mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-09-29 02:24:53 +02:00
207 lines
4.4 KiB
JSON
207 lines
4.4 KiB
JSON
{
|
|
"schemaVersion": 1,
|
|
"id": "microsoft-wef-appendix-c",
|
|
"scope": "native-channel-settings-only",
|
|
"source": "https://learn.microsoft.com/en-us/windows/security/operating-system-security/device-management/use-windows-event-forwarding-to-assist-in-intrusion-detection",
|
|
"reviewed": "2026-09-19",
|
|
"controls": [
|
|
{
|
|
"channel": "Microsoft-Windows-CAPI2/Operational",
|
|
"enabled": true,
|
|
"sourceExampleBytes": 102432768,
|
|
"readerSid": "S-1-5-32-573",
|
|
"readerMask": 1
|
|
},
|
|
{
|
|
"channel": "Microsoft-Windows-AppLocker/EXE and DLL",
|
|
"enabled": null,
|
|
"sourceExampleBytes": 102432768,
|
|
"readerSid": null,
|
|
"readerMask": null
|
|
},
|
|
{
|
|
"channel": "Microsoft-Windows-DriverFrameworks-UserMode/Operational",
|
|
"enabled": true,
|
|
"sourceExampleBytes": 52432896,
|
|
"readerSid": null,
|
|
"readerMask": null
|
|
}
|
|
],
|
|
"querySets": {
|
|
"Baseline": {
|
|
"channels": [
|
|
{
|
|
"name": "Application",
|
|
"queryIds": [
|
|
"15",
|
|
"37",
|
|
"40"
|
|
]
|
|
},
|
|
{
|
|
"name": "Microsoft-Windows-AppLocker/EXE and DLL",
|
|
"queryIds": [
|
|
"1"
|
|
]
|
|
},
|
|
{
|
|
"name": "Microsoft-Windows-AppLocker/MSI and Script",
|
|
"queryIds": [
|
|
"1"
|
|
]
|
|
},
|
|
{
|
|
"name": "Microsoft-Windows-AppLocker/Packaged app-Deployment",
|
|
"queryIds": [
|
|
"11"
|
|
]
|
|
},
|
|
{
|
|
"name": "Microsoft-Windows-AppLocker/Packaged app-Execution",
|
|
"queryIds": [
|
|
"10"
|
|
]
|
|
},
|
|
{
|
|
"name": "Microsoft-Windows-SMBClient/Operational",
|
|
"queryIds": [
|
|
"36"
|
|
]
|
|
},
|
|
{
|
|
"name": "Microsoft-Windows-SmartCard-Audit/Authentication",
|
|
"queryIds": [
|
|
"35"
|
|
]
|
|
},
|
|
{
|
|
"name": "Microsoft-Windows-TaskScheduler/Operational",
|
|
"queryIds": [
|
|
"3"
|
|
]
|
|
},
|
|
{
|
|
"name": "Microsoft-Windows-TerminalServices-RDPClient/Operational",
|
|
"queryIds": [
|
|
"31"
|
|
]
|
|
},
|
|
{
|
|
"name": "Microsoft-Windows-Windows Defender/Operational",
|
|
"queryIds": [
|
|
"41"
|
|
]
|
|
},
|
|
{
|
|
"name": "Security",
|
|
"queryIds": [
|
|
"2",
|
|
"5",
|
|
"6",
|
|
"7",
|
|
"8",
|
|
"14",
|
|
"16",
|
|
"18",
|
|
"19",
|
|
"20",
|
|
"21",
|
|
"22",
|
|
"23",
|
|
"26",
|
|
"27",
|
|
"28",
|
|
"29",
|
|
"30",
|
|
"32",
|
|
"34",
|
|
"42"
|
|
]
|
|
},
|
|
{
|
|
"name": "System",
|
|
"queryIds": [
|
|
"0",
|
|
"3",
|
|
"4",
|
|
"5",
|
|
"9",
|
|
"13",
|
|
"17"
|
|
]
|
|
}
|
|
],
|
|
"excludedQueries": [
|
|
{
|
|
"queryId": "12",
|
|
"reason": "EMET is not built in"
|
|
},
|
|
{
|
|
"queryId": "39",
|
|
"reason": "Sysmon is out of scope"
|
|
}
|
|
]
|
|
},
|
|
"Suspect": {
|
|
"channels": [
|
|
{
|
|
"name": "Microsoft-Windows-CAPI2/Operational",
|
|
"queryIds": [
|
|
"2"
|
|
]
|
|
},
|
|
{
|
|
"name": "Microsoft-Windows-DNS-Client/Operational",
|
|
"queryIds": [
|
|
"7"
|
|
]
|
|
},
|
|
{
|
|
"name": "Microsoft-Windows-DriverFrameworks-UserMode/Operational",
|
|
"queryIds": [
|
|
"13"
|
|
]
|
|
},
|
|
{
|
|
"name": "Microsoft-Windows-LSA/Operational",
|
|
"queryIds": [
|
|
"4"
|
|
]
|
|
},
|
|
{
|
|
"name": "Microsoft-Windows-PowerShell/Operational",
|
|
"queryIds": [
|
|
"12"
|
|
]
|
|
},
|
|
{
|
|
"name": "Security",
|
|
"queryIds": [
|
|
"0",
|
|
"3",
|
|
"5",
|
|
"6",
|
|
"8",
|
|
"9",
|
|
"10",
|
|
"11"
|
|
]
|
|
},
|
|
{
|
|
"name": "System",
|
|
"queryIds": [
|
|
"1"
|
|
]
|
|
},
|
|
{
|
|
"name": "Windows PowerShell",
|
|
"queryIds": [
|
|
"14"
|
|
]
|
|
}
|
|
],
|
|
"excludedQueries": []
|
|
}
|
|
}
|
|
}
|