All Rules in Microsoft.AdvancedThreatAnalytics.1_7 Management Pack

 DisplayNameDescriptionIDTargetCategoryEnabledInstance NameCounter NameFrequencyEvent_IDEvent SourceAlert GenerateAlert SeverityAlert PriorityRemotableEvent Log
Microsoft.AdvancedThreatAnalytics.1_7.Center.AbnormalBehaviorSuspiciousActivityAbnormal Behavior Suspicious Activity Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.AbnormalBehaviorSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.AbnormalSmbSuspiciousActivityAbnormal SMB Suspicious Activity Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.AbnormalSmbSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.AccountEnumerationSuspiciousActivityAccount Enumeration Suspicious Activity Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.AccountEnumerationSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.BruteForceSuspiciousActivityBrute Force Suspicious Activity Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.BruteForceSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.CenterDatabaseDataDriveFreeSpaceMonitoringAlertATA 1.7 - Center Database Data Drive Free Space Monitoring Alert Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.CenterDatabaseDataDriveFreeSpaceMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterAvailabilityHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.CenterOverloadedMonitoringAlertATA 1.7 - Center Overloaded Monitoring Alert Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.CenterOverloadedMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.CertificateExpiryMonitoringAlertATA 1.7 - Certificate Expiry Monitoring Alert Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.CertificateExpiryMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterConfigurationHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.ComputerPreauthenticationFailedSuspiciousActivityComputer Pre-Authentication Failed Suspicious Activity Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.ComputerPreauthenticationFailedSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseAtSvcBlockSizeDatabase AtSVC Block SizeThe number of Network Activities of a specific type queued to be written to the databaseMicrosoft.AdvancedThreatAnalytics.1_7.Center.DatabaseAtSvcBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase AtSVC Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseDirectoryServicesActivityBlockSizeDatabase DirectoryServicesActivity Block SizeThe number of Network Activities of a specific type queued to be written to the databaseMicrosoft.AdvancedThreatAnalytics.1_7.Center.DatabaseDirectoryServicesActivityBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase DirectoryServicesActivity Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseDisconnectedMonitoringAlertATA 1.7 - Database Disconnected Monitoring Alert Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.DatabaseDisconnectedMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterAvailabilityHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseDnsBlockSizeDatabase DNS Block SizeThe number of Network Activities of a specific type queued to be written to the databaseMicrosoft.AdvancedThreatAnalytics.1_7.Center.DatabaseDnsBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase DNS Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseDrsrBlockSizeDatabase DRSR Block SizeThe number of Network Activities of a specific type queued to be written to the databaseMicrosoft.AdvancedThreatAnalytics.1_7.Center.DatabaseDrsrBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase DRSR Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseKerberosApBlockSizeDatabase KerberosAP Block SizeThe number of Network Activities of a specific type queued to be written to the databaseMicrosoft.AdvancedThreatAnalytics.1_7.Center.DatabaseKerberosApBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase KerberosAP Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseKerberosAsBlockSizeDatabase KerberosAS Block SizeThe number of Network Activities of a specific type queued to be written to the databaseMicrosoft.AdvancedThreatAnalytics.1_7.Center.DatabaseKerberosAsBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase KerberosAS Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseKerberosTgsBlockSizeDatabase KerberosTGS Block SizeThe number of Network Activities of a specific type queued to be written to the databaseMicrosoft.AdvancedThreatAnalytics.1_7.Center.DatabaseKerberosTgsBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase KerberosTGS Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseLdapBlockSizeDatabase LDAP Block SizeThe number of Network Activities of a specific type queued to be written to the databaseMicrosoft.AdvancedThreatAnalytics.1_7.Center.DatabaseLdapBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase LDAP Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseLsaRpcBlockSizeDatabase LsaRPC Block SizeThe number of Network Activities of a specific type queued to be written to the databaseMicrosoft.AdvancedThreatAnalytics.1_7.Center.DatabaseLsaRpcBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase LsaRPC Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseNetlogonBlockSizeDatabase