Microsoft Defender for Endpoint

This inventory contains data from HKLM\SOFTWARE\Microsoft\Windows Advanced Threat Protection. Last updated: 15 July 2026

ProviderRule namesBound event IDs
Anaheim-SmartScreen
  • UriLookup
  • BreakTheGlass
Anti Tampering
  • ETW Provider tampering
  • Process tampering
  • Com tampering
  • Event ID 1
  • Event ID 2
  • Event ID 3
Application Error
  • UserCrashLog
AppLocker
  • Srp New Policy Applied
  • AppLocker Process Audit
  • AppLocker Process Block
  • AppLocker Script Audit
  • AppLocker Script Block
  • AppLocker Appx Process Audit
  • AppLocker Appx Process Block
  • AppLocker Appx script Audit
  • AppLocker Appx script Block
  • Wldp Script File Audited
  • Wldp Script File Disabled
AttackSurfaceMonitor
  • Device creation via AST
  • Device IOCTL called
Audit-CVE
  • CveEventWrite
Bits-Client
  • EVT_JOB_CREATION
  • EVT_JOB_CANCEL
  • BITS_EV_JOB_CANCELLED
  • BITS_EV_JOB_TAKE_OWNERSHIP
  • EVT_JOB_ADDFILE
Bluetooth-Policy
  • Bluetooth_PolicyServiceBlockAudit
CodeIntegrity
  • CiRevokedDriverNotLoaded
  • CiRevokedImageNotLoaded
  • DeviceGuard policy failure audit
  • DeviceGuard policy failure
  • Code Integrity signature information
  • Smartlocker Operational Success
  • Smartlocker Operational Audit
  • Smartlocker Operational Failure
  • Activate Policy Succeded
Crypto-DPAPI-Events
  • DPAPI Crypt Data
Dhcp-Client
  • DhcpAddressPlumbed
  • DhcpAddressUnplumbed
DHCPV6-Client-Events
  • DhcpV6AddressPlumbed
  • DhcpV6AddressUnplumbed
DNS-Client
  • Send query to DNS server
  • Send query to DNS server Aggregation
  • Dns query response
DotNETRuntime
  • CLR ModuleDCStart
EDP-Audit-Regular
  • WIP Sensitive Data Copied
  • WIP Application Generated
EDP-Audit-TCB
  • WIP File Protection Removed
FilterManager
  • FLTMGR_FILTER_REGISTERED
Generic ETW CreateFile Pattern
  • Remote Non PE Create File Event
  • PE Create File Event
  • SMB create File Event
  • Outlook Create File Event
  • Non PE Create File Event
  • Shell Link Create File Event
  • Shell Link Create File Event (Remote)
  • WDATP Tampering Create File Event
  • WDATP Program Files Create File Event
  • User Create File Event
  • Browsers Create File Event
  • Email Archive Create File Event
  • Event ID 1
IE-SmartScreen
  • UrlBlockLookup
Kernel Integrity
  • KernelIntegrityCheck
  • Event ID 1
Kernel-Audit-API-Calls
  • ObMgrSymlinkCreation
Kernel-Network
  • Kernel network bytes sent TCP IPv4 non Filtered
  • Kernel network bytes sent TCP IPv6 non Filtered
  • Kernel Network Byte Send IPv4 Filtered
  • Kernel network bytes received TCP IPv4 non Filtered
  • Kernel network bytes received TCP IPv6 non Filtered
Kernel-PnP-Events
  • configuration blocked by policy
  • Device Config Success by policy
Ldap-Client
  • Ldap Search
LiveId
  • Function token provider
  • Event ID 11008: +.
