McAfee ePolicy Orchestrator

EventTitleChannelSampleRule
1003Error starting taskMcAfeeEPOEventNY
1026Unable to clean infected fileMcAfeeEPOEventNY
1028Unable to delete infected fileMcAfeeEPOEventNY
1029File added to the exceptions listMcAfeeEPOEventNY
1040Activity log errorMcAfeeEPOEventNY
1055Unable to delete infected fileMcAfeeEPOEventNY
1062Error sending alertMcAfeeEPOEventNY
1067Unable to start scheduled taskMcAfeeEPOEventNY
1076Error logging informationMcAfeeEPOEventNY
1119Update failedMcAfeeEPOEventNY
1123Update failedMcAfeeEPOEventNY
1127On-access scan engine disabledMcAfeeEPOEventNY
1298File infected: clean, delete, and quarantine all failedMcAfeeEPOEventNY
1310Multiple-extension heuristic detection: delete and quarantine failedMcAfeeEPOEventNY
2002Unable to clean infected fileMcAfeeEPOEventNY
2004Unable to delete infected fileMcAfeeEPOEventNY
2005File added to the exceptions listMcAfeeEPOEventNY
2009Unable to move infected file to quarantineMcAfeeEPOEventNY
2015File added to the exceptions listMcAfeeEPOEventNY
2402Update failedMcAfeeEPOEventNY
2412Deployment failedMcAfeeEPOEventNY
2413Attempt to uninstall the McAfee agentMcAfeeEPOEventNY
3032Error opening or creating the activity log fileMcAfeeEPOEventNY
3033Activity log file maximum size reachedMcAfeeEPOEventNY
3034Unable to write the activity log fileMcAfeeEPOEventNY
3036Error initializing the activity log fileMcAfeeEPOEventNY
3038Error writing to the activity logMcAfeeEPOEventNY
4650Spam email detectedMcAfeeEPOEventNY
16025Agent Handler is downMcAfeeEPOEventNY
35009Endpoint firewall disabledMcAfeeEPOEventNY

Event ID 1003: Error starting task

#
Channel
McAfeeEPOEvent

Description

McAfee ePO threat/operational event (task). Error starting task.

Community Notes #

Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

Event ID 1026: Unable to clean infected file

#
Channel
McAfeeEPOEvent

Description

McAfee ePO threat/operational event (threat). Unable to clean infected file.

Community Notes #

Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

Event ID 1028: Unable to delete infected file

#
Channel
McAfeeEPOEvent

Description

McAfee ePO threat/operational event (threat). Unable to delete infected file.

Community Notes #

Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

Event ID 1029: File added to the exceptions list

#
Channel
McAfeeEPOEvent

Description

McAfee ePO threat/operational event (exclusion). File added to the exceptions list.

Community Notes #

Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB. This id shares its label with sibling ids in the same rule group; the rule does not distinguish them per-id.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

Event ID 1040: Activity log error

#
Channel
McAfeeEPOEvent

Description

McAfee ePO threat/operational event (logging). Activity log error.

Community Notes #

Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

Event ID 1055: Unable to delete infected file

#
Channel
McAfeeEPOEvent

Description

McAfee ePO threat/operational event (threat). Unable to delete infected file.

Community Notes #

Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

Event ID 1062: Error sending alert

#
Channel
McAfeeEPOEvent

Description

McAfee ePO threat/operational event (alerting). Error sending alert.

Community Notes #

Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

Event ID 1067: Unable to start scheduled task

#
Channel
McAfeeEPOEvent

Description

McAfee ePO threat/operational event (task). Unable to start scheduled task.

Community Notes #

Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

Event ID 1076: Error logging information

#
Channel
McAfeeEPOEvent

Description

McAfee ePO threat/operational event (logging). Error logging information.

Community Notes #

Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

Event ID 1119: Update failed

#
Channel
McAfeeEPOEvent

Description

McAfee ePO threat/operational event (update). Update failed.

Community Notes #

Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB. This id shares its label with sibling ids in the same rule group; the rule does not distinguish them per-id.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

Event ID 1123: Update failed

#
Channel
McAfeeEPOEvent

Description

McAfee ePO threat/operational event (update). Update failed.

Community Notes #

Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB. This id shares its label with sibling ids in the same rule group; the rule does not distinguish them per-id.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

Event ID 1127: On-access scan engine disabled

#
Channel
McAfeeEPOEvent

Description

McAfee ePO threat/operational event (protection-state). On-access scan engine disabled.

