{
  "version": "Notebook/1.0",
  "items": [
    {
      "type": 9,
      "content": {
        "version": "KqlParameterItem/1.0",
        "crossComponentResources": [
          "value::selected"
        ],
        "parameters": [
          {
            "id": "982e7108-791d-4582-b245-f6c618045e71",
            "version": "KqlParameterItem/1.0",
            "name": "subscriptionId",
            "type": 6,
            "isGlobal": true,
            "value": "",
            "typeSettings": {
              "additionalResourceOptions": [
                "value::1"
              ],
              "includeAll": false
            },
            "label": "Subscription"
          },
          {
            "id": "733de5e8-7809-4625-8ad9-8f92d5f800dc",
            "version": "KqlParameterItem/1.0",
            "name": "Workspace",
            "type": 5,
            "isGlobal": true,
            "query": "resources\r\n| where type == \"microsoft.operationalinsights/workspaces\"\r\n| project id, name\r\n| order by tolower(name) asc",
            "crossComponentResources": [
              "{subscriptionId}"
            ],
            "typeSettings": {
              "additionalResourceOptions": []
            },
            "queryType": 1,
            "resourceType": "microsoft.resourcegraph/resources",
            "value": ""
          },
          {
            "id": "09b4b7ab-4411-4a5a-a74b-192c42d5e951",
            "version": "KqlParameterItem/1.0",
            "name": "Help",
            "type": 10,
            "isRequired": true,
            "typeSettings": {
              "additionalResourceOptions": [],
              "showDefault": false
            },
            "jsonData": "[\"Yes\",\"No\"]",
            "timeContext": {
              "durationMs": 86400000
            },
            "value": "No"
          },
          {
            "id": "6cc3c2b9-6cf3-467b-980d-a50e35b679df",
            "version": "KqlParameterItem/1.0",
            "name": "Tab",
            "type": 1,
            "isGlobal": true,
            "value": "0",
            "timeContext": {
              "durationMs": 86400000
            }
          },
          {
            "id": "b4f2ef62-94e2-44d3-8a50-ad40ad4be9fe",
            "version": "KqlParameterItem/1.0",
            "name": "Tab2",
            "type": 1,
            "isGlobal": true,
            "value": "1"
          },
          {
            "id": "3f575490-f742-4737-93a0-c01762fe1e7c",
            "version": "KqlParameterItem/1.0",
            "name": "selectedDataSource",
            "type": 1,
            "isGlobal": true,
            "isHiddenWhenLocked": true
          },
          {
            "id": "858fa5cb-4376-449a-801c-7a26cc023e54",
            "version": "KqlParameterItem/1.0",
            "name": "resourceGroup",
            "type": 1,
            "isGlobal": true,
            "isHiddenWhenLocked": true,
            "criteriaData": [
              {
                "criteriaContext": {
                  "operator": "Default",
                  "resultValType": "static",
                  "resultVal": "{Workspace:resourcegroup}"
                }
              }
            ]
          },
          {
            "id": "3aa6d8ec-2bb0-484b-8492-d405f622cff1",
            "version": "KqlParameterItem/1.0",
            "name": "Subscriptionpath",
            "type": 1,
            "isHiddenWhenLocked": true,
            "criteriaData": [
              {
                "criteriaContext": {
                  "operator": "Default",
                  "resultValType": "param",
                  "resultVal": "subscriptionId"
                }
              }
            ]
          },
          {
            "id": "b8fb7658-f575-4360-acd6-2a924c0776fa",
            "version": "KqlParameterItem/1.0",
            "name": "selectedRule",
            "type": 1,
            "isGlobal": true,
            "isHiddenWhenLocked": true,
            "value": ""
          },
          {
            "id": "2964a1a8-7f3f-4390-b590-58d8d0a15a55",
            "version": "KqlParameterItem/1.0",
            "name": "WSLocation",
            "type": 1,
            "query": "resources\r\n| where type == 'microsoft.operationalinsights/workspaces'\r\n| where id == '{Workspace}'\r\n| project location",
            "crossComponentResources": [
              "value::selected"
            ],
            "isHiddenWhenLocked": true,
            "queryType": 1,
            "resourceType": "microsoft.resourcegraph/resources"
          },
          {
            "id": "929201b4-0b2b-472c-b57b-537072346cd4",
            "version": "KqlParameterItem/1.0",
            "name": "selectedRuleFormatted",
            "type": 1,
            "query": "print rule=dynamic({selectedRule})\r\n| evaluate bag_unpack(rule)\r\n| extend type = column_ifexists(\"kind\",\"Custom\")\r\n| project rule = pack_all()\r\n| project ruleFormatted = todynamic(replace_regex(tostring(rule), @'[\\s-]', @'_'))",
            "isHiddenWhenLocked": true,
            "typeSettings": {
              "multiLineText": true,
              "editorLanguage": "json",
              "multiLineHeight": 2,
              "preFormatJsonData": true
            },
            "queryType": 0,
            "resourceType": "microsoft.operationalinsights/workspaces"
          }
        ],
        "style": "above",
        "queryType": 1,
        "resourceType": "microsoft.resourcegraph/resources"
      },
      "name": "Parameters"
    },
    {
      "type": 1,
      "content": {
        "json": "### Help\r\n\r\nIf experiencing issues with the NSA event IDs, follow these steps to address the error:\r\n1. Find the nsaRecommendedEvents parameter.\r\n2. Click edit under the parameter.\r\n3. Click on the parameter name and click on the pencil icon.\r\n4. Click 'mark as trusted'.\r\n5. Click save.\r\n\r\nThis process is required when utilizing external sources of information outside of Azure. Once the source is trusted, the data can be used in the workbook.",
        "style": "info"
      },
      "conditionalVisibility": {
        "parameterName": "Help",
        "comparison": "isEqualTo",
        "value": "Yes"
      },
      "name": "text - 22"
    },
    {
      "type": 9,
      "content": {
        "version": "KqlParameterItem/1.0",
        "parameters": [
          {
            "id": "a76aa783-57a3-48b0-aa92-c35ee2c9e594",
            "version": "KqlParameterItem/1.0",
            "name": "nsaRecommendedEvents",
            "type": 1,
            "isGlobal": true,
            "query": "{\"version\":\"CustomEndpoint/1.0\",\"data\":null,\"headers\":[],\"method\":\"GET\",\"url\":\"https://raw.githubusercontent.com/nsacyber/Event-Forwarding-Guidance/master/Events/RecommendedEvents.json\",\"contentType\":\"text/plain\",\"urlParams\":[],\"transformers\":null,\"ignoreStandardHeaders\":true}",
            "isHiddenWhenLocked": true,
            "typeSettings": {
              "multiLineText": true,
              "editorLanguage": "json",
              "preFormatJsonData": true
            },
            "timeContext": {
              "durationMs": 86400000
            },
            "queryType": 10
          }
        ],
        "style": "pills",
        "queryType": 10
      },
      "name": "parameters - 1"
    },
    {
      "type": 1,
      "content": {
        "json": "#### Feedback\r\n\r\nLooking to provide feedback? Use [this form here](https://forms.microsoft.com/r/dQvGMjpD2H)."
      },
      "name": "text - 21"
    },
    {
      "type": 11,
      "content": {
        "version": "LinkItem/1.0",
        "style": "tabs",
        "tabStyle": "bigger",
        "links": [
          {
            "id": "c800723a-60f6-46a4-a5a8-fa5d03df5e94",
            "cellValue": "Tab",
            "linkTarget": "parameter",
            "linkLabel": "Introduction",
            "subTarget": "0",
            "style": "link"
          },
          {
            "id": "e42c1fb9-4928-4f58-9ba9-1b4985710f30",
            "cellValue": "null",
            "linkTarget": "step",
            "linkLabel": "➡",
            "style": "link"
          },
          {
            "id": "9bd8be06-3040-45d8-ac03-5130f1bac6b7",
            "cellValue": "Tab",
            "linkTarget": "parameter",
            "linkLabel": "Identify Data Sources / Configure DCR",
            "subTarget": "1",
            "style": "link"
          },
          {
            "id": "6630f564-4a55-449a-b9e9-3b25222ff10a",
            "cellValue": "null",
            "linkTarget": "step",
            "linkLabel": "➡",
            "style": "link"
          },
          {
            "id": "6c8007d8-88d2-4e04-a6ba-e42a705b1c67",
            "cellValue": "Tab",
            "linkTarget": "parameter",
            "linkLabel": "Review/Modify DCR Rules",
            "subTarget": "2",
            "style": "link"
          },
          {
            "id": "1a1d9663-88dd-4e5e-809d-fd5411f0437e",
            "cellValue": "null",
            "linkTarget": "step",
            "linkLabel": "➡",
            "style": "link"
          },
          {
            "id": "f654b71d-5ea6-436a-88e8-acd750855ceb",
            "cellValue": "Tab",
            "linkTarget": "parameter",
            "linkLabel": "Dataflow and Transformation",
            "subTarget": "3",
            "style": "link"
          },
          {
            "id": "3293616c-89ab-4795-a45c-bba0ca7717b7",
            "cellValue": "null",
            "linkTarget": "step",
            "linkLabel": "➡",
            "style": "link"
          },
          {
            "id": "c8010832-64eb-4bc5-9c20-cf09fdc0bc95",
            "cellValue": "Tab",
            "linkTarget": "parameter",
            "linkLabel": "DCR Reporting",
            "subTarget": "5",
            "style": "link"
          },
          {
            "id": "2576699f-2f6b-49d9-9024-10af11d04dee",
            "cellValue": "Tab",
            "linkTarget": "parameter",
            "linkLabel": "Helpful Tools/Workbooks",
            "subTarget": "4",
            "style": "link"
          }
        ]
      },
      "name": "Step Tabs",
      "styleSettings": {
        "margin": "30px 0px 0px 0px"
      }
    },
    {
      "type": 12,
      "content": {
        "version": "NotebookGroup/1.0",
        "groupType": "editable",
        "items": [
          {
            "type": 1,
            "content": {
              "json": "[Data Collection Rules (DCRs)](https://docs.microsoft.com/azure/azure-monitor/essentials/data-collection-rule-overview) define the data collection process in Azure Monitor. DCRs specify what data should be collected, how to transform that data, and where to send that data. Some DCRs will be created and managed by Azure Monitor to collect a specific set of data to enable insights and visualizations. You may also create your own DCRs to define the set of data required for other scenarios.\r\n\r\n![recommended](https://shields.io/badge/-Identify_what_to_collect-blue) \r\n- You first want to identify what type of data sources you wish to collect.\r\n\r\n![recommended](https://shields.io/badge/-Identify_where_to_store_logs-blue) \r\n- Identify the target workspace to store the data based on region, compliance regulations, access. (Only if this applies)\r\n\r\n![recommended](https://shields.io/badge/-Decide_to_filter_or_transform_the_data-blue) \r\n- Decide if you wish to transform the data prior to storing the data\r\n\t- It's recommended to parse and filter the data prior to ingestion, but you can leverage KQL to transform/filter the data prior to storage. \r\n\r\n![recommended](https://shields.io/badge/-Begin_onboarding_and_complete_dependencies-blue) \r\n- **Complete pre-requisites and onboard devices**\r\n\t- You will then want to complete any initial pre-requisites and onboarding to ensure you have the data sources ready to send logs to the target workspace.\r\n\r\n\r\n\t\t"
            },
            "conditionalVisibility": {
              "parameterName": "Tab",
              "comparison": "isEqualTo",
              "value": "0"
            },
            "name": "text - 1",
            "styleSettings": {
              "margin": "50px 0px 0px 0px"
            }
          },
          {
            "type": 12,
            "content": {
              "version": "NotebookGroup/1.0",
              "groupType": "editable",
              "title": "Docs",
              "expandable": true,
              "expanded": true,
              "items": [
                {
                  "type": 11,
                  "content": {
                    "version": "LinkItem/1.0",
                    "style": "tabs",
                    "links": [
                      {
                        "id": "08792354-ed17-4f76-b40c-082f70ef6539",
                        "cellValue": "IntroTab",
                        "linkTarget": "parameter",
                        "linkLabel": "Azure Data Sources",
                        "subTarget": "1",
                        "style": "link"
                      },
                      {
                        "id": "6aa4434a-e32c-407e-8cfb-706ba8254db1",
                        "cellValue": "IntroTab",
                        "linkTarget": "parameter",
                        "linkLabel": "On-premise and Cloud Data Sources",
                        "subTarget": "2",
                        "style": "link"
                      },
                      {
                        "id": "8b416835-81ae-41f9-a18c-38e87e9dc4af",
                        "cellValue": "IntroTab",
                        "linkTarget": "parameter",
                        "linkLabel": "Custom/Transform",
                        "subTarget": "3",
                        "style": "link"
                      }
                    ]
                  },
                  "name": "links - 2"
                },
                {
                  "type": 12,
                  "content": {
                    "version": "NotebookGroup/1.0",
                    "groupType": "editable",
                    "items": [
                      {
                        "type": 11,
                        "content": {
                          "version": "LinkItem/1.0",
                          "style": "nav",
                          "links": [
                            {
                              "id": "08ca0c35-e97c-4bbc-9717-539012d51fb0",
                              "cellValue": "selectedWorkbook",
                              "linkTarget": "parameter",
                              "linkLabel": "AMA Migration Tracker",
                              "subTarget": "AMA Migration Tracker",
                              "style": "secondary"
                            },
                            {
                              "id": "a0e6fedc-a28f-4fb7-bd4c-90455ac19602",
                              "cellValue": "selectedWorkbook",
                              "linkTarget": "parameter",
                              "linkLabel": "Workspace Usage Report",
                              "subTarget": "Workspace Usage Report",
                              "style": "secondary"
                            },
                            {
                              "id": "9bc722a3-81a5-406a-b54f-9d1c3dc4a2c6",
                              "cellValue": "selectedWorkbook",
                              "linkTarget": "parameter",
                              "linkLabel": "Investigation Insights",
                              "subTarget": "Investigation Insights",
                              "style": "primary"
                            },
                            {
                              "id": "7e9f91a3-7ca5-4e4c-9b4d-5371b7f00297",
                              "cellValue": "https://docs.microsoft.com/azure/azure-monitor/agents/azure-monitor-agent-migration-tools",
                              "linkTarget": "Url",
                              "linkLabel": "DCR Config Generator (PowerShell Script)",
                              "style": "link"
                            }
                          ]
                        },
                        "name": "links - 0"
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "template",
                          "loadFromTemplateId": "https://securityinsights.hosting.portal.azure.net/securityinsights/Content/Workbooks/AMAmigrationTracker.json",
                          "items": []
                        },
                        "conditionalVisibility": {
                          "parameterName": "selectedWorkbook",
                          "comparison": "isEqualTo",
                          "value": "AMA Migration Tracker"
                        },
                        "name": "AMA Migration Tracker"
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "template",
                          "loadFromTemplateId": "https://securityinsights.hosting.portal.azure.net/securityinsights/Content/Workbooks/WorkspaceUsage.json",
                          "items": []
                        },
                        "conditionalVisibility": {
                          "parameterName": "selectedWorkbook",
                          "comparison": "isEqualTo",
                          "value": "Workspace Usage Report"
                        },
                        "name": "Workspace Usage Report"
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "template",
                          "loadFromTemplateId": "https://securityinsights.hosting.portal.azure.net/securityinsights/Content/Workbooks/InvestigationInsights.json",
                          "items": []
                        },
                        "conditionalVisibility": {
                          "parameterName": "selectedWorkbook",
                          "comparison": "isEqualTo",
                          "value": "Investigation Insights"
                        },
                        "name": "Workspace Usage Report - Copy"
                      }
                    ]
                  },
                  "conditionalVisibilities": [
                    {
                      "parameterName": "Tab",
                      "comparison": "isEqualTo",
                      "value": "1"
                    },
                    {
                      "parameterName": "Tab2",
                      "comparison": "isEqualTo",
                      "value": "5"
                    }
                  ],
                  "name": "Helpful Tools"
                },
                {
                  "type": 1,
                  "content": {
                    "json": "\r\n## Onboard Azure Resources\r\n![recommended](https://shields.io/badge/-Recommended-darkgreen) \r\n- Onboard Azure Resources automatically by including them as data sources when [configuring a Data Collection Rule](https://learn.microsoft.com/azure/azure-monitor/essentials/data-collection-rule-overview#create-a-data-collection-rule) in the portal.\r\n\r\n![Alternative](https://shields.io/badge/-Alternative-purple)\r\n- Workloads also could also be onboarded to Sentinel via [Defender for Cloud](https://learn.microsoft.com/azure/defender-for-cloud/auto-deploy-azure-monitoring-agent), or [Azure Policy](https://learn.microsoft.com/azure/azure-monitor/agents/azure-monitor-agent-manage?tabs=azure-portal#use-azure-policy) using [Extensions](https://docs.microsoft.com/azure/azure-monitor/agents/azure-monitor-agent-manage?tabs=ARMAgentPowerShell%2CPowerShellWindows%2CPowerShellWindowsArc%2CCLIWindows%2CCLIWindowsArc) to deploy the AMA Agent.\r\n\r\n![recommended](https://shields.io/badge/-Manual-orange)\r\n- Install manually with installer script provided during configuration of Data Colleciton Rule or downloading the Arc agent installer manually.\r\n- [Download the client installer (preview)](https://go.microsoft.com/fwlink/?linkid=2192409) and follow the [guidance](https://go.microsoft.com/fwlink/?linkid=2191897) here.\r\n\r\n"
                  },
                  "conditionalVisibility": {
                    "parameterName": "IntroTab",
                    "comparison": "isEqualTo",
                    "value": "1"
                  },
                  "name": "On-premise and Cloud "
                },
                {
                  "type": 1,
                  "content": {
                    "json": "## Cloud and On-premises devices\r\ndevices residing in other cloud environments (ie: AWS, Google) or on-premises will require installing an [agent](https://go.microsoft.com/fwlink/?linkid=2191897).\r\n\r\n![recommended](https://shields.io/badge/-Recommended-darkgreen) \r\n- Its highly recommended to onboard devices via [Azure Arc](https://learn.microsoft.com/azure/azure-arc/servers/learn/quick-enable-hybrid-vm) (It's Free). Once onboarded, it will look similar to an Azure VM where you can now point your data collection rule to it, load extensions, run scripts, and additional basic management. \r\n\t- [Connect hybrid machines to Azure Arc](https://docs.microsoft.com/azure/azure-arc/servers/onboard-portal)\r\n\t- Once you have onboarded the machines to Azure Arc, they will appear as a VM. You may configure data colleciton for these devices via an existing DCR or by creating a new one as shown in the Azure Data Sources tab.\r\n\r\n![recommended](https://shields.io/badge/-Manual-orange) \r\n- Manual installation - Leverage the scripts provided for the associated agent to onboard manually. \r\n\t- [Connect hybrid machines to Azure by using Powershell](https://docs.microsoft.com/azure/azure-arc/servers/onboard-powershell)"
                  },
                  "conditionalVisibility": {
                    "parameterName": "IntroTab",
                    "comparison": "isEqualTo",
                    "value": "2"
                  },
                  "name": "On-premise and Cloud  - Copy"
                },
                {
                  "type": 1,
                  "content": {
                    "json": "## Custom Logs and Transformation Rules\r\n\r\nFor general information, please see: </br>\r\n- [Custom logs via API](https://learn.microsoft.com/azure/azure-monitor/logs/logs-ingestion-api-overview) </br>\r\n- [Custom logs via Agent](https://learn.microsoft.com/azure/azure-monitor/agents/data-collection-text-log) </br>\r\n- [Transfromation rules](https://learn.microsoft.com/azure/azure-monitor/essentials/data-collection-transformations)\r\n\r\n![Custom](https://shields.io/badge/-Custom-darkgreen) \r\n- Custom log ingestion via API endpoint will require a [data collection endpoint](https://learn.microsoft.com/azure/azure-monitor/essentials/data-collection-endpoint-overview?tabs=portal).\r\n- Once the endpoint is configured, data collection rules can be applied to the endpoint for ingestion.\r\n- Calls made to the ingestion API will point at the URI of the DCE that was created.\r\n\t\r\n![Transform](https://shields.io/badge/-Transform-orange) \r\n\r\nIt is recommended to apply transformations to logs that require data to be dropped, modified, or transformed. These tables most commonly fall within that category: </br>\r\n- SecurityEvent\r\n- Syslog provided by multiple vendors or for parsing the message\r\n- CommonSecurityLog provided by multiple vendors </br>\r\n\r\nTransformations follow a simple KQL structure to apply the changes at ingest time. Examples structures can be found [here](https://learn.microsoft.com/azure/azure-monitor/essentials/data-collection-transformations-structure)."
