EVTX-to-MITRE-Attack
Set of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.
File Explorer
Download Latest Version (.zip)- ID1116-1117-Defender threat detected.evtx
- ID1151-Defender health status.evtx
- ID11,13,17,18-PSexec as system execution.evtx
- ID4624,4688,5140,5145-Eternal Romance - MS17_010_psexec (GLOBAL).evtx
- ID4674,5142-Mimikatz print spool privileges requested.evtx
- ID4674,6416 New external device connected (PrintNightmare).evtx
- ID4688,4698,4699,5145,4624-ATexec remote trask creation (GLOBAL).evtx
- ID4688,5140,5145-WMIexec execution via SMB (GLOBAL).evtx
- ID4720,4698-Fortinet APT group abuse on Windows.evtx
- ID4742,4935,4662,4661,5137-DCshadow attack (GLOBAL) failed.evtx
- ID47x,4661-4662,5136,4688,4697-SAM the admin (CVE-2021-42287).evtx
- ID5140-5145,4688,4697-Encrypted payload deployed with service over SMB (GLOBAL).evtx
- ID5145-4624-DonPAPI full extraction.evtx
- ID1149-RDP success logins to multiple hosts.evtx
- ID33205-SQL Server failed login with disabled SA account.evtx
- ID4625-failed login with denied access due to account restriction.evtx
- ID1-WMI spwaning PowerShell process - WMImplant.evtx
- ID1-WMIexec process execution.evtx
- ID3-7-10-Suspicious DLL loaded (CME+Mimikatz).evtx
- ID4688-5145-WMIexec execution via SMB.evtx
- ID4688-4698 Persistent scheduled task with SYSTEM privileges creation.evtx
- ID4688-Interactive shell using AT schedule task.evtx
- ID4688-Scheduled task creation.evtx
- ID4698-4699-Fast created & deleted task by ATexec (susp. arg.).evtx
- ID4698-4699-Fast created & deleted task by SMBexec (sups. arg.).evtx
- ID5145-Remote schedule task creation (ATexec).evtx
- ID4103-4104-Payload download via PowerShell.evtx
- ID4688-Encoded PowerShell MSF payload via process execution.evtx
- ID800-4103-Interactive PipeShell over named pipe (server and client).evtx
- ID4688-SQL Server payload injectection for reverse shell (MSF).evtx
- ID4688-Edge payload download via command.evtx
- ID5145-remote service creation over SMB.evtx
- ID5145-service massive remote creation via named pipe - Tchopper.evtx
- ID7000,7009,7045-Payload deployed via service - Tchopper.evtx
- ID7009-Service deployment time out (meterpreter).evtx
- ID33205-SQL Server member added to database role.evtx
- ID33205-SQL Server member added to server role.evtx
- ID33205-SQL Server user linked to a database.evtx
- ID4688-SPN added to an account.evtx
- ID4723-5145-password reset with changeNTLM (Mimikatz).evtx
- ID4724-5145-password reset with setNTLM (Mimikatz).evtx
- ID4728-4756-Member added to sensitive domain groups.evtx
- ID4728-Massive account group membership change.evtx
- ID4728-Member adding to a group by the same account.evtx
- ID4732-4733-Quick added-removed user from local group.evtx
- ID4732-DNSadmin new member added.evtx
- ID4732-User added to local admin groups.evtx
- ID4738,5136-SPN set on user account.evtx
- ID4738-Account is sensitive and cannot be delegated.evtx
- ID4738-Account with password not required.evtx
- ID4738-Do not require Kerberos preauthentication.evtx
- ID4738-Password cannot be changed.evtx
- ID4738-Password never expires.evtx
- ID4738-Use only Kerberos DES encryption types.evtx
- ID4738-User set with reversible psw encryption.evtx
- ID4742,5136-Enable Trust this computer for delegation (to any service, Kerberos only).evtx
- ID4742,5136-Enable Trust this computer for delegation (to specified service, any protocol).evtx
- ID4742,5136-Enable Trust this computer for delegation (to specified service, Kerberos only).evtx
- ID4742,5136-SPN set on computer account.evtx
- ID4742-SPN set on computer account (DCshadow).evtx
- ID4756-Exchange admin group change.evtx
- ID4781-4738-User renamed to admin or likely.evtx
- ID4781-Computer account renamed without a trailing $ (CVE-2021-42278).evtx
- ID5136-4662 AD object owner changed.evtx
- ID5136-Computer account set for RBCD delegation.evtx
- ID33205-SQL Server Disabled SA user activated.evtx
- ID33205-SQL Server local user created.evtx
- ID4688-User creation via commandline.evtx
- ID472, 4728 Hidden user creation.evtx
- ID4720-4726 Fast created-deleted user.evtx
- ID4720-Admin like user created.evtx
- ID4720-Fake computer account created.evtx
- ID4720-Local user created.evtx
- ID4722-Guest account activated.evtx
- ID4741-Computer account created with privileges.evtx
- ID4742-4743-Fast created & deleted computer account.evtx
- ID3-59-60-BITS job created.evtx
- ID4688-BITS transfer initiated.evtx
- ID60-High volume file downloaded with BITS.evtx
- ID800-4103-4104-PowerShell BITS job started.evtx
- ID11-Exchange transport config modified.evtx
- ID6-Failed to install an Exchange transport agent.evtx
- ID11715-SQL Server started in single mode for psw recovery.evtx
- ID15457-SQL server CLR lateral movement.evtx
- ID15457-SQL Server CMDshell enabled.evtx
- ID4688-SQL Server started in single mode for psw recovery.evtx
- ID4688-sqlcmd tool abuse in SQL Server.evtx
- ID13-New service for Mimikatz.evtx
- ID4688-4697 RDP hijack via service creation.evtx
- ID4688-Command SC to create service on remote host.evtx
- ID4688-Service abuse with Failure Command.evtx
- ID4688-Service abuse with malicious path.evtx
- ID4688-Service created (command).evtx
- ID4688-Service permissions modified (registry).evtx
- ID4688-Service permissions modified (sc).evtx
- ID4697-MSF payload deployed via service.evtx
- ID4697-New service for Mimikatz.evtx
- ID7045-4697-SMBexec service registration.evtx
- ID7045-7036 PSexec service installation.evtx
- ID7045-New service for Mimikatz +npcap.evtx
- ID7045-Random service installation.evtx
- ID800-4103-4104-Service abuse with Failure Command.evtx
- ID800-4103-4104-Service abuse with malicious path.evtx
- ID800-4103-4104-Service creation (PowerShell).evtx
- ID13-WMIimplant registry crash control.evtx
- ID19-20-WMI registration via PowerLurk.evtx
- ID4688-netsh helper DLL.evtx
- ID5136-AdminSDholder backdoor obfuscation (via localizationDisplayId).evtx
- ID5136-AdminSDholder permissions changed.evtx
- ID800-4103-4104-WMI registration via PowerLurk.evtx
- ID12-LSA Protect mode enabled RunAsPPL.evtx
- ID4622-New SSP loaded in LSA (only legitim).evtx
- ID4664-symbolic link created.evtx
- ID150-Failed DLL loaded by DNS server.evtx
- ID4688-DNS DLL serverlevelplugindll command.evtx
- ID770-Success DLL loaded by DNS server.evtx
- ID800-4103-4104-Print spooler privilege escalation (CVE-2020-1048).evtx
- ID12-13 Mini_Plasma_PoC_AbortHydration_ArbitraryRegKey_EoP.evtx
- ID4673-Privilege SeMachineAccountPrivilege called.evtx
- ID4648-4624-RunAsCS login.evtx
- ID4688,4624-RottenPotatoNG.evtx
- ID4688,4648,4624-Runas execution with different user.evtx
- ID4704-4705-User righ assigned to account.evtx
- ID4717-4718-System security granded to account.evtx
- ID 4765 - SID history added.evtx
- ID 4865 4706 - trust added.evtx
- ID5136-4662 sensitive GPO edited.evtx
- ID1-CMD executed via sticky key call.evtx
- ID11-New sethc file created from CMD copy.evtx
- ID12,13-Stickey key registry update.evtx
- ID4656-Failed sethc replacement by CMD.evtx
- ID4688-Stickey command reg update + execution.evtx
- 1-Print spool spawned a CMD shell (PrintNightMare).evtx
- ID316,300,301,316,823,848-Mimispool printer server instal.evtx
- ID354-808-Mimispool printer installation (PrintNightmare).evtx
- ID4688,6416,4648-SystemNightMare.evtx
- International_Payments_Pricing_Sheet_072022.pdf
- 4624,4674,4688- CrackMap Exec SMB mimikatz.evtx
- ID1-CrackMapExec payload execution.evtx
- ID400-800-CrackMapExec payload execution.evtx
- ID4103-4104-CrackMapExec payload execution.evtx
- ID4688-Obfuscated payload transfer via service name - Tchopper.evtx
- ID104-1102-Event log cleared.evtx
- ID4688-Clear event log attempt (native).evtx
- ID4688-Clear event log attempt (wmi).evtx
