Collection Priority Reference

952 events across 54 providers from 12 sources.

Download as JSON (952 events)

SourceEvents
Palantir Windows Event Forwarding73
NSA Event Forwarding Guidance105
Microsoft Defender for Endpoint19
Microsoft Appendix L: Events to Monitor352
Microsoft Windows Event Forwarding for Intrusion Detection47
ASD Priority Logs for SIEM Ingestion181
Olaf Hartong ATTACKdatamap124
Yamato Security EventLog Baseline Guide521
mdecrevoisier Windows Auditing Baseline36
JSCU-NL Logging Essentials199
ANSSI Guide to Microsoft Logging72
Splunk User Behavior Analytics102
Provider / ChannelIDTitleSources
Application Error/Application1000Faulting application name: %1, version: %2, time stamp: 0x%3 Faulting module name: %4, version: %5, time stamp: 0x%6 Exception code: 0x%7 Fault off...Microsoft-WEF, JSCU-NL Recommended
Application Hang/Application1002The program Widgets.Microsoft-WEF, JSCU-NL Recommended
LsaSrv/Operational300Groups assigned to a new logon.Microsoft-WEF, ANSSI Recommended
AppLocker/EXE and DLL8000AppID policy conversion failed.ASD, Olaf Hartong Recommended
AppLocker/EXE and DLL8001The AppLocker policy was applied successfully to this computer.ASD, Olaf Hartong Recommended
AppLocker/EXE and DLL8002%11 was allowed to run.NSA, Olaf Hartong, JSCU-NL Recommended
AppLocker/EXE and DLL8003%11 was allowed to run but would have been prevented from running if the AppLocker policy were enforced.Palantir, Olaf Hartong, JSCU-NL Recommended
AppLocker/EXE and DLL8004%11 was prevented from running.Palantir, ASD, Olaf Hartong, JSCU-NL Recommended
AppLocker/MSI and Script8005%11 was allowed to run.NSA, Olaf Hartong, JSCU-NL Recommended
AppLocker/MSI and Script8006%11 was allowed to run but would have been prevented from running if the AppLocker policy were enforced.NSA, Olaf Hartong, JSCU-NL Recommended
AppLocker/MSI and Script8007%11 was prevented from running.NSA, ASD, Olaf Hartong, JSCU-NL Recommended
AppLocker/EXE and DLL8008%2: AppLocker component not available on this SKU.ASD, Olaf Hartong Recommended
AppLocker/Packaged app-Execution8020%11 was allowed to run.NSA, Olaf Hartong, JSCU-NL Recommended
AppLocker/Packaged app-Execution8022%11 was prevented from running.ASD, Olaf Hartong Recommended
AppLocker/Packaged app-Deployment8023%11 was allowed to be installed.NSA, Olaf Hartong, JSCU-NL Recommended
AppLocker/Packaged app-Deployment8025%11 was prevented from running.ASD, Olaf Hartong Recommended
AppLocker/Packaged app-Execution8027No packaged apps can be executed while Exe rules are being enforced and no Packaged app rules have been configured.ASD, Olaf Hartong Recommended
Bits-Client/Operational1BITS job "%2" with ID %1 has been resumed.Yamato Security, JSCU-NL Recommended
Bits-Client/Operational3The BITS service created a new job.Yamato Security, JSCU-NL Recommended
Bits-Client/Operational4The transfer job is complete.Yamato Security, JSCU-NL Recommended
Bits-Client/Operational59BITS started the %2 transfer job that is associated with the %4 URL.Yamato Security, JSCU-NL Recommended
CodeIntegrity/Operational3001Code Integrity determined an unsigned kernel module %2 is loaded into the system.NSA, Yamato Security Recommended
CodeIntegrity/Operational3002Code Integrity is unable to verify the image integrity of the file %2 because the set of per-page image hashes could not be found on the system.NSA, Yamato Security Recommended
CodeIntegrity/Operational3003Code Integrity is unable to verify the image integrity of the file %2 because the set of per-page image hashes could not be found on the system.NSA, Yamato Security Recommended
CodeIntegrity/Operational3004Windows is unable to verify the image integrity of the file %2 because file hash could not be found on the system.NSA, Yamato Security Recommended
CodeIntegrity/Operational3010Code Integrity was unable to load the %2 catalog.NSA, Yamato Security Recommended
CodeIntegrity/Operational3023The driver %2 is blocked from loading as the driver has been revoked by Microsoft.NSA, Yamato Security Recommended
CodeIntegrity/Operational3033Code Integrity determined that a process (%4) attempted to load %2 that did not meet the %5 signing level requirements.Palantir, ASD, Yamato Security Recommended
CodeIntegrity/Operational3063Code Integrity determined that a process (%4) attempted to load %2 that did not meet the security requirements for %5.ASD, Yamato Security Recommended
CodeIntegrity/Operational3065Code Integrity determined that a process (%4) attempted to load %2 that did not meet the security requirements for %5.Palantir, Yamato Security Recommended
CodeIntegrity/Operational3077Code Integrity determined that a process (%4) attempted to load %2 that did not meet the %5 signing level requirements or violated code integrity p...ASD, Yamato Security Recommended
CodeIntegrity/Operational3089Signature information for another event.ASD, Yamato Security Recommended
DNS-Client/Operational3008DNS query is completed for the name %1, type %2, query options %3 with status %4 Results %5.Microsoft-WEF, JSCU-NL Recommended
DNSServer/Analytical257RESPONSE_SUCCESS: TCP=.NSA, ASD Recommended
DriverFrameworks-UserMode/Operational2004The UMDF Host is loading driver %4 at level %3 for device %2.Microsoft-WEF, ANSSI Recommended
Eventlog/System104The System log file was cleared.Microsoft-WEF, JSCU-NL, ANSSI Recommended
Eventlog/Security1102The audit log was cleared.Microsoft-AppendixL High
ASD, Olaf Hartong, JSCU-NL, ANSSI, Splunk-UBA Recommended
Kernel-General/System12The operating system started at system time 1.3825413334687505e+09.Microsoft-WEF, JSCU-NL, ANSSI Recommended
Kernel-General/System13The operating system is shutting down at system time StopTime.Microsoft-WEF, JSCU-NL Recommended
NTLM/Operational8001NTLM client blocked audit: Audit outgoing NTLM authentication traffic that would be blocked.Palantir, Yamato Security Recommended
NTLM/Operational8002NTLM server blocked audit: Audit Incoming NTLM Traffic that would be blocked Calling process PID: %1 Calling process name: %2 Calling process LUID:...Palantir, Yamato Security Recommended
NTLM/Operational8003NTLM server blocked in the domain audit: Audit NTLM authentication in this domain User: %1 Domain: %2 Workstation: %3 PID: %4 Process: %5 Logon typ...Palantir, Yamato Security Recommended
PowerShell/Operational4100%3 Context: %1 User Data: %2.Olaf Hartong, Yamato Security Recommended