LsaSrv
  • Encryption oracle remediation
  • LsaSrv UI user
  • LsaSrv UI computer account
Machine state
  • Timna - OXO HKLM reg keys
  • Onboarding information collection
  • Url Cache Size
  • Timna - VA - .NET Framework
  • Timna - VA - Office click to run
  • Timna - secure configuration - application configuration (compatibility)
  • Timna - Internet Explorer - version information
  • Timna - SCA configurations
  • Timna - Information Gathering
  • Timna - KBs
  • AppUsage process list
  • Timna - Firmware - TPM
  • Timna - Internet Explorer Installation Status
  • Timna - Firmware - BaseBoard
  • Timna - Firmware - Bios
  • Timna - Local Users
  • Timna - Computer system information
  • WDAV tamper-protection (Windows Defender configuration)
  • WDAV tamper-protection (Windows Defender configuration)
  • Timna - Add or remove programs
  • Timna - Add or remove programs - WOW6432Node
  • Timna - Add or remove programs (hkey_users)
  • Timna - Add or remove programs - WOW6432Node (hkey_users)
  • WDAV state
  • Firewall state
  • CodeIntegrity state
  • AppGuard state
  • SmartScreen state
  • KernelIntegrity state
  • AntiExploit State
  • HIPS ASR state
  • FolderGuard state
  • Windows Updates state
  • Machine properties state
  • BitLocker state
  • Firmware State
  • KB Item State
  • KB Index State
  • Isolation State
  • Capabilities State
  • Azure Vm Metadata State
  • Registry collection
  • AppGuard state GP
  • Network protection configuration
  • Timna - secure configuration
  • LDAP Security Configuration
  • Disable Remote Registry Service
  • Disable NTLM authentication for Windows workstations
  • Exchange OwaVersion Collection
  • SCA WMI Defender configurations
  • XSPM - TPM Status
  • XSPM - RDP Status
  • XSPM - HKLM PowerShell Execution Status
  • Effective Configuration
  • Event ID 2
  • Event ID 3
  • Event ID 4
  • Event ID 5
  • Event ID 6
  • Event ID 7
  • Event ID 8
  • Event ID 9
  • Event ID 10
  • Event ID 11
  • Event ID 12
  • Event ID 13
  • Event ID 16
  • Event ID 17
  • Event ID 18
  • Event ID 19
  • Event ID 20
  • Event ID 21
  • Event ID 22
  • Event ID 1000
  • Event ID 1001
  • Event ID 1002
Microsoft-Antimalware-Engine
  • BmFileOverwriteEvent
  • AVEngineBASTelemetry
  • UefiFirmwareVolume
  • AVEngineThreatTelemetry
  • AVEngineNonThreatTelemetry
  • AvDeviceHeartbeat
Microsoft-Antimalware-RTP
  • DC_RemovableStorageRWE
  • DC_DataDuplicationEvent
  • DC_DevicePresenceEvent
  • DC_HealthReportEvent
Microsoft-Antimalware-Scan-Interface
  • AMSIScan
  • AMSIContent
  • AMSIContentForIIS
  • AMSIContentForDotNet
  • VssAmsiContent
Microsoft-Antimalware-Service
  • RemediationInfo
  • HIPS
  • NetworkFilterLookup
  • NetworkFilterBypass
  • TroubleshootingModeNotification
  • TamperProtectionNotification
  • HipsAsrUserExclusionInfo
  • NetworkFilterConnectionInfo
  • MpPreferenceExclusionsHardening
  • PolicyExclusionsHardening
Microsoft-Antimalware-UacScan
  • UacScanExe
  • UacScanCom
  • UacScanPackagedApp
  • UacScanOther
Microsoft-ThreatProtectionService
  • SqliStatelessDetector
microsoft-windows-grouppolicy
  • DomainControllerDiscovery
Microsoft.Office.Security
  • Office SafeDocs file scanning
Microsoft.Windows.ComOleAut32
  • Com OleAut32 - TypeLibVerifyTrust
  • Com OleAut32 - TypeLibMonikerFallback
  • Com OleAut32 - TypeLibRegister
  • Com OleAut32 - TypeLibLoad
  • Com OleAut32 - TypeLibMonikerLoad
