Changelog for Security.Monitoring Management Pack

1.0.7.1 [...]

TypeNameChange
DataSourceModuleTypeSecurityMonitoringMP.LocalAccountChange.DSAdded
DataSourceModuleTypeSecurityMonitoringMP.Modules.SecurityLogClear.DSAdded
DataSourceModuleTypeSecurityMonitoringMP.Modules.SystemLogClear.DSAdded
DataSourceModuleTypeSecurityMonitoringMP.SuspiciousUserContext.DSAdded
DataSourceModuleTypeSecurityMonitoringMP.4688CommandAudit.DSChanged
DataSourceModuleTypeSecurityMonitoringMP.DCServiceCreation.DSChanged
DataSourceModuleTypeSecurityMonitoringMP.GPOMonitoring.GPOEvent.DSChanged
DataSourceModuleTypeSecurityMonitoringMP.WriteableDirectories.DSChanged
MonitorPropertyOverrideOverrideForMonitorSecurityMonitoringMPUseLogonCredentialExistsMonitor.Server2012R2Deleted
ReferencesSecurity.MonitoringChanged
RuleSecurity.Monitoring.SecurityLogClearedv2Added
RuleSecurity.Monitoring.SuspiciousUserContextAdded
RuleSecurity.Monitoring.SystemLogClearedv2Added
RuleSecurity.Monitoring.Event.ByPassExecutionPolicyChanged
RuleSecurity.Monitoring.Event.InvokeEncodedCommandChanged
RuleSecurity.Monitoring.Event.InvokeRemoteExpressionChanged
RuleSecurity.Monitoring.Event.PowerShellRuninMemoryOnlyChanged
RuleSecurity.Monitoring.SecurityMonitoring.Event.GPOCreationChanged
RuleSecurity.Monitoring.SecurityMonitoring.Event.GPODeletionRuleChanged
RuleSecurityMonitoring.Event.FailedLoginChanged
RuleSecurityMonitoringMP.Accounts.LocalAdminChangeChanged
RuleSecurityMonitoringMP.Event.SecurityLogClearedChanged
RuleSecurityMonitoringMP.Event.SystemLogClearedChanged

1.0.6.0 [...]

TypeNameChange
AggregateMonitorSecurity.Monitoring.DCAuditSettingsAdded
AggregateMonitorSecurity.Monitoring.MemberServerAuditSettingsAdded
ClassTypeSecurity.Monitoring.AdminAccountsAdded
ClassTypeSecurity.Monitoring.SecurityMonitoringDAAdded
ClassTypeSecurity.Monitoring.SecurityMonitoringDA.DomainControllersAdded
ClassTypeSecurity.Monitoring.SecurityMonitoringDA.MemberServersAdded
ClassTypeSecurity.Monitoring.WindowsComputersExtendedWriteableDirectoryMonitoringAdded
ClassTypeSecurity.Monitoring.WriteableLocationsAdded
ClassTypeSecurity.Monitoring.WriteableLocationsSeedClassAdded
DataSourceModuleTypeSecurity.Monitoring.AuditPol.DSAdded
DataSourceModuleTypeSecurity.Monitoring.DistributedApplication.DataSourceAdded
DataSourceModuleTypeSecurity.Monitoring.DistributedApplicationMS.DataSourceAdded
DataSourceModuleTypeSecurityMonitoringMP.4688CommandAudit.DSAdded
DataSourceModuleTypeSecurityMonitoringMP.DCServiceCreation.DSAdded
DataSourceModuleTypeSecurityMonitoringMP.Discoveries.DiscoverWriteableFileLocationsAdded
DataSourceModuleTypeSecurityMonitoringMP.ScheduledTaskCreation.DSAdded
DataSourceModuleTypeSecurityMonitoringMP.WriteableDirectories.DSAdded
DataSourceModuleTypeSecurityMonitoringMP.WriteableDirectoriesExtended.DSAdded
DataSourceModuleTypeSecurity.Monitoring.SMBv1Connections.DSChanged
DependencyMonitorSecurity.Monitoring.AccountLogonForDCAdded
DependencyMonitorSecurity.Monitoring.AccountLogonForMSAdded
DependencyMonitorSecurity.Monitoring.DCConfigGroupRollupAdded
DependencyMonitorSecurity.Monitoring.DCDirectoryServicesAuditAdded
DependencyMonitorSecurity.Monitoring.IncludeCommandLineonDCsAdded
DependencyMonitorSecurity.Monitoring.IncludeCommandLineonMSAdded
DependencyMonitorSecurity.Monitoring.MemberServerProcessCreationAdded
DependencyMonitorSecurity.Monitoring.SecurityGroupManagementforDCAdded
DependencyMonitorSecurity.Monitoring.SpecialGroupLogonDCAdded
DependencyMonitorSecurity.Monitoring.SpecialGroupLogonMSAdded
DependencyMonitorSecurity.Monitoring.UserAcctforMSAdded
DiscoverySecurity.Monitoring.AdminAccountDiscoveryAdded
DiscoverySecurity.Monitoring.DA.DCDiscoveryAdded
DiscoverySecurity.Monitoring.DA.MSDiscoveryAdded
DiscoverySecurity.Monitoring.Discoveries.UserWriteableLocationSeedAdded
DiscoverySecurity.Monitoring.DiscoverWriteableFileLocationsAdded
DiscoverySecurity.Monitoring.PopulateExtendedWriteableDirectoryComputerGroupAdded
FolderSecurityMonitoringMP.Folder.AdministrationAdded
FolderItemi23e6b51216814447b3b73c5124fae3d3Added
FolderItemi2465151f071a4563af2090f8f6f734ceAdded
FolderItemibbd540dc68af4043bfdb9f75cf03ae00Added
FolderItemif879997c69ee482abc74aca8ebbe4367Added
MonitorPropertyOverrideOverrideForMonitorSecurityMonitoringAccountLogonAuditingMemberServerForContextMicrosoftSystemCenterManagementServerComputersGroupAdded
MonitorPropertyOverrideOverrideForMonitorSecurityMonitoringCommandLineAuditingMemberServerForContextMicrosoftSystemCenterManagementServerComputersGroupAdded
MonitorPropertyOverrideOverrideForMonitorSecurityMonitoringProcessCreationMemberServerForContextMicrosoftSystemCenterManagementServerComputersGroupAdded
MonitorPropertyOverrideOverrideForMonitorSecurityMonitoringSpecialGroupLogonMemberServerForContextMicrosoftSystemCenterManagementServerComputersGroupAdded
MonitorPropertyOverrideOverrideForMonitorSecurityMonitoringUserAccountManagementAuditingMemberServerForContextMicrosoftSystemCenterManagementServerComputersGroupAdded
ProbeActionModuleTypeSecurity.Monitoring.AuditPol.PowerShellAdded
ProbeActionModuleTypeSecurity.Monitoring.SMBv1Connections.PowerShellChanged
ReferencesSecurity.MonitoringChanged
RelationshipTypeSecurity.Monitoring.SecurityMonitoringDARelationshipsAdded
RelationshipTypeSecurity.Monitoring.SecurityMonitoringDARelationshipsForDCsAdded
RelationshipTypeSecurity.Monitoring.SecurityMonitoringDARelationshipsForMemberServersAdded
RelationshipTypeSecurity.Monitoring.SecurityMonitoringDARelationshipsforMSAdded
ReportSecurity.Monitoring.LegacyTLSConnectionReportAdded
ReportResourceLegacyTLSConnectionReport.IDAdded
RuleSecurity.Monitoring.CollectLegacyTLSEventsAdded
RuleSecurity.Monitoring.Event.ByPassExecutionPolicyAdded
RuleSecurity.Monitoring.Event.InvokeEncodedCommandAdded