Netlogon Block SizeThe number of Network Activities of a specific type queued to be written to the databaseMicrosoft.AdvancedThreatAnalytics.1_7.Center.DatabaseNetlogonBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase Netlogon Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseNtlmBlockSizeDatabase NTLM Block SizeThe number of Network Activities of a specific type queued to be written to the databaseMicrosoft.AdvancedThreatAnalytics.1_7.Center.DatabaseNtlmBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase NTLM Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseNtlmEventBlockSizeDatabase NTLMEvent Block SizeThe number of Network Activities of a specific type queued to be written to the databaseMicrosoft.AdvancedThreatAnalytics.1_7.Center.DatabaseNtlmEventBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase NTLMEvent Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseServiceControlBlockSizeDatabase ServiceControl Block SizeThe number of Network Activities of a specific type queued to be written to the databaseMicrosoft.AdvancedThreatAnalytics.1_7.Center.DatabaseServiceControlBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase ServiceControl Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseSmbBlockSizeDatabase SMB Block SizeThe number of Network Activities of a specific type queued to be written to the databaseMicrosoft.AdvancedThreatAnalytics.1_7.Center.DatabaseSmbBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase SMB Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseSrvSvcBlockSizeDatabase SrvSVC Block SizeThe number of Network Activities of a specific type queued to be written to the databaseMicrosoft.AdvancedThreatAnalytics.1_7.Center.DatabaseSrvSvcBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase SrvSVC Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseTaskSchedulerBlockSizeDatabase TaskScheduler Block SizeThe number of Network Activities of a specific type queued to be written to the databaseMicrosoft.AdvancedThreatAnalytics.1_7.Center.DatabaseTaskSchedulerBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase TaskScheduler Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DirectoryServicesClientAccountPasswordExpiryMonitoringAlertATA 1.7 - Directory Services Client Account Password Expiry Monitoring Alert Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.DirectoryServicesClientAccountPasswordExpiryMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterConfigurationHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.DirectoryServicesReplicationSuspiciousActivityDirectory Services Replication Suspicious Activity Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.DirectoryServicesReplicationSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.DnsReconnaissanceSuspiciousActivityDNS Reconnaissance Suspicious Activity Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.DnsReconnaissanceSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.DomainSynchronizerNotAssignedMonitoringAlertATA 1.7 - Domain Synchronizer Not Assigned Monitoring Alert Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.DomainSynchronizerNotAssignedMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterConfigurationHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.EncryptionDowngradeSuspiciousActivityEncryption Downgrade Suspicious Activity Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.EncryptionDowngradeSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.EncryptionDowngradeSuspiciousActivity_GoldenTicketEncryption Downgrade Suspicious Activity (Golden Ticket) Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.EncryptionDowngradeSuspiciousActivity_GoldenTicketMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.EncryptionDowngradeSuspiciousActivity_OverpasstheHashEncryption Downgrade Suspicious Activity (Overpass the Hash) Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.EncryptionDowngradeSuspiciousActivity_OverpasstheHashMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.EncryptionDowngradeSuspiciousActivity_SkeletonKeyEncryption Downgrade Suspicious Activity (Skeleton Key) Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.EncryptionDowngradeSuspiciousActivity_SkeletonKeyMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.EntityProfilerNetworkActivityBlockSizeEntityProfiler Network Activity Block SizeThe number of Network Activities (NAs) queued for profilingMicrosoft.AdvancedThreatAnalytics.1_7.Center.EntityProfilerNetworkActivityBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterEntityProfiler Network Activity Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.EntityReceiverEntityBatchBlockSizeEntityReceiver Entity Batch Block SizeThe number of entity batches queued by the ATA CenterMicrosoft.AdvancedThreatAnalytics.1_7.Center.EntityReceiverEntityBatchBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterEntityReceiver Entity Batch Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.EnumerateSessionsSuspiciousActivityEnumerate Sessions Suspicious Activity Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.EnumerateSessionsSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.ForgedPacSuspiciousActivityForged Pac