                  },
                  "conditionalVisibility": {
                    "parameterName": "IntroTab",
                    "comparison": "isEqualTo",
                    "value": "3"
                  },
                  "name": "Custom and Transform"
                }
              ]
            },
            "name": "Docs"
          }
        ]
      },
      "conditionalVisibility": {
        "parameterName": "Tab",
        "comparison": "isEqualTo",
        "value": "0"
      },
      "name": "Group - Introduction"
    },
    {
      "type": 12,
      "content": {
        "version": "NotebookGroup/1.0",
        "groupType": "editable",
        "items": [
          {
            "type": 11,
            "content": {
              "version": "LinkItem/1.0",
              "style": "tabs",
              "links": [
                {
                  "id": "58a180c2-4ed9-4762-a6ed-e2a6eb9178d3",
                  "cellValue": "Tab3",
                  "linkTarget": "parameter",
                  "linkLabel": "Dataflow",
                  "subTarget": "2",
                  "style": "link"
                }
              ]
            },
            "name": "links - 3"
          },
          {
            "type": 9,
            "content": {
              "version": "KqlParameterItem/1.0",
              "parameters": [
                {
                  "id": "e0b8ba82-eafb-4fb5-a0a9-1c06712da540",
                  "version": "KqlParameterItem/1.0",
                  "name": "dataSourceTypes",
                  "type": 1,
                  "query": "print types=dynamic({selectedRule:$.dataSources})\r\n| project keys = bag_keys(types)",
                  "isHiddenWhenLocked": true,
                  "timeContext": {
                    "durationMs": 86400000
                  },
                  "queryType": 0,
                  "resourceType": "microsoft.operationalinsights/workspaces"
                },
                {
                  "id": "673fb5e8-2b4b-4713-bc7d-bd01e49a195d",
                  "version": "KqlParameterItem/1.0",
                  "name": "kqlQueries",
                  "type": 1,
                  "isHiddenWhenLocked": true,
                  "criteriaData": [
                    {
                      "criteriaContext": {
                        "leftOperand": "selectedRule",
                        "operator": "isValidJson",
                        "rightValType": "param",
                        "resultValType": "static",
                        "resultVal": "{selectedRule:$.queries}"
                      }
                    },
                    {
                      "criteriaContext": {
                        "operator": "Default",
                        "rightValType": "param",
                        "resultValType": "param"
                      }
                    }
                  ]
                },
                {
                  "id": "d4b35594-c0cf-48e6-b6cf-2f137522f59d",
                  "version": "KqlParameterItem/1.0",
                  "name": "kqlConfigured",
                  "type": 1,
                  "isHiddenWhenLocked": true,
                  "criteriaData": [
                    {
                      "criteriaContext": {
                        "leftOperand": "kqlQueries",
                        "operator": "isNotNull",
                        "rightValType": "param",
                        "resultValType": "static",
                        "resultVal": "true"
                      }
                    },
                    {
                      "criteriaContext": {
                        "operator": "Default",
                        "resultValType": "static",
                        "resultVal": "false"
                      }
                    }
                  ]
                },
                {
                  "id": "390017c9-d523-4a5a-b2b2-61e7814bac36",
                  "version": "KqlParameterItem/1.0",
                  "name": "selectedInputStream",
                  "type": 1,
                  "isHiddenWhenLocked": true
                },
                {
                  "id": "351bccb0-9cbb-4e5f-a4b9-1d5933c78cb8",
                  "version": "KqlParameterItem/1.0",
                  "name": "selectedRuleType",
                  "type": 1,
                  "isHiddenWhenLocked": true,
                  "criteriaData": [
                    {
                      "criteriaContext": {
                        "leftOperand": "selectedRule",
                        "operator": "isValidJson",
                        "rightValType": "param",
                        "resultValType": "static",
                        "resultVal": "{selectedRule:$.kind}"
                      }
                    },
                    {
                      "criteriaContext": {
                        "operator": "Default",
                        "rightValType": "param",
                        "resultValType": "param"
                      }
                    }
                  ]
                },
                {
                  "id": "59c29b06-aceb-4ffb-814a-f98ee1a02577",
                  "version": "KqlParameterItem/1.0",
                  "name": "icons",
                  "type": 1,
                  "isGlobal": true,
                  "query": "{\"version\":\"1.0.0\",\"content\":\"{\\r\\n\\t\\\"icons\\\": {\\r\\n\\t\\t\\\"Windows\\\" : \\\"Windows\\\",\\r\\n\\t\\t\\\"Syslog\\\" : \\\"linux\\\",\\r\\n\\t\\t\\\"Custom\\\" : \\\"StackEdit\\\",\\r\\n\\t\\t\\\"WorkspaceTransforms\\\" : \\\"Tailwind CSS\\\"\\r\\n\\t}\\r\\n}\",\"transformers\":null}",
                  "isHiddenWhenLocked": true,
                  "queryType": 8
                },
                {
                  "id": "9325c0ca-0338-488f-a4eb-58242472a2f3",
                  "version": "KqlParameterItem/1.0",
                  "name": "selectedRuleIcon",
                  "type": 1,
                  "isGlobal": true,
                  "query": "print icons=dynamic({icons})\r\n| evaluate bag_unpack(icons)\r\n| project icon = column_ifexists(\"{selectedRuleType}\",\"Databricks\")",
                  "isHiddenWhenLocked": true,
                  "queryType": 0,
                  "resourceType": "microsoft.operationalinsights/workspaces"
                }
              ],
              "style": "pills",
              "doNotRunWhenHidden": true,
              "queryType": 0,
              "resourceType": "microsoft.operationalinsights/workspaces"
            },
            "name": "parameters - 3"
          },
          {
            "type": 1,
            "content": {
              "json": "### Help and Guide\r\n\r\nThis tab is meant to disect the data collection stream that is configued within the DCR that was selected in the previous tab. This section breaks up the stream into data sources, data flow, transformation, and destination. </br>\r\n\r\nThis information should be used when reviewing DCRs granularly. \r\n\r\n#### Data Sources\r\nThis portion will list the type of stream (Windows, Syslog, Custom, etc.) The stream name will show which table the data will be sent to. The name of the source can be clicked on to review the properties from the DCR. A source will not be listed if the source is custom or a workspace transform.</br>\r\n\r\n#### Data Flow\r\nThis portion will list the start of the stream, if there is a KQL transform and what it is, and the end location for the data. If there is a transformation rule in place to send the data elsewhere, this area will refect that. Ex. Custom-SecurityEvent -> Microsoft-SecurityEvent </br>\r\n\r\nIf looking to add or modify existing transform KQL for the DCR, go back to the third tab and use the 'modify DCR' section to modify and update the template. If looking to create a new table transformation, go back to the second tab and use the 'transform DCR' button to create a new one. </br>\r\n\r\n#### Destination Workspace\r\nThis portion will highlight the streams that exist within the DCR and which workspace they are pointing to. In a multi-homing DCR, more than one workspace will be listed.\r\n",
              "style": "info"
            },
            "conditionalVisibility": {
              "parameterName": "Help",
              "comparison": "isEqualTo",
              "value": "Yes"
            },
            "name": "text - 5"
          },
          {
            "type": 1,
            "content": {
              "json": "\r\n![DCR Name](https://shields.io/badge/{selectedRuleFormatted:$.name}-{selectedRuleFormatted:$.type}-blue?logo={selectedRuleIcon}&style=for-the-badge)"
            },
            "name": "text - 4"
          },
          {
            "type": 12,
            "content": {
              "version": "NotebookGroup/1.0",
              "groupType": "editable",
              "items": [
                {
                  "type": 12,
                  "content": {
                    "version": "NotebookGroup/1.0",
                    "groupType": "editable",
                    "items": [
                      {
                        "type": 1,
                        "content": {
                          "json": "\r\n**Data Source types :** <br>\r\n{dataSourceTypes:$.*}"
                        },
                        "conditionalVisibility": {
                          "parameterName": "selectedRuleType",
                          "comparison": "isNotEqualTo",
                          "value": "WorkspaceTransforms"
                        },
                        "name": "Help"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "{\"version\":\"1.0.0\",\"content\":\"{selectedRule:$.dataSources}\",\"transformers\":[{\"type\":\"jsonpath\",\"settings\":{\"tablePath\":\"$.*.*\",\"columns\":[{\"path\":\"name\",\"columnid\":\"name\"},{\"path\":\"streams.*\",\"columnid\":\"streamName\",\"substringRegexMatch\":\"Microsoft-(.*)\",\"substringReplace\":\"$1\"},{\"path\":\"streams.*\",\"columnid\":\"streams\"},{\"path\":\"$\",\"columnid\":\"properties\"}]}}]}",
                          "size": 0,
                          "title": "Data Sources",
                          "noDataMessage": "This DCR either does not have a data source or the source is custom.",
                          "noDataMessageStyle": 4,
                          "exportFieldName": "stream",
                          "exportParameterName": "selectedDataSource",
                          "exportToExcelOptions": "all",
                          "queryType": 8,
                          "gridSettings": {
                            "formatters": [
                              {
                                "columnMatch": "name",
                                "formatter": 7,
                                "formatOptions": {
                                  "linkTarget": "GenericDetails",
                                  "linkIsContextBlade": true,
                                  "customColumnWidthSetting": "32ch"
                                }
                              },
                              {
                                "columnMatch": "streamName",
                                "formatter": 5,
                                "formatOptions": {
                                  "customColumnWidthSetting": "18.5714ch"
                                }
                              },
                              {
                                "columnMatch": "streams",
                                "formatter": 0,
                                "formatOptions": {
                                  "customColumnWidthSetting": "26.8571ch"
                                }
                              },
                              {
                                "columnMatch": "properties",
                                "formatter": 7,
                                "formatOptions": {
                                  "linkTarget": "CellDetails",
                                  "linkLabel": "📝",
                                  "linkIsContextBlade": true,
                                  "customColumnWidthSetting": "13ch"
                                }
                              }
                            ],
                            "labelSettings": [
                              {
                                "columnId": "streamName",
                                "label": "Stream Name"
                              },
                              {
                                "columnId": "streams",
                                "label": "Stream"
                              },
                              {
                                "columnId": "properties",
                                "label": " "
                              }
                            ]
                          },
                          "sortBy": []
                        },
                        "conditionalVisibility": {
                          "parameterName": "selectedRuleType",
                          "comparison": "isNotEqualTo",
                          "value": "WorkspaceTransforms"
                        },
                        "name": "Data Sources",
                        "styleSettings": {
                          "padding": "5px",
                          "showBorder": true
                        }
                      }
                    ]
                  },
                  "customWidth": "33",
                  "name": "dataSource"
                },
                {
                  "type": 12,
                  "content": {
                    "version": "NotebookGroup/1.0",
                    "groupType": "editable",
                    "items": [
                      {
                        "type": 9,
                        "content": {
                          "version": "KqlParameterItem/1.0",
                          "crossComponentResources": [
                            "{Workspace}"
                          ],
                          "parameters": [
                            {
                              "id": "3aaecd6f-67c4-4094-afc9-1a83287c37ed",
                              "version": "KqlParameterItem/1.0",
                              "name": "DestinationName",
                              "type": 1,
                              "query": "print destination = '{selectedRule:$.destinations}'\r\n| extend workspaceResourceId = tostring(parse_json(tostring(parse_json(destination).logAnalytics))[0].workspaceResourceId)\r\n| project DestinationName = split(workspaceResourceId, '/')[8]",
                              "crossComponentResources": [
                                "{Workspace}"
                              ],
                              "isHiddenWhenLocked": true,
                              "timeContext": {
                                "durationMs": 86400000
                              },
                              "queryType": 0,
                              "resourceType": "microsoft.operationalinsights/workspaces"
                            }
                          ],
                          "style": "pills",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces"
                        },
                        "name": "parameters - 3"
                      },
                      {
                        "type": 1,
                        "content": {
                          "json": "## Data Flow\r\n---\r\n\r\nThis ties the data source streams with the destination and applies any transformation to the data prior to ingestion into the workspace\r\n\r\n![dataSource](https://shields.io/badge/{dataSourceTypes:$.*}-orange) \r\n![right_arrow](https://shields.io/badge/--------------▶-darkgreen) \r\n![dataSource](https://shields.io/badge/TransformKQL-darkgray?style=flat-square)\r\n![right_arrow](https://shields.io/badge/-------------▶-darkgreen) \r\n![dataSource](https://shields.io/badge/{DestinationName}-blue)\r\n"
                        },
                        "name": "Help - Copy"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "{\"version\":\"1.0.0\",\"content\":\"{selectedRule:$.dataFlows}\",\"transformers\":[{\"type\":\"jsonpath\",\"settings\":{\"tablePath\":\"$.*\",\"columns\":[{\"path\":\"streams.*\",\"columnid\":\"stream\"},{\"path\":\"transformKql\",\"columnid\":\"transformKql\"},{\"path\":\"destinations.*\",\"columnid\":\"destination\"},{\"path\":\"streams.*\",\"columnid\":\"tableName\",\"substringRegexMatch\":\"(Microsoft)-(Table-)+(.*)\",\"substringReplace\":\"$3\"}]}}]}",
                          "size": 4,
                          "title": "Ingestion Time Transformation (KQL)",
                          "noDataMessage": "There seems to be no Data Sources configured for data collection rule",
                          "noDataMessageStyle": 4,
                          "exportedParameters": [
                            {
                              "fieldName": "stream",
                              "parameterName": "selectedInputStream"
                            },
                            {
                              "fieldName": "selectedDestination",
                              "parameterName": "destination",
                              "parameterType": 1
                            },
                            {
                              "fieldName": "transformKql",
                              "parameterName": "selectedKql",
                              "parameterType": 1
                            },
                            {
                              "fieldName": "tableName",
                              "parameterName": "selectedTableName",
                              "parameterType": 1
                            }
                          ],
                          "exportToExcelOptions": "all",
                          "queryType": 8,
                          "gridSettings": {
                            "formatters": [
                              {
                                "columnMatch": "transformKql",
                                "formatter": 7,
                                "formatOptions": {
                                  "linkTarget": "CellDetails",
                                  "linkLabel": "✒ KQL",
                                  "linkIsContextBlade": true
                                }
                              },
                              {
                                "columnMatch": "destination",
                                "formatter": 5
                              },
                              {
                                "columnMatch": "name",
                                "formatter": 0,
                                "formatOptions": {
                                  "customColumnWidthSetting": "32ch"
                                }
                              },
                              {
                                "columnMatch": "streams",
                                "formatter": 0,
                                "formatOptions": {
                                  "customColumnWidthSetting": "26.8571ch"
                                }
                              },
                              {
                                "columnMatch": "properties",
                                "formatter": 7,
                                "formatOptions": {
                                  "linkTarget": "CellDetails",
                                  "linkLabel": "📝",
                                  "linkIsContextBlade": true,
                                  "customColumnWidthSetting": "13ch"
                                }
                              }
                            ],
                            "labelSettings": [
                              {
                                "columnId": "stream",
                                "label": "Stream Name"
                              },
                              {
                                "columnId": "transformKql",
                                "label": "KQL"
                              }
                            ]
                          },
                          "sortBy": []
                        },
                        "name": "Ingestion Time Transformation (KQL)",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 9,
                        "content": {
                          "version": "KqlParameterItem/1.0",
                          "crossComponentResources": [
                            "{Workspace}"
                          ],
                          "parameters": [
                            {
                              "id": "054dd561-f425-4633-9201-b0cb7255f4b9",
                              "version": "KqlParameterItem/1.0",
                              "name": "selectedKql",
                              "label": "KQL Query",
                              "type": 1,
                              "isGlobal": true,
                              "typeSettings": {
                                "multiLineText": true,
                                "editorLanguage": "kql"
                              },
                              "timeContext": {
                                "durationMs": 86400000
                              },
                              "value": "source | project ReceiptTime, DeviceVendor, DeviceProduct, TimeGenerated, DeviceEventClassID,LogSeverity,OriginalLogSeverity,DeviceAction,SimplifiedDeviceAction,DestinationPort,DestinationIP,DeviceName,Protocol,SourcePort,SourceIP,ThreatSeverity,MaliciousIPLongitude,MaliciousIPLatitude,DeviceVersion,Activity,ApplicationProtocol,EventCount,DestinationTranslatedPort,DeviceExternalID,DeviceInboundInterface,DeviceOutboundInterface,DestinationProcessId,ProcessID,ExternalID,FileSize,ReceivedBytes,OldFileSize,SentBytes,RequestURL,RequestClientApplication,SourceTranslatedPort,SourceProcessId,SourceUserName,EventType,DeviceCustomFloatingPoint1,DeviceCustomFloatingPoint1Label,DeviceCustomFloatingPoint2,DeviceCustomFloatingPoint3,DeviceCustomFloatingPoint4,DeviceCustomFloatingPoint4Label,DeviceCustomNumber1,DeviceCustomNumber2,DeviceCustomNumber3,DeviceCustomString1,DeviceCustomString1Label,DeviceCustomString2,DeviceCustomString2Label,DeviceCustomString3,DeviceCustomString3Label,DeviceCustomString4,DeviceCustomString4Label,DeviceCustomString5Label,FlexNumber1,FlexNumber2,AdditionalExtensions,StartTime,EndTime,Type"
                            }
                          ],
                          "style": "above",
                          "doNotRunWhenHidden": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces"
                        },
                        "conditionalVisibility": {
                          "parameterName": "kqlConfigured",
                          "comparison": "isEqualTo",
                          "value": "true"
                        },
                        "name": "KQL Query Editor"
                      }
                    ]
                  },
                  "customWidth": "33",
                  "name": "Dataflow"
                },
                {
                  "type": 12,
                  "content": {
                    "version": "NotebookGroup/1.0",
                    "groupType": "editable",
                    "items": [
                      {
                        "type": 1,
                        "content": {
                          "json": "## Destination Workspace\r\n---\r\n\r\nThis ties the data source streams with the destination and applies any transformation to the data prior to ingestion into the workspace"
                        },
                        "name": "Help - Copy - Copy"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "{\"version\":\"1.0.0\",\"content\":\"{selectedRule:$.destinations}\",\"transformers\":[{\"type\":\"jsonpath\",\"settings\":{\"tablePath\":\"$.logAnalytics\",\"columns\":[{\"path\":\"name\",\"columnid\":\"stream\"},{\"path\":\"workspaceResourceId\",\"columnid\":\"workspaceResourceId\"},{\"path\":\"$\",\"columnid\":\"properties\"}]}}]}",
                          "size": 0,
                          "title": "Destinations",
                          "noDataMessage": "No destinations configured",
                          "exportedParameters": [
                            {
                              "fieldName": "id",
                              "parameterName": "destination",
                              "parameterType": 5
                            }
                          ],
                          "queryType": 8,
                          "gridSettings": {
                            "formatters": [
                              {
                                "columnMatch": "properties",
                                "formatter": 7,
                                "formatOptions": {
                                  "linkTarget": "CellDetails",
                                  "linkLabel": "📝",
                                  "linkIsContextBlade": true
                                }
                              },
                              {
                                "columnMatch": "info",
                                "formatter": 7,
                                "formatOptions": {
                                  "linkColumn": "properties",
                                  "linkTarget": "CellDetails",
                                  "linkLabel": "📝",
                                  "linkIsContextBlade": true
                                }
                              },
                              {
                                "columnMatch": "id",
                                "formatter": 13,
                                "formatOptions": {
                                  "linkTarget": "Resource",
                                  "linkIsContextBlade": true,
                                  "showIcon": true
                                }
                              }
                            ],
                            "labelSettings": [
                              {
                                "columnId": "stream",
                                "label": "Stream"
                              },
                              {
                                "columnId": "workspaceResourceId",
                                "label": "Workspace Resource Id"
                              },
                              {
                                "columnId": "properties",
                                "label": "  "
                              }
                            ]
                          }
                        },
                        "name": "Destinations",
                        "styleSettings": {
                          "margin": "0px",
                          "showBorder": true
                        }
                      }
                    ]
                  },
                  "customWidth": "33",
                  "name": "Destinations"
                }
              ]
            },
            "conditionalVisibility": {
              "parameterName": "Tab3",
              "comparison": "isEqualTo",
              "value": "2"
            },
            "name": "Data Transformation"
          }
        ]
      },
      "conditionalVisibility": {
        "parameterName": "Tab",
        "comparison": "isEqualTo",
        "value": "3"
      },
      "name": "Transformation",
      "styleSettings": {
        "margin": "35px 0px 0px 0px",
        "padding": "5px"
      }
    },
    {
      "type": 12,
      "content": {
        "version": "NotebookGroup/1.0",
        "groupType": "editable",
        "items": [
          {
            "type": 1,
            "content": {
              "json": "### Help\r\n\r\nA few options are offered:\r\n- Linux\r\n- Windows\r\n- Table Transform\r\n- Essentials\r\n\r\n#### Linux\r\nThe Linux button will open two options for deploying DCRs. The two options are for Syslog or CEF. When one of the buttons is clicked, a DCR wizard will open for the log type. This DCR wizard is the same experience that be found in Azure Monitor.\r\n\r\n#### Windows\r\nThe Windows button will expand collection options based on scenarios such as: </br>\r\n- NSA Recommended Event IDs\r\n- MITRE Tactic Alignment\r\n- Recommended Event IDs\r\n- File path via the existing wizard</br>\r\n\r\n#### Transform\r\nThe Table Transformation button will open a builder to assist in building a table transform DCR. These DCRs will apply ingestion transformation to logs brought in (these rules do not apply to AMA data sources).\r\n\r\n#### Custom Logs\r\nThis button will open the tables blade wizard for creating new custom logs via DCR. This will provide the ability to upload a file to generate the schema and create a transformation on the data at ingestion time.\r\n\r\n#### Essentials\r\nThe Essentials button will expand options for UEBA, Analytic Rules, and Hunting. These three options will allow for DCRs that contains the essential event IDs for both features to operate to be deployed.\r\n",
              "style": "info"
            },
            "conditionalVisibility": {
              "parameterName": "Help",
              "comparison": "isEqualTo",
              "value": "Yes"
            },
            "name": "text - 3"
          },
          {
            "type": 12,
            "content": {
              "version": "NotebookGroup/1.0",
              "groupType": "editable",
              "title": "Create New DCR Rule",
              "items": [
                {
                  "type": 11,
                  "content": {
                    "version": "LinkItem/1.0",
                    "style": "paragraph",
                    "links": [
                      {
                        "id": "a2977917-b1c7-46fc-b88f-82c4a11dcf03",
                        "cellValue": "Datatype",
                        "linkTarget": "parameter",
                        "linkLabel": "New Linux DCR",
                        "subTarget": "Linux",
                        "style": "primary",
                        "linkIsContextBlade": true,
                        "bladeOpenContext": {
                          "bladeName": "CreateDataCollectionRulesViewModel",
                          "extensionName": "Microsoft_Azure_Monitoring",
                          "bladeJsonParameters": "{\r\n    \"_provisioningContext\": {\r\n        \"initialValues\": {\r\n            \"subscriptionIds\": [\r\n                \"{workspace:subscriptionId}\"\r\n            ],\r\n            \"resourceGroupNames\": [],\r\n            \"locationNames\": [\r\n                \"westeurope\",\r\n                \"westus\",\r\n                \"eastus2\",\r\n                \"westus2\",\r\n                \"eastus\"\r\n            ]\r\n        },\r\n        \"telemetryId\": \"65c98228-848a-4561-aa84-bac77ce9d4d0\",\r\n        \"marketplaceItem\": {\r\n            \"categoryIds\": [],\r\n            \"id\": \"Microsoft.Portal\",\r\n            \"itemDisplayName\": \"NoMarketplace\",\r\n            \"products\": [],\r\n            \"version\": \"\",\r\n            \"productsWithNoPricing\": [],\r\n            \"publisherDisplayName\": \"Microsoft.Portal\",\r\n            \"deploymentName\": \"NoMarketplace\",\r\n            \"launchingContext\": {\r\n                \"telemetryId\": \"65c98228-848a-4561-aa84-bac77ce9d4d0\",\r\n                \"source\": [\r\n                    \"ARGBrowseResourcesInMenu\",\r\n                    \"{ Name: Part, Type: [0]HubsExtension-[1]ARGBrowseResourcesInMenu-[2]TemplateBladeVirtualLens-[5]ARGBrowseResourcesInMenu, Id: Part-ARGBrowseResourcesInMenu-72 }\",\r\n                    \"Part-ARGBrowseResourcesInMenu-72\"\r\n                ],\r\n                \"galleryItemId\": \"\"\r\n            },\r\n            \"deploymentTemplateFileUris\": {},\r\n            \"uiMetadata\": null\r\n        }\r\n    }\r\n}"
                        }
                      },
                      {
                        "id": "b720a13c-3218-4d3a-ba6c-e4a4717d3ccd",
                        "cellValue": "Datatype",
                        "linkTarget": "parameter",
                        "linkLabel": "New Windows DCR",
                        "subTarget": "Windows",
                        "style": "primary"
                      },
                      {
                        "id": "f0afb95c-3b88-4ee4-b0d7-b99db79bfb0e",
                        "cellValue": "Datatype",
                        "linkTarget": "parameter",
                        "linkLabel": "New Table Transformation DCR",
                        "subTarget": "Transformation",
                        "style": "primary",
                        "linkIsContextBlade": true,
                        "bladeOpenContext": {
                          "bladeName": "CreateCustomLogV2TableBlade",
                          "extensionName": "Microsoft_OperationsManagementSuite_Workspace",
                          "bladeJsonParameters": "{\r\n    \"workspaceResourceId\": \"{workspace}\"\r\n}"
                        }
                      },
                      {
                        "id": "9e06e297-0b3b-4f75-af24-35ebc2484066",
                        "linkTarget": "OpenBlade",
                        "linkLabel": "New Custom Log",
                        "style": "primary",
                        "bladeOpenContext": {
                          "bladeName": "CreateCustomLogV2TableBlade",
                          "extensionName": "Microsoft_OperationsManagementSuite_Workspace",
                          "bladeJsonParameters": "{\r\n    \"workspaceResourceId\": \"{Workspace}\"\r\n}"
                        }
                      },
                      {
                        "id": "a1dd77fa-db73-4404-bcaf-a88dbf214c34",
                        "cellValue": "Datatype",
                        "linkTarget": "parameter",
                        "linkLabel": "New Event Hub Connection",
                        "subTarget": "EH",
                        "style": "primary"
                      },
                      {
                        "id": "996d81db-4bfa-483a-8569-51413b12b0d1",
                        "cellValue": "Datatype",
                        "linkTarget": "parameter",
                        "linkLabel": "Essentials",
                        "subTarget": "Essentials",
                        "style": "primary"
                      },
                      {
                        "id": "b444ecd7-507a-4582-bd37-58d363a44598",
                        "cellValue": "Datatype",
                        "linkTarget": "parameter",
                        "linkLabel": "Reset",
                        "subTarget": "Reset",
                        "style": "primary"
                      }
                    ]
                  },
                  "name": "links - 17",
                  "styleSettings": {
                    "padding": "10px 0px 0px 20px"
                  }
                },
                {
                  "type": 11,
                  "content": {
                    "version": "LinkItem/1.0",
                    "style": "paragraph",
                    "links": [
                      {
                        "id": "484d54d4-60cc-4039-a99e-9086d970a562",
                        "cellValue": "Logtype",
                        "linkTarget": "parameter",
                        "linkLabel": "NSA Category Events",
                        "subTarget": "NSA",
                        "style": "primary"
                      },
                      {
                        "id": "2b867bfd-b2e2-424b-a909-04c2ce6210de",
                        "cellValue": "Logtype",
                        "linkTarget": "parameter",
                        "linkLabel": "MITRE Category Events",
                        "subTarget": "MITRE",
                        "style": "primary"
                      },
                      {
                        "id": "8b75c8b9-b89f-4a24-a3b1-b769673e996d",
                        "cellValue": "Logtype",
                        "linkTarget": "parameter",
                        "linkLabel": "Recommended Event ID",
                        "subTarget": "WE",
                        "style": "primary"
                      },
                      {
                        "id": "63fdd0de-71ec-4986-b780-f4e071f20aea",
                        "linkTarget": "OpenBlade",
                        "linkLabel": "AMA Data Connector",
                        "style": "primary",
                        "bladeOpenContext": {
                          "bladeName": "DataConnectorBlade",
                          "extensionName": "Microsoft_Azure_Security_Insights",
                          "bladeJsonParameters": "{\r\n    \"dataConnectorId\": \"WindowsSecurityEvents\",\r\n    \"initialConnectorTab\": 0,\r\n    \"subscriptionId\": \"{subscriptionId:subscriptionId}\",\r\n    \"resourceGroup\": \"{Workspace:resourceGroup}\",\r\n    \"workspaceName\": \"{Workspace:name}\",\r\n\t\t\"workspaceArmId\": \"{Workspace}\"\r\n}"
                        }
                      },
                      {
                        "id": "1bfb7359-bc4a-4317-9d45-0e00da0c2607",
                        "linkTarget": "OpenBlade",
                        "linkLabel": "File Path DCR",
                        "style": "primary",
                        "linkIsContextBlade": true,
                        "bladeOpenContext": {
                          "bladeName": "CreateDataCollectionRulesViewModel",
                          "extensionName": "Microsoft_Azure_Monitoring",
                          "bladeParameters": []
                        }
                      }
                    ]
                  },
                  "conditionalVisibility": {
                    "parameterName": "Datatype",
                    "comparison": "isEqualTo",
                    "value": "Windows"
                  },
                  "name": "links - 19",
                  "styleSettings": {
                    "padding": "10px 0px 0px 40px"
                  }
                },
                {
                  "type": 11,
                  "content": {
                    "version": "LinkItem/1.0",
                    "style": "paragraph",
                    "links": [
                      {
                        "id": "4462597f-29fe-40b8-9a78-5892f9c28bc7",
                        "cellValue": "",
                        "linkTarget": "OpenBlade",
                        "linkLabel": "New Syslog DCR",
                        "subTarget": "NSA",
                        "style": "primary",
                        "linkIsContextBlade": true,
                        "bladeOpenContext": {
                          "bladeName": "CreateDataCollectionRulesViewModel",
                          "extensionName": "Microsoft_Azure_Monitoring",
                          "bladeJsonParameters": "{\r\n    \"workspaceResourceId\": \"{workspace}\",\r\n    \"subscriptionId\": \"{workspace:subscriptionId}\",\r\n    \"resourceGroup\": \"{workspace:resourceGroup}\"\r\n}"
                        }
                      },
                      {
                        "id": "f2d25bc2-dc66-43cd-bd70-aa0eb559744d",
                        "cellValue": "",
                        "linkTarget": "OpenBlade",
                        "linkLabel": "New CEF DCR",
                        "subTarget": "MITRE",
                        "style": "primary",
                        "linkIsContextBlade": true,
                        "bladeOpenContext": {
                          "bladeName": "DataConnectorBlade",
                          "extensionName": "Microsoft_Azure_Security_Insights",
                          "bladeJsonParameters": "{\r\n    \"dataConnectorId\": \"CefAma\",\r\n    \"initialConnectorTab\": 0,\r\n    \"subscriptionId\": \"{Workspace:subscriptionId}\",\r\n    \"resourceGroup\": \"{Workspace:resourceGroup}\",\r\n    \"workspaceName\": \"{Workspace:name}\"\r\n}"
                        }
                      }
                    ]
                  },
                  "conditionalVisibility": {
                    "parameterName": "Datatype",
                    "comparison": "isEqualTo",
                    "value": "Linux"
                  },
                  "name": "links - 19 - Copy",
                  "styleSettings": {
                    "padding": "10px 0px 0px 40px"
                  }
                },
                {
                  "type": 11,
                  "content": {
                    "version": "LinkItem/1.0",
                    "style": "paragraph",
                    "links": [
                      {
                        "id": "f844edef-ff48-49c2-9094-2e86b08e1d8b",
                        "cellValue": "Essentialtype",
                        "linkTarget": "parameter",
                        "linkLabel": "UEBA Essentials",
                        "subTarget": "UEBA",
                        "style": "primary"
                      },
                      {
                        "id": "2fa98174-6556-4c95-afc4-cd77333f1085",
                        "cellValue": "Essentialtype",
                        "linkTarget": "parameter",
                        "linkLabel": "Analytic Rule Essentials",
                        "subTarget": "AR",
                        "style": "primary"
                      },
                      {
                        "id": "6effe25f-99fc-4987-8239-9cdc9aeaf324",
                        "cellValue": "Essentialtype",
                        "linkTarget": "parameter",
                        "linkLabel": "Hunting Essentials",
                        "subTarget": "Hunting",
                        "style": "primary"
                      }
                    ]
                  },
                  "conditionalVisibility": {
                    "parameterName": "Datatype",
                    "comparison": "isEqualTo",
                    "value": "Essentials"
                  },
                  "name": "Essentials Buttons",
                  "styleSettings": {
                    "padding": "10px 0px 0px 40px"
                  }
                },
                {
                  "type": 12,
                  "content": {
                    "version": "NotebookGroup/1.0",
                    "groupType": "editable",
                    "items": [
                      {
                        "type": 1,
                        "content": {
                          "json": "### Help\r\n\r\n#### Data Collection Transformation\r\n\r\n[Transformations in Azure Monitor](https://docs.microsoft.com/data-collection-transformations.md) allow you to filter or modify incoming data before it's stored in a Log Analytics workspace. They are implemented as a [Kusto Query Language (KQL)](https://docs.microsoft.com/azure/data-explorer/kusto/query/) statement in a [data collection rule (DCR)](https://docs.microsoft.com/azure/azure-monitor/essentials/data-collection-rule-overview). \r\n\r\n- [Data collection transformations in Azure Monitor](https://docs.microsoft.com/azure/azure-monitor/essentials/data-collection-transformations)\r\n\r\n#### Considerations\r\n- During ingestion time transformation, you are limited to a smaller set of [functions/operators](https://docs.microsoft.com/azure/azure-monitor/essentials/data-collection-transformations-structure) to filter/transform the data.\r\n\t- Since the transformation is applied to each record individually, it can't use any KQL operators that act on multiple records.\r\n\t- For example, summarize isn't supported since it summarizes multiple records. \r\n\r\n#### Data Collection Endpoints (DCE)\r\n[Data Collection Endpoints](https://docs.microsoft.com/azure/azure-monitor/essentials/data-collection-endpoint-overview?tabs=portal) are not required unless you:\r\n- Have a need to provide connection for certain data sources of Azure Monitor. \r\n- Wish to use only use private links to communicate and send data and prevent ingesting through the public network access. [(Click for Example)](https://docs.microsoft.com/azure/azure-monitor/essentials/data-collection-endpoint-sample)\r\n\r\nTo create a table transform rule: </br>\r\n1. Select the workspace that houses the tables that should be transformed.\r\n2. Select a table that will be transformed.\r\n3. Choose a DCR name that will be for the rule.\r\n4. Review the schema for the selected table in order to see which columns already exist.\r\n5. For transformation, enter a query in the TransformQuery box. Make sure that it is a single line.\r\n6. Optional: Click on 'Open Workspace Editor' to open the workspace in order to write queries and verify that. Copy the query body and paste it into the TransformQuery box. Ensure that the table remains as 'source'.\r\n7. Click on the 'Deploy Transform DCR' button to deploy the template.",
                          "style": "info"
                        },
                        "conditionalVisibility": {
                          "parameterName": "Help",
                          "comparison": "isEqualTo",
                          "value": "Yes"
                        },
                        "name": "Transform"
                      },
                      {
                        "type": 9,
                        "content": {
                          "version": "KqlParameterItem/1.0",
                          "crossComponentResources": [
                            "value::selected"
                          ],
                          "parameters": [
                            {
                              "id": "c0a60e1b-51db-4099-86d7-08a1154a0d24",
                              "version": "KqlParameterItem/1.0",
                              "name": "TransformWorkspace",
                              "type": 5,
                              "query": "resources\r\n| where type == 'microsoft.operationalinsights/workspaces'\r\n| project id, name\r\n| order by name asc",
                              "crossComponentResources": [
                                "value::selected"
                              ],
                              "typeSettings": {
                                "additionalResourceOptions": [],
                                "showDefault": false
                              },
                              "timeContext": {
                                "durationMs": 86400000
                              },
                              "queryType": 1,
                              "resourceType": "microsoft.resourcegraph/resources",
                              "value": "",
                              "label": "Workspace"
                            }
                          ],
                          "style": "above",
                          "queryType": 1,
                          "resourceType": "microsoft.resourcegraph/resources"
                        },
                        "name": "parameters - 8"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "Usage\r\n| summarize by DataType\r\n| where DataType !has '_CL'\r\n| where DataType !in('SecurityEvent', 'WindowsEvent', 'Syslog', 'CommonSecurityLog', 'AzureDiagnostics', 'Anomalies', 'BehaviorAnalytics')\r\n| order by DataType asc",
                          "size": 2,
                          "title": "Choose a Table to Transform",
                          "timeContext": {
                            "durationMs": 604800000
                          },
                          "exportFieldName": "DataType",
                          "exportParameterName": "DataType",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "crossComponentResources": [
                            "{TransformWorkspace}"
                          ],
                          "gridSettings": {
                            "rowLimit": 500,
                            "filter": true
                          }
                        },
                        "customWidth": "33",
                        "showPin": false,
                        "name": "query - 3"
                      },
                      {
                        "type": 9,
                        "content": {
                          "version": "KqlParameterItem/1.0",
                          "crossComponentResources": [
                            "{TransformWorkspace}"
                          ],
                          "parameters": [
                            {
                              "id": "375977b8-4c33-41a2-b8a5-a27c4ebcf120",
                              "version": "KqlParameterItem/1.0",
                              "name": "DCRName",
                              "label": "DCR Name",
                              "type": 1,
                              "timeContext": {
                                "durationMs": 86400000
                              },
                              "value": "WBTransformTest2"
                            },
                            {
                              "id": "1245f368-82db-4a9f-8e0c-ebd870b6661c",
                              "version": "KqlParameterItem/1.0",
                              "name": "Table",
                              "type": 1,
                              "isRequired": true,
                              "query": "print '{DataType}'",
                              "crossComponentResources": [
                                "{TransformWorkspace}"
                              ],
                              "timeContext": {
                                "durationMs": 86400000
                              },
                              "queryType": 0,
                              "resourceType": "microsoft.operationalinsights/workspaces"
                            },
                            {
                              "id": "5dcbc7c9-f302-4fc6-a8dc-69ea30e7b710",
                              "version": "KqlParameterItem/1.0",
                              "name": "workspaceLocation",
                              "type": 1,
                              "query": "resources\r\n| where type == 'microsoft.operationalinsights/workspaces'\r\n| where id == '{TransformWorkspace}'\r\n| project location",
                              "crossComponentResources": [
                                "{subscriptionId}"
                              ],
                              "isHiddenWhenLocked": true,
                              "timeContext": {
                                "durationMs": 86400000
                              },
                              "queryType": 1,
                              "resourceType": "microsoft.resourcegraph/resources"
                            }
                          ],
                          "style": "above",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces"
                        },
                        "customWidth": "25",
                        "name": "parameters - 4"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "table('{Table}')\r\n| getschema\r\n| order by ColumnName asc",
                          "size": 2,
                          "title": "Available Schema for {Table}",
                          "timeContext": {
                            "durationMs": 86400000
                          },
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "crossComponentResources": [
                            "{TransformWorkspace}"
                          ],
                          "gridSettings": {
                            "filter": true
                          }
                        },
                        "customWidth": "33",
                        "name": "query - 9"
                      },
                      {
                        "type": 9,
                        "content": {
                          "version": "KqlParameterItem/1.0",
                          "parameters": [
                            {
                              "id": "98376cc3-1a48-4a09-99ac-f4f160ce619d",
                              "version": "KqlParameterItem/1.0",
                              "name": "TransformQuery",
                              "type": 1,
                              "typeSettings": {
                                "multiLineText": true,
                                "editorLanguage": "kql"
                              },
                              "timeContext": {
                                "durationMs": 86400000
                              },
                              "value": "source | project-away ActorContextId"
                            }
                          ],
                          "style": "above",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces"
                        },
                        "name": "parameters - 7"
                      },
                      {
                        "type": 1,
                        "content": {
                          "json": "### Warning\r\n\r\nThe template will not deploy if the transformation query is multi-lined. IN order to avoid issues with creating or deploying the template, make sure that the query is a single line.",
                          "style": "warning"
                        },
                        "name": "text - 7"
                      },
                      {
                        "type": 11,
                        "content": {
                          "version": "LinkItem/1.0",
                          "style": "paragraph",
                          "links": [
                            {
                              "id": "472428e4-3a55-4b8a-a940-23b0272eec06",
                              "cellValue": "",
                              "linkTarget": "OpenBlade",
                              "linkLabel": "Open Workspace Editor",
                              "subTarget": "logs",
                              "style": "primary",
                              "linkIsContextBlade": true,
                              "bladeOpenContext": {
                                "bladeName": "LogsBlade",
                                "extensionName": "Microsoft_Azure_Monitoring_Logs",
                                "bladeParameters": [
                                  {
                                    "name": "resourceId",
                                    "source": "static",
                                    "value": "{TransformWorkspace}"
                                  },
                                  {
                                    "name": "source",
                                    "source": "static",
                                    "value": "LogsBlade.AnalyticsShareLinkToQuery"
                                  }
                                ]
                              }
                            },
                            {
                              "id": "57580a59-508e-47e4-8646-6b08ef65d835",
                              "linkTarget": "ArmAction",
                              "linkLabel": "Deploy Transform DCR",
                              "style": "primary",
                              "linkIsContextBlade": true,
                              "armActionContext": {
                                "path": "{subscriptionId}/resourceGroups/{TransformWorkspace:resourceGroup}/providers/Microsoft.Insights/dataCollectionRules/{DCRName}?api-version=2021-09-01-preview",
                                "headers": [],
                                "params": [],
                                "body": "{\r\n  \"location\":\"{workspaceLocation}\",\r\n  \"kind\":\"WorkspaceTransforms\",\r\n  \"properties\":{\r\n        \"destinations\": {\r\n          \"logAnalytics\": [\r\n            {\r\n              \"workspaceResourceId\": \"{TransformWorkspace}\",\r\n              \"name\": \"{TransformWorkspace:name}\"\r\n            }\r\n          ]\r\n        },\r\n        \"dataFlows\": [\r\n          {\r\n            \"streams\": [\r\n              \"Microsoft-Table-{DataType}\"\r\n            ],\r\n            \"destinations\": [\r\n              \"{TransformWorkspace:name}\"\r\n            ],\r\n            \"transformKql\": \"{TransformQuery}\"\r\n          }\r\n        ]\r\n  }\r\n}",
                                "httpMethod": "PUT",
                                "title": "Update Data Collection Rule: {DCRName}",
                                "description": "### You are about to commit changes to DCR {DCRName}. Please confirm the changes you have made are valid and are the intended changes that you would like to push. This API will be redeploying the ARM template for this DCR. Connected machines will not be dropped.\r\n",
                                "runLabel": "Deploy Transformation DCR"
                              }
                            }
                          ]
                        },
                        "name": "links - 9"
                      }
                    ]
                  },
                  "conditionalVisibility": {
                    "parameterName": "Datatype",
                    "comparison": "isEqualTo",
                    "value": "Transformation"
                  },
                  "name": "Transformation"
                },
                {
                  "type": 1,
                  "content": {
                    "json": "### Help\r\n\r\nThis section will allow users to choose different scenarios and categorizations in order to define which event IDs are ingested via DCR. In order to do so:\r\n1. Click on a category for event IDs to be populated.\r\n2. Select which category of events should be inested.\r\n3. Manually enter any additional event IDs that are needed.\r\n4. Review the event IDs to ensure anything of interest is configured for ingestion.\r\n5. Provide a name for the DCR.\r\n6. Click on the 'Deploy DCR' button.",
                    "style": "info"
                  },
                  "conditionalVisibilities": [
                    {
                      "parameterName": "Help",
                      "comparison": "isEqualTo",
                      "value": "Yes"
                    },
                    {
                      "parameterName": "Datatype",
                      "comparison": "isEqualTo",
                      "value": "Windows"
                    }
                  ],
                  "name": "WESelection"
                },
                {
                  "type": 1,
                  "content": {
                    "json": "---------------------------------------------------------------------------------"
                  },
                  "name": "text - 8"
                },
                {
                  "type": 12,
                  "content": {
                    "version": "NotebookGroup/1.0",
                    "groupType": "editable",
                    "items": [
                      {
                        "type": 1,
                        "content": {
                          "json": "### Help\r\n\r\nThe 3 tiers listed below for ingestion are in reference to the tiers available today via the Legacy Agent connector (MMA) and the Security Event via AMA connector.\r\n\r\nFor the exact events collected in each tier, please see: https://learn.microsoft.com/azure/sentinel/windows-security-event-id-reference#event-id-reference\r\n",
                          "style": "info"
                        },
                        "conditionalVisibility": {
                          "parameterName": "Help",
                          "comparison": "isEqualTo",
                          "value": "Yes"
                        },
                        "name": "Tiers"
                      },
                      {
                        "type": 9,
                        "content": {
                          "version": "KqlParameterItem/1.0",
                          "parameters": [
                            {
                              "id": "6db21dd5-5ea5-4933-929e-34e15bf0d51e",
                              "version": "KqlParameterItem/1.0",
                              "name": "IngestionTier",
                              "label": "Ingestion Tier",
                              "type": 10,
                              "isRequired": true,
                              "value": "Common",
                              "typeSettings": {
                                "additionalResourceOptions": [],
                                "showDefault": false
                              },
                              "jsonData": "[\"None\", \"Minimal\", \"Common\"]",
                              "timeContext": {
                                "durationMs": 86400000
                              }
                            }
                          ],
                          "style": "above",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces"
                        },
                        "conditionalVisibility": {
                          "parameterName": "Datatype",
                          "comparison": "isNotEqualTo",
                          "value": "Essentials"
                        },
                        "name": "parameters - 6"
                      },
                      {
                        "type": 1,
                        "content": {
                          "json": "### Help\r\n\r\nThese options have been pulled from a public NSA list of recommended events to monitor. Each event is categorized grouped based on classification. Selecting one of the options below will generate the xPath required to ingest the events. For any additional events of interest, either selet an ingestion tier above or manually enter event IDs below where provided.",
                          "style": "info"
                        },
                        "conditionalVisibilities": [
                          {
                            "parameterName": "Logtype",
                            "comparison": "isEqualTo",
                            "value": "NSA"
                          },
                          {
                            "parameterName": "Help",
                            "comparison": "isEqualTo",
                            "value": "Yes"
                          }
                        ],
                        "name": "NSA"
                      },
                      {
                        "type": 9,
                        "content": {
                          "version": "KqlParameterItem/1.0",
                          "parameters": [
                            {
                              "id": "1bf9ebfc-f43f-43d6-a5ad-63579f90a689",
                              "version": "KqlParameterItem/1.0",
                              "name": "Identity",
                              "label": "Identity Events",
                              "type": 10,
                              "isRequired": true,
                              "isGlobal": true,
                              "value": "Ingest",
                              "typeSettings": {
                                "additionalResourceOptions": [],
                                "showDefault": false
                              },
                              "jsonData": "[\"Ingest\", \"Ignore\"]",
                              "timeContext": {
                                "durationMs": 86400000
                              }
                            },
                            {
                              "id": "11c786f8-1d45-4b62-8927-50c02aea5c1c",
                              "version": "KqlParameterItem/1.0",
                              "name": "Network",
                              "label": "Network Events",
                              "type": 10,
                              "isRequired": true,
                              "isGlobal": true,
                              "value": "Ingest",
                              "typeSettings": {
                                "additionalResourceOptions": [],
                                "showDefault": false
                              },
                              "jsonData": "[\"Ingest\", \"Ignore\"]",
                              "timeContext": {
