Sigma rule coverage

328 events across 69 providers with Sigma detection rules, 4302 rule mappings total.

Microsoft-Windows-Security-Auditing

Event ID 675: Pre-authentication failed (legacy Windows 2003 Kerberos event; superseded by 4771). 1 rule
Event ID 4611: A trusted logon process has been registered with the Local Security Authority. 1 rule
Event ID 4616: The system time was changed. 2 rules
Event ID 4622: A security package has been loaded by the Local Security Authority. 1 rule
Event ID 4624: An account was successfully logged on. 29 rules
Event ID 4625: An account failed to log on. 11 rules
Event ID 4634: An account was logged off. 1 rule
Event ID 4647: User initiated logoff. 1 rule
Event ID 4648: A logon was attempted using explicit credentials. 4 rules
Event ID 4649: A replay attack was detected. 1 rule
Event ID 4656: A handle to an object was requested. 18 rules
Event ID 4657: A registry value was modified. 5 rules
Event ID 4658: The handle to an object was closed. 1 rule
Event ID 4661: A handle to an object was requested. 9 rules
Event ID 4662: An operation was performed on an object. 13 rules
Event ID 4663: An attempt was made to access an object. 22 rules
Event ID 4664: An attempt was made to create a hard link. 1 rule
Event ID 4673: A privileged service was called. 3 rules
Event ID 4674: An operation was attempted on a privileged object. 4 rules
Event ID 4688: A new process has been created. 735 rules
Event ID 4692: Backup of data protection master key was attempted. 1 rule
Event ID 4697: A service was installed in the system. 27 rules
Event ID 4698: A scheduled task was created. 7 rules
Event ID 4699: A scheduled task was deleted. 4 rules
Event ID 4701: A scheduled task was disabled. 2 rules
Event ID 4702: A scheduled task was updated. 2 rules
Event ID 4704: A user right was assigned. 2 rules
Event ID 4706: A new trust was created to a domain. 1 rule
Event ID 4717: System security access was granted to an account. 1 rule
Event ID 4719: System audit policy was changed. 3 rules
Event ID 4720: A user account was created. 8 rules
Event ID 4722: A user account was enabled. 1 rule
Event ID 4723: An attempt was made to change an account's password. 2 rules
Event ID 4724: An attempt was made to reset an account's password. 4 rules
Event ID 4726: A user account was deleted. 1 rule
Event ID 4727: A security-enabled global group was created. 1 rule
Event ID 4728: A member was added to a security-enabled global group. 12 rules
Event ID 4729: A member was removed from a security-enabled global group. 1 rule
Event ID 4730: A security-enabled global group was deleted. 1 rule
Event ID 4731: A security-enabled local group was created. 1 rule
Event ID 4732: A member was added to a security-enabled local group. 11 rules
Event ID 4737: A security-enabled global group was changed. 1 rule
Event ID 4738: A user account was changed. 9 rules
Event ID 4741: A computer account was created. 4 rules
Event ID 4742: A computer account was changed. 9 rules
Event ID 4743: A computer account was deleted. 1 rule
Event ID 4754: A security-enabled universal group was created. 1 rule
Event ID 4755: A security-enabled universal group was changed. 1 rule
Event ID 4756: A member was added to a security-enabled universal group. 11 rules
Event ID 4765: SID History was added to an account. 1 rule
Event ID 4766: An attempt to add SID History to an account failed. 1 rule
Event ID 4768: A Kerberos authentication ticket (TGT) was requested. 10 rules
Event ID 4769: A Kerberos service ticket was requested. 10 rules
Event ID 4770: A Kerberos service ticket was renewed. 1 rule
Event ID 4771: Kerberos pre-authentication failed. 4 rules
Event ID 4776: The domain controller attempted to validate the credentials for an account. 4 rules
Event ID 4781: The name of an account was changed. 5 rules
Event ID 4794: An attempt was made to set the Directory Services Restore Mode administrator password. 2 rules
Event ID 4799: A security-enabled local group membership was enumerated. 3 rules
Event ID 4800: The workstation was locked. 1 rule
Event ID 4825: A user was denied the access to Remote Desktop. 2 rules
Event ID 4886: Certificate Services received a certificate request. 1 rule
Event ID 4887: Certificate Services approved a certificate request and issued a certificate. 1 rule
Event ID 4898: Certificate Services loaded a template. 2 rules
Event ID 4899: A Certificate Services template was updated. 2 rules
Event ID 4904: An attempt was made to register a security event source. 1 rule
Event ID 4905: An attempt was made to unregister a security event source. 1 rule
Event ID 4950: A Windows Firewall setting has changed. 1 rule
Event ID 4964: Special groups have been assigned to a new logon. 1 rule
Event ID 5038: Code integrity determined that the image hash of a file is not valid. 1 rule
Event ID 5123: A configuration entry changed in the OCSP Responder Service. 1 rule
Event ID 5124: A security setting was updated on OCSP Responder Service. 1 rule
Event ID 5136: A directory service object was modified. 20 rules
Event ID 5137: A directory service object was created. 1 rule
Event ID 5140: A network share object was accessed. 5 rules
Event ID 5142: A network share object was added. 2 rules
Event ID 5143: A network share object was modified. 2 rules
Event ID 5145: A network share object was checked to see whether client can be granted desired access. 43 rules
Event ID 5156: The Windows Filtering Platform has permitted a connection. 3 rules
Event ID 5157: The Windows Filtering Platform has blocked a connection. 1 rule
Event ID 5379: Credential Manager credentials were read. 3 rules
Event ID 5382: Vault credentials were read. 1 rule
Event ID 5441: The following filter was present when the Windows Filtering Platform Base Filtering Engine started. 1 rule
Event ID 5447: A Windows Filtering Platform filter has been changed. 2 rules
Event ID 5449: A Windows Filtering Platform provider context has been changed. 1 rule
Event ID 6281: Code Integrity determined that the page hashes of an image file are not valid. 1 rule
Event ID 6416: A new external device was recognized by the system. 2 rules
Event ID 6423: The installation of this device is forbidden by system policy. 1 rule

