| DisplayName | Description | ID | Target | Category | Enabled | Instance Name | Counter Name | Frequency | Event_ID | Event Source | Alert Generate | Alert Severity | Alert Priority | Remotable | Event Log |
| (Security Event ID 4728) - A member was added to a security-enabled global group | | SCC.Active.Directory.Audit.AddToGlblSecGrp | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 0 | | True | Warning | Normal | True | Security |
| An Active Directory Site was Created | | SCC.Active.Directory.Audit.ADSiteCreated | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 0 | | True | Warning | Normal | True | Security |
| An Active Directory Site was Deleted | | SCC.Active.Directory.Audit.ADSiteDeleted | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 5141 | | True | Error | Normal | True | Security |
| An Active Directory Site Link was Created | | SCC.Active.Directory.Audit.ADSiteLinkCreated | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 0 | | True | Warning | Normal | True | Security |
| An Active Directory Site Link was Deleted | | SCC.Active.Directory.Audit.ADSiteLinkDeleted | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 5141 | | True | Error | Normal | True | Security |
| An Active Directory Site has been Modified | | SCC.Active.Directory.Audit.ADSiteModified | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 5136 | | True | Warning | Normal | True | Security |
| An Active Directory Subnet was Created | | SCC.Active.Directory.Audit.ADSubnetCreated | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 5137 | | True | Warning | Normal | True | Security |
| An Active Directory Subnet was Deleted | | SCC.Active.Directory.Audit.ADSubnetDeleted | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 5141 | | True | Error | Normal | True | Security |
| An Active Directory Subnet was Modified | | SCC.Active.Directory.Audit.ADSubnetModified | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 5136 | | True | Error | Normal | True | Security |
| (Security Event ID 4723) - Change password attempt | | SCC.Active.Directory.Audit.ChgPasswordAttempt | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 0 | | True | Warning | Normal | True | Security |
| Collet Account and Group Events (misc 47XX events) (DO NOT ENABLE for development only) | 4723,4726-4729,4738,4739,4740,4754,4755,4756,4758,4764
| SCC.Active.Directory.Audit.CollectAcctGrpEvents | SCC.Active.Directory.Audit.Win2008.AuditTarget | EventCollection | False | | | 0 | 0 | | False | | | True | Security |
| Collect Event 5136: Object Modifications (DO NOT ENABLE development only) | Collects events related to directory service object modification | SCC.Active.Directory.Audit.CollEvt5136 | SCC.Active.Directory.Audit.Win2008.AuditTarget | EventCollection | False | | | 0 | 0 | | False | | | True | Security |
| Collect Event 5136: Object Creation (DO NOT ENABLE development only) | | SCC.Active.Directory.Audit.CollEvt5137 | SCC.Active.Directory.Audit.Win2008.AuditTarget | EventCollection | False | | | 0 | 0 | | False | | | True | Security |
| Collect Event 5139: Object Moved (DO NOT ENABLE development only) | | SCC.Active.Directory.Audit.CollEvt5139 | SCC.Active.Directory.Audit.Win2008.AuditTarget | EventCollection | False | | | 0 | 0 | | False | | | True | Security |
| Collect Event 5141: Object Deleted (DO NOT ENABLE development only) | | SCC.Active.Directory.Audit.CollEvt5141 | SCC.Active.Directory.Audit.Win2008.AuditTarget | EventCollection | False | | | 0 | 0 | | False | | | True | Security |
| (Security Event ID 4727) - A security-enabled global group was created | | SCC.Active.Directory.Audit.CreatedGlblSecGrp | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 0 | | True | Error | Normal | True | Security |
| (Security Event ID 4739) - Domain Policy was changed | | SCC.Active.Directory.Audit.DomainPolicyChange | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 0 | | True | Warning | Normal | True | Security |
| (Security Event ID 4730) - A security-enabled global group was deleted | | SCC.Active.Directory.Audit.Event4730 | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 0 | | True | Error | Normal | True | Security |
| A Group Policy Object (GPO) has been Created | | SCC.Active.Directory.Audit.GPOCreated | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 0 | | True | Warning | Normal | True | Security |
| A Group Policy Object (GPO) was Deleted | | SCC.Active.Directory.Audit.GPODeleted | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 0 | | True | Error | Normal | True | Security |
| A Group Policy Object (GPO) was Modified | | SCC.Active.Directory.Audit.GPOModified | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 5136 | | True | Error | Normal | True | Security |