Suspicious Activity Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.ForgedPacSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.GatewayCaptureNetworkAdapterFaultedMonitoringAlertATA 1.7 - Gateway Capture Network Adapter Faulted Monitoring Alert Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.GatewayCaptureNetworkAdapterFaultedMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterAvailabilityHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.GatewayCaptureNetworkAdapterMissingMonitoringAlertATA 1.7 - Gateway Capture Network Adapter Missing Monitoring Alert Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.GatewayCaptureNetworkAdapterMissingMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterConfigurationHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.GatewayDirectoryServicesClientConnectivityMonitoringAlertATA 1.7 - Gateway Directory Services Client Connectivity Monitoring Alert Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.GatewayDirectoryServicesClientConnectivityMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterAvailabilityHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.GatewayDisconnectedMonitoringAlertATA 1.7 - Gateway Disconnected Monitoring Alert Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.GatewayDisconnectedMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterAvailabilityHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.GatewayLowMemoryMonitoringAlertATA 1.7 - Gateway Low Memory Monitoring Alert Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.GatewayLowMemoryMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.GatewayNotReceivingTrafficMonitoringAlertATA 1.7 - Gateway Not Receiving Traffic Monitoring Alert Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.GatewayNotReceivingTrafficMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterAvailabilityHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.GatewayOverloadedEventActivitiesMonitoringAlertATA 1.7 - Gateway Overloaded Event Activities Monitoring Alert Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.GatewayOverloadedEventActivitiesMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.GatewayOverloadedNetworkActivitiesMonitoringAlertATA 1.7 - Gateway Overloaded Network Activities Monitoring Alert Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.GatewayOverloadedNetworkActivitiesMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.GatewaysOutdatedMonitoringAlertATA 1.7 - Gateways Outdated Monitoring Alert Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.GatewaysOutdatedMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterConfigurationHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.GatewayStartFailureMonitoringAlertATA 1.7 - Gateway Start Failure Monitoring Alert Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.GatewayStartFailureMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterAvailabilityHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.HoneytokenActivitySuspiciousActivityHoneytoken Activity Suspicious Activity Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.HoneytokenActivitySuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.LdapSimpleBindCleartextPasswordSuspiciousActivityLDAP Simple Bind Cleartext Password Suspicious Activity Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.LdapSimpleBindCleartextPasswordSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.MailMonitoringAlertATA 1.7 - Mail Monitoring Alert Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.MailMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterConfigurationHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.MassiveObjectDeletionSuspiciousActivityMassive Object Deletion Suspicious Activity Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.MassiveObjectDeletionSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.NetworkActivityProcessorNetworkActivityBlockSizeNetworkActivityProcessor Network Activity Block SizeThe number of Network Activities (NAs) queued for processingMicrosoft.AdvancedThreatAnalytics.1_7.Center.NetworkActivityProcessorNetworkActivityBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterNetworkActivityProcessor Network Activity Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.PassTheHashSuspiciousActivityPass The Hash Suspicious Activity Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.PassTheHashSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.PassTheTicketSuspiciousActivityPass The Ticket Suspicious Activity Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.PassTheTicketSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.RemoteExecutionSuspiciousActivityRemote Execution Suspicious Activity Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.RemoteExecutionSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.RetrieveDataProtectionBackupKeySuspiciousActivityRetrieve Data Protection Backup Key Suspicious Activity Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.RetrieveDataProtectionBackupKeySuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.SamrReconnaissanceSuspiciousActivitySAMR Reconnaissance Suspicious Activity Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.SamrReconnaissanceSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.SyslogMonitoringAlertATA 1.7 - Syslog Monitoring Alert Alert RuleMicrosoft.AdvancedThreatAnalytics.1_7.Center.SyslogMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterConfigurationHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.ActiveDirectoryAuthenticationFailureATA Gateway Failed to Authenticate Against the Domain ControllerRule to monitor Microsoft ATA 1.7 Gateway - ATA Gateway Failed to Authenticate Against the Domain ControllerMicrosoft.AdvancedThreatAnalytics.1_7.Gateway.ActiveDirectoryAuthenticationFailureMicrosoft.AdvancedThreatAnalytics.1_7.