  • Com OleAut32 - GetDocumentationDllLoad
Microsoft.Windows.Console.Host
  • conhost cooked read buffer
Microsoft.Windows.Defender
  • Legacy Process Creation
  • Elam bypass
Microsoft.Windows.FileSystem.CloudFiles
  • CfRegisterSyncRoot_Success
Microsoft.Windows.HVSI.ContainerService
  • CreateVMEnd
  • SuspendComputeSystemEnd
  • ResumeComputeSystemEnd
Microsoft.Windows.HVSI.Manager
  • LaunchDocumentInContainer
Microsoft.Windows.HyperV.Compute
  • ContainerStopped
Microsoft.Windows.NdrCollector
  • ModelCollectorNdrScanner
  • NdrCollectorHyperVVmDiscovery
  • NdrCollectorAdUserComputer
  • NdrCollectorAdUserComputerV2
  • NdrCollectorAdUserComputerV3
  • NdrCollectorLdapExchangeServerV3
  • NdrCollectorVirtualMachineInfo
  • NdrCollectorHyperVVmDiscoveryV2
  • NdrCollectorDomainTrust
  • NdrCollectorDomainController
  • NdrCollectorAdcaInfo
  • NdrCollectorAadConnectInfo
  • NdrCollectorAadConnectInfoV2
  • NdrCollectorDiscoveredAadConnectInfo
  • NdrCollectorSccmInfo
  • NdrCollectorSccmAgentInfo
  • NdrCollectorAdfsInfoV2
  • NdrCollectorDefaultGatewayDiscovery
  • NdrCollectorVeritasBackupExecInfo
Microsoft.Windows.NdrScanner
  • NdrScannerDefaultGatewayDiscovery
  • NdrScannerSsh
  • SipDiscoveryNdrScanner
  • SnmpDiscoveryNdrScanner
  • WsDiscoveryNdrScanner
  • mDnsNdrScanner
  • UPnPNdrScanner
  • NdrScannerTelemetry
  • NdrCveLocalScanner
  • NdrScannerBannerGrab
  • NdrScannerFtpBannerGrab
  • NdrScannerHostDiscovery
  • NdrScannerPortScan
  • NdrScannerHttpProbe
  • NdrScannerIcmp
  • NdrScannerIpp
  • NdrScannerWsdExtension
  • NdrScannerNetBios
  • NdrScannerSmb
  • NdrScannerSmbV1
  • NdrScannerPjl
  • NdrScannerCrestronIP
  • NdrScannerLdap
  • NdrScannerAfp
  • NdrScannerRdpNla
  • NdrScannerNtlm
  • ShieldsUpSetupResults
  • NdrScannerIphoneSync
  • NdrScannerAirplay
  • NdrScannerRpcMapper
  • NdrScannerVnc
  • NdrScannerSlp
  • NdrLdapComputerDiscovery
  • NdrScannerSpring4Shell
  • SnmpExtendedDiscoveryNdrScanner
Microsoft.Windows.Oct.Enclave
  • SGRM Assertion Event
Microsoft.Windows.OLE.Clipboard
  • OLE Clipboard Get Data
Microsoft.Windows.Print.Winspool
  • Print Job Created
Microsoft.Windows.Security.Wininit
  • lsaIsoStartupCheck
  • LsassStarted
Microsoft.Windows.Security.Wsc
  • WSC RegisterAntiVirus
  • WSC UnregisterAntiVirus
Microsoft.Windows.Sense.AccountsLockoutProvider
  • AccountLockoutPolicy
Microsoft.Windows.Sense.BrowserExtensionCollection
  • CollectedBrowserExtensions
  • TvmCollectedBrowserExtensionsIndex
Microsoft.Windows.Sense.CollectionEtw
  • AWS CLI authentication data
  • Azure CLI authentication data
  • GCP ADC Authentication Data
  • GCP Gcloud CLI Authentication Data
  • DangerousWifiProfiles
  • LocalServices
  • LocalServicesIndex
  • Timna - Products files scanning
  • Timna - open handles scanning
  • Timna - Products files scanning index
  • DataCollection - Certificate not installed
  • DataCollection - execution policy reduced
  • Logon Audit Security Policy
  • Browser data logged Azure user
  • Browser data logged AWS user
  • Browser data logged Azure users unified
  • Browser data logged AWS users unified
  • Azure CLI Authentication Data Unified
  • AWS CLI Authentication Data Unified
  • GCP ADC Authentication Data Unified
  • GCP Gcloud CLI Authentication Data Unified
  • DataCollection - Action response
  • DataCollection - Action failure
Microsoft.Windows.Sense.ConnectivityChecker
  • ConnectivityCheckerReport
