windows-event-logs
Installation
SKILL.md
Windows Event Logs — detection authoring
This skill encodes the Windows-native event log knowledge required for detection content that depends on Security, Sysmon, PowerShell, or System event channels. It bridges the gap between raw Windows telemetry and the platform-specific query skills used by your SIEM or EDR.
1. Event channel landscape
| Channel | Log name | Key content |
|---|---|---|
| Security | Security |
Authentication, process creation, object access, policy changes, account management |
| Sysmon | Microsoft-Windows-Sysmon/Operational |
Process creation with hashes, network connections, file creation, registry, DNS, WMI, named pipes, clipboard |
| PowerShell | Microsoft-Windows-PowerShell/Operational |
ScriptBlock logging (4104), Module logging (4103) |
| System | System |
Service installation (7045), driver loads, system state |
| Windows Defender | Microsoft-Windows-Windows Defender/Operational |
AV detections, exclusion changes, tamper events |
| Task Scheduler | Microsoft-Windows-TaskScheduler/Operational |
Scheduled task creation/modification/execution |
| WMI | Microsoft-Windows-WMI-Activity/Operational |
WMI subscription events |
| AppLocker | Microsoft-Windows-AppLocker/* |
Application execution control |
| NTLM | Microsoft-Windows-NTLM/Operational |
NTLM authentication events (requires audit policy) |