IIS configuration auditing lets you monitor the changes that are done to the IIS configuration store and it generates event messages related to this. IIS is a known vector for attackers. If it is in use, it is a good idea to be logging events generated by it. Helix Enterprise is currently focused on detecting when new modules are added to IIS.
Number of occurrences in rules | Eventid | Event log | Event source or category |
|---|---|---|---|
1 | 29 | Microsoft-IIS-Configuration/Operational | Microsoft-IIS-Configuration/Operational |