Data Source: Windows Event Log Defender 1129

Description

Logs an event when a user overrides a security policy set by an Attack Surface Reduction rule in Microsoft Defender.

Details

Property Value
Source WinEventLog:Microsoft-Windows-Windows Defender/Operational
Sourcetype XmlWinEventLog
Separator EventCode
Name ▲▼ Technique ▲▼ Type ▲▼
Windows Defender ASR Block Events Command and Scripting Interpreter, Spearphishing Attachment, Spearphishing Link Anomaly
Windows Defender ASR Rules Stacking Spearphishing Attachment, Spearphishing Link, Command and Scripting Interpreter Hunting

Supported Apps

Event Fields

+ Fields
  <span class="pill kill-chain">_time</span>
  
  <span class="pill kill-chain">ComputerName</span>
  
  <span class="pill kill-chain">EventCode</span>
  
  <span class="pill kill-chain">EventType</span>
  
  <span class="pill kill-chain">ID</span>
  
  <span class="pill kill-chain">Keywords</span>
  
  <span class="pill kill-chain">LogName</span>
  
  <span class="pill kill-chain">Message</span>
  
  <span class="pill kill-chain">OpCode</span>
  
  <span class="pill kill-chain">Path</span>
  
  <span class="pill kill-chain">Process_Name</span>
  
  <span class="pill kill-chain">RecordNumber</span>
  
  <span class="pill kill-chain">Sid</span>
  
  <span class="pill kill-chain">SidType</span>
  
  <span class="pill kill-chain">SourceName</span>
  
  <span class="pill kill-chain">TaskCategory</span>
  
  <span class="pill kill-chain">Type</span>
  
  <span class="pill kill-chain">User</span>
  
  <span class="pill kill-chain">category</span>
  
  <span class="pill kill-chain">date_hour</span>
  
  <span class="pill kill-chain">date_mday</span>
  
  <span class="pill kill-chain">date_minute</span>
  
  <span class="pill kill-chain">date_month</span>
  
  <span class="pill kill-chain">date_second</span>
  
  <span class="pill kill-chain">date_wday</span>
  
  <span class="pill kill-chain">date_year</span>
  
  <span class="pill kill-chain">date_zone</span>
  
  <span class="pill kill-chain">dvc_nt_host</span>
  
  <span class="pill kill-chain">event_id</span>
  
  <span class="pill kill-chain">eventtype</span>
  
  <span class="pill kill-chain">host</span>
  
  <span class="pill kill-chain">id</span>
  
  <span class="pill kill-chain">index</span>
  
  <span class="pill kill-chain">linecount</span>
  
  <span class="pill kill-chain">punct</span>
  
  <span class="pill kill-chain">severity</span>
  
  <span class="pill kill-chain">severity_id</span>
  
  <span class="pill kill-chain">signature_id</span>
  
  <span class="pill kill-chain">source</span>
  
  <span class="pill kill-chain">sourcetype</span>
  
  <span class="pill kill-chain">splunk_server</span>
  
  <span class="pill kill-chain">tag</span>
  
  <span class="pill kill-chain">tag::eventtype</span>
  
  <span class="pill kill-chain">timeendpos</span>
  
  <span class="pill kill-chain">timestartpos</span>
  
  <span class="pill kill-chain">vendor_product</span>
  
</div>

Source: GitHub | Version: 3