PowerShell/Operational4101%3 Context: %1 User Data: %2.Olaf Hartong, Yamato Security Recommended
PowerShell/Operational4102%3 Context: %1 User Data: %2.Olaf Hartong, Yamato Security Recommended
PowerShell/Operational4103%3 Context: %1 User Data: %2.ASD, Olaf Hartong, Yamato Security, ANSSI Recommended
Splunk-UBA Low
PowerShell/Operational4104Creating Scriptblock text (%1 of %2): %3 ScriptBlock ID: %4 Path: %5.ASD, Olaf Hartong, Yamato Security, JSCU-NL, ANSSI Recommended
Splunk-UBA Low
PowerShell/Operational4105Started invocation of ScriptBlock ID: %1 Runspace ID: %2.Microsoft-WEF, Yamato Security, ANSSI Recommended
PowerShell/Operational4106Completed invocation of ScriptBlock ID: %1 Runspace ID: %2.Microsoft-WEF, Yamato Security, ANSSI Recommended
Security-Auditing/Security4608Windows is starting up.Yamato Security, mdecrevoisier Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4609Windows is shutting down.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4610An authentication package has been loaded by the Local Security Authority.ASD, Yamato Security, mdecrevoisier, JSCU-NL Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4611A trusted logon process has been registered with the Local Security Authority.ASD, Yamato Security, JSCU-NL Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4612Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits.ASD, Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4614A notification package has been loaded by the Security Account Manager.ASD, Yamato Security, JSCU-NL Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4615Invalid use of LPC port.ASD, Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4616The system time was changed.Microsoft-WEF, ASD, Yamato Security, JSCU-NL, ANSSI Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4618A monitored security event pattern has occurred.Microsoft-AppendixL High
ASD, Yamato Security Recommended
Splunk-UBA Low
Security-Auditing/Security4621Administrator recovered system from CrashOnAuditFail.Microsoft-AppendixL Medium
ASD, Yamato Security Recommended
Security-Auditing/Security4622A security package has been loaded by the Local Security Authority.ASD, Yamato Security, JSCU-NL Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4624An account was successfully logged on.Splunk-UBA High
Palantir, ASD, Olaf Hartong, Yamato Security, mdecrevoisier, JSCU-NL, ANSSI Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4625An account failed to log on.Splunk-UBA High
Palantir, ASD, Olaf Hartong, Yamato Security, mdecrevoisier, JSCU-NL, ANSSI Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4627Group membership information.ASD, JSCU-NL Recommended
Splunk-UBA Low
Security-Auditing/Security4634An account was logged off.Splunk-UBA High
Palantir, ASD, Yamato Security, JSCU-NL Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4647User initiated logoff.Palantir, ASD, Yamato Security, JSCU-NL Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4648A logon was attempted using explicit credentials.Palantir, ASD, Yamato Security, JSCU-NL, ANSSI Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4649A replay attack was detected.Microsoft-AppendixL High
Palantir, ASD, Yamato Security, mdecrevoisier, JSCU-NL Recommended
Splunk-UBA Low
Security-Auditing/Security4656A handle to an object was requested.Palantir, ASD, Yamato Security, mdecrevoisier Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4657A registry value was modified.Microsoft-WEF, Olaf Hartong, Yamato Security, JSCU-NL, ANSSI Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4658The handle to an object was closed.ASD, Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4660An object was deleted.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4661A handle to an object was requested.ASD, Yamato Security, mdecrevoisier Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4662An operation was performed on an object.ASD, mdecrevoisier Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4663An attempt was made to access an object.Palantir, ASD, Olaf Hartong, Yamato Security, JSCU-NL Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4664An attempt was made to create a hard link.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4670Permissions on an object were changed.ASD, Yamato Security, mdecrevoisier Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4671An application attempted to access a blocked ordinal through the TBS.ASD, Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4672Special privileges assigned to new logon.Palantir, ASD, Yamato Security, JSCU-NL, ANSSI Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4673A privileged service was called.Palantir, ASD, Yamato Security, mdecrevoisier, JSCU-NL Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4674An operation was attempted on a privileged object.Palantir, ASD, Yamato Security Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4675SIDs were filtered.Microsoft-AppendixL Medium
Palantir, ASD, Yamato Security Recommended
Security-Auditing/Security4688A new process has been created.ASD, Olaf Hartong, Yamato Security, mdecrevoisier, JSCU-NL, ANSSI Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4689A process has exited.Palantir, ASD, Olaf Hartong, JSCU-NL, ANSSI Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4690An attempt was made to duplicate a handle to an object.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4691Indirect access to an object was requested.ASD, Yamato Security, mdecrevoisier Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4692Backup of data protection master key was attempted.Microsoft-AppendixL Medium
Splunk-UBA Low
Security-Auditing/Security4693Recovery of data protection master key was attempted.Microsoft-AppendixL Medium
Splunk-UBA Low
Security-Auditing/Security4694Protection of auditable protected data was attempted.ASD Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4695Unprotection of auditable protected data was attempted.ASD Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4696A primary token was assigned to process.ASD, Yamato Security Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4697A service was installed in the system.Palantir, ASD, Yamato Security, JSCU-NL Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4698A scheduled task was created.Palantir, ASD, Yamato Security, JSCU-NL, ANSSI Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4699A scheduled task was deleted.Palantir, ASD, Yamato Security, JSCU-NL, ANSSI Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4700A scheduled task was enabled.Palantir, ASD, Yamato Security, JSCU-NL, ANSSI Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4701A scheduled task was disabled.Palantir, ASD, Yamato Security, JSCU-NL, ANSSI Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4702A scheduled task was updated.ASD, Yamato Security, JSCU-NL, ANSSI Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4703A user right was adjusted.ASD, mdecrevoisier Recommended
