| Abnormal Authentication & Access | account-creation ↳syslog-json-4720 ↳cef-4720 ↳cef-windows-account-4720 ↳sk4-json-4720 ↳s-xml-4720 ↳raw-windows-account-624 ↳wls-4720 ↳s-4720-jp ↳mcafee-siem-4720 ↳windows-xml-4720 ↳raw-windows-account-4720 ↳cef-624 ↳ad-json-4720 ↳json-4720-1 ↳json-4720 ↳l-4720 ↳ad-audit-4720
account-deleted ↳s-xml-4726 ↳raw-windows-account-4726 ↳json-4726 ↳s-4726-jp ↳nxlog-json-4726 ↳wls-4726 ↳mcafee-siem-4726 ↳raw-windows-account-630 ↳ad-audit-4726 ↳raw-4743 ↳raw-4743-1 ↳ad-audit-4743 ↳raw-4743-2
account-disabled ↳s-xml-4725 ↳raw-windows-account-629 ↳syslog-json-4725 ↳cef-4725 ↳wls-4725 ↳sk4-json-4725 ↳n-forwarded-cef-4725 ↳mcafee-siem-4725 ↳raw-windows-account-4725 ↳json-4725 ↳s-4725-jp ↳l-4725 ↳s-windows-event-4725 ↳s-windows-event-629 ↳ad-audit-4725
account-enabled ↳syslog-json-4722 ↳cef-4722 ↳sk4-json-4722 ↳mcafee-siem-4722 ↳n-forwarded-cef-4722 ↳json-4722 ↳raw-windows-account-4722 ↳windows-xml-4722 ↳ad-json-4722 ↳l-4722 ↳s-windows-event-626 ↳s-windows-event-4722 ↳s-4722-jp ↳ad-audit-4722
account-lockout ↳cef-4740 ↳s-4740-2 ↳s-windows-event-644 ↳s-4740-1 ↳raw-windows-account-644 ↳raw-windows-account-4740 ↳n-forwarded-cef-4740 ↳s-windows-event-4740 ↳wls-4740 ↳mcafee-siem-4740 ↳s-xml-4740 ↳json-4740-1 ↳json-4740 ↳ad-json-4740 ↳l-4740 ↳wls-644 ↳emc-syslog-4740 ↳q-microsoft-4740 ↳s-4740-jp ↳syslog-json-4740 ↳ad-audit-4740 ↳cef-ad-fs-audit-516 ↳s-516
account-password-change ↳s-xml-4723 ↳syslog-json-4723 ↳cef-4723 ↳s-627 ↳raw-4723 ↳mcafee-siem-4723 ↳wls-4723 ↳json-4723 ↳nic-627 ↳emc-syslog-4723 ↳wls-627 ↳l-4723 ↳raw-627 ↳s-4723-jp ↳s-windows-event-4723 ↳s-windows-event-627 ↳json-4723-1 ↳json-4723-2 ↳ad-audit-4723
account-password-reset ↳s-xml-4724 ↳syslog-json-4724 ↳cef-4724 ↳ad-json-4724 ↳wls-4724 ↳sk4-json-4724 ↳mcafee-siem-4724 ↳q-628 ↳n-forwarded-cef-4724 ↳raw-4724 ↳json-4724 ↳raw-628 ↳s-windows-event-4724 ↳l-4724 ↳s-4724-jp ↳json-4724-1 ↳json-4724-2 ↳ad-audit-4724
account-switch ↳raw-552 ↳s-windows-event-552 ↳q-microsoft-4648 ↳json-4648-1 ↳n-forwarded-cef-4648 ↳n-forwarded-cef-552 ↳xml-4648 ↳json-4648 ↳json-4648-2 ↳emc-syslog-4648 ↳s-windows-event-4648 ↳s-4648-jp ↳exalms-552 ↳raw-4648-2 ↳syslog-4648 ↳cef-4648 ↳raw-4648-3 ↳s-windows-4648 ↳raw-4648-4 ↳cef-snare-552 ↳raw-4648-5 ↳mcafee-siem-4648 ↳raw-4648 ↳cef-snare-4648 ↳raw-4648-1 ↳windows-events-4648
account-unlocked ↳json-4767 ↳syslog-json-4767 ↳l-4767 ↳xml-4767 ↳ad-json-4767 ↳sk4-json-4767 ↳wazuh-4767 ↳raw-4767 ↳ad-audit-4767
app-login ↳wazuh-sql-login ↳azure-app-logon ↳azure-app-logon-2 ↳azure-app-logon-3
audit-log-clear ↳cef-1102 ↳raw-1102 ↳s-xml-1102 ↳s-517 ↳xml-1102 ↳xml-104 ↳snare-517 ↳s-1102 ↳xml-1102-1 ↳q-1102 ↳s-windows-event-1102 ↳snare-1102 ↳raw-104