Community Notes #

Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

Event ID 1298: File infected: clean, delete, and quarantine all failed

#
Channel
McAfeeEPOEvent

Description

McAfee ePO threat/operational event (threat). File infected: clean, delete, and quarantine all failed.

Community Notes #

Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

Event ID 1310: Multiple-extension heuristic detection: delete and quarantine failed

#
Channel
McAfeeEPOEvent

Description

McAfee ePO threat/operational event (threat). Multiple-extension heuristic detection: delete and quarantine failed.

Community Notes #

Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

Event ID 2002: Unable to clean infected file

#
Channel
McAfeeEPOEvent

Description

McAfee ePO threat/operational event (threat). Unable to clean infected file.

Community Notes #

Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

Event ID 2004: Unable to delete infected file

#
Channel
McAfeeEPOEvent

Description

McAfee ePO threat/operational event (threat). Unable to delete infected file.

Community Notes #

Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

Event ID 2005: File added to the exceptions list

#
Channel
McAfeeEPOEvent

Description

McAfee ePO threat/operational event (exclusion). File added to the exceptions list.

Community Notes #

Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB. This id shares its label with sibling ids in the same rule group; the rule does not distinguish them per-id.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

Event ID 2009: Unable to move infected file to quarantine

#
Channel
McAfeeEPOEvent

Description

McAfee ePO threat/operational event (threat). Unable to move infected file to quarantine.

Community Notes #

Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB. Meaning assigned by elimination (the rule's case default branch), not an explicit per-id label.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

Event ID 2015: File added to the exceptions list

#
Channel
McAfeeEPOEvent

Description

McAfee ePO threat/operational event (exclusion). File added to the exceptions list.

Community Notes #

Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB. This id shares its label with sibling ids in the same rule group; the rule does not distinguish them per-id.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

Event ID 2402: Update failed

#
Channel
McAfeeEPOEvent

Description

McAfee ePO threat/operational event (update). Update failed.

Community Notes #

Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB. This id shares its label with sibling ids in the same rule group; the rule does not distinguish them per-id.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

Event ID 2412: Deployment failed

#
Channel
McAfeeEPOEvent

Description

McAfee ePO threat/operational event (deployment). Deployment failed.

Community Notes #

Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

Event ID 2413: Attempt to uninstall the McAfee agent

#
Channel
McAfeeEPOEvent

Description

McAfee ePO threat/operational event (deployment). Attempt to uninstall the McAfee agent.

Community Notes #

Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

Event ID 3032: Error opening or creating the activity log file

#
Channel
McAfeeEPOEvent

Description

McAfee ePO threat/operational event (logging). Error opening or creating the activity log file.

Community Notes #

Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

Event ID 3033: Activity log file maximum size reached

#
Channel
McAfeeEPOEvent

Description

McAfee ePO threat/operational event (logging). Activity log file maximum size reached.

Community Notes #

Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

Event ID 3034: Unable to write the activity log file

#
Channel
McAfeeEPOEvent

Description

McAfee ePO threat/operational event (logging). Unable to write the activity log file.

Community Notes #

Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

Event ID 3036: Error initializing the activity log file

#
Channel
McAfeeEPOEvent

Description

McAfee ePO threat/operational event (logging). Error initializing the activity log file.

Community Notes #

Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

Event ID 3038: Error writing to the activity log

#
Channel
McAfeeEPOEvent

Description

McAfee ePO threat/operational event (logging). Error writing to the activity log.

Community Notes #

Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB. Meaning assigned by elimination (the rule's case default branch), not an explicit per-id label.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

Event ID 4650: Spam email detected

#
Channel
McAfeeEPOEvent

Description

McAfee ePO threat/operational event (email). Spam email detected.

Community Notes #

Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

Event ID 16025: Agent Handler is down

#
Channel
McAfeeEPOEvent

Description

McAfee ePO threat/operational event (infrastructure). Agent Handler is down.

Community Notes #

Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

Event ID 35009: Endpoint firewall disabled

#
Channel
McAfeeEPOEvent

Description

McAfee ePO threat/operational event (protection-state). Endpoint firewall disabled.

Community Notes #

Third-party product event (McAfee / Trellix ePolicy Orchestrator), collected into Microsoft Sentinel's McAfeeEPOEvent table and matched by the Sentinel 'McAfee ePolicy Orchestrator' solution rules on the EventId field. Grounding is the Microsoft-curated Sentinel solution and the rules' own semantics; the McAfee/Trellix KB portals (KB52417/KB54677/KB85494) that number these events were unreachable when this was authored, so per-id text is rule-encoded, not vendor-KB.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

References #