All Rules in category: Security Monitoring Management Pack

IDManagement Pack NameManagement Pack Version
Security.Monitoring.Collect.SMBv1ConnectionsSecurity.Monitoring1.0.7.1
Security.Monitoring.CollectionRule.CollectLAPSEventsSecurity.Monitoring1.0.7.1
Security.Monitoring.CollectLegacyTLSEventsSecurity.Monitoring1.0.7.1
Security.Monitoring.Event.4688.GenericCryptoRansomWareSecurity.Monitoring1.0.7.1
Security.Monitoring.Event.ByPassExecutionPolicySecurity.Monitoring1.0.7.1
Security.Monitoring.Event.InvokeEncodedCommandSecurity.Monitoring1.0.7.1
Security.Monitoring.Event.InvokeRemoteExpressionSecurity.Monitoring1.0.7.1
Security.Monitoring.Event.KillWindowsDefenderSecurity.Monitoring1.0.7.1
Security.Monitoring.Event.PowerShellRuninMemoryOnlySecurity.Monitoring1.0.7.1
Security.Monitoring.Event.RemoteRegSvr32Security.Monitoring1.0.7.1
Security.Monitoring.Event.SeDebugPrivilegeEscalationSecurity.Monitoring1.0.7.1
Security.Monitoring.Event.WMIPersistenceSecurity.Monitoring1.0.7.1
Security.Monitoring.Event.WMIRemote.DestinationSecurity.Monitoring1.0.7.1
Security.Monitoring.Event.WMIRemote.SourceSecurity.Monitoring1.0.7.1
Security.Monitoring.EventCollection.LanManSecurity.Monitoring1.0.7.1
Security.Monitoring.EventCollection.NTLMV1Security.Monitoring1.0.7.1
Security.Monitoring.EventCollection.WdigestAuthenticationSecurity.Monitoring1.0.7.1
Security.Monitoring.ExecutableRunFromUserWriteableDirectorySecurity.Monitoring1.0.7.1
Security.Monitoring.ExecutableRuninWriteableDirectoriesExtendedSecurity.Monitoring1.0.7.1
Security.Monitoring.ForwardedEvents.4688.GenericCryptoRansomWareSecurity.Monitoring1.0.7.1
Security.Monitoring.ForwardedEvents.ByPassExecutionPolicySecurity.Monitoring1.0.7.1
Security.Monitoring.ForwardedEvents.CollectLAPSEventsSecurity.Monitoring1.0.7.1
Security.Monitoring.ForwardedEvents.DebugEscalationSecurity.Monitoring1.0.7.1
Security.Monitoring.ForwardedEvents.ExecutableRunFromUserWriteableDirectorySecurity.Monitoring1.0.7.1
Security.Monitoring.ForwardedEvents.FindAVSignatureSecurity.Monitoring1.0.7.1
Security.Monitoring.ForwardedEvents.GetDLLLoadPathSecurity.Monitoring1.0.7.1
Security.Monitoring.ForwardedEvents.GetHTTPStatusSecurity.Monitoring1.0.7.1
Security.Monitoring.ForwardedEvents.GetKeystrokeSecurity.Monitoring1.0.7.1
Security.Monitoring.ForwardedEvents.InvokeDLLInjectionSecurity.Monitoring1.0.7.1
Security.Monitoring.ForwardedEvents.InvokeEncodedCommandSecurity.Monitoring1.0.7.1
Security.Monitoring.ForwardedEvents.InvokeMimikatzSecurity.Monitoring1.0.7.1
Security.Monitoring.ForwardedEvents.InvokeNinjaCopySecurity.Monitoring1.0.7.1
Security.Monitoring.ForwardedEvents.InvokePortScanSecurity.Monitoring1.0.7.1
Security.Monitoring.ForwardedEvents.InvokeRemoteExpressionSecurity.Monitoring1.0.7.1
Security.Monitoring.ForwardedEvents.InvokeShellCodeInUseSecurity.Monitoring1.0.7.1
Security.Monitoring.ForwardedEvents.KillWindowsDefenderSecurity.Monitoring1.0.7.1
Security.Monitoring.ForwardedEvents.PowerShellRuninMemoryOnlySecurity.Monitoring1.0.7.1
Security.Monitoring.ForwardedEvents.PowerShellStartHiddenProcessSecurity.Monitoring1.0.7.1
Security.Monitoring.ForwardedEvents.RemoteRegSvr32Security.Monitoring1.0.7.1
Security.Monitoring.PowerShellLog.FindAVSignatureSecurity.Monitoring1.0.7.1
Security.Monitoring.PowerShellLog.GetDLLLoadPathSecurity.Monitoring1.0.7.1
Security.Monitoring.PowerShellLog.GetHTTPStatusSecurity.Monitoring1.0.7.1
Security.Monitoring.PowerShellLog.GetKeystrokeSecurity.Monitoring1.0.7.1
Security.Monitoring.PowerShellLog.InvokeDLLInjectionSecurity.Monitoring1.0.7.1
Security.Monitoring.PowerShellLog.InvokeMimikatzInUseSecurity.Monitoring1.0.7.1
Security.Monitoring.PowerShellLog.InvokeNinjaCopySecurity.Monitoring1.0.7.1
Security.Monitoring.PowerShellLog.InvokePortScanSecurity.Monitoring1.0.7.1
Security.Monitoring.PowerShellLog.InvokeShellCodeInUseSecurity.Monitoring1.0.7.1
Security.Monitoring.PowerShellLog.PowerShellStartHiddenProcessSecurity.Monitoring1.0.7.1
Security.Monitoring.SecurityLogClearedv2Security.Monitoring1.0.7.1
Security.Monitoring.SecurityMonitoring.Event.DCOUModifySecurity.Monitoring1.0.7.1
Security.Monitoring.SecurityMonitoring.Event.GPOCreationSecurity.Monitoring1.0.7.1
Security.Monitoring.SecurityMonitoring.Event.GPODeletionRuleSecurity.Monitoring1.0.7.1
Security.Monitoring.SecurityMonitoring.Event.ScheduledTaskCreatedOnServerSecurity.Monitoring1.0.7.1
Security.Monitoring.SecurityMonitoring.Event.ServiceCreatedonDCSecurity.Monitoring1.0.7.1
Security.Monitoring.SuspiciousUserContextSecurity.Monitoring1.0.7.1