                                "durationMs": 86400000
                              }
                            },
                            {
                              "id": "167aaf7c-1f21-4f9d-88b5-708ff14f1548",
                              "version": "KqlParameterItem/1.0",
                              "name": "System",
                              "label": "System Events",
                              "type": 10,
                              "isRequired": true,
                              "isGlobal": true,
                              "value": "Ingest",
                              "typeSettings": {
                                "additionalResourceOptions": [],
                                "showDefault": false
                              },
                              "jsonData": "[\"Ingest\", \"Ignore\"]",
                              "timeContext": {
                                "durationMs": 86400000
                              }
                            },
                            {
                              "id": "5e26a9d7-0ed2-426b-b726-037776557b98",
                              "version": "KqlParameterItem/1.0",
                              "name": "User",
                              "label": "User Events",
                              "type": 10,
                              "isRequired": true,
                              "isGlobal": true,
                              "value": "Ingest",
                              "typeSettings": {
                                "additionalResourceOptions": [],
                                "showDefault": false
                              },
                              "jsonData": "[\"Ingest\", \"Ignore\"]",
                              "timeContext": {
                                "durationMs": 86400000
                              }
                            }
                          ],
                          "style": "formHorizontal",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces"
                        },
                        "conditionalVisibility": {
                          "parameterName": "Logtype",
                          "comparison": "isEqualTo",
                          "value": "NSA"
                        },
                        "name": "parameters - 0"
                      },
                      {
                        "type": 1,
                        "content": {
                          "json": "### Help\r\n\r\nThe options below are align event IDs with different MITRE tactics. Selecting ingest for the different tactics will generate the xPath for collecting the relevant events. For any additional events outside of the tactics, either select an ingestion tier above or manually enter event IDs below where provided. </br>\r\n\r\nFor more information on MSTIC, please see https://www.microsoft.com/security/blog/microsoft-security-intelligence/",
                          "style": "info"
                        },
                        "conditionalVisibilities": [
                          {
                            "parameterName": "Logtype",
                            "comparison": "isEqualTo",
                            "value": "MITRE"
                          },
                          {
                            "parameterName": "Help",
                            "comparison": "isEqualTo",
                            "value": "Yes"
                          }
                        ],
                        "name": "MITRE"
                      },
                      {
                        "type": 9,
                        "content": {
                          "version": "KqlParameterItem/1.0",
                          "parameters": [
                            {
                              "id": "079b84fd-d325-4ad2-8036-7fe314d46a58",
                              "version": "KqlParameterItem/1.0",
                              "name": "Antivirus",
                              "type": 10,
                              "isRequired": true,
                              "value": "Ingest",
                              "typeSettings": {
                                "additionalResourceOptions": [],
                                "showDefault": false
                              },
                              "jsonData": "[\"Ingest\", \"Ignore\"]",
                              "timeContext": {
                                "durationMs": 86400000
                              }
                            },
                            {
                              "id": "516b88b0-c704-4144-b6d5-c94a68d7c012",
                              "version": "KqlParameterItem/1.0",
                              "name": "InitialAccess",
                              "label": "Initial Access",
                              "type": 10,
                              "isRequired": true,
                              "value": "Ingest",
                              "typeSettings": {
                                "additionalResourceOptions": []
                              },
                              "jsonData": "[\"Ingest\",\"Ignore\"]",
                              "timeContext": {
                                "durationMs": 86400000
                              }
                            },
                            {
                              "version": "KqlParameterItem/1.0",
                              "name": "Execution",
                              "type": 10,
                              "isRequired": true,
                              "value": "Ingest",
                              "typeSettings": {
                                "additionalResourceOptions": [],
                                "showDefault": false
                              },
                              "jsonData": "[\"Ingest\",\"Ignore\"]",
                              "timeContext": {
                                "durationMs": 86400000
                              },
                              "id": "a95ade43-6954-4de4-8306-50416e451421"
                            },
                            {
                              "version": "KqlParameterItem/1.0",
                              "name": "Persistance",
                              "type": 10,
                              "isRequired": true,
                              "value": "Ingest",
                              "typeSettings": {
                                "additionalResourceOptions": [],
                                "showDefault": false
                              },
                              "jsonData": "[\"Ingest\",\"Ignore\"]",
                              "timeContext": {
                                "durationMs": 86400000
                              },
                              "id": "01054dff-1fe8-4e08-93a6-71371ff05cd9"
                            }
                          ],
                          "style": "formHorizontal",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces"
                        },
                        "customWidth": "25",
                        "conditionalVisibility": {
                          "parameterName": "Logtype",
                          "comparison": "isEqualTo",
                          "value": "MITRE"
                        },
                        "name": "parameters - 2"
                      },
                      {
                        "type": 9,
                        "content": {
                          "version": "KqlParameterItem/1.0",
                          "parameters": [
                            {
                              "id": "8684d555-8eba-4ed4-8671-15249793ab37",
                              "version": "KqlParameterItem/1.0",
                              "name": "PrivilegeEscalation",
                              "type": 10,
                              "isRequired": true,
                              "typeSettings": {
                                "additionalResourceOptions": [],
                                "showDefault": false
                              },
                              "jsonData": "[\"Ingest\", \"Ignore\"]",
                              "timeContext": {
                                "durationMs": 86400000
                              },
                              "value": "Ingest",
                              "label": "Privilege Escalation"
                            },
                            {
                              "id": "1dfdc339-e15b-4e1b-b1e9-7fd3f8cde17c",
                              "version": "KqlParameterItem/1.0",
                              "name": "DefenseEvasion",
                              "label": "Defense Evasion",
                              "type": 10,
                              "isRequired": true,
                              "typeSettings": {
                                "additionalResourceOptions": []
                              },
                              "jsonData": "[\"Ingest\",\"Ignore\"]",
                              "timeContext": {
                                "durationMs": 86400000
                              },
                              "value": "Ingest"
                            },
                            {
                              "id": "1a5e2745-d18d-4f05-bf95-65756d9823d8",
                              "version": "KqlParameterItem/1.0",
                              "name": "CredentialAccess",
                              "type": 10,
                              "isRequired": true,
                              "typeSettings": {
                                "additionalResourceOptions": [],
                                "showDefault": false
                              },
                              "jsonData": "[\"Ingest\",\"Ignore\"]",
                              "timeContext": {
                                "durationMs": 86400000
                              },
                              "value": "Ingest",
                              "label": "Credential Access"
                            },
                            {
                              "id": "987e0627-9e44-447e-934e-62fc68f97b93",
                              "version": "KqlParameterItem/1.0",
                              "name": "Discovery",
                              "type": 10,
                              "isRequired": true,
                              "typeSettings": {
                                "additionalResourceOptions": [],
                                "showDefault": false
                              },
                              "jsonData": "[\"Ingest\",\"Ignore\"]",
                              "timeContext": {
                                "durationMs": 86400000
                              },
                              "value": "Ingest"
                            }
                          ],
                          "style": "formHorizontal",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces"
                        },
                        "customWidth": "25",
                        "conditionalVisibility": {
                          "parameterName": "Logtype",
                          "comparison": "isEqualTo",
                          "value": "MITRE"
                        },
                        "name": "parameters - 2 - Copy"
                      },
                      {
                        "type": 9,
                        "content": {
                          "version": "KqlParameterItem/1.0",
                          "parameters": [
                            {
                              "id": "cd9b50db-1ce9-447d-bb92-671a0c80f1d1",
                              "version": "KqlParameterItem/1.0",
                              "name": "LateralMovement",
                              "type": 10,
                              "isRequired": true,
                              "typeSettings": {
                                "additionalResourceOptions": [],
                                "showDefault": false
                              },
                              "jsonData": "[\"Ingest\", \"Ignore\"]",
                              "timeContext": {
                                "durationMs": 86400000
                              },
                              "label": "Lateral Movement",
                              "value": "Ingest"
                            },
                            {
                              "id": "8b57a824-1cb4-40b2-8e46-b2f26f2f9145",
                              "version": "KqlParameterItem/1.0",
                              "name": "Collection",
                              "type": 10,
                              "isRequired": true,
                              "typeSettings": {
                                "additionalResourceOptions": []
                              },
                              "jsonData": "[\"Ingest\",\"Ignore\"]",
                              "timeContext": {
                                "durationMs": 86400000
                              },
                              "value": "Ingest"
                            },
                            {
                              "id": "611a0a8a-9ff0-4062-8566-93b30e7c6293",
                              "version": "KqlParameterItem/1.0",
                              "name": "CommandandControl",
                              "type": 10,
                              "isRequired": true,
                              "typeSettings": {
                                "additionalResourceOptions": [],
                                "showDefault": false
                              },
                              "jsonData": "[\"Ingest\",\"Ignore\"]",
                              "timeContext": {
                                "durationMs": 86400000
                              },
                              "label": "Command and Control",
                              "value": "Ingest"
                            },
                            {
                              "id": "c9c33eae-6172-4cf7-bf58-19e43f2b4964",
                              "version": "KqlParameterItem/1.0",
                              "name": "Impact",
                              "type": 10,
                              "isRequired": true,
                              "typeSettings": {
                                "additionalResourceOptions": [],
                                "showDefault": false
                              },
                              "jsonData": "[\"Ingest\",\"Ignore\"]",
                              "timeContext": {
                                "durationMs": 86400000
                              },
                              "value": "Ingest"
                            }
                          ],
                          "style": "formHorizontal",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces"
                        },
                        "customWidth": "25",
                        "conditionalVisibility": {
                          "parameterName": "Logtype",
                          "comparison": "isEqualTo",
                          "value": "MITRE"
                        },
                        "name": "parameters - 2 - Copy - Copy"
                      },
                      {
                        "type": 1,
                        "content": {
                          "json": "### Help\r\n\r\nThese events are recommended by MSFT as highlighted here: https://learn.microsoft.com/windows-server/identity/ad-ds/plan/appendix-l--events-to-monitor </br>\r\n\r\nThese events are categorized by criticality level. Selecting different levels will modify which events have xPath generated for them. If there are additional events needed outside of the list provided, select an ingestion tier above or manually enter event IDs below in the space provided."
                        },
                        "conditionalVisibilities": [
                          {
                            "parameterName": "Logtype",
                            "comparison": "isEqualTo",
                            "value": "WE"
                          },
                          {
                            "parameterName": "Help",
                            "comparison": "isEqualTo",
                            "value": "Yes"
                          }
                        ],
                        "name": "WE"
                      },
                      {
                        "type": 9,
                        "content": {
                          "version": "KqlParameterItem/1.0",
                          "parameters": [
                            {
                              "id": "7ba1a4b5-73ae-45a7-a50a-2ab90081e43d",
                              "version": "KqlParameterItem/1.0",
                              "name": "Criticality",
                              "label": "Log Criticality Level",
                              "type": 2,
                              "multiSelect": true,
                              "quote": "'",
                              "delimiter": ",",
                              "typeSettings": {
                                "additionalResourceOptions": [],
                                "showDefault": false
                              },
                              "jsonData": "[\"Low\", \"Medium\", \"High\"]",
                              "timeContext": {
                                "durationMs": 86400000
                              },
                              "value": [
                                "Low",
                                "Medium",
                                "High"
                              ]
                            }
                          ],
                          "style": "above",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces"
                        },
                        "conditionalVisibility": {
                          "parameterName": "Logtype",
                          "comparison": "isEqualTo",
                          "value": "WE"
                        },
                        "name": "parameters - 8"
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "crossComponentResources": [
                                  "{Workspace}"
                                ],
                                "parameters": [
                                  {
                                    "id": "635fce4f-0b3b-484c-a9f1-cd622e35d2cc",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "MinimalEvents",
                                    "type": 1,
                                    "query": "let Minimal = datatable(EventID:int)[1102, 4624, 4625, 4657, 4663, 4688, 4700, 4702, 4719, 4720, 4722, 4723, 4724, 4727, 4728, 4732, 4735, 4737, 4739, 4740, 4754, 4755, 4756, 4767, 4799, 4825, 4946, 4948, 4956, 5024, 5033, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8222];\r\nMinimal",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "id": "39ec786d-9769-4441-84a4-71e4722839ab",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "CommonEvents",
                                    "type": 1,
                                    "query": "let Common = datatable(EventID:int)[1, 299, 300, 324, 340, 403, 404, 410, 411, 412, 413, 431, 500, 501, 1100, 1102, 1107, 1108, 4608, 4610, 4611, 4614, 4622, 4624, 4625, 4634, 4647, 4648, 4649, 4657, 4661, 4662, 4663, 4665, 4666, 4667, 4688, 4670, 4672, 4673, 4674, 4675, 4689, 4697, 4700, 4702, 4704, 4705, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4733, 4732, 4735, 4737, 4738, 4739, 4740, 4742, 4744, 4745, 4746, 4750, 4751, 4752, 4754, 4755, 4756, 4757, 4760, 4761, 4762, 4764, 4767, 4768, 4771, 4774, 4778, 4779, 4781, 4793, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4825, 4826, 4870, 4886, 4887, 4888, 4893, 4898, 4902, 4904, 4905, 4907, 4931, 4932, 4933, 4946, 4948, 4956, 4985, 5024, 5033, 5059, 5136, 5137, 5140, 5145, 5632, 6144, 6145, 6272, 6273, 6278, 6416, 6423, 6424, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8222, 26401, 30004];\r\nCommon",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "id": "6797a90e-08cf-4ccf-8abb-a5b0f25080f5",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "IngestArray",
                                    "type": 1,
                                    "query": "let test1 = case('{IngestionTier}' == 'Minimal', dynamic('{MinimalEvents}'),\r\n                '{IngestionTier}' == 'Common', dynamic('{CommonEvents}'),\r\n                dynamic([]));\r\nprint test1",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  }
                                ],
                                "style": "pills",
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces"
                              },
                              "name": "parameters - 8"
                            },
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "crossComponentResources": [
                                  "{Workspace}"
                                ],
                                "parameters": [
                                  {
                                    "id": "6079823a-de73-4e2b-9646-aeb37d4e4b48",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "nsaIds",
                                    "type": 1,
                                    "query": "// First Parse the NSA JSON\r\nprint events=todynamic({nsaRecommendedEvents:parsejson})\r\n| extend events = events['Recommended Events to Collect']\r\n// First we pivot the data\r\n| mv-apply events on (\r\n    extend Category = tostring(bag_keys(events)[0])\r\n| extend IdentityCheck = iff('{Identity}' == 'Ingest', Category in (\"Account Usage\", \"Pass the Hash Detection\", \"Remote Desktop Logon Detection\"), false),\r\n            NetworkCheck = iff('{Network}' == 'Ingest', Category in (\"Network Policy\", \"Windows Firewall\"), false),\r\n            SystemCheck = iff('{System}' == 'Ingest', Category in (\"Application Whitelisting\", \"Application Crashes\", \"System or Service Failures\", \"Clearing Event Logs\", \"Software and Service Installation\", \"Kernel Driver Signing\", \"Windows Defender Activities\", \"DNS/Directory Services\", \"Certificate Service\", \"Boot Events\", \"System Integrity\") , false),\r\n            UserCheck = iff('{User}' == 'Ingest', Category in (\"PowerShell Activities\", \"Mobile Device Activities\") , false)\r\n    | extend description = events[Category].description\r\n    | extend events = events[Category].events\r\n    | where IdentityCheck == true or IdentityCheck == true or NetworkCheck == true or UserCheck == true\r\n)\r\n| mv-apply events on (\r\n    extend eventName = tostring(bag_keys(events)[0])\r\n    | extend eventId = tostring(bag_keys(events[eventName])[0])\r\n    | extend properties = events[eventName][eventId]\r\n    | project-away events\r\n)\r\n| evaluate bag_unpack(properties)\r\n| project eventId = split(replace_regex(eventId,@'\\s',@''),','), eventName\r\n| mvexpand eventId\r\n| summarize by toint(eventId), eventName\r\n| sort by eventId asc\r\n| project packed = pack_all()",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "id": "d9c8b4c7-6ef0-4b03-a16e-025d4173450b",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "ManualEvents",
                                    "type": 9,
                                    "multiSelect": true,
                                    "quote": "'",
                                    "delimiter": ",",
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "label": "Manual Events"
                                  },
                                  {
                                    "version": "KqlParameterItem/1.0",
                                    "name": "NSAExclude",
                                    "label": "Excluded Events",
                                    "type": 9,
                                    "multiSelect": true,
                                    "quote": "'",
                                    "delimiter": ",",
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "id": "3aa6089a-1bb6-4b2f-afc4-e98245a26f06"
                                  },
                                  {
                                    "id": "df2785ed-52c6-4aee-ac01-c6cbdbc1a06e",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "parseManual",
                                    "type": 1,
                                    "query": "let manualIds = \"{ManualEvents}\";\r\nprint ids=manualIds\r\n| project ids = todynamic(strcat('[', replace_regex(ids,\"\\'\",\"\"),']'))\r\n| mv-expand ids\r\n| project ids = toint(ids)",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "version": "KqlParameterItem/1.0",
                                    "name": "parseExclude",
                                    "type": 1,
                                    "query": "let manualIds = \"{NSAExclude}\";\r\nprint ids=manualIds\r\n| project ids = todynamic(strcat('[', replace_regex(ids,\"\\'\",\"\"),']'))\r\n| mv-expand ids\r\n| project ids = toint(ids)",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces",
                                    "id": "4373b5ea-0a14-486a-a3ee-894f826c637a"
                                  },
                                  {
                                    "id": "0a5d6d8f-7b8f-4c56-8515-3ac94d679f5d",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "merged",
                                    "type": 1,
                                    "query": "let manual_ids = () {\r\n    print ids=todynamic(\"{parseManual}\")\r\n    | mvexpand ids\r\n    | project ids = toint(ids)\r\n};\r\nlet exclude_ids = () {\r\n    print ids=todynamic(\"{parseExclude}\")\r\n    | mvexpand ids\r\n    | project ids = toint(ids)\r\n};\r\nlet tierIds = () {\r\n    print ids = todynamic(\"{IngestArray}\")\r\n    | mvexpand ids\r\n    | project ids = toint(ids)\r\n};\r\nlet nsaIds = () {\r\n    print  ids=todynamic(\"{nsaIds:escapejson}\")\r\n    | mvexpand ids\r\n    | project ids = toint(ids.eventId)\r\n};\r\nunion manual_ids, tierIds, nsaIds\r\n| where isnotempty(ids)\r\n| where ids !in (exclude_ids)\r\n| summarize by ids\r\n| sort by ids asc",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "id": "088873b1-b01e-4d65-bff8-0c50dc997953",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "generatedJSON",
                                    "type": 1,
                                    "query": "// Referenced merged array\r\nlet generated = () {\r\n    print merged=\"{merged:escapejson}\"\r\n    | extend merged=todynamic(merged)\r\n    | mvexpand merged\r\n    | top 100 by toint(merged) asc\r\n    | extend merged = tostring(strcat(\"(EventID=\",merged,\")\"))\r\n    | sort by tolong(merged) asc\r\n    | extend index=row_rank(merged)\r\n    | summarize merged=makeset(merged) by (index/10)\r\n    | extend concat= strcat_array(merged,\" or \")\r\n    | project p = strcat(\"Security!*[System[\",concat,\"]]\")\r\n    | summarize makeset(p)\r\n};\r\ngenerated",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "id": "74e91498-8d65-40f0-bb63-6f5cc918bff7",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "NSADCR2",
                                    "type": 1,
                                    "isGlobal": true,
                                    "query": "let Count = print merged=\"{merged:escapejson}\"\r\n    | extend merged=todynamic(merged)\r\n    | mvexpand merged\r\n    | summarize count()\r\n    | extend Counter = toint(count_);\r\nlet Check =\r\n    Count\r\n    | extend Check = iff(Counter <= 100, 'DCR not needed', 'DCR needed')\r\n    | extend Math = Counter - 100\r\n    | extend diff = iff(Math < 0 or Math > 100, 'New DCR will not work', array_split(todynamic(\"{merged:escapejson}\"), 100)[1])\r\n    | extend diff = todynamic(diff)\r\n    | mv-expand diff\r\n    | project toint(diff)\r\n    | top 100 by diff asc\r\n    | summarize Array = make_set(diff);\r\nlet Configure = (Array:dynamic) { \r\nprint Array \r\n    | extend Array = todynamic(Array)\r\n    | mv-expand Array\r\n    | extend merged = tostring(strcat(\"(EventID=\",Array,\")\"))\r\n    | sort by tolong(merged) asc\r\n    | extend index=row_rank(merged)\r\n    | summarize merged=makeset(merged) by (index/10)\r\n    | extend concat= strcat_array(merged,\" or \")\r\n    | project p = iff(Array == 'New DCR will not work', 'New DCR will not work', strcat(\"Security!*[System[\",concat,\"]]\"))\r\n    | summarize make_set_if(p, p != 'New DCR will not work')\r\n    };\r\nConfigure(toscalar(Check))\r\n| extend set_p = iff(set_p == '[]', 'Blank', set_p)",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "id": "12cb75c1-fc94-47c6-ba0d-0acef7fc1aaf",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "NSADCR3",
                                    "type": 1,
                                    "isGlobal": true,
                                    "query": "let Count = print merged=\"{merged:escapejson}\"\r\n    | extend merged=todynamic(merged)\r\n    | mvexpand merged\r\n    | summarize count()\r\n    | extend Counter = toint(count_);\r\nlet Check =\r\n    Count\r\n    | extend Check = iff(Counter <= 200, 'DCR not needed', 'DCR needed')\r\n    | extend Math = Counter - 100\r\n    | extend diff = iff(Math < 0 or Math > 200, 'New DCR will not work', array_split(todynamic(\"{merged:escapejson}\"), 200)[1])\r\n    | extend diff = todynamic(diff)\r\n    | mv-expand diff\r\n    | project toint(diff)\r\n    | top 100 by diff asc\r\n    | summarize Array = make_set(diff);\r\nlet Configure = (Array:dynamic) { print Array\r\n    | extend Array = todynamic(Array)\r\n    | mv-expand Array\r\n    | extend merged = tostring(strcat(\"(EventID=\",Array,\")\"))\r\n    | sort by tolong(merged) asc\r\n    | extend index=row_rank(merged)\r\n    | summarize merged=makeset(merged) by (index/10)\r\n    | extend concat= strcat_array(merged,\" or \")\r\n    | project p = iff(Array == 'New DCR will not work', 'New DCR will not work', strcat(\"Security!*[System[\",concat,\"]]\"))\r\n    | summarize make_set_if(p, p != 'New DCR will not work')\r\n    };\r\nConfigure(toscalar(Check))\r\n| extend set_p = iff(set_p == '[]', 'Blank', set_p)",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  }
                                ],
                                "style": "above",
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces"
                              },
                              "conditionalVisibility": {
                                "parameterName": "Logtype",
                                "comparison": "isEqualTo",
                                "value": "NSA"
                              },
                              "name": "Merged Set"
                            },
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "crossComponentResources": [
                                  "{Workspace}"
                                ],
                                "parameters": [
                                  {
                                    "id": "f2c1b60a-8461-4d02-a7ef-39e2bd4d3fd6",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "mitreIds",
                                    "type": 1,