Microsoft-Windows-Sysmon

Event ID 1: Process creation 1482 rules
Event ID 2: A process changed a file creation time 2 rules
Event ID 3: Network connection 61 rules
Event ID 4: Sysmon service state changed 1 rule
Event ID 6: Driver loaded 10 rules
Event ID 7: Image loaded 126 rules
Event ID 8: CreateRemoteThread 15 rules
Event ID 9: RawAccessRead 1 rule
Event ID 10: ProcessAccess 30 rules
Event ID 11: FileCreate 226 rules
Event ID 12: RegistryEvent (Object create and delete) 50 rules
Event ID 13: RegistryEvent (Value Set) 276 rules
Event ID 14: RegistryEvent (Key and Value Rename) 55 rules
Event ID 15: FileCreateStreamHash 9 rules
Event ID 16: ServiceConfigurationChange 2 rules
Event ID 17: PipeEvent (Pipe Created) 20 rules
Event ID 18: PipeEvent (Pipe Connected) 20 rules
Event ID 19: WmiEvent (WmiEventFilter activity detected) 4 rules
Event ID 20: WmiEvent (WmiEventConsumer activity detected) 4 rules
Event ID 21: WmiEvent (WmiEventConsumerToFilter activity detected) 4 rules
Event ID 22: DNSEvent (DNS query) 28 rules
Event ID 23: FileDelete (File Delete archived) 14 rules
Event ID 25: ProcessTampering (Process image change) 1 rule
Event ID 26: FileDeleteDetected (File Delete logged) 14 rules
Event ID 27: FileBlockExecutable 1 rule
Event ID 28: FileBlockShredding 1 rule
Event ID 29: FileExecutableDetected 2 rules
Event ID 255: Error report: UtcTime: UtcTime ID: ID Description: Description. 1 rule

