (warn bypassed)NN
AsrUntrustedUsbProcessAuditedASR untrusted process from USB (audited)Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator.NN
AsrUntrustedUsbProcessBlockedASR untrusted process from USB (blocked)Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.NN
AsrUntrustedUsbProcessWarnBypassedASR untrusted process from USB (warn bypassed)NN
AsrVulnerableSignedDriverAuditedASR vulnerable signed driver (audited)Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator.NN
AsrVulnerableSignedDriverBlockedASR vulnerable signed driver (blocked)Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.NN
AsrVulnerableSignedDriverWarnBypassedASR vulnerable signed driver (warn bypassed)NN
AsrWebShellOnServerAuditedASR webshell creation on Windows Server (audited)Windows-Defender Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator.NN
AsrWebShellOnServerBlockedASR webshell creation on Windows Server (blocked)Windows-Defender Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.NN
AsrWebShellWarnBypassedASR webshell creation (warn bypassed)NN
AuditPolicyModificationAudit policy modifiedYN
BitLockerAuditCompletedBitLocker audit completedNN
BluetoothPolicyTriggeredBluetooth policy triggeredNN
BrowserLaunchedToOpenUrlBrowser launched to open URLYY
BruteForceActivityDetectedBrute force activity detectedNN
CertificateServicesApprovedCertificateRequestCertificate Services approved certificate requestYN
CertificateServicesLoadedTemplateCertificate Services loaded templateYN
CertificateServicesReceivedCertificateRequestCertificate Services received certificate requestYN
ClrUnbackedModuleLoadedCLR unbacked module loadedYY
ContainedUserLogonBlockedContained user logon blockedYN
ContainedUserRpcAccessBlockedContained user RPC access blockedYN
ContainedUserSmbFileOpenBlockedContained user SMB file open blockedYN
ControlFlowGuardViolationControl Flow Guard violationNN
ControlledFolderAccessViolationAuditedControlled folder access violation (audited)Windows-Defender Event ID 1124: ProcessName would have been blocked from modifying Path by Controlled Folder Access.YN
ControlledFolderAccessViolationBlockedControlled folder access violation (blocked)Windows-Defender Event ID 1123: ProcessName has been blocked from modifying Path by Controlled Folder Access.NN
CreateRemoteThreadApiCallCreateRemoteThread API callYY
CredentialsBackupCredentials backed upNN
DeviceBootAttestationInfoDevice boot attestation infoNN
DirectoryServiceObjectCreatedDirectory Service object createdYN
DirectoryServiceObjectModifiedDirectory Service object modifiedNN
DnsQueryResponseDNS query responseYN
DpapiAccessedDPAPI accessedYN
DriverLoadDriver loadedYY
ExploitGuardAcgAuditedExploit Guard ACG (audited)YN
ExploitGuardAcgEnforcedExploit Guard ACG (blocked)NN
ExploitGuardChildProcessAuditedExploit Guard child process (audited)YN
ExploitGuardChildProcessBlockedExploit Guard child process (blocked)NN
ExploitGuardEafViolationAuditedExploit Guard EAF violation (audited)NN
ExploitGuardEafViolationBlockedExploit Guard EAF violation (blocked)NN
ExploitGuardIafViolationAuditedExploit Guard IAF violation (audited)NN
ExploitGuardIafViolationBlockedExploit Guard IAF violation (blocked)NN
ExploitGuardLowIntegrityImageAuditedExploit Guard low-integrity image (audited)YN
ExploitGuardLowIntegrityImageBlockedExploit Guard low-integrity image (blocked)NN
ExploitGuardNetworkProtectionAuditedExploit Guard Network Protection (audited)Windows-Defender Event ID 1125: Your IT administrator would have caused Microsoft Defender Exploit Guard to block a potentially dangerous network connection.NN
ExploitGuardNetworkProtectionBlockedExploit Guard Network Protection (blocked)Windows-Defender Event ID 1126: Your IT administrator has caused Microsoft Defender Exploit Guard to block a potentially dangerous network connection.NN
ExploitGuardNonMicrosoftSignedAuditedExploit Guard non-Microsoft signed image (audited)NN
ExploitGuardNonMicrosoftSignedBlockedExploit Guard non-Microsoft signed image (blocked)YY
ExploitGuardRopExploitAuditedExploit Guard ROP exploit (audited)NN
ExploitGuardRopExploitBlockedExploit Guard ROP exploit (blocked)NN
