Collection Priority Reference
952 events across 54 providers from 12 sources.
Download as JSON (952 events)
| Provider / Channel | ID | Title | Sources |
|---|---|---|---|
| Application Error/Application | 1000 | Faulting application name: %1, version: %2, time stamp: 0x%3 Faulting module name: %4, version: %5, time stamp: 0x%6 Exception code: 0x%7 Fault off... | Microsoft-WEF, JSCU-NL Recommended |
| Application Hang/Application | 1002 | The program Widgets. | Microsoft-WEF, JSCU-NL Recommended |
| LsaSrv/Operational | 300 | Groups assigned to a new logon. | Microsoft-WEF, ANSSI Recommended |
| AppLocker/EXE and DLL | 8000 | AppID policy conversion failed. | ASD, Olaf Hartong Recommended |
| AppLocker/EXE and DLL | 8001 | The AppLocker policy was applied successfully to this computer. | ASD, Olaf Hartong Recommended |
| AppLocker/EXE and DLL | 8002 | %11 was allowed to run. | NSA, Olaf Hartong, JSCU-NL Recommended |
| AppLocker/EXE and DLL | 8003 | %11 was allowed to run but would have been prevented from running if the AppLocker policy were enforced. | Palantir, Olaf Hartong, JSCU-NL Recommended |
| AppLocker/EXE and DLL | 8004 | %11 was prevented from running. | Palantir, ASD, Olaf Hartong, JSCU-NL Recommended |
| AppLocker/MSI and Script | 8005 | %11 was allowed to run. | NSA, Olaf Hartong, JSCU-NL Recommended |
| AppLocker/MSI and Script | 8006 | %11 was allowed to run but would have been prevented from running if the AppLocker policy were enforced. | NSA, Olaf Hartong, JSCU-NL Recommended |
| AppLocker/MSI and Script | 8007 | %11 was prevented from running. | NSA, ASD, Olaf Hartong, JSCU-NL Recommended |
| AppLocker/EXE and DLL | 8008 | %2: AppLocker component not available on this SKU. | ASD, Olaf Hartong Recommended |
| AppLocker/Packaged app-Execution | 8020 | %11 was allowed to run. | NSA, Olaf Hartong, JSCU-NL Recommended |
| AppLocker/Packaged app-Execution | 8022 | %11 was prevented from running. | ASD, Olaf Hartong Recommended |
| AppLocker/Packaged app-Deployment | 8023 | %11 was allowed to be installed. | NSA, Olaf Hartong, JSCU-NL Recommended |
| AppLocker/Packaged app-Deployment | 8025 | %11 was prevented from running. | ASD, Olaf Hartong Recommended |
| AppLocker/Packaged app-Execution | 8027 | No packaged apps can be executed while Exe rules are being enforced and no Packaged app rules have been configured. | ASD, Olaf Hartong Recommended |
| Bits-Client/Operational | 1 | BITS job "%2" with ID %1 has been resumed. | Yamato Security, JSCU-NL Recommended |
| Bits-Client/Operational | 3 | The BITS service created a new job. | Yamato Security, JSCU-NL Recommended |
| Bits-Client/Operational | 4 | The transfer job is complete. | Yamato Security, JSCU-NL Recommended |
| Bits-Client/Operational | 59 | BITS started the %2 transfer job that is associated with the %4 URL. | Yamato Security, JSCU-NL Recommended |
| CodeIntegrity/Operational | 3001 | Code Integrity determined an unsigned kernel module %2 is loaded into the system. | NSA, Yamato Security Recommended |
| CodeIntegrity/Operational | 3002 | Code Integrity is unable to verify the image integrity of the file %2 because the set of per-page image hashes could not be found on the system. | NSA, Yamato Security Recommended |
| CodeIntegrity/Operational | 3003 | Code Integrity is unable to verify the image integrity of the file %2 because the set of per-page image hashes could not be found on the system. | NSA, Yamato Security Recommended |
| CodeIntegrity/Operational | 3004 | Windows is unable to verify the image integrity of the file %2 because file hash could not be found on the system. | NSA, Yamato Security Recommended |
| CodeIntegrity/Operational | 3010 | Code Integrity was unable to load the %2 catalog. | NSA, Yamato Security Recommended |
| CodeIntegrity/Operational | 3023 | The driver %2 is blocked from loading as the driver has been revoked by Microsoft. | NSA, Yamato Security Recommended |
| CodeIntegrity/Operational | 3033 | Code Integrity determined that a process (%4) attempted to load %2 that did not meet the %5 signing level requirements. | Palantir, ASD, Yamato Security Recommended |
| CodeIntegrity/Operational | 3063 | Code Integrity determined that a process (%4) attempted to load %2 that did not meet the security requirements for %5. | ASD, Yamato Security Recommended |
| CodeIntegrity/Operational | 3065 | Code Integrity determined that a process (%4) attempted to load %2 that did not meet the security requirements for %5. | Palantir, Yamato Security Recommended |
| CodeIntegrity/Operational | 3077 | Code Integrity determined that a process (%4) attempted to load %2 that did not meet the %5 signing level requirements or violated code integrity p... | ASD, Yamato Security Recommended |
| CodeIntegrity/Operational | 3089 | Signature information for another event. | ASD, Yamato Security Recommended |
| DNS-Client/Operational | 3008 | DNS query is completed for the name %1, type %2, query options %3 with status %4 Results %5. | Microsoft-WEF, JSCU-NL Recommended |
| DNSServer/Analytical | 257 | RESPONSE_SUCCESS: TCP=. | NSA, ASD Recommended |
| DriverFrameworks-UserMode/Operational | 2004 | The UMDF Host is loading driver %4 at level %3 for device %2. | Microsoft-WEF, ANSSI Recommended |
| Eventlog/System | 104 | The System log file was cleared. | Microsoft-WEF, JSCU-NL, ANSSI Recommended |
| Eventlog/Security | 1102 | The audit log was cleared. | Microsoft-AppendixL High ASD, Olaf Hartong, JSCU-NL, ANSSI, Splunk-UBA Recommended |
| Kernel-General/System | 12 | The operating system started at system time 1.3825413334687505e+09. | Microsoft-WEF, JSCU-NL, ANSSI Recommended |
| Kernel-General/System | 13 | The operating system is shutting down at system time StopTime. | Microsoft-WEF, JSCU-NL Recommended |
| NTLM/Operational | 8001 | NTLM client blocked audit: Audit outgoing NTLM authentication traffic that would be blocked. | Palantir, Yamato Security Recommended |
| NTLM/Operational | 8002 | NTLM server blocked audit: Audit Incoming NTLM Traffic that would be blocked Calling process PID: %1 Calling process name: %2 Calling process LUID:... | Palantir, Yamato Security Recommended |
| NTLM/Operational | 8003 | NTLM server blocked in the domain audit: Audit NTLM authentication in this domain User: %1 Domain: %2 Workstation: %3 PID: %4 Process: %5 Logon typ... | Palantir, Yamato Security Recommended |
| PowerShell/Operational | 4100 | %3 Context: %1 User Data: %2. | Olaf Hartong, Yamato Security Recommended |
| PowerShell/Operational | 4101 | %3 Context: %1 User Data: %2. | Olaf Hartong, Yamato Security Recommended |
| PowerShell/Operational | 4102 | %3 Context: %1 User Data: %2. | Olaf Hartong, Yamato Security Recommended |