Microsoft-Windows-Windows-Defender

Event ID 1006: ProductName has detected malware or other potentially unwanted software. 1 rule
Event ID 1009: ProductName has restored an item from quarantine. 1 rule
Event ID 1013: Product Name has removed history of malware and other potentially unwanted software. 1 rule
Event ID 1015: ProductName has detected a suspicious behavior. 1 rule
Event ID 1116: Product Name has detected malware or other potentially unwanted software. 4 rules
Event ID 1117: Product Name has taken action to protect this machine from malware or other potentially unwanted software. 1 rule
Event ID 1119: ProductName has encountered a critical error when taking action on malware or other potentially unwanted software. 1 rule
Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator. 2 rules
Event ID 1151: Endpoint Protection client health report (time in UTC). 1 rule
Event ID 3002: ProductName Real-Time Protection feature has encountered an error and failed. 2 rules
Event ID 3007: ProductName Real-time Protection feature has restarted. 1 rule
Event ID 5001: Product Name Real-time Protection scanning for malware and other potentially unwanted software was disabled. 1 rule
Event ID 5007: Product Name Configuration has changed. 5 rules
Event ID 5010: ProductName scanning for spyware and other potentially unwanted software is disabled. 1 rule
Event ID 5012: ProductName scanning for viruses is disabled. 1 rule
Event ID 5013: Tamper Protection Changed Type a change to Product Name. 1 rule
Event ID 5101: {Product Name} grace period has expired. 1 rule

Microsoft-Windows-Windows-Firewall-With-Advanced-Security

Event ID 2002: A Windows Defender Firewall setting has changed. 1 rule
Event ID 2003: A Windows Defender Firewall setting in the Profiles profile has changed. 2 rules
Event ID 2004: A rule has been added to the Windows Defender Firewall exception list. 6 rules
Event ID 2005: A rule has been modified in the Windows Defender Firewall exception list. 2 rules
Event ID 2006: A rule has been deleted in the Windows Defender Firewall exception list. 1 rule
Event ID 2008: Windows Defender Firewall Group Policy settings have changed. 1 rule
Event ID 2009: The Windows Defender Firewall service failed to load Group Policy. 1 rule
Event ID 2032: Windows Defender Firewall has been reset to its default configuration. 1 rule
Event ID 2033: All rules have been deleted from the Windows Defender Firewall configuration on this computer. 1 rule
Event ID 2052: A rule has been deleted in the Windows Defender Firewall exception list. 1 rule
Event ID 2059: All rules have been deleted from the Windows Defender Firewall configuration on this computer. 1 rule
Event ID 2060: Windows Defender Firewall has been reset to its default configuration. 1 rule
Event ID 2071: A rule has been added to the Windows Defender Firewall exception list. 3 rules
Event ID 2073: A rule has been modified in the Windows Defender Firewall exception list. 1 rule
Event ID 2082: A Windows Defender Firewall setting in the Profiles profile has changed. 1 rule
Event ID 2083: A Windows Defender Firewall setting has changed. 1 rule
Event ID 2097: A rule has been added to the Windows Defender Firewall exception list. 3 rules