audit-policy-change ↳s-4719-1 ↳q-microsoft-4719 ↳cef-snare-4719 ↳xml-4719 ↳s-612 ↳s-windows-event-4719 ↳raw-4719 ↳snare-4719 ↳json-4719 ↳s-4719 ↳snare-612 ↳exalms-4719
authentication-failed ↳q-adfs-auth-failed-2 ↳q-adfs-auth-failed ↳q-adfs-auth-failed-1 ↳adfs-auth-failed ↳s-adfs-auth-failed ↳cef-ad-fs-audit-299 ↳cef-ad-fs-audit-501 ↳cef-ad-fs-audit-500 ↳cef-ad-fs-audit-411 ↳cef-ad-fs-audit-413 ↳cef-azure-authentication ↳azure-app-auth-events ↳json-windows-auth ↳s-xml-1203 ↳s-xml-1203-1 ↳s-xml-1201-1
authentication-successful ↳adfs-500-auth-successful ↳q-adfs-auth-successful-1 ↳q-adfs-auth-successful ↳adfs-299-auth-successful ↳cef-ad-fs-audit-299 ↳cef-ad-fs-audit-501 ↳cef-ad-fs-audit-500 ↳adfs-501-auth-successful ↳cef-azure-authentication ↳azure-app-auth-events ↳json-windows-auth ↳s-xml-1202 ↳s-xml-1200 ↳s-xml-1200-1 ↳s-xml-1202-1
failed-app-login ↳wazuh-sql-login ↳azure-app-logon ↳azure-app-logon-2 ↳azure-app-logon-3
failed-logon ↳cef-4776 ↳raw-4776 ↳json-4768-3 ↳cef-snare-680 ↳raw-4771 ↳wazuh-4776 ↳xml-4768 ↳s-windows-4776 ↳cef-4771 ↳s-windows-4771 ↳xml-4769 ↳s-4771-jp ↳cef-windows-4771 ↳syslog-4769-ch ↳cef-windows-4776 ↳emc-syslog-4768 ↳json-4768-1 ↳json-4768-2 ↳q-680 ↳raw-680 ↳wls-4768 ↳wls-4769 ↳raw-4769 ↳raw-4768 ↳s-4768-jp ↳logstash-4769 ↳json-4776-1 ↳logstash-4768 ↳windows-events-4769 ↳s-680 ↳json-4776-2 ↳wls-675 ↳json-4769-2 ↳syslog-4768-ch ↳raw-4769-1 ↳wls-4776 ↳exalms-680 ↳wls-4771 ↳r-nic-4771 ↳raw-4769-5 ↳s-673 ↳n-forwarded-cef-680 ↳raw-4769-4 ↳raw-4769-3 ↳s-675 ↳raw-4769-2 ↳raw-4769-7 ↳raw-4769-6 ↳json-4769-1 ↳s-672 ↳ad-audit-4769 ↳evntslog-672 ↳evntslog-675 ↳q-675 ↳syslog-4776-ch ↳q-672 ↳cef-snare-4769 ↳q-673 ↳extrahop-4771 ↳raw-4768-2 ↳evntslog-680 ↳raw-4768-1 ↳raw-4768-5 ↳raw-4768-4 ↳greenbay-4776 ↳raw-4768-3 ↳s-4769-jp ↳cef-673 ↳cef-672 ↳extrahop-4768 ↳extrahop-4769 ↳n-forwarded-cef-4776 ↳raw-4776-1 ↳syslog-4776-multiline ↳mcafee-siem-4768 ↳raw-4776-5 ↳mcafee-siem-4769 ↳raw-4776-4 ↳raw-4776-3 ↳raw-4776-2 ↳mcafee-siem-4776 ↳mcafee-siem-4771 ↳n-forwarded-cef-4771 ↳raw-675 ↳raw-672 ↳raw-673 ↳xml-4769-1 ↳windows-events-4776 ↳n-forwarded-cef-4769 ↳n-forwarded-cef-4768 ↳u-680 ↳json-4768 ↳json-4769 ↳windows-4768-1 ↳s-xml-4771 ↳exalms-4776 ↳cef-4768 ↳raw-4771-2 ↳cef-4769 ↳s-4776-jp ↳json-xml-4771 ↳xml-4776 ↳json-4771 ↳cef-windows-4769 ↳cef-windows-4768 ↳json-xml-4769 ↳json-xml-4768 ↳json-4776 ↳s-4625-jp ↳cef-4625 ↳s-windows-4625 ↳exalms-4625 ↳syslog-4625-ch ↳rs-4625 ↳s-windows-event-534 ↳wls-4625 ↳xml-4625 ↳wazuh-4625 ↳xml-4625-1 ↳json-4625-1 ↳mcafee-siem-4625 ↳n-forwarded-cef-4625 ↳json-4625-2 ↳raw-4625 ↳json-4625 ↳spanish-raw-4625 ↳emc-syslog-4625 ↳raw-failed-logon-2003 ↳s-windows-event-4625 ↳cef-windows-4625 ↳n-forwarded-cef-failed-logon-2003 ↳raw-4625-1 ↳ad-audit-json-4771 ↳ad-audit-4771 ↳ad-audit-4625 ↳json-windows-events-netlogon ↳raw-5805 ↳xml-4825 ↳xml-1310
failed-vpn-login ↳json-windows-vpn-login
kerberos-logon ↳raw-672 ↳json-4768-3 ↳syslog-4768-ch ↳xml-4768 ↳raw-4768-2 ↳n-forwarded-cef-4768 ↳raw-4768-1 ↳raw-4768-5 ↳json-4768 ↳raw-4768-4 ↳raw-4768-3 ↳emc-syslog-4768 ↳windows-4768-1 ↳json-4768-1 ↳cef-672 ↳json-4768-2 ↳s-672 ↳extrahop-4768 ↳cef-4768 ↳evntslog-672 ↳wls-4768 ↳mcafee-siem-4768 ↳raw-4768 ↳s-4768-jp ↳q-672 ↳logstash-4768 ↳cef-windows-4768 ↳json-xml-4768 ↳ad-audit-4768 ↳ad-audit-json-4768
local-logon ↳s-4624-jp ↳rs-4624 ↳xml-4624 ↳xml-4624-1 ↳json-4624-2 ↳n-forwarded-cef-4624 ↳json-4624-1 ↳json-4624 ↳evntslog-528 ↳nic-528 ↳emc-syslog-4624 ↳s-windows-event-528 ↳s-windows-event-4624 ↳raw-4624-7 ↳raw-4624-6 ↳raw-4624-5 ↳raw-4624-4 ↳windows-events-4624 ↳n-forwarded-cef-528 ↳raw-4624-9 ↳cef-528 ↳cef-4624 ↳raw-4624-8 ↳wazuh-4624 ↳r-nic-528 ↳raw-4624 ↳mcafee-siem-4624 ↳wls-4624 ↳raw-4624-10 ↳cef-windows-4624 ↳raw-528 ↳logstash-4624 ↳cef-snare-4624 ↳raw-4624-3 ↳raw-4624-2 ↳raw-4624-1 ↳s-4624-jp ↳rs-4624 ↳xml-4624 ↳xml-4624-1 ↳json-4624-2 ↳n-forwarded-cef-4624 ↳json-4624-1 ↳json-4624 ↳evntslog-528 ↳emc-syslog-4624 ↳s-windows-event-528 ↳s-windows-event-4624 ↳raw-4624-7 ↳raw-4624-6 ↳raw-4624-5 ↳raw-4624-4 ↳windows-events-4624 ↳n-forwarded-cef-528 ↳raw-4624-9 ↳cef-4624 ↳cef-528 ↳raw-4624-8 ↳wazuh-4624 ↳r-nic-528 ↳raw-4624 ↳mcafee-siem-4624 ↳wls-4624 ↳raw-4624-10 ↳cef-windows-4624 ↳raw-528 ↳logstash-4624 ↳cef-snare-4624 ↳raw-4624-3 ↳raw-4624-2 ↳raw-4624-1 ↳windows-rdp-login
member-added ↳json-member-added-2008 ↳wls-member-added-2008-notype ↳emc-syslog-member-added-2008 ↳s-member-added-2008-jp ↳n-forwarded-cef-member-added-2008 ↳sk4-json-member-added-2008 ↳ad-json-member-added-2008 ↳raw-member-added-2003 ↳s-member-added-2003 ↳json-4728 ↳s-member-added-2008 ↳snare-cef-member-added-2008 ↳syslog-json-member-added-2008 ↳u-member-added-2008 ↳raw-member-added-2008 ↳l-member-added-2008 ↳cef-windows-member-added-2003 ↳cef-member-added-2008 ↳q-member-added-2008 ↳cef-member-added-2003 ↳windows-xml-member-added-2008 ↳jp-member-added-3 ↳jp-member-added-1 ↳jp-member-added-2 ↳s-windows-event-636 ↳evntslog-member-added-2003 ↳s-windows-event-4728 ↳s-xml-windows-member-3 ↳s-xml-windows-member-1 ↳s-xml-windows-member-2 ↳s-xml-windows-member-4756 ↳s-windows-event-4732 ↳ad-audit-4728
