Security and identity
11sources
136reasons
2conditions
13decode tables
An account, credential, permission or audit setting changed in a way worth checking.
How the agent recognises this on a host
- Microsoft Defender Antivirus writes its operational channel on the host.
- The installed-product inventory names the protection products present.
The sources below carry those markers.
| Source | What it is | Status |
|---|---|---|
| Microsoft Defender Antivirus event log | Microsoft Defender Antivirus detections, remediation outcomes and engine health from the Defender operational channel. | Live |
| Windows Security event log | The Security channel: sign-in outcomes, privilege use, directory changes and audit policy changes. | Live |
| Windows System event log | The System channel: service, driver, disk, network, cluster and hardware faults from the operating system itself. | Live |
| Installed product summary | A rolled-up view of installed products, including protection-category coverage. | Live |
What is scored here
| Source | Signals | What they are |
|---|---|---|
| Disk volumes | 1 | BitLocker protection dropped |
| Installed products | 1 | product removed |
| Microsoft Defender Antivirus event log | 13 | av config changed, av definition update failed, av engine failed, av protection disabled, av scan failed, av suspicious behavior detected, av tamper blocked, av threat detected, av threat not remediated, av threat remediated, av threat remediation failed, defender asr blocked, defender network protection blocked |
| Windows Application event log | 13 | adcs ca chain failed, adcs crl publish failed, cert enroll failed, cert expiring, entra password hash sync failed, entra sync run failed, entra sync scheduler aborted, mfa not configured, mfa sign in succeeded, mfa unavailable access granted, mfa user not enrolled, security agent config fetch failed, security agent host isolated |
| Windows application platform event channels | 2 | appid certificate store verification failed, appid certificate store verified |
| Windows identity and security event channels | 26 | applocker audit would block, applocker unsupported windows edition, bitlocker recovery key backup failed, bitlocker secure boot unavailable, cert expired, cert expiring, code integrity catalog load failed, code integrity driver revoked, code integrity image hash missing, code integrity policy audit would block, code integrity policy blocked, code integrity signing level blocked, crypto key operation failed, defender sensor connection failed, device encryption enable failed, dpapi unprotect failed, entra sign in failed, entra token acquisition failed, exploit mitigation audit would block, exploit mitigation blocked, exploit mitigation shadow stack mismatch, laps password backup failed, ntlm authentication used, vbs key isolation failed, windows hello key registration failed, windows hello provisioning blocked |
| Windows management event channels | 3 | dfsr partner communication failed, dfsr replication stopped, dfsr sysvol initial sync pending |
| Windows platform event channels | 1 | platform tamper indicator reported |
| Windows Security event log | 56 | account changed, account created, account deleted, account disabled, account enabled, account locked out, account password change failed, account password reset, account password reset failed, adcs audit evidence tampered, adcs config changed, adcs request failed, anonymous remote sign in, audit event processing failed, audit events dropped, audit log cleared, audit log full, audit policy changed, directory object access denied, directory object changed, directory object created, directory object deleted, directory replication access requested, domain policy changed, dsrm password change failed, dsrm password changed, event logging stopped, explicit credential used, group member added, group member removed, guest account sign in, kerberos preauth failed, kerberos rc4 ticket issued, kerberos ticket failed, logon right granted, logon right removed, nps access denied, nps lockout, nps request discarded, ntlm validation failed, principal renamed, process exited abnormally, psdirect handshake probe, replay attack detected, security group changed, security group created, security group deleted, service installed, sid history add failed, sid history added, sign in failed, special group sign in, win insecure boot config, win registry value changed, win registry value created, win registry value deleted |
| Windows System event log | 19 | av unsigned code blocked, http ssl binding created, http ssl binding deleted, http ssl config failed, kerberos cert domain unresolved, kerberos etype unsupported, kerberos pac verify failed, kerberos smartcard cert missing, kerberos weak krbtgt key, platform tamper indicator reported, security agent service start failed, security agent service terminated, service installed, tls cert expired, tls cert name mismatch, tls cert untrusted ca, tls cipher mismatch, tls client credential failed, tls server credential failed |
| Windows PowerShell event channels | 3 | win powershell script block framework code, win powershell script block repeated, win powershell script block sensitive command |