Microsoft-Windows-CodeIntegrity

Event ID 3001: Code Integrity determined an unsigned kernel module FileNameBuffer is loaded into the system. 1 rule
Event ID 3021: Code Integrity determined a revoked kernel module FileNameBuffer is loaded into the system. 1 rule
Event ID 3022: Code Integrity determined a revoked kernel module FileNameBuffer is loaded into the system. 1 rule
Event ID 3023: The driver FileNameBuffer is blocked from loading as the driver has been revoked by Microsoft. 1 rule
Event ID 3032: Code Integrity determined a revoked image FileNameBuffer is loaded into the system. 1 rule
Event ID 3033: Code Integrity determined that a process (ProcessNameBuffer) attempted to load FileNameBuffer that did not meet the RequestedPolicy signing level requirements. 1 rule
Event ID 3034: Code Integrity determined that a process (ProcessNameBuffer) attempted to load FileNameBuffer that did not meet the RequestedPolicy signing level requirements or violated code integrity p... 1 rule
Event ID 3035: Code Integrity determined a revoked image FileNameBuffer is loaded into the system. 1 rule
Event ID 3036: Windows is unable to verify the integrity of the file FileNameBuffer because the signing certificate has been revoked. 1 rule
Event ID 3037: Code Integrity determined an unsigned image FileNameBuffer is loaded into the system. 1 rule
Event ID 3077: Code Integrity determined that a process (Process Name) attempted to load File Name that did not meet the Requested Signing Level signing level requirements or violated code integrity p... 1 rule
Event ID 3082: Code Integrity determined kernel module FileNameBuffer that did not meet the WHQL requirements is loaded into the system. 1 rule
Event ID 3083: Code Integrity determined kernel module FileNameBuffer that did not meet the WHQL requirements is loaded into the system. 1 rule
Event ID 3104: Windows blocked file FileNameBuffer which has been disallowed for protected processes. 1 rule

MSSQLSERVER

Event ID 8128 1 rule
Event ID 15457 4 rules
Event ID 17199 1 rule
Event ID 17200 1 rule
Event ID 17201 1 rule
Event ID 17202 1 rule
Event ID 17810 1 rule
Event ID 18456 2 rules
Event ID 18470 1 rule
Event ID 33205 14 rules

Microsoft-Windows-AppLocker

Event ID 8002: FilePathBuffer was allowed to run. 1 rule
Event ID 8003: RuleAndFileData.FilePath was allowed to run but would have been prevented from running if the AppLocker policy were enforced. 1 rule
Event ID 8004: FilePathBuffer was prevented from running. 1 rule
Event ID 8006: FilePathBuffer was allowed to run but would have been prevented from running if the AppLocker policy were enforced. 1 rule
Event ID 8007: FilePathBuffer was prevented from running. 1 rule
Event ID 8021: PackageBuffer was allowed to run but would have been prevented from running if the AppLocker policy were enforced. 1 rule
Event ID 8022: PackageBuffer was prevented from running. 1 rule
Event ID 8024: PackageBuffer was allowed to run but would have been prevented from running if the AppLocker policy were enforced. 1 rule
Event ID 8025: PackageBuffer was prevented from running. 1 rule

Microsoft-Windows-AppXDeployment-Server

Event ID 400: Deployment DeploymentOperation operation with target volume MountPoint on Package PackageFullName from: Path finished successfully. 2 rules
Event ID 401: Deployment DeploymentOperation operation with target volume MountPoint on Package PackageFullName from: Path failed with error ErrorCode. 2 rules
Event ID 412: error ErrorCode: Deployment of package PackageFullName was blocked by AppLocker. 1 rule
Event ID 441: The package deployment operation is blocked by the "Allow deployment operations in special profiles" policy. 1 rule
Event ID 442: Deployment of package PackageFullName to volume MountPoint failed because deployments to non-system volumes are blocked by the "Disable deployment of Windows Store apps... 1 rule
Event ID 453: Package PackageFullName is blocked by a platform policy: PolicyReason. 1 rule
Event ID 454: Package PackageFullName is blocked by a platform policy: PolicyReason. 1 rule
Event ID 603: Started deployment DeploymentOperation operation on a package with main parameter Path and Options Flags and FlagsHigh. 1 rule
Event ID 854: Successfully added the following uri(s) to be processed: Path. 4 rules

