McAfee ePolicy Orchestrator
Event ID 1003: Error starting task
#Description
McAfee ePO threat/operational event (task). Error starting task.
Community Notes #
Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1070, T1562↳ also matches Event ID 1067: Unable to start scheduled task
Event ID 1026: Unable to clean infected file
#Description
McAfee ePO threat/operational event (threat). Unable to clean infected file.
Community Notes #
Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1070, T1562↳ also matches Event ID 1028: Unable to delete infected file, Event ID 1055: Unable to delete infected file, Event ID 1298: File infected: clean, delete, and quarantine all failed, Event ID 1310: Multiple-extension heuristic detection: delete and quarantine failed, Event ID 2002: Unable to clean infected file, Event ID 2004: Unable to delete infected file, Event ID 2009: Unable to move infected file to quarantine
Event ID 1028: Unable to delete infected file
#Description
McAfee ePO threat/operational event (threat). Unable to delete infected file.
Community Notes #
Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1070, T1562↳ also matches Event ID 1026: Unable to clean infected file, Event ID 1055: Unable to delete infected file, Event ID 1298: File infected: clean, delete, and quarantine all failed, Event ID 1310: Multiple-extension heuristic detection: delete and quarantine failed, Event ID 2002: Unable to clean infected file, Event ID 2004: Unable to delete infected file, Event ID 2009: Unable to move infected file to quarantine
Event ID 1029: File added to the exceptions list
#Description
McAfee ePO threat/operational event (exclusion). File added to the exceptions list.
Community Notes #
Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB. This id shares its label with sibling ids in the same rule group; the rule does not distinguish them per-id.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1070, T1562↳ also matches Event ID 2005: File added to the exceptions list, Event ID 2015: File added to the exceptions list
Event ID 1040: Activity log error
#Description
McAfee ePO threat/operational event (logging). Activity log error.
Community Notes #
Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1070, T1562↳ also matches Event ID 1076: Error logging information, Event ID 3032: Error opening or creating the activity log file, Event ID 3033: Activity log file maximum size reached, Event ID 3034: Unable to write the activity log file, Event ID 3036: Error initializing the activity log file, Event ID 3038: Error writing to the activity log
Event ID 1055: Unable to delete infected file
#Description
McAfee ePO threat/operational event (threat). Unable to delete infected file.
Community Notes #
Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1070, T1562↳ also matches Event ID 1026: Unable to clean infected file, Event ID 1028: Unable to delete infected file, Event ID 1298: File infected: clean, delete, and quarantine all failed, Event ID 1310: Multiple-extension heuristic detection: delete and quarantine failed, Event ID 2002: Unable to clean infected file, Event ID 2004: Unable to delete infected file, Event ID 2009: Unable to move infected file to quarantine
Event ID 1062: Error sending alert
#Description
McAfee ePO threat/operational event (alerting). Error sending alert.
Community Notes #
Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1070, T1562
Event ID 1067: Unable to start scheduled task
#Description
McAfee ePO threat/operational event (task). Unable to start scheduled task.
Community Notes #
Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1070, T1562↳ also matches Event ID 1003: Error starting task
Event ID 1076: Error logging information
#Description
McAfee ePO threat/operational event (logging). Error logging information.
Community Notes #
Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1070, T1562↳ also matches Event ID 1040: Activity log error, Event ID 3032: Error opening or creating the activity log file, Event ID 3033: Activity log file maximum size reached, Event ID 3034: Unable to write the activity log file, Event ID 3036: Error initializing the activity log file, Event ID 3038: Error writing to the activity log
Event ID 1119: Update failed
#Description
McAfee ePO threat/operational event (update). Update failed.
Community Notes #
Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB. This id shares its label with sibling ids in the same rule group; the rule does not distinguish them per-id.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1070, T1562↳ also matches Event ID 1123: Update failed, Event ID 2402: Update failed
Event ID 1123: Update failed
#Description
McAfee ePO threat/operational event (update). Update failed.
Community Notes #
Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB. This id shares its label with sibling ids in the same rule group; the rule does not distinguish them per-id.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1070, T1562↳ also matches Event ID 1119: Update failed, Event ID 2402: Update failed
Event ID 1127: On-access scan engine disabled
#Description
McAfee ePO threat/operational event (protection-state). On-access scan engine disabled.
Community Notes #
Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1070, T1562
Event ID 1298: File infected: clean, delete, and quarantine all failed
#Description
McAfee ePO threat/operational event (threat). File infected: clean, delete, and quarantine all failed.
Community Notes #
Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1070, T1562↳ also matches Event ID 1026: Unable to clean infected file, Event ID 1028: Unable to delete infected file, Event ID 1055: Unable to delete infected file, Event ID 1310: Multiple-extension heuristic detection: delete and quarantine failed, Event ID 2002: Unable to clean infected file, Event ID 2004: Unable to delete infected file, Event ID 2009: Unable to move infected file to quarantine
Event ID 1310: Multiple-extension heuristic detection: delete and quarantine failed
#Description
McAfee ePO threat/operational event (threat). Multiple-extension heuristic detection: delete and quarantine failed.
Community Notes #
Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1070, T1562↳ also matches Event ID 1026: Unable to clean infected file, Event ID 1028: Unable to delete infected file, Event ID 1055: Unable to delete infected file, Event ID 1298: File infected: clean, delete, and quarantine all failed, Event ID 2002: Unable to clean infected file, Event ID 2004: Unable to delete infected file, Event ID 2009: Unable to move infected file to quarantine
Event ID 2002: Unable to clean infected file
#Description
McAfee ePO threat/operational event (threat). Unable to clean infected file.
