windows-event-logs

Installation
SKILL.md

Windows Event Logs — detection authoring

This skill encodes the Windows-native event log knowledge required for detection content that depends on Security, Sysmon, PowerShell, or System event channels. It bridges the gap between raw Windows telemetry and the platform-specific query skills used by your SIEM or EDR.


1. Event channel landscape

Channel Log name Key content
Security Security Authentication, process creation, object access, policy changes, account management
Sysmon Microsoft-Windows-Sysmon/Operational Process creation with hashes, network connections, file creation, registry, DNS, WMI, named pipes, clipboard
PowerShell Microsoft-Windows-PowerShell/Operational ScriptBlock logging (4104), Module logging (4103)
System System Service installation (7045), driver loads, system state
Windows Defender Microsoft-Windows-Windows Defender/Operational AV detections, exclusion changes, tamper events
Task Scheduler Microsoft-Windows-TaskScheduler/Operational Scheduled task creation/modification/execution
WMI Microsoft-Windows-WMI-Activity/Operational WMI subscription events
AppLocker Microsoft-Windows-AppLocker/* Application execution control
NTLM Microsoft-Windows-NTLM/Operational NTLM authentication events (requires audit policy)
Installs
3
First Seen
Sep 16, 2026