member-removed ↳nic-member-removed-2008 ↳s-member-removed-2003 ↳s-windows-event-633 ↳ad-json-member-removed-2008 ↳s-windows-event-4729 ↳cef-member-removed-2008 ↳s-member-removed-2008 ↳raw-member-removed-2008 ↳raw-member-removed-2008-2 ↳sk4-json-member-removed-2008 ↳raw-member-removed-2008-3 ↳raw-member-removed-2008-1 ↳q-member-removed-2003 ↳raw-member-removed-2003 ↳n-forwarded-cef-member-removed-2008 ↳cef-windows-member-removed-2003 ↳u-member-removed-2008 ↳json-4729 ↳xml-member-removed-2008 ↳s-windows-event-637 ↳s-windows-event-4733 ↳nic-member-removed-2003 ↳q-member-removed-2008 ↳json-member-removed ↳s-xml-windows-member-4757 ↳s-xml-windows-member-4 ↳s-xml-windows-member-5 ↳s-xml-windows-member-6 ↳ad-audit-4729
nac-logon ↳q-6272 ↳json-6272 ↳json-6272-1 ↳xml-6272 ↳xml-nps-logon
ntlm-logon ↳cef-4776 ↳raw-4776 ↳cef-snare-680 ↳wazuh-4776 ↳s-windows-4776 ↳evntslog-680 ↳wls-4776 ↳exalms-680 ↳u-680 ↳n-forwarded-cef-680 ↳greenbay-4776 ↳cef-windows-4776 ↳q-680 ↳exalms-4776 ↳s-4776-jp ↳raw-680 ↳n-forwarded-cef-4776 ↳raw-4776-1 ↳syslog-4776-multiline ↳xml-4776 ↳raw-4776-5 ↳raw-4776-4 ↳raw-4776-3 ↳raw-4776-2 ↳mcafee-siem-4776 ↳syslog-4776-ch ↳emc-syslog-4776 ↳json-4776-1 ↳s-680 ↳json-4776-2 ↳json-4776 ↳xml-windows-ntlm-logon-8001 ↳xml-windows-ntlm-logon-8003 ↳xml-windows-ntlm-logon-8002
privileged-access ↳l-4673 ↳l-4672 ↳s-windows-event-576 ↳s-4672-jp ↳raw-4673 ↳raw-4672 ↳snare-576 ↳snare-577 ↳cef-4672 ↳wazuh-4673 ↳windows-events-4672 ↳s-windows-4672 ↳cef-4673 ↳s-windows-4673 ↳cef-windows-4673 ↳raw-4672-2 ↳raw-4673-1 ↳s-576 ↳raw-4672-1 ↳raw-4673-2 ↳raw-4672-3 ↳wls-windows-privileged-access ↳cef-576 ↳cef-snare-4673 ↳exalms-576 ↳xml-4672 ↳json-4672-1 ↳json-4673-1 ↳json-4672-2 ↳cef-snare-576 ↳xml-4673 ↳json-xml-4673 ↳cef-snare-577 ↳json-4673-2 ↳spanish-raw-4672 ↳s-windows-event-4672 ↳s-windows-event-4673 ↳mcafee-siem-4672 ↳n-forwarded-cef-4673 ↳n-forwarded-cef-4672 ↳greenbay-privileged-access ↳json-4672 ↳json-4673 ↳emc-syslog-4673 ↳emc-syslog-4672
privileged-object-access ↳s-4674-jp ↳raw-4674 ↳cef-4674 ↳exalms-4674 ↳xml-4674 ↳s-windows-event-578 ↳snare-578 ↳windows-xml-4674 ↳cef-snare-578 ↳s-windows-4674 ↳xml-4674-1 ↳s-windows-event-4674 ↳cef-windows-4674 ↳raw-4674-5 ↳raw-4674-2 ↳json-4674 ↳l-4674 ↳emc-syslog-4674 ↳raw-4674-1 ↳wls-windows-privileged-access ↳raw-4674-4 ↳raw-4674-3
remote-access ↳json-4769-2 ↳raw-673 ↳xml-4769-1 ↳n-forwarded-cef-4769 ↳raw-4769-1 ↳xml-4769 ↳raw-4769-5 ↳s-673 ↳raw-4769-4 ↳raw-4769-3 ↳json-4769 ↳raw-4769-2 ↳emc-syslog-4769 ↳syslog-4769-ch ↳raw-4769-7 ↳s-4769-jp ↳raw-4769-6 ↳cef-673 ↳json-4769-1 ↳ad-audit-4769 ↳extrahop-4769 ↳cef-4769 ↳evntslog-673 ↳wls-4769 ↳mcafee-siem-4769 ↳raw-4769 ↳logstash-4769 ↳cef-snare-4769 ↳cef-windows-4769 ↳q-673 ↳windows-events-4769 ↳json-xml-4769 ↳raw-674 ↳nic-4770 ↳s-4770-jp ↳raw-4770 ↳n-forwarded-cef-4770 ↳raw-4770-1 ↳mcafee-siem-4770 ↳json-xml-4770 ↳json-4770 ↳extrahop-4770 ↳s-xml-4770 ↳cef-4770 ↳s-4624-jp ↳exalms-540 ↳rs-4624 ↳xml-4624 ↳xml-4624-1 ↳json-4624-2 ↳n-forwarded-cef-4624 ↳json-4624-1 ↳json-4624 ↳evntslog-528 ↳nic-528 ↳emc-syslog-4624 ↳s-windows-event-528 ↳s-windows-event-4624 ↳raw-4624-7 ↳r-nic-540 ↳raw-4624-6 ↳raw-540 ↳s-windows-event-540 ↳raw-4624-5 ↳raw-4624-4 ↳windows-events-4624 ↳n-forwarded-cef-528 ↳raw-4624-9 ↳cef-528 ↳cef-4624 ↳raw-4624-8 ↳wazuh-4624 ↳r-nic-528 ↳raw-4624 ↳n-forwarded-cef-540 ↳mcafee-siem-4624 ↳wls-4624 ↳raw-4624-10 ↳cef-windows-4624 ↳raw-528 ↳logstash-4624 ↳cef-snare-4624 ↳raw-4624-3 ↳cef-540 ↳raw-4624-2 ↳raw-4624-1 ↳s-4624-jp ↳exalms-540 ↳rs-4624 ↳xml-4624 ↳xml-4624-1 ↳json-4624-2 ↳n-forwarded-cef-4624 ↳json-4624-1 ↳json-4624 ↳evntslog-528 ↳nic-528 ↳emc-syslog-4624 ↳s-windows-event-528 ↳s-windows-event-4624 ↳ad-audit-json-4624 ↳raw-4624-7 ↳r-nic-540 ↳raw-4624-6 ↳raw-540 ↳raw-4624-5 ↳s-windows-event-540 ↳raw-4624-4 ↳windows-events-4624 ↳n-forwarded-cef-528 ↳raw-4624-9 ↳cef-528 ↳cef-4624 ↳raw-4624-8 ↳wazuh-4624 ↳r-nic-528 ↳raw-4624 ↳n-forwarded-cef-540 ↳mcafee-siem-4624 ↳wls-4624 ↳raw-4624-10 ↳cef-windows-4624 ↳raw-528 ↳logstash-4624 ↳cef-snare-4624 ↳raw-4624-3 ↳cef-540 ↳raw-4624-2 ↳raw-4624-1 ↳s-4624-jp ↳rs-4624 ↳xml-4624 ↳xml-4624-1 ↳json-4624-2 ↳n-forwarded-cef-4624 ↳json-4624-1 ↳json-4624 ↳evntslog-528 ↳nic-528 ↳emc-syslog-4624 ↳s-windows-event-528 ↳s-windows-event-4624 ↳raw-4624-7 ↳raw-4624-6 ↳raw-4624-5 ↳raw-4624-4 ↳windows-events-4624 ↳n-forwarded-cef-528 ↳raw-4624-9 ↳cef-528 ↳cef-4624 ↳raw-4624-8 ↳wazuh-4624 ↳r-nic-528 ↳raw-4624 ↳mcafee-siem-4624 ↳raw-4624-10 ↳cef-windows-4624 ↳raw-528 ↳logstash-4624 ↳cef-snare-4624 ↳raw-4624-3 ↳raw-4624-2 ↳raw-4624-1 ↳s-4624-jp ↳rs-4624 ↳xml-4624 ↳xml-4624-1 ↳json-4624-2 ↳n-forwarded-cef-4624 ↳json-4624-1 ↳json-4624 ↳evntslog-528 ↳nic-528 ↳emc-syslog-4624 ↳s-windows-event-528 ↳s-windows-event-4624 ↳raw-4624-7 ↳raw-4624-6 ↳raw-4624-5 ↳raw-4624-4 ↳windows-events-4624 ↳n-forwarded-cef-528 ↳raw-4624-9 ↳cef-528 ↳cef-4624 ↳raw-4624-8 ↳wazuh-4624 ↳r-nic-528 ↳raw-4624 ↳mcafee-siem-4624 ↳wls-4624 ↳raw-4624-10 ↳cef-windows-4624 ↳raw-528 ↳logstash-4624 ↳cef-snare-4624 ↳raw-4624-3 ↳raw-4624-2 ↳raw-4624-1 ↳raw-552 ↳s-windows-event-552 ↳json-4648-1 ↳n-forwarded-cef-4648 ↳n-forwarded-cef-552 ↳xml-4648 ↳json-4648 ↳json-4648-2 ↳emc-syslog-4648 ↳s-windows-event-4648 ↳s-4648-jp ↳exalms-552 ↳raw-4648-2 ↳syslog-4648 ↳cef-4648 ↳raw-4648-3 ↳s-windows-4648 ↳raw-4648-4 ↳cef-snare-552 ↳raw-4648-5 ↳mcafee-siem-4648 ↳raw-4648 ↳cef-snare-4648 ↳raw-4648-1 ↳windows-events-4648
