configuring-windows-event-logging-for-detection
Warn
Audited by Snyk on Apr 7, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 1.00). The skill instructs the agent to modify system-wide audit policies, registry keys, event log sizes, WinRM/event forwarding and GPO settings—actions that require administrative privileges and change the machine's state.
Issues (1)
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata