Skip to main content

Security and identity

11sources
136reasons
2conditions
13decode tables

An account, credential, permission or audit setting changed in a way worth checking.

How the agent recognises this on a host​

  • Microsoft Defender Antivirus writes its operational channel on the host.
  • The installed-product inventory names the protection products present.

The sources below carry those markers.

SourceWhat it isStatus
Microsoft Defender Antivirus event logMicrosoft Defender Antivirus detections, remediation outcomes and engine health from the Defender operational channel.Live
Windows Security event logThe Security channel: sign-in outcomes, privilege use, directory changes and audit policy changes.Live
Windows System event logThe System channel: service, driver, disk, network, cluster and hardware faults from the operating system itself.Live
Installed product summaryA rolled-up view of installed products, including protection-category coverage.Live

What is scored here​

SourceSignalsWhat they are
Disk volumes1BitLocker protection dropped
Installed products1product removed
Microsoft Defender Antivirus event log13av config changed, av definition update failed, av engine failed, av protection disabled, av scan failed, av suspicious behavior detected, av tamper blocked, av threat detected, av threat not remediated, av threat remediated, av threat remediation failed, defender asr blocked, defender network protection blocked
Windows Application event log13adcs ca chain failed, adcs crl publish failed, cert enroll failed, cert expiring, entra password hash sync failed, entra sync run failed, entra sync scheduler aborted, mfa not configured, mfa sign in succeeded, mfa unavailable access granted, mfa user not enrolled, security agent config fetch failed, security agent host isolated
Windows application platform event channels2appid certificate store verification failed, appid certificate store verified
Windows identity and security event channels26applocker audit would block, applocker unsupported windows edition, bitlocker recovery key backup failed, bitlocker secure boot unavailable, cert expired, cert expiring, code integrity catalog load failed, code integrity driver revoked, code integrity image hash missing, code integrity policy audit would block, code integrity policy blocked, code integrity signing level blocked, crypto key operation failed, defender sensor connection failed, device encryption enable failed, dpapi unprotect failed, entra sign in failed, entra token acquisition failed, exploit mitigation audit would block, exploit mitigation blocked, exploit mitigation shadow stack mismatch, laps password backup failed, ntlm authentication used, vbs key isolation failed, windows hello key registration failed, windows hello provisioning blocked
Windows management event channels3dfsr partner communication failed, dfsr replication stopped, dfsr sysvol initial sync pending
Windows platform event channels1platform tamper indicator reported
Windows Security event log56account changed, account created, account deleted, account disabled, account enabled, account locked out, account password change failed, account password reset, account password reset failed, adcs audit evidence tampered, adcs config changed, adcs request failed, anonymous remote sign in, audit event processing failed, audit events dropped, audit log cleared, audit log full, audit policy changed, directory object access denied, directory object changed, directory object created, directory object deleted, directory replication access requested, domain policy changed, dsrm password change failed, dsrm password changed, event logging stopped, explicit credential used, group member added, group member removed, guest account sign in, kerberos preauth failed, kerberos rc4 ticket issued, kerberos ticket failed, logon right granted, logon right removed, nps access denied, nps lockout, nps request discarded, ntlm validation failed, principal renamed, process exited abnormally, psdirect handshake probe, replay attack detected, security group changed, security group created, security group deleted, service installed, sid history add failed, sid history added, sign in failed, special group sign in, win insecure boot config, win registry value changed, win registry value created, win registry value deleted
Windows System event log19av unsigned code blocked, http ssl binding created, http ssl binding deleted, http ssl config failed, kerberos cert domain unresolved, kerberos etype unsupported, kerberos pac verify failed, kerberos smartcard cert missing, kerberos weak krbtgt key, platform tamper indicator reported, security agent service start failed, security agent service terminated, service installed, tls cert expired, tls cert name mismatch, tls cert untrusted ca, tls cipher mismatch, tls client credential failed, tls server credential failed
Windows PowerShell event channels3win powershell script block framework code, win powershell script block repeated, win powershell script block sensitive command