| (Security Event ID 4713) - Kerberos policy was changed | | SCC.Active.Directory.Audit.KerbPolChg | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 0 | | True | Warning | Normal | True | Security |
| (Security Event ID 1102) - The audit log was cleared | | SCC.Active.Directory.Audit.NewElement | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 0 | | True | Warning | Normal | True | Security |
| An Organizational Unit was Created | | SCC.Active.Directory.Audit.OUCreated | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 0 | | True | Warning | Normal | True | Security |
| An Organizational Unit was Deleted | | SCC.Active.Directory.Audit.OUDeleted | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 0 | | True | Error | Normal | True | Security |
| An Organizational Unit was Modified | | SCC.Active.Directory.Audit.OUModified | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 0 | | True | Warning | Normal | True | Security |
| An Organizational Unit was Moved | | SCC.Active.Directory.Audit.OUMoved | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 0 | | True | Warning | Normal | True | Security |
| (Security Event ID 4729) - A member was removed from a security-enabled global group | | SCC.Active.Directory.Audit.RemoveFromGlblSecGrp | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 0 | | True | Warning | Normal | True | Security |
| (Security Event ID 1104) - The security event log was cleared | | SCC.Active.Directory.Audit.SecurityLogCleared | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 0 | | True | Warning | Normal | True | Security |
| (Security Event ID 4706) - A new trust was created to a domain | | SCC.Active.Directory.Audit.TrustCreated | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 0 | | True | Warning | Normal | True | Security |
| (Security Event ID 4707) - A trust to a domain was removed | | SCC.Active.Directory.Audit.TrustRemoved | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 0 | | True | Warning | Normal | True | Security |
| (Security Event ID 4755) - A security-enabled universal group was changed | This rule results in numerous non-actionable alerts during create and delete operations. Therefore, it is disabled by default. | SCC.Active.Directory.Audit.UnivGrpChanged | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | False | | | 0 | 0 | | True | Warning | Normal | True | Security |
| (Security Event ID 4754) - A security-enabled universal group was created | | SCC.Active.Directory.Audit.UnivGrpCreated | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 0 | | True | Warning | Normal | True | Security |
| (Security Event ID 4758) - A security-enabled universal group was deleted | | SCC.Active.Directory.Audit.UnivGrpDeleted | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 0 | | True | Error | Normal | True | Security |
| (Security Event ID 4756) - A member was added to a security-enabled universal group | | SCC.Active.Directory.Audit.UnivGrpMemAdded | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 0 | | True | Warning | Normal | True | Security |
| (Security Event ID 4757) - A member was removed from a security-enabled universal group | | SCC.Active.Directory.Audit.UnivGrpMemRemoved | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 0 | | True | Warning | Normal | True | Security |
| (Security Event ID 4764) - A group’s type was changed | | SCC.Active.Directory.Audit.UnivGrpTypeChanged | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 0 | | True | Error | Normal | True | Security |
| A User Account was Modified | This rule results in numerous non-actionable alerts during create and delete operations. Therefore, it is disabled by default. | SCC.Active.Directory.Audit.UserAccountChange | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 5136 | | True | Error | Normal | True | Security |
| (Security Event ID 4720) - A User Account was Created | | SCC.Active.Directory.Audit.UserAcctCreated | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 0 | | True | Warning | Normal | True | Security |
| (Security Event ID 4726) - A user account was deleted | | SCC.Active.Directory.Audit.UserAcctDeleted | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 0 | | True | Error | Normal | True | Security |
| (Security Event ID 4725) - A user account was disabled | | SCC.Active.Directory.Audit.UserAcctDisabled | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 0 | | True | Warning | Normal | True | Security |
| (Security Event ID 4740) - A user account was locked out | | SCC.Active.Directory.Audit.UserAcctLockout | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 0 | | True | Error | Normal | True | Security |
| (Security Event ID 4740) - A User Account Password was Set | | SCC.Active.Directory.Audit.UserAcctPasswordSet | SCC.Active.Directory.Audit.Win2008.AuditTarget | SecurityHealth | True | | | 0 | 0 | | True | Warning | Normal | True | Security |