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.CountersDisabledCounters might be disabled in the registryRule to monitor Microsoft ATA 1.7 Gateway - Counters might be disabled in the registryMicrosoft.AdvancedThreatAnalytics.1_7.Gateway.CountersDisabledMicrosoft.AdvancedThreatAnalytics.1_7.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.EntityResolverActivityBlockSizeEntityResolver Activity Block SizeThe amount of Network Activities (NAs) queued for resolutionMicrosoft.AdvancedThreatAnalytics.1_7.Gateway.EntityResolverActivityBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.GatewayPerformanceCollectionTrueMicrosoft ATA GatewayEntityResolver Activity Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.EntitySenderEntityBatchBlockSizeEntitySender Entity Batch Block SizeThe amount of Network Activities (NAs) queued to be sent to the ATA CenterMicrosoft.AdvancedThreatAnalytics.1_7.Gateway.EntitySenderEntityBatchBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.GatewayPerformanceCollectionTrueMicrosoft ATA GatewayEntitySender Entity Batch Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.EntitySenderEntityBatchSendTimeEntitySender Entity Batch Send TimeThe amount of time it took to send the last batchMicrosoft.AdvancedThreatAnalytics.1_7.Gateway.EntitySenderEntityBatchSendTimeMicrosoft.AdvancedThreatAnalytics.1_7.GatewayPerformanceCollectionTrueMicrosoft ATA GatewayEntitySender Entity Batch Send Time3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.FailedToAuthenticateAgainstCenterATA Gateway Failed to Authenticate Against CenterRule to monitor Microsoft ATA 1.7 Gateway - ATA Gateway Failed to Authenticate Against CenterMicrosoft.AdvancedThreatAnalytics.1_7.Gateway.FailedToAuthenticateAgainstCenterMicrosoft.AdvancedThreatAnalytics.1_7.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.FailedToEstablishConnectionToCenterATA Gateway failed to establish connection to the ATA CenterRule to monitor Microsoft ATA 1.7 Gateway - ATA Gateway failed to establish connection to the ATA CenterMicrosoft.AdvancedThreatAnalytics.1_7.Gateway.FailedToEstablishConnectionToCenterMicrosoft.AdvancedThreatAnalytics.1_7.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.FailedToParseSyslogATA Gateway Failed to Parse SIEM Syslog MessageRule to monitor Microsoft ATA 1.7 Gateway - ATA Gateway Failed to Parse SIEM Syslog MessageMicrosoft.AdvancedThreatAnalytics.1_7.Gateway.FailedToParseSyslogMicrosoft.AdvancedThreatAnalytics.1_7.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.FailedToQueryDCUsingLDAPProtocolATA Gateway failed to query the domain controller using the LDAP protocolRule to monitor Microsoft ATA 1.7 Gateway - ATA Gateway failed to query the domain controller using the LDAP protocolMicrosoft.AdvancedThreatAnalytics.1_7.Gateway.FailedToQueryDCUsingLDAPProtocolMicrosoft.AdvancedThreatAnalytics.1_7.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.FailedToSynchronizeConfigurationFromCenterATA Gateway failed to synchronize the configuration from the ATA CenterRule to monitor Microsoft ATA 1.7 Gateway - ATA Gateway failed to synchronize the configuration from the ATA CenterMicrosoft.AdvancedThreatAnalytics.1_7.Gateway.FailedToSynchronizeConfigurationFromCenterMicrosoft.AdvancedThreatAnalytics.1_7.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.FailedToValidateCenterCertificateChainATA Gateway Failed to Validate Center Certificate ChainRule to monitor Microsoft ATA 1.7 Gateway - ATA Gateway Failed to Validate Center Certificate ChainMicrosoft.AdvancedThreatAnalytics.1_7.Gateway.FailedToValidateCenterCertificateChainMicrosoft.AdvancedThreatAnalytics.1_7.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.GatewayDoesNotHaveEnoughMemoryATA Gateway does not have enough memoryRule to monitor Microsoft ATA 1.7 Gateway - ATA Gateway does not have enough memoryMicrosoft.AdvancedThreatAnalytics.1_7.Gateway.GatewayDoesNotHaveEnoughMemoryMicrosoft.AdvancedThreatAnalytics.1_7.