                                    "query": "let holder = datatable(Category:string, Value: string)[\r\n    \"Antivirus\", '{Antivirus}',\r\n    \"InitialAccess\", '{InitialAccess}',\r\n    \"Execution\", '{Execution}',\r\n    \"Persistance\", '{Persistance}',\r\n    \"Privilege Escalation\", '{PrivilegeEscalation}',\r\n    \"Defense Evasion\", '{DefenseEvasion}',\r\n    \"Credential Access\", '{CredentialAccess}',\r\n    \"Discovery\", '{Discovery}',\r\n    \"Lateral Movement\", '{LateralMovement}',\r\n    \"Collection\", '{Collection}',\r\n    \"Command and Control\", '{CommandandControl}',\r\n    \"Impact\", '{Impact}'\r\n];\r\nlet set_items = holder | where Value == 'Ingest';\r\nlet mitre_ids = dynamic([\r\n    {\r\n        \"Tactic\":  \"Antivirus\",\r\n        \"Technique\":  \"Antivirus\",\r\n        \"Description\":  \"Defender: antivirus not up to date\",\r\n        \"EventIDs\":  \"1151\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"Antivirus\",\r\n        \"Technique\":  \"Antivirus\",\r\n        \"Description\":  \"Defender: massive malware outbreak detected on multiple hosts\",\r\n        \"EventIDs\":  \"1116\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"Antivirus\",\r\n        \"Technique\":  \"Antivirus\",\r\n        \"Description\":  \"Defender: massive malwares detected on a single host\",\r\n        \"EventIDs\":  \"1116\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0001-Initial access\",\r\n        \"Technique\":  \"T1078.002-Valid accounts-Domain accounts\",\r\n        \"Description\":  \"Login denied due to account policy restrictions\",\r\n        \"EventIDs\":  \"4625\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0001-Initial access\",\r\n        \"Technique\":  \"T1078.002-Valid accounts-Domain accounts\",\r\n        \"Description\":  \"Login failure from a single source with a disabled account\",\r\n        \"EventIDs\":  \"33205\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0001-Initial access\",\r\n        \"Technique\":  \"T1078.002-Valid accounts-Domain accounts\",\r\n        \"Description\":  \"Success login on OpenSSH server\",\r\n        \"EventIDs\":  \"4624,4\",\r\n        \"Threat Details\":  \"SSH server\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0001-Initial access\",\r\n        \"Technique\":  \"T1078-Valid accounts\",\r\n        \"Description\":  \"RDP reconnaissance with valid credentials performed to multiple hosts\",\r\n        \"EventIDs\":  \"4624,1149\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0002-Execution\",\r\n        \"Technique\":  \"T1047-Windows Management Instrumentation\",\r\n        \"Description\":  \"Impacket WMIexec process execution\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"WMIexec\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0002-Execution\",\r\n        \"Technique\":  \"T1053.005-Scheduled Task\",\r\n        \"Description\":  \"Interactive shell triggered by scheduled task (at, deprecated)\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0002-Execution\",\r\n        \"Technique\":  \"T1053.005-Scheduled Task\",\r\n        \"Description\":  \"Persistent scheduled task with SYSTEM privileges creation\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0002-Execution\",\r\n        \"Technique\":  \"T1053.005-Scheduled Task\",\r\n        \"Description\":  \"Remote schedule task creation via named pipes\",\r\n        \"EventIDs\":  \"5145\",\r\n        \"Threat Details\":  \"Atexec\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0002-Execution\",\r\n        \"Technique\":  \"T1053.005-Scheduled Task\",\r\n        \"Description\":  \"Schedule task created and deleted in a short period of time\",\r\n        \"EventIDs\":  \"4698,4699\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0002-Execution\",\r\n        \"Technique\":  \"T1053.005-Scheduled Task\",\r\n        \"Description\":  \"Schedule task created with suspicious arguments\",\r\n        \"EventIDs\":  \"4698\",\r\n        \"Threat Details\":  \"Atexec\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0002-Execution\",\r\n        \"Technique\":  \"T1053.005-Scheduled Task\",\r\n        \"Description\":  \"Schedule task fastly created and deleted\",\r\n        \"EventIDs\":  \"46,984,699\",\r\n        \"Threat Details\":  \"Atexec\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0002-Execution\",\r\n        \"Technique\":  \"T1053.005-Scheduled Task\",\r\n        \"Description\":  \"Scheduled task creation\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0002-Execution\",\r\n        \"Technique\":  \"T1059.001-Command and Scripting Interpreter: PowerShell\",\r\n        \"Description\":  \"Encoded PowerShell payload deployed\",\r\n        \"EventIDs\":  \"800,4103,4104\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0002-Execution\",\r\n        \"Technique\":  \"T1059.001-Command and Scripting Interpreter: PowerShell\",\r\n        \"Description\":  \"Interactive PipeShell over SMB named pipe\",\r\n        \"EventIDs\":  \"800,4103,4104\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0002-Execution\",\r\n        \"Technique\":  \"T1059.001-Command and Scripting Interpreter: PowerShell\",\r\n        \"Description\":  \"Payload downloaded via PowerShell\",\r\n        \"EventIDs\":  \"800,4103,4104\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0002-Execution\",\r\n        \"Technique\":  \"T1059.003-Windows Command Shell\",\r\n        \"Description\":  \"Encoded PowerShell payload deployed via process execution\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0002-Execution\",\r\n        \"Technique\":  \"T1059.003-Windows Command Shell\",\r\n        \"Description\":  \"SQL Server payload injectection for reverse shell (MSF)\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0002-Execution\",\r\n        \"Technique\":  \"T1204-User execution\",\r\n        \"Description\":  \"Edge abuse for payload download via console\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0002-Execution\",\r\n        \"Technique\":  \"T1204-User execution\",\r\n        \"Description\":  \"Edge/Chrome headless feature abuse for payload download\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0002-Execution\",\r\n        \"Technique\":  \"T1569.002-Service Execution\",\r\n        \"Description\":  \"PSexec installation detected\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0002-Execution\",\r\n        \"Technique\":  \"T1569.002-Service Execution\",\r\n        \"Description\":  \"Service massive failures (native)\",\r\n        \"EventIDs\":  \"7000,7009\",\r\n        \"Threat Details\":  \"Tchopper\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0002-Execution\",\r\n        \"Technique\":  \"T1569.002-Service Execution\",\r\n        \"Description\":  \"Service massive installation (native)\",\r\n        \"EventIDs\":  \"7045,4697\",\r\n        \"Threat Details\":  \"Tchopper\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0002-Execution\",\r\n        \"Technique\":  \"T1569.002-Service Execution\",\r\n        \"Description\":  \"Service massive remote creation via named pipes (native)\",\r\n        \"EventIDs\":  \"5145\",\r\n        \"Threat Details\":  \"Tchopper\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1078.002-Valid accounts-Domain accounts\",\r\n        \"Description\":  \"Account renamed to ?admin? (or likely)\",\r\n        \"EventIDs\":  \"4781\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098.xxx-Account manipulation\",\r\n        \"Description\":  \"Computer account created with privileges\",\r\n        \"EventIDs\":  \"4741\",\r\n        \"Threat Details\":  \"CVE-2021-42278/42287 \\u0026 SAM-the-admin\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098.xxx-Account manipulation\",\r\n        \"Description\":  \"Computer account renamed without a trailing $\",\r\n        \"EventIDs\":  \"4781\",\r\n        \"Threat Details\":  \"CVE-2021-42278/42287 \\u0026 SAM-the-admin\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098.xxx-Account Manipulation\",\r\n        \"Description\":  \"High risk domain group membership change\",\r\n        \"EventIDs\":  \"4728,4756\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098.xxx-Account Manipulation\",\r\n        \"Description\":  \"High risk local-domain local group membership change\",\r\n        \"EventIDs\":  \"4732\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098.xxx-Account manipulation\",\r\n        \"Description\":  \"Host delegation settings changed for potential abuse (any protocol)\",\r\n        \"EventIDs\":  \"4742\",\r\n        \"Threat Details\":  \"Rubeus\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098.xxx-Account manipulation\",\r\n        \"Description\":  \"Host delegation settings changed for potential abuse (any service, Kerberos only)\",\r\n        \"EventIDs\":  \"4742\",\r\n        \"Threat Details\":  \"Rubeus\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098.xxx-Account manipulation\",\r\n        \"Description\":  \"Host delegation settings changed for potential abuse (Kerberos only)\",\r\n        \"EventIDs\":  \"4742\",\r\n        \"Threat Details\":  \"Rubeus\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098.xxx-Account Manipulation\",\r\n        \"Description\":  \"Medium risk local-domain local group membership change\",\r\n        \"EventIDs\":  \"4732\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098.xxx-Account Manipulation\",\r\n        \"Description\":  \"Member added and removed from a group by a user account in a short period of time\",\r\n        \"EventIDs\":  \"4728,29,4756,57,4732,33\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098.xxx-Account manipulation\",\r\n        \"Description\":  \"Member added to a built-in Exchange security group\",\r\n        \"EventIDs\":  \"4756\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098.xxx-Account Manipulation\",\r\n        \"Description\":  \"Member added to a group by the same account\",\r\n        \"EventIDs\":  \"472,847,564,732\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098.xxx-Account Manipulation\",\r\n        \"Description\":  \"Member added to a local group by a user account\",\r\n        \"EventIDs\":  \"4732\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098.xxx-Account manipulation\",\r\n        \"Description\":  \"Member added to DNSadmin group for DLL abuse\",\r\n        \"EventIDs\":  \"4732\",\r\n        \"Threat Details\":  \"DNS DLL abuse\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098.xxx-Account manipulation\",\r\n        \"Description\":  \"New admin (or likely) created by a non administrative account\",\r\n        \"EventIDs\":  \"4720\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098.xxx-Account manipulation\",\r\n        \"Description\":  \"SPN modification of a computer account (Directory Services)\",\r\n        \"EventIDs\":  \"5136\",\r\n        \"Threat Details\":  \"DCShadow\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098.xxx-Account manipulation\",\r\n        \"Description\":  \"SPN modification of a computer account\",\r\n        \"EventIDs\":  \"4742\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098.xxx-Account manipulation\",\r\n        \"Description\":  \"SPN modification of a computer account\",\r\n        \"EventIDs\":  \"4742\",\r\n        \"Threat Details\":  \"DCShadow\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098.xxx-Account manipulation\",\r\n        \"Description\":  \"SPN modification of a user account\",\r\n        \"EventIDs\":  \"5136\",\r\n        \"Threat Details\":  \"Kerberoasting\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098.xxx-Account manipulation\",\r\n        \"Description\":  \"SQL Server: new member added to a database role\",\r\n        \"EventIDs\":  \"33205\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098.xxx-Account manipulation\",\r\n        \"Description\":  \"SQL Server: new member added to server role\",\r\n        \"EventIDs\":  \"33205\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098.xxx-Account manipulation\",\r\n        \"Description\":  \"User account created and/or set with reversible encryption detected\",\r\n        \"EventIDs\":  \"4738\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098.xxx-Account manipulation\",\r\n        \"Description\":  \"User account marked as ?sensitive and cannot be delegated? its had protection removed\",\r\n        \"EventIDs\":  \"4738\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098.xxx-Account manipulation\",\r\n        \"Description\":  \"User account set to not require Kerberos pre-authentication\",\r\n        \"EventIDs\":  \"4738\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098.xxx-Account manipulation\",\r\n        \"Description\":  \"User account set to use Kerberos DES encryption\",\r\n        \"EventIDs\":  \"4738\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098.xxx-Account manipulation\",\r\n        \"Description\":  \"User account with password set to never expire detected\",\r\n        \"EventIDs\":  \"4738\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098.xxx-Account manipulation\",\r\n        \"Description\":  \"User account with password set to not require detected\",\r\n        \"EventIDs\":  \"4738\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098.xxx-Account manipulation\",\r\n        \"Description\":  \"User password change using current hash password ? ChangeNTLM\",\r\n        \"EventIDs\":  \"4723\",\r\n        \"Threat Details\":  \"Mimikatz\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098.xxx-Account manipulation\",\r\n        \"Description\":  \"User password change without previous password known ? SetNTLM\",\r\n        \"EventIDs\":  \"4724\",\r\n        \"Threat Details\":  \"Mimikatz\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098.xxx-Account Manipulation\",\r\n        \"Description\":  \"User performing massive group membership changes on multiple differents groups\",\r\n        \"EventIDs\":  \"47,284,756\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098-Account Manipulation\",\r\n        \"Description\":  \"Disabled guest or builtin account activated\",\r\n        \"EventIDs\":  \"4722\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1098-Account Manipulation\",\r\n        \"Description\":  \"SPN added to an account (command)\",\r\n        \"EventIDs\":  \"4688,1\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1136.001-Create account-Local account\",\r\n        \"Description\":  \"Hidden account creation (with fast deletion)\",\r\n        \"EventIDs\":  \"4720,4726\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1136.001-Create account-Local account\",\r\n        \"Description\":  \"Local user account created on a single host\",\r\n        \"EventIDs\":  \"4720\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1136.001-Create account-Local account\",\r\n        \"Description\":  \"SQL Server: disabled SA account enabled\",\r\n        \"EventIDs\":  \"33205\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1136.002-Create account-Domain account\",\r\n        \"Description\":  \"Computer account created and deleted in a short period of time\",\r\n        \"EventIDs\":  \"4741,4743\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1136.002-Create account-Domain account\",\r\n        \"Description\":  \"User account created and deleted in a short period of time\",\r\n        \"EventIDs\":  \"4720,4726\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1136.002-Create account-Domain account\",\r\n        \"Description\":  \"User account creation disguised in a computer account\",\r\n        \"EventIDs\":  \"4720,4781\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1136-Create account\",\r\n        \"Description\":  \"User creation via commandline\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1505.001-SQL Stored Procedures\",\r\n        \"Description\":  \"SQL lateral movement with CLR\",\r\n        \"EventIDs\":  \"15457\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1505.001-SQL Stored Procedures\",\r\n        \"Description\":  \"SQL Server xp_cmdshell procedure activated\",\r\n        \"EventIDs\":  \"18457\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1505.001-SQL Stored Procedures\",\r\n        \"Description\":  \"SQL Server: sqlcmd \\u0026 ossql utilities abuse\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1505.001-SQL Stored Procedures\",\r\n        \"Description\":  \"SQL Server: started in single mode for password recovery\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1505.002-Server Software Component: Transport Agent\",\r\n        \"Description\":  \"Exchange transport agent injection via configuration file\",\r\n        \"EventIDs\":  \"11\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1505.002-Server Software Component: Transport Agent\",\r\n        \"Description\":  \"Exchange transport agent installation artifacts\",\r\n        \"EventIDs\":  \"6-Jan\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1543.003-Create or Modify System Process-Windows Service\",\r\n        \"Description\":  \"Encoded PowerShell payload deployed via service installation\",\r\n        \"EventIDs\":  \"7045,4697\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1543.003-Create or Modify System Process-Windows Service\",\r\n        \"Description\":  \"Impacket SMBexec service registration (native)\",\r\n        \"EventIDs\":  \"7045,4697\",\r\n        \"Threat Details\":  \"SMBexec\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1543.003-Create or Modify System Process-Windows Service\",\r\n        \"Description\":  \"Mimikatz service driver installation detected\",\r\n        \"EventIDs\":  \"7045,4697\",\r\n        \"Threat Details\":  \"Mimikatz\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1543.003-Create or Modify System Process-Windows Service\",\r\n        \"Description\":  \"Service abuse with backdoored ?command failure? (PowerShell)\",\r\n        \"EventIDs\":  \"800,4103,4104\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1543.003-Create or Modify System Process-Windows Service\",\r\n        \"Description\":  \"Service abuse with backdoored ?command failure? (registry)\",\r\n        \"EventIDs\":  \"4688,1\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1543.003-Create or Modify System Process-Windows Service\",\r\n        \"Description\":  \"Service abuse with backdoored ?command failure? (service)\",\r\n        \"EventIDs\":  \"4688,1\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1543.003-Create or Modify System Process-Windows Service\",\r\n        \"Description\":  \"Service abuse with malicious ImagePath (PowerShell)\",\r\n        \"EventIDs\":  \"800,4103,4104\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1543.003-Create or Modify System Process-Windows Service\",\r\n        \"Description\":  \"Service abuse with malicious ImagePath (registry)\",\r\n        \"EventIDs\":  \"4688,1\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1543.003-Create or Modify System Process-Windows Service\",\r\n        \"Description\":  \"Service abuse with malicious ImagePath (service)\",\r\n        \"EventIDs\":  \"4688,1\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1543.003-Create or Modify System Process-Windows Service\",\r\n        \"Description\":  \"Service created for RDP session hijack\",\r\n        \"EventIDs\":  \"7045,4697\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1543.003-Create or Modify System Process-Windows Service\",\r\n        \"Description\":  \"Service creation (command)\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1543.003-Create or Modify System Process-Windows Service\",\r\n        \"Description\":  \"Service creation (PowerShell)\",\r\n        \"EventIDs\":  \"800,4103,4104\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1546.003-Windows Management Instrumentation Event Subscription\",\r\n        \"Description\":  \"System crash behavior manipulation (registry)\",\r\n        \"EventIDs\":  \"13\",\r\n        \"Threat Details\":  \"WMImplant\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1546.003-Windows Management Instrumentation Event Subscription\",\r\n        \"Description\":  \"WMI registration (PowerShell)\",\r\n        \"EventIDs\":  \"800,4103,4104\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1546.003-Windows Management Instrumentation Event Subscription\",\r\n        \"Description\":  \"WMI registration\",\r\n        \"EventIDs\":  \"19,20,21\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1546.007-Netsh Helper DLL\",\r\n        \"Description\":  \"Netsh helper DLL command abuse\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1546.007-Netsh Helper DLL\",\r\n        \"Description\":  \"Netsh helper DLL registry abuse\",\r\n        \"EventIDs\":  \"13-Dec\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1546-Event Triggered Execution\",\r\n        \"Description\":  \"AdminSDHolder container permissions modified\",\r\n        \"EventIDs\":  \"5136\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1546-Event Triggered Execution\",\r\n        \"Description\":  \"localizationDisplayId attribute abuse for backdoor introduction\",\r\n        \"EventIDs\":  \"5136\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1547.008-Boot or Logon Autostart Execution: LSASS Driver\",\r\n        \"Description\":  \"win-os-security package (SSP) loaded into LSA (native)\",\r\n        \"EventIDs\":  \"4622\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1574.002-DLL Side-Loading\",\r\n        \"Description\":  \"DNS DLL ?serverlevelplugindll? command execution (+registry set)\",\r\n        \"EventIDs\":  \"13-Jan\",\r\n        \"Threat Details\":  \"DNS DLL abuse\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1574.002-DLL Side-Loading\",\r\n        \"Description\":  \"Failed DLL loaded by DNS server\",\r\n        \"EventIDs\":  \"150\",\r\n        \"Threat Details\":  \"DNS DLL abuse\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1574.002-DLL Side-Loading\",\r\n        \"Description\":  \"Success DLL loaded by DNS server\",\r\n        \"EventIDs\":  \"770\",\r\n        \"Threat Details\":  \"DNS DLL abuse\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1574.010-Hijack execution flow: service file permissions weakness\",\r\n        \"Description\":  \"Service permissions modified (registry)\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0003-Persistence\",\r\n        \"Technique\":  \"T1574.010-Hijack execution flow: service file permissions weakness\",\r\n        \"Description\":  \"Service permissions modified (service)\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0004-Privilege Escalation\",\r\n        \"Technique\":  \"T1068-Exploitation for Privilege Escalation\",\r\n        \"Description\":  \"Privilege SeMachineAccountPrivilege abuse\",\r\n        \"EventIDs\":  \"4673\",\r\n        \"Threat Details\":  \"CVE-2021-42278,42287 \\u0026 SAM-the-admin\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0004-Privilege Escalation\",\r\n        \"Technique\":  \"T1134.001- Access Token Manipulation: Token Impersonation,Theft\",\r\n        \"Description\":  \"Anonymous login\",\r\n        \"EventIDs\":  \"4624,4688\",\r\n        \"Threat Details\":  \"RottenPotatoNG\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0004-Privilege Escalation\",\r\n        \"Technique\":  \"T1134.002- Access Token Manipulation: Create Process with Token\",\r\n        \"Description\":  \"Privilege escalation via runas (command)\",\r\n        \"EventIDs\":  \"4688,4648,4624\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0004-Privilege Escalation\",\r\n        \"Technique\":  \"T1134.002- Access Token Manipulation: Create Process with Token\",\r\n        \"Description\":  \"Privilege escalation via RunasCS\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0004-Privilege Escalation\",\r\n        \"Technique\":  \"T1134-Access Token Manipulation\",\r\n        \"Description\":  \"New access rights granted to an account by a standard user\",\r\n        \"EventIDs\":  \"4717\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0004-Privilege Escalation\",\r\n        \"Technique\":  \"T1134-Access Token Manipulation\",\r\n        \"Description\":  \"User right granted to an account by a standard user\",\r\n        \"EventIDs\":  \"4704\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0004-Privilege Escalation\",\r\n        \"Technique\":  \"T1484.001-Domain Policy Modification-Group Policy Modification\",\r\n        \"Description\":  \"Modification of a sensitive Group Policy\",\r\n        \"EventIDs\":  \"5136\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0004-Privilege Escalation\",\r\n        \"Technique\":  \"T1543.003-Create or Modify System Process-Windows Service\",\r\n        \"Description\":  \"PSexec service installation detected\",\r\n        \"EventIDs\":  \"7045,4697\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0004-Privilege Escalation\",\r\n        \"Technique\":  \"T1546.008-Event Triggered Execution: Accessibility Features\",\r\n        \"Description\":  \"CMD executed by stickey key and detected via hash\",\r\n        \"EventIDs\":  \"1\",\r\n        \"Threat Details\":  \"Sticky key\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0004-Privilege Escalation\",\r\n        \"Technique\":  \"T1546.008-Event Triggered Execution: Accessibility Features\",\r\n        \"Description\":  \"Sticky key called CMD via command execution\",\r\n        \"EventIDs\":  \"4688,1\",\r\n        \"Threat Details\":  \"Sticky key\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0004-Privilege Escalation\",\r\n        \"Technique\":  \"T1546.008-Event Triggered Execution: Accessibility Features\",\r\n        \"Description\":  \"Sticky key failed sethc replacement by CMD\",\r\n        \"EventIDs\":  \"4656\",\r\n        \"Threat Details\":  \"Sticky key\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0004-Privilege Escalation\",\r\n        \"Technique\":  \"T1546.008-Event Triggered Execution: Accessibility Features\",\r\n        \"Description\":  \"Sticky key file created from CMD copy\",\r\n        \"EventIDs\":  \"11\",\r\n        \"Threat Details\":  \"Sticky key\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0004-Privilege Escalation\",\r\n        \"Technique\":  \"T1546.008-Event Triggered Execution: Accessibility Features\",\r\n        \"Description\":  \"Sticky key IFEO command for registry change\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"Sticky key\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0004-Privilege Escalation\",\r\n        \"Technique\":  \"T1546.008-Event Triggered Execution: Accessibility Features\",\r\n        \"Description\":  \"Sticky key IFEO registry changed\",\r\n        \"EventIDs\":  \"13-Dec\",\r\n        \"Threat Details\":  \"Sticky key\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0004-Privilege Escalation\",\r\n        \"Technique\":  \"T1547.010-Port Monitors\",\r\n        \"Description\":  \"Print spooler privilege escalation via printer added\",\r\n        \"EventIDs\":  \"800,4103,4104\",\r\n        \"Threat Details\":  \"PrintNightmare (CVE-2021-1675 / CVE-2021-34527)\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0004-Privilege Escalation\",\r\n        \"Technique\":  \"T1574.002-DLL Side-Loading\",\r\n        \"Description\":  \"External printer mapped\",\r\n        \"EventIDs\":  \"4688,4648\",\r\n        \"Threat Details\":  \"PrintNightmare (CVE-2021-1675 / CVE-2021-34527)\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0004-Privilege Escalation\",\r\n        \"Technique\":  \"T1574.002-DLL Side-Loading\",\r\n        \"Description\":  \"Printer spool driver from Mimikatz installed\",\r\n        \"EventIDs\":  \"808 , 354 , 321\",\r\n        \"Threat Details\":  \"PrintNightmare (CVE-2021-1675 / CVE-2021-34527)\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0004-Privilege Escalation\",\r\n        \"Technique\":  \"T1574.002-DLL Side-Loading\",\r\n        \"Description\":  \"proxi\",\r\n        \"EventIDs\":  \"6416\",\r\n        \"Threat Details\":  \"PrintNightmare (CVE-2021-1675 / CVE-2021-34527)\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0004-Privilege Escalation\",\r\n        \"Technique\":  \"T1574.002-DLL Side-Loading\",\r\n        \"Description\":  \"Spool process spawned a CMD shell\",\r\n        \"EventIDs\":  \"4688,1\",\r\n        \"Threat Details\":  \"PrintNightmare (CVE-2021-1675 / CVE-2021-34527)\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1027-Obfuscated Files or Information\",\r\n        \"Description\":  \"Payload obfuscated transfer via service name\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"Tchopper\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1070.001-Indicator Removal on Host\",\r\n        \"Description\":  \"Event log file(s) cleared\",\r\n        \"EventIDs\":  \"104,1102\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1070.001-Indicator Removal on Host\",\r\n        \"Description\":  \"Tentative of clearing event log file(s) detected (command)\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1070.001-Indicator Removal on Host\",\r\n        \"Description\":  \"Tentative of clearing event log file(s) detected (PowerShell)\",\r\n        \"EventIDs\":  \"800,4103,4104\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1070.001-Indicator Removal on Host\",\r\n        \"Description\":  \"Tentative of clearing event log file(s) detected (wmi)\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1070.006-Timestomp\",\r\n        \"Description\":  \"System time changed\",\r\n        \"EventIDs\":  \"4616\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1070.xxx-Audit policy disabled\",\r\n        \"Description\":  \"Audit policy disabled\",\r\n        \"EventIDs\":  \"4719\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1070.xxx-Audit policy disabled\",\r\n        \"Description\":  \"Domain policy changed on one or multiple hosts\",\r\n        \"EventIDs\":  \"4739\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1070.xxx-Audit policy disabled\",\r\n        \"Description\":  \"Membership of a special group updated\",\r\n        \"EventIDs\":  \"4908\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1070.xxx-Audit policy disabled\",\r\n        \"Description\":  \"SQL Server: Audit object deleted\",\r\n        \"EventIDs\":  \"33205\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1070.xxx-Audit policy disabled\",\r\n        \"Description\":  \"SQL Server: Audit object disabled\",\r\n        \"EventIDs\":  \"33205\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1070.xxx-Audit policy disabled\",\r\n        \"Description\":  \"SQL Server: Audit specifications deleted\",\r\n        \"EventIDs\":  \"33205\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1070.xxx-Audit policy disabled\",\r\n        \"Description\":  \"SQL Server: Audit specifications disabled\",\r\n        \"EventIDs\":  \"33205\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1070.xxx-Audit policy disabled\",\r\n        \"Description\":  \"SQL Server: Database audit specifications deleted\",\r\n        \"EventIDs\":  \"33205\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1070.xxx-Audit policy disabled\",\r\n        \"Description\":  \"SQL Server: Database audit specifications disabled\",\r\n        \"EventIDs\":  \"33205\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1070.xxx-Audit policy disabled\",\r\n        \"Description\":  \"Tentative of disabling or clearing audit policy by commandline\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1078.002-Valid accounts-Domain accounts\",\r\n        \"Description\":  \"Login from a user member of a ?special group? detected (special logon)\",\r\n        \"EventIDs\":  \"4964\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1112-Modify registry\",\r\n        \"Description\":  \"Impacket SMBexec service registration (registry)\",\r\n        \"EventIDs\":  \"13\",\r\n        \"Threat Details\":  \"SMBexec\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1197-BITS job\",\r\n        \"Description\":  \"Command execution related to a suspicious BITS activity detected\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1197-BITS job\",\r\n        \"Description\":  \"Command execution related to a suspicious BITS activity detected\",\r\n        \"EventIDs\":  \"800,4103,4104\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1197-BITS job\",\r\n        \"Description\":  \"High amount of data downloaded via BITS\",\r\n        \"EventIDs\":  \"60\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1207-Rogue domain controller\",\r\n        \"Description\":  \"New fake domain controller registration\",\r\n        \"EventIDs\":  \"5137 , 5141\",\r\n        \"Threat Details\":  \"DCShadow\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1207-Rogue domain controller\",\r\n        \"Description\":  \"Sensitive attributes accessed\",\r\n        \"EventIDs\":  \"4662\",\r\n        \"Threat Details\":  \"DCShadow\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1222.001-File and Directory Permissions Modification\",\r\n        \"Description\":  \"Computer account modifying AD permissions\",\r\n        \"EventIDs\":  \"5136\",\r\n        \"Threat Details\":  \"PrivExchange\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1222.001-File and Directory Permissions Modification\",\r\n        \"Description\":  \"Network share permissions changed\",\r\n        \"EventIDs\":  \"5143\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1222.001-File and Directory Permissions Modification\",\r\n        \"Description\":  \"OCSP security settings changed\",\r\n        \"EventIDs\":  \"5124(OCSP)\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1222.001-File and Directory Permissions Modification\",\r\n        \"Description\":  \"Permissions changed on a GPO\",\r\n        \"EventIDs\":  \"5136\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1222.001-File and Directory Permissions Modification\",\r\n        \"Description\":  \"Sensitive GUID related to ?Replicate directory changes? detected\",\r\n        \"EventIDs\":  \"4662\",\r\n        \"Threat Details\":  \"DCSync\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1553.003- Subvert Trust Controls: SIP and Trust Provider Hijacking\",\r\n        \"Description\":  \"\",\r\n        \"EventIDs\":  \"13-Dec\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1562.001-Impair Defenses-Disable or modify tools\",\r\n        \"Description\":  \"Defender: critical security component disabled (command)\",\r\n        \"EventIDs\":  \"4688,1\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1562.001-Impair Defenses-Disable or modify tools\",\r\n        \"Description\":  \"Defender: critical security component disabled (PowerShell)\",\r\n        \"EventIDs\":  \"800,4103,4104\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1562.001-Impair Defenses-Disable or modify tools\",\r\n        \"Description\":  \"Defender: default action set to allow any threat (PowerShell)\",\r\n        \"EventIDs\":  \"800,4103,4104\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1562.001-Impair Defenses-Disable or modify tools\",\r\n        \"Description\":  \"Defender: exclusion added (native)\",\r\n        \"EventIDs\":  \"5007\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1562.001-Impair Defenses-Disable or modify tools\",\r\n        \"Description\":  \"Defender: exclusion added (PowerShell)\",\r\n        \"EventIDs\":  \"800,4103,4104\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1562.001-Impair Defenses-Disable or modify tools\",\r\n        \"Description\":  \"Defender: service component status disabled (Registry via Sysmon)\",\r\n        \"EventIDs\":  \"13\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1562.004-Disable or Modify System Firewall\",\r\n        \"Description\":  \"Firewall deactivation (cmd)\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1562.004-Disable or Modify System Firewall\",\r\n        \"Description\":  \"Firewall deactivation (firewall)\",\r\n        \"EventIDs\":  \"2003,4950\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1562.004-Disable or Modify System Firewall\",\r\n        \"Description\":  \"Firewall deactivation (PowerShell)\",\r\n        \"EventIDs\":  \"800,4103,4104\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1562.004-Disable/modify firewall (rule)\",\r\n        \"Description\":  \"Any/any firewall rule created\",\r\n        \"EventIDs\":  \"2004\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1562.004-Disable/modify firewall (rule)\",\r\n        \"Description\":  \"Firewall rule created by a suspicious command (netsh.exe, wmiprvse.exe)\",\r\n        \"EventIDs\":  \"2004\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1562.004-Disable/modify firewall (rule)\",\r\n        \"Description\":  \"Firewall rule created by a user account\",\r\n        \"EventIDs\":  \"2004\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1562.004-Disable,modify firewall (rule)\",\r\n        \"Description\":  \"OpenSSH server firewall configuration (command)\",\r\n        \"EventIDs\":  \"4688,1\",\r\n        \"Threat Details\":  \"SSH server\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1562.004-Disable/modify firewall (rule)\",\r\n        \"Description\":  \"OpenSSH server firewall configuration (firewall)\",\r\n        \"EventIDs\":  \"2004\",\r\n        \"Threat Details\":  \"SSH server\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1562.004-Disable/modify firewall (rule)\",\r\n        \"Description\":  \"OpenSSH server firewall configuration (PowerShell)\",\r\n        \"EventIDs\":  \"800,4103,4104\",\r\n        \"Threat Details\":  \"SSH server\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0005-Defense Evasion\",\r\n        \"Technique\":  \"T1564.006-Hide Artifacts: Run Virtual Instance\",\r\n        \"Description\":  \"WSL for Windows installation detected\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1003.001-Credential dumping: LSASS\",\r\n        \"Description\":  \"LSASS credential dump with LSASSY (kernel)\",\r\n        \"EventIDs\":  \"4656,4663\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1003.001-Credential dumping: LSASS\",\r\n        \"Description\":  \"LSASS credential dump with LSASSY (PowerShell)\",\r\n        \"EventIDs\":  \"800,4103,4104\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1003.001-Credential dumping: LSASS\",\r\n        \"Description\":  \"LSASS credential dump with LSASSY (process)\",\r\n        \"EventIDs\":  \"4688,1\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1003.001-Credential dumping: LSASS\",\r\n        \"Description\":  \"LSASS credential dump with LSASSY (share)\",\r\n        \"EventIDs\":  \"5145\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1003.001-Credential dumping: LSASS\",\r\n        \"Description\":  \"LSASS credentials dump via Task Manager (file)\",\r\n        \"EventIDs\":  \"11\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1003.001-Credential dumping: LSASS\",\r\n        \"Description\":  \"LSASS dump indicator via Task Manager access\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1003.001-Credential dumping: LSASS\",\r\n        \"Description\":  \"LSASS process accessed by a non system account\",\r\n        \"EventIDs\":  \"4656,4663\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1003.001-Credential dumping: LSASS\",\r\n        \"Description\":  \"SAM database user credential dump\",\r\n        \"EventIDs\":  \"4661\",\r\n        \"Threat Details\":  \"Mimikatz\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1003.002-Security Account Manager\",\r\n        \"Description\":  \"Password dump over SMB ADMIN$\",\r\n        \"EventIDs\":  \"5145\",\r\n        \"Threat Details\":  \"Secretdump\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1003.002-Security Account Manager\",\r\n        \"Description\":  \"SAM database access during DCshadow\",\r\n        \"EventIDs\":  \"4661\",\r\n        \"Threat Details\":  \"DCShadow\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1003.003-NTDS\",\r\n        \"Description\":  \"IFM created\",\r\n        \"EventIDs\":  \"325,327\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1003.003-NTDS\",\r\n        \"Description\":  \"IFM created from command line\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1003.003-OS Credential-Dumping NTDS\",\r\n        \"Description\":  \"DSRM configuration changed (Reg via command)\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1003.003-OS Credential-Dumping NTDS\",\r\n        \"Description\":  \"DSRM configuration changed (Reg via PowerShell)\",\r\n        \"EventIDs\":  \"800,4103,4104\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1003.003-OS Credential-Dumping NTDS\",\r\n        \"Description\":  \"DSRM password reset\",\r\n        \"EventIDs\":  \"4794\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1003.006-DCSync\",\r\n        \"Description\":  \"Member added to a sensitive Exchange security group to perform DCsync attack\",\r\n        \"EventIDs\":  \"4756\",\r\n        \"Threat Details\":  \"DCSync\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1003-Credential dumping\",\r\n        \"Description\":  \"Backdoor introduction via registry permission change through WMI (DAMP)\",\r\n        \"EventIDs\":  \"4674\",\r\n        \"Threat Details\":  \"DAMP\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1003-Credential dumping\",\r\n        \"Description\":  \"Diskshadow abuse\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1003-Credential dumping\",\r\n        \"Description\":  \"Wdigest authentication enabled (Reg via command)\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1003-Credential dumping\",\r\n        \"Description\":  \"Wdigest authentication enabled (Reg via Sysmon)\",\r\n        \"EventIDs\":  \"13-Dec\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1040-Network sniffing\",\r\n        \"Description\":  \"Windows native sniffing tool Pktmon usage\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1110.xxx-Brut force\",\r\n        \"Description\":  \"Brutforce enumeration on Windows OpenSSH server with non existing user\",\r\n        \"EventIDs\":  \"4625,4\",\r\n        \"Threat Details\":  \"SSH server\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1110.xxx-Brut force\",\r\n        \"Description\":  \"Brutforce on Windows OpenSSH server with valid user\",\r\n        \"EventIDs\":  \"4625,4\",\r\n        \"Threat Details\":  \"SSH server\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1110.xxx-Brut force\",\r\n        \"Description\":  \"Kerberos brutforce enumeration with existing,unexsting users (Kerbrute)\",\r\n        \"EventIDs\":  \"4771,4768\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1110.xxx-Brut force\",\r\n        \"Description\":  \"Kerberos brutforce with not existing users\",\r\n        \"EventIDs\":  \"4771,4768\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1110.xxx-Brut force\",\r\n        \"Description\":  \"Login failure from a single source with different non existing accounts\",\r\n        \"EventIDs\":  \"33205\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1552.004-Unsecured Credentials-Private Keys\",\r\n        \"Description\":  \"Unknown application accessing certificate private key detected\",\r\n        \"EventIDs\":  \"70(CAPI2)\",\r\n        \"Threat Details\":  \"Mimikatz\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1555.003-Credentials from Password Stores: Credentials from Web Browsers\",\r\n        \"Description\":  \"User browser credentials dump via network share\",\r\n        \"EventIDs\":  \"5145\",\r\n        \"Threat Details\":  \"DonPapi, Lazagne\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1555.004-Windows Credential Manager\",\r\n        \"Description\":  \"Credentials (protected by DPAPI) dump via network share\",\r\n        \"EventIDs\":  \"5145\",\r\n        \"Threat Details\":  \"DonPapi, Lazagne\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1555-Credentials from Password Stores\",\r\n        \"Description\":  \"Suspicious Active Directory DPAPI attributes accessed\",\r\n        \"EventIDs\":  \"4662\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1555-Credentials from Password Stores\",\r\n        \"Description\":  \"User files dump via network share\",\r\n        \"EventIDs\":  \"5145\",\r\n        \"Threat Details\":  \"DonPapi, Lazagne\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1557.001-MiM:LLMNR/NBT-NS Poisoning and SMB Relay\",\r\n        \"Description\":  \"Discovery for print spooler bug abuse via named pipe\",\r\n        \"EventIDs\":  \"5145\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1558.001-Golden Ticket\",\r\n        \"Description\":  \"Kerberos TGS ticket request related to a potential Golden ticket\",\r\n        \"EventIDs\":  \"4769\",\r\n        \"Threat Details\":  \"Golden ticket\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1558.001-Golden Ticket\",\r\n        \"Description\":  \"SMB Admin share accessed with a forged Golden ticket\",\r\n        \"EventIDs\":  \"5140,5145\",\r\n        \"Threat Details\":  \"Golden ticket\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1558.001-Golden Ticket\",\r\n        \"Description\":  \"Success login impersonation with forged Golden ticket\",\r\n        \"EventIDs\":  \"4624\",\r\n        \"Threat Details\":  \"Golden ticket\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1558.003-Kerberoasting\",\r\n        \"Description\":  \"KerberOAST ticket (TGS) request detected (low encryption)\",\r\n        \"EventIDs\":  \"4769\",\r\n        \"Threat Details\":  \"Kerberoast\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1558.004-Steal or Forge Kerberos Tickets: AS-REP Roasting\",\r\n        \"Description\":  \"Kerberos AS-REP Roasting ticket request detected\",\r\n        \"EventIDs\":  \"4768\",\r\n        \"Threat Details\":  \"AS-REP Roasting\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1558-Steal or Forge Kerberos Tickets\",\r\n        \"Description\":  \"Kerberos ticket without a trailing $\",\r\n        \"EventIDs\":  \"4768-4769\",\r\n        \"Threat Details\":  \"CVE-2021-42278/42287 \\u0026 SAM-the-admin\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0006-Credential Access\",\r\n        \"Technique\":  \"T1558-Steal or Forge Kerberos Tickets\",\r\n        \"Description\":  \"Suspicious Kerberos proxiable ticket\",\r\n        \"EventIDs\":  \"4768\",\r\n        \"Threat Details\":  \"CVE-2021-42278/42287 \\u0026 SAM-the-admin\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0007-Discovery\",\r\n        \"Technique\":  \"T1016-System Network Configuration Discovery\",\r\n        \"Description\":  \"Firewall configuration enumerated (command)\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0007-Discovery\",\r\n        \"Technique\":  \"T1016-System Network Configuration Discovery\",\r\n        \"Description\":  \"Firewall configuration enumerated (PowerShell)\",\r\n        \"EventIDs\":  \"800,4103,4104\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0007-Discovery\",\r\n        \"Technique\":  \"T1016-System Network Configuration Discovery\",\r\n        \"Description\":  \"Tentative of zone transfer from a non DNS server detected\",\r\n        \"EventIDs\":  \"6004(DNSserver)\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0007-Discovery\",\r\n        \"Technique\":  \"T1018-Remote System Discovery\",\r\n        \"Description\":  \"DNS hosts file accessed via network share\",\r\n        \"EventIDs\":  \"5145\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0007-Discovery\",\r\n        \"Technique\":  \"T1046-Network Service Scanning\",\r\n        \"Description\":  \"RDP discovery performed on multiple hosts\",\r\n        \"EventIDs\":  \"4625,131\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0007-Discovery\",\r\n        \"Technique\":  \"T1046-Network Service Scanning\",\r\n        \"Description\":  \"Suspicious anonymous login\",\r\n        \"EventIDs\":  \"4624\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0007-Discovery\",\r\n        \"Technique\":  \"T1069.001-Discovery domain groups\",\r\n        \"Description\":  \"Local domain group enumeration via RID brutforce\",\r\n        \"EventIDs\":  \"4661\",\r\n        \"Threat Details\":  \"CrackMapExec\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0007-Discovery\",\r\n        \"Technique\":  \"T1069.001-Discovery local groups\",\r\n        \"Description\":  \"Remote local administrator group enumerated\",\r\n        \"EventIDs\":  \"4799\",\r\n        \"Threat Details\":  \"SharpHound\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0007-Discovery\",\r\n        \"Technique\":  \"T1069.002-Discovery domain groups\",\r\n        \"Description\":  \"Domain group enumeration\",\r\n        \"EventIDs\":  \"4661\",\r\n        \"Threat Details\":  \"CrackMapExec\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0007-Discovery\",\r\n        \"Technique\":  \"T1069.002-Discovery domain groups\",\r\n        \"Description\":  \"Honeypot object (container, computer, group, user) enumerated\",\r\n        \"EventIDs\":  \"4662\",\r\n        \"Threat Details\":  \"SharpHound\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0007-Discovery\",\r\n        \"Technique\":  \"T1069.002-Discovery domain groups\",\r\n        \"Description\":  \"Massive SAM domain users \\u0026 groups discovery\",\r\n        \"EventIDs\":  \"4661\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0007-Discovery\",\r\n        \"Technique\":  \"T1069.002-Discovery domain groups\",\r\n        \"Description\":  \"Sensitive SAM domain user \\u0026 groups discovery\",\r\n        \"EventIDs\":  \"4661\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0007-Discovery\",\r\n        \"Technique\":  \"T1069-Permission Groups Discovery\",\r\n        \"Description\":  \"Group discovery via commandline\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0007-Discovery\",\r\n        \"Technique\":  \"T1069-Permission Groups Discovery\",\r\n        \"Description\":  \"Group discovery via PowerShell\",\r\n        \"EventIDs\":  \"800,4103,4104\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0007-Discovery\",\r\n        \"Technique\":  \"T1082-System Information Discovery\",\r\n        \"Description\":  \"Audit policy settings collection\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0007-Discovery\",\r\n        \"Technique\":  \"T1087.002-Domain Account discovery\",\r\n        \"Description\":  \"Active Directory PowerShell module called from a non administrative host\",\r\n        \"EventIDs\":  \"600\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0007-Discovery\",\r\n        \"Technique\":  \"T1087.002-Domain Account discovery\",\r\n        \"Description\":  \"Single source performing host enumeration over Kerberos ticket (TGS) detected\",\r\n        \"EventIDs\":  \"4769\",\r\n        \"Threat Details\":  \"SharpHound\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0007-Discovery\",\r\n        \"Technique\":  \"T1087-Account discovery\",\r\n        \"Description\":  \"SPN enumeration (command)\",\r\n        \"EventIDs\":  \"4688,1\",\r\n        \"Threat Details\":  \"Kerberoast\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0007-Discovery\",\r\n        \"Technique\":  \"T1087-Account discovery\",\r\n        \"Description\":  \"SPN enumeration (PowerShell)\",\r\n        \"EventIDs\":  \"800,4103,4104\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0007-Discovery\",\r\n        \"Technique\":  \"T1087-Account discovery\",\r\n        \"Description\":  \"User enumeration via commandline\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0007-Discovery\",\r\n        \"Technique\":  \"T1135-Network Share Discovery\",\r\n        \"Description\":  \"Host performing advanced named pipes enumeration on different hosts via SMB\",\r\n        \"EventIDs\":  \"5145\",\r\n        \"Threat Details\":  \"SharpHound\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0007-Discovery\",\r\n        \"Technique\":  \"T1135-Network Share Discovery\",\r\n        \"Description\":  \"Network share discovery and/or connection via commandline\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0007-Discovery\",\r\n        \"Technique\":  \"T1135-Network Share Discovery\",\r\n        \"Description\":  \"Network share manipulation via commandline\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0007-Discovery\",\r\n        \"Technique\":  \"T1201-Password Policy Discovery\",\r\n        \"Description\":  \"Domain password policy enumeration\",\r\n        \"EventIDs\":  \"4661\",\r\n        \"Threat Details\":  \"CrackMapExec\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0007-Discovery\",\r\n        \"Technique\":  \"T1201-Password Policy Discovery\",\r\n        \"Description\":  \"Password policy discovery via commandline\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0007-Discovery\",\r\n        \"Technique\":  \"T1482-Domain Trust Discovery\",\r\n        \"Description\":  \"Active Directory Forest PowerShell class called from a non administrative host\",\r\n        \"EventIDs\":  \"800,4103,4104\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0008-Lateral Movement\",\r\n        \"Technique\":  \"T1021.001-Remote Desktop Protocol\",\r\n        \"Description\":  \"Denied RDP login with valid credentials\",\r\n        \"EventIDs\":  \"4825\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0008-Lateral Movement\",\r\n        \"Technique\":  \"T1021.002-SMB Windows Admin Shares\",\r\n        \"Description\":  \"Admin share accessed via SMB (basic)\",\r\n        \"EventIDs\":  \"5140,5145\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0008-Lateral Movement\",\r\n        \"Technique\":  \"T1021.002-SMB Windows Admin Shares\",\r\n        \"Description\":  \"Impacket WMIexec execution via SMB admin share\",\r\n        \"EventIDs\":  \"5145\",\r\n        \"Threat Details\":  \"WMIexec\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0008-Lateral Movement\",\r\n        \"Technique\":  \"T1021.002-SMB Windows Admin Shares\",\r\n        \"Description\":  \"Lateral movement by mounting a network share ? net use (command)\",\r\n        \"EventIDs\":  \"4688,4648\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0008-Lateral Movement\",\r\n        \"Technique\":  \"T1021.002-SMB Windows Admin Shares\",\r\n        \"Description\":  \"Multiple failed attempt to network share\",\r\n        \"EventIDs\":  \"5140,5145\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0008-Lateral Movement\",\r\n        \"Technique\":  \"T1021.002-SMB Windows Admin Shares\",\r\n        \"Description\":  \"New file share created on a host\",\r\n        \"EventIDs\":  \"5142\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0008-Lateral Movement\",\r\n        \"Technique\":  \"T1021.002-SMB Windows Admin Shares\",\r\n        \"Description\":  \"Psexec remote execution via SMB\",\r\n        \"EventIDs\":  \"5145\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0008-Lateral Movement\",\r\n        \"Technique\":  \"T1021.002-SMB Windows Admin Shares\",\r\n        \"Description\":  \"Remote service creation over SMB\",\r\n        \"EventIDs\":  \"5145\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0008-Lateral Movement\",\r\n        \"Technique\":  \"T1021.002-SMB Windows Admin Shares\",\r\n        \"Description\":  \"Remote shell execuction via SMB admin share\",\r\n        \"EventIDs\":  \"5145\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0008-Lateral Movement\",\r\n        \"Technique\":  \"T1021.002-SMB Windows Admin Shares\",\r\n        \"Description\":  \"Shared printer creation\",\r\n        \"EventIDs\":  \"5142\",\r\n        \"Threat Details\":  \"PrintNightmare (CVE-2021-1675 / CVE-2021-34527)\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0008-Lateral Movement\",\r\n        \"Technique\":  \"T1021.003-DCOM\",\r\n        \"Description\":  \"DCOM lateral movement (via MMC20)\",\r\n        \"EventIDs\":  \"4104\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0008-Lateral Movement\",\r\n        \"Technique\":  \"T1021.003-DCOM\",\r\n        \"Description\":  \"DCOMexec privilege abuse\",\r\n        \"EventIDs\":  \"4674\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0008-Lateral Movement\",\r\n        \"Technique\":  \"T1021.003-DCOM\",\r\n        \"Description\":  \"DCOMexec process abuse via MMC\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0008-Lateral Movement\",\r\n        \"Technique\":  \"T1021.004-Remote services: SSH\",\r\n        \"Description\":  \"OpenSSH native server feature installation\",\r\n        \"EventIDs\":  \"800,4103,4104\",\r\n        \"Threat Details\":  \"SSH server\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0008-Lateral Movement\",\r\n        \"Technique\":  \"T1021.004-Remote services: SSH\",\r\n        \"Description\":  \"OpenSSH server for Windows activation,configuration detected\",\r\n        \"EventIDs\":  \"800,4103,4104\",\r\n        \"Threat Details\":  \"SSH server\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0008-Lateral Movement\",\r\n        \"Technique\":  \"T1021.006-Windows Remote Management\",\r\n        \"Description\":  \"WinRM listening service reconnaissance\",\r\n        \"EventIDs\":  \"4656\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0008-Lateral Movement\",\r\n        \"Technique\":  \"T1550.002-Use Alternate Authentication Material: Pass the Hash\",\r\n        \"Description\":  \"LSASS dump via process access\",\r\n        \"EventIDs\":  \"10\",\r\n        \"Threat Details\":  \"Mimikatz\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0008-Lateral Movement\",\r\n        \"Technique\":  \"T1550.002-Use Alternate Authentication Material: Pass the Hash\",\r\n        \"Description\":  \"Pass-the-hash login\",\r\n        \"EventIDs\":  \"4624\",\r\n        \"Threat Details\":  \"Mimikatz\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0008-Lateral Movement\",\r\n        \"Technique\":  \"T1563.002-RDP hijacking\",\r\n        \"Description\":  \"RDP session hijack via TSCON abuse command\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0009-Collection\",\r\n        \"Technique\":  \"T1125-Video capture\",\r\n        \"Description\":  \"RDP shadow session started (registry)\",\r\n        \"EventIDs\":  \"13\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0011-Command and control\",\r\n        \"Technique\":  \"T1572-Protocol tunneling\",\r\n        \"Description\":  \"RDP tunneling configuration enabled for port forwarding\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0040-Impact\",\r\n        \"Technique\":  \"T1490-Inhibit System Recovery\",\r\n        \"Description\":  \"VSS backup deletion (PowerShell)\",\r\n        \"EventIDs\":  \"800,4103,4104\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0040-Impact\",\r\n        \"Technique\":  \"T1490-Inhibit System Recovery\",\r\n        \"Description\":  \"VSS backup deletion (WMI)\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0040-Impact\",\r\n        \"Technique\":  \"T1490-Inhibit System Recovery\",\r\n        \"Description\":  \"Windows native backup deletion\",\r\n        \"EventIDs\":  \"4688\",\r\n        \"Threat Details\":  \"\"\r\n    },\r\n    {\r\n        \"Tactic\":  \"TA0040-Impact\",\r\n        \"Technique\":  \"T1565-Data manipulation\",\r\n        \"Description\":  \"DNS hosts file modified\",\r\n        \"EventIDs\":  \"11\",\r\n        \"Threat Details\":  \"\"\r\n    }\r\n]);\r\nprint mitre_ids\r\n| mv-expand print_0\r\n| project Tactic = tostring(print_0.Tactic), Technique = tostring(print_0.Technique), Description = tostring(print_0.Description), EventIDs = tostring(print_0.EventIDs), Threat_Details = tostring(print_0.[\"Threat Details\"])\r\n| where Tactic has_any (set_items)\r\n| extend EventIDs = split(EventIDs, ',')\r\n| extend EventIDs = replace_regex(tostring(EventIDs), '\\\"', '')\r\n| mv-expand todynamic(EventIDs)\r\n| distinct toint(EventIDs)\r\n| where isnotempty(EventIDs)\r\n| order by EventIDs asc\r\n",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "id": "0e5e8493-a476-415b-978d-958c441cf95e",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "ManualEventsMitre",
                                    "type": 9,
                                    "multiSelect": true,
                                    "quote": "'",
                                    "delimiter": ",",
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "label": "Manual Events"
                                  },
                                  {
                                    "version": "KqlParameterItem/1.0",
                                    "name": "MitreExclude",
                                    "label": "Excluded Events",
                                    "type": 9,
                                    "multiSelect": true,
                                    "quote": "'",
                                    "delimiter": ",",
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "id": "0d59a7d0-4c2e-4a65-98ce-ba96dca3f547"
                                  },
                                  {
                                    "id": "7e90a02e-8fe4-4230-a481-b96fe99b1447",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "parseManualMitre",
                                    "type": 1,
                                    "query": "let manualIds = \"{ManualEventsMitre}\";\r\nprint ids=manualIds\r\n| project ids = todynamic(strcat('[', replace_regex(ids,\"\\'\",\"\"),']'))\r\n| mv-expand ids\r\n| project ids = toint(ids)",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "version": "KqlParameterItem/1.0",
                                    "name": "parseExcludeMitre",
                                    "type": 1,
                                    "query": "let manualIds = \"{MitreExclude}\";\r\nprint ids=manualIds\r\n| project ids = todynamic(strcat('[', replace_regex(ids,\"\\'\",\"\"),']'))\r\n| mv-expand ids\r\n| project ids = toint(ids)",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces",
                                    "id": "d185c858-e55a-4ca3-aaa7-fde70bcc848b"
                                  },
                                  {
                                    "id": "16384634-2db8-4235-8930-7cd467fb6a18",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "mergedMitre",
                                    "type": 1,
                                    "query": "let manual_ids = () {\r\n    print ids=todynamic(\"{parseManualMitre}\")\r\n    | mvexpand ids\r\n    | project ids = toint(ids)\r\n};\r\nlet exclude_ids = () {\r\n    print ids=todynamic(\"{parseExcludeMitre}\")\r\n    | mvexpand ids\r\n    | project ids = toint(ids)\r\n};\r\nlet tierIds = () {\r\n    print ids = todynamic(\"{IngestArray}\")\r\n    | mvexpand ids\r\n    | project ids = toint(ids)\r\n};\r\nlet mitreIds = () {\r\n    print  ids=todynamic('{mitreIds}')\r\n    | mv-expand ids\r\n    | project ids = toint(ids)\r\n};\r\nunion manual_ids, tierIds, mitreIds\r\n| where ids !in (exclude_ids)\r\n| where isnotempty(ids)\r\n| summarize by ids\r\n| sort by ids asc",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "id": "9b0c1c80-cc90-4de7-b29b-d8139a05d4b6",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "generatedJSONMitre",
                                    "type": 1,
                                    "query": "// Referenced merged array\r\nlet generated = () {\r\n    print merged=\"{mergedMitre:escapejson}\"\r\n    | extend merged=todynamic(merged)\r\n    | mvexpand merged\r\n    | top 100 by toint(merged) asc\r\n    | extend merged = tostring(strcat(\"(EventID=\",merged,\")\"))\r\n    | sort by tolong(merged) asc\r\n    | extend index=row_rank(merged)\r\n    | summarize merged=makeset(merged) by (index/10)\r\n    | extend concat= strcat_array(merged,\" or \")\r\n    | project p = strcat(\"Security!*[System[\",concat,\"]]\")\r\n    | summarize makeset(p)\r\n};\r\ngenerated",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "id": "025e76a7-19a2-4d4e-a596-3e7da508ef9d",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "MITREDCR2",
                                    "type": 1,
                                    "isGlobal": true,
                                    "query": "let Count = print merged=\"{mergedMitre:escapejson}\"\r\n    | extend merged=todynamic(merged)\r\n    | mvexpand merged\r\n    | summarize count()\r\n    | extend Counter = toint(count_);\r\nlet Check =\r\n    Count\r\n    | extend Check = iff(Counter <= 100, 'DCR not needed', 'DCR needed')\r\n    | extend Math = Counter - 100\r\n    | extend diff = iff(Math < 0 or Math > 100, 'New DCR will not work', array_split(todynamic(\"{mergedMitre:escapejson}\"), 100)[1])\r\n    | extend diff = todynamic(diff)\r\n    | mv-expand diff\r\n    | project toint(diff)\r\n    | top 100 by diff asc\r\n    | summarize Array = make_set(diff);\r\nlet Configure = (Array:dynamic) { print Array\r\n    | extend Array = todynamic(Array)\r\n    | mv-expand Array\r\n    | extend merged = tostring(strcat(\"(EventID=\",Array,\")\"))\r\n    | sort by tolong(merged) asc\r\n    | extend index=row_rank(merged)\r\n    | summarize merged=makeset(merged) by (index/10)\r\n    | extend concat= strcat_array(merged,\" or \")\r\n    | project p = iff(Array == 'New DCR will not work', 'New DCR will not work', strcat(\"Security!*[System[\",concat,\"]]\"))\r\n    | summarize make_set_if(p, p != 'New DCR will not work')\r\n    };\r\nConfigure(toscalar(Check))\r\n| extend set_p = iff(set_p == '[]', 'Blank', set_p)",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "id": "cb873124-8a43-40b9-8045-aaeb8f269810",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "MITREDCR3",