- ID800-4103-4104-Clear event log attempt.evtx
- ID4616-system time changed.evtx
- ID4964-Login of a member of a special group.evtx
- ID11,13-SMBexec service registration.evtx
- ID4624,4670,4688,4674-Registry permission change via WMI (DAMP).evtx
- ID800-4103-4104-Registry permission change via WMI (DAMP) PowerShell on source.evtx
- ID4688-Certutil download.evtx
- ID9-WSL module installation (KBC).evtx
- ID4662-Sensitive attributes accessed (DCshadow).evtx
- ID5137-Fake domain controller registration (DCshadow).evtx
- ID5124-OCSP security settings changed.evtx
- ID5136-Permission change on OU by computer.evtx
- ID5136-Permission change on OU by user.evtx
- ID5136-Permission change on top root AD (DCsync).evtx
- ID5136-Permissions changed on a GPO.evtx
- ID5143-File share permissions changed.evtx
- ID12-13 SIP provider registration.evtx
- ID 5376, 5379, 5382, 5381, 5382 credential manager and vault.evtx
- ID1-SYSMON driver unload (FilterManager).evtx
- ID13-Defender service configuration disabled.evtx
- ID4688-Defender critical features disabled (command).evtx
- ID4688-Defender service deactivation attempt.evtx
- ID5007-Defender threat exclusion (native).evtx
- ID8-Module Virtualization disabled (Credential Guard).evtx
- ID800-4103-4104 Defender critical features disabled (PowerShell).evtx
- ID800-4103-4104 Defender default action allow any (PowerShell).evtx
- ID800-4103-4104 Defender exclusion added (PowerShell).evtx
- ID33205-SQL Server audit object disabled.evtx
- ID33205-SQL Server audit object deleted.evtx
- ID33205-SQL Server audit specification deleted.evtx
- ID33205-SQL Server audit specification disabled.evtx
- ID33205-SQL Server Database audit specification deleted.evtx
- ID33205-SQL Server Database audit specification disabled.evtx
- ID4688-Audit policy clear attempt.evtx
- ID4688-Audit policy deactivation attempt.evtx
- ID4719-Audit policy deactivation.evtx
- ID4739-Domain policy changed by non system account.evtx
- ID4885,4876,4877,5123,5124-ADCS PKI OCSP.evtx
- ID4908-Special group table changed.evtx
- ID541-DNS server auditing changed.evtx
- ID2003-4950-Firewall disabled.evtx
- ID2004-Any any firewall rule created.evtx
- ID2004-New firewall rule created by PowerShell.evtx
- ID4103-4104-2004-OpenSSH firewall rule activation.evtx
- ID4688-5447-4950-Firewall disabled (command).evtx
- ID800-4103-Firewall disabled.evtx
- ID4688-Linux Subsystem installation (WSL).evtx
- ID1-12-13-Wdigest authentication activation.evtx
- ID1-LSASS dump with LSASSY (SYSMON).evtx
- ID10-Mimikatz LSASS process dump.evtx
- ID11-LSASS credentials dump via Task Manager.evtx
- ID11-Mimikatz LSA SSP clear text password exfiltration.evtx
- ID325-327-IFM created - ESENT.evtx
- ID4656, 5145, 4674-Impacket secret dump via SMB.evtx
- ID4656-4663-4658 Mimikatz sekurlsa password dump.evtx
- ID4661-4658 Mimikatz sekurlsa password dump SAM.evtx
- ID4661-Suspicious SAM access to password attributes by LSASS (Dcshadow).evtx
- ID4662-DCsync attack using Mimikatz.evtx
- ID4663-Task Manager used to dump LSASS process.evtx
- ID4688-4663-4656-LSASS dump with LSASSY (process).evtx
- ID4688-Diskshadow abuse.evtx
- ID4688-IFM created.evtx
- ID4688-Task Manager access indicator for potential LSASS dump.evtx
- ID4756-Exchange critical group change (DCsync).evtx
- ID4794-4688-DSRM password set with NTDSutil.evtx
- ID800-4103-4104-LSASS dump with LSASSY (PowerShell).evtx
- ID-4688 Native Windows sniffer Pktmon usage.evtx
- ID 4776,4625-AccountRestore local bruteforce.evtx
- ID18456-SQL Server failed login because only Windows auth.evtx
- ID33205-SQL Server failed login because only Windows auth.evtx
- ID33205-SQL Server failed login with non existing accounts.evtx
- ID33205-SQL Server failed login with SA wrong password.evtx
- ID4-OpenSSH brutforce with non existing users (sshd logs).evtx
- ID4-OpenSSH brutforce with valid users.evtx