RuleSecurity.Monitoring.Event.InvokeRemoteExpressionAdded
RuleSecurity.Monitoring.Event.KillWindowsDefenderAdded
RuleSecurity.Monitoring.Event.PowerShellRuninMemoryOnlyAdded
RuleSecurity.Monitoring.Event.WMIPersistenceAdded
RuleSecurity.Monitoring.Event.WMIRemote.DestinationAdded
RuleSecurity.Monitoring.Event.WMIRemote.SourceAdded
RuleSecurity.Monitoring.ExecutableRunFromUserWriteableDirectoryAdded
RuleSecurity.Monitoring.ExecutableRuninWriteableDirectoriesExtendedAdded
RuleSecurity.Monitoring.ForwardedEvents.ByPassExecutionPolicyAdded
RuleSecurity.Monitoring.ForwardedEvents.ExecutableRunFromUserWriteableDirectoryAdded
RuleSecurity.Monitoring.ForwardedEvents.InvokeEncodedCommandAdded
RuleSecurity.Monitoring.ForwardedEvents.InvokeRemoteExpressionAdded
RuleSecurity.Monitoring.ForwardedEvents.KillWindowsDefenderAdded
RuleSecurity.Monitoring.ForwardedEvents.PowerShellRuninMemoryOnlyAdded
RuleSecurity.Monitoring.SecurityMonitoring.Event.ScheduledTaskCreatedOnServerAdded
RuleSecurity.Monitoring.SecurityMonitoring.Event.ServiceCreatedonDCAdded
RuleSecurity.Monitoring.Collect.SMBv1ConnectionsChanged
RuleSecurity.Monitoring.Event.RemoteRegSvr32Changed
RuleSecurity.Monitoring.ForwardedEvents.4688.GenericCryptoRansomWareChanged
RuleSecurity.Monitoring.ForwardedEvents.RemoteRegSvr32Changed
RuleSecurityMonitoringMP.Event.4688.SuspiciousApplockerJavaChanged
RuleSecurityMonitoringMP.Event.4688.SuspiciousApplockerRegsvrChanged
RuleSecurityMonitoringMP.Event.4688.SuspiciousCMDChanged
RuleSecurityMonitoringMP.Event.4688.SuspiciousFTPCommandChanged
RuleSecurityMonitoringMP.Event.4688.SuspiciousRegChanged
RuleSecurityMonitoringMP.Event.4688.SuspiciousWindowsPositionChanged
RuleSecurityMonitoringMP.ForwardedEvents.4688.SuspiciousApplockerJavaChanged
RuleSecurityMonitoringMP.ForwardedEvents.4688.SuspiciousApplockerRegsvrChanged
RuleSecurityMonitoringMP.ForwardedEvents.4688.SuspiciousCMDChanged
RuleSecurityMonitoringMP.ForwardedEvents.4688.SuspiciousFTPCommandChanged
RuleSecurityMonitoringMP.ForwardedEvents.4688.SuspiciousRegChanged
RuleSecurityMonitoringMP.ForwardedEvents.4688.SuspiciousWindowsPositionChanged
RuleSecurityMonitoringMP.ThreatHunt.BatchLogonInUseChanged
RuleSecurityMonitoringMP.Event.ScheduledTaskCreationDeleted
RuleSecurityMonitoringMP.Event.ServiceCreatedonDCDeleted
RulePropertyOverrideOverrideForRuleSecurityMonitoringExecutableRunFromUserWriteableDirectoryAdded
RulePropertyOverrideOverrideForRuleSecurityMonitoringMPEventLocalAccountCreatedonServer.DomainControllersAdded
RulePropertyOverrideOverrideForRuleSecurityMonitoringMPEventLocalAdminChange.DomainControllersAdded
RulePropertyOverrideOverrideForRuleSecurityMonitoringMP.Pth.PtHAgainstTier1.ServerDCComputerDeleted
RulePropertyOverrideOverrideForRuleSecurityMonitoringMP.Pth.PtHAgainstTier1.SQLComputerDeleted
TaskSecurityMonitoring.PowerShell.Task.CreateUserWriteableRegKeyAdded
