All Rules in Microsoft.AdvancedThreatAnalytics.1_8 Management Pack

 DisplayNameDescriptionIDTargetCategoryEnabledInstance NameCounter NameFrequencyEvent_IDEvent SourceAlert GenerateAlert SeverityAlert PriorityRemotableEvent Log
Microsoft.AdvancedThreatAnalytics.1_8.Center.AbnormalBehaviorSuspiciousActivity異常行為可疑活動警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.AbnormalBehaviorSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.AbnormalProtocolSuspiciousActivity異常通訊協定可疑活動警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.AbnormalProtocolSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.AbnormalSensitiveGroupMembershipChangeSuspiciousActivity異常敏感群組成員資格變更可疑活動警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.AbnormalSensitiveGroupMembershipChangeSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.AbnormalVpnSuspiciousActivity異常 VPN 可疑活動警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.AbnormalVpnSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.AccountEnumerationSuspiciousActivity帳戶列舉可疑活動警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.AccountEnumerationSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.BruteForceSuspiciousActivity暴力密碼破解可疑活動警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.BruteForceSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.CenterDatabaseDataDriveFreeSpaceMonitoringAlertATA 1.8 - 中心資料庫資料磁碟機可用空間監視警示的警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.CenterDatabaseDataDriveFreeSpaceMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_8.CenterAvailabilityHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.CenterDatabaseDisconnectedMonitoringAlertATA 1.8 - 中心資料庫中斷連線監視警示的警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.CenterDatabaseDisconnectedMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_8.CenterAvailabilityHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.CenterExternalIpAddressResolutionFailureMonitoringAlertATA 1.8 - 中心外部 IP 位址解析失敗監視警示的警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.CenterExternalIpAddressResolutionFailureMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_8.CenterAvailabilityHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.CenterMailMonitoringAlertATA 1.8 - 中心郵件監視警示的警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.CenterMailMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_8.CenterConfigurationHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.CenterNotReceivingTrafficMonitoringAlertATA 1.8 - 中心未接收流量監視警示的警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.CenterNotReceivingTrafficMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_8.CenterAvailabilityHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.CenterOverloadedMonitoringAlertATA 1.8 - 中心負載過重監視警示的警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.CenterOverloadedMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_8.CenterPerformanceHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.CenterSyslogMonitoringAlertATA 1.8 - 中心 Syslog 監視警示的警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.CenterSyslogMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_8.CenterConfigurationHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.CertificateExpiryMonitoringAlertATA 1.8 - 憑證過期監視警示的警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.CertificateExpiryMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_8.CenterConfigurationHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.ComputerPreauthenticationFailedSuspiciousActivity電腦預先驗證失敗可疑活動警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.ComputerPreauthenticationFailedSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseAtSvcBlockSize資料庫 AtSVC 區塊大小1.8Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseAtSvcBlockSizeMicrosoft.AdvancedThreatAnalytics.1_8.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase AtSVC Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseDirectoryServicesActivityBlockSize資料庫 DirectoryServicesActivity 區塊大小1.8Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseDirectoryServicesActivityBlockSizeMicrosoft.AdvancedThreatAnalytics.1_8.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase DirectoryServicesActivity Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseDnsBlockSizeDatabase DNS Block Size1.8Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseDnsBlockSizeMicrosoft.AdvancedThreatAnalytics.1_8.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase DNS Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseDrsrBlockSizeDatabase DRSR Block Size1.8Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseDrsrBlockSizeMicrosoft.AdvancedThreatAnalytics.1_8.