The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Category

Prev Next

The category of logon event. Supports the predefined options described below. For more information on Windows Event IDs, see Windows Logon Events and Windows Logon Types sections.

  • Local: Any local logon

  • Network:Windows Event ID 4624/4625 of type 3 (Network) or Windows Event ID 4648 (incoming or outgoing) and not accessing a share.

  • Network Share:

    • Windows Event ID 5145.

    • Windows Event ID 4648 and destined for a CIFS (Common Internet File System).

  • RDP: Windows Event ID 4624 if type 10 (RemoteInteractive) or Windows Event ID 21/25.

  • SSH: SSH events from Linux systems.

  • ARD: Apple Remote Desktop from macOS systems

  • PsExeco: PsExec logon using Sys Internals tool or a similar technique. Enriched from 4624 network event.

  • WMI: Windows Management Instrumentation logon activity which was enriche from a 4624 network event.

  • WinRM: Windows Remote Management logon activity which was enriched from a 4624 network event.

  • RPCo: Windows Remote Procedure Call logon activity which was enriched from a 4624 network event.

  • LDAP: LDAP logon and query which was enriched from a 4624 network event.

  • Any – Returns all results, regardless of type, no filter is applied.