Security-Auditing/Security4704A user right was assigned.NSA, ASD Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4705A user right was removed.ASD Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4706A new trust was created to a domain.Microsoft-AppendixL Medium
NSA, ASD, Yamato Security, JSCU-NL Recommended
Splunk-UBA Low
Security-Auditing/Security4707A trust to a domain was removed.ASD, Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4713Kerberos policy was changed.Microsoft-AppendixL Medium
NSA, ASD, Yamato Security, JSCU-NL Recommended
Splunk-UBA Low
Security-Auditing/Security4714Data Recovery Agent group policy for Encrypting File System (EFS) has changed.Microsoft-AppendixL Medium
NSA Recommended
Security-Auditing/Security4715The audit policy (SACL) on an object was changed.Microsoft-AppendixL Medium
Yamato Security, mdecrevoisier, JSCU-NL Recommended
Splunk-UBA Low
Security-Auditing/Security4716Trusted domain information was modified.Microsoft-AppendixL Medium
NSA, ASD, Yamato Security, JSCU-NL Recommended
Security-Auditing/Security4717System security access was granted to an account.ASD, Yamato Security, JSCU-NL Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4718System security access was removed from an account.ASD, Yamato Security Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4719System audit policy was changed.Microsoft-AppendixL High
ASD, Yamato Security, JSCU-NL Recommended
Splunk-UBA Low
Security-Auditing/Security4720A user account was created.Palantir, ASD, Yamato Security, mdecrevoisier, JSCU-NL, ANSSI Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4722A user account was enabled.Palantir, ASD, Yamato Security, JSCU-NL, ANSSI Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4723An attempt was made to change an account's password.Palantir, ASD, Yamato Security, mdecrevoisier, JSCU-NL Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4724An attempt was made to reset an account's password.Microsoft-AppendixL Medium
Palantir, ASD, Olaf Hartong, Yamato Security, JSCU-NL Recommended
Splunk-UBA Low
Security-Auditing/Security4725A user account was disabled.Palantir, ASD, Yamato Security, JSCU-NL, ANSSI Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4726A user account was deleted.Palantir, ASD, Yamato Security, JSCU-NL, ANSSI Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4727A security-enabled global group was created.Microsoft-AppendixL Medium
ASD, Yamato Security, JSCU-NL Recommended
Splunk-UBA Low
Security-Auditing/Security4728A member was added to a security-enabled global group.Palantir, ASD, Olaf Hartong, Yamato Security, JSCU-NL, ANSSI Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4729A member was removed from a security-enabled global group.ASD, Yamato Security, JSCU-NL Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4730A security-enabled global group was deleted.ASD, Yamato Security, JSCU-NL Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4731A security-enabled local group was created.NSA, ASD, Yamato Security, mdecrevoisier, JSCU-NL Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4732A member was added to a security-enabled local group.Palantir, ASD, Olaf Hartong, Yamato Security, JSCU-NL, ANSSI Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4733A member was removed from a security-enabled local group.Microsoft-WEF, ASD, Yamato Security, JSCU-NL Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4734A security-enabled local group was deleted.ASD, Yamato Security, JSCU-NL Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4735A security-enabled local group was changed.Microsoft-AppendixL Medium
NSA, ASD, Yamato Security, JSCU-NL Recommended
Splunk-UBA Low
Security-Auditing/Security4737A security-enabled global group was changed.Microsoft-AppendixL Medium
ASD, Yamato Security, JSCU-NL Recommended
Splunk-UBA Low
Security-Auditing/Security4738A user account was changed.ASD, Olaf Hartong, Yamato Security, JSCU-NL Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4739Domain Policy was changed.Microsoft-AppendixL Medium
ASD, Yamato Security, JSCU-NL Recommended
Security-Auditing/Security4740A user account was locked out.Splunk-UBA High
Palantir, ASD, Yamato Security, JSCU-NL, ANSSI Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4741A computer account was created.ASD, Yamato Security, mdecrevoisier, JSCU-NL Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4742A computer account was changed.ASD, Yamato Security, JSCU-NL Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4743A computer account was deleted.ASD, Yamato Security, JSCU-NL Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4744A security-disabled local group was created.Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4745A security-disabled local group was changed.Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4746A member was added to a security-disabled local group.Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4747A member was removed from a security-disabled local group.Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4750A security-disabled global group was changed.Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4754A security-enabled universal group was created.Microsoft-AppendixL Medium
ASD, Yamato Security, JSCU-NL Recommended
Splunk-UBA Low
Security-Auditing/Security4755A security-enabled universal group was changed.Microsoft-AppendixL Medium
ASD, Yamato Security, JSCU-NL Recommended
Splunk-UBA Low
