Windows Security Events For SOC – Part 2

Here is the continuation of the list of Windows Security Events for SOC.

Windows Security Events for SOC
Windows Security Events for SOC

 

 

 

 

 

 

Note that event ID 1116 is one of the most critical events and is logged by Microsoft Defender Antivirus/compatible antivirus whenever a malware or other potentially unwanted software is detected on a system.

Key Details:
Source: Microsoft-Windows-Defender and Other Antivirus products as well
Event ID: 1116
Task Category: Malware Protection
Level: Information

What it Means: The antimalware platform has successfully identified a potential malware or other malicious content.
Potential Threat: The detected software poses a risk to your system’s security.

The SOC team and Security Operations team can initiate the investigation to dive deeper and validate cleaning, source of infection and other corrective measures needed.

Published by

Jamez

Sherlock Holmes

Leave a Reply

Discover more from Cybersecurity 24x7

Subscribe now to keep reading and get access to the full archive.

Continue reading