Community Notes #
Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1070, T1562↳ also matches Event ID 1026: Unable to clean infected file, Event ID 1028: Unable to delete infected file, Event ID 1055: Unable to delete infected file, Event ID 1298: File infected: clean, delete, and quarantine all failed, Event ID 1310: Multiple-extension heuristic detection: delete and quarantine failed, Event ID 2004: Unable to delete infected file, Event ID 2009: Unable to move infected file to quarantine
Event ID 2004: Unable to delete infected file
#Description
McAfee ePO threat/operational event (threat). Unable to delete infected file.
Community Notes #
Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1070, T1562↳ also matches Event ID 1026: Unable to clean infected file, Event ID 1028: Unable to delete infected file, Event ID 1055: Unable to delete infected file, Event ID 1298: File infected: clean, delete, and quarantine all failed, Event ID 1310: Multiple-extension heuristic detection: delete and quarantine failed, Event ID 2002: Unable to clean infected file, Event ID 2009: Unable to move infected file to quarantine
Event ID 2005: File added to the exceptions list
#Description
McAfee ePO threat/operational event (exclusion). File added to the exceptions list.
Community Notes #
Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB. This id shares its label with sibling ids in the same rule group; the rule does not distinguish them per-id.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1070, T1562↳ also matches Event ID 1029: File added to the exceptions list, Event ID 2015: File added to the exceptions list
Event ID 2009: Unable to move infected file to quarantine
#Description
McAfee ePO threat/operational event (threat). Unable to move infected file to quarantine.
Community Notes #
Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB. Meaning assigned by elimination (the rule's case default branch), not an explicit per-id label.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1070, T1562↳ also matches Event ID 1026: Unable to clean infected file, Event ID 1028: Unable to delete infected file, Event ID 1055: Unable to delete infected file, Event ID 1298: File infected: clean, delete, and quarantine all failed, Event ID 1310: Multiple-extension heuristic detection: delete and quarantine failed, Event ID 2002: Unable to clean infected file, Event ID 2004: Unable to delete infected file
Event ID 2015: File added to the exceptions list
#Description
McAfee ePO threat/operational event (exclusion). File added to the exceptions list.
Community Notes #
Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB. This id shares its label with sibling ids in the same rule group; the rule does not distinguish them per-id.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1070, T1562↳ also matches Event ID 1029: File added to the exceptions list, Event ID 2005: File added to the exceptions list
Event ID 2402: Update failed
#Description
McAfee ePO threat/operational event (update). Update failed.
Community Notes #
Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB. This id shares its label with sibling ids in the same rule group; the rule does not distinguish them per-id.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1070, T1562↳ also matches Event ID 1119: Update failed, Event ID 1123: Update failed
Event ID 2412: Deployment failed
#Description
McAfee ePO threat/operational event (deployment). Deployment failed.
Community Notes #
Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1562
Event ID 2413: Attempt to uninstall the McAfee agent
#Description
McAfee ePO threat/operational event (deployment). Attempt to uninstall the McAfee agent.
Community Notes #
Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1070, T1562
Event ID 3032: Error opening or creating the activity log file
#Description
McAfee ePO threat/operational event (logging). Error opening or creating the activity log file.
Community Notes #
Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1070, T1562↳ also matches Event ID 1040: Activity log error, Event ID 1076: Error logging information, Event ID 3033: Activity log file maximum size reached, Event ID 3034: Unable to write the activity log file, Event ID 3036: Error initializing the activity log file, Event ID 3038: Error writing to the activity log
Event ID 3033: Activity log file maximum size reached
#Description
McAfee ePO threat/operational event (logging). Activity log file maximum size reached.
Community Notes #
Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1070, T1562↳ also matches Event ID 1040: Activity log error, Event ID 1076: Error logging information, Event ID 3032: Error opening or creating the activity log file, Event ID 3034: Unable to write the activity log file, Event ID 3036: Error initializing the activity log file, Event ID 3038: Error writing to the activity log
Event ID 3034: Unable to write the activity log file
#Description
McAfee ePO threat/operational event (logging). Unable to write the activity log file.
Community Notes #
Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1070, T1562↳ also matches Event ID 1040: Activity log error, Event ID 1076: Error logging information, Event ID 3032: Error opening or creating the activity log file, Event ID 3033: Activity log file maximum size reached, Event ID 3036: Error initializing the activity log file, Event ID 3038: Error writing to the activity log
Event ID 3036: Error initializing the activity log file
#Description
McAfee ePO threat/operational event (logging). Error initializing the activity log file.
Community Notes #
Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1070, T1562↳ also matches Event ID 1040: Activity log error, Event ID 1076: Error logging information, Event ID 3032: Error opening or creating the activity log file, Event ID 3033: Activity log file maximum size reached, Event ID 3034: Unable to write the activity log file, Event ID 3038: Error writing to the activity log
Event ID 3038: Error writing to the activity log
#Description
McAfee ePO threat/operational event (logging). Error writing to the activity log.
Community Notes #
Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB. Meaning assigned by elimination (the rule's case default branch), not an explicit per-id label.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1070, T1562↳ also matches Event ID 1040: Activity log error, Event ID 1076: Error logging information, Event ID 3032: Error opening or creating the activity log file, Event ID 3033: Activity log file maximum size reached, Event ID 3034: Unable to write the activity log file, Event ID 3036: Error initializing the activity log file
Event ID 4650: Spam email detected
#Description
McAfee ePO threat/operational event (email). Spam email detected.
Community Notes #
Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1566
Event ID 16025: Agent Handler is down
#Description
McAfee ePO threat/operational event (infrastructure). Agent Handler is down.
Community Notes #
Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1562
Event ID 35009: Endpoint firewall disabled
#Description
McAfee ePO threat/operational event (protection-state). Endpoint firewall disabled.
Community Notes #
Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1071, T1562