| PowerShell/Operational | 4103 | %3 Context: %1 User Data: %2. | ASD, Olaf Hartong, Yamato Security, ANSSI Recommended Splunk-UBA Low |
| PowerShell/Operational | 4104 | Creating Scriptblock text (%1 of %2): %3 ScriptBlock ID: %4 Path: %5. | ASD, Olaf Hartong, Yamato Security, JSCU-NL, ANSSI Recommended Splunk-UBA Low |
| PowerShell/Operational | 4105 | Started invocation of ScriptBlock ID: %1 Runspace ID: %2. | Microsoft-WEF, Yamato Security, ANSSI Recommended |
| PowerShell/Operational | 4106 | Completed invocation of ScriptBlock ID: %1 Runspace ID: %2. | Microsoft-WEF, Yamato Security, ANSSI Recommended |
| Security-Auditing/Security | 4608 | Windows is starting up. | Yamato Security, mdecrevoisier Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4609 | Windows is shutting down. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4610 | An authentication package has been loaded by the Local Security Authority. | ASD, Yamato Security, mdecrevoisier, JSCU-NL Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4611 | A trusted logon process has been registered with the Local Security Authority. | ASD, Yamato Security, JSCU-NL Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4612 | Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits. | ASD, Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4614 | A notification package has been loaded by the Security Account Manager. | ASD, Yamato Security, JSCU-NL Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4615 | Invalid use of LPC port. | ASD, Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4616 | The system time was changed. | Microsoft-WEF, ASD, Yamato Security, JSCU-NL, ANSSI Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4618 | A monitored security event pattern has occurred. | Microsoft-AppendixL High ASD, Yamato Security Recommended Splunk-UBA Low |
| Security-Auditing/Security | 4621 | Administrator recovered system from CrashOnAuditFail. | Microsoft-AppendixL Medium ASD, Yamato Security Recommended |
| Security-Auditing/Security | 4622 | A security package has been loaded by the Local Security Authority. | ASD, Yamato Security, JSCU-NL Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4624 | An account was successfully logged on. | Splunk-UBA High Palantir, ASD, Olaf Hartong, Yamato Security, mdecrevoisier, JSCU-NL, ANSSI Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4625 | An account failed to log on. | Splunk-UBA High Palantir, ASD, Olaf Hartong, Yamato Security, mdecrevoisier, JSCU-NL, ANSSI Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4627 | Group membership information. | ASD, JSCU-NL Recommended Splunk-UBA Low |
| Security-Auditing/Security | 4634 | An account was logged off. | Splunk-UBA High Palantir, ASD, Yamato Security, JSCU-NL Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4647 | User initiated logoff. | Palantir, ASD, Yamato Security, JSCU-NL Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4648 | A logon was attempted using explicit credentials. | Palantir, ASD, Yamato Security, JSCU-NL, ANSSI Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4649 | A replay attack was detected. | Microsoft-AppendixL High Palantir, ASD, Yamato Security, mdecrevoisier, JSCU-NL Recommended Splunk-UBA Low |
| Security-Auditing/Security | 4656 | A handle to an object was requested. | Palantir, ASD, Yamato Security, mdecrevoisier Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4657 | A registry value was modified. | Microsoft-WEF, Olaf Hartong, Yamato Security, JSCU-NL, ANSSI Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4658 | The handle to an object was closed. | ASD, Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4660 | An object was deleted. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4661 | A handle to an object was requested. | ASD, Yamato Security, mdecrevoisier Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4662 | An operation was performed on an object. | ASD, mdecrevoisier Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4663 | An attempt was made to access an object. | Palantir, ASD, Olaf Hartong, Yamato Security, JSCU-NL Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4664 | An attempt was made to create a hard link. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4670 | Permissions on an object were changed. | ASD, Yamato Security, mdecrevoisier Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4671 | An application attempted to access a blocked ordinal through the TBS. | ASD, Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4672 | Special privileges assigned to new logon. | Palantir, ASD, Yamato Security, JSCU-NL, ANSSI Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4673 | A privileged service was called. | Palantir, ASD, Yamato Security, mdecrevoisier, JSCU-NL Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4674 | An operation was attempted on a privileged object. | Palantir, ASD, Yamato Security Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4675 | SIDs were filtered. | Microsoft-AppendixL Medium Palantir, ASD, Yamato Security Recommended |
| Security-Auditing/Security | 4688 | A new process has been created. | ASD, Olaf Hartong, Yamato Security, mdecrevoisier, JSCU-NL, ANSSI Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4689 | A process has exited. | Palantir, ASD, Olaf Hartong, JSCU-NL, ANSSI Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4690 | An attempt was made to duplicate a handle to an object. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4691 | Indirect access to an object was requested. | ASD, Yamato Security, mdecrevoisier Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4692 | Backup of data protection master key was attempted. | Microsoft-AppendixL Medium Splunk-UBA Low |
| Security-Auditing/Security | 4693 | Recovery of data protection master key was attempted. | Microsoft-AppendixL Medium Splunk-UBA Low |
| Security-Auditing/Security | 4694 | Protection of auditable protected data was attempted. | ASD Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4695 | Unprotection of auditable protected data was attempted. | ASD Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4696 | A primary token was assigned to process. | ASD, Yamato Security Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4697 | A service was installed in the system. | Palantir, ASD, Yamato Security, JSCU-NL Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4698 | A scheduled task was created. | Palantir, ASD, Yamato Security, JSCU-NL, ANSSI Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4699 | A scheduled task was deleted. | Palantir, ASD, Yamato Security, JSCU-NL, ANSSI Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4700 | A scheduled task was enabled. | Palantir, ASD, Yamato Security, JSCU-NL, ANSSI Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4701 | A scheduled task was disabled. | Palantir, ASD, Yamato Security, JSCU-NL, ANSSI Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4702 | A scheduled task was updated. | ASD, Yamato Security, JSCU-NL, ANSSI Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4703 | A user right was adjusted. | ASD, mdecrevoisier Recommended |