ExploitGuardSharedBinaryAuditedExploit Guard shared binary load (audited)NN
ExploitGuardSharedBinaryBlockedExploit Guard shared binary load (blocked)NN
ExploitGuardWin32SystemCallAuditedExploit Guard Win32k system-call (audited)YN
ExploitGuardWin32SystemCallBlockedExploit Guard Win32k system-call (blocked)NN
ExternalDeviceConnectedExternal device connectedNN
ExternalDeviceDisconnectedExternal device disconnectedNN
FileTimestampModificationEventFile timestamp modifiedNN
FirewallInboundConnectionBlockedFirewall inbound connection blockedYN
FirewallInboundConnectionToAppBlockedFirewall inbound connection to app blockedYN
FirewallOutboundConnectionBlockedFirewall outbound connection blockedYN
FirewallServiceStoppedFirewall service stoppedNN
GetAsyncKeyStateApiCallGetAsyncKeyState API callNN
GetClipboardDataGetClipboardData API callNN
LdapSearchLDAP searchYY
LogonRightsSettingEnabledLogon rights setting enabledNN
MemoryRemoteProtectRemote virtual memory protection changeNY
NamedPipeEventNamed pipe eventYY
NetworkProtectionUserBypassEventNetwork protection user bypassNN
NetworkShareObjectAccessCheckedNetwork share object access checkedNN
NetworkShareObjectAddedNetwork share object addedNN
NetworkShareObjectDeletedNetwork share object deletedNN
NetworkShareObjectModifiedNetwork share object modifiedNN
NtAllocateVirtualMemoryApiCallNtAllocateVirtualMemory API callYY
NtAllocateVirtualMemoryRemoteApiCallRemote virtual memory allocation (NtAllocateVirtualMemory)YY
NtMapViewOfSectionRemoteApiCallRemote section map (NtMapViewOfSection)NY
NtProtectVirtualMemoryApiCallNtProtectVirtualMemory API callYY
OpenProcessApiCallProcess opened (OpenProcess API call)YY
OtherAlertRelatedActivityOther alert-related activityYN
PasswordChangeAttemptPassword change attemptNN
PlistPropertyModifiedPlist property modifiedNN
PnpDeviceAllowedPnP device allowedNN
PnpDeviceBlockedPnP device blockedNN
PnpDeviceConnectedPnP device connectedYN
PowerShellCommandPowerShell command executedYY
PrintJobBlockedPrint job blockedNN
ProcessCreatedUsingWmiQueryProcess created using WMI queryYN
ProcessPrimaryTokenModifiedProcess primary token modifiedYY
PTraceDetectedPTrace detectedNN
QueueUserApcRemoteApiCallRemote APC queued (QueueUserApc)NY
ReadProcessMemoryApiCallReadProcessMemory API callYY
RemoteDesktopConnectionRemote Desktop connectionNN
RemoteWmiOperationRemote WMI operationNN
RemovableStorageFileEventRemovable storage file eventNN
RemovableStoragePolicyTriggeredRemovable storage policy triggeredNN
SafeDocFileScanSafe Documents file scannedNN
ScheduledTaskCreatedScheduled task createdYN
ScheduledTaskDeletedScheduled task deletedYN
ScheduledTaskDisabledScheduled task disabledNN
ScheduledTaskEnabledScheduled task enabledNN
ScheduledTaskUpdatedScheduled task updatedYN
ScreenshotTakenScreenshot takenNN
SecurityGroupCreatedSecurity group createdYN
SecurityGroupDeletedSecurity group deletedYN
SecurityLogClearedSecurity log clearedYN
SensitiveFileReadSensitive file readNN
ServiceInstalledService installedYN
SetThreadContextRemoteApiCallRemote thread context change (SetThreadContext)NY
ShellLinkCreateFileEventShell link (LNK) file createdYN
SmartScreenAppWarningSmartScreen app warningNN
SmartScreenExploitWarningSmartScreen exploit warningNN
SmartScreenUrlWarningSmartScreen URL warningNN
SmartScreenUserOverrideSmartScreen user overrideNN
TamperingAttemptTampering attemptYN
TvmAxonTelemetryEventThreat and vulnerability management telemetryYN
UntrustedWifiConnectionUntrusted Wi-Fi connectionNN
UsbDriveDriveLetterChangedUSB drive letter changedNN
UsbDriveMountedUSB drive mountedYY
UsbDriveUnmountedUSB drive unmountedNN
UserAccountAddedToLocalGroupUser account added to local groupYY
UserAccountCreatedUser account createdYY
UserAccountDeletedUser account deletedYN
UserAccountModifiedUser account modifiedYY
UserAccountPasswordResetAttemptUser account password reset attemptYN
UserAccountRemovedFromLocalGroupUser account removed from local groupYN
WmiBindEventFilterToConsumerWMI EventFilter bound to consumerYN
WriteToLsassProcessMemoryWrite to LSASS process memoryNN

