Skip to content

Hide Navigation Hide TOC

Important Windows Event Auditing Disabled (ab4561b1-6c7e-48a7-ad08-087cfb9ce8f1)

Detects scenarios where system auditing for important events such as "Process Creation" or "Logon" events is disabled.

Cluster A Galaxy A Cluster B Galaxy B Level
Disable Windows Event Logging - T1562.002 (4eb28bed-d11a-4641-9863-c2ac017d910a) Attack Pattern Important Windows Event Auditing Disabled (ab4561b1-6c7e-48a7-ad08-087cfb9ce8f1) Sigma-Rules 1
Disable Windows Event Logging - T1562.002 (4eb28bed-d11a-4641-9863-c2ac017d910a) Attack Pattern Impair Defenses - T1562 (3d333250-30e4-4a82-9edc-756c68afc529) Attack Pattern 2