| Security-Auditing/Security | 4704 | A user right was assigned. | NSA, ASD Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4705 | A user right was removed. | ASD Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4706 | A new trust was created to a domain. | Microsoft-AppendixL Medium NSA, ASD, Yamato Security, JSCU-NL Recommended Splunk-UBA Low |
| Security-Auditing/Security | 4707 | A trust to a domain was removed. | ASD, Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4713 | Kerberos policy was changed. | Microsoft-AppendixL Medium NSA, ASD, Yamato Security, JSCU-NL Recommended Splunk-UBA Low |
| Security-Auditing/Security | 4714 | Data Recovery Agent group policy for Encrypting File System (EFS) has changed. | Microsoft-AppendixL Medium NSA Recommended |
| Security-Auditing/Security | 4715 | The audit policy (SACL) on an object was changed. | Microsoft-AppendixL Medium Yamato Security, mdecrevoisier, JSCU-NL Recommended Splunk-UBA Low |
| Security-Auditing/Security | 4716 | Trusted domain information was modified. | Microsoft-AppendixL Medium NSA, ASD, Yamato Security, JSCU-NL Recommended |
| Security-Auditing/Security | 4717 | System security access was granted to an account. | ASD, Yamato Security, JSCU-NL Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4718 | System security access was removed from an account. | ASD, Yamato Security Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4719 | System audit policy was changed. | Microsoft-AppendixL High ASD, Yamato Security, JSCU-NL Recommended Splunk-UBA Low |
| Security-Auditing/Security | 4720 | A user account was created. | Palantir, ASD, Yamato Security, mdecrevoisier, JSCU-NL, ANSSI Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4722 | A user account was enabled. | Palantir, ASD, Yamato Security, JSCU-NL, ANSSI Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4723 | An attempt was made to change an account's password. | Palantir, ASD, Yamato Security, mdecrevoisier, JSCU-NL Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4724 | An attempt was made to reset an account's password. | Microsoft-AppendixL Medium Palantir, ASD, Olaf Hartong, Yamato Security, JSCU-NL Recommended Splunk-UBA Low |
| Security-Auditing/Security | 4725 | A user account was disabled. | Palantir, ASD, Yamato Security, JSCU-NL, ANSSI Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4726 | A user account was deleted. | Palantir, ASD, Yamato Security, JSCU-NL, ANSSI Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4727 | A security-enabled global group was created. | Microsoft-AppendixL Medium ASD, Yamato Security, JSCU-NL Recommended Splunk-UBA Low |
| Security-Auditing/Security | 4728 | A member was added to a security-enabled global group. | Palantir, ASD, Olaf Hartong, Yamato Security, JSCU-NL, ANSSI Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4729 | A member was removed from a security-enabled global group. | ASD, Yamato Security, JSCU-NL Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4730 | A security-enabled global group was deleted. | ASD, Yamato Security, JSCU-NL Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4731 | A security-enabled local group was created. | NSA, ASD, Yamato Security, mdecrevoisier, JSCU-NL Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4732 | A member was added to a security-enabled local group. | Palantir, ASD, Olaf Hartong, Yamato Security, JSCU-NL, ANSSI Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4733 | A member was removed from a security-enabled local group. | Microsoft-WEF, ASD, Yamato Security, JSCU-NL Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4734 | A security-enabled local group was deleted. | ASD, Yamato Security, JSCU-NL Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4735 | A security-enabled local group was changed. | Microsoft-AppendixL Medium NSA, ASD, Yamato Security, JSCU-NL Recommended Splunk-UBA Low |
| Security-Auditing/Security | 4737 | A security-enabled global group was changed. | Microsoft-AppendixL Medium ASD, Yamato Security, JSCU-NL Recommended Splunk-UBA Low |
| Security-Auditing/Security | 4738 | A user account was changed. | ASD, Olaf Hartong, Yamato Security, JSCU-NL Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4739 | Domain Policy was changed. | Microsoft-AppendixL Medium ASD, Yamato Security, JSCU-NL Recommended |
| Security-Auditing/Security | 4740 | A user account was locked out. | Splunk-UBA High Palantir, ASD, Yamato Security, JSCU-NL, ANSSI Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4741 | A computer account was created. | ASD, Yamato Security, mdecrevoisier, JSCU-NL Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4742 | A computer account was changed. | ASD, Yamato Security, JSCU-NL Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4743 | A computer account was deleted. | ASD, Yamato Security, JSCU-NL Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4744 | A security-disabled local group was created. | Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4745 | A security-disabled local group was changed. | Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4746 | A member was added to a security-disabled local group. | Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4747 | A member was removed from a security-disabled local group. | Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4750 | A security-disabled global group was changed. | Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4754 | A security-enabled universal group was created. | Microsoft-AppendixL Medium ASD, Yamato Security, JSCU-NL Recommended Splunk-UBA Low |
| Security-Auditing/Security | 4755 | A security-enabled universal group was changed. | Microsoft-AppendixL Medium ASD, Yamato Security, JSCU-NL Recommended Splunk-UBA Low |
| Security-Auditing/Security | 4756 | A member was added to a security-enabled universal group. | Palantir, ASD, Yamato Security, JSCU-NL, ANSSI Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4757 | A member was removed from a security-enabled universal group. | ASD, Yamato Security, JSCU-NL Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4758 | A security-enabled universal group was deleted. | ASD, Yamato Security, JSCU-NL Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4759 | A security-disabled universal group was created. | Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4760 | A security-disabled universal group was changed. | Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4761 | A member was added to a security-disabled universal group. | Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4764 | A group’s type was changed. | Microsoft-AppendixL Medium ASD, Yamato Security, JSCU-NL Recommended |
| Security-Auditing/Security | 4765 | SID History was added to an account. | Microsoft-AppendixL High ASD, Yamato Security Recommended |
| Security-Auditing/Security | 4766 | An attempt to add SID History to an account failed. | Microsoft-AppendixL High ASD, Yamato Security Recommended |
| Security-Auditing/Security | 4767 | A user account was unlocked. | NSA, ASD, Yamato Security, JSCU-NL Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4768 | A Kerberos authentication ticket (TGT) was requested. | Splunk-UBA High Palantir, ASD, mdecrevoisier, JSCU-NL Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4769 | A Kerberos service ticket was requested. | Splunk-UBA High Palantir, ASD, Olaf Hartong, Yamato Security, mdecrevoisier, JSCU-NL Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4770 | A Kerberos service ticket was renewed. | ASD, Yamato Security Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4771 | Kerberos pre-authentication failed. | Palantir, ASD, JSCU-NL Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4772 | A Kerberos authentication ticket request failed. | Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4774 | An account was mapped for logon. | Palantir, Yamato Security, mdecrevoisier Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4775 | An account could not be mapped for logon. | Palantir, Yamato Security, mdecrevoisier Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4776 | The domain controller attempted to validate the credentials for an account. | Splunk-UBA High Palantir, ASD, Yamato Security, ANSSI Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4777 | The domain controller failed to validate the credentials for an account. | Palantir, Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4778 | A session was reconnected to a Window Station. | Palantir, Yamato Security, JSCU-NL, ANSSI Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4779 | A session was disconnected from a Window Station. | Palantir, ASD, Yamato Security, JSCU-NL, ANSSI Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4780 | The ACL was set on accounts which are members of administrators groups. | Microsoft-AppendixL Medium ASD, Yamato Security, JSCU-NL Recommended |
| Security-Auditing/Security | 4781 | The name of an account was changed. | NSA, ASD, Yamato Security, JSCU-NL Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4782 | The password hash an account was accessed. | NSA, mdecrevoisier, JSCU-NL Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4793 | The Password Policy Checking API was called. | NSA Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4794 | An attempt was made to set the Directory Services Restore Mode administrator password. | Microsoft-AppendixL High ASD, Yamato Security, JSCU-NL Recommended |
| Security-Auditing/Security | 4797 | An attempt was made to query the existence of a blank password for an account. | Yamato Security Recommended Splunk-UBA Low |
| Security-Auditing/Security | 4798 | A user's local group membership was enumerated. | Yamato Security, JSCU-NL Recommended Splunk-UBA Low |
| Security-Auditing/Security | 4799 | A security-enabled local group membership was enumerated. | Yamato Security, JSCU-NL Recommended Splunk-UBA Low |
| Security-Auditing/Security | 4800 | The workstation was locked. | Palantir, Yamato Security Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4801 | The workstation was unlocked. | Palantir, Yamato Security Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4802 | The screen saver was invoked. | Palantir, Yamato Security Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4803 | The screen saver was dismissed. | Palantir, Yamato Security Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4816 | RPC detected an integrity violation while decrypting an incoming message. | Microsoft-AppendixL Medium Yamato Security Recommended |
| Security-Auditing/Security | 4817 | Auditing settings on object were changed. | Yamato Security, JSCU-NL Recommended |
| Security-Auditing/Security | 4820 | A Kerberos Ticket-granting-ticket (TGT) was denied because the device does not meet the access control restrictions. | ASD Recommended Splunk-UBA Low |
| Security-Auditing/Security | 4825 | A user was denied the access to Remote Desktop. | Yamato Security, mdecrevoisier Recommended |
| Security-Auditing/Security | 4864 | A namespace collision was detected. | ASD, Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4865 | A trusted forest information entry was added. | Microsoft-AppendixL Medium ASD, Yamato Security, JSCU-NL Recommended |
| Security-Auditing/Security | 4866 | A trusted forest information entry was removed. | Microsoft-AppendixL Medium ASD, Yamato Security, JSCU-NL Recommended |
| Security-Auditing/Security | 4867 | A trusted forest information entry was modified. | Microsoft-AppendixL Medium ASD, Yamato Security, JSCU-NL Recommended |
| Security-Auditing/Security | 4868 | The certificate manager denied a pending certificate request. | Microsoft-AppendixL Medium Yamato Security, mdecrevoisier Recommended |
| Security-Auditing/Security | 4869 | Certificate Services received a resubmitted certificate request. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4870 | Certificate Services revoked a certificate. | Microsoft-AppendixL Medium NSA, Yamato Security Recommended |
| Security-Auditing/Security | 4871 | Certificate Services received a request to publish the certificate revocation list (CRL). | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4872 | Certificate Services published the certificate revocation list (CRL). | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4873 | A certificate request extension changed. | NSA, Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4874 | One or more certificate request attributes changed. | NSA, Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4875 | Certificate Services received a request to shut down. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4876 | Certificate Services backup started. | ASD, Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4877 | Certificate Services backup completed. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4878 | Certificate Services restore started. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4879 | Certificate Services restore completed. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4880 | Certificate Services started. | Microsoft-WEF, Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4881 | Certificate Services stopped. | Microsoft-WEF, Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4882 | The security permissions for Certificate Services changed. | Microsoft-AppendixL Medium NSA, Yamato Security Recommended |
| Security-Auditing/Security | 4883 | Certificate Services retrieved an archived key. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4884 | Certificate Services imported a certificate into its database. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4885 | The audit filter for Certificate Services changed. | Microsoft-AppendixL Medium NSA, Yamato Security Recommended |
| Security-Auditing/Security | 4886 | Certificate Services received a certificate request. | Microsoft-WEF, ASD, Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4887 | Certificate Services approved a certificate request and issued a certificate. | Microsoft-WEF, ASD, Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4888 | Certificate Services denied a certificate request. | Microsoft-WEF, Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4889 | Certificate Services set the status of a certificate request to pending. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4890 | The certificate manager settings for Certificate Services changed. | Microsoft-AppendixL Medium NSA, Yamato Security Recommended |
| Security-Auditing/Security | 4891 | A configuration entry changed in Certificate Services. | NSA, Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4892 | A property of Certificate Services changed. | Microsoft-AppendixL Medium NSA, Yamato Security Recommended |
| Security-Auditing/Security | 4893 | Certificate Services archived a key. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4894 | Certificate Services imported and archived a key. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4895 | Certificate Services published the CA certificate to Active Directory Domain Services. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4896 | One or more rows have been deleted from the certificate database. | Microsoft-AppendixL Medium Microsoft-WEF, Yamato Security Recommended |
| Security-Auditing/Security | 4897 | Role separation enabled. | Microsoft-AppendixL High ASD, Yamato Security Recommended |
| Security-Auditing/Security | 4898 | Certificate Services loaded a template. | Microsoft-WEF, Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4899 | A Certificate Services template was updated. | NSA, ASD Recommended |
| Security-Auditing/Security | 4900 | Certificate Services template security was updated. | NSA, ASD Recommended |
| Security-Auditing/Security | 4902 | The Per-user audit policy table was created. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4904 | An attempt was made to register a security event source. | Yamato Security, JSCU-NL Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4905 | An attempt was made to unregister a security event source. | Yamato Security, JSCU-NL Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4906 | The CrashOnAuditFail value has changed. | Microsoft-AppendixL Medium Yamato Security, JSCU-NL Recommended |
| Security-Auditing/Security | 4907 | Auditing settings on object were changed. | Microsoft-AppendixL Medium Yamato Security, JSCU-NL Recommended Splunk-UBA Low |
| Security-Auditing/Security | 4908 | Special Groups Logon table modified. | Microsoft-AppendixL Medium Yamato Security, JSCU-NL Recommended |
| Security-Auditing/Security | 4912 | Per User Audit Policy was changed. | Microsoft-AppendixL Medium Yamato Security, JSCU-NL Recommended |
| Security-Auditing/Security | 4928 | An Active Directory replica source naming context was established. | ASD, mdecrevoisier Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4929 | An Active Directory replica source naming context was removed. | ASD Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4944 | The following policy was active when the Windows Firewall started. | mdecrevoisier Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 4946 | A change has been made to Windows Firewall exception list. A rule was added. | Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4947 | A change has been made to Windows Firewall exception list. A rule was modified. | Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4948 | A change has been made to Windows Firewall exception list. A rule was deleted. | Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4950 | A Windows Firewall setting has changed. | Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 4960 | IPsec dropped an inbound packet that failed an integrity check. | Microsoft-AppendixL Medium ASD Recommended |
| Security-Auditing/Security | 4961 | IPsec dropped an inbound packet that failed a replay check. | Microsoft-AppendixL Medium ASD Recommended |
| Security-Auditing/Security | 4962 | IPsec dropped an inbound packet that failed a replay check. | Microsoft-AppendixL Medium ASD Recommended |
| Security-Auditing/Security | 4963 | IPsec dropped an inbound clear text packet that should have been secured. | Microsoft-AppendixL Medium ASD Recommended |
| Security-Auditing/Security | 4964 | Special groups have been assigned to a new logon. | Microsoft-AppendixL High Palantir, ASD, Yamato Security, mdecrevoisier Recommended |
| Security-Auditing/Security | 4965 | IPsec received a packet from a remote computer with an incorrect Security Parameter Index (SPI). | Microsoft-AppendixL Medium ASD Recommended |
| Security-Auditing/Security | 4985 | The state of a transaction has changed. | ASD, Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 5031 | The Windows Firewall Service blocked an application from accepting incoming connections on the network. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 5038 | Code integrity determined that the image hash of a file is not valid. | Microsoft-AppendixL Medium NSA, ASD, Olaf Hartong, Yamato Security, mdecrevoisier, JSCU-NL Recommended |
| Security-Auditing/Security | 5039 | A registry key was virtualized. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 5051 | A file was virtualized. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 5056 | A cryptographic self test was performed. | ASD, Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 5057 | A cryptographic primitive operation failed. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 5060 | Verification operation failed. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 5061 | Cryptographic operation. | ASD, Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 5062 | A kernel-mode cryptographic self test was performed. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 5120 | OCSP Responder Service Started. | Microsoft-AppendixL Medium Yamato Security, mdecrevoisier Recommended |
| Security-Auditing/Security | 5121 | OCSP Responder Service Stopped. | Microsoft-AppendixL Medium Yamato Security Recommended |
| Security-Auditing/Security | 5123 | A configuration entry changed in the OCSP Responder Service. | Microsoft-AppendixL Medium Yamato Security Recommended |
| Security-Auditing/Security | 5124 | A security setting was updated on OCSP Responder Service. | Microsoft-AppendixL High ASD, Yamato Security Recommended |
| Security-Auditing/Security | 5136 | A directory service object was modified. | NSA, ASD, mdecrevoisier Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 5137 | A directory service object was created. | NSA, ASD Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 5138 | A directory service object was undeleted. | NSA, ASD Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 5139 | A directory service object was moved. | NSA, ASD Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 5140 | A network share object was accessed. | Palantir, Olaf Hartong, Yamato Security, mdecrevoisier, JSCU-NL, ANSSI Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 5141 | A directory service object was deleted. | NSA, ASD Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 5142 | A network share object was added. | Microsoft-WEF, Yamato Security, JSCU-NL, ANSSI Recommended Splunk-UBA Low |
| Security-Auditing/Security | 5144 | A network share object was deleted. | Microsoft-WEF, Yamato Security, ANSSI Recommended Splunk-UBA Low |
| Security-Auditing/Security | 5145 | A network share object was checked to see whether client can be granted desired access. | Palantir, Olaf Hartong, mdecrevoisier, ANSSI Recommended Splunk-UBA Low |
| Security-Auditing/Security | 5148 | The Windows Filtering Platform has detected a DoS attack and entered a defensive mode. | Yamato Security, mdecrevoisier Recommended |
| Security-Auditing/Security | 5154 | The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 5155 | The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 5156 | The Windows Filtering Platform has permitted a connection. | Olaf Hartong, Yamato Security Recommended Microsoft-AppendixL, Splunk-UBA Low |
| Security-Auditing/Security | 5157 | The Windows Filtering Platform has blocked a connection. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 5158 | The Windows Filtering Platform has permitted a bind to a local port. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 5159 | The Windows Filtering Platform has blocked a bind to a local port. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 5376 | Credential Manager credentials were backed up. | Microsoft-AppendixL Medium NSA, ASD, Yamato Security, JSCU-NL Recommended |
| Security-Auditing/Security | 5377 | Credential Manager credentials were restored from a backup. | Microsoft-AppendixL Medium NSA, ASD, Yamato Security, JSCU-NL Recommended |
| Security-Auditing/Security | 5378 | The requested credentials delegation was disallowed by policy. | Palantir, Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 5379 | Credential Manager credentials were read. | Yamato Security Recommended Splunk-UBA Low |
| Security-Auditing/Security | 5632 | A request was made to authenticate to a wireless network. | Microsoft-WEF, Yamato Security, JSCU-NL, ANSSI Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 5633 | A request was made to authenticate to a wired network. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 5888 | An object in the COM+ Catalog was modified. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 5889 | An object was deleted from the COM+ Catalog. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 5890 | An object was added to the COM+ Catalog. | Yamato Security Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 6272 | Network Policy Server granted access to a user. | Microsoft-WEF, mdecrevoisier Recommended Microsoft-AppendixL Low |
| Security-Auditing/Security | 6273 | Network Policy Server denied access to a user. | Microsoft-AppendixL Medium Microsoft-WEF Recommended Splunk-UBA Low |
| Security-Auditing/Security | 6274 | Network Policy Server discarded the request for a user. | Microsoft-AppendixL Medium Microsoft-WEF Recommended |
| Security-Auditing/Security | 6275 | Network Policy Server discarded the accounting request for a user. | Microsoft-AppendixL Medium Microsoft-WEF Recommended |
| Security-Auditing/Security | 6276 | Network Policy Server quarantined a user. | Microsoft-AppendixL Medium Microsoft-WEF Recommended Splunk-UBA Low |
| Security-Auditing/Security | 6277 | Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy. | Microsoft-AppendixL Medium Microsoft-WEF Recommended Splunk-UBA Low |
| Security-Auditing/Security | 6278 | Network Policy Server granted full access to a user because the host met the defined health policy. | Microsoft-AppendixL Medium Microsoft-WEF Recommended |
| Security-Auditing/Security | 6279 | Network Policy Server locked the user account due to repeated failed authentication attempts. | Microsoft-AppendixL Medium Microsoft-WEF Recommended |
| Security-Auditing/Security | 6280 | Network Policy Server unlocked the user account. | Microsoft-AppendixL Medium Microsoft-WEF Recommended |
| Security-Auditing/Security | 6281 | Code Integrity determined that the page hashes of an image file are not valid. | NSA, ASD, Olaf Hartong, Yamato Security, JSCU-NL Recommended |
| Security-Auditing/Security | 6410 | Code integrity determined that a file does not meet the security requirements to load into a process. | ASD, Yamato Security, JSCU-NL Recommended |
| Security-Auditing/Security | 6416 | A new external device was recognized by the system. | Yamato Security, mdecrevoisier, JSCU-NL, ANSSI Recommended Splunk-UBA Low |
| SoftwareRestrictionPolicies/Application | 865 | Access to %1 has been restricted by your Administrator by the default software restriction policy level. | NSA, JSCU-NL Recommended |
| SoftwareRestrictionPolicies/Application | 866 | Access to %1 has been restricted by your Administrator by location with policy rule %2 placed on path %3. | NSA, JSCU-NL, ANSSI Recommended |
| SoftwareRestrictionPolicies/Application | 867 | Access to %1 has been restricted by your Administrator by software publisher policy. | NSA, JSCU-NL Recommended |
| SoftwareRestrictionPolicies/Application | 868 | Access to %1 has been restricted by your Administrator by policy rule %2. | NSA, JSCU-NL Recommended |
| SoftwareRestrictionPolicies/Application | 882 | Access to %1 has been restricted by your Administrator by policy rule %2. | NSA, JSCU-NL Recommended |