                                    "type": 1,
                                    "isGlobal": true,
                                    "query": "let Count = print merged=\"{mergedMitre:escapejson}\"\r\n    | extend merged=todynamic(merged)\r\n    | mvexpand merged\r\n    | summarize count()\r\n    | extend Counter = toint(count_);\r\nlet Check =\r\n    Count\r\n    | extend Check = iff(Counter <= 100, 'DCR not needed', 'DCR needed')\r\n    | extend Math = Counter - 200\r\n    | extend diff = iff(Math < 0 or Math > 100, 'New DCR will not work', array_split(todynamic(\"{mergedMitre:escapejson}\"), 200)[1])\r\n    | extend diff = todynamic(diff)\r\n    | mv-expand diff\r\n    | project toint(diff)\r\n    | top 100 by diff asc\r\n    | summarize Array = make_set(diff);\r\nlet Configure = (Array:dynamic) { print Array\r\n    | extend Array = todynamic(Array)\r\n    | mv-expand Array\r\n    | extend merged = tostring(strcat(\"(EventID=\",Array,\")\"))\r\n    | sort by tolong(merged) asc\r\n    | extend index=row_rank(merged)\r\n    | summarize merged=makeset(merged) by (index/10)\r\n    | extend concat= strcat_array(merged,\" or \")\r\n    | project p = iff(Array == 'New DCR will not work', 'New DCR will not work', strcat(\"Security!*[System[\",concat,\"]]\"))\r\n    | summarize make_set_if(p, p != 'New DCR will not work')\r\n    };\r\nConfigure(toscalar(Check))\r\n| extend set_p = iff(set_p == '[]', 'Blank', set_p)",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  }
                                ],
                                "style": "above",
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces"
                              },
                              "conditionalVisibility": {
                                "parameterName": "Logtype",
                                "comparison": "isEqualTo",
                                "value": "MITRE"
                              },
                              "name": "Merged Set - Copy"
                            },
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "crossComponentResources": [
                                  "{Workspace}"
                                ],
                                "parameters": [
                                  {
                                    "id": "211d63a4-c1c8-4d3e-8cfa-4f0930b4985a",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "msftIds",
                                    "type": 1,
                                    "query": "let msft_ids = dynamic([\r\n  {\r\n    \"Current Windows Event ID\": 4618,\r\n    \"Potential Criticality\": \"High\",\r\n    \"Event Summary\": \"A monitored security event pattern has occurred.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4649,\r\n    \"Potential Criticality\": \"High\",\r\n    \"Event Summary\": \"A replay attack was detected. May be a harmless false positive due to misconfiguration error.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4719,\r\n    \"Potential Criticality\": \"High\",\r\n    \"Event Summary\": \"System audit policy was changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4765,\r\n    \"Potential Criticality\": \"High\",\r\n    \"Event Summary\": \"SID History was added to an account.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4766,\r\n    \"Potential Criticality\": \"High\",\r\n    \"Event Summary\": \"An attempt to add SID History to an account failed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4794,\r\n    \"Potential Criticality\": \"High\",\r\n    \"Event Summary\": \"An attempt was made to set the Directory Services Restore Mode.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4897,\r\n    \"Potential Criticality\": \"High\",\r\n    \"Event Summary\": \"Role separation enabled:\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4964,\r\n    \"Potential Criticality\": \"High\",\r\n    \"Event Summary\": \"Special groups have been assigned to a new logon.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5124,\r\n    \"Potential Criticality\": \"High\",\r\n    \"Event Summary\": \"A security setting was updated on the OCSP Responder Service\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": \"N/A\",\r\n    \"Potential Criticality\": \"High\",\r\n    \"Event Summary\": \"Possible denial-of-service (DoS) attack\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 1102,\r\n    \"Potential Criticality\": \"High\",\r\n    \"Event Summary\": \"The audit log was cleared\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4621,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"Administrator recovered system from CrashOnAuditFail. Users who are not administrators will now be allowed to log on. Some auditable activity might not have been recorded.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4675,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"SIDs were filtered.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4692,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"Backup of data protection master key was attempted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4693,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"Recovery of data protection master key was attempted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4706,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"A new trust was created to a domain.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4713,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"Kerberos policy was changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4714,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"Encrypted data recovery policy was changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4715,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"The audit policy (SACL) on an object was changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4716,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"Trusted domain information was modified.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4724,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"An attempt was made to reset an account's password.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4727,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"A security-enabled global group was created.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4735,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"A security-enabled local group was changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4737,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"A security-enabled global group was changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4739,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"Domain Policy was changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4754,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"A security-enabled universal group was created.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4755,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"A security-enabled universal group was changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4764,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"A security-disabled group was deleted\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4764,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"A group's type was changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4780,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"The ACL was set on accounts which are members of administrators groups.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4816,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"RPC detected an integrity violation while decrypting an incoming message.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4865,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"A trusted forest information entry was added.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4866,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"A trusted forest information entry was removed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4867,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"A trusted forest information entry was modified.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4868,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"The certificate manager denied a pending certificate request.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4870,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"Certificate Services revoked a certificate.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4882,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"The security permissions for Certificate Services changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4885,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"The audit filter for Certificate Services changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4890,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"The certificate manager settings for Certificate Services changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4892,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"A property of Certificate Services changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4896,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"One or more rows have been deleted from the certificate database.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4906,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"The CrashOnAuditFail value has changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4907,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"Auditing settings on object were changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4908,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"Special Groups Logon table modified.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4912,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"Per User Audit Policy was changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4960,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"IPsec dropped an inbound packet that failed an integrity check. If this problem persists, it could indicate a network issue or that packets are being modified in transit to this computer. Verify that the packets sent from the remote computer are the same as those received by this computer. This error might also indicate interoperability problems with other IPsec implementations.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4961,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"IPsec dropped an inbound packet that failed a replay check. If this problem persists, it could indicate a replay attack against this computer.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4962,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"IPsec dropped an inbound packet that failed a replay check. The inbound packet had too low a sequence number to ensure it was not a replay.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4963,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"IPsec dropped an inbound clear text packet that should have been secured. This is usually due to the remote computer changing its IPsec policy without informing this computer. This could also be a spoofing attack attempt.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4965,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"IPsec received a packet from a remote computer with an incorrect Security Parameter Index (SPI). This is usually caused by malfunctioning hardware that is corrupting packets. If these errors persist, verify that the packets sent from the remote computer are the same as those received by this computer. This error may also indicate interoperability problems with other IPsec implementations. In that case, if connectivity is not impeded, then these events can be ignored.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4976,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"During Main Mode negotiation, IPsec received an invalid negotiation packet. If this problem persists, it could indicate a network issue or an attempt to modify or replay this negotiation.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4977,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"During Quick Mode negotiation, IPsec received an invalid negotiation packet. If this problem persists, it could indicate a network issue or an attempt to modify or replay this negotiation.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4978,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"During Extended Mode negotiation, IPsec received an invalid negotiation packet. If this problem persists, it could indicate a network issue or an attempt to modify or replay this negotiation.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4983,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"An IPsec Extended Mode negotiation failed. The corresponding Main Mode security association has been deleted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4984,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"An IPsec Extended Mode negotiation failed. The corresponding Main Mode security association has been deleted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5027,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"The Windows Firewall Service was unable to retrieve the security policy from the local storage. The service will continue enforcing the current policy.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5028,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"The Windows Firewall Service was unable to parse the new security policy. The service will continue with currently enforced policy.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5029,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"The Windows Firewall Service failed to initialize the driver. The service will continue to enforce the current policy.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5030,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"The Windows Firewall Service failed to start.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5035,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"The Windows Firewall Driver failed to start.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5037,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"The Windows Firewall Driver detected critical runtime error. Terminating.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5038,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5120,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"OCSP Responder Service Started\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5121,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"OCSP Responder Service Stopped\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5122,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"A configuration entry changed in OCSP Responder Service\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5123,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"A configuration entry changed in OCSP Responder Service\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5376,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"Credential Manager credentials were backed up.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5377,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"Credential Manager credentials were restored from a backup.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5453,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"An IPsec negotiation with a remote computer failed because the IKE and AuthIP IPsec Keying Modules (IKEEXT) service is not started.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5480,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"IPsec Services failed to get the complete list of network interfaces on the computer. This poses a potential security risk because some of the network interfaces may not get the protection provided by the applied IPsec filters. Use the IP Security Monitor snap-in to diagnose the problem.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5483,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"IPsec Services failed to initialize RPC server. IPsec Services could not be started.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5484,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"IPsec Services has experienced a critical failure and has been shut down. The shutdown of IPsec Services can put the computer at greater risk of network attack or expose the computer to potential security risks.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5485,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"IPsec Services failed to process some IPsec filters on a plug-and-play event for network interfaces. This poses a potential security risk because some of the network interfaces may not get the protection provided by the applied IPsec filters. Use the IP Security Monitor snap-in to diagnose the problem.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5827,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"The Netlogon service denied a vulnerable Netlogon secure channel connection from a machine account.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5828,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"The Netlogon service denied a vulnerable Netlogon secure channel connection using a trust account.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 6145,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"One or more errors occurred while processing security policy in the Group Policy objects.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 6273,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"Network Policy Server denied access to a user.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 6274,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"Network Policy Server discarded the request for a user.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 6275,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"Network Policy Server discarded the accounting request for a user.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 6276,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"Network Policy Server quarantined a user.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 6277,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 6278,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"Network Policy Server granted full access to a user because the host met the defined health policy.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 6279,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"Network Policy Server locked the user account due to repeated failed authentication attempts.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 6280,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"Network Policy Server unlocked the user account.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": \"-\",\r\n    \"Legacy Windows Event ID\": 640,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"General account database changed\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": \"-\",\r\n    \"Legacy Windows Event ID\": 619,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"Quality of Service Policy changed\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 24586,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"An error was encountered converting volume\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 24592,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"An attempt to automatically restart conversion on volume %2 failed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 24593,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"Metadata write: Volume %2 returning errors while trying to modify metadata. If failures continue, decrypt volume\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 24594,\r\n    \"Potential Criticality\": \"Medium\",\r\n    \"Event Summary\": \"Metadata rebuild: An attempt to write a copy of metadata on volume %2 failed and may appear as disk corruption. If failures continue, decrypt volume.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4608,\r\n    \"Legacy Windows Event ID\": 512,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Windows is starting up.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4609,\r\n    \"Legacy Windows Event ID\": 513,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Windows is shutting down.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4610,\r\n    \"Legacy Windows Event ID\": 514,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An authentication package has been loaded by the Local Security Authority.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4611,\r\n    \"Legacy Windows Event ID\": 515,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A trusted logon process has been registered with the Local Security Authority.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4612,\r\n    \"Legacy Windows Event ID\": 516,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4614,\r\n    \"Legacy Windows Event ID\": 518,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A notification package has been loaded by the Security Account Manager.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4615,\r\n    \"Legacy Windows Event ID\": 519,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Invalid use of LPC port.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4616,\r\n    \"Legacy Windows Event ID\": 520,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The system time was changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4622,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A security package has been loaded by the Local Security Authority.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4624,\r\n    \"Legacy Windows Event ID\": \"528,540\",\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An account was successfully logged on.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4625,\r\n    \"Legacy Windows Event ID\": \"529-537,539\",\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An account failed to log on.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4634,\r\n    \"Legacy Windows Event ID\": 538,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An account was logged off.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4646,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"IKE DoS-prevention mode started.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4647,\r\n    \"Legacy Windows Event ID\": 551,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"User initiated logoff.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4648,\r\n    \"Legacy Windows Event ID\": 552,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A logon was attempted using explicit credentials.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4650,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An IPsec Main Mode security association was established. Extended Mode was not enabled. Certificate authentication was not used.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4651,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An IPsec Main Mode security association was established. Extended Mode was not enabled. A certificate was used for authentication.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4652,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An IPsec Main Mode negotiation failed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4653,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An IPsec Main Mode negotiation failed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4654,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An IPsec Quick Mode negotiation failed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4655,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An IPsec Main Mode security association ended.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4656,\r\n    \"Legacy Windows Event ID\": 560,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A handle to an object was requested.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4657,\r\n    \"Legacy Windows Event ID\": 567,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A registry value was modified.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4658,\r\n    \"Legacy Windows Event ID\": 562,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The handle to an object was closed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4659,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A handle to an object was requested with intent to delete.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4660,\r\n    \"Legacy Windows Event ID\": 564,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An object was deleted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4661,\r\n    \"Legacy Windows Event ID\": 565,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A handle to an object was requested.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4662,\r\n    \"Legacy Windows Event ID\": 566,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An operation was performed on an object.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4663,\r\n    \"Legacy Windows Event ID\": 567,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An attempt was made to access an object.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4664,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An attempt was made to create a hard link.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4665,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An attempt was made to create an application client context.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4666,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An application attempted an operation:\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4667,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An application client context was deleted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4668,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An application was initialized.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4670,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Permissions on an object were changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4671,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An application attempted to access a blocked ordinal through the TBS.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4672,\r\n    \"Legacy Windows Event ID\": 576,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Special privileges assigned to new logon.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4673,\r\n    \"Legacy Windows Event ID\": 577,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A privileged service was called.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4674,\r\n    \"Legacy Windows Event ID\": 578,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An operation was attempted on a privileged object.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4688,\r\n    \"Legacy Windows Event ID\": 592,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A new process has been created.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4689,\r\n    \"Legacy Windows Event ID\": 593,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A process has exited.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4690,\r\n    \"Legacy Windows Event ID\": 594,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An attempt was made to duplicate a handle to an object.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4691,\r\n    \"Legacy Windows Event ID\": 595,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Indirect access to an object was requested.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4694,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Protection of auditable protected data was attempted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4695,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Unprotection of auditable protected data was attempted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4696,\r\n    \"Legacy Windows Event ID\": 600,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A primary token was assigned to process.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4697,\r\n    \"Legacy Windows Event ID\": 601,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Attempt to install a service\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4698,\r\n    \"Legacy Windows Event ID\": 602,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A scheduled task was created.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4699,\r\n    \"Legacy Windows Event ID\": 602,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A scheduled task was deleted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4700,\r\n    \"Legacy Windows Event ID\": 602,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A scheduled task was enabled.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4701,\r\n    \"Legacy Windows Event ID\": 602,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A scheduled task was disabled.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4702,\r\n    \"Legacy Windows Event ID\": 602,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A scheduled task was updated.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4704,\r\n    \"Legacy Windows Event ID\": 608,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A user right was assigned.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4705,\r\n    \"Legacy Windows Event ID\": 609,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A user right was removed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4707,\r\n    \"Legacy Windows Event ID\": 611,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A trust to a domain was removed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4709,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"IPsec Services was started.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4710,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"IPsec Services was disabled.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4711,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"May contain any one of the following: PAStore Engine applied locally cached copy of Active Directory storage IPsec policy on the computer. PAStore Engine applied Active Directory storage IPsec policy on the computer. PAStore Engine applied local registry storage IPsec policy on the computer. PAStore Engine failed to apply locally cached copy of Active Directory storage IPsec policy on the computer. PAStore Engine failed to apply Active Directory storage IPsec policy on the computer. PAStore Engine failed to apply local registry storage IPsec policy on the computer. PAStore Engine failed to apply some rules of the active IPsec policy on the computer. PAStore Engine failed to load directory storage IPsec policy on the computer. PAStore Engine loaded directory storage IPsec policy on the computer. PAStore Engine failed to load local storage IPsec policy on the computer. PAStore Engine loaded local storage IPsec policy on the computer.PAStore Engine polled for changes to the active IPsec policy and detected no changes.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4712,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"IPsec Services encountered a potentially serious failure.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4717,\r\n    \"Legacy Windows Event ID\": 621,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"System security access was granted to an account.