Security-Auditing/Security4756A member was added to a security-enabled universal group.Palantir, ASD, Yamato Security, JSCU-NL, ANSSI Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4757A member was removed from a security-enabled universal group.ASD, Yamato Security, JSCU-NL Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4758A security-enabled universal group was deleted.ASD, Yamato Security, JSCU-NL Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4759A security-disabled universal group was created.Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4760A security-disabled universal group was changed.Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4761A member was added to a security-disabled universal group.Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4764A group’s type was changed.Microsoft-AppendixL Medium
ASD, Yamato Security, JSCU-NL Recommended
Security-Auditing/Security4765SID History was added to an account.Microsoft-AppendixL High
ASD, Yamato Security Recommended
Security-Auditing/Security4766An attempt to add SID History to an account failed.Microsoft-AppendixL High
ASD, Yamato Security Recommended
Security-Auditing/Security4767A user account was unlocked.NSA, ASD, Yamato Security, JSCU-NL Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4768A Kerberos authentication ticket (TGT) was requested.Splunk-UBA High
Palantir, ASD, mdecrevoisier, JSCU-NL Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4769A Kerberos service ticket was requested.Splunk-UBA High
Palantir, ASD, Olaf Hartong, Yamato Security, mdecrevoisier, JSCU-NL Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4770A Kerberos service ticket was renewed.ASD, Yamato Security Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4771Kerberos pre-authentication failed.Palantir, ASD, JSCU-NL Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4772A Kerberos authentication ticket request failed.Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4774An account was mapped for logon.Palantir, Yamato Security, mdecrevoisier Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4775An account could not be mapped for logon.Palantir, Yamato Security, mdecrevoisier Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4776The domain controller attempted to validate the credentials for an account.Splunk-UBA High
Palantir, ASD, Yamato Security, ANSSI Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4777The domain controller failed to validate the credentials for an account.Palantir, Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4778A session was reconnected to a Window Station.Palantir, Yamato Security, JSCU-NL, ANSSI Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4779A session was disconnected from a Window Station.Palantir, ASD, Yamato Security, JSCU-NL, ANSSI Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4780The ACL was set on accounts which are members of administrators groups.Microsoft-AppendixL Medium
ASD, Yamato Security, JSCU-NL Recommended
Security-Auditing/Security4781The name of an account was changed.NSA, ASD, Yamato Security, JSCU-NL Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4782The password hash an account was accessed.NSA, mdecrevoisier, JSCU-NL Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4793The Password Policy Checking API was called.NSA Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4794An attempt was made to set the Directory Services Restore Mode administrator password.Microsoft-AppendixL High
ASD, Yamato Security, JSCU-NL Recommended
Security-Auditing/Security4797An attempt was made to query the existence of a blank password for an account.Yamato Security Recommended
Splunk-UBA Low
Security-Auditing/Security4798A user's local group membership was enumerated.Yamato Security, JSCU-NL Recommended
Splunk-UBA Low
Security-Auditing/Security4799A security-enabled local group membership was enumerated.Yamato Security, JSCU-NL Recommended
Splunk-UBA Low
Security-Auditing/Security4800The workstation was locked.Palantir, Yamato Security Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4801The workstation was unlocked.Palantir, Yamato Security Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4802The screen saver was invoked.Palantir, Yamato Security Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4803The screen saver was dismissed.Palantir, Yamato Security Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4816RPC detected an integrity violation while decrypting an incoming message.Microsoft-AppendixL Medium
Yamato Security Recommended
Security-Auditing/Security4817Auditing settings on object were changed.Yamato Security, JSCU-NL Recommended
Security-Auditing/Security4820A Kerberos Ticket-granting-ticket (TGT) was denied because the device does not meet the access control restrictions.ASD Recommended
Splunk-UBA Low
Security-Auditing/Security4825A user was denied the access to Remote Desktop.Yamato Security, mdecrevoisier Recommended
Security-Auditing/Security4864A namespace collision was detected.ASD, Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4865A trusted forest information entry was added.Microsoft-AppendixL Medium
ASD, Yamato Security, JSCU-NL Recommended
Security-Auditing/Security4866A trusted forest information entry was removed.Microsoft-AppendixL Medium
ASD, Yamato Security, JSCU-NL Recommended
Security-Auditing/Security4867A trusted forest information entry was modified.Microsoft-AppendixL Medium
ASD, Yamato Security, JSCU-NL Recommended
Security-Auditing/Security4868The certificate manager denied a pending certificate request.Microsoft-AppendixL Medium
Yamato Security, mdecrevoisier Recommended
Security-Auditing/Security4869Certificate Services received a resubmitted certificate request.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4870Certificate Services revoked a certificate.Microsoft-AppendixL Medium
NSA, Yamato Security Recommended
Security-Auditing/Security4871Certificate Services received a request to publish the certificate revocation list (CRL).Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4872Certificate Services published the certificate revocation list (CRL).Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4873A certificate request extension changed.NSA, Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4874One or more certificate request attributes changed.NSA, Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4875Certificate Services received a request to shut down.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4876Certificate Services backup started.ASD, Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4877Certificate Services backup completed.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4878Certificate Services restore started.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4879Certificate Services restore completed.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4880Certificate Services started.Microsoft-WEF, Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4881Certificate Services stopped.Microsoft-WEF, Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4882The security permissions for Certificate Services changed.Microsoft-AppendixL Medium