TaskSecurityMonitoring.PowerShell.Task.RemoveUserWriteableRegKeyAdded
UnitMonitorSecurity.Monitoring.AuditAccountLogonDCAdded
UnitMonitorSecurity.Monitoring.AuditAccountLogonMSAdded
UnitMonitorSecurity.Monitoring.DirectoryServiceChangeAuditingAdded
UnitMonitorSecurity.Monitoring.IncludeCommandLineProcessCreationonDCsAdded
UnitMonitorSecurity.Monitoring.IncludeCommandLineProcessCreationonMSAdded
UnitMonitorSecurity.Monitoring.ProcessCreationMemberServerAdded
UnitMonitorSecurity.Monitoring.SecurityAudit.ProcessCreationDCAdded
UnitMonitorSecurity.Monitoring.SGManagementDCAdded
UnitMonitorSecurity.Monitoring.SpecialGroupLogonAuditingEnabledonDCAdded
UnitMonitorSecurity.Monitoring.SpecialGroupLogonEnabledOnMemberServersAdded
UnitMonitorSecurity.Monitoring.UserAccountMgmtMSAdded
UnitMonitorSecurityMonitoringMP.UseLogonCredentialExistsMonitorChanged
UnitMonitorTypeSecurity.Monitoring.AuditPolMonitorTypeAdded
UnitMonitorTypeSecurityMonitoringMP.CommandLineAuditSettingAdded
UnitMonitorTypeCheckRegValueChanged
ViewSecurityMonitoringMP.View.DADocumentationAdded
ViewSecurityMonitoringMP.View.DCDistributedAppAdded
ViewSecurityMonitoringMP.View.MemberServerDistributedAppAdded
ViewSecurityMonitoringMP.View.OnlineDocumentationAdded

1.0.4.272 [...]

TypeNameChange
DataSourceModuleTypeSecurity.Monitoring.MultiStringRegistry.DSAdded
DataSourceModuleTypeSecurity.Monitoring.SMBv1Connections.DSAdded
DataSourceModuleTypeSecurityMonitoring.Event.RepeatedFailedLogind.DSAdded
DataSourceModuleTypeSecurityMonitoringMP.GPOMonitoring.GPOEvent.DSAdded
DataSourceModuleTypeSecurityMonitoringMP.GPOMonitoring.Event.DSChanged
ProbeActionModuleTypeSecurity.Monitoring.MultiStringRegistry.PowerShellAdded
ProbeActionModuleTypeSecurity.Monitoring.SMBv1Connections.PowerShellAdded
ReportSecurity.Monitoring.AlertSummaryAdded
ReportSecurity.Monitoring.BatchLogonReportAdded
ReportSecurity.Monitoring.EventCollectionSummaryAdded
ReportSecurity.Monitoring.LanManConnectionReportAdded
ReportSecurity.Monitoring.NTLMv1ConnectionReportAdded
ReportSecurity.Monitoring.SMBv1ConnectionReportAdded
ReportSecurity.Monitoring.WDigestConnectionReportAdded
ReportResourceAlertSummary.IDAdded
ReportResourceBatchLogonReport.IDAdded
ReportResourceEventCollectionSummary.IDAdded
ReportResourceLanManConnectionReport.IDAdded
ReportResourceNTLMv1ConnectionReport.IDAdded
ReportResourceSMBv1ConnectionReport.IDAdded
ReportResourceWDigestConnectionReport.IDAdded
ReportResourceFailedLoginDetails.IDChanged
ReportResourceFailedLoginSummary.IDChanged
ReportResourceFailedLoginSummary24.IDChanged
RuleSecurity.Monitoring.Collect.SMBv1ConnectionsAdded
RuleSecurity.Monitoring.CollectionRule.CollectLAPSEventsAdded
RuleSecurity.Monitoring.Event.4688.GenericCryptoRansomWareAdded
RuleSecurity.Monitoring.Event.RemoteRegSvr32Added
RuleSecurity.Monitoring.Event.SeDebugPrivilegeEscalationAdded
RuleSecurity.Monitoring.EventCollection.LanManAdded
