Elastic rule coverage

51 events across 6 providers with Elastic detection rules, 922 rule mappings total. Each rule links to its own page (predicates, exclusions, shared indicators). For the rule-centric ATT&CK browse across every vendor, see all detection rules; non-Windows Elastic rules are grouped by platform and technique at Elastic non-Windows coverage.

Microsoft-Windows-Security-Auditing

Event ID 4624 An account was successfully logged on. 11 rules
Event ID 4625 An account failed to log on. 6 rules
Event ID 4656 A handle to an object was requested. 1 rule
Event ID 4662 An operation was performed on an object. 6 rules
Event ID 4672 Special privileges assigned to new logon. 1 rule
Event ID 4674 An operation was attempted on a privileged object. 1 rule
Event ID 4688 A new process has been created. 259 rules
Event ID 4697 A service was installed in the system. 4 rules
Event ID 4698 A scheduled task was created. 3 rules
Event ID 4699 A scheduled task was deleted. 1 rule
Event ID 4702 A scheduled task was updated. 1 rule
Event ID 4703 A user right was adjusted. 1 rule
Event ID 4704 A user right was assigned. 1 rule
Event ID 4719 System audit policy was changed. 1 rule
Event ID 4720 A user account was created. 1 rule
Event ID 4723 An attempt was made to change an account's password. 1 rule
Event ID 4724 An attempt was made to reset an account's password. 1 rule
Event ID 4728 A member was added to a security-enabled global group. 2 rules
Event ID 4732 A member was added to a security-enabled local group. 1 rule
Event ID 4738 A user account was changed. 3 rules
Event ID 4742 A computer account was changed. 1 rule
Event ID 4756 A member was added to a security-enabled universal group. 1 rule
Event ID 4768 A Kerberos authentication ticket (TGT) was requested. 1 rule
Event ID 4769 A Kerberos service ticket was requested. 1 rule
Event ID 4781 The name of an account was changed. 1 rule
Event ID 5136 A directory service object was modified. 11 rules
Event ID 5137 A directory service object was created. 5 rules
Event ID 5145 A network share object was checked to see whether client can be granted desired access. 8 rules
Event ID 5152 The Windows Filtering Platform blocked a packet. 1 rule
Event ID 5157 The Windows Filtering Platform has blocked a connection. 1 rule
Event ID 5382 Vault credentials were read. 1 rule

Microsoft-Windows-Sysmon

Event ID 1 Process creation 259 rules
Event ID 2 A process changed a file creation time 1 rule
Event ID 3 Network connection 49 rules
Event ID 6 Driver loaded 2 rules
Event ID 7 Image loaded 20 rules
Event ID 8 CreateRemoteThread 1 rule
Event ID 10 ProcessAccess 7 rules
Event ID 11 FileCreate 34 rules
Event ID 12 RegistryEvent (Object create and delete) 60 rules
Event ID 13 RegistryEvent (Value Set) 60 rules
Event ID 14 RegistryEvent (Key and Value Rename) 60 rules
Event ID 17 PipeEvent (Pipe Created) 1 rule
Event ID 22 DNSEvent (DNS query) 3 rules
Event ID 23 FileDelete (File Delete archived) 5 rules
Event ID 26 FileDeleteDetected (File Delete logged) 5 rules

Microsoft-Windows-Eventlog

Event ID 104 The LogFileCleared.Channel log file was cleared. 1 rule
Event ID 1102 The audit log was cleared. 1 rule

Microsoft-Windows-PowerShell

Event ID 4104 Creating Scriptblock text (MessageNumber of MessageTotal). 13 rules

Microsoft-Windows-WMI-Activity

Event ID 21 WMI Events were bound. 1 rule

Service-Control-Manager

Event ID 7045 1 rule