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase DRSR Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseKerberosApBlockSize資料庫 KerberosAP 區塊大小1.8Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseKerberosApBlockSizeMicrosoft.AdvancedThreatAnalytics.1_8.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase KerberosAP Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseKerberosAsBlockSizeDatabase KerberosAS Block Size1.8Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseKerberosAsBlockSizeMicrosoft.AdvancedThreatAnalytics.1_8.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase KerberosAS Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseKerberosTgsBlockSize資料庫 KerberosTGS 區塊大小1.8Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseKerberosTgsBlockSizeMicrosoft.AdvancedThreatAnalytics.1_8.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase KerberosTGS Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseLdapBlockSizeDatabase LDAP Block Size1.8Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseLdapBlockSizeMicrosoft.AdvancedThreatAnalytics.1_8.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase LDAP Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseLsaRpcBlockSize資料庫 LsaRPC 區塊大小1.8Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseLsaRpcBlockSizeMicrosoft.AdvancedThreatAnalytics.1_8.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase LsaRPC Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseNetlogonBlockSize資料庫 Netlogon 區塊大小1.8Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseNetlogonBlockSizeMicrosoft.AdvancedThreatAnalytics.1_8.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase Netlogon Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseNtlmBlockSize資料庫 NTLM 區塊大小1.8Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseNtlmBlockSizeMicrosoft.AdvancedThreatAnalytics.1_8.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase NTLM Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseNtlmEventBlockSize資料庫 NTLMEvent 區塊大小1.8Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseNtlmEventBlockSizeMicrosoft.AdvancedThreatAnalytics.1_8.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase NTLMEvent Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseServiceControlBlockSize資料庫 ServiceControl 區塊大小1.8Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseServiceControlBlockSizeMicrosoft.AdvancedThreatAnalytics.1_8.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase ServiceControl Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseSmbBlockSizeDatabase SMB Block Size1.8Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseSmbBlockSizeMicrosoft.AdvancedThreatAnalytics.1_8.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase SMB Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseSrvSvcBlockSize資料庫 SrvSVC 區塊大小1.8Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseSrvSvcBlockSizeMicrosoft.AdvancedThreatAnalytics.1_8.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase SrvSVC Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseTaskSchedulerBlockSizeDatabase TaskScheduler Block Size1.8Microsoft.AdvancedThreatAnalytics.1_8.Center.DatabaseTaskSchedulerBlockSizeMicrosoft.AdvancedThreatAnalytics.1_8.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase TaskScheduler Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_8.Center.DirectoryServicesReplicationSuspiciousActivity目錄服務複寫可疑活動警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.DirectoryServicesReplicationSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.DnsReconnaissanceSuspiciousActivityDNS 偵查可疑活動警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.DnsReconnaissanceSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.EncryptionDowngradeSuspiciousActivity加密降級可疑活動警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.EncryptionDowngradeSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.EntityProfilerNetworkActivityBlockSizeEntityProfiler 網路活動區塊大小1.8Microsoft.AdvancedThreatAnalytics.1_8.Center.EntityProfilerNetworkActivityBlockSizeMicrosoft.AdvancedThreatAnalytics.1_8.CenterPerformanceCollectionTrueMicrosoft ATA CenterEntityProfiler Network Activity Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_8.Center.EntityReceiverEntityBatchBlockSizeEntityReceiver 實體批次區塊大小1.8Microsoft.AdvancedThreatAnalytics.1_8.Center.EntityReceiverEntityBatchBlockSizeMicrosoft.AdvancedThreatAnalytics.1_8.CenterPerformanceCollectionTrueMicrosoft ATA CenterEntityReceiver Entity Batch Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_8.Center.EnumerateSessionsSuspiciousActivity加密降級可疑活動 (黃金票證) 警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.EnumerateSessionsSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.ForgedPacSuspiciousActivity加密降級可疑活動 (略過雜湊) 