Security and identity
7sources
98reasons
2conditions
7decode tables
An account, credential, permission or audit setting changed in a way worth checking.
How the agent recognises this on a host
- Microsoft Defender Antivirus writes its operational channel on the host.
- The installed-product inventory names the protection products present.
The sources below carry those markers.
| Source | What it is | Status |
|---|---|---|
| Microsoft Defender Antivirus event log | Microsoft Defender Antivirus detections, remediation outcomes and engine health from the Defender operational channel. | Live |
| Windows Security event log | The Security channel: sign-in outcomes, privilege use, directory changes and audit policy changes. | Live |
| Windows System event log | The System channel: service, driver, disk, network, cluster and hardware faults from the operating system itself. | Live |
| Installed product summary | A rolled-up view of installed products, including protection-category coverage. | Live |
What is scored here
| Source | Signals | What they are |
|---|---|---|
| Disk volumes | 1 | BitLocker protection dropped |
| Installed products | 1 | product removed |
| Microsoft Defender Antivirus event log | 13 | av config changed, av definition update failed, av engine failed, av protection disabled, av scan failed, av suspicious behavior detected, av tamper blocked, av threat detected, av threat not remediated, av threat remediated, av threat remediation failed, defender asr block, defender network protection block |
| Windows Application event log | 13 | adcs ca chain failed, adcs crl publish failed, cert enroll failed, cert expiring, entra password hash sync failed, entra sync run failed, entra sync scheduler aborted, mfa login succeeded, mfa not configured, mfa unavailable access granted, mfa user not enrolled, security agent config fetch failed, security agent host isolated |
| Windows Security event log | 50 | account changed, account created, account deleted, account disabled, account enabled, account locked out, account password change failed, account password reset, account password reset failed, adcs audit evidence tampered, adcs config changed, adcs request failed, anonymous remote logon, audit events dropped, audit log cleared, audit log full, audit pipeline error, audit policy changed, directory object access denied, directory object changed, directory replication access requested, domain policy changed, dsrm password change failed, dsrm password changed, event logging stopped, explicit credential use, group member added, group member removed, guest account sign in, kerberos preauth failed, kerberos rc4 ticket, kerberos ticket failed, logon failed, logon right granted, logon right removed, nps access denied, nps lockout, nps request discarded, ntlm validation failed, principal renamed, psdirect handshake probe, registry value changed, replay attack detected, security group changed, security group created, security group deleted, service installed, sid history add failed, sid history added, special group logon |
| Windows System event log | 19 | av unsigned code blocked, firmware attack indicator reported, http ssl binding created, http ssl binding deleted, http ssl config failed, kerberos cert domain unresolved, kerberos etype unsupported, kerberos pac verify failed, kerberos smartcard cert missing, kerberos weak krbtgt key, security agent service start failed, security agent service terminated, service installed, tls cert expired, tls cert name mismatch, tls cert untrusted ca, tls cipher mismatch, tls client credential failed, tls server credential failed |
| Windows PowerShell event channels | 3 | win powershell script block framework code, win powershell script block repeat, win powershell script block watchlist hit |