  • ConnectivityCheckerFailure
Microsoft.Windows.Sense.GeneratedETW
  • HangDetection - report a hung component
  • HangDetection - looking for hung components
  • ResourceManagerEvent
  • OfflineCommandStatus
  • IsolationAutoRecoveryHandler
  • IsolationStartup_IsolationAfterReboot
  • PlatformUpdateStatus
  • PlatformUpdateStatus_Collector
  • Create process using G-ETW
  • OsInfo
  • OsSettings
  • SecurityLogCleared
  • LogCleared
  • StorageVolumeInformation
  • Policy dispatcher critical error
  • PSScriptSignatureValidation_Mismatch
  • RunPSScript_InvalidSasUrl
  • RunPSScript_InvalidValidationConfig
  • OnlineActionSampler_InvalidCmd
  • FirewallConfiguratorApplyEvent
  • FirewallConfiguratorRemoveEvent
  • FirewallConfiguratorGeneralEvent
  • LMF Policy Applied
  • LMF force close SMB session
  • LMF force disconnect WTS session
  • LMF force logoff WTS session
  • SmbBouncerPolicy policy applied
  • Geppetto policy applied
  • Geppetto policy removal
  • SBG policy applied
  • SBG policy removed
  • SBG mitigation
  • RiskAssessment policy applied
  • RiskAssessment policy removed
  • WDAC policy applied
  • WfpConfigurator policy applied
  • WfpConfigurator policy removed
  • DeviceContain policy applied
  • DeviceContain policy did not match
  • DeviceContain policy removed
  • OffboardingEpochBlock policy applied
  • Offboarding blob epoch blocked
  • Offboarding blob epoch blocked - audit
  • WfpGuard Policy Applied
  • DLP Telemetry Event
  • DLP Operational Information
  • CrashCollector_CrashReport
  • CrashCollector_WER
  • InternalOpticsEvent
  • InternalOpticsCompressedEvent
  • Sense Uploaded Size
  • PerformanceCounterProcessAndSystem
  • PerformanceCounterProcess
  • Orchestrator info
  • Orchestrator error
  • SenseService_ShutdownEvent
  • SenseService_StopEvent
  • SenseService_RestartEvent
  • SenseService_UpdateInfoEvent
  • SenseService_UpdateFailedEvent
  • LogicResolverTelemetry
Microsoft.Windows.Sense.Immune
  • Driver Collection Event
  • ImmuneCodeIntegrity
  • ImmuneComTelemetry
  • ImmuneComAnalyzer
Microsoft.Windows.Sense.LocalGroupsUsersCollection
  • Timna - LocalGroupsUsers
Microsoft.Windows.Sense.Olympus
  • ADFS pre-authentication
  • ADFS post-authentication
Microsoft.Windows.Sense.PasswordPolicyProvider
  • PasswordPolicy
Microsoft.Windows.Sense.PendingRebootUpdates
  • Timna - Pending Reboot Collection
Microsoft.Windows.Sense.RegHeartBeat
  • Possible ACL Tampering
Microsoft.Windows.Sense.ResearchCollectionEtw
  • WfpFilterAudit
  • WfpFilterDelete
Microsoft.Windows.Sense.ScheduledTasksCollection
  • ScheduledTasks
Microsoft.Windows.Sense.SenseCm
  • SenseCM
  • CheckinScriptResults
Microsoft.Windows.Sense.SenseCm
  • CheckinScriptResults
Microsoft.Windows.Sense.SharesCollection
  • Shares
Microsoft.Windows.Sense.SubAuth
  • SubAuth user logon audited
  • SubAuth user logon blocked
  • SubAuth initialization completion
  • SubAuth package conflict detection
  • SubAuth policy updated
  • SubAuth policy removed
Microsoft.Windows.Sense.TimnaProductsFromRegistry
  • Timna - Products From Registry 64 PowerShell
  • Timna - Products From Registry 6432 PowerShell
  • Timna - Products From User Registry 64 PowerShell
  • Timna - Products From User Registry 6432 PowerShell
Microsoft.Windows.Sense.Tvm.Axon
  • Timna - SenseTVM registry programs collection event
  • Timna - SenseTVM windows programs collection event