警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.ForgedPacSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.GatewayCaptureNetworkAdapterFaultedMonitoringAlertATA 1.8 - 閘道擷取網路介面卡錯誤監視警示的警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.GatewayCaptureNetworkAdapterFaultedMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_8.CenterAvailabilityHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.GatewayCaptureNetworkAdapterMissingMonitoringAlertATA 1.8 - 閘道擷取網路介面卡遺漏監視警示的警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.GatewayCaptureNetworkAdapterMissingMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_8.CenterConfigurationHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.GatewayDirectoryServicesClientAccountPasswordExpiryMonitoringAlertATA 1.8 - 閘道目錄服務用戶端帳戶密碼過期監視警示的警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.GatewayDirectoryServicesClientAccountPasswordExpiryMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_8.CenterConfigurationHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.GatewayDirectoryServicesClientConnectivityMonitoringAlertATA 1.8 - 閘道目錄服務用戶端連線監視警示的警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.GatewayDirectoryServicesClientConnectivityMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_8.CenterAvailabilityHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.GatewayDisconnectedMonitoringAlertATA 1.8 - 閘道中斷連線監視警示的警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.GatewayDisconnectedMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_8.CenterAvailabilityHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.GatewayDomainSynchronizerNotAssignedMonitoringAlertATA 1.8 - 未指派閘道網域同步器監視警示的警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.GatewayDomainSynchronizerNotAssignedMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_8.CenterConfigurationHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.GatewayLowMemoryMonitoringAlertATA 1.8 - 閘道記憶體不足監視警示的警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.GatewayLowMemoryMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_8.CenterPerformanceHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.GatewayOverloadedEventActivitiesMonitoringAlertATA 1.8 - 閘道負載過重事件活動監視警示的警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.GatewayOverloadedEventActivitiesMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_8.CenterPerformanceHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.GatewayOverloadedNetworkActivitiesMonitoringAlertATA 1.8 - 閘道負載過重網路活動監視警示的警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.GatewayOverloadedNetworkActivitiesMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_8.CenterPerformanceHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.GatewayRadiusEventListenerMonitoringAlertATA 1.8 - 閘道 Radius 事件接聽程式監視警示的警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.GatewayRadiusEventListenerMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_8.CenterAvailabilityHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.GatewaysOutdatedMonitoringAlertATA 1.8 - 閘道過期監視警示的警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.GatewaysOutdatedMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_8.CenterConfigurationHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.GatewayStartFailureMonitoringAlertATA 1.8 - 閘道啟動失敗監視警示的警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.GatewayStartFailureMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_8.CenterAvailabilityHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.GatewaySyslogEventListenerMonitoringAlertATA 1.8 - 閘道 Syslog 事件接聽程式監視警示的警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.GatewaySyslogEventListenerMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_8.CenterAvailabilityHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.GoldenTicketSuspiciousActivity加密降級可疑活動 (萬能鑰匙) 警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.GoldenTicketSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.HoneytokenActivitySuspiciousActivity列舉工作階段可疑活動警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.HoneytokenActivitySuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.LdapBruteForceSuspiciousActivity偽造的 PAC 可疑活動警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.LdapBruteForceSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.LdapCleartextPasswordSuspiciousActivityHoneytoken 活動可疑活動警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.LdapCleartextPasswordSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.MassiveObjectDeletionSuspiciousActivityLDAP 簡單繫結純文字密碼可疑活動警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.MassiveObjectDeletionSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.NetworkActivityProcessorNetworkActivityBlockSizeNetworkActivityProcessor 