Microsoft-Windows-Kerberos-Key-Distribution-Center

Event ID 16: While processing a TGS request for the target server Target, the account Account did not have a suitable key for generating a Kerberos ticket (the missing key has an ID of ID) 1 rule
Event ID 27: While processing a TGS request for the target server Target, the account Name did not have a suitable key for generating a Kerberos ticket (the missing key has an ID of ID) 1 rule
Event ID 35: The Key Distribution Center (KDC) encountered a ticket-granting-ticket (TGT) from another KDC (IssuingKDC) that did not contain a PAC attributes field 1 rule
Event ID 36: The Key Distribution Center (KDC) encountered a ticket that did not contain a PAC while processing a request for another ticket 1 rule
Event ID 37: The Key Distribution Center (KDC) encountered a ticket that did not contain information about the account that requested the ticket while processing a request for another ticket 1 rule
Event ID 38: The Key Distribution Center (KDC) encountered a ticket that contained inconsistent information about the account that requested the ticket 1 rule
Event ID 39: The Key Distribution Center (KDC) encountered a user certificate that was valid but could not be mapped to a user in a secure way (such as via explicit mapping, key trust mapping, or a SID) 1 rule
Event ID 41: The Key Distribution Center (KDC) encountered a user certificate that was valid but contained a different SID than the user to which it mapped 1 rule
Event ID 42: The Kerberos Key Distribution Center lacks strong keys for account 1 rule

Service-Control-Manager

Event ID 7000: The param1 service failed to start due to the following error: 1 rule
Event ID 7009: A timeout was reached (param1 milliseconds) while waiting for the param2 service to connect 1 rule
Event ID 7023: The param1 service terminated with the following error: 2 rules
Event ID 7034: The param1 service terminated unexpectedly 1 rule
Event ID 7036: The Microsoft Software Shadow Copy Provider service entered the stopped state. 3 rules
Event ID 7045: A service was installed in the system. 55 rules

Microsoft-Windows-SMBClient

Event ID 30803: Failed to establish a network connection. 1 rule
Event ID 30804: A network connection was disconnected. 1 rule
Event ID 30806: The client re-established its session to the server. 1 rule
Event ID 31017: Rejected an insecure guest logon. 1 rule
Event ID 31018: Guidance: An administrator has enabled AllowInsecureGuestAuth. 1 rule

Microsoft-Windows-SoftwareRestrictionPolicies

Event ID 865: Access to AttemptedPath has been restricted by your Administrator by the default software restriction policy level. 1 rule
Event ID 866: Access to AttemptedPath has been restricted by your Administrator by location with policy rule SrpRuleGuid placed on path RulePath. 1 rule
Event ID 867: Access to AttemptedPath has been restricted by your Administrator by software publisher policy. 1 rule
Event ID 868: Access to AttemptedPath has been restricted by your Administrator by policy rule SrpRuleGuid. 1 rule
Event ID 882: Access to AttemptedPath has been restricted by your Administrator by policy rule SrpRuleGuid. 1 rule

Microsoft-Windows-WindowsUpdateClient

Event ID 16: Unable to Connect: Windows is unable to connect to the automatic updates service and therefore cannot download and install updates according to the... 1 rule
Event ID 20: Installation Failure: Windows failed to install the following update with error errorCode: updateTitle. 1 rule
Event ID 24: Uninstallation Failure: Windows failed to uninstall the following update with error errorCode: updatelist. 1 rule
Event ID 213: Revert Failure: Windows failed to revert the following update with error errorCode: updatelist. 1 rule
Event ID 217: Commit Failure: Windows failed to commit the following update with error errorCode: updatelist. 1 rule

MsiInstaller

Event ID 1033: Windows Installer installed the product. 2 rules
Event ID 1034: Product: Data_0. 1 rule
Event ID 1040: Beginning a Windows Installer transaction: %0 2 rules
Event ID 1042: Ending a Windows Installer transaction: %0 2 rules
Event ID 11724 1 rule

ESENT

Event ID 216 1 rule
Event ID 325 3 rules
Event ID 326 2 rules
Event ID 327 2 rules

