Page Contents
- Vendor Field Map
- Microsoft-Windows-Security-Auditing
- Event ID: 4608
- Event ID: 4610
- Event ID: 4611
- Event ID: 4614
- Event ID: 4616
- Event ID: 4622
- Event ID: 4624
- Event ID: 4625
- Event ID: 4627
- Event ID: 4634
- Event ID: 4647
- Event ID: 4648
- Event ID: 4653
- Event ID: 4656
- Event ID: 4657
- Event ID: 4658
- Event ID: 4659
- Event ID: 4660
- Event ID: 4661
- Event ID: 4662
- Event ID: 4663
- Event ID: 4664
- Event ID: 4670
- Event ID: 4672
- Event ID: 4673
- Event ID: 4674
- Event ID: 4675
- Event ID: 4688
- Event ID: 4689
- Event ID: 4690
- Event ID: 4692
- Event ID: 4695
- Event ID: 4697
- Event ID: 4698
- Event ID: 4699
- Event ID: 4700
- Event ID: 4701
- Event ID: 4702
- Event ID: 4703
- Event ID: 4704
- Event ID: 4705
- Event ID: 4713
- Event ID: 4714
- Event ID: 4716
- Event ID: 4717
- Event ID: 4718
- Event ID: 4719
- Event ID: 4720
- Event ID: 4722
- Event ID: 4723
- Event ID: 4724
- Event ID: 4725
- Event ID: 4726
- Event ID: 4727
- Event ID: 4728
- Event ID: 4729
- Event ID: 4730
- Event ID: 4731
- Event ID: 4732
- Event ID: 4733
- Event ID: 4734
- Event ID: 4735
- Event ID: 4737
- Event ID: 4738
- Event ID: 4739
- Event ID: 4740
- Event ID: 4741
- Event ID: 4742
- Event ID: 4743
- Event ID: 4744
- Event ID: 4745
- Event ID: 4746
- Event ID: 4747
- Event ID: 4748
- Event ID: 4749
- Event ID: 4750
- Event ID: 4751
- Event ID: 4752
- Event ID: 4753
- Event ID: 4754
- Event ID: 4755
- Event ID: 4756
- Event ID: 4757
- Event ID: 4758
- Event ID: 4759
- Event ID: 4760
- Event ID: 4761
- Event ID: 4762
- Event ID: 4763
- Event ID: 4764
- Event ID: 4767
- Event ID: 4768
- Event ID: 4769
- Event ID: 4770
- Event ID: 4771
- Event ID: 4774
- Event ID: 4776
- Event ID: 4778
- Event ID: 4779
- Event ID: 4780
- Event ID: 4781
- Event ID: 4785
- Event ID: 4786
- Event ID: 4787
- Event ID: 4788
- Event ID: 4793
- Event ID: 4798
- Event ID: 4799
- Event ID: 4800
- Event ID: 4817
- Event ID: 4902
- Event ID: 4904
- Event ID: 4905
- Event ID: 4907
- Event ID: 4912
- Event ID: 4928
- Event ID: 4929
- Event ID: 4930
- Event ID: 4931
- Event ID: 4932
- Event ID: 4933
- Event ID: 4944
- Event ID: 4945
- Event ID: 4946
- Event ID: 4947
- Event ID: 4948
- Event ID: 4949
- Event ID: 4950
- Event ID: 4953
- Event ID: 4954
- Event ID: 4956
- Event ID: 4957
- Event ID: 4985
- Event ID: 5024
- Event ID: 5031
- Event ID: 5033
- Event ID: 5038
- Event ID: 5056
- Event ID: 5058
- Event ID: 5059
- Event ID: 5061
- Event ID: 5136
- Event ID: 5137
- Event ID: 5139
- Event ID: 5140
- Event ID: 5141
- Event ID: 5142
- Event ID: 5143
- Event ID: 5144
- Event ID: 5145
- Event ID: 5152
- Event ID: 5154
- Event ID: 5156
- Event ID: 5157
- Event ID: 5158
- Event ID: 5169
- Event ID: 5170
- Event ID: 5440
- Event ID: 5441
- Event ID: 5442
- Event ID: 5444
- Event ID: 5446
- Event ID: 5447
- Event ID: 5448
- Event ID: 5449
- Event ID: 5450
- Event ID: 5478
- Event ID: 6144
- Event ID: 6272
- Event ID: 6273
- Event ID: 6274
- Event ID: 6278
- Event ID: 6416
- Microsoft-Windows-Winlogon
- Microsoft-Windows-RestartManager
- Microsoft-Windows-GroupPolicy
- Microsoft-Windows-TaskScheduler
- PowerShell
- Microsoft-Windows-TerminalServices-Printers
- Microsoft-Windows-TerminalServices-LocalSessionManager
- MsiInstaller
- Service Control Manager
- User32
- ADSync
- SceCli
- Microsoft-Windows-Eventlog
- Windows_Error_Reporting
- Microsoft-Windows-AppLocker
- Microsoft-Windows-PrintService
- DefaultJSONEventSource
- Microsoft Windows Defender
- Microsoft Windows Perflib
- Sysmon Remote Threat Creation
- DNS Events
- Microsoft Windows WMI Activity
- Windows BITS Client
- Microsoft Windows SMB Client
- ASP.NET
- Microsoft-Windows-Security-Auditing