網路活動區塊大小1.8Microsoft.AdvancedThreatAnalytics.1_8.Center.NetworkActivityProcessorNetworkActivityBlockSizeMicrosoft.AdvancedThreatAnalytics.1_8.CenterPerformanceCollectionTrueMicrosoft ATA CenterNetworkActivityProcessor Network Activity Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_8.Center.PassTheHashSuspiciousActivity大量物件刪除可疑活動警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.PassTheHashSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.PassTheTicketSuspiciousActivity傳遞雜湊可疑活動警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.PassTheTicketSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.RemoteExecutionSuspiciousActivity傳遞票證可疑活動警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.RemoteExecutionSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.RetrieveDataProtectionBackupKeySuspiciousActivity遠端執行可疑活動警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.RetrieveDataProtectionBackupKeySuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.SamrReconnaissanceSuspiciousActivity擷取資料保護備份金鑰可疑活動警示規則Microsoft.AdvancedThreatAnalytics.1_8.Center.SamrReconnaissanceSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Gateway.ActiveDirectoryAuthenticationFailureATA 閘道無法對網域控制站進行驗證監視 Microsoft ATA 1.8 閘道的規則 - ATA 閘道無法對網域控制站進行驗證Microsoft.AdvancedThreatAnalytics.1_8.Gateway.ActiveDirectoryAuthenticationFailureMicrosoft.AdvancedThreatAnalytics.1_8.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_8.Gateway.CountersDisabled登錄中可能已停用計數器監視 Microsoft ATA 1.8 閘道的規則 - 登錄中可能已停用計數器Microsoft.AdvancedThreatAnalytics.1_8.Gateway.CountersDisabledMicrosoft.AdvancedThreatAnalytics.1_8.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_8.Gateway.EntityResolverActivityBlockSizeEntityResolver 活動區塊大小1.8Microsoft.AdvancedThreatAnalytics.1_8.Gateway.EntityResolverActivityBlockSizeMicrosoft.AdvancedThreatAnalytics.1_8.GatewayPerformanceCollectionTrueMicrosoft ATA GatewayEntityResolver Activity Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_8.Gateway.EntitySenderEntityBatchBlockSizeEntitySender 實體批次區塊大小1.8Microsoft.AdvancedThreatAnalytics.1_8.Gateway.EntitySenderEntityBatchBlockSizeMicrosoft.AdvancedThreatAnalytics.1_8.GatewayPerformanceCollectionTrueMicrosoft ATA GatewayEntitySender Entity Batch Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_8.Gateway.EntitySenderEntityBatchSendTimeEntitySender 實體批次傳送時間1.8Microsoft.AdvancedThreatAnalytics.1_8.Gateway.EntitySenderEntityBatchSendTimeMicrosoft.AdvancedThreatAnalytics.1_8.GatewayPerformanceCollectionTrueMicrosoft ATA GatewayEntitySender Entity Batch Send Time3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_8.Gateway.FailedToAuthenticateAgainstCenterATA 閘道無法對 中心進行驗證監視 Microsoft ATA 1.8 閘道的規則 - ATA 閘道無法對中心進行驗證Microsoft.AdvancedThreatAnalytics.1_8.Gateway.FailedToAuthenticateAgainstCenterMicrosoft.AdvancedThreatAnalytics.1_8.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_8.Gateway.FailedToEstablishConnectionToCenterATA 閘道無法建立與 ATA 中心的連線監視 Microsoft ATA 1.8 閘道的規則 - ATA 閘道無法建立與 ATA 中心的連線Microsoft.AdvancedThreatAnalytics.1_8.Gateway.FailedToEstablishConnectionToCenterMicrosoft.AdvancedThreatAnalytics.1_8.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_8.Gateway.FailedToParseSyslogATA 閘道無法剖析 SIEM Syslog 訊息監視 Microsoft ATA 1.8 閘道的規則 - ATA 閘道無法剖析 SIEM Syslog 訊息Microsoft.AdvancedThreatAnalytics.1_8.Gateway.FailedToParseSyslogMicrosoft.AdvancedThreatAnalytics.1_8.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_8.Gateway.FailedToQueryDCUsingLDAPProtocolATA 閘道無法使用 LDAP 通訊協定查詢網域控制站監視 Microsoft ATA 1.8 閘道的規則 - ATA 閘道無法使用 LDAP 通訊協定查詢網域控制站Microsoft.AdvancedThreatAnalytics.1_8.Gateway.FailedToQueryDCUsingLDAPProtocolMicrosoft.AdvancedThreatAnalytics.1_8.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_8.Gateway.FailedToSynchronizeConfigurationFromCenterATA 閘道無法同步來自 ATA 中心的設定監視 Microsoft ATA 1.8 閘道的規則 - ATA 閘道無法同步來自 ATA 中心的設定Microsoft.AdvancedThreatAnalytics.1_8.Gateway.FailedToSynchronizeConfigurationFromCenterMicrosoft.AdvancedThreatAnalytics.1_8.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_8.Gateway.FailedToValidateCenterCertificateChainATA 閘道無法驗證中心憑證鏈結監視 Microsoft ATA 1.8 閘道的規則 - ATA 閘道無法驗證中心憑證鏈結Microsoft.AdvancedThreatAnalytics.1_8.Gateway.FailedToValidateCenterCertificateChainMicrosoft.AdvancedThreatAnalytics.1_8.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_8.Gateway.GatewayDoesNotHaveEnoughMemoryATA 閘道的記憶體不足監視 Microsoft ATA 1.8 閘道的規則 - ATA 閘道的記憶體不足Microsoft.AdvancedThreatAnalytics.1_8.Gateway.GatewayDoesNotHaveEnoughMemoryMicrosoft.AdvancedThreatAnalytics.1_8.