Kusto rule coverage

132 events across 17 providers with Microsoft Sentinel and Defender XDR Kusto detection rules, 757 rule mappings total. Each rule links to its own page (predicates, exclusions, shared indicators). For the rule-centric ATT&CK browse across every vendor, see all detection rules; non-Windows Kusto rules are grouped by platform and technique at Kusto non-Windows coverage.

Microsoft-Windows-Security-Auditing

Event ID 412 AD FS authentication failure. 1 rule
Event ID 501 AD FS proxy authentication request. 1 rule
Event ID 4624 An account was successfully logged on. 24 rules
Event ID 4625 An account failed to log on. 13 rules
Event ID 4634 An account was logged off. 5 rules
Event ID 4647 User initiated logoff. 1 rule
Event ID 4648 A logon was attempted using explicit credentials. 1 rule
Event ID 4656 A handle to an object was requested. 4 rules
Event ID 4657 A registry value was modified. 12 rules
Event ID 4660 An object was deleted. 5 rules
Event ID 4662 An operation was performed on an object. 4 rules
Event ID 4663 An attempt was made to access an object. 26 rules
Event ID 4670 Permissions on an object were changed. 1 rule
Event ID 4672 Special privileges assigned to new logon. 1 rule
Event ID 4675 SIDs were filtered. 1 rule
Event ID 4688 A new process has been created. 93 rules
Event ID 4689 A process has exited. 12 rules
Event ID 4697 A service was installed in the system. 1 rule
Event ID 4698 A scheduled task was created. 1 rule
Event ID 4699 A scheduled task was deleted. 1 rule
Event ID 4700 A scheduled task was enabled. 1 rule
Event ID 4701 A scheduled task was disabled. 1 rule
Event ID 4702 A scheduled task was updated. 1 rule
Event ID 4720 A user account was created. 4 rules
Event ID 4722 A user account was enabled. 2 rules
Event ID 4723 An attempt was made to change an account's password. 2 rules
Event ID 4724 An attempt was made to reset an account's password. 1 rule
Event ID 4725 A user account was disabled. 1 rule
Event ID 4726 A user account was deleted. 1 rule
Event ID 4727 A security-enabled global group was created. 1 rule
Event ID 4728 A member was added to a security-enabled global group. 3 rules
Event ID 4729 A member was removed from a security-enabled global group. 1 rule
Event ID 4731 A security-enabled local group was created. 1 rule
Event ID 4732 A member was added to a security-enabled local group. 5 rules
Event ID 4733 A member was removed from a security-enabled local group. 1 rule
Event ID 4738 A user account was changed. 2 rules
Event ID 4754 A security-enabled universal group was created. 1 rule
Event ID 4756 A member was added to a security-enabled universal group. 3 rules
Event ID 4757 A member was removed from a security-enabled universal group. 1 rule
Event ID 4768 A Kerberos authentication ticket (TGT) was requested. 2 rules
Event ID 4769 A Kerberos service ticket was requested. 4 rules
Event ID 5058 Key file operation. 1 rule
Event ID 5059 Key migration operation. 1 rule
Event ID 5136 A directory service object was modified. 5 rules
Event ID 5143 A network share object was modified. 1 rule
Event ID 5145 A network share object was checked to see whether client can be granted desired access. 2 rules
Event ID 5152 The Windows Filtering Platform blocked a packet. 8 rules
Event ID 5154 The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections. 8 rules
Event ID 5155 The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections. 8 rules
Event ID 5156 The Windows Filtering Platform has permitted a connection. 35 rules
Event ID 5157 The Windows Filtering Platform has blocked a connection. 11 rules
Event ID 5158 The Windows Filtering Platform has permitted a bind to a local port. 8 rules
Event ID 5159 The Windows Filtering Platform has blocked a bind to a local port. 8 rules

Microsoft-Windows-Sysmon

Event ID 1 Process creation 73 rules
Event ID 2 A process changed a file creation time 1 rule
Event ID 3 Network connection 34 rules
Event ID 4 Sysmon service state changed 1 rule
Event ID 5 Process terminated 13 rules
Event ID 6 Driver loaded 2 rules
Event ID 7 Image loaded 8 rules
Event ID 8 CreateRemoteThread 4 rules
Event ID 10 ProcessAccess 2 rules
Event ID 11 FileCreate 17 rules
Event ID 12 RegistryEvent (Object create and delete) 5 rules
Event ID 13 RegistryEvent (Value Set) 15 rules
Event ID 14 RegistryEvent (Key and Value Rename) 5 rules
Event ID 17 PipeEvent (Pipe Created) 3 rules
Event ID 18 PipeEvent (Pipe Connected) 5 rules
Event ID 19 WmiEvent (WmiEventFilter activity detected) 1 rule
Event ID 20 WmiEvent (WmiEventConsumer activity detected) 1 rule
Event ID 21 WmiEvent (WmiEventConsumerToFilter activity detected) 1 rule
Event ID 22 DNSEvent (DNS query) 11 rules
Event ID 23 FileDelete (File Delete archived) 4 rules
Event ID 26 FileDeleteDetected (File Delete logged) 4 rules

