Files
WELA/config/eid_subcategory_mapping-org.csv
github-actions[bot] edab9c4504 Automated update
2025-03-09 06:55:32 +00:00

5.1 KiB

1CategorySubcategoryGUID
2System69979848-797A-11D9-BED3-505054503030
3SystemSecurity State Change0CCE9210-69AE-11D9-BED3-505054503030
4SystemSecurity System Extension0CCE9211-69AE-11D9-BED3-505054503030
5SystemSystem Integrity0CCE9212-69AE-11D9-BED3-505054503030
6SystemIPsec Driver0CCE9213-69AE-11D9-BED3-505054503030
7SystemOther System Events0CCE9214-69AE-11D9-BED3-505054503030
8Logon/Logoff69979849-797A-11D9-BED3-505054503030
9Logon/LogoffLogon0CCE9215-69AE-11D9-BED3-505054503030
10Logon/LogoffLogoff0CCE9216-69AE-11D9-BED3-505054503030
11Logon/LogoffAccount Lockout0CCE9217-69AE-11D9-BED3-505054503030
12Logon/LogoffIPsec Main Mode0CCE9218-69AE-11D9-BED3-505054503030
13Logon/LogoffIPsec Quick Mode0CCE9219-69AE-11D9-BED3-505054503030
14Logon/LogoffIPsec Extended Mode0CCE921A-69AE-11D9-BED3-505054503030
15Logon/LogoffSpecial Logon0CCE921B-69AE-11D9-BED3-505054503030
16Logon/LogoffOther Logon/Logoff Events0CCE921C-69AE-11D9-BED3-505054503030
17Logon/LogoffNetwork Policy Server0CCE9243-69AE-11D9-BED3-505054503030
18Logon/LogoffUser / Device Claims0CCE9247-69AE-11D9-BED3-505054503030
19Logon/LogoffGroup Membership0CCE9249-69AE-11D9-BED3-505054503030
20Object Access6997984A-797A-11D9-BED3-505054503030
21Object AccessFile System0CCE921D-69AE-11D9-BED3-505054503030
22Object AccessRegistry0CCE921E-69AE-11D9-BED3-505054503030
23Object AccessKernel Object0CCE921F-69AE-11D9-BED3-505054503030
24Object AccessSAM0CCE9220-69AE-11D9-BED3-505054503030
25Object AccessCertification Services0CCE9221-69AE-11D9-BED3-505054503030
26Object AccessApplication Generated0CCE9222-69AE-11D9-BED3-505054503030
27Object AccessHandle Manipulation0CCE9223-69AE-11D9-BED3-505054503030
28Object AccessFile Share0CCE9224-69AE-11D9-BED3-505054503030
29Object AccessFiltering Platform Packet Drop0CCE9225-69AE-11D9-BED3-505054503030
30Object AccessFiltering Platform Connection0CCE9226-69AE-11D9-BED3-505054503030
31Object AccessOther Object Access Events0CCE9227-69AE-11D9-BED3-505054503030
32Object AccessDetailed File Share0CCE9244-69AE-11D9-BED3-505054503030
33Object AccessRemovable Storage0CCE9245-69AE-11D9-BED3-505054503030
34Object AccessCentral Policy Staging0CCE9246-69AE-11D9-BED3-505054503030
35Privilege Use6997984B-797A-11D9-BED3-505054503030
36Privilege UseSensitive Privilege Use0CCE9228-69AE-11D9-BED3-505054503030
37Privilege UseNon Sensitive Privilege Use0CCE9229-69AE-11D9-BED3-505054503030
38Privilege UseOther Privilege Use Events0CCE922A-69AE-11D9-BED3-505054503030
39Detailed Tracking6997984C-797A-11D9-BED3-505054503030
40Detailed TrackingProcess Creation0CCE922B-69AE-11D9-BED3-505054503030
41Detailed TrackingProcess Termination0CCE922C-69AE-11D9-BED3-505054503030
42Detailed TrackingDPAPI Activity0CCE922D-69AE-11D9-BED3-505054503030
43Detailed TrackingRPC Events0CCE922E-69AE-11D9-BED3-505054503030
44Detailed TrackingPlug and Play Events0CCE9248-69AE-11D9-BED3-505054503030
45Detailed TrackingToken Right Adjusted Events0CCE924A-69AE-11D9-BED3-505054503030
46Policy Change6997984D-797A-11D9-BED3-505054503030
47Policy ChangeAudit Policy Change0CCE922F-69AE-11D9-BED3-505054503030
48Policy ChangeAuthentication Policy Change0CCE9230-69AE-11D9-BED3-505054503030
49Policy ChangeAuthorization Policy Change0CCE9231-69AE-11D9-BED3-505054503030
50Policy ChangeMPSSVC Rule-Level Policy Change0CCE9232-69AE-11D9-BED3-505054503030
51Policy ChangeFiltering Platform Policy Change0CCE9233-69AE-11D9-BED3-505054503030
52Policy ChangeOther Policy Change Events0CCE9234-69AE-11D9-BED3-505054503030
53Account Management6997984E-797A-11D9-BED3-505054503030
54Account ManagementUser Account Management0CCE9235-69AE-11D9-BED3-505054503030
55Account ManagementComputer Account Management0CCE9236-69AE-11D9-BED3-505054503030
56Account ManagementSecurity Group Management0CCE9237-69AE-11D9-BED3-505054503030
57Account ManagementDistribution Group Management0CCE9238-69AE-11D9-BED3-505054503030
58Account ManagementApplication Group Management0CCE9239-69AE-11D9-BED3-505054503030
59Account ManagementOther Account Management Events0CCE923A-69AE-11D9-BED3-505054503030
60DS Access6997984F-797A-11D9-BED3-505054503030
61DS AccessDirectory Service Access0CCE923B-69AE-11D9-BED3-505054503030
62DS AccessDirectory Service Changes0CCE923C-69AE-11D9-BED3-505054503030
63DS AccessDirectory Service Replication0CCE923D-69AE-11D9-BED3-505054503030
64DS AccessDetailed Directory Service Replication0CCE923E-69AE-11D9-BED3-505054503030
65Account Logon69979850-797A-11D9-BED3-505054503030
66Account LogonCredential Validation0CCE923F-69AE-11D9-BED3-505054503030
67Account LogonKerberos Service Ticket Operations0CCE9240-69AE-11D9-BED3-505054503030
68Account LogonOther Account Logon Events0CCE9241-69AE-11D9-BED3-505054503030
69Account LogonKerberos Authentication Service0CCE9242-69AE-11D9-BED3-505054503030