Windows
StandardWindows consists of security analytics components that normalize Windows events, which enables you to analyze Windows data. Logpoint aggregates and normalizes logs related to CPU, disk, memory, configuration, I/O, Active Directory (AD), and Domain Name Server (DNS) from Windows systems so you can analyze the information through dashboards and security reports. The automated alerts enable you to detect potential threats, malware, or malicious events early and take corrective actions against them. DNSCompiledNormalizer is compatible with CNDP.
Package Details
- Normalization package
- LP_Microsoft Antimalware
- LP_Microsoft Direct Access
- LP_Windows Firewall
- Search template
- LP_ADFS Issued Claim Identity
- LP_Beaconing for Threat Hunting with Microsoft Sysmon
- K b list
- ADMINS
- FILE_EXTENSIONS
- LOGPOINT_GROUPS
- Log source template
- Windows
- Report
- LP_Windows Administrator Report
- LP_Active Directory Report
- LP_Windows Configuration Report
- LP_Active Directory Authentication Requests
- LP_Active Directory Object Management
- LP_AD: User Authentication Requests
- LP_AD: User Account Management
- LP_AD: Security Group Management
- LP_AD: Policy Changes
- LP_AD: OU and GPO
- LP_AD: Distribution Group Management
- LP_AD: Critical User Activities
- LP_AD: Computer Account Management
- LP_AD: Service
- LP_AD: Machine Authentication Requests
- Pluggable normalizer
- LPA_Windows
- ADFSNormalizer
- DNSCompiledNormalizer
- DNSCompiledNormalizerEU
- WindowsNPSCompiledNormalizer
- WindowsSysmonCompiledNormalizer
- WindowsDHCPCompiledNormalizer
- WindowsSecurityAuditing
- Dashboard
- LP_AD: Computer Account Management
- LP_AD: Critical User Activities
- LP_AD: Distribution Group Management
- LP_AD: Machine Authentication Requests
- LP_AD: OU and GPO
- LP_AD: Policy Changes
- LP_AD: Security Group Management
- LP_AD: Service
- LP_AD: User Account Management
- LP_AD: User Authentication Requests
- LP_ADFS Auditing
- LP_AppLocker
- LP_Windows Antimalware
- LP_Windows Authentication
- LP_Windows BITS
- LP_Windows Configuration
- LP_Windows DHCP
- LP_Windows DNS
- LP_Windows File Auditing
- LP_Windows Overview
- LP_Windows Service Control Manager
- LP_Windows Sysmon Overview
- Alert
- LP_ADPrivescCVE-2022-26923Exploitation
- LP_ApplicationExecutionAttemptBlockedbyAppLocker
- LP_AppLockerSmartlockerFilterdetectedfilebeingwrittenbyprocess
- LP_NgrokExecution
- LP_NgrokRDPTunnelDetected
- LP_PossiblePasstheHashActivityDetected
- LP_WindowsAuditLogsCleared
- LP_WindowsAuthenticationPolicyChange
- LP_WindowsBlockInheritanceonOUorDomain
- LP_WindowsBulkPrintataTime
- LP_WindowsDataCopiedtoRemovableDevice
- LP_WindowsDelegationofAuthorityChangeonOUorDomain
- LP_WindowsDirectoryServiceStateChange
- LP_WindowsDomainPolicyChange
- LP_WindowsExcessiveAmountofFilesCopiedtoRemovableDevice
- LP_WindowsFailedLoginAttemptsusingDisabledAccount
- LP_WindowsFailedLoginAttemptUsingServiceAccount
- LP_WindowsFailedLoginFollowedbyLockoutEvent
- LP_WindowsFileAccess
- LP_WindowsGPOLinkedorUnlinkedtoOUorDomain
- LP_WindowsGroupCreatedorDeleted
- LP_WindowsGroupPolicyObjectChanges
- LP_WindowsGroupPolicyObjectCreation
- LP_WindowsGroupPolicyObjectDeletion
- LP_WindowsKerberosPre-authenticationfailed
- LP_WindowsKerberosServiceTicketRequest
- LP_WindowsLocalUserManagement
- LP_WindowsLogonRightsChanges
- LP_WindowsMultipleAccountPasswordchangesbyUser
- LP_WindowsMultipleFailedAttemptsagainstaSingleAccount
- LP_WindowsMultipleUniqueLockouts
- LP_WindowsOUCreation
- LP_WindowsOUDeletion
- LP_WindowsPasswordNeverExpires
- LP_WindowsPossibleRansomwareDetection
- LP_WindowsSecurityServiceTerminated
- LP_WindowsSuccessfulBruteForceAttackfromSameSource
- LP_WindowsSuccessfulBruteForceAttackfromSameUser
- LP_WindowsSuccessfulRemoteInteractiveLogin
- LP_WindowsunBlockInheritanceonDomain
- LP_WindowsunBlockInheritanceonOU
- LP_WindowsunBlockInheritanceonOUandDomain
- LP_WindowsUserAccountChangetoEndwithDollarSign
- LP_WindowsUserAccountCreatedorRemoved
- LP_WindowsUserAccountCreatedviaCommandLine
- LP_WindowsUserAccountwasCreatedwithaDollarSign
- LP_WindowsUserAddedorRemovefromGroup
- LP_WindowsUserAddedtoAdministratorGroup
- LP_WindowsUserRemovedfromAdministratorGroup
- LP_WindowsUserRightsChanges
- LP_WindowsUsersDisabled
- LP_WindowsUsersEnabled
- LP_WindowsWMIFilterLinkedorUnlinkedwithGPO
Key Information
- DNSCompiledNormalizerEU is available for this release only.
- Logpoint only supports JSON logs for Windows, so we recommend you use the Logpoint or NXLog Agent to generate logs in .json format. Go to NXLog Sample Configuration to obtain the NXLog Sample Configuration file.
- You must configure Sysmon correctly for the alerts to work. Go to Sysmon Configuration to obtain the Sysmon Configuration file.
Enhancements
Bug Fix
Past Releases
Windows v5.6.1 ▾
Enhancement
Windows v5.5.0 ▾
Enhancements
Mapped the following fields to maintain consistency:
| Raw Log Field | Normalized Field | Event ID | Compiled Normalizer |
| Product | Application | 7 | WindowsSysmonCompiledNormalizer |
| DATA (milt-line value) | server_address | - | DNSCompiledNormalizer, DNSCompiledNormalizerEU |
| Source | source | 4698 | WindowsSecurityAuditing |
Bug Fixes
Windows v5.4.9 ▾
Bug Fixes
Windows v5.4.8 ▾
Enhancements
Renamed the following field name in LPA_Windows :
-
process_nametoprocess -
processnamelengthtoprocess_name_length -
sha1_flat_hash_sizetohash_datasize -
productnametoproduct -
statustostatus_code -
userwriteabletois_user_writeable -
processnamebuffertobuffer -
requestedsigningleveltorequested_signing_level -
securerequiredtosecure_required
Bug Fix
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.
To use the provided queries in the widgets with logon_process=User32, it's necessary to configure Windows Event Forwarding (WEF) on the Windows workstations.
Many queries contain
-user="ANONYMOUS LOGON"
-caller_user="ANONYMOUS LOGON"
-domain="NT AUTHORITY"
-caller_domain="NT AUTHORITY"
For none english windows versions it’s necessary to modify them to national values.