remote-logon ↳raw-674 ↳nic-4770 ↳s-4770-jp ↳raw-4770 ↳n-forwarded-cef-4770 ↳raw-4770-1 ↳mcafee-siem-4770 ↳json-xml-4770 ↳json-4770 ↳extrahop-4770 ↳s-xml-4770 ↳cef-4770 ↳s-4624-jp ↳rs-4624 ↳xml-4624 ↳xml-4624-1 ↳json-4624-2 ↳n-forwarded-cef-4624 ↳json-4624-1 ↳json-4624 ↳evntslog-528 ↳nic-528 ↳emc-syslog-4624 ↳s-windows-event-528 ↳s-windows-event-4624 ↳raw-4624-7 ↳raw-4624-6 ↳raw-4624-5 ↳raw-4624-4 ↳windows-events-4624 ↳n-forwarded-cef-528 ↳raw-4624-9 ↳cef-528 ↳cef-4624 ↳raw-4624-8 ↳wazuh-4624 ↳r-nic-528 ↳raw-4624 ↳mcafee-siem-4624 ↳wls-4624 ↳raw-4624-10 ↳cef-windows-4624 ↳raw-528 ↳logstash-4624 ↳cef-snare-4624 ↳raw-4624-3 ↳raw-4624-2 ↳raw-4624-1 ↳s-4624-jp ↳rs-4624 ↳xml-4624 ↳xml-4624-1 ↳json-4624-2 ↳n-forwarded-cef-4624 ↳json-4624-1 ↳json-4624 ↳evntslog-528 ↳nic-528 ↳emc-syslog-4624 ↳s-windows-event-528 ↳s-windows-event-4624 ↳raw-4624-7 ↳raw-4624-6 ↳raw-4624-5 ↳raw-4624-4 ↳windows-events-4624 ↳n-forwarded-cef-528 ↳raw-4624-9 ↳cef-528 ↳cef-4624 ↳raw-4624-8 ↳wazuh-4624 ↳r-nic-528 ↳raw-4624 ↳mcafee-siem-4624 ↳wls-4624 ↳raw-4624-10 ↳cef-windows-4624 ↳raw-528 ↳logstash-4624 ↳cef-snare-4624 ↳raw-4624-3 ↳raw-4624-2 ↳raw-4624-1 ↳json-4778 ↳xml-4778 ↳raw-4778 ↳s-windows-event-4778 ↳raw-4778-1 ↳mcafee-siem-4778 ↳raw-552 ↳s-windows-event-552 ↳json-4648-1 ↳n-forwarded-cef-4648 ↳n-forwarded-cef-552 ↳xml-4648 ↳json-4648 ↳json-4648-2 ↳emc-syslog-4648 ↳s-windows-event-4648 ↳s-4648-jp ↳exalms-552 ↳raw-4648-2 ↳syslog-4648 ↳cef-4648 ↳raw-4648-3 ↳s-windows-4648 ↳raw-4648-4 ↳cef-snare-552 ↳raw-4648-5 ↳mcafee-siem-4648 ↳raw-4648 ↳cef-snare-4648 ↳raw-4648-1 ↳windows-events-4648 ↳ad-audit-4778 ↳windows-rdp-login ↳raw-1149-1 ↳xml-1149 ↳raw-1149
vpn-login ↳json-windows-vpn-login ↳s-xml-windows-member-11 ↳s-xml-windows-member-9 ↳s-xml-windows-member-13 ↳s-xml-windows-member-7
vpn-logout ↳s-xml-windows-member-10 ↳s-xml-windows-member-14 ↳s-xml-windows-member-8
workstation-unlocked ↳s-4624-jp ↳rs-4624 ↳xml-4624 ↳xml-4624-1 ↳json-4624-2 ↳n-forwarded-cef-4624 ↳json-4624-1 ↳json-4624 ↳evntslog-528 ↳nic-528 ↳emc-syslog-4624 ↳s-windows-event-528 ↳s-windows-event-4624 ↳raw-4624-7 ↳raw-4624-6 ↳raw-4624-5 ↳raw-4624-4 ↳windows-events-4624 ↳n-forwarded-cef-528 ↳raw-4624-9 ↳cef-528 ↳cef-4624 ↳raw-4624-8 ↳wazuh-4624 ↳r-nic-528 ↳raw-4624 ↳mcafee-siem-4624 ↳raw-4624-10 ↳cef-windows-4624 ↳raw-528 ↳logstash-4624 ↳cef-snare-4624 ↳raw-4624-3 ↳raw-4624-2 ↳raw-4624-1 ↳s-4624-jp ↳rs-4624 ↳xml-4624 ↳xml-4624-1 ↳json-4624-2 ↳n-forwarded-cef-4624 ↳json-4624-1 ↳json-4624 ↳evntslog-528 ↳nic-528 ↳emc-syslog-4624 ↳s-windows-event-528 ↳s-windows-event-4624 ↳raw-4624-7 ↳raw-4624-6 ↳raw-4624-5 ↳raw-4624-4 ↳windows-events-4624 ↳n-forwarded-cef-528 ↳raw-4624-9 ↳cef-528 ↳cef-4624 ↳raw-4624-8 ↳wazuh-4624 ↳r-nic-528 ↳raw-4624 ↳mcafee-siem-4624 ↳raw-4624-10 ↳cef-windows-4624 ↳raw-528 ↳logstash-4624 ↳cef-snare-4624 ↳raw-4624-3 ↳raw-4624-2 ↳raw-4624-1 ↳s-4801 ↳cef-4801 ↳s-4801-1 ↳q-4801 ↳sk4-json-4801 ↳xml-4801 ↳s-windows-event-4801 ↳raw-4801 ↳ad-audit-4801