RuleSecurity.Monitoring.EventCollection.NTLMV1Added
RuleSecurity.Monitoring.EventCollection.WdigestAuthenticationAdded
RuleSecurity.Monitoring.ForwardedEvents.4688.GenericCryptoRansomWareAdded
RuleSecurity.Monitoring.ForwardedEvents.CollectLAPSEventsAdded
RuleSecurity.Monitoring.ForwardedEvents.DebugEscalationAdded
RuleSecurity.Monitoring.ForwardedEvents.FindAVSignatureAdded
RuleSecurity.Monitoring.ForwardedEvents.GetDLLLoadPathAdded
RuleSecurity.Monitoring.ForwardedEvents.GetHTTPStatusAdded
RuleSecurity.Monitoring.ForwardedEvents.GetKeystrokeAdded
RuleSecurity.Monitoring.ForwardedEvents.InvokeDLLInjectionAdded
RuleSecurity.Monitoring.ForwardedEvents.InvokeMimikatzAdded
RuleSecurity.Monitoring.ForwardedEvents.InvokeNinjaCopyAdded
RuleSecurity.Monitoring.ForwardedEvents.InvokePortScanAdded
RuleSecurity.Monitoring.ForwardedEvents.InvokeShellCodeInUseAdded
RuleSecurity.Monitoring.ForwardedEvents.PowerShellStartHiddenProcessAdded
RuleSecurity.Monitoring.ForwardedEvents.RemoteRegSvr32Added
RuleSecurity.Monitoring.PowerShellLog.FindAVSignatureAdded
RuleSecurity.Monitoring.PowerShellLog.GetDLLLoadPathAdded
RuleSecurity.Monitoring.PowerShellLog.GetHTTPStatusAdded
RuleSecurity.Monitoring.PowerShellLog.GetKeystrokeAdded
RuleSecurity.Monitoring.PowerShellLog.InvokeDLLInjectionAdded
RuleSecurity.Monitoring.PowerShellLog.InvokeMimikatzInUseAdded
RuleSecurity.Monitoring.PowerShellLog.InvokeNinjaCopyAdded
RuleSecurity.Monitoring.PowerShellLog.InvokePortScanAdded
RuleSecurity.Monitoring.PowerShellLog.InvokeShellCodeInUseAdded
RuleSecurity.Monitoring.PowerShellLog.PowerShellStartHiddenProcessAdded
RuleSecurity.Monitoring.SecurityMonitoring.Event.DCOUModifyAdded
RuleSecurity.Monitoring.SecurityMonitoring.Event.GPOCreationAdded
RuleSecurity.Monitoring.SecurityMonitoring.Event.GPODeletionRuleAdded
RuleSecurityMonitoring.Event.FailedLoginChanged
RuleSecurityMonitoringMP.Accounts.DomainAdminChangeChanged
RuleSecurityMonitoringMP.Accounts.EnterpriseAdminChangeChanged
RuleSecurityMonitoringMP.Accounts.LocalAdminChangeChanged
RuleSecurityMonitoringMP.Accounts.SchemaAdminChangeChanged
RuleSecurityMonitoringMP.APPLocker.MimikatzChanged
RuleSecurityMonitoringMP.APPLocker.ProhibitedAppChanged
RuleSecurityMonitoringMP.APPLocker.PSExecChanged
RuleSecurityMonitoringMP.APPLocker.WCEChanged
RuleSecurityMonitoringMP.APPLocker.WinRarChanged
RuleSecurityMonitoringMP.Event.4688.SuspiciousApplockerJavaChanged
RuleSecurityMonitoringMP.Event.4688.SuspiciousApplockerRegsvrChanged
RuleSecurityMonitoringMP.Event.4688.SuspiciousCMDChanged
RuleSecurityMonitoringMP.Event.4688.SuspiciousFTPCommandChanged
RuleSecurityMonitoringMP.Event.4688.SuspiciousRegChanged
RuleSecurityMonitoringMP.Event.4688.SuspiciousWindowsPositionChanged
RuleSecurityMonitoringMP.Event.GoldenTicketDetectionChanged
RuleSecurityMonitoringMP.Event.LocalAccountCreatedonServerChanged
RuleSecurityMonitoringMP.Event.ScheduledTaskCreationChanged