- ID4625-OpenSSH brutforce with non existing users.evtx
- ID4625-OpenSSH brutforce with valid users.evtx
- ID4768-4771-Kerberos brutforce with non existing users.evtx
- ID4768-4771-Kerberos user enumeration (Kerbrute).evtx
- ID4771-Kerberos brutforce with valid user.evtx
- ID70-CAPI-Private key accessed Mimikatz.evtx
- ID4662-Sensitve DPAPI attributes accessed.evtx
- ID5145-user file-credentials-browser dump via network share.evtx
- ID5145-Print spooler bug abuse.evtx
- ID515-DNS entry created with wildcard.evtx
- ID4624-Success login with Golden ticket.evtx
- ID4768-4769-Kerberos host ticket without a trailing $.evtx
- ID4768-Kerberos AS-REP Roasting.evtx
- ID4769-Golden ticket issued.evtx
- ID4769-Kerberoast ticket with low encryption.evtx
- ID 39 KDC - ADCS ESC 1 auth request.evtx
- ID 4882 - ADCS ESC 7.evtx
- ID 4886-4887 - ADCS ESC 1.evtx
- ID 4886-4887 - ADCS ESC 2.evtx
- ID 4886-4887 - ADCS ESC 3.evtx
- ID4688-Audit policy enumerated.evtx
- ID4688-Firewall configuration enumerated (command).evtx
- ID4688-Scheduled task configuration enumeration.evtx
- ID6004-DNS-server-failed zone transfer.evtx
- ID800-4103-4104-Firewall configuration enumerated (PowerShell).evtx
- ID5145-DNS hosts files access via network share.evtx
- ID131-RDP brutforce (no user info).evtx
- ID4624-Anonymous login with domain specified (DonPapi).evtx
- ID4661-Local group enumeration with RID brutforce with CME.evtx
- ID4661-SAM sensitive domain users & groups discovery.evtx
- ID4662-Domain group enumeration CME.evtx
- ID4688-Group discovery via commandline.evtx
- ID4799-4624-Local admin group enumerated by SharpHound.evtx
- ID800-4103-4104-Domain group discovery via PowerShell.evtx
- ID800-4103-4104-Local group discovery via PowerShell.evtx.evtx
- ID1-SPN discovery (SYSMON process).evtx
- ID4103-4104 - SPN discovery (moder nPowerShell).evtx
- ID4662-4624-Honeypot account property read.evtx
- ID4688-List all Service Principal Names (SPN).evtx
- ID4688-User enumeration via command.evtx
- ID4769-Kerberos TGS host enumeration (Bloodhound).evtx
- ID600-Active Directory module called by PowerShell.evtx
- ID800 - SPN discovery (PowerShell).evtx
- ID4688-Network share discovery or connection via commandline.evtx
- ID5140-5145-Bloodhound-SharpHound enumeration via SMB.evtx
- ID5140-Failed ADMIN$ share access.evtx
- ID4661-Password policy enumeration.evtx
- ID4688-Password policy discovery via commandline.evtx
- ID800,4103,4104-Active Directory Forest PowerShell class.evtx
- ID4688,4778,4779 RDP hijack direct.evtx
- ID4688-4778 RDP hijack command execution.evtx
- ID4825-Denied RDP connection with valid credentials.evtx
- ID4688,4697,5140-5145 PSexec remote execution + admin share.evtx
- ID4688-4648 Lateral movement with net use.evtx
- ID4688-Network share manipulation via commandline.evtx
- ID5140-ADMIN$ share connection with Golden ticket.evtx
- ID5142- New file share created.evtx
- ID5142-5143-Mimispool print share created and modified.evtx
- ID5145-remote shell execution via SMB admin share.evtx
- ID4103,4104-DCOMexec native via PowerShell.evtx
- ID4688,4674-DCOMexec process spawned.evtx
- ID4-OpenSSH server listening.evtx
- ID4103-4104-OpenSSH server activation and config.evtx
- ID4103-4104-OpenSSH server install.evtx
- ID4656-WS Management listener enumeration.evtx
- ID4624-Mimikatz Pass the hash.evtx
- WSUS Remote Code Execution (CVE-2025-59287 filtered.evtx
- ID13-RDP shadow session configuration enabled (registry).evtx
- ID5600-proxy configuration changed.evtx
- ID4688-netsh RDP port forwarding abuse.evtx
- ID 768,775,793,796,817,840-BitLocker encryption activated.evtx
- ID4688-Delete VSS backup (WMI).evtx
- ID4688-Delete Window backup (webadmin).evtx
- ID800-4103-4104-Delete VSS backup (PowerShell).evtx
- ID11-DNS hosts files modified.evtx
- .gitignore
- LICENSE.md
- README.md
// repository documentation
Was this content helpful?
(0 ratings)