| T1021 - Remote Services T1078 - Valid Accounts T1078.002 - T1078.002 T1078.003 - Valid Accounts: Local Accounts T1110 - Brute Force T1133 - External Remote Services
| |
| Account Manipulation | account-creation ↳syslog-json-4720 ↳cef-4720 ↳cef-windows-account-4720 ↳sk4-json-4720 ↳s-xml-4720 ↳raw-windows-account-624 ↳wls-4720 ↳s-4720-jp ↳mcafee-siem-4720 ↳windows-xml-4720 ↳raw-windows-account-4720 ↳cef-624 ↳ad-json-4720 ↳json-4720-1 ↳json-4720 ↳l-4720 ↳ad-audit-4720
account-deleted ↳s-xml-4726 ↳raw-windows-account-4726 ↳json-4726 ↳s-4726-jp ↳nxlog-json-4726 ↳wls-4726 ↳mcafee-siem-4726 ↳raw-windows-account-630 ↳ad-audit-4726 ↳raw-4743 ↳raw-4743-1 ↳ad-audit-4743 ↳raw-4743-2
account-password-change ↳s-xml-4723 ↳syslog-json-4723 ↳cef-4723 ↳s-627 ↳raw-4723 ↳mcafee-siem-4723 ↳wls-4723 ↳json-4723 ↳nic-627 ↳emc-syslog-4723 ↳wls-627 ↳l-4723 ↳raw-627 ↳s-4723-jp ↳s-windows-event-4723 ↳s-windows-event-627 ↳json-4723-1 ↳json-4723-2 ↳ad-audit-4723
account-password-reset ↳s-xml-4724 ↳syslog-json-4724 ↳cef-4724 ↳ad-json-4724 ↳wls-4724 ↳sk4-json-4724 ↳mcafee-siem-4724 ↳q-628 ↳n-forwarded-cef-4724 ↳raw-4724 ↳json-4724 ↳raw-628 ↳s-windows-event-4724 ↳l-4724 ↳s-4724-jp ↳json-4724-1 ↳json-4724-2 ↳ad-audit-4724
ds-access ↳cef-snare-5136 ↳xml-5137 ↳xml-5138 ↳sk4-json-5137 ↳xml-5136 ↳raw-4738 ↳s-5137 ↳xml-5139 ↳n-forwarded-cef-5136 ↳nic-5141 ↳s-5141-1 ↳mcafee-siem-5137 ↳mcafee-siem-5136 ↳s-windows-event-4780 ↳json-xml-5141 ↳nic-5136 ↳wazuh-4738 ↳nic-5137 ↳json-5136 ↳ad-audit-5139 ↳raw-5138 ↳json-4738-1 ↳raw-5139 ↳raw-5136 ↳json-4738-2 ↳s-5141 ↳raw-5137 ↳cef-5136 ↳xml-4738 ↳cef-windows-ds-access-5137 ↳json-4738 ↳r-syslog-5136 ↳raw-5141 ↳mcafee-siem-5141 ↳json-5136-1 ↳xml-5141 ↳sk4-json-5141 ↳jp-4662 ↳exalms-4742 ↳raw-4742 ↳xml-4742-jp ↳sk4-json-4662 ↳json-4662-1 ↳raw-4662 ↳xml-4662 ↳exalms-4662 ↳raw-4662-1 ↳n-forwarded-cef-4662 ↳windows-xml-4742 ↳s-4662 ↳cef-windows-4742 ↳xml-4662-jp ↳json-4662 ↳q-4662 ↳raw-4662-2 ↳raw-4662-3 ↳ad-audit-5141 ↳ad-audit-4738 ↳ad-audit-5136 ↳ad-audit-4662 ↳ad-audit-5137 ↳ad-audit-4742 ↳raw-4929 ↳raw-4928
member-added ↳json-member-added-2008 ↳wls-member-added-2008-notype ↳emc-syslog-member-added-2008 ↳s-member-added-2008-jp ↳n-forwarded-cef-member-added-2008 ↳sk4-json-member-added-2008 ↳ad-json-member-added-2008 ↳raw-member-added-2003 ↳s-member-added-2003 ↳json-4728 ↳s-member-added-2008 ↳snare-cef-member-added-2008 ↳syslog-json-member-added-2008 ↳u-member-added-2008 ↳raw-member-added-2008 ↳l-member-added-2008 ↳cef-windows-member-added-2003 ↳cef-member-added-2008 ↳q-member-added-2008 ↳cef-member-added-2003 ↳windows-xml-member-added-2008 ↳jp-member-added-3 ↳jp-member-added-1 ↳jp-member-added-2 ↳s-windows-event-636 ↳evntslog-member-added-2003 ↳s-windows-event-4728 ↳s-xml-windows-member-3 ↳s-xml-windows-member-1 ↳s-xml-windows-member-2 ↳s-xml-windows-member-4756 ↳s-windows-event-4732 ↳ad-audit-4728
