All Rules in Microsoft.IntelligencePacks.ThreatDetection Management Pack

 DisplayNameDescriptionIDTargetCategoryEnabledInstance NameCounter NameFrequencyEvent_IDEvent SourceAlert GenerateAlert SeverityAlert PriorityRemotableEvent Log
Microsoft.RomeDetection.EnableAscPoliciesMicrosoft Azure Security Center policies runnerEnable all the required policies for Azure Security Center detection engineMicrosoft.RomeDetection.EnableAscPoliciesMicrosoft.Windows.ComputerCustomFalse00FalseFalse
Microsoft.RomeDetection.EnableAscPolicies.CollectRuleErrorsMonitoring - Microsoft Azure Security Center policies runnerCollects error events from Microsoft Azure Security Center policies runner rules for monitoring purposesMicrosoft.RomeDetection.EnableAscPolicies.CollectRuleErrorsMicrosoft.Windows.ComputerCustomFalse00FalseFalse
Microsoft.SystemCenter.AppLockerEventExeAndDll.CollectRuleErrorsMonitoring - AppLocker events of type EXE and DLLCollects error events from AppLocker events of type EXE and DLL rules for monitoring purposesMicrosoft.SystemCenter.AppLockerEventExeAndDll.CollectRuleErrorsMicrosoft.Windows.ComputerCustomFalse00FalseFalse
Microsoft.SystemCenter.AppLockerEventMsiAndScript.CollectRuleErrorsMonitoring - AppLocker events of type MSI and ScriptCollects error events from AppLocker events of type MSI and Script rules for monitoring purposesMicrosoft.SystemCenter.AppLockerEventMsiAndScript.CollectRuleErrorsMicrosoft.Windows.ComputerCustomFalse00FalseFalse
Microsoft.SystemCenter.CollectAppLockerEventExeAndDllCollect AppLocker EventsThis rule collects events from the AppLocker EXE and DLL event log and sends them to the cloudMicrosoft.SystemCenter.CollectAppLockerEventExeAndDllMicrosoft.Windows.ComputerEventCollectionFalse00FalseTrueMicrosoft-Windows-AppLocker/EXE and DLL
Microsoft.SystemCenter.CollectAppLockerEventMsiAndScriptCollect AppLocker EventsThis rule collects events from the AppLocker MSI and Script event log and sends them to the cloudMicrosoft.SystemCenter.CollectAppLockerEventMsiAndScriptMicrosoft.Windows.ComputerEventCollectionFalse00FalseTrueMicrosoft-Windows-AppLocker/MSI and Script
Microsoft.SystemCenter.CollectThreatDetectionSecurityEventCollect Security EventsThis rule collects events from the Security event log and sends them to the cloudMicrosoft.SystemCenter.CollectThreatDetectionSecurityEventMicrosoft.Windows.ComputerEventCollectionFalse00FalseTrueSecurity
Microsoft.SystemCenter.CollectThreatDetectionSystemEventCollect System EventsThis rule collects events from the System event log and sends them to the cloudMicrosoft.SystemCenter.CollectThreatDetectionSystemEventMicrosoft.Windows.ComputerEventCollectionFalse00FalseTrueSystem
Microsoft.SystemCenter.ThreatDetection.CollectRuleErrors.SecurityEventMonitoring - Threat detection security eventsCollects error events from threat detection security event rules for monitoring purposesMicrosoft.SystemCenter.ThreatDetection.CollectRuleErrors.SecurityEventMicrosoft.Windows.ComputerCustomFalse00FalseFalse
Microsoft.SystemCenter.ThreatDetection.CollectRuleErrors.SystemEventMonitoring - Threat detection system eventsCollects error events from threat detection system event rules for monitoring purposesMicrosoft.SystemCenter.ThreatDetection.CollectRuleErrors.SystemEventMicrosoft.Windows.ComputerCustomFalse00FalseFalse