NSA, Yamato Security Recommended
Security-Auditing/Security4883Certificate Services retrieved an archived key.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4884Certificate Services imported a certificate into its database.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4885The audit filter for Certificate Services changed.Microsoft-AppendixL Medium
NSA, Yamato Security Recommended
Security-Auditing/Security4886Certificate Services received a certificate request.Microsoft-WEF, ASD, Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4887Certificate Services approved a certificate request and issued a certificate.Microsoft-WEF, ASD, Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4888Certificate Services denied a certificate request.Microsoft-WEF, Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4889Certificate Services set the status of a certificate request to pending.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4890The certificate manager settings for Certificate Services changed.Microsoft-AppendixL Medium
NSA, Yamato Security Recommended
Security-Auditing/Security4891A configuration entry changed in Certificate Services.NSA, Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4892A property of Certificate Services changed.Microsoft-AppendixL Medium
NSA, Yamato Security Recommended
Security-Auditing/Security4893Certificate Services archived a key.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4894Certificate Services imported and archived a key.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4895Certificate Services published the CA certificate to Active Directory Domain Services.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4896One or more rows have been deleted from the certificate database.Microsoft-AppendixL Medium
Microsoft-WEF, Yamato Security Recommended
Security-Auditing/Security4897Role separation enabled.Microsoft-AppendixL High
ASD, Yamato Security Recommended
Security-Auditing/Security4898Certificate Services loaded a template.Microsoft-WEF, Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4899A Certificate Services template was updated.NSA, ASD Recommended
Security-Auditing/Security4900Certificate Services template security was updated.NSA, ASD Recommended
Security-Auditing/Security4902The Per-user audit policy table was created.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4904An attempt was made to register a security event source.Yamato Security, JSCU-NL Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4905An attempt was made to unregister a security event source.Yamato Security, JSCU-NL Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4906The CrashOnAuditFail value has changed.Microsoft-AppendixL Medium
Yamato Security, JSCU-NL Recommended
Security-Auditing/Security4907Auditing settings on object were changed.Microsoft-AppendixL Medium
Yamato Security, JSCU-NL Recommended
Splunk-UBA Low
Security-Auditing/Security4908Special Groups Logon table modified.Microsoft-AppendixL Medium
Yamato Security, JSCU-NL Recommended
Security-Auditing/Security4912Per User Audit Policy was changed.Microsoft-AppendixL Medium
Yamato Security, JSCU-NL Recommended
Security-Auditing/Security4928An Active Directory replica source naming context was established.ASD, mdecrevoisier Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4929An Active Directory replica source naming context was removed.ASD Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4944The following policy was active when the Windows Firewall started.mdecrevoisier Recommended
Microsoft-AppendixL Low
Security-Auditing/Security4946A change has been made to Windows Firewall exception list. A rule was added.Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4947A change has been made to Windows Firewall exception list. A rule was modified.Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4948A change has been made to Windows Firewall exception list. A rule was deleted.Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4950A Windows Firewall setting has changed.Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security4960IPsec dropped an inbound packet that failed an integrity check.Microsoft-AppendixL Medium
ASD Recommended
Security-Auditing/Security4961IPsec dropped an inbound packet that failed a replay check.Microsoft-AppendixL Medium
ASD Recommended
Security-Auditing/Security4962IPsec dropped an inbound packet that failed a replay check.Microsoft-AppendixL Medium
ASD Recommended
Security-Auditing/Security4963IPsec dropped an inbound clear text packet that should have been secured.Microsoft-AppendixL Medium
ASD Recommended
Security-Auditing/Security4964Special groups have been assigned to a new logon.Microsoft-AppendixL High
Palantir, ASD, Yamato Security, mdecrevoisier Recommended
Security-Auditing/Security4965IPsec received a packet from a remote computer with an incorrect Security Parameter Index (SPI).Microsoft-AppendixL Medium
ASD Recommended
Security-Auditing/Security4985The state of a transaction has changed.ASD, Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security5031The Windows Firewall Service blocked an application from accepting incoming connections on the network.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security5038Code integrity determined that the image hash of a file is not valid.Microsoft-AppendixL Medium
NSA, ASD, Olaf Hartong, Yamato Security, mdecrevoisier, JSCU-NL Recommended
Security-Auditing/Security5039A registry key was virtualized.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security5051A file was virtualized.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security5056A cryptographic self test was performed.ASD, Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security5057A cryptographic primitive operation failed.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security5060Verification operation failed.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security5061Cryptographic operation.ASD, Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security5062A kernel-mode cryptographic self test was performed.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security5120OCSP Responder Service Started.Microsoft-AppendixL Medium
Yamato Security, mdecrevoisier Recommended
Security-Auditing/Security5121OCSP Responder Service Stopped.Microsoft-AppendixL Medium
Yamato Security Recommended
Security-Auditing/Security5123A configuration entry changed in the OCSP Responder Service.Microsoft-AppendixL Medium
Yamato Security Recommended
Security-Auditing/Security5124A security setting was updated on OCSP Responder Service.Microsoft-AppendixL High
ASD, Yamato Security Recommended
Security-Auditing/Security5136A directory service object was modified.NSA, ASD, mdecrevoisier Recommended
Microsoft-AppendixL Low
Security-Auditing/Security5137A directory service object was created.NSA, ASD Recommended
Microsoft-AppendixL Low
Security-Auditing/Security5138A directory service object was undeleted.NSA, ASD Recommended
Microsoft-AppendixL Low
Security-Auditing/Security5139A directory service object was moved.NSA, ASD Recommended
Microsoft-AppendixL Low
Security-Auditing/Security5140A network share object was accessed.Palantir, Olaf Hartong, Yamato Security, mdecrevoisier, JSCU-NL, ANSSI Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security5141A directory service object was deleted.NSA, ASD Recommended
Microsoft-AppendixL Low
Security-Auditing/Security5142A network share object was added.Microsoft-WEF, Yamato Security, JSCU-NL, ANSSI Recommended
Splunk-UBA Low
Security-Auditing/Security5144A network share object was deleted.Microsoft-WEF, Yamato Security, ANSSI Recommended
Splunk-UBA Low
Security-Auditing/Security5145A network share object was checked to see whether client can be granted desired access.Palantir, Olaf Hartong, mdecrevoisier, ANSSI Recommended
Splunk-UBA Low
Security-Auditing/Security5148The Windows Filtering Platform has detected a DoS attack and entered a defensive mode.Yamato Security, mdecrevoisier Recommended
Security-Auditing/Security5154The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security5155The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security5156The Windows Filtering Platform has permitted a connection.Olaf Hartong, Yamato Security Recommended
Microsoft-AppendixL, Splunk-UBA Low
Security-Auditing/Security5157The Windows Filtering Platform has blocked a connection.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security5158The Windows Filtering Platform has permitted a bind to a local port.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security5159The Windows Filtering Platform has blocked a bind to a local port.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security5376Credential Manager credentials were backed up.Microsoft-AppendixL Medium
NSA, ASD, Yamato Security, JSCU-NL Recommended
Security-Auditing/Security5377Credential Manager credentials were restored from a backup.Microsoft-AppendixL Medium
NSA, ASD, Yamato Security, JSCU-NL Recommended
Security-Auditing/Security5378The requested credentials delegation was disallowed by policy.Palantir, Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security5379Credential Manager credentials were read.Yamato Security Recommended
Splunk-UBA Low
Security-Auditing/Security5632A request was made to authenticate to a wireless network.Microsoft-WEF, Yamato Security, JSCU-NL, ANSSI Recommended
Microsoft-AppendixL Low
Security-Auditing/Security5633A request was made to authenticate to a wired network.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security5888An object in the COM+ Catalog was modified.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security5889An object was deleted from the COM+ Catalog.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security5890An object was added to the COM+ Catalog.Yamato Security Recommended
Microsoft-AppendixL Low
Security-Auditing/Security6272Network Policy Server granted access to a user.Microsoft-WEF, mdecrevoisier Recommended
Microsoft-AppendixL Low
Security-Auditing/Security6273Network Policy Server denied access to a user.Microsoft-AppendixL Medium
Microsoft-WEF Recommended
Splunk-UBA Low
Security-Auditing/Security6274Network Policy Server discarded the request for a user.Microsoft-AppendixL Medium
Microsoft-WEF Recommended
Security-Auditing/Security6275Network Policy Server discarded the accounting request for a user.Microsoft-AppendixL Medium
Microsoft-WEF Recommended
Security-Auditing/Security6276Network Policy Server quarantined a user.Microsoft-AppendixL Medium
Microsoft-WEF Recommended
Splunk-UBA Low
Security-Auditing/Security6277Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy.Microsoft-AppendixL Medium
Microsoft-WEF Recommended
Splunk-UBA Low
Security-Auditing/Security6278Network Policy Server granted full access to a user because the host met the defined health policy.Microsoft-AppendixL Medium
Microsoft-WEF Recommended
Security-Auditing/Security6279Network Policy Server locked the user account due to repeated failed authentication attempts.Microsoft-AppendixL Medium
Microsoft-WEF Recommended
Security-Auditing/Security6280Network Policy Server unlocked the user account.Microsoft-AppendixL Medium
Microsoft-WEF Recommended
Security-Auditing/Security6281Code Integrity determined that the page hashes of an image file are not valid.NSA, ASD, Olaf Hartong, Yamato Security, JSCU-NL Recommended
Security-Auditing/Security6410Code integrity determined that a file does not meet the security requirements to load into a process.ASD, Yamato Security, JSCU-NL Recommended
Security-Auditing/Security6416A new external device was recognized by the system.Yamato Security, mdecrevoisier, JSCU-NL, ANSSI Recommended
Splunk-UBA Low
SoftwareRestrictionPolicies/Application865Access to %1 has been restricted by your Administrator by the default software restriction policy level.NSA, JSCU-NL Recommended
SoftwareRestrictionPolicies/Application866Access to %1 has been restricted by your Administrator by location with policy rule %2 placed on path %3.NSA, JSCU-NL, ANSSI Recommended
SoftwareRestrictionPolicies/Application867Access to %1 has been restricted by your Administrator by software publisher policy.NSA, JSCU-NL Recommended
SoftwareRestrictionPolicies/Application868Access to %1 has been restricted by your Administrator by policy rule %2.NSA, JSCU-NL Recommended