RuleSecurityMonitoringMP.Event.SecurityLogClearedChanged
RuleSecurityMonitoringMP.Event.ServiceCreatedonDCChanged
RuleSecurityMonitoringMP.Event.ServiceCreatedonMemberServerChanged
RuleSecurityMonitoringMP.Event.ServiceKnownThreatChanged
RuleSecurityMonitoringMP.Event.SmartCardDisabledChanged
RuleSecurityMonitoringMP.Event.SoftwareInstallOnServerChanged
RuleSecurityMonitoringMP.Event.SoftwareRemovedFromServerChanged
RuleSecurityMonitoringMP.Event.SystemLogClearedChanged
RuleSecurityMonitoringMP.Event.SystemPoweredOffChanged
RuleSecurityMonitoringMP.Event.SystemRestartedChanged
RuleSecurityMonitoringMP.Event.UnexpectedShutdownChanged
RuleSecurityMonitoringMP.ForwardedEvents.4688.SuspiciousApplockerJavaChanged
RuleSecurityMonitoringMP.ForwardedEvents.4688.SuspiciousApplockerRegsvrChanged
RuleSecurityMonitoringMP.ForwardedEvents.4688.SuspiciousCMDChanged
RuleSecurityMonitoringMP.ForwardedEvents.4688.SuspiciousFTPCommandChanged
RuleSecurityMonitoringMP.ForwardedEvents.4688.SuspiciousRegChanged
RuleSecurityMonitoringMP.ForwardedEvents.4688.SuspiciousWindowsPositionChanged
RuleSecurityMonitoringMP.ForwardedEvents.CredentialSwapChanged
RuleSecurityMonitoringMP.ForwardedEvents.LocalUserCreatedDeletedChanged
RuleSecurityMonitoringMP.ForwardedEvents.ProhibitedAppChanged
RuleSecurityMonitoringMP.ForwardedEvents.PtHTier2Changed
RuleSecurityMonitoringMP.ForwardedEvents.SecurityLogClearedChanged
RuleSecurityMonitoringMP.ForwardedEvents.ServiceCreationChanged
RuleSecurityMonitoringMP.ForwardedEvents.ServiceCreationKnownThreatsChanged
RuleSecurityMonitoringMP.ForwardedEvents.SpecialGroupLogonChanged
RuleSecurityMonitoringMP.ForwardedEvents.SystemLogClearedChanged
RuleSecurityMonitoringMP.GPOMonitoring.EventAndScript.RuleChanged
RuleSecurityMonitoringMP.Pth.CredentialSwapChanged
RuleSecurityMonitoringMP.Pth.PtHAgainstDCChanged
RuleSecurityMonitoringMP.Pth.PtHAgainstTier1Changed
RuleSecurityMonitoringMP.ThreatHunt.BatchLogonInUseChanged
RuleSecurityMonitoringMP.ThreatHunt.SpecialGroupLogonChanged
RuleSecurityMonitoringMP.Event.GPOCreationDeleted
RuleSecurityMonitoringMP.Event.GPODelectionDeleted
RuleSecurityMonitoringMP.ForwardedEvents.PowerSploitDeleted
RuleSecurityMonitoringMP.PowerShellLog.PowerSploitDeleted
RuleSecurityMonitoringMP.ThreatHunt.GoldenTicketDeleted
RulePropertyOverrideOverrideForRuleSecurityMonitoringEventSeDebugPrivilegeEscalationAdded
RulePropertyOverrideOverrideForRuleSecurityMonitoringMPEventLocalAccountCreatedonServer.DomainControllersDeleted
UnitMonitorSecurity.Monitoring.Monitors.AuthenticationPackagesAdded
UnitMonitorSecurityMonitoringMP.Event.RepeatedLogonMonitorChanged
UnitMonitorSecurityMonitoringMP.WDigestRegConfiguredMonitorChanged
UnitMonitorTypeCheckRegValueAdded
UnitMonitorTypeCheckRegValueStringAdded
UnitMonitorTypeMultiStringRegMonitorTypeAdded

1.0.3.5 [...]

 FIRST VERSION OF THIS MANAGEMENT PACK