DisruptionAndResponseEvents (16)

ActionTypeDescriptionSampleRule
(any)Attack disruption and predictive shielding activityYN
ContainedRestrictedUserSmbFileOpenBlockedContained restricted user SMB file open blockedNN
ContainedUserLogonBlockedContained user logon blockedYN
ContainedUserLogonBlockedByDomainControllerContained user logon blocked by domain controllerNN
ContainedUserRemoteDesktopSessionDisconnectedContained user remote desktop session disconnectedNN
ContainedUserRemoteDesktopSessionStoppedContained user remote desktop session stoppedNN
ContainedUserRpcAccessBlockedContained user RPC access blockedYN
ContainedUserSmbFileOpenBlockedContained user SMB file open blockedYN
ContainedUserSmbFileOpenBlockedAggregationContained user SMB file open blocked (aggregated)NN
ContainedUserSmbSessionStoppedContained user SMB session stoppedNN
GroupPolicyAccessBlockedGroup policy access blockedNN
GroupPolicyHardeningPolicyAppliedGroup policy hardening policy appliedNN
GroupPolicyHardeningPolicyRemovedGroup policy hardening policy removedNN
SafeBootBlockedSafe boot blockedNN
SafeBootGuardPolicyAppliedSafe boot guard policy appliedNN
SafeBootGuardPolicyRemovedSafe boot guard policy removedNN

EmailEvents (1)

ActionTypeDescriptionSampleRule
(any)Email processedYY

EmailUrlInfo (1)

ActionTypeDescriptionSampleRule
(any)Email URL observedYY

EmailAttachmentInfo (1)

ActionTypeDescriptionSampleRule
(any)Email attachment observedYN

EmailPostDeliveryEvents (5)

ActionTypeDescriptionSampleRule
(any)Post-delivery email actionNN
Malware ZAPMalware ZAPNN
Manual RemediationManual remediationNN
Phish ZAPPhish ZAPNN
Spam ZAPSpam ZAPNN

UrlClickEvents (6)

ActionTypeDescriptionSampleRule
(any)URL click activityNY
ClickAllowedClick allowedNN
ClickBlockedClick blockedNN
ClickBlockedByTenantPolicyClick blocked by tenant policyNN
UrlErrorPageURL error pageNN
UrlScanInProgressURL scan in progressNN

MessageEvents (1)

ActionTypeDescriptionSampleRule
(any)Teams message processedNY

MessageUrlInfo (1)

ActionTypeDescriptionSampleRule
(any)Teams message URL observedNY

MessagePostDeliveryEvents (5)

