// Nach Log-Kanal
- Alle
- AppLocker
- Aufgabenplanung
- BITS
- Defender
- Directory Service
- NTLM
- PowerShell
- Remote-Zugriff
- Security
- Sysmon
- System
- WMI
// Nach MITRE-Taktik
- Initial Access
- Execution
- Persistence
- Privilege Escalation
- Defense Evasion
- Credential Access
- Discovery
- Lateral Movement
- Collection
- Command and Control
- Impact
| ID | Bedeutung | Kanal | Relevanz | MITRE |
|---|---|---|---|---|
| 2889 | Unsignierte LDAP-Anmeldung am Domain Controller | Directory Service | mittel | T1557, T1040 |
| 4663 | Zugriff auf ein Objekt | Security | mittel | T1555.003, T1005, T1486 |
| 5142 | Netzwerkfreigabe angelegt, geändert oder gelöscht | Security | mittel | T1074.002, T1570 |
| 8004 | NTLM-Authentifizierung am Domain Controller | NTLM | mittel | T1550.002, T1557.001 |