atomic-threat-coverage/pivoting.csv
2019-02-13 20:27:19 +01:00

101 KiB

1fieldcategoryplatformtypechannelproviderdata_neededenrichmentenrichment requirements
2EventIDOS LogsWindowsWindows LogSystemService Control ManagerDN_0005_7045_windows_service_insatalled
3HostnameOS LogsWindowsWindows LogSystemService Control ManagerDN_0005_7045_windows_service_insatalled
4ComputerOS LogsWindowsWindows LogSystemService Control ManagerDN_0005_7045_windows_service_insatalled
5ProcessIDOS LogsWindowsWindows LogSystemService Control ManagerDN_0005_7045_windows_service_insatalled
6ServiceNameOS LogsWindowsWindows LogSystemService Control ManagerDN_0005_7045_windows_service_insatalled
7ImagePathOS LogsWindowsWindows LogSystemService Control ManagerDN_0005_7045_windows_service_insatalled
8ServiceFileNameOS LogsWindowsWindows LogSystemService Control ManagerDN_0005_7045_windows_service_insatalled
9ServiceTypeOS LogsWindowsWindows LogSystemService Control ManagerDN_0005_7045_windows_service_insatalled
10StartTypeOS LogsWindowsWindows LogSystemService Control ManagerDN_0005_7045_windows_service_insatalled
11AccountNameOS LogsWindowsWindows LogSystemService Control ManagerDN_0005_7045_windows_service_insatalled
12UserSidOS LogsWindowsWindows LogSystemService Control ManagerDN_0005_7045_windows_service_insatalled
13EventIDOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0026_5136_windows_directory_service_object_was_modified
14ComputerOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0026_5136_windows_directory_service_object_was_modified
15HostnameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0026_5136_windows_directory_service_object_was_modified
16OpCorrelationIDOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0026_5136_windows_directory_service_object_was_modified
17AppCorrelationIDOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0026_5136_windows_directory_service_object_was_modified
18SubjectUserSidOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0026_5136_windows_directory_service_object_was_modified
19SubjectUserNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0026_5136_windows_directory_service_object_was_modified
20SubjectDomainNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0026_5136_windows_directory_service_object_was_modified
21SubjectLogonIdOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0026_5136_windows_directory_service_object_was_modified
22DSNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0026_5136_windows_directory_service_object_was_modified
23DSTypeOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0026_5136_windows_directory_service_object_was_modified
24ObjectDNOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0026_5136_windows_directory_service_object_was_modified
25ObjectGUIDOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0026_5136_windows_directory_service_object_was_modified
26ObjectClassOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0026_5136_windows_directory_service_object_was_modified
27AttributeLDAPDisplayNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0026_5136_windows_directory_service_object_was_modified
28AttributeSyntaxOIDOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0026_5136_windows_directory_service_object_was_modified
29AttributeValueOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0026_5136_windows_directory_service_object_was_modified
30OperationTypeOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0026_5136_windows_directory_service_object_was_modified
31EventIDOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0007_3_windows_sysmon_network_connection
32ComputerOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0007_3_windows_sysmon_network_connection
33HostnameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0007_3_windows_sysmon_network_connection
34UtcTimeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0007_3_windows_sysmon_network_connection
35ProcessGuidOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0007_3_windows_sysmon_network_connection
36ProcessIdOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0007_3_windows_sysmon_network_connection
37ImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0007_3_windows_sysmon_network_connection
38UserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0007_3_windows_sysmon_network_connection
39ProtocolOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0007_3_windows_sysmon_network_connection
40InitiatedOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0007_3_windows_sysmon_network_connection
41SourceIsIpv6OS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0007_3_windows_sysmon_network_connection
42SourceIpOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0007_3_windows_sysmon_network_connection
43SourceHostnameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0007_3_windows_sysmon_network_connection
44SourcePortOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0007_3_windows_sysmon_network_connection
45SourcePortNameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0007_3_windows_sysmon_network_connection
46DestinationIsIpv6OS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0007_3_windows_sysmon_network_connection
47DestinationIpOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0007_3_windows_sysmon_network_connection
48DestinationHostnameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0007_3_windows_sysmon_network_connection
49DestinationPortOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0007_3_windows_sysmon_network_connection
50DestinationPortNameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0007_3_windows_sysmon_network_connection
51EventIDOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0009_5_windows_sysmon_process_terminated
52ComputerOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0009_5_windows_sysmon_process_terminated
53HostnameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0009_5_windows_sysmon_process_terminated
54UtcTimeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0009_5_windows_sysmon_process_terminated
55ProcessGuidOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0009_5_windows_sysmon_process_terminated
56ProcessIdOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0009_5_windows_sysmon_process_terminated
57ImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0009_5_windows_sysmon_process_terminated
58EventIDOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0030_4662_operation_was_performed_on_an_object
59ComputerOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0030_4662_operation_was_performed_on_an_object
60HostnameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0030_4662_operation_was_performed_on_an_object
61SubjectUserSidOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0030_4662_operation_was_performed_on_an_object
62SubjectUserNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0030_4662_operation_was_performed_on_an_object
63SubjectDomainNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0030_4662_operation_was_performed_on_an_object
64SubjectLogonIdOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0030_4662_operation_was_performed_on_an_object
65ObjectServerOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0030_4662_operation_was_performed_on_an_object
66ObjectTypeOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0030_4662_operation_was_performed_on_an_object
67ObjectNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0030_4662_operation_was_performed_on_an_object
68OperationTypeOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0030_4662_operation_was_performed_on_an_object
69HandleIdOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0030_4662_operation_was_performed_on_an_object
70AccessListOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0030_4662_operation_was_performed_on_an_object
71AccessMaskOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0030_4662_operation_was_performed_on_an_object
72PropertiesOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0030_4662_operation_was_performed_on_an_object
73AdditionalInfoOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0030_4662_operation_was_performed_on_an_object
74AdditionalInfo2OS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0030_4662_operation_was_performed_on_an_object
75EventIDOS LogsWindowsApplications and Services LogsWindows PowerShellPowerShellDN_0038_400_windows_powershell_engine_lifecycle
76ComputerOS LogsWindowsApplications and Services LogsWindows PowerShellPowerShellDN_0038_400_windows_powershell_engine_lifecycle
77HostnameOS LogsWindowsApplications and Services LogsWindows PowerShellPowerShellDN_0038_400_windows_powershell_engine_lifecycle
78EventIDOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0015_11_windows_sysmon_FileCreate
79ComputerOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0015_11_windows_sysmon_FileCreate
80HostnameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0015_11_windows_sysmon_FileCreate
81UtcTimeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0015_11_windows_sysmon_FileCreate
82ProcessGuidOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0015_11_windows_sysmon_FileCreate
83ProcessIdOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0015_11_windows_sysmon_FileCreate
84ImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0015_11_windows_sysmon_FileCreate
85TargetFilenameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0015_11_windows_sysmon_FileCreate
86CreationUtcTimeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0015_11_windows_sysmon_FileCreate
87EventIDOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0032_5145_network_share_object_was_accessed_detailed
88ComputerOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0032_5145_network_share_object_was_accessed_detailed
89HostnameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0032_5145_network_share_object_was_accessed_detailed
90SubjectUserSidOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0032_5145_network_share_object_was_accessed_detailed
91SubjectUserNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0032_5145_network_share_object_was_accessed_detailed
92SubjectDomainNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0032_5145_network_share_object_was_accessed_detailed
93SubjectLogonIdOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0032_5145_network_share_object_was_accessed_detailed
94ObjectTypeOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0032_5145_network_share_object_was_accessed_detailed
95IpAddressOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0032_5145_network_share_object_was_accessed_detailed
96IpPortOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0032_5145_network_share_object_was_accessed_detailed
97ShareNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0032_5145_network_share_object_was_accessed_detailed
98ShareLocalPathOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0032_5145_network_share_object_was_accessed_detailed
99RelativeTargetNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0032_5145_network_share_object_was_accessed_detailed
100AccessMaskOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0032_5145_network_share_object_was_accessed_detailed
101AccessListOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0032_5145_network_share_object_was_accessed_detailed
102AccessReasonOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0032_5145_network_share_object_was_accessed_detailed
103EventIDOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
104AccountNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
105HostnameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
106ComputerOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
107SubjectUserSidOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
108SubjectUserNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
109SubjectDomainNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
110SubjectLogonIdOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
111TargetUserSidOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
112TargetUserNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
113TargetDomainNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
114TargetLogonIdOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
115LogonTypeOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
116LogonProcessNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
117AuthenticationPackageNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
118WorkstationNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
119LogonGuidOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
120TransmittedServicesOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
121LmPackageNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
122KeyLengthOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
123ProcessIdOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
124ProcessNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
125IpAddressOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
126IpPortOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
127ImpersonationLevelOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
128RestrictedAdminModeOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
129TargetOutboundUserNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
130TargetOutboundDomainNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
131VirtualAccountOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
132TargetLinkedLogonIdOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
133ElevatedTokenOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0004_4624_windows_account_logon
134EventIDOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0010_6_windows_sysmon_driver_loaded
135ComputerOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0010_6_windows_sysmon_driver_loaded
136HostnameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0010_6_windows_sysmon_driver_loaded
137UtcTimeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0010_6_windows_sysmon_driver_loaded
138ImageLoadedOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0010_6_windows_sysmon_driver_loaded
139HashesOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0010_6_windows_sysmon_driver_loaded
140Sha256hashOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0010_6_windows_sysmon_driver_loaded
141Md5hashOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0010_6_windows_sysmon_driver_loaded
142SignedOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0010_6_windows_sysmon_driver_loaded
143SignatureOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0010_6_windows_sysmon_driver_loaded
144SignatureStatusOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0010_6_windows_sysmon_driver_loaded
145EventIDOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0001_4688_windows_process_creation
146HostnameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0001_4688_windows_process_creation
147SubjectUserSidOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0001_4688_windows_process_creation
148SubjectUserNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0001_4688_windows_process_creation
149SubjectDomainNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0001_4688_windows_process_creation
150SubjectLogonIdOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0001_4688_windows_process_creation
151NewProcessIdOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0001_4688_windows_process_creation
152NewProcessNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0001_4688_windows_process_creation
153TokenElevationTypeOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0001_4688_windows_process_creation
154ProcessIdOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0001_4688_windows_process_creation
155ProcessPidOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0001_4688_windows_process_creation
156TargetUserSidOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0001_4688_windows_process_creation
157TargetUserNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0001_4688_windows_process_creation
158TargetDomainNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0001_4688_windows_process_creation
159TargetLogonIdOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0001_4688_windows_process_creation
160ParentProcessNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0001_4688_windows_process_creation
161MandatoryLabelOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0001_4688_windows_process_creation
162ProcessNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0001_4688_windows_process_creation
163ImageOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0001_4688_windows_process_creation
164EventIDOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0019_15_windows_sysmon_FileCreateStreamHash
165ComputerOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0019_15_windows_sysmon_FileCreateStreamHash
166HostnameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0019_15_windows_sysmon_FileCreateStreamHash
167UtcTimeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0019_15_windows_sysmon_FileCreateStreamHash
168ProcessGuidOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0019_15_windows_sysmon_FileCreateStreamHash
169ProcessIdOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0019_15_windows_sysmon_FileCreateStreamHash
170ImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0019_15_windows_sysmon_FileCreateStreamHash
171TargetFilenameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0019_15_windows_sysmon_FileCreateStreamHash
172CreationUtcTimeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0019_15_windows_sysmon_FileCreateStreamHash
173HashOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0019_15_windows_sysmon_FileCreateStreamHash
174EventIDOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0028_4794_directory_services_restore_mode_admin_password_set
175ComputerOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0028_4794_directory_services_restore_mode_admin_password_set
176HostnameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0028_4794_directory_services_restore_mode_admin_password_set
177SubjectUserSidOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0028_4794_directory_services_restore_mode_admin_password_set
178SubjectUserNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0028_4794_directory_services_restore_mode_admin_password_set
179SubjectDomainNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0028_4794_directory_services_restore_mode_admin_password_set
180SubjectLogonIdOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0028_4794_directory_services_restore_mode_admin_password_set
181WorkstationOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0028_4794_directory_services_restore_mode_admin_password_set
182StatusOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0028_4794_directory_services_restore_mode_admin_password_set
183EventIDOS LogsWindowsWindows LogSystemMicrosoft-Windows-Kernel-GeneralDN_0083_16_access_history_in_hive_was_cleared
184HostnameOS LogsWindowsWindows LogSystemMicrosoft-Windows-Kernel-GeneralDN_0083_16_access_history_in_hive_was_cleared
185ComputerOS LogsWindowsWindows LogSystemMicrosoft-Windows-Kernel-GeneralDN_0083_16_access_history_in_hive_was_cleared
186HiveNameLengthOS LogsWindowsWindows LogSystemMicrosoft-Windows-Kernel-GeneralDN_0083_16_access_history_in_hive_was_cleared
187HiveNameOS LogsWindowsWindows LogSystemMicrosoft-Windows-Kernel-GeneralDN_0083_16_access_history_in_hive_was_cleared
188KeysUpdatedOS LogsWindowsWindows LogSystemMicrosoft-Windows-Kernel-GeneralDN_0083_16_access_history_in_hive_was_cleared
189DirtyPagesOS LogsWindowsWindows LogSystemMicrosoft-Windows-Kernel-GeneralDN_0083_16_access_history_in_hive_was_cleared
190EventIDOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0012_8_windows_sysmon_CreateRemoteThread
191ComputerOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0012_8_windows_sysmon_CreateRemoteThread
192HostnameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0012_8_windows_sysmon_CreateRemoteThread
193UtcTimeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0012_8_windows_sysmon_CreateRemoteThread
194SourceProcessGuidOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0012_8_windows_sysmon_CreateRemoteThread
195SourceProcessIdOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0012_8_windows_sysmon_CreateRemoteThread
196SourceImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0012_8_windows_sysmon_CreateRemoteThread
197TargetProcessGuidOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0012_8_windows_sysmon_CreateRemoteThread
198TargetProcessIdOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0012_8_windows_sysmon_CreateRemoteThread
199TargetImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0012_8_windows_sysmon_CreateRemoteThread
200NewThreadIdOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0012_8_windows_sysmon_CreateRemoteThread
201StartAddressOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0012_8_windows_sysmon_CreateRemoteThread
202StartModuleOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0012_8_windows_sysmon_CreateRemoteThread
203StartFunctionOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0012_8_windows_sysmon_CreateRemoteThread
204EventIDOS LogsWindowsApplications and Services LogsMicrosoft-Windows-WMI-Activity/OperationalMicrosoft-Windows-WMI-ActivityDN_0081_5861_wmi_activity
205ComputerOS LogsWindowsApplications and Services LogsMicrosoft-Windows-WMI-Activity/OperationalMicrosoft-Windows-WMI-ActivityDN_0081_5861_wmi_activity
206HostnameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-WMI-Activity/OperationalMicrosoft-Windows-WMI-ActivityDN_0081_5861_wmi_activity
207NamespaceOS LogsWindowsApplications and Services LogsMicrosoft-Windows-WMI-Activity/OperationalMicrosoft-Windows-WMI-ActivityDN_0081_5861_wmi_activity
208ESSOS LogsWindowsApplications and Services LogsMicrosoft-Windows-WMI-Activity/OperationalMicrosoft-Windows-WMI-ActivityDN_0081_5861_wmi_activity
209ConsumerOS LogsWindowsApplications and Services LogsMicrosoft-Windows-WMI-Activity/OperationalMicrosoft-Windows-WMI-ActivityDN_0081_5861_wmi_activity
210PossibleCauseOS LogsWindowsApplications and Services LogsMicrosoft-Windows-WMI-Activity/OperationalMicrosoft-Windows-WMI-ActivityDN_0081_5861_wmi_activity
211CreatorSIDOS LogsWindowsApplications and Services LogsMicrosoft-Windows-WMI-Activity/OperationalMicrosoft-Windows-WMI-ActivityDN_0081_5861_wmi_activity
212EventNamespaceOS LogsWindowsApplications and Services LogsMicrosoft-Windows-WMI-Activity/OperationalMicrosoft-Windows-WMI-ActivityDN_0081_5861_wmi_activity
213QueryOS LogsWindowsApplications and Services LogsMicrosoft-Windows-WMI-Activity/OperationalMicrosoft-Windows-WMI-ActivityDN_0081_5861_wmi_activity
214QueryLanguageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-WMI-Activity/OperationalMicrosoft-Windows-WMI-ActivityDN_0081_5861_wmi_activity
215EventFilterOS LogsWindowsApplications and Services LogsMicrosoft-Windows-WMI-Activity/OperationalMicrosoft-Windows-WMI-ActivityDN_0081_5861_wmi_activity
216EventIDOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0023_20_windows_sysmon_WmiEvent
217ComputerOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0023_20_windows_sysmon_WmiEvent
218HostnameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0023_20_windows_sysmon_WmiEvent
219UtcTimeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0023_20_windows_sysmon_WmiEvent
220EventTypeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0023_20_windows_sysmon_WmiEvent
221OperationOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0023_20_windows_sysmon_WmiEvent
222UserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0023_20_windows_sysmon_WmiEvent
223NameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0023_20_windows_sysmon_WmiEvent
224TypeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0023_20_windows_sysmon_WmiEvent
225DestinationOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0023_20_windows_sysmon_WmiEvent
226RuleNameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0023_20_windows_sysmon_WmiEvent
227EventIDOS LogsWindowsApplications and Services LogsMicrosoft-Windows-WMI-Activity/OperationalMicrosoft-Windows-WMI-ActivityDN_0080_5859_wmi_activity
228ComputerOS LogsWindowsApplications and Services LogsMicrosoft-Windows-WMI-Activity/OperationalMicrosoft-Windows-WMI-ActivityDN_0080_5859_wmi_activity
229HostnameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-WMI-Activity/OperationalMicrosoft-Windows-WMI-ActivityDN_0080_5859_wmi_activity
230NamespaceNameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-WMI-Activity/OperationalMicrosoft-Windows-WMI-ActivityDN_0080_5859_wmi_activity
231QueryOS LogsWindowsApplications and Services LogsMicrosoft-Windows-WMI-Activity/OperationalMicrosoft-Windows-WMI-ActivityDN_0080_5859_wmi_activity
232ProcessIDOS LogsWindowsApplications and Services LogsMicrosoft-Windows-WMI-Activity/OperationalMicrosoft-Windows-WMI-ActivityDN_0080_5859_wmi_activity
233ProviderOS LogsWindowsApplications and Services LogsMicrosoft-Windows-WMI-Activity/OperationalMicrosoft-Windows-WMI-ActivityDN_0080_5859_wmi_activity
234queryidOS LogsWindowsApplications and Services LogsMicrosoft-Windows-WMI-Activity/OperationalMicrosoft-Windows-WMI-ActivityDN_0080_5859_wmi_activity
235PossibleCauseOS LogsWindowsApplications and Services LogsMicrosoft-Windows-WMI-Activity/OperationalMicrosoft-Windows-WMI-ActivityDN_0080_5859_wmi_activity
236CorrelationActivityIDOS LogsWindowsApplications and Services LogsMicrosoft-Windows-WMI-Activity/OperationalMicrosoft-Windows-WMI-ActivityDN_0080_5859_wmi_activity
237EventIDOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0063_4697_service_was_installed_in_the_system
238ComputerOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0063_4697_service_was_installed_in_the_system
239HostnameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0063_4697_service_was_installed_in_the_system
240SubjectUserSidOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0063_4697_service_was_installed_in_the_system
241SubjectUserNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0063_4697_service_was_installed_in_the_system
242SubjectDomainNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0063_4697_service_was_installed_in_the_system
243SubjectLogonIdOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0063_4697_service_was_installed_in_the_system
244ServiceNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0063_4697_service_was_installed_in_the_system
245ServiceFileNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0063_4697_service_was_installed_in_the_system
246ServiceTypeOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0063_4697_service_was_installed_in_the_system
247ServiceStartTypeOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0063_4697_service_was_installed_in_the_system
248ServiceAccountOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0063_4697_service_was_installed_in_the_system
249EventIDOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0024_21_windows_sysmon_WmiEvent
250ComputerOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0024_21_windows_sysmon_WmiEvent
251HostnameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0024_21_windows_sysmon_WmiEvent
252UtcTimeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0024_21_windows_sysmon_WmiEvent
253EventTypeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0024_21_windows_sysmon_WmiEvent
254OperationOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0024_21_windows_sysmon_WmiEvent
255UserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0024_21_windows_sysmon_WmiEvent
256ConsumerOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0024_21_windows_sysmon_WmiEvent
257RuleNameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0024_21_windows_sysmon_WmiEvent
258FilterOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0024_21_windows_sysmon_WmiEvent
259EventIDOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0008_4_windows_sysmon_sysmon_service_state_changed
260ComputerOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0008_4_windows_sysmon_sysmon_service_state_changed
261HostnameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0008_4_windows_sysmon_sysmon_service_state_changed
262UtcTimeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0008_4_windows_sysmon_sysmon_service_state_changed
263StateOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0008_4_windows_sysmon_sysmon_service_state_changed
264EventIDOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0033_5140_network_share_object_was_accessed
265ComputerOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0033_5140_network_share_object_was_accessed
266HostnameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0033_5140_network_share_object_was_accessed
267SubjectUserSidOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0033_5140_network_share_object_was_accessed
268SubjectUserNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0033_5140_network_share_object_was_accessed
269SubjectDomainNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0033_5140_network_share_object_was_accessed
270SubjectLogonIdOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0033_5140_network_share_object_was_accessed
271ObjectTypeOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0033_5140_network_share_object_was_accessed
272IpAddressOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0033_5140_network_share_object_was_accessed
273IpPortOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0033_5140_network_share_object_was_accessed
274ShareNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0033_5140_network_share_object_was_accessed
275ShareLocalPathOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0033_5140_network_share_object_was_accessed
276AccessMaskOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0033_5140_network_share_object_was_accessed
277AccessListOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0033_5140_network_share_object_was_accessed
278EventIDOS LogsWindowsApplications and Services LogsDNS ServerMicrosoft-Windows-DNS-Server-ServiceDN_0036_150_dns_server_could_not_load_dll
279HostnameOS LogsWindowsApplications and Services LogsDNS ServerMicrosoft-Windows-DNS-Server-ServiceDN_0036_150_dns_server_could_not_load_dll
280ComputerOS LogsWindowsApplications and Services LogsDNS ServerMicrosoft-Windows-DNS-Server-ServiceDN_0036_150_dns_server_could_not_load_dll
281EventIDOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0013_9_windows_sysmon_RawAccessRead
282ComputerOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0013_9_windows_sysmon_RawAccessRead
283HostnameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0013_9_windows_sysmon_RawAccessRead
284UtcTimeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0013_9_windows_sysmon_RawAccessRead
285ProcessGuidOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0013_9_windows_sysmon_RawAccessRead
286ProcessIdOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0013_9_windows_sysmon_RawAccessRead
287ImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0013_9_windows_sysmon_RawAccessRead
288DeviceOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0013_9_windows_sysmon_RawAccessRead
289EventIDOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0017_13_windows_sysmon_RegistryEvent
290ComputerOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0017_13_windows_sysmon_RegistryEvent
291HostnameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0017_13_windows_sysmon_RegistryEvent
292EventTypeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0017_13_windows_sysmon_RegistryEvent
293UtcTimeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0017_13_windows_sysmon_RegistryEvent
294ProcessGuidOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0017_13_windows_sysmon_RegistryEvent
295ProcessIdOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0017_13_windows_sysmon_RegistryEvent
296ImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0017_13_windows_sysmon_RegistryEvent
297TargetObjectOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0017_13_windows_sysmon_RegistryEvent
298DetailsOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0017_13_windows_sysmon_RegistryEvent
299EventIDOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0014_10_windows_sysmon_ProcessAccess
300ComputerOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0014_10_windows_sysmon_ProcessAccess
301HostnameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0014_10_windows_sysmon_ProcessAccess
302UtcTimeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0014_10_windows_sysmon_ProcessAccess
303SourceProcessGUIDOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0014_10_windows_sysmon_ProcessAccess
304SourceProcessIdOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0014_10_windows_sysmon_ProcessAccess
305SourceThreadIdOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0014_10_windows_sysmon_ProcessAccess
306SourceImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0014_10_windows_sysmon_ProcessAccess
307TargetProcessGUIDOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0014_10_windows_sysmon_ProcessAccess
308TargetProcessIdOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0014_10_windows_sysmon_ProcessAccess
309TargetImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0014_10_windows_sysmon_ProcessAccess
310GrantedAccessOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0014_10_windows_sysmon_ProcessAccess
311CallTraceOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0014_10_windows_sysmon_ProcessAccess
312EventIDOS LogsWindowsApplications and Services LogsMicrosoft-Windows-PowerShell/OperationalMicrosoft-Windows-PowerShellDN_0037_4103_windows_powershell_executing_pipeline
313ComputerOS LogsWindowsApplications and Services LogsMicrosoft-Windows-PowerShell/OperationalMicrosoft-Windows-PowerShellDN_0037_4103_windows_powershell_executing_pipeline
314HostnameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-PowerShell/OperationalMicrosoft-Windows-PowerShellDN_0037_4103_windows_powershell_executing_pipeline
315ContextInfoOS LogsWindowsApplications and Services LogsMicrosoft-Windows-PowerShell/OperationalMicrosoft-Windows-PowerShellDN_0037_4103_windows_powershell_executing_pipeline
316UserDataOS LogsWindowsApplications and Services LogsMicrosoft-Windows-PowerShell/OperationalMicrosoft-Windows-PowerShellDN_0037_4103_windows_powershell_executing_pipeline
317PayloadOS LogsWindowsApplications and Services LogsMicrosoft-Windows-PowerShell/OperationalMicrosoft-Windows-PowerShellDN_0037_4103_windows_powershell_executing_pipeline
318EventIDOS LogsWindowsWindows LogSystemMicrosoft-Windows-EventlogDN_0034_104_log_file_was_cleared
319ComputerOS LogsWindowsWindows LogSystemMicrosoft-Windows-EventlogDN_0034_104_log_file_was_cleared
320HostnameOS LogsWindowsWindows LogSystemMicrosoft-Windows-EventlogDN_0034_104_log_file_was_cleared
321SubjectUserNameOS LogsWindowsWindows LogSystemMicrosoft-Windows-EventlogDN_0034_104_log_file_was_cleared
322SubjectDomainNameOS LogsWindowsWindows LogSystemMicrosoft-Windows-EventlogDN_0034_104_log_file_was_cleared
323ChannelOS LogsWindowsWindows LogSystemMicrosoft-Windows-EventlogDN_0034_104_log_file_was_cleared
324EventIDOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0027_4738_user_account_was_changed
325ComputerOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0027_4738_user_account_was_changed
326TargetUserNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0027_4738_user_account_was_changed
327HostnameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0027_4738_user_account_was_changed
328TargetDomainNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0027_4738_user_account_was_changed
329TargetSidOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0027_4738_user_account_was_changed
330SubjectUserSidOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0027_4738_user_account_was_changed
331SubjectUserNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0027_4738_user_account_was_changed
332SubjectDomainNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0027_4738_user_account_was_changed
333SubjectLogonIdOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0027_4738_user_account_was_changed
334PrivilegeListOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0027_4738_user_account_was_changed
335SamAccountNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0027_4738_user_account_was_changed
336DisplayNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0027_4738_user_account_was_changed
337UserPrincipalNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0027_4738_user_account_was_changed
338HomeDirectoryOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0027_4738_user_account_was_changed
339HomePathOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0027_4738_user_account_was_changed
340ScriptPathOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0027_4738_user_account_was_changed
341ProfilePathOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0027_4738_user_account_was_changed
342UserWorkstationsOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0027_4738_user_account_was_changed
343PasswordLastSetOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0027_4738_user_account_was_changed
344AccountExpiresOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0027_4738_user_account_was_changed
345PrimaryGroupIdOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0027_4738_user_account_was_changed
346AllowedToDelegateToOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0027_4738_user_account_was_changed
347OldUacValueOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0027_4738_user_account_was_changed
348NewUacValueOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0027_4738_user_account_was_changed
349UserAccountControlOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0027_4738_user_account_was_changed
350UserParametersOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0027_4738_user_account_was_changed
351SidHistoryOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0027_4738_user_account_was_changed
352LogonHoursOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0027_4738_user_account_was_changed
353EventIDOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0006_2_windows_sysmon_process_changed_a_file_creation_time
354ComputerOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0006_2_windows_sysmon_process_changed_a_file_creation_time
355HostnameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0006_2_windows_sysmon_process_changed_a_file_creation_time
356UtcTimeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0006_2_windows_sysmon_process_changed_a_file_creation_time
357ProcessGuidOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0006_2_windows_sysmon_process_changed_a_file_creation_time
358ProcessIdOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0006_2_windows_sysmon_process_changed_a_file_creation_time
359ImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0006_2_windows_sysmon_process_changed_a_file_creation_time
360TargetFilenameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0006_2_windows_sysmon_process_changed_a_file_creation_time
361CreationUtcTimeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0006_2_windows_sysmon_process_changed_a_file_creation_time
362PreviousCreationUtcTimeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0006_2_windows_sysmon_process_changed_a_file_creation_time
363EventIDOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0011_7_windows_sysmon_image_loaded
364ComputerOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0011_7_windows_sysmon_image_loaded
365HostnameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0011_7_windows_sysmon_image_loaded
366UtcTimeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0011_7_windows_sysmon_image_loaded
367ProcessGuidOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0011_7_windows_sysmon_image_loaded
368ProcessIdOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0011_7_windows_sysmon_image_loaded
369ImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0011_7_windows_sysmon_image_loaded
370ImageLoadedOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0011_7_windows_sysmon_image_loaded
371HashesOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0011_7_windows_sysmon_image_loaded
372SignedOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0011_7_windows_sysmon_image_loaded
373SignatureOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0011_7_windows_sysmon_image_loaded
374SignatureStatusOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0011_7_windows_sysmon_image_loaded
375EventIDOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0016_12_windows_sysmon_RegistryEvent
376ComputerOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0016_12_windows_sysmon_RegistryEvent
377HostnameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0016_12_windows_sysmon_RegistryEvent
378EventTypeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0016_12_windows_sysmon_RegistryEvent
379UtcTimeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0016_12_windows_sysmon_RegistryEvent
380ProcessGuidOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0016_12_windows_sysmon_RegistryEvent
381ProcessIdOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0016_12_windows_sysmon_RegistryEvent
382ImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0016_12_windows_sysmon_RegistryEvent
383TargetObjectOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0016_12_windows_sysmon_RegistryEvent
384EventIDOS LogsWindowsWindows LogSystemService Control ManagerDN_0031_7036_service_started_stopped
385ComputerOS LogsWindowsWindows LogSystemService Control ManagerDN_0031_7036_service_started_stopped
386HostnameOS LogsWindowsWindows LogSystemService Control ManagerDN_0031_7036_service_started_stopped
387param1OS LogsWindowsWindows LogSystemService Control ManagerDN_0031_7036_service_started_stopped
388param2OS LogsWindowsWindows LogSystemService Control ManagerDN_0031_7036_service_started_stopped
389EventIDOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0022_19_windows_sysmon_WmiEvent
390ComputerOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0022_19_windows_sysmon_WmiEvent
391HostnameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0022_19_windows_sysmon_WmiEvent
392UtcTimeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0022_19_windows_sysmon_WmiEvent
393EventTypeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0022_19_windows_sysmon_WmiEvent
394OperationOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0022_19_windows_sysmon_WmiEvent
395UserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0022_19_windows_sysmon_WmiEvent
396EventNamespaceOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0022_19_windows_sysmon_WmiEvent
397NameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0022_19_windows_sysmon_WmiEvent
398QueryOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0022_19_windows_sysmon_WmiEvent
399RuleNameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0022_19_windows_sysmon_WmiEvent
400EventIDOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0029_4661_handle_to_an_object_was_requested
401ComputerOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0029_4661_handle_to_an_object_was_requested
402HostnameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0029_4661_handle_to_an_object_was_requested
403SubjectUserSidOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0029_4661_handle_to_an_object_was_requested
404SubjectUserNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0029_4661_handle_to_an_object_was_requested
405SubjectDomainNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0029_4661_handle_to_an_object_was_requested
406SubjectLogonIdOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0029_4661_handle_to_an_object_was_requested
407ObjectServerOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0029_4661_handle_to_an_object_was_requested
408ObjectTypeOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0029_4661_handle_to_an_object_was_requested
409ObjectNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0029_4661_handle_to_an_object_was_requested
410HandleIdOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0029_4661_handle_to_an_object_was_requested
411TransactionIdOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0029_4661_handle_to_an_object_was_requested
412AccessListOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0029_4661_handle_to_an_object_was_requested
413AccessMaskOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0029_4661_handle_to_an_object_was_requested
414PrivilegeListOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0029_4661_handle_to_an_object_was_requested
415PropertiesOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0029_4661_handle_to_an_object_was_requested
416RestrictedSidCountOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0029_4661_handle_to_an_object_was_requested
417ProcessIdOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0029_4661_handle_to_an_object_was_requested
418ProcessNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0029_4661_handle_to_an_object_was_requested
419EventIDOS LogsWindowsApplications and Services LogsMicrosoft-Windows-TaskScheduler/OperationalMicrosoft-Windows-TaskSchedulerDN_0035_106_task_scheduler_task_registered
420ComputerOS LogsWindowsApplications and Services LogsMicrosoft-Windows-TaskScheduler/OperationalMicrosoft-Windows-TaskSchedulerDN_0035_106_task_scheduler_task_registered
421HostnameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-TaskScheduler/OperationalMicrosoft-Windows-TaskSchedulerDN_0035_106_task_scheduler_task_registered
422TaskNameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-TaskScheduler/OperationalMicrosoft-Windows-TaskSchedulerDN_0035_106_task_scheduler_task_registered
423UserContextOS LogsWindowsApplications and Services LogsMicrosoft-Windows-TaskScheduler/OperationalMicrosoft-Windows-TaskSchedulerDN_0035_106_task_scheduler_task_registered
424EventIDOS LogsWindowsApplications and Services LogsMicrosoft-Windows-PowerShell/OperationalMicrosoft-Windows-PowerShellDN_0036_4104_windows_powershell_script_block
425ComputerOS LogsWindowsApplications and Services LogsMicrosoft-Windows-PowerShell/OperationalMicrosoft-Windows-PowerShellDN_0036_4104_windows_powershell_script_block
426HostnameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-PowerShell/OperationalMicrosoft-Windows-PowerShellDN_0036_4104_windows_powershell_script_block
427MessageNumberOS LogsWindowsApplications and Services LogsMicrosoft-Windows-PowerShell/OperationalMicrosoft-Windows-PowerShellDN_0036_4104_windows_powershell_script_block
428MessageTotalOS LogsWindowsApplications and Services LogsMicrosoft-Windows-PowerShell/OperationalMicrosoft-Windows-PowerShellDN_0036_4104_windows_powershell_script_block
429ScriptBlockTextOS LogsWindowsApplications and Services LogsMicrosoft-Windows-PowerShell/OperationalMicrosoft-Windows-PowerShellDN_0036_4104_windows_powershell_script_block
430ScriptBlockIdOS LogsWindowsApplications and Services LogsMicrosoft-Windows-PowerShell/OperationalMicrosoft-Windows-PowerShellDN_0036_4104_windows_powershell_script_block
431PathOS LogsWindowsApplications and Services LogsMicrosoft-Windows-PowerShell/OperationalMicrosoft-Windows-PowerShellDN_0036_4104_windows_powershell_script_block
432EventIDOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creation
433HostnameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creation
434ComputerOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creation
435UtcTimeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creation
436UsernameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creation
437UserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creation
438ProcessGuidOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creation
439ProcessIdOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creation
440ProcessNameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creation
441CommandLineOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creation
442LogonGuidOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creation
443LogonIdOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creation
444TerminalSessionidOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creation
445IntegrityLevelOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creation
446HashesOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creation
447ImphashOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creation
448Sha256hashOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creation
449Sha1hashOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creation
450Md5hashOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creation
451ImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creation
452ParentImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creation
453ParentProcessGuidOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creation
454ParentProcessIdOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creation
455ParentProcessNameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creation
456ParentCommandLineOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creation
457EventIDOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0021_18_windows_sysmon_PipeEvent
458ComputerOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0021_18_windows_sysmon_PipeEvent
459HostnameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0021_18_windows_sysmon_PipeEvent
460UtcTimeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0021_18_windows_sysmon_PipeEvent
461ProcessGuidOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0021_18_windows_sysmon_PipeEvent
462ProcessIdOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0021_18_windows_sysmon_PipeEvent
463PipeNameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0021_18_windows_sysmon_PipeEvent
464ImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0021_18_windows_sysmon_PipeEvent
465EventIDOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0018_14_windows_sysmon_RegistryEvent
466ComputerOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0018_14_windows_sysmon_RegistryEvent
467HostnameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0018_14_windows_sysmon_RegistryEvent
468EventTypeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0018_14_windows_sysmon_RegistryEvent
469UtcTimeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0018_14_windows_sysmon_RegistryEvent
470ProcessGuidOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0018_14_windows_sysmon_RegistryEvent
471ProcessIdOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0018_14_windows_sysmon_RegistryEvent
472ImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0018_14_windows_sysmon_RegistryEvent
473TargetObjectOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0018_14_windows_sysmon_RegistryEvent
474NewNameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0018_14_windows_sysmon_RegistryEvent
475EventIDOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0020_17_windows_sysmon_PipeEvent
476ComputerOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0020_17_windows_sysmon_PipeEvent
477HostnameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0020_17_windows_sysmon_PipeEvent
478UtcTimeOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0020_17_windows_sysmon_PipeEvent
479ProcessGuidOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0020_17_windows_sysmon_PipeEvent
480ProcessIdOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0020_17_windows_sysmon_PipeEvent
481PipeNameOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0020_17_windows_sysmon_PipeEvent
482ImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0020_17_windows_sysmon_PipeEvent
483EventIDOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0002_4688_windows_process_creation_with_commandline
484HostnameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0002_4688_windows_process_creation_with_commandline
485SubjectUserSidOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0002_4688_windows_process_creation_with_commandline
486SubjectUserNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0002_4688_windows_process_creation_with_commandline
487SubjectDomainNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0002_4688_windows_process_creation_with_commandline
488SubjectLogonIdOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0002_4688_windows_process_creation_with_commandline
489NewProcessIdOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0002_4688_windows_process_creation_with_commandline
490ProcessIdOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0002_4688_windows_process_creation_with_commandline
491NewProcessNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0002_4688_windows_process_creation_with_commandline
492ProcessNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0002_4688_windows_process_creation_with_commandline
493NewProcessNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0002_4688_windows_process_creation_with_commandline
494ImageOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0002_4688_windows_process_creation_with_commandline
495TokenElevationTypeOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0002_4688_windows_process_creation_with_commandline
496CommandLineOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0002_4688_windows_process_creation_with_commandline
497ProcessCommandLineOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0002_4688_windows_process_creation_with_commandline
498ProcesssCommandLineOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0002_4688_windows_process_creation_with_commandline
499TargetUserSidOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0002_4688_windows_process_creation_with_commandline
500TargetUserNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0002_4688_windows_process_creation_with_commandline
501TargetDomainNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0002_4688_windows_process_creation_with_commandline
502TargetLogonIdOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0002_4688_windows_process_creation_with_commandline
503ParentProcessNameOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0002_4688_windows_process_creation_with_commandline
504ParentImageOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0002_4688_windows_process_creation_with_commandline
505MandatoryLabelOS LogsWindowsWindows LogSecurityMicrosoft-Windows-Security-AuditingDN_0002_4688_windows_process_creation_with_commandline
506HostnameAV AlertsantivirusNoneNoneNoneDN_0084_av_alert
507SignatureAV AlertsantivirusNoneNoneNoneDN_0084_av_alert
508AlertTitleAV AlertsantivirusNoneNoneNoneDN_0084_av_alert
509CategoryAV AlertsantivirusNoneNoneNoneDN_0084_av_alert
510SeverityAV AlertsantivirusNoneNoneNoneDN_0084_av_alert
511Sha1AV AlertsantivirusNoneNoneNoneDN_0084_av_alert
512FileNameAV AlertsantivirusNoneNoneNoneDN_0084_av_alert
513FilePathAV AlertsantivirusNoneNoneNoneDN_0084_av_alert
514IpAddressAV AlertsantivirusNoneNoneNoneDN_0084_av_alert
515UserNameAV AlertsantivirusNoneNoneNoneDN_0084_av_alert
516UserDomainAV AlertsantivirusNoneNoneNoneDN_0084_av_alert
517FileHashAV AlertsantivirusNoneNoneNoneDN_0084_av_alert
518HashesAV AlertsantivirusNoneNoneNoneDN_0084_av_alert
519ImphashAV AlertsantivirusNoneNoneNoneDN_0084_av_alert
520Sha256hashAV AlertsantivirusNoneNoneNoneDN_0084_av_alert
521Sha1hashAV AlertsantivirusNoneNoneNoneDN_0084_av_alert
522Md5hashAV AlertsantivirusNoneNoneNoneDN_0084_av_alert
523event_data.ParentIntegrityLevelOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creationEN_0002_enrich_sysmon_event_id_1_with_parent_infoEN_0001_cache_sysmon_event_id_1_info
524event_data.ParentUserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creationEN_0002_enrich_sysmon_event_id_1_with_parent_infoEN_0001_cache_sysmon_event_id_1_info
525event_data.ParentOfParentImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creationEN_0002_enrich_sysmon_event_id_1_with_parent_infoEN_0001_cache_sysmon_event_id_1_info
526ParentIntegrityLevelOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creationEN_0002_enrich_sysmon_event_id_1_with_parent_infoEN_0001_cache_sysmon_event_id_1_info
527ParentUserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creationEN_0002_enrich_sysmon_event_id_1_with_parent_infoEN_0001_cache_sysmon_event_id_1_info
528ParentOfParentImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0003_1_windows_sysmon_process_creationEN_0002_enrich_sysmon_event_id_1_with_parent_infoEN_0001_cache_sysmon_event_id_1_info
529event_data.IntegrityLevelOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0007_3_windows_sysmon_network_connectionEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
530event_data.UserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0007_3_windows_sysmon_network_connectionEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
531event_data.CommandLineOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0007_3_windows_sysmon_network_connectionEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
532event_data.ParentImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0007_3_windows_sysmon_network_connectionEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
533IntegrityLevelOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0007_3_windows_sysmon_network_connectionEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
534UserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0007_3_windows_sysmon_network_connectionEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
535CommandLineOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0007_3_windows_sysmon_network_connectionEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
536ParentImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0007_3_windows_sysmon_network_connectionEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
537event_data.IntegrityLevelOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0009_5_windows_sysmon_process_terminatedEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
538event_data.UserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0009_5_windows_sysmon_process_terminatedEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
539event_data.CommandLineOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0009_5_windows_sysmon_process_terminatedEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
540event_data.ParentImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0009_5_windows_sysmon_process_terminatedEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
541IntegrityLevelOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0009_5_windows_sysmon_process_terminatedEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
542UserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0009_5_windows_sysmon_process_terminatedEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
543CommandLineOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0009_5_windows_sysmon_process_terminatedEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
544ParentImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0009_5_windows_sysmon_process_terminatedEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
545event_data.IntegrityLevelOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0015_11_windows_sysmon_FileCreateEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
546event_data.UserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0015_11_windows_sysmon_FileCreateEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
547event_data.CommandLineOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0015_11_windows_sysmon_FileCreateEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
548event_data.ParentImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0015_11_windows_sysmon_FileCreateEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
549IntegrityLevelOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0015_11_windows_sysmon_FileCreateEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
550UserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0015_11_windows_sysmon_FileCreateEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
551CommandLineOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0015_11_windows_sysmon_FileCreateEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
552ParentImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0015_11_windows_sysmon_FileCreateEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
553event_data.IntegrityLevelOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0019_15_windows_sysmon_FileCreateStreamHashEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
554event_data.UserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0019_15_windows_sysmon_FileCreateStreamHashEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
555event_data.CommandLineOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0019_15_windows_sysmon_FileCreateStreamHashEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
556event_data.ParentImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0019_15_windows_sysmon_FileCreateStreamHashEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
557IntegrityLevelOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0019_15_windows_sysmon_FileCreateStreamHashEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
558UserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0019_15_windows_sysmon_FileCreateStreamHashEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
559CommandLineOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0019_15_windows_sysmon_FileCreateStreamHashEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
560ParentImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0019_15_windows_sysmon_FileCreateStreamHashEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
561event_data.IntegrityLevelOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0013_9_windows_sysmon_RawAccessReadEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
562event_data.UserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0013_9_windows_sysmon_RawAccessReadEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
563event_data.CommandLineOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0013_9_windows_sysmon_RawAccessReadEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
564event_data.ParentImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0013_9_windows_sysmon_RawAccessReadEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
565IntegrityLevelOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0013_9_windows_sysmon_RawAccessReadEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
566UserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0013_9_windows_sysmon_RawAccessReadEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
567CommandLineOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0013_9_windows_sysmon_RawAccessReadEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
568ParentImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0013_9_windows_sysmon_RawAccessReadEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