  • Timna - SenseTVM windows services collection event
  • Timna - SenseTVM browser extensions collection event
  • Timna - SenseTVM certificates collection event
  • Timna - SenseTVM pending updates collection event
  • Timna - SenseTVM ms store appx collection event
  • Timna - SenseTVM windows KBs collection event
  • Timna - SenseTVM PE collection event
  • Timna - SenseTVM dev library collection event
  • Timna - SenseTVM regex file extraction collection event
  • Timna - SenseTVM JSON config collection event
  • Timna - SenseTVM device info event
  • Timna - SenseTVM windows device info event
  • Timna - SenseTVM telemetry event
  • Timna - SenseTVM scrubbed telemetry event
Microsoft.Windows.Sense.Tvm.Collector
  • Timna - VA collector event
  • TvmCveLocalScanner
  • Outbound block windows firewall rules that have no exceptions/scoping
  • Collect Local security policy user rights assignments
  • Collect device users roles info and authority
  • Collect device services info
Microsoft.Windows.Sense.Tvm.NetworkScanner
  • NetworkScanOutput
  • NetworkScanAgentTrace
  • Petra - Scan command status
  • Timna - Internet Explorer Installation Status (Petra4Windows)
  • Timna - KBs (Petra4Windows)
  • Timna - Computer system information (Petra4Windows)
  • Timna - Firmware - BaseBoard (Petra4Windows)
  • Timna - Firmware - Bios (Petra4Windows)
  • Timna - Local Users (Petra4Windows)
  • Timna - Firmware - TPM (Petra4Windows)
  • Timna - VA - .NET Framework (Petra4Windows)
  • Timna - VA - Office click to run (Petra4Windows)
  • Timna - Internet Explorer - version information (Petra4Windows)
  • Timna - Add or remove programs (Petra4Windows)
  • Timna - Add or remove programs - WOW6432Node (Petra4Windows)
  • Timna - Add or remove programs (hkey_users) (Petra4Windows)
  • Timna - Add or remove programs - WOW6432Node (hkey_users) (Petra4Windows)
  • Petra - Operating system data (Petra4Windows)
  • Petra - Computer system data (Petra4Windows)
  • Timna - secure configuration - application configuration (compatibility) (Petra4Windows)
  • Timna - SCA configurations (Petra4Windows)
  • Timna - secure configuration (Petra4Windows)
  • Timna - Information Gathering (Petra4Windows)
Microsoft.Windows.Sense.TvmBaselineAssessorEtw
  • TvmBaselineAssessor
Microsoft.Windows.Sense.TvmCertificateCollectionEtw
  • TvmCertificateCollection
  • TvmCertificateIndexCollection
Microsoft.Windows.Sense.TvmInfoGatheringCollectorEtw
  • TvmInfoGatheringCollector
Microsoft.Windows.Sense.ValidationEtw
  • DataCollection - Parent Validation
Microsoft.Windows.Sense.WDCollection
  • MDATP Security Baseline - AntiVirus
Microsoft.Windows.SenseComponent.GeneratedETW
  • PerformanceCounterProcessAndSystem
  • PerformanceCounterProcess
Microsoft.Windows.SenseNdr
  • SenseNdrMdns
  • SenseNdrMdnsCveLog4j
  • SenseNdrDhcp
  • SenseNdrDhcpV6
  • SenseNdrLldp
  • SenseNdrLlmnr
  • SenseNdrSsdp
  • SenseNdrCDP
  • SenseNdrArp
  • SenseNdrArpRequest
  • SenseNdrTcpHeader
  • SenseNdrNbns
  • SenseNdrMndp
  • SenseNdrWsd
  • SenseNdrUdpHeader
  • SenseNdrIPHeader
  • SenseNdrTcpHeaderSynPackets
  • SenseNdr Telemetery
  • ZeekSetupStatusEvent
  • SenseNdrInfo
  • SenseNdrError
  • SenseNdrThrottling
  • SenseNdrSignaturePii
  • SenseNdrSignatureNtlm
  • SenseNdrSignatureSmbServerGuid
  • SenseNdrSignatureMsBrowser
  • SenseNdrSignatureHttpServerHeader
  • SenseNdrSignaturePublicIpScan
  • SenseNdrSignaturePublicIpScanUdp