ActionTypeDescriptionSampleRule
(any)Message post-delivery activityNN
Malware ZAPMalware ZAPNN
Manual RemediationManual remediationNN
Phish ZAPPhish ZAPNN
Spam ZAPSpam ZAPNN

IdentityLogonEvents (3)

ActionTypeDescriptionSampleRule
(any)Identity logon activityYY
LogonFailedIdentity logon failedYN
LogonSuccessIdentity logon succeededYY

IdentityQueryEvents (5)

ActionTypeDescriptionSampleRule
(any)Identity query activityNN
DNS queryDNS queryNN
LDAP queryLDAP queryNY
LdapQueryLdap queryNN
SAMR querySAMR queryNN

IdentityDirectoryEvents (63)

ActionTypeDescriptionSampleRule
(any)Directory service activityNN
Account Constrained Delegation SPNs changedAccount constrained delegation SPNs changedNN
Account Constrained Delegation State changedAccount constrained delegation state changedNN
Account Delegation changedAccount delegation changedNN
Account Deleted changedAccount deleted changedNN
Account disabledAccount disabledNN
Account Disabled changedAccount disabled changedNN
Account Display Name changedAccount display name changedNN
Account enabledAccount enabledNN
Account expiredAccount expiredNN
Account Expiry Time changedAccount expiry time changedNN
Account Name changedAccount name changedNN
Account password change failedAccount password change failedNN
Account Password changedAccount password changedNN
Account Password expiredAccount password expiredNN
Account Password Never Expires changedAccount password never expires changedNN
Account Password Not Required changedAccount password not required changedNN
Account Path changedAccount path changedNN
Account primary group ID changedAccount primary group ID changedNN
Account Smart Card Required changedAccount smart card required changedNN
Account Supported Encryption Types changedAccount supported encryption types changedNN
Account Unlock changedAccount unlock changedNN
Account Upn Name changedAccount UPN name changedNN
Active Directory security group createdActive Directory security group createdNN
ADCS certificate issuedADCS certificate issuedNN
ADFS DKM property readADFS DKM property readNN
ADFS settings changedADFS settings changedNN
DES encryption restriction changedDES encryption restriction changedNN
Device Account CreatedDevice account createdNN
Device dNSHostName changedDevice DNS host name changedNN
Device Operating System changedDevice operating system changedNN
Directory Service replicationDirectory service replicationNN
Domain trusts enumeratedDomain trusts enumeratedNN
Entra Connect password writeback failedEntra Connect password writeback failedNN
GMSA password readGMSA password readNN
Group Membership changedGroup membership changedNN
Group Policy display name changedGroup Policy display name changedNN
Group Policy Object createdGroup Policy object createdNN
Group Policy Object deletedGroup Policy object deletedNN
Group Policy settings changedGroup Policy settings changedNN
Kerberos preauthentication flag changedKerberos preauthentication flag changedNN
Plaintext password allow status changedPlaintext password allow status changedNN
Potential lateral movement path identifiedPotential lateral movement path identifiedNN
PowerShell executionPowerShell executionNN
Private Data RetrievalPrivate data retrievalNN
SAM account name changedSAM account name changedNN
Security Principal createdSecurity principal createdNN
Security Principal deleted changedSecurity principal deleted changedNN
Security Principal Display Name changedSecurity principal display name changedNN
Security Principal Name changedSecurity principal name changedNN
Security Principal Path changedSecurity principal path changedNN
Security Principal Sam Name changedSecurity principal SAM name changedNN
Sensitive DACL changedSensitive DACL changedNN
Service creationService creationNN
SID-History changedSID history changedNN
SMB sessionSMB sessionNN
SmbFileCopySMB file copyNN
Task schedulingTask schedulingNN
User Mail changedUser mail changedNN
User Manager changedUser manager changedNN
User Phone Number changedUser phone number changedNN
User Title changedUser title changedNN
Wmi executionWMI executionNN

References