Showing 399 of 399 events
Complete Security.evtx Event ID reference. Criticality tiers (High / Medium / Low) sourced directly from Microsoft Appendix L: Events to Monitor. High = investigate every occurrence. Medium = investigate if unexpected or volume exceeds baseline. Low = baseline/informational.
60 curated highest-signal Sigma rules from SigmaHQ/sigma that use Windows Security event IDs as their primary log source. Each rule links to the raw YAML on GitHub. Rules are organized by tactic โ click any Event ID chip to jump to that event in the reference tab.
These are behavioral detections โ field-level conditions require a SIEM with parsed event fields. All rules are vendor-agnostic and can be converted to Splunk, Elastic, Microsoft Sentinel, QRadar, and others via sigconverter.io.