Security.Monitoring.SystemLogClearedv2Security.Monitoring1.0.7.1
SecurityMonitoring.Event.FailedLoginSecurity.Monitoring1.0.7.1
SecurityMonitoring.Failed.Login.Attempts.CollectionSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.Accounts.DomainAdminChangeSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.Accounts.EnterpriseAdminChangeSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.Accounts.LocalAdminChangeSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.Accounts.SchemaAdminChangeSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.APPLocker.MimikatzSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.APPLocker.ProhibitedAppSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.APPLocker.PSExecSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.APPLocker.WCESecurity.Monitoring1.0.7.1
SecurityMonitoringMP.APPLocker.WinRarSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.Event.4688.SuspiciousApplockerJavaSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.Event.4688.SuspiciousApplockerRegsvrSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.Event.4688.SuspiciousCMDSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.Event.4688.SuspiciousFTPCommandSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.Event.4688.SuspiciousRegSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.Event.4688.SuspiciousWindowsPositionSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.Event.GoldenTicketDetectionSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.Event.LocalAccountCreatedonServerSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.Event.SecurityLogClearedSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.Event.ServiceCreatedonMemberServerSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.Event.ServiceKnownThreatSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.Event.SmartCardDisabledSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.Event.SoftwareInstallOnServerSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.Event.SoftwareRemovedFromServerSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.Event.SystemLogClearedSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.Event.SystemPoweredOffSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.Event.SystemRestartedSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.Event.UnexpectedShutdownSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.EventCollection.4672Security.Monitoring1.0.7.1
SecurityMonitoringMP.EventCollection.BatchLogonSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.EventCollection.GoldenTicketSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.EventCollection.SpecialGroupLogonSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.ForwardedEvents.4688.SuspiciousApplockerJavaSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.ForwardedEvents.4688.SuspiciousApplockerRegsvrSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.ForwardedEvents.4688.SuspiciousCMDSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.ForwardedEvents.4688.SuspiciousFTPCommandSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.ForwardedEvents.4688.SuspiciousRegSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.ForwardedEvents.4688.SuspiciousWindowsPositionSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.ForwardedEvents.CredentialSwapSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.ForwardedEvents.LocalUserCreatedDeletedSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.ForwardedEvents.ProhibitedAppSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.ForwardedEvents.PtHTier2Security.Monitoring1.0.7.1
SecurityMonitoringMP.ForwardedEvents.SecurityLogClearedSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.ForwardedEvents.ServiceCreationSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.ForwardedEvents.ServiceCreationKnownThreatsSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.ForwardedEvents.SpecialGroupLogonSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.ForwardedEvents.SystemLogClearedSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.GPOMonitoring.EventAndScript.RuleSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.Pth.CredentialSwapSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.Pth.PtHAgainstDCSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.Pth.PtHAgainstTier1Security.Monitoring1.0.7.1
SecurityMonitoringMP.ThreatHunt.BatchLogonInUseSecurity.Monitoring1.0.7.1
SecurityMonitoringMP.ThreatHunt.SpecialGroupLogonSecurity.Monitoring1.0.7.1