member-removed ↳nic-member-removed-2008 ↳s-member-removed-2003 ↳s-windows-event-633 ↳ad-json-member-removed-2008 ↳s-windows-event-4729 ↳cef-member-removed-2008 ↳s-member-removed-2008 ↳raw-member-removed-2008 ↳raw-member-removed-2008-2 ↳sk4-json-member-removed-2008 ↳raw-member-removed-2008-3 ↳raw-member-removed-2008-1 ↳q-member-removed-2003 ↳raw-member-removed-2003 ↳n-forwarded-cef-member-removed-2008 ↳cef-windows-member-removed-2003 ↳u-member-removed-2008 ↳json-4729 ↳xml-member-removed-2008 ↳s-windows-event-637 ↳s-windows-event-4733 ↳nic-member-removed-2003 ↳q-member-removed-2008 ↳json-member-removed ↳s-xml-windows-member-4757 ↳s-xml-windows-member-4 ↳s-xml-windows-member-5 ↳s-xml-windows-member-6 ↳ad-audit-4729
process-created ↳mcafee-siem-process-created ↳cef-4688 ↳u-4688 ↳cef-snare-4688 ↳n-forwarded-cef-4688 ↳json-process-created ↳s-windows-4688 ↳l-4688-v2 ↳xml-4688 ↳wls-4688 ↳raw-process-created-1 ↳cef-snare-process-created ↳json-process-created-1 ↳snare-592 ↳json-process-created-2 ↳s-windows-process-created ↳nic-4688 ↳spanish-raw-4688 ↳emc-syslog-4688 ↳raw-process-created ↳s-4688-jp ↳s-592 ↳s-windows-event-4688 ↳cef-powershell-300 ↳raw-4104 ↳cef-powershell-600 ↳xml-powershell-4104 ↳powershell-800-syslog ↳windows-powershell-800 ↳powershell-process-created ↳powershell-800 ↳win-powershell-command ↳powershell-process-created-1 ↳powershell-process-created-2 ↳cef-windows-4104 ↳raw-powershell-600 ↳windows-xml-powershell-process-created ↳powershell-800-syslog-1 ↳windows-xml-powershell-process-created-2 ↳cef-powershell-4104 ↳s-windows-event-601 ↳windows-xml-powershell-process-created-1 ↳cef-powershell-4102 ↳powershell-4104 ↳json-4104 ↳windows-xml-powershell-800 ↳ad-audit-4688 ↳xml-5861 ↳cef-azure-process-created
vpn-logout ↳s-xml-windows-member-10 ↳s-xml-windows-member-14 ↳s-xml-windows-member-8
| T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1136.002 - T1136.002 T1207 - Rogue Domain Controller T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1484 - Group Policy Modification T1531 - Account Access Removal T1559.002 - T1559.002
| |
| Physical Security | vpn-login ↳json-windows-vpn-login ↳s-xml-windows-member-11 ↳s-xml-windows-member-9 ↳s-xml-windows-member-13 ↳s-xml-windows-member-7
| T1133 - External Remote Services
| |
| Next Page -->> | | | |