  • SenseNdrSignatureIphoneSync
  • SenseNdrSignatureCveDetection
  • SenseNdrSignatureSpring4Shell
  • SenseNdrSignatureKerberos
  • SenseNdrSignatureLdapRbcdModify
  • SenseNdrSignatureMsMsdt
  • SenseNdrSignatureJavaReferenceOverLdap
  • SenseNdrSignatureSkypeSsrf
  • SenseNdrZeekSignatureBacnetBroadcastDiscovery
  • SenseNdrZeekSignatureBacnetFW
  • SenseNdrZeekSignatureBacnetLocation
  • SenseNdrZeekSignatureBacnetModel
  • SenseNdrZeekSignatureBacnetHostname
  • SenseNdrZeekSignatureBacnetVendorCode
  • SenseNdrZeekSignatureBacnetVendorName
  • SenseNdrSignatureDns
  • SenseNdrSignatureDnsCveLog4j
  • SenseNdrSignatureJavaRMI
  • SenseNdrSignatureSrvSvc
  • SenseNdrSignatureWakeOnLan
  • SenseNdrSignatureNegoEx
  • SenseNdrSignaturePointOfCareTesting
  • SenseNDRSignatureProfinetEPM
  • SenseNDRSignatureProfinetIMZeroFive
  • SenseNDRSignatureProfinetAssetManagement
  • SenseNdrZeekDceRpc
  • SenseNdrZeekSamr
  • SenseNdrZeekSrvSvc
  • SenseNdrZeekDns
  • SenseNdrZeekFtp
  • SenseNdrZeekConnTcp
  • SenseNdrZeekConnUdp
  • SenseNdrZeekSignature
  • SenseNdrZeekDhcpV6Exploit
  • SenseNdrZeekSmbGhost
  • SenseNdrZeekIcmp
  • SenseNdrZeekHttp
  • SenseNdrZeekNtlm
  • SenseNdrZeekSmbServerGuid
  • SenseNdrZeekSsh
  • SenseNdrZeekSmtp
  • SenseNdrZeekKerberos
  • SenseNdrZeekSsl
  • SenseNdrZeekSmbFiles
  • SenseNdrZeekSmbMapping
  • SenseNdrZeekFiles
  • SenseNdrZeekWireguard
  • SenseNdrZeekNotice
  • SenseNdrZeekPrintNightmare
  • ZeekNdrRunnerEvent
  • SenseNdrZeekStatistics
  • SenseNdrZeekHealthLevelSeven
  • SenseNdrZeekPointOfCareTesting
  • SenseNdrZeekDicom
  • SenseNdrZeekModbus
  • SenseNdrZeekSnmp
  • SenseNdrZeekEnip
  • SenseNdrZeekCip
  • SenseNDRZeekBacnetProperty
  • SenseNDRZeekBacnetIAmVendor
  • SenseNdrZeekModbusReadDeviceID
  • SenseNdrZeekNicteaming
  • SenseNdrZeekBacnetProperty
  • SenseNdrZeekS7CommPlus
  • SenseNdrZeekSignatureS7Comm
  • SenseNdrZeekBoundarySix
  • SenseNdrZeekReporterEvent
  • SenseNdrZeekKerberosAuthTicketOut
  • SenseNdrZeekKerberosAuthTicketIn
  • SenseNdrZeekKerberosTgs
  • SenseNdrSignatureTCPCIPGetAll
  • SenseNdrSignatureUDPCIPGetAll
  • SenseNdrSignatureTCPCIPGetSingle
  • SenseNdrSignatureUDPCIPGetSingle
  • SenseNdrSignatureUDPENIPListCIPIdentity
  • SenseNdrSignatureTCPENIPListCIPIdentity
  • SenseNdrSignatureBacnetBroadcastDiscovery
  • SenseNdrSignatureBacnetProperty
  • SenseNdrSignatureSNMPSysDescription
  • SenseNdrSignatureSNMPSysName
  • SenseNdrSignatureS7CommReadSZL_0111
  • SenseNdrSignatureS7CommReadSZL_001C
  • SenseNdrSignatureS7CommReadSZL_0011
  • SenseNdrSignatureModbusReadDeviceID
  • SenseNDRSignatureSiemensSICAM
  • SenseNDRSignatureS7CommPlusCreateObject
  • SenseNDRSignatureS7CommPlusGetVarSubStreamed
  • SenseNDRSignatureS7CommPlusGeneric
  • SenseNDRSignatureCSP2DiagnosticStatusResponseLocal
  • SenseNDRSignatureCSP2DiagnosticStatusResponseRemote
  • SenseNDRSignatureCSP2Generic
  • SenseNdrSignatureHoneywellDiscovery
  • SenseNdrZeekGhostCat
  • SenseNdrZeekProfinetIoCm
  • SenseNdrZeekProfinetHandshakeEPM
  • SenseNdrZeekJA4SSH
  • SenseNDRSignatureEmersonCpcE2SignOn
  • SenseNDRSignatureEmersonCpcE2CtrlList
  • SenseNdrZeekEmersonCpcE2
Microsoft.Windows.ServiceControlManager
  • ServiceStarted
Microsoft.Windows.User32
  • System shutdown (CSRSS)
Microsoft.Windows.WebDefense.SenseLogging
  • ThreatAssessmentSenseEvent
Microsoft.Windows.WSL.DefenderPlugin
  • WSLDefenderPlugin
NTLM