| Sysmon/Operational | 1 | Process creation | ASD, Olaf Hartong, JSCU-NL Recommended |
| Sysmon/Operational | 2 | A process changed a file creation time | Olaf Hartong, JSCU-NL Recommended |
| Sysmon/Operational | 3 | Network connection | Olaf Hartong, JSCU-NL Recommended |
| Sysmon/Operational | 4 | Sysmon service state changed | Olaf Hartong, JSCU-NL Recommended |
| Sysmon/Operational | 5 | Process terminated | Palantir, Olaf Hartong, JSCU-NL Recommended |
| Sysmon/Operational | 6 | Driver loaded | Olaf Hartong, JSCU-NL Recommended |
| Sysmon/Operational | 7 | Image loaded | Olaf Hartong, JSCU-NL Recommended |
| Sysmon/Operational | 8 | CreateRemoteThread | Palantir, Olaf Hartong, JSCU-NL Recommended |
| Sysmon/Operational | 11 | FileCreate | Palantir, Olaf Hartong, JSCU-NL Recommended |
| Sysmon/Operational | 12 | RegistryEvent (Object create and delete) | Palantir, Olaf Hartong, JSCU-NL Recommended |
| Sysmon/Operational | 13 | RegistryEvent (Value Set) | Palantir, Olaf Hartong, JSCU-NL Recommended |
| Sysmon/Operational | 14 | RegistryEvent (Key and Value Rename) | Palantir, Olaf Hartong, JSCU-NL Recommended |
| Sysmon/Operational | 15 | FileCreateStreamHash | Palantir, Olaf Hartong, JSCU-NL Recommended |
| Sysmon/Operational | 16 | ServiceConfigurationChange | Olaf Hartong, JSCU-NL Recommended |
| Sysmon/Operational | 17 | PipeEvent (Pipe Created) | Palantir, Olaf Hartong, JSCU-NL Recommended |
| Sysmon/Operational | 18 | PipeEvent (Pipe Connected) | Palantir, Olaf Hartong, JSCU-NL Recommended |
| Sysmon/Operational | 19 | WmiEvent (WmiEventFilter activity detected) | Olaf Hartong, JSCU-NL Recommended |
| Sysmon/Operational | 20 | WmiEvent (WmiEventConsumer activity detected) | Olaf Hartong, JSCU-NL Recommended |
| Sysmon/Operational | 21 | WmiEvent (WmiEventConsumerToFilter activity detected) | Olaf Hartong, JSCU-NL Recommended |
| Sysmon/Operational | 23 | FileDelete (File Delete archived) | Palantir, JSCU-NL Recommended |
| Sysmon/Operational | 25 | ProcessTampering (Process image change) | Palantir, JSCU-NL Recommended |
| TaskScheduler/Operational | 100 | Task Scheduler started "%3" instance of the "%1" task for user "%2". | Olaf Hartong, Yamato Security, ANSSI Recommended |
| TaskScheduler/Operational | 101 | Task Scheduler failed to start "%1" task for user "%2". | Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 102 | Task Scheduler successfully finished "%3" instance of the "%1" task for user "%2". | Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 103 | Task Scheduler failed to start instance "%2" of "%1" task for user "%3" . | Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 104 | Task Scheduler failed to log on "%1" . | Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 105 | Task Scheduler failed to impersonate "%1" . | Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 106 | User "%2" registered Task Scheduler task "%1". | Microsoft-WEF, Olaf Hartong, Yamato Security, ANSSI Recommended |
| TaskScheduler/Operational | 107 | Task Scheduler launched "%2" instance of task "%1" due to a time trigger condition. | Olaf Hartong, Yamato Security, ANSSI Recommended |
| TaskScheduler/Operational | 108 | Task Scheduler launched "%2" instance of task "%1" according to an event trigger. | Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 109 | Task Scheduler launched "%2" instance of task "%1" according to a registration trigger. | Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 110 | Task Scheduler launched "%2" instance of task "%1" for user "%3" . | Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 111 | Task Scheduler terminated "%2" instance of the "%1" task. | Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 112 | Task Scheduler could not start task "%1" because the network was unavailable. | Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 113 | Task registered task "%1" , but not all specified triggers will start the task. | Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 114 | Task Scheduler could not launch task "%1" as scheduled. | Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 115 | Task Scheduler failed to roll back a transaction when updating or deleting a task. | Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 116 | Task Scheduler validated the configuration for task "%1" , but credentials could not be stored. | Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 117 | Task Scheduler launched "%2" instance of task "%1" due to an idle condition. | Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 118 | Task Scheduler launched "%2" instance of task "%1" due to system startup. | ASD, Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 119 | Task Scheduler launched "%3" instance of task "%1" due to user "%2" logon. | ASD, Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 120 | Task Scheduler launched "%3" instance of task "%1" due to user "%2" connecting to the console trigger. | Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 121 | Task Scheduler launched "%3" instance of task "%1" due to user "%2" disconnecting from the console trigger. | Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 122 | Task Scheduler launched "%3" instance of task "%1" due to user "%2" remotely connecting trigger. | Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 123 | Task Scheduler launched "%3" instance of task "%1" due to user "%2" remotely disconnecting trigger. | Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 124 | Task Scheduler launched "%3" instance of task "%1" due to user "%2" locking the computer trigger. | Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 125 | Task Scheduler launched "%3" instance of task "%1" due to user "%2" unlocking the computer trigger. | Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 126 | Task Scheduler failed to execute task "%1" . | Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 127 | Task Scheduler failed to execute task "%1" due to a shutdown race condition. | Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 128 | Task Scheduler did not launch task "%1" , because current time exceeds the configured task end time. | Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 129 | Task Scheduler launch task "%1" , instance "%2" with process ID %3. | ASD, Olaf Hartong, Yamato Security, ANSSI Recommended |