Defender-DeviceEvents

any Defender event (any) 10 rules
PowerShellCommand PowerShell command executed 1 rule
AmsiScriptContent AMSI script content captured 1 rule
CreateRemoteThreadApiCall CreateRemoteThread API call 4 rules
NamedPipeEvent Named pipe event 2 rules
UserAccountAddedToLocalGroup User account added to local group 1 rule
OpenProcessApiCall Process opened (OpenProcess API call) 1 rule
ProcessPrimaryTokenModified Process primary token modified 1 rule
LdapSearch LDAP search 1 rule
ClrUnbackedModuleLoaded CLR unbacked module loaded 1 rule
AsrUntrustedExecutableAudited ASR untrusted executable (audited) 1 rule
DriverLoad Driver loaded 2 rules
NtAllocateVirtualMemoryRemoteApiCall Remote virtual memory allocation (NtAllocateVirtualMemory) 3 rules
MemoryRemoteProtect Remote virtual memory protection change 2 rules
NtMapViewOfSectionRemoteApiCall Remote section map (NtMapViewOfSection) 3 rules
QueueUserApcRemoteApiCall Remote APC queued (QueueUserApc) 3 rules
SetThreadContextRemoteApiCall Remote thread context change (SetThreadContext) 3 rules
NtAllocateVirtualMemoryApiCall NtAllocateVirtualMemory API call 1 rule
ReadProcessMemoryApiCall ReadProcessMemory API call 1 rule

Microsoft-Windows-Threat-Intelligence

Event ID 1 Remote Virtual Memory Allocation 3 rules
Event ID 2 Remote Virtual Memory Protection Change 2 rules
Event ID 3 Remote Section Map 3 rules
Event ID 4 Remote APC Queue 3 rules
Event ID 5 Remote Thread Context Change 3 rules
Event ID 6 Local Virtual Memory Allocation 1 rule
Event ID 11 Local Virtual Memory Read 1 rule
Event ID 30 Driver Load 2 rules

Defender-DeviceNetworkEvents

any Network activity (any) 9 rules
ConnectionSuccess Connection succeeded 13 rules
ConnectionFailed Connection failed 1 rule
InboundConnectionAccepted Inbound connection accepted 1 rule
ConnectionAttempt Connection attempt 1 rule
NetworkSignatureInspected Network signature inspected 1 rule

Defender-DeviceFileEvents

any File activity (any) 4 rules
FileCreated File created 7 rules
FileModified File modified 1 rule
FileRenamed File renamed 3 rules

Defender-DeviceRegistryEvents

RegistryKeyDeleted Registry key deleted 5 rules
RegistryValueSet Registry value set 10 rules
RegistryValueDeleted Registry value deleted 5 rules
RegistryKeyRenamed Registry key renamed 5 rules

Microsoft-Windows-Windows-Defender

Event ID 1116 1 rule
Event ID 1117 1 rule
Event ID 1121 1 rule
Event ID 1122 1 rule

Defender-DeviceLogonEvents

any Logon activity (any) 2 rules
LogonSuccess Logon succeeded 5 rules
LogonFailed Logon failed 1 rule

Defender-DeviceImageLoadEvents

any Image load (any) 6 rules
ImageLoaded Image loaded 3 rules

Defender-DeviceProcessEvents

any Process activity (any) 42 rules
ProcessCreated Process created 8 rules

Microsoft-Windows-DotNETRuntime

Event ID 152 ModuleID=ModuleID. 1 rule

Microsoft-Windows-Eventlog

Event ID 1102 The audit log was cleared. 2 rules

Microsoft-Windows-Kernel-Audit-API-Calls

Event ID 5 OpenProcess API call audited 1 rule

Microsoft-Windows-LDAP-Client

Event ID 30 LDAP search request 1 rule

Microsoft-Windows-PowerShell

Event ID 4104 Creating Scriptblock text (MessageNumber of MessageTotal). 1 rule

Service-Control-Manager

Event ID 7045 1 rule