Windows

Prev Next

Events pertaining to Microsoft Windows. Event logs can vary greatly based on OS version, event ID, log gathering method, and other environmental factors.

These events belong to the windows metaclass.

The args, eventid, msg, pprocess, process, and source fields are used in Trellix detection rules.

Taxonomy

Type

Description

args

string

Arguments passed to a function, command, or operation

callingdomain

string

Authentication domain of a remote calling identity, typically observed in windows event logs as calling domain

callinglogonid

string

Caller logon identifier

callinguid

string

Caller user identifier

callingusername

string

Arguments passed to a function, command, or operation

eventid

string

Event identifier

logonguid

string

Logon globally unique identifier (GUID)

logonid

string

Logon user identifier (UID), unique between reboots on the same computer

msg

string

Free-form message

pid

integer

Process identifier

ppid

integer

Parent process identifier

pprocess

string

Parent process name

process

string

Process name

source

string

Origin or log source

targetdomain

string

Target system or user domain

targetlogonid

string

Typically observed in host IDS/IPS, AV, and others when referencing a targeted system or user

targetusername

string

Target system or user name