dfir-scripts / SecurityEventIDs

Security Event ID Template

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Microsoft Windows Security Audit Events

Reference and Visualization

Mapping of the Microsoft Spreadsheet that contains detailed information about event IDs in the Security.evtx.

EventIDs

Category

SubCategory

Minimum Operating System

Additionially there are mappings to relevant verbs identified in the description fields as well as key words fields in the message section:

Verbs

This site was written with Obsidian which includes some very useful graph visualization and search capabilities!

Resources

Microsoft Appendix L - Events to Monitor awesome-event-ids Ultimate Windows Security

About

Security Event ID Template


Languages

Language:HTML 100.0%