SoftwareRestrictionPolicies/Application882Access to %1 has been restricted by your Administrator by policy rule %2.NSA, JSCU-NL Recommended
Sysmon/Operational1Process creationASD, Olaf Hartong, JSCU-NL Recommended
Sysmon/Operational2A process changed a file creation timeOlaf Hartong, JSCU-NL Recommended
Sysmon/Operational3Network connectionOlaf Hartong, JSCU-NL Recommended
Sysmon/Operational4Sysmon service state changedOlaf Hartong, JSCU-NL Recommended
Sysmon/Operational5Process terminatedPalantir, Olaf Hartong, JSCU-NL Recommended
Sysmon/Operational6Driver loadedOlaf Hartong, JSCU-NL Recommended
Sysmon/Operational7Image loadedOlaf Hartong, JSCU-NL Recommended
Sysmon/Operational8CreateRemoteThreadPalantir, Olaf Hartong, JSCU-NL Recommended
Sysmon/Operational11FileCreatePalantir, Olaf Hartong, JSCU-NL Recommended
Sysmon/Operational12RegistryEvent (Object create and delete)Palantir, Olaf Hartong, JSCU-NL Recommended
Sysmon/Operational13RegistryEvent (Value Set)Palantir, Olaf Hartong, JSCU-NL Recommended
Sysmon/Operational14RegistryEvent (Key and Value Rename)Palantir, Olaf Hartong, JSCU-NL Recommended
Sysmon/Operational15FileCreateStreamHashPalantir, Olaf Hartong, JSCU-NL Recommended
Sysmon/Operational16ServiceConfigurationChangeOlaf Hartong, JSCU-NL Recommended
Sysmon/Operational17PipeEvent (Pipe Created)Palantir, Olaf Hartong, JSCU-NL Recommended
Sysmon/Operational18PipeEvent (Pipe Connected)Palantir, Olaf Hartong, JSCU-NL Recommended
Sysmon/Operational19WmiEvent (WmiEventFilter activity detected)Olaf Hartong, JSCU-NL Recommended
Sysmon/Operational20WmiEvent (WmiEventConsumer activity detected)Olaf Hartong, JSCU-NL Recommended
Sysmon/Operational21WmiEvent (WmiEventConsumerToFilter activity detected)Olaf Hartong, JSCU-NL Recommended
Sysmon/Operational23FileDelete (File Delete archived)Palantir, JSCU-NL Recommended
Sysmon/Operational25ProcessTampering (Process image change)Palantir, JSCU-NL Recommended
TaskScheduler/Operational100Task Scheduler started "%3" instance of the "%1" task for user "%2".Olaf Hartong, Yamato Security, ANSSI Recommended
TaskScheduler/Operational101Task Scheduler failed to start "%1" task for user "%2".Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational102Task Scheduler successfully finished "%3" instance of the "%1" task for user "%2".Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational103Task Scheduler failed to start instance "%2" of "%1" task for user "%3" .Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational104Task Scheduler failed to log on "%1" .Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational105Task Scheduler failed to impersonate "%1" .Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational106User "%2" registered Task Scheduler task "%1".Microsoft-WEF, Olaf Hartong, Yamato Security, ANSSI Recommended
TaskScheduler/Operational107Task Scheduler launched "%2" instance of task "%1" due to a time trigger condition.Olaf Hartong, Yamato Security, ANSSI Recommended
TaskScheduler/Operational108Task Scheduler launched "%2" instance of task "%1" according to an event trigger.Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational109Task Scheduler launched "%2" instance of task "%1" according to a registration trigger.Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational110Task Scheduler launched "%2" instance of task "%1" for user "%3" .Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational111Task Scheduler terminated "%2" instance of the "%1" task.Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational112Task Scheduler could not start task "%1" because the network was unavailable.Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational113Task registered task "%1" , but not all specified triggers will start the task.Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational114Task Scheduler could not launch task "%1" as scheduled.Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational115Task Scheduler failed to roll back a transaction when updating or deleting a task.Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational116Task Scheduler validated the configuration for task "%1" , but credentials could not be stored.Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational117Task Scheduler launched "%2" instance of task "%1" due to an idle condition.Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational118Task Scheduler launched "%2" instance of task "%1" due to system startup.ASD, Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational119Task Scheduler launched "%3" instance of task "%1" due to user "%2" logon.ASD, Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational120Task Scheduler launched "%3" instance of task "%1" due to user "%2" connecting to the console trigger.Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational121Task Scheduler launched "%3" instance of task "%1" due to user "%2" disconnecting from the console trigger.Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational122Task Scheduler launched "%3" instance of task "%1" due to user "%2" remotely connecting trigger.Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational123Task Scheduler launched "%3" instance of task "%1" due to user "%2" remotely disconnecting trigger.Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational124Task Scheduler launched "%3" instance of task "%1" due to user "%2" locking the computer trigger.Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational125Task Scheduler launched "%3" instance of task "%1" due to user "%2" unlocking the computer trigger.Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational126Task Scheduler failed to execute task "%1" .Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational127Task Scheduler failed to execute task "%1" due to a shutdown race condition.Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational128Task Scheduler did not launch task "%1" , because current time exceeds the configured task end time.Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational129Task Scheduler launch task "%1" , instance "%2" with process ID %3.ASD, Olaf Hartong, Yamato Security, ANSSI Recommended
TaskScheduler/Operational130Task Scheduler failed to start task "%1" due to the service being busy.Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational131Task Scheduler failed to start task "%1" because the number of tasks in the task queue exceeding the quota currently configured to %2.Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational132Task Scheduler task launching queue quota is approaching its preset limit of tasks currently configured to %1.Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational133Task Scheduler failed to start task %1" in TaskEngine "%2" for user "%3".Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational134Task Engine "%1" for user "%2" is approaching its preset limit of tasks.Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational135Task Scheduler could not start task "%1" because the machine was not idle.Olaf Hartong, Yamato Security Recommended
TaskScheduler/Operational140User "%2" updated Task Scheduler task "%1".Yamato Security, ANSSI Recommended
TaskScheduler/Operational141User "%2" deleted Task Scheduler task "%1".Microsoft-WEF, Yamato Security, ANSSI Recommended
TaskScheduler/Operational142User "%2" disabled Task Scheduler task "%1".Microsoft-WEF, Yamato Security, ANSSI Recommended
TaskScheduler/Operational200Task Scheduler launched action "%2" in instance "%3" of task "%1".NSA, ASD, Olaf Hartong, Yamato Security, JSCU-NL, ANSSI Recommended
TaskScheduler/Operational201Task Scheduler successfully completed task "%1" , instance "%3" , action "%2" .Yamato Security, JSCU-NL Recommended
TerminalServices-ClientActiveXCore/Operational1024RDP ClientActiveX is trying to connect to the serverMicrosoft-WEF, JSCU-NL, ANSSI Recommended
TerminalServices-LocalSessionManager/Operational21Remote Desktop Services: Session logon succeeded: User: %1 Session ID: %2 Source Network Address: %3.ASD, Yamato Security Recommended
TerminalServices-LocalSessionManager/Operational22Remote Desktop Services: Shell start notification received: User: %1 Session ID: %2 Source Network Address: %3.ASD, Yamato Security Recommended
TerminalServices-LocalSessionManager/Operational23Remote Desktop Services: Session logoff succeeded: User: %1 Session ID: %2.ASD, Yamato Security Recommended
TerminalServices-LocalSessionManager/Operational24Remote Desktop Services: Session has been disconnected: User: EC2AMAZ-3NFFVNI\samurai Session ID: 5 Source Network Address: 219.ASD, Yamato Security Recommended
TerminalServices-LocalSessionManager/Operational25Remote Desktop Services: Session reconnection succeeded: User: EC2AMAZ-3NFFVNI\samurai Session ID: 4 Source Network Address: 219.ASD, Yamato Security Recommended
Windows Defender/Operational1005%1 scan has encountered an error and terminated.NSA, Olaf Hartong Recommended
Windows Defender/Operational1006%1 has detected malware or other potentially unwanted software.Microsoft-Defender, Olaf Hartong, JSCU-NL Recommended
Windows Defender/Operational1007%1 has taken action to protect this machine from malware or other potentially unwanted software.Microsoft-Defender, JSCU-NL Recommended
Windows Defender/Operational1008%1 has encountered an error when taking action on malware or other potentially unwanted software.Microsoft-Defender, Olaf Hartong, JSCU-NL Recommended
Windows Defender/Operational1009%1 has restored an item from quarantine.Microsoft-WEF, JSCU-NL Recommended
Windows Defender/Operational1010%1 has encountered an error trying to restore an item from quarantine.NSA, Olaf Hartong, JSCU-NL Recommended
Windows Defender/Operational1116%1 has detected malware or other potentially unwanted software.Microsoft-Defender, Olaf Hartong, JSCU-NL Recommended
Windows Defender/Operational1117%1 has taken action to protect this machine from malware or other potentially unwanted software.Microsoft-Defender, Olaf Hartong, JSCU-NL Recommended
Windows Defender/Operational1118%1 has encountered a non-critical error when taking action on malware or other potentially unwanted software.Microsoft-Defender, JSCU-NL Recommended
Windows Defender/Operational1119%1 has encountered a critical error when taking action on malware or other potentially unwanted software.Microsoft-Defender, JSCU-NL Recommended
Windows Defender/Operational1121Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.Microsoft-Defender, JSCU-NL Recommended
Windows Defender/Operational2001%1 has encountered an error trying to update security intelligence.Microsoft-Defender, Olaf Hartong Recommended
Windows Defender/Operational2003%1 has encountered an error trying to update the engine.NSA, Olaf Hartong Recommended
Windows Defender/Operational2004%1 has encountered an error trying to update security intelligence and will attempt to revert to a previous version.NSA, Olaf Hartong Recommended
Windows Defender/Operational3002%1 Real-Time Protection feature has encountered an error and failed.Microsoft-Defender, Olaf Hartong Recommended
Windows Defender/Operational5007%1 Configuration has changed.Microsoft-Defender, JSCU-NL Recommended
Windows Defender/Operational5008%1 engine has been terminated due to an unexpected error.Microsoft-Defender, Olaf Hartong Recommended
WMI-Activity/Operational5857%1 provider started with result code %2.Palantir, ASD, Yamato Security, JSCU-NL Recommended
WMI-Activity/Operational5858Id = %1; ClientMachine = %2; User = %3; ClientProcessId = %4; Component = %5; Operation = %6; ResultCode = %7; PossibleCause = %8.Palantir, ASD, Yamato Security, JSCU-NL Recommended
WMI-Activity/Operational5859Namespace = %1; NotificationQuery = %2; OwnerName = %3; HostProcessID = %4; Provider= %5, queryID = %6; PossibleCause = %7.Palantir, ASD, Yamato Security Recommended
WMI-Activity/Operational5860Namespace = %1; NotificationQuery = %2; UserName = %3; ClientProcessID = %4, ClientMachine = %5; PossibleCause = %6.Palantir, ASD, Yamato Security, JSCU-NL Recommended
WMI-Activity/Operational5861Namespace = %1; Eventfilter = %2 (refer to its activate eventid:5859); Consumer = %3; PossibleCause = %4.Palantir, ASD, Olaf Hartong, Yamato Security, JSCU-NL Recommended
PowerShell/Windows PowerShell400ASD, Olaf Hartong Recommended
PowerShell/Windows PowerShell800Microsoft-WEF, ANSSI Recommended
Service Control Manager/System7031NSA, JSCU-NL Recommended
Service Control Manager/System7034NSA, JSCU-NL Recommended
Service Control Manager/System7040The start type of the msdsm service was changed from boot start to demand start.Palantir, Olaf Hartong, JSCU-NL Recommended
Service Control Manager/System7045A service was installed in the system.Palantir, Olaf Hartong, ASD, ANSSI Recommended
Splunk-UBA Low

This table shows the 383 events other pages link to directly.