569event_data.IntegrityLevelOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0017_13_windows_sysmon_RegistryEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
570event_data.UserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0017_13_windows_sysmon_RegistryEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
571event_data.CommandLineOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0017_13_windows_sysmon_RegistryEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
572event_data.ParentImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0017_13_windows_sysmon_RegistryEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
573IntegrityLevelOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0017_13_windows_sysmon_RegistryEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
574UserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0017_13_windows_sysmon_RegistryEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
575CommandLineOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0017_13_windows_sysmon_RegistryEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
576ParentImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0017_13_windows_sysmon_RegistryEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
577event_data.IntegrityLevelOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0006_2_windows_sysmon_process_changed_a_file_creation_timeEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
578event_data.UserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0006_2_windows_sysmon_process_changed_a_file_creation_timeEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
579event_data.CommandLineOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0006_2_windows_sysmon_process_changed_a_file_creation_timeEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
580event_data.ParentImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0006_2_windows_sysmon_process_changed_a_file_creation_timeEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
581IntegrityLevelOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0006_2_windows_sysmon_process_changed_a_file_creation_timeEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
582UserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0006_2_windows_sysmon_process_changed_a_file_creation_timeEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
583CommandLineOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0006_2_windows_sysmon_process_changed_a_file_creation_timeEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
584ParentImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0006_2_windows_sysmon_process_changed_a_file_creation_timeEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
585event_data.IntegrityLevelOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0011_7_windows_sysmon_image_loadedEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
586event_data.UserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0011_7_windows_sysmon_image_loadedEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
587event_data.CommandLineOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0011_7_windows_sysmon_image_loadedEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
588event_data.ParentImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0011_7_windows_sysmon_image_loadedEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
589IntegrityLevelOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0011_7_windows_sysmon_image_loadedEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
590UserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0011_7_windows_sysmon_image_loadedEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
591CommandLineOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0011_7_windows_sysmon_image_loadedEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
592ParentImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0011_7_windows_sysmon_image_loadedEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
593event_data.IntegrityLevelOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0016_12_windows_sysmon_RegistryEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
594event_data.UserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0016_12_windows_sysmon_RegistryEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
595event_data.CommandLineOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0016_12_windows_sysmon_RegistryEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
596event_data.ParentImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0016_12_windows_sysmon_RegistryEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
597IntegrityLevelOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0016_12_windows_sysmon_RegistryEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
598UserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0016_12_windows_sysmon_RegistryEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
599CommandLineOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0016_12_windows_sysmon_RegistryEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
600ParentImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0016_12_windows_sysmon_RegistryEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
601event_data.IntegrityLevelOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0021_18_windows_sysmon_PipeEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
602event_data.UserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0021_18_windows_sysmon_PipeEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
603event_data.CommandLineOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0021_18_windows_sysmon_PipeEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
604event_data.ParentImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0021_18_windows_sysmon_PipeEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
605IntegrityLevelOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0021_18_windows_sysmon_PipeEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
606UserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0021_18_windows_sysmon_PipeEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
607CommandLineOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0021_18_windows_sysmon_PipeEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
608ParentImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0021_18_windows_sysmon_PipeEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
609event_data.IntegrityLevelOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0018_14_windows_sysmon_RegistryEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
610event_data.UserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0018_14_windows_sysmon_RegistryEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
611event_data.CommandLineOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0018_14_windows_sysmon_RegistryEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
612event_data.ParentImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0018_14_windows_sysmon_RegistryEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
613IntegrityLevelOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0018_14_windows_sysmon_RegistryEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
614UserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0018_14_windows_sysmon_RegistryEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
615CommandLineOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0018_14_windows_sysmon_RegistryEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
616ParentImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0018_14_windows_sysmon_RegistryEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
617event_data.IntegrityLevelOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0020_17_windows_sysmon_PipeEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
618event_data.UserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0020_17_windows_sysmon_PipeEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
619event_data.CommandLineOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0020_17_windows_sysmon_PipeEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
620event_data.ParentImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0020_17_windows_sysmon_PipeEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
621IntegrityLevelOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0020_17_windows_sysmon_PipeEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
622UserOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0020_17_windows_sysmon_PipeEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
623CommandLineOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0020_17_windows_sysmon_PipeEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info
624ParentImageOS LogsWindowsApplications and Services LogsMicrosoft-Windows-Sysmon/OperationalMicrosoft-Windows-SysmonDN_0020_17_windows_sysmon_PipeEventEN_0003_enrich_other_sysmon_events_with_event_id_1_dataEN_0001_cache_sysmon_event_id_1_info