Events pertaining to Microsoft Windows. Event logs can vary greatly based on OS version, event ID, log gathering method, and other environmental factors.
These events belong to the windows metaclass.
The args, eventid, msg, pprocess, process, and source fields are used in Trellix detection rules.
Taxonomy | Type | Description |
|---|---|---|
| string | Arguments passed to a function, command, or operation |
| string | Authentication domain of a remote calling identity, typically observed in windows event logs as calling domain |
| string | Caller logon identifier |
| string | Caller user identifier |
| string | Arguments passed to a function, command, or operation |
| string | Event identifier |
| string | Logon globally unique identifier (GUID) |
| string | Logon user identifier (UID), unique between reboots on the same computer |
| string | Free-form message |
| integer | Process identifier |
| integer | Parent process identifier |
| string | Parent process name |
| string | Process name |
| string | Origin or log source |
| string | Target system or user domain |
| string | Typically observed in host IDS/IPS, AV, and others when referencing a targeted system or user |
| string | Target system or user name |