// Nach Log-Kanal
- Alle
- AppLocker
- Aufgabenplanung
- BITS
- Defender
- Directory Service
- NTLM
- PowerShell
- Remote-Zugriff
- Security
- Sysmon
- System
- WMI
// Nach MITRE-Taktik
- Initial Access
- Execution
- Persistence
- Privilege Escalation
- Defense Evasion
- Credential Access
- Discovery
- Lateral Movement
- Collection
- Command and Control
- Impact
| ID | Bedeutung | Kanal | Relevanz | MITRE |
|---|---|---|---|---|
| 7 | Image geladen | Sysmon | mittel | T1574.001, T1620, T1003.001 |
| 9 | Direkter Lesezugriff auf ein Laufwerk | Sysmon | hoch | T1003.003, T1006 |
| 10 | Prozesszugriff | Sysmon | hoch | T1003.001, T1055 |
| 11 | Datei erstellt | Sysmon | mittel | T1105, T1547.001, T1003.001, T1486 |
| 1121 | ASR-Regel hat blockiert oder im Audit ausgelöst | Defender | hoch | T1566.001, T1003.001, T1047 |
| 2889 | Unsignierte LDAP-Anmeldung am Domain Controller | Directory Service | mittel | T1557, T1040 |
| 4625 | Fehlgeschlagene Anmeldung | Security | hoch | T1110.001, T1110.003, T1133 |
| 4662 | Operation an AD-Objekt (DCSync) | Security | hoch | T1003.006 |
| 4663 | Zugriff auf ein Objekt | Security | mittel | T1555.003, T1005, T1486 |
| 4673 | Privilegierter Dienst aufgerufen | Security | mittel | T1134, T1558 |
| 4738 | Benutzerkonto geändert | Security | mittel | T1098, T1558.004 |
| 4740 | Benutzerkonto gesperrt | Security | mittel | T1110.001 |
| 4767 | Benutzerkonto entsperrt | Security | niedrig | T1110, T1098 |
| 4768 | Kerberos-TGT angefordert | Security | hoch | T1558.004, T1087.002 |
| 4769 | Kerberos-Diensticket angefordert | Security | hoch | T1558.003, T1558.001 |
| 4771 | Kerberos-Vorauthentifizierung fehlgeschlagen | Security | hoch | T1110.001, T1110.003 |
| 4776 | NTLM-Anmeldedaten geprüft | Security | hoch | T1110.003, T1110.001, T1550.002 |
| 4887 | Zertifikat angefordert und ausgestellt | Security | hoch | T1649 |
| 5136 | Verzeichnisobjekt geändert | Security | hoch | T1484.001, T1098, T1556, T1558.003 |
| 5379 | Anmeldeinformationen aus der Anmeldeinformationsverwaltung gelesen | Security | mittel | T1555.004 |
| 8004 | NTLM-Authentifizierung am Domain Controller | NTLM | mittel | T1550.002, T1557.001 |
// Artikel zum Thema