Microsoft-Windows-DHCP-Server

Event ID 1031: [EVENT_SERVER_CALLOUT_UNHANDLED_EXCEPTION] The installed server callout .dll file has caused an exception. 1 rule
Event ID 1032: [EVENT_SERVER_CALLOUT_LOAD_EXCEPTION] The installed server callout .dll file has caused an exception. The .dll file couldn't be loaded. 1 rule
Event ID 1033: [EVENT_SERVER_CALLOUT_LOAD_SUCCESS] The DHCP service has successfully loaded one or more callout DLLs. 1 rule
Event ID 1034: [EVENT_SERVER_READ_ONLY_GROUP_ERROR] The DHCP service has failed to load one or more callout DLLs. 1 rule

Microsoft-Windows-DNS-Server-Service

Event ID 150: The DNS server could not load or initialize the plug-in DLL Name. 2 rules
Event ID 770: A DNS server plugin DLL has been loaded from location param1 on server param2. 2 rules
Event ID 771: The V1 plugin interface has been implemented in server level plugin DLL. 1 rule
Event ID 6004: The DNS server received a zone transfer request from param1 for a non-existent or non-authoritative zone param2. 2 rules

Microsoft-Windows-PrintService

Event ID 316: Printer driver param1 for param2 param3 was added or updated. 1 rule
Event ID 321: File(s) param1 associated with printer param2 were added or updated. 1 rule
Event ID 354: param1 initialization failed at param2. 1 rule
Event ID 808: The print spooler failed to load a plug-in module PluginDllName, error code ErrorCode. 2 rules

Microsoft-Windows-TaskScheduler

Event ID 129: Task Scheduler launch task "Name" , instance "TaskName" with process ID Path. 3 rules
Event ID 140: User "TaskName" updated Task Scheduler task "Name". 1 rule
Event ID 141: User "TaskName" deleted Task Scheduler task "Name". 2 rules
Event ID 142: User "TaskName" disabled Task Scheduler task "Name". 1 rule

Microsoft-Windows-TerminalServices-RemoteConnectionManager

Event ID 1149: Remote Desktop Services: User authentication succeeded. 3 rules
Event ID 20503: Shadow View Session Started. 1 rule
Event ID 20504: Shadow View Session Stopped. 1 rule
Event ID 20508: Shadow View Permission Granted. 1 rule

LsaSrv

Event ID 300: Groups assigned to a new logon. 1 rule
Event ID 6038: Microsoft Windows Server has detected that NTLM authentication is presently being used between clients and this server. 1 rule
Event ID 6039: Microsoft Windows Server has detected that NTLM authentication is being used between clients and this server. 1 rule

MSExchange-CmdletLogs

Event ID 1 1 rule
Event ID 6 3 rules
Event ID 8: Task <TaskName> throwing unhandled exception. 1 rule

Microsoft-ServiceBus-Client

Event ID 40300: Service Bus relay client connection-state event. 1 rule
Event ID 40301: Service Bus relay client connection-state event. 1 rule
Event ID 40302: Service Bus relay client connection-state event. 1 rule

Microsoft-Windows-Bits-Client

Event ID 3: The BITS service created a new job: jobTitle, with owner jobId. 2 rules
Event ID 60: BITS stopped transferring the name transfer job that is associated with the url URL. 1 rule
Event ID 16403: task_016403 5 rules

Microsoft-Windows-DriverFrameworks-UserMode

Event ID 2003: The UMDF Host Process (UMDFHostDeviceArrivalBegin.LifetimeId) has been asked to load drivers for device UMDFHostDeviceArrivalBegin.InstanceId. 1 rule
Event ID 2100: Received a Pnp or Power operation (UMDFHostDeviceRequest.RequestMajorCode, UMDFHostDeviceRequest.RequestMinorCode) for device UMDFHostDeviceRequest.InstanceId. 1 rule
Event ID 2102: Forwarded a finished Pnp or Power operation (UMDFHostDeviceRequest.RequestMajorCode, UMDFHostDeviceRequest.RequestMinorCode) to the lower driver for device UMDFHostDeviceRequest.InstanceId with sta... 1 rule

Microsoft-Windows-Eventlog

Event ID 104: The LogFileCleared.Channel log file was cleared. 3 rules
Event ID 517: The audit log was cleared (legacy Windows 2000/XP/2003 event; superseded by 1102). 1 rule
Event ID 1102: The audit log was cleared. 2 rules

Microsoft-Windows-TerminalServices-LocalSessionManager

Event ID 21: Remote Desktop Services: Session logon succeeded. 2 rules
Event ID 24: Remote Desktop Services: Session has been disconnected. 1 rule
Event ID 25: Remote Desktop Services: Session reconnection succeeded. 1 rule

Microsoft-Windows-WMI-Activity

Event ID 5858: Id = Operation_ClientFailure.Id; ClientMachine = Operation_ClientFailure.ClientMachine; User = Operation_ClientFailure.User; ClientProcessId = Operation_ClientFailure.ClientProcessId; Component = O... 1 rule
Event ID 5859: Namespace = Operation_EssStarted.NamespaceName; NotificationQuery = Operation_EssStarted.Query; OwnerName = Operation_EssStarted.User; HostProcessID = Operation_EssStarted.Processid; Provider= Oper... 1 rule
Event ID 5861: Namespace = Operation_ESStoConsumerBinding.Namespace; Eventfilter = Operation_ESStoConsumerBinding.ESS (refer to its activate eventid:5859); Consumer = Operation_ESStoConsumerBinding.CONSUMER; Poss... 1 rule

NETLOGON

Event ID 5723 1 rule
Event ID 5805 1 rule
Event ID 5829: The Netlogon service allowed a vulnerable Netlogon secure channel connection. 1 rule

PowerShell

Event ID 400 11 rules
Event ID 600 2 rules
Event ID 800 37 rules

Microsoft-Windows-BitLocker-API

Event ID 768: BitLocker encryption was started for volume VolumeMountPoint using AlgorithmType algorithm. 1 rule
Event ID 775: A BitLocker key protector was created. 1 rule

Microsoft-Windows-Directory-Services-SAM

Event ID 16990: The security account manager blocked a non-administrator from creating an Active Directory account in this domain with mismatched objectClass and u... 1 rule
Event ID 16991: The security account manager blocked a non-administrator from creating or renaming a computer account using an invalid sAMAccountName. 1 rule

Microsoft-Windows-NTLM

Event ID 8001: NTLM client blocked audit: Audit outgoing NTLM authentication traffic that would be blocked. 1 rule
Event ID 8004: NTLM authentication in this domain audit (domain controller): Audit NTLM authentication in this domain. 1 rule

Microsoft-Windows-PowerShell

Event ID 4103: Payload Context: ContextInfo User Data: UserData. 71 rules
Event ID 4104: Creating Scriptblock text (MessageNumber of MessageTotal). 218 rules

Microsoft-Windows-RemoteDesktopServices-RdpCoreTS

Event ID 131: The server accepted a new ConnType connection from client ClientIP. 1 rule
Event ID 148: Channel ChannelName has been closed between the server and the client on transport tunnel: TunnelID. 1 rule

Microsoft-Windows-Security-Mitigations

Event ID 11: Process 'ProcessPath' (PID ProcessId) would have been blocked from loading the non-Microsoft-signed binary 'ImageName'. 2 rules
Event ID 12: Process 'ProcessPath' (PID ProcessId) was blocked from loading the non-Microsoft-signed binary 'ImageName'. 2 rules

ScreenConnect

Event ID 200: Executed command of length. 1 rule
Event ID 201: Transferred files with action 'Transfer'. 1 rule

TermDD

Event ID 50 1 rule
Event ID 56 1 rule

Application-Error

Event ID 1000: Faulting application name: Faulting_application_name, version: version, time stamp: 0xFaulting_module_name. 5 rules

Application-Popup

Event ID 26: Application popup: Caption : Message. 1 rule

MSExchange-Control-Panel

Event ID 4: The Exchange Control Panel web application encountered an unhandled ASP.NET exception. 1 rule

Microsoft-Windows-AppModel-Runtime

Event ID 201: Created process ProcessID for application ApplicationName in package PackageName. 1 rule

Microsoft-Windows-AppxPackagingOM

Event ID 157: The app package signature was validated for core content of the app package published by subjectName. 1 rule

Microsoft-Windows-Audit-CVE

Event ID 1: Possible detection of CVE: PossibleDetectionOfCVE. 1 rule

Microsoft-Windows-Backup

Event ID 524: The system catalog has been deleted. 1 rule

Microsoft-Windows-CAPI2

Event ID 70: For more details for this event, please refer to the "Details" section 1 rule

Microsoft-Windows-CertificateServicesClient-Lifecycle-System

Event ID 1007: A certificate has been exported. 1 rule

Microsoft-Windows-CertificationAuthority

Event ID 53: Active Directory Certificate Services denied request Name because RequestId. 1 rule

Microsoft-Windows-DNS-Client

Event ID 3008: DNS query is completed for the name QueryName, type QueryType, query options QueryOptions with status QueryStatus Results QueryResults. 6 rules

Microsoft-Windows-DNSServer

Event ID 257: RESPONSE_SUCCESS: TCP=TCP; InterfaceIP=InterfaceIP; Destination=Destination; AA=AA; AD=AD; QNAME=QNAME; QTYPE=QTYPE; XID=XID; DNSSEC=DNSSEC; RCODE=RCODE; Port=Port; Flags=Flags; Scop... 1 rule

Microsoft-Windows-Diagnosis-Scripted

Event ID 101: The scripted diagnostic engine started initializing a diagnostic package located at PackagePath. 1 rule

Microsoft-Windows-DistributedCOM

Event ID 10001: Unable to start a DCOM Server: param3 as param4/param5. 1 rule

Microsoft-Windows-IIS-Configuration

Event ID 29: Changes to 'Configuration' at 'ConfigPath' have successfully been committed. 4 rules

Microsoft-Windows-Iphlpsvc

Event ID 4100: ISATAP router address IsatapRouter was set with status ErrorCode. 1 rule

Microsoft-Windows-Kernel-General

Event ID 16: The access history in hive HiveName was cleared updating KeysUpdated keys and creating DirtyPages modified pages. 1 rule

Microsoft-Windows-LDAP-Client

Event ID 30: LDAP search request 1 rule

Microsoft-Windows-MSMQ

Event ID 2027: A corrupted packet was encountered. 1 rule

Microsoft-Windows-Ntfs

Event ID 98: Volume DriveName (DeviceName) CorruptionActionState. 1 rule

Microsoft-Windows-SMBServer

Event ID 4000: The SMB client connection to the share was established. 1 rule

Microsoft-Windows-Servicing

Event ID 9: Selectable update CbsUpdateChangeState.UpdateName of package CbsUpdateChangeState.PackageIdentifier was successfully turned on. 1 rule

Microsoft-Windows-Shell-Core

Event ID 28115: Shortcut for application Name with ID AppID and flags Flags is added to app resolver cache. 1 rule

Microsoft-Windows-User-Profiles-Service

Event ID 1511: Windows cannot find the local profile and is logging you on with a temporary profile. 1 rule

Microsoft-Windows-WER-SystemErrorReporting

Event ID 1001: The computer has rebooted from a bugcheck. 1 rule

Microsoft-Windows-WinINet-Config

Event ID 5600: task_0 1 rule

Ntfs

Event ID 55: A corruption was discovered in the file system structure on volume DriveName. 1 rule

OpenSSH

Event ID 4: process: payload. 2 rules

RPCFW

Event ID 3: An RPC server function was called. 17 rules

Windows-Error-Reporting

Event ID 1001: Fault bucket , type. 1 rule

Windows-Server-Update-Services

Event ID 7053: The WSUS administration console has encountered an unexpected error. 1 rule