DFIR Reference v0.1

Windows Security Event IDs

Complete Security.evtx Event ID reference. Criticality tiers (High / Medium / Low) sourced directly from Microsoft Appendix L: Events to Monitor. High = investigate every occurrence. Medium = investigate if unexpected or volume exceeds baseline. Low = baseline/informational.

399Event IDs
79In Appendix L
9๐Ÿ”ด High
72๐ŸŸก Medium
Microsoft Appendix L (Criticality Source) Microsoft Security Auditing Events Spreadsheet Ultimate Windows Security
Showing 399 of 399 events
Copied!

โšก Sigma Detection Playbook โ€” Security.evtx

60 curated highest-signal Sigma rules from SigmaHQ/sigma that use Windows Security event IDs as their primary log source. Each rule links to the raw YAML on GitHub. Rules are organized by tactic โ€” click any Event ID chip to jump to that event in the reference tab.

These are behavioral detections โ€” field-level conditions require a SIEM with parsed event fields. All rules are vendor-agnostic and can be converted to Splunk, Elastic, Microsoft Sentinel, QRadar, and others via sigconverter.io.

60 detection rules 44 event IDs covered Source: SigmaHQ/sigma (DRL 1.1) Convert: sigconverter.io
โŒ•