  • NTLM Client Blocked Audit
Powershell cmdlets
  • Cmdlet start
  • Amsi Start
PrintService
  • Device Control Print Failed due to Restrictions
RemoteDesktopServices-RdpCoreTS
  • RdpCoreTS Accept Connection
  • RdpCoreTS MST120 Virtual channel
RPC
  • RPC Interface Registration
  • RPC Interface Unregistration
RPC-Audit
  • Remote RPC inbound audit
  • Remote RPC inbound block
SEC
  • LoadImage_ForProtectedProcess
  • Delete file
  • DeviceIoControl volsnap
  • Filter Process Termination
  • Atomic Open Remote File And Acquire Oplock
  • Retry Failed IO
  • Open network share
  • Admin share opened remotely
  • Outgoing admin share access, parent folder only
  • Outgoing admin share access, raw events
  • Registry Query Info Key
  • System rename extension aggregation
  • Named Pipe
  • Event18
  • Event19
  • Event23
  • Event23_ForSense
  • Event23_ForAmsiDetector
  • Event24
  • Event25
  • Event27
  • Event28
  • Event29
  • Event30
  • Event32
  • Event33
  • Open process for read
  • Event35
  • Event36
  • Event37
  • Event38
  • File create aggregation
  • File delete aggregation
  • File rename aggregation
  • File create extension aggregation
  • File delete extension aggregation
  • File rename extension aggregation
  • SEC unload
  • High value file read
  • High value file read aggregation
  • RegistryQueryValue
  • File Open
  • File Open By Process
  • Unauthorized file access attempts
  • Registry Save Key
  • Process Termination Aggregation
  • Process Commandline Assertion Violation
  • Script read from network share
  • [FirstNSeen] LoadImage
  • LMF File Open Blocked Audit
  • LMF File Open Blocked Audit Aggregation
  • LMF network share access blocked
  • LMF sysvol access blocked
SEC-WFP
  • WfpGuard Block Event
  • Contain connection blocked callout (legacy)
  • ContainExclusions
  • ManualDeviceContainBlock
  • DisruptionContainBlock
  • DisruptionContainHvaAudit
  • OutgoingTrafficBlockerAudit
  • OutgoingTrafficBlockerBlock
SecureETW
  • Logon event
  • SE_AUDITID_ETW_PROCESS_CREATED
  • An Attempt was made to reset an account password
  • File permissions change
  • Persistent cryptographic key export.
  • Taking Ownership on File from TrustedInstaller
  • Taking Ownership on MDE Key
  • Hardlink Create Audit Event
  • Sense tampering through object sacl change
  • A service was installed
  • An account failed to log on
  • A scheduled task was created
  • A scheduled task was deleted
  • A scheduled task was updated
  • A user account was created
  • Plug and Play event
  • Firewall service started
  • Firewall service stopped
  • Firewall app blocked from listening
  • Firewall has blocked a connection outbound
  • Firewall has blocked a connection inbound
  • Credman - Credentials Backup
  • Credman - Read Credentials
  • Vault Credential - Find Credential
  • Vault Credential - Enumerate Credentials
  • Vault Credential - Get Unique Credential
  • Logon using explicit credentials
  • System Audit Policy was changed
  • A user account was deleted
  • A member was added to a security-enabled local group
  • Local group created
  • A user account was deleted
  • Local group removed
  • Local group deleted
  • A user account was changed
  • A member was added to a security-enabled local group
  • User's local group membership was enumerated
  • Security-enabled local group membership was enumerated
  • Persistent cryptographic key operation.
  • SE_AUDITID_ETW_RPC_INBOUND_CALL
  • LMF RPC Inbound enforcement
  • SE_AUDITID_ETW_LOGON_FAILURE
  • LMF network logon enforcement
Security-Mitigations
  • AuditProcessProcessBlockGeneratingDynamicCode
  • EnforceProcessProcessBlockGeneratingDynamicCode
  • AuditProcessProcessBlockCreatingChildProcess
  • EnforceProcessProcessBlockCreatingChildProcess
  • AuditProcessLoadLowILImage
  • EnforceProcessLoadLowILImage
  • AuditProcessLoadBinaryFromRemoteShare
  • EnforceProcessLoadBinaryFromRemoteShare
  • AuditProcessCallWin32k
  • EnforceProcessCallWin32k
  • AuditProcessLoadNonMicrosoftSignedBinary
  • EnforceProcessLoadNonMicrosoftSignedBinary
  • AuditExportAddressFilter
  • EnforceExportAddressFilter
  • AuditExportAddressFilterPlus
  • EnforceExportAddressFilterPlus
  • AuditImportAddressFilter
  • EnforceInputAddressFilter
  • AuditRopStackPivot
  • EnforceRopStackPivot
  • AuditRopCallerCheck
  • EnforceRopCallerCheck
  • AuditRopSimExec
  • EnforceRopSimExec
Services
  • ServiceSendControlStop
  • ServiceConfigChangeStartType
  • ServiceConfigChangeBinaryPathName
  • ServiceConfigChangeAccountInfo
SGRM Report
  • SGRM Report
  • SGRM Error
  • Event ID 1
  • Event ID 2
Shell-Core
  • Open http link
  • Open .lnk file
  • Explorer_ExecutingFromRunKey
SmartScreen
  • AppLookup
  • UserDecision
TCPIP
  • Connection accepted
  • Listening socket created
  • Connect Complete
  • Connect Failure
TerminalServices-LocalSessionManager
  • TerminalServices-LOGON
  • TerminalServices-RECONNECT
ThreatIntelligence
  • MemAllocRemote
  • MemProtectRemote
  • MapViewRemote
  • QueueUserApcRemote
  • SetThreadContextRemote
  • MemAllocForHighRisk
  • MemAllocForMeterpreter
  • Image region local vmprotect
  • MapViewForHighRiskProcesses
  • ReadVMRemote
  • ReadVMRemote clone
  • WriteVMRemote - lsass
  • SuspendThread
  • ResumeThread
  • SuspendProcess
  • ResumeProcess
  • FreezeProcess
  • ThawProcess
  • AllocVmKernelCallerRemote
  • ProtectVmKernelCallerRemote
  • QueueUserApcKernelCallerRemote
  • Driver Object Creation
  • Device Object Creation
  • Token Impersonation
User32
  • System shutdown
VHDMP
  • VHDMP Virtual Disk Mount
WER-Diag
  • CFG Violation
Win32k
  • UpdateEvent
  • KLRegRawInput (20H1+)
  • KLRegRawInput
  • KLGetAsyncKeyState
  • KLSetWindowsHook
  • BitBlt API call Aggregation
Windows Defender
  • WDAV Scan Started
  • WDAV Scan Completed
  • WDAV Scan Cancelled
  • WDAV Scan Failed
  • MALWAREPROTECTION_RTP_ENABLED
  • MALWAREPROTECTION_RTP_DISABLED
  • MALWAREPROTECTION_CONFIG_CHANGED
  • Defender Signature drop
  • Attempted Defender AV Tampering
WMI-Activity
  • Remote Win32_Process:Create
  • Remote WMI execution
  • Remote WMI Process Creation (RS5+)
  • WMI remote query
  • WMI local query
  • Remote WMI Repository Update
  • Local Win32_Process:Create
  • Local WMI Process Creation (RS5+)
  • WMI bind filter to consumer
  • WMI Class Creation and Usage