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.GatewayUpdaterResourceManagerCommitMemoryMaxSizeGatewayUpdaterResourceManager Commit Memory Max SizeThe maximum amount of committed memory (in bytes) that the Lightweight Gateway process can consumeMicrosoft.AdvancedThreatAnalytics.1_7.Gateway.GatewayUpdaterResourceManagerCommitMemoryMaxSizeMicrosoft.AdvancedThreatAnalytics.1_7.GatewayPerformanceCollectionTrueMicrosoft ATA Gateway UpdaterGatewayUpdaterResourceManager Commit Memory Max Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.GatewayUpdaterResourceManagerCPUTimeMax_GatewayUpdaterResourceManager CPU Time Max \%The maximum amount of CPU time (in percentage) that the Lightweight Gateway process can consumeMicrosoft.AdvancedThreatAnalytics.1_7.Gateway.GatewayUpdaterResourceManagerCPUTimeMax_Microsoft.AdvancedThreatAnalytics.1_7.GatewayPerformanceCollectionTrueMicrosoft ATA Gateway UpdaterGatewayUpdaterResourceManager CPU Time Max \%3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.GatewayUpdaterResourceManagerWorkingSetLimitSizeGatewayUpdaterResourceManager Working Set Limit SizeThe Maximum amount of physical memory (in bytes) that the Lightweight Gateway process can consumeMicrosoft.AdvancedThreatAnalytics.1_7.Gateway.GatewayUpdaterResourceManagerWorkingSetLimitSizeMicrosoft.AdvancedThreatAnalytics.1_7.GatewayPerformanceCollectionTrueMicrosoft ATA Gateway UpdaterGatewayUpdaterResourceManager Working Set Limit Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.HostEntryInHOSTSFileThere is a host entry in the HOSTS file pointing to the machine's shortnameRule to monitor Microsoft ATA 1.7 Gateway - There is a host entry in the HOSTS file pointing to the machine's shortnameMicrosoft.AdvancedThreatAnalytics.1_7.Gateway.HostEntryInHOSTSFileMicrosoft.AdvancedThreatAnalytics.1_7.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.MessageAnalyzerIsInstalledOnGatewayMessage Analyzer is installed on the ATA GatewayRule to monitor Microsoft ATA 1.7 Gateway - Message Analyzer is installed on the ATA GatewayMicrosoft.AdvancedThreatAnalytics.1_7.Gateway.MessageAnalyzerIsInstalledOnGatewayMicrosoft.AdvancedThreatAnalytics.1_7.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.NetworkActivityTranslatorMessageData0BlockSizeNetworkActivityTranslator Message Data 0 Block SizeThe amount of traffic queued for translation to Network Activities (NAs)Microsoft.AdvancedThreatAnalytics.1_7.Gateway.NetworkActivityTranslatorMessageData0BlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.GatewayPerformanceCollectionTrueMicrosoft ATA GatewayNetworkActivityTranslator Message Data 0 Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.NetworkActivityTranslatorMessageData1BlockSizeNetworkActivityTranslator Message Data 1 Block SizeThe amount of traffic queued for translation to Network Activities (NAs)Microsoft.AdvancedThreatAnalytics.1_7.Gateway.NetworkActivityTranslatorMessageData1BlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.GatewayPerformanceCollectionTrueMicrosoft ATA GatewayNetworkActivityTranslator Message Data 1 Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.NetworkActivityTranslatorMessageData2BlockSizeNetworkActivityTranslator Message Data 2 Block SizeThe amount of traffic queued for translation to Network Activities (NAs)Microsoft.AdvancedThreatAnalytics.1_7.Gateway.NetworkActivityTranslatorMessageData2BlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.GatewayPerformanceCollectionTrueMicrosoft ATA GatewayNetworkActivityTranslator Message Data 2 Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.NetworkListenerETWDroppedEvents_SecNetworkListener ETW Dropped Events/SecThe amount of traffic being dropped by the ATA Gateway every secondMicrosoft.AdvancedThreatAnalytics.1_7.Gateway.NetworkListenerETWDroppedEvents_SecMicrosoft.AdvancedThreatAnalytics.1_7.GatewayPerformanceCollectionTrueMicrosoft ATA GatewayNetworkListener ETW Dropped Events/Sec3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.NetworkListenerPEFDroppedEvents_SecNetworkListener PEF Dropped Events/SecThe amount of traffic being dropped by the ATA Gateway every secondMicrosoft.AdvancedThreatAnalytics.1_7.Gateway.NetworkListenerPEFDroppedEvents_SecMicrosoft.AdvancedThreatAnalytics.1_7.GatewayPerformanceCollectionTrueMicrosoft ATA GatewayNetworkListener PEF Dropped Events/Sec3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.NetworkListenerPEFParsedMessages_SecNetworkListener PEF Parsed Messages/SecThe amount of traffic being processed by the ATA Gateway every secondMicrosoft.AdvancedThreatAnalytics.1_7.Gateway.NetworkListenerPEFParsedMessages_SecMicrosoft.AdvancedThreatAnalytics.1_7.GatewayPerformanceCollectionTrueMicrosoft ATA GatewayNetworkListener PEF Parsed Messages/Sec3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.OtherPendingInstallationsThere are other pending installations on your computerRule to monitor Microsoft ATA 1.7 Gateway - There are other pending installations on your computerMicrosoft.AdvancedThreatAnalytics.1_7.Gateway.OtherPendingInstallationsMicrosoft.AdvancedThreatAnalytics.1_7.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.PEFWasNotInstalledCorrectlyPEF (Message Analyzer) was not installed correctlyRule to monitor Microsoft ATA 1.7 Gateway - PEF (Message Analyzer) was not installed correctlyMicrosoft.AdvancedThreatAnalytics.1_7.Gateway.PEFWasNotInstalledCorrectlyMicrosoft.AdvancedThreatAnalytics.1_7.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.PIDsWasEnabledForProcessNamesInGatewayPIDs was enabled for process names in the ATA GatewayRule to monitor Microsoft ATA 1.7 Gateway - PIDs was enabled for process names in the ATA GatewayMicrosoft.AdvancedThreatAnalytics.1_7.Gateway.PIDsWasEnabledForProcessNamesInGatewayMicrosoft.AdvancedThreatAnalytics.1_7.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue