Skip to main content

Security and identity

7sources
98reasons
2conditions
7decode tables

An account, credential, permission or audit setting changed in a way worth checking.

How the agent recognises this on a host

  • Microsoft Defender Antivirus writes its operational channel on the host.
  • The installed-product inventory names the protection products present.

The sources below carry those markers.

SourceWhat it isStatus
Microsoft Defender Antivirus event logMicrosoft Defender Antivirus detections, remediation outcomes and engine health from the Defender operational channel.Live
Windows Security event logThe Security channel: sign-in outcomes, privilege use, directory changes and audit policy changes.Live
Windows System event logThe System channel: service, driver, disk, network, cluster and hardware faults from the operating system itself.Live
Installed product summaryA rolled-up view of installed products, including protection-category coverage.Live

What is scored here

SourceSignalsWhat they are
Disk volumes1BitLocker protection dropped
Installed products1product removed
Microsoft Defender Antivirus event log13av config changed, av definition update failed, av engine failed, av protection disabled, av scan failed, av suspicious behavior detected, av tamper blocked, av threat detected, av threat not remediated, av threat remediated, av threat remediation failed, defender asr block, defender network protection block
Windows Application event log13adcs ca chain failed, adcs crl publish failed, cert enroll failed, cert expiring, entra password hash sync failed, entra sync run failed, entra sync scheduler aborted, mfa login succeeded, mfa not configured, mfa unavailable access granted, mfa user not enrolled, security agent config fetch failed, security agent host isolated
Windows Security event log50account changed, account created, account deleted, account disabled, account enabled, account locked out, account password change failed, account password reset, account password reset failed, adcs audit evidence tampered, adcs config changed, adcs request failed, anonymous remote logon, audit events dropped, audit log cleared, audit log full, audit pipeline error, audit policy changed, directory object access denied, directory object changed, directory replication access requested, domain policy changed, dsrm password change failed, dsrm password changed, event logging stopped, explicit credential use, group member added, group member removed, guest account sign in, kerberos preauth failed, kerberos rc4 ticket, kerberos ticket failed, logon failed, logon right granted, logon right removed, nps access denied, nps lockout, nps request discarded, ntlm validation failed, principal renamed, psdirect handshake probe, registry value changed, replay attack detected, security group changed, security group created, security group deleted, service installed, sid history add failed, sid history added, special group logon
Windows System event log19av unsigned code blocked, firmware attack indicator reported, http ssl binding created, http ssl binding deleted, http ssl config failed, kerberos cert domain unresolved, kerberos etype unsupported, kerberos pac verify failed, kerberos smartcard cert missing, kerberos weak krbtgt key, security agent service start failed, security agent service terminated, service installed, tls cert expired, tls cert name mismatch, tls cert untrusted ca, tls cipher mismatch, tls client credential failed, tls server credential failed
Windows PowerShell event channels3win powershell script block framework code, win powershell script block repeat, win powershell script block watchlist hit