| TaskScheduler/Operational | 130 | Task Scheduler failed to start task "%1" due to the service being busy. | Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 131 | Task Scheduler failed to start task "%1" because the number of tasks in the task queue exceeding the quota currently configured to %2. | Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 132 | Task Scheduler task launching queue quota is approaching its preset limit of tasks currently configured to %1. | Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 133 | Task Scheduler failed to start task %1" in TaskEngine "%2" for user "%3". | Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 134 | Task Engine "%1" for user "%2" is approaching its preset limit of tasks. | Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 135 | Task Scheduler could not start task "%1" because the machine was not idle. | Olaf Hartong, Yamato Security Recommended |
| TaskScheduler/Operational | 140 | User "%2" updated Task Scheduler task "%1". | Yamato Security, ANSSI Recommended |
| TaskScheduler/Operational | 141 | User "%2" deleted Task Scheduler task "%1". | Microsoft-WEF, Yamato Security, ANSSI Recommended |
| TaskScheduler/Operational | 142 | User "%2" disabled Task Scheduler task "%1". | Microsoft-WEF, Yamato Security, ANSSI Recommended |
| TaskScheduler/Operational | 200 | Task Scheduler launched action "%2" in instance "%3" of task "%1". | NSA, ASD, Olaf Hartong, Yamato Security, JSCU-NL, ANSSI Recommended |
| TaskScheduler/Operational | 201 | Task Scheduler successfully completed task "%1" , instance "%3" , action "%2" . | Yamato Security, JSCU-NL Recommended |
| TerminalServices-ClientActiveXCore/Operational | 1024 | RDP ClientActiveX is trying to connect to the server | Microsoft-WEF, JSCU-NL, ANSSI Recommended |
| TerminalServices-LocalSessionManager/Operational | 21 | Remote Desktop Services: Session logon succeeded: User: %1 Session ID: %2 Source Network Address: %3. | ASD, Yamato Security Recommended |
| TerminalServices-LocalSessionManager/Operational | 22 | Remote Desktop Services: Shell start notification received: User: %1 Session ID: %2 Source Network Address: %3. | ASD, Yamato Security Recommended |
| TerminalServices-LocalSessionManager/Operational | 23 | Remote Desktop Services: Session logoff succeeded: User: %1 Session ID: %2. | ASD, Yamato Security Recommended |
| TerminalServices-LocalSessionManager/Operational | 24 | Remote Desktop Services: Session has been disconnected: User: EC2AMAZ-3NFFVNI\samurai Session ID: 5 Source Network Address: 219. | ASD, Yamato Security Recommended |
| TerminalServices-LocalSessionManager/Operational | 25 | Remote Desktop Services: Session reconnection succeeded: User: EC2AMAZ-3NFFVNI\samurai Session ID: 4 Source Network Address: 219. | ASD, Yamato Security Recommended |
| Windows Defender/Operational | 1005 | %1 scan has encountered an error and terminated. | NSA, Olaf Hartong Recommended |
| Windows Defender/Operational | 1006 | %1 has detected malware or other potentially unwanted software. | Microsoft-Defender, Olaf Hartong, JSCU-NL Recommended |
| Windows Defender/Operational | 1007 | %1 has taken action to protect this machine from malware or other potentially unwanted software. | Microsoft-Defender, JSCU-NL Recommended |
| Windows Defender/Operational | 1008 | %1 has encountered an error when taking action on malware or other potentially unwanted software. | Microsoft-Defender, Olaf Hartong, JSCU-NL Recommended |
| Windows Defender/Operational | 1009 | %1 has restored an item from quarantine. | Microsoft-WEF, JSCU-NL Recommended |
| Windows Defender/Operational | 1010 | %1 has encountered an error trying to restore an item from quarantine. | NSA, Olaf Hartong, JSCU-NL Recommended |
| Windows Defender/Operational | 1116 | %1 has detected malware or other potentially unwanted software. | Microsoft-Defender, Olaf Hartong, JSCU-NL Recommended |
| Windows Defender/Operational | 1117 | %1 has taken action to protect this machine from malware or other potentially unwanted software. | Microsoft-Defender, Olaf Hartong, JSCU-NL Recommended |
| Windows Defender/Operational | 1118 | %1 has encountered a non-critical error when taking action on malware or other potentially unwanted software. | Microsoft-Defender, JSCU-NL Recommended |
| Windows Defender/Operational | 1119 | %1 has encountered a critical error when taking action on malware or other potentially unwanted software. | Microsoft-Defender, JSCU-NL Recommended |
| Windows Defender/Operational | 1121 | Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator. | Microsoft-Defender, JSCU-NL Recommended |
| Windows Defender/Operational | 2001 | %1 has encountered an error trying to update security intelligence. | Microsoft-Defender, Olaf Hartong Recommended |
| Windows Defender/Operational | 2003 | %1 has encountered an error trying to update the engine. | NSA, Olaf Hartong Recommended |
| Windows Defender/Operational | 2004 | %1 has encountered an error trying to update security intelligence and will attempt to revert to a previous version. | NSA, Olaf Hartong Recommended |
| Windows Defender/Operational | 3002 | %1 Real-Time Protection feature has encountered an error and failed. | Microsoft-Defender, Olaf Hartong Recommended |
| Windows Defender/Operational | 5007 | %1 Configuration has changed. | Microsoft-Defender, JSCU-NL Recommended |
| Windows Defender/Operational | 5008 | %1 engine has been terminated due to an unexpected error. | Microsoft-Defender, Olaf Hartong Recommended |
| WMI-Activity/Operational | 5857 | %1 provider started with result code %2. | Palantir, ASD, Yamato Security, JSCU-NL Recommended |
| WMI-Activity/Operational | 5858 | Id = %1; ClientMachine = %2; User = %3; ClientProcessId = %4; Component = %5; Operation = %6; ResultCode = %7; PossibleCause = %8. | Palantir, ASD, Yamato Security, JSCU-NL Recommended |
| WMI-Activity/Operational | 5859 | Namespace = %1; NotificationQuery = %2; OwnerName = %3; HostProcessID = %4; Provider= %5, queryID = %6; PossibleCause = %7. | Palantir, ASD, Yamato Security Recommended |
| WMI-Activity/Operational | 5860 | Namespace = %1; NotificationQuery = %2; UserName = %3; ClientProcessID = %4, ClientMachine = %5; PossibleCause = %6. | Palantir, ASD, Yamato Security, JSCU-NL Recommended |
| WMI-Activity/Operational | 5861 | Namespace = %1; Eventfilter = %2 (refer to its activate eventid:5859); Consumer = %3; PossibleCause = %4. | Palantir, ASD, Olaf Hartong, Yamato Security, JSCU-NL Recommended |
| PowerShell/Windows PowerShell | 400 | ASD, Olaf Hartong Recommended | |
| PowerShell/Windows PowerShell | 800 | Microsoft-WEF, ANSSI Recommended | |
| Service Control Manager/System | 7031 | NSA, JSCU-NL Recommended | |
| Service Control Manager/System | 7034 | NSA, JSCU-NL Recommended | |
| Service Control Manager/System | 7040 | The start type of the msdsm service was changed from boot start to demand start. | Palantir, Olaf Hartong, JSCU-NL Recommended |
| Service Control Manager/System | 7045 | A service was installed in the system. | Palantir, Olaf Hartong, ASD, ANSSI Recommended Splunk-UBA Low |
This table shows the 383 events other pages link to directly.