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_8.Gateway.GatewayUpdaterResourceManagerCommitMemoryMaxSizeGatewayUpdaterResourceManager 認可記憶體大小上限1.8Microsoft.AdvancedThreatAnalytics.1_8.Gateway.GatewayUpdaterResourceManagerCommitMemoryMaxSizeMicrosoft.AdvancedThreatAnalytics.1_8.GatewayPerformanceCollectionTrueMicrosoft ATA Gateway UpdaterGatewayUpdaterResourceManager Commit Memory Max Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_8.Gateway.GatewayUpdaterResourceManagerCPUTimeMax_GatewayUpdaterResourceManager CPU 時間上限 \%1.8Microsoft.AdvancedThreatAnalytics.1_8.Gateway.GatewayUpdaterResourceManagerCPUTimeMax_Microsoft.AdvancedThreatAnalytics.1_8.GatewayPerformanceCollectionTrueMicrosoft ATA Gateway UpdaterGatewayUpdaterResourceManager CPU Time Max \%3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_8.Gateway.GatewayUpdaterResourceManagerWorkingSetLimitSizeGatewayUpdaterResourceManager 工作集限制大小1.8Microsoft.AdvancedThreatAnalytics.1_8.Gateway.GatewayUpdaterResourceManagerWorkingSetLimitSizeMicrosoft.AdvancedThreatAnalytics.1_8.GatewayPerformanceCollectionTrueMicrosoft ATA Gateway UpdaterGatewayUpdaterResourceManager Working Set Limit Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_8.Gateway.HostEntryInHOSTSFileHOSTS 檔案中有指向電腦簡短名稱的主機項目監視 Microsoft ATA 1.8 閘道的規則 - HOSTS 檔案中有指向電腦簡短名稱的主機項目Microsoft.AdvancedThreatAnalytics.1_8.Gateway.HostEntryInHOSTSFileMicrosoft.AdvancedThreatAnalytics.1_8.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_8.Gateway.MessageAnalyzerIsInstalledOnGateway郵件分析器已安裝在 ATA 閘道上監視 Microsoft ATA 1.8 閘道的規則 - 郵件分析器已安裝在 ATA 閘道上Microsoft.AdvancedThreatAnalytics.1_8.Gateway.MessageAnalyzerIsInstalledOnGatewayMicrosoft.AdvancedThreatAnalytics.1_8.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_8.Gateway.NetworkActivityTranslatorMessageData0BlockSizeNetworkActivityTranslator 郵件資料 0 區塊大小1.8Microsoft.AdvancedThreatAnalytics.1_8.Gateway.NetworkActivityTranslatorMessageData0BlockSizeMicrosoft.AdvancedThreatAnalytics.1_8.GatewayPerformanceCollectionTrueMicrosoft ATA GatewayNetworkActivityTranslator Message Data 0 Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_8.Gateway.NetworkListenerETWDroppedEvents_SecNetworkListener ETW 捨棄的事件/秒1.8Microsoft.AdvancedThreatAnalytics.1_8.Gateway.NetworkListenerETWDroppedEvents_SecMicrosoft.AdvancedThreatAnalytics.1_8.GatewayPerformanceCollectionTrueMicrosoft ATA GatewayNetworkListener ETW Dropped Events/Sec3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_8.Gateway.NetworkListenerPEFDroppedEvents_SecNetworkListener PEF 捨棄的事件/秒1.8Microsoft.AdvancedThreatAnalytics.1_8.Gateway.NetworkListenerPEFDroppedEvents_SecMicrosoft.AdvancedThreatAnalytics.1_8.GatewayPerformanceCollectionTrueMicrosoft ATA GatewayNetworkListener PEF Dropped Events/Sec3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_8.Gateway.NetworkListenerPEFParsedMessages_SecNetworkListener PEF 剖析的郵件/秒1.8Microsoft.AdvancedThreatAnalytics.1_8.Gateway.NetworkListenerPEFParsedMessages_SecMicrosoft.AdvancedThreatAnalytics.1_8.GatewayPerformanceCollectionTrueMicrosoft ATA GatewayNetworkListener PEF Parsed Messages/Sec3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_8.Gateway.OtherPendingInstallations電腦上有其他擱置中的安裝監視 Microsoft ATA 1.8 閘道的規則 - 電腦上有其他暫止的安裝Microsoft.AdvancedThreatAnalytics.1_8.Gateway.OtherPendingInstallationsMicrosoft.AdvancedThreatAnalytics.1_8.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_8.Gateway.PEFWasNotInstalledCorrectly未正確安裝 PEF (郵件分析器)監視 Microsoft ATA 1.8 閘道的規則 - 未正確安裝 PEF (郵件分析器)Microsoft.AdvancedThreatAnalytics.1_8.Gateway.PEFWasNotInstalledCorrectlyMicrosoft.AdvancedThreatAnalytics.1_8.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_8.Gateway.PIDsWasEnabledForProcessNamesInGateway已為 ATA 閘道中的處理序名稱啟用 PID監視 Microsoft ATA 1.8 閘道的規則 - 已為 ATA 閘道中的處理序名稱啟用 PIDMicrosoft.AdvancedThreatAnalytics.1_8.Gateway.PIDsWasEnabledForProcessNamesInGatewayMicrosoft.AdvancedThreatAnalytics.1_8.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_8.Center.EncryptionDowngradeGoldenTicketSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.Center.EncryptionDowngradeGoldenTicketSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.Center.EncryptionDowngradeGoldenTicketSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.EncryptionDowngradeOverPasstheHashSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.Center.EncryptionDowngradeOverPasstheHashSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.Center.EncryptionDowngradeOverPasstheHashSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_8.Center.EncryptionDowngradeSkeletonKeySuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.Center.EncryptionDowngradeSkeletonKeySuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.Center.EncryptionDowngradeSkeletonKeySuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_8.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA