Regex ID | Rule Name | Rule Type | Common Event | Classification |
---|
1000293 | EVID 4624 : Logon Events | Base Rule | Authentication Activity | Authentication Success |
General Authentication Failure | Sub Rule | Authentication Failure Activity | Authentication Failure |
EVID 4624 : Authentication Success | Sub Rule | Authentication Activity | Authentication Success |
EVID 4624 : Anonymous Logon Type 11 | Sub Rule | User Logon | Authentication Success |
EVID 540 : System Logon Type 8 | Sub Rule | Computer Logon | Authentication Success |
EVID 540 : System Logon Type 5 | Sub Rule | Service Logon | Authentication Success |
EVID 540 : System Logon Type 7 | Sub Rule | Computer Logon | Authentication Success |
EVID 540 : Anonymous Logon Type 11 | Sub Rule | User Logon | Authentication Success |
EVID 540 : System Logon Type 11 | Sub Rule | Computer Logon | Authentication Success |
EVID 540 : System Logon Type 4 | Sub Rule | Computer Logon | Authentication Success |
EVID 540 : System Logon Type 10 | Sub Rule | Computer Logon | Authentication Success |
EVID 540 : Anonymous Logon Type 8 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : Anonymous Logon Type 2 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : Anonymous Logon Type 5 | Sub Rule | Service Logon | Authentication Success |
EVID 540 : Anonymous Logon Type 10 | Sub Rule | User Logon | Authentication Success |
EVID 540 : System Logon Type 3 | Sub Rule | Computer Logon | Authentication Success |
EVID 540 : Anonymous Logon Type 9 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : Anonymous Logon Type 4 | Sub Rule | User Logon | Authentication Success |
EVID 540 : Anonymous Logon Type 8 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : System Logon Type 3 | Sub Rule | Computer Logon | Authentication Success |
EVID 4624 : Anonymous Logon Type 7 | Sub Rule | User Logon | Authentication Success |
EVID 540 : Anonymous Logon Type 7 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : Anonymous Logon Type 9 | Sub Rule | User Logon | Authentication Success |
EVID 540 : System Logon Type 2 | Sub Rule | Computer Logon | Authentication Success |
EVID 540 : Anonymous Logon Type 5 | Sub Rule | Service Logon | Authentication Success |
EVID 4624 : Anonymous Logon Type 8 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : System Logon Type 2 | Sub Rule | Computer Logon | Authentication Success |
EVID 540 : Anonymous Logon Type 4 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : System Logon Type 7 | Sub Rule | Computer Logon | Authentication Success |
EVID 540 : System Logon Type 9 | Sub Rule | Computer Logon | Authentication Success |
EVID 4624 : Anonymous Logon Type 10 | Sub Rule | User Logon | Authentication Success |
EVID 540 : Anonymous Logon Type 2 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : System Logon Type 5 | Sub Rule | Service Logon | Authentication Success |
EVID 4624 : Anonymous Logon Type 11 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : Anonymous Logon Type 4 | Sub Rule | User Logon | Authentication Success |
EVID 540 : Anonymous Logon Type 4 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : System Logon Type 4 | Sub Rule | Computer Logon | Authentication Success |
EVID 4624 : Anonymous Logon Type 7 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : System Logon Type 9 | Sub Rule | Computer Logon | Authentication Success |
EVID 4624 : Anonymous Logon Type 2 | Sub Rule | User Logon | Authentication Success |
EVID 540 : Anonymous Logon Type 9 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : Anonymous Logon Type 5 | Sub Rule | Service Logon | Authentication Success |
EVID 540 : Anonymous Logon Type 5 | Sub Rule | Service Logon | Authentication Success |
EVID 4624 : System Logon Type 8 | Sub Rule | Computer Logon | Authentication Success |
EVID 540 : Anonymous Logon Type 7 | Sub Rule | User Logon | Authentication Success |
EVID 540 : Anonymous Logon Type 10 | Sub Rule | User Logon | Authentication Success |
EVID 540 : Anonymous Logon Type 11 | Sub Rule | User Logon | Authentication Success |
EVID 540 : Anonymous Logon Type 2 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : Anonymous Logon Type 9 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : System Logon Type 11 | Sub Rule | Computer Logon | Authentication Success |
EVID 4624 : System Logon Type 10 | Sub Rule | Computer Logon | Authentication Success |
EVID 4624 : Anonymous Logon Type 8 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : Anonymous Logon Type 10 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : Administrator Logon Type 2 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : Administrator Logon Type 9 | Sub Rule | User Logon | Authentication Success |
EVID 540 : Administrator Logon Type 2 | Sub Rule | User Logon | Authentication Success |
EVID 540 : Administrator Logon Type 7 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : Administrator Logon Type 8 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : Administrator Logon Type 5 | Sub Rule | Service Logon | Authentication Success |
EVID 540 : Administrator Logon Type 5 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : Administrator Logon Type 7 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : Administrator Logon Type 4 | Sub Rule | User Logon | Authentication Success |
EVID 540 : Administrator Logon Type 4 | Sub Rule | User Logon | Authentication Success |
EVID 540 : Administrator Logon Type 9 | Sub Rule | User Logon | Authentication Success |
EVID 540 : Administrator Logon Type 11 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : Administrator Logon Type 11 | Sub Rule | User Logon | Authentication Success |
EVID 540 : Administrator Logon Type 10 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : Administrator Logon Type 10 | Sub Rule | User Logon | Authentication Success |
EVID 540 : Administrator Logon Type 8 | Sub Rule | User Logon | Authentication Success |
EVID 540 : User Logon Type 10 | Sub Rule | User Logon | Authentication Success |
EVID 540 : User Logon Type 11 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : User Logon Type 9 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : User Logon Type 8 | Sub Rule | User Logon | Authentication Success |
EVID 540 : User Logon Type 2 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : User Logon Type 5 | Sub Rule | Service Logon | Authentication Success |
EVID 4624 : User Logon Type 4 | Sub Rule | User Logon | Authentication Success |
EVID 540 : User Logon Type 7 | Sub Rule | User Logon | Authentication Success |
EVID 540 : User Logon Type 9 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : User Logon Type 10 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : User Logon Type 11 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : User Logon Type 7 | Sub Rule | User Logon | Authentication Success |
EVID 540 : User Logon Type 5 | Sub Rule | Service Logon | Authentication Success |
EVID 540 : User Logon Type 4 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : User Logon Type 2 | Sub Rule | User Logon | Authentication Success |
EVID 540 : User Logon Type 8 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : Anonymous Logon Type 3 | Sub Rule | Authentication Activity | Authentication Success |
EVID 540 : Administrator Logon Type 3 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : Administrator Logon Type 3 | Sub Rule | Authentication Activity | Authentication Success |
EVID 4624 : System Logon Type 3 | Sub Rule | Computer Logon | Authentication Success |
EVID 4624 : User Logon Type 3 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : Anonymous Logon Type 3 | Sub Rule | Authentication Activity | Authentication Success |
EVID 540 : Anonymous Logon Type 3 | Sub Rule | User Logon | Authentication Success |
EVID 540 : Anonymous Logon Type 3 | Sub Rule | User Logon | Authentication Success |
EVID 540 : System Logon Type 3 | Sub Rule | Computer Logon | Authentication Success |
EVID 540 : User Logon Type 3 | Sub Rule | User Logon | Authentication Success |
EVID 4624 : User Logon Type 3 | Sub Rule | User Logon | Authentication Success |