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4718,\r\n    \"Legacy Windows Event ID\": 622,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"System security access was removed from an account.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4720,\r\n    \"Legacy Windows Event ID\": 624,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A user account was created.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4722,\r\n    \"Legacy Windows Event ID\": 626,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A user account was enabled.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4723,\r\n    \"Legacy Windows Event ID\": 627,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An attempt was made to change an account's password.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4725,\r\n    \"Legacy Windows Event ID\": 629,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A user account was disabled.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4726,\r\n    \"Legacy Windows Event ID\": 630,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A user account was deleted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4728,\r\n    \"Legacy Windows Event ID\": 632,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A member was added to a security-enabled global group.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4729,\r\n    \"Legacy Windows Event ID\": 633,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A member was removed from a security-enabled global group.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4730,\r\n    \"Legacy Windows Event ID\": 634,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A security-enabled global group was deleted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4731,\r\n    \"Legacy Windows Event ID\": 635,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A security-enabled local group was created.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4732,\r\n    \"Legacy Windows Event ID\": 636,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A member was added to a security-enabled local group.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4733,\r\n    \"Legacy Windows Event ID\": 637,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A member was removed from a security-enabled local group.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4734,\r\n    \"Legacy Windows Event ID\": 638,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A security-enabled local group was deleted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4738,\r\n    \"Legacy Windows Event ID\": 642,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A user account was changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4740,\r\n    \"Legacy Windows Event ID\": 644,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A user account was locked out.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4741,\r\n    \"Legacy Windows Event ID\": 645,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A computer account was changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4742,\r\n    \"Legacy Windows Event ID\": 646,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A computer account was changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4743,\r\n    \"Legacy Windows Event ID\": 647,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A computer account was deleted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4744,\r\n    \"Legacy Windows Event ID\": 648,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A security-disabled local group was created.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4745,\r\n    \"Legacy Windows Event ID\": 649,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A security-disabled local group was changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4746,\r\n    \"Legacy Windows Event ID\": 650,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A member was added to a security-disabled local group.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4747,\r\n    \"Legacy Windows Event ID\": 651,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A member was removed from a security-disabled local group.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4748,\r\n    \"Legacy Windows Event ID\": 652,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A security-disabled local group was deleted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4749,\r\n    \"Legacy Windows Event ID\": 653,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A security-disabled global group was created.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4750,\r\n    \"Legacy Windows Event ID\": 654,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A security-disabled global group was changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4751,\r\n    \"Legacy Windows Event ID\": 655,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A member was added to a security-disabled global group.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4752,\r\n    \"Legacy Windows Event ID\": 656,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A member was removed from a security-disabled global group.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4753,\r\n    \"Legacy Windows Event ID\": 657,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A security-disabled global group was deleted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4756,\r\n    \"Legacy Windows Event ID\": 660,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A member was added to a security-enabled universal group.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4757,\r\n    \"Legacy Windows Event ID\": 661,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A member was removed from a security-enabled universal group.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4758,\r\n    \"Legacy Windows Event ID\": 662,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A security-enabled universal group was deleted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4759,\r\n    \"Legacy Windows Event ID\": 663,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A security-disabled universal group was created.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4760,\r\n    \"Legacy Windows Event ID\": 664,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A security-disabled universal group was changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4761,\r\n    \"Legacy Windows Event ID\": 665,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A member was added to a security-disabled universal group.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4762,\r\n    \"Legacy Windows Event ID\": 666,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A member was removed from a security-disabled universal group.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4767,\r\n    \"Legacy Windows Event ID\": 671,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A user account was unlocked.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4768,\r\n    \"Legacy Windows Event ID\": \"672,676\",\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A Kerberos authentication ticket (TGT) was requested.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4769,\r\n    \"Legacy Windows Event ID\": 673,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A Kerberos service ticket was requested.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4770,\r\n    \"Legacy Windows Event ID\": 674,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A Kerberos service ticket was renewed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4771,\r\n    \"Legacy Windows Event ID\": 675,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Kerberos pre-authentication failed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4772,\r\n    \"Legacy Windows Event ID\": 672,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A Kerberos authentication ticket request failed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4774,\r\n    \"Legacy Windows Event ID\": 678,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An account was mapped for logon.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4775,\r\n    \"Legacy Windows Event ID\": 679,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An account could not be mapped for logon.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4776,\r\n    \"Legacy Windows Event ID\": \"680,681\",\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The domain controller attempted to validate the credentials for an account.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4777,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The domain controller failed to validate the credentials for an account.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4778,\r\n    \"Legacy Windows Event ID\": 682,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A session was reconnected to a Window Station.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4779,\r\n    \"Legacy Windows Event ID\": 683,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A session was disconnected from a Window Station.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4781,\r\n    \"Legacy Windows Event ID\": 685,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The name of an account was changed:\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4782,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The password hash an account was accessed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4783,\r\n    \"Legacy Windows Event ID\": 667,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A basic application group was created.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4784,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A basic application group was changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4785,\r\n    \"Legacy Windows Event ID\": 689,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A member was added to a basic application group.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4786,\r\n    \"Legacy Windows Event ID\": 690,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A member was removed from a basic application group.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4787,\r\n    \"Legacy Windows Event ID\": 691,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A nonmember was added to a basic application group.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4788,\r\n    \"Legacy Windows Event ID\": 692,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A nonmember was removed from a basic application group.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4789,\r\n    \"Legacy Windows Event ID\": 693,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A basic application group was deleted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4790,\r\n    \"Legacy Windows Event ID\": 694,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An LDAP query group was created.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4793,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The Password Policy Checking API was called.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4800,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The workstation was locked.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4801,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The workstation was unlocked.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4802,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The screen saver was invoked.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4803,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The screen saver was dismissed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4864,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A namespace collision was detected.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4869,\r\n    \"Legacy Windows Event ID\": 773,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Certificate Services received a resubmitted certificate request.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4871,\r\n    \"Legacy Windows Event ID\": 775,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Certificate Services received a request to publish the certificate revocation list (CRL).\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4872,\r\n    \"Legacy Windows Event ID\": 776,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Certificate Services published the certificate revocation list (CRL).\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4873,\r\n    \"Legacy Windows Event ID\": 777,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A certificate request extension changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4874,\r\n    \"Legacy Windows Event ID\": 778,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"One or more certificate request attributes changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4875,\r\n    \"Legacy Windows Event ID\": 779,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Certificate Services received a request to shut down.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4876,\r\n    \"Legacy Windows Event ID\": 780,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Certificate Services backup started.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4877,\r\n    \"Legacy Windows Event ID\": 781,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Certificate Services backup completed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4878,\r\n    \"Legacy Windows Event ID\": 782,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Certificate Services restore started.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4879,\r\n    \"Legacy Windows Event ID\": 783,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Certificate Services restore completed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4880,\r\n    \"Legacy Windows Event ID\": 784,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Certificate Services started.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4881,\r\n    \"Legacy Windows Event ID\": 785,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Certificate Services stopped.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4883,\r\n    \"Legacy Windows Event ID\": 787,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Certificate Services retrieved an archived key.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4884,\r\n    \"Legacy Windows Event ID\": 788,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Certificate Services imported a certificate into its database.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4886,\r\n    \"Legacy Windows Event ID\": 790,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Certificate Services received a certificate request.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4887,\r\n    \"Legacy Windows Event ID\": 791,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Certificate Services approved a certificate request and issued a certificate.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4888,\r\n    \"Legacy Windows Event ID\": 792,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Certificate Services denied a certificate request.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4889,\r\n    \"Legacy Windows Event ID\": 793,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Certificate Services set the status of a certificate request to pending.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4891,\r\n    \"Legacy Windows Event ID\": 795,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A configuration entry changed in Certificate Services.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4893,\r\n    \"Legacy Windows Event ID\": 797,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Certificate Services archived a key.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4894,\r\n    \"Legacy Windows Event ID\": 798,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Certificate Services imported and archived a key.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4895,\r\n    \"Legacy Windows Event ID\": 799,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Certificate Services published the CA certificate to Active Directory Domain Services.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4898,\r\n    \"Legacy Windows Event ID\": 802,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Certificate Services loaded a template.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4902,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The Per-user audit policy table was created.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4904,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An attempt was made to register a security event source.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4905,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An attempt was made to unregister a security event source.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4909,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The local policy settings for the TBS were changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4910,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The Group Policy settings for the TBS were changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4928,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An Active Directory replica source naming context was established.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4929,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An Active Directory replica source naming context was removed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4930,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An Active Directory replica source naming context was modified.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4931,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An Active Directory replica destination naming context was modified.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4932,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Synchronization of a replica of an Active Directory naming context has begun.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4933,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Synchronization of a replica of an Active Directory naming context has ended.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4934,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Attributes of an Active Directory object were replicated.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4935,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Replication failure begins.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4936,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Replication failure ends.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4937,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A lingering object was removed from a replica.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4944,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The following policy was active when the Windows Firewall started.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4945,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A rule was listed when the Windows Firewall started.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4946,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A change has been made to Windows Firewall exception list. A rule was added.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4947,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A change has been made to Windows Firewall exception list. A rule was modified.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4948,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A change has been made to Windows Firewall exception list. A rule was deleted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4949,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Windows Firewall settings were restored to the default values.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4950,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A Windows Firewall setting has changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4951,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A rule has been ignored because its major version number was not recognized by Windows Firewall.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4952,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Parts of a rule have been ignored because its minor version number was not recognized by Windows Firewall. The other parts of the rule will be enforced.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4953,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A rule has been ignored by Windows Firewall because it could not parse the rule.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4954,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Windows Firewall Group Policy settings have changed. The new settings have been applied.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4956,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Windows Firewall has changed the active profile.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4957,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Windows Firewall did not apply the following rule:\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4958,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Windows Firewall did not apply the following rule because the rule referred to items not configured on this computer:\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4979,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"IPsec Main Mode and Extended Mode security associations were established.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4980,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"IPsec Main Mode and Extended Mode security associations were established.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4981,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"IPsec Main Mode and Extended Mode security associations were established.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4982,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"IPsec Main Mode and Extended Mode security associations were established.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 4985,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The state of a transaction has changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5024,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The Windows Firewall Service has started successfully.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5025,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The Windows Firewall Service has been stopped.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5031,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The Windows Firewall Service blocked an application from accepting incoming connections on the network.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5032,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5033,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The Windows Firewall Driver has started successfully.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5034,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The Windows Firewall Driver has been stopped.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5039,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A registry key was virtualized.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5040,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A change has been made to IPsec settings. An Authentication Set was added.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5041,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A change has been made to IPsec settings. An Authentication Set was modified.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5042,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A change has been made to IPsec settings. An Authentication Set was deleted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5043,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A change has been made to IPsec settings. A Connection Security Rule was added.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5044,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A change has been made to IPsec settings. A Connection Security Rule was modified.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5045,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A change has been made to IPsec settings. A Connection Security Rule was deleted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5046,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A change has been made to IPsec settings. A Crypto Set was added.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5047,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A change has been made to IPsec settings. A Crypto Set was modified.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5048,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A change has been made to IPsec settings. A Crypto Set was deleted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5050,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An attempt to programmatically disable the Windows Firewall using a call to InetFwProfile.FirewallEnabled(False)\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5051,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A file was virtualized.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5056,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A cryptographic self test was performed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5057,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A cryptographic primitive operation failed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5058,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Key file operation.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5059,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Key migration operation.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5060,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Verification operation failed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5061,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Cryptographic operation.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5062,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A kernel-mode cryptographic self test was performed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5063,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A cryptographic provider operation was attempted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5064,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A cryptographic context operation was attempted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5065,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A cryptographic context modification was attempted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5066,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A cryptographic function operation was attempted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5067,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A cryptographic function modification was attempted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5068,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A cryptographic function provider operation was attempted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5069,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A cryptographic function property operation was attempted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5070,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A cryptographic function property modification was attempted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5125,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A request was submitted to the OCSP Responder Service\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5126,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Signing Certificate was automatically updated by the OCSP Responder Service\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5127,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The OCSP Revocation Provider successfully updated the revocation information\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5136,\r\n    \"Legacy Windows Event ID\": 566,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A directory service object was modified.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5137,\r\n    \"Legacy Windows Event ID\": 566,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A directory service object was created.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5138,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A directory service object was undeleted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5139,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A directory service object was moved.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5140,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A network share object was accessed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5141,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A directory service object was deleted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5152,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The Windows Filtering Platform blocked a packet.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5153,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A more restrictive Windows Filtering Platform filter has blocked a packet.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5154,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5155,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5156,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The Windows Filtering Platform has allowed a connection.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5157,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The Windows Filtering Platform has blocked a connection.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5158,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The Windows Filtering Platform has permitted a bind to a local port.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5159,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The Windows Filtering Platform has blocked a bind to a local port.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5378,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The requested credentials delegation was disallowed by policy.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5440,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The following callout was present when the Windows Filtering Platform Base Filtering Engine started.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5441,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The following filter was present when the Windows Filtering Platform Base Filtering Engine started.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5442,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The following provider was present when the Windows Filtering Platform Base Filtering Engine started.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5443,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The following provider context was present when the Windows Filtering Platform Base Filtering Engine started.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5444,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The following sublayer was present when the Windows Filtering Platform Base Filtering Engine started.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5446,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A Windows Filtering Platform callout has been changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5447,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A Windows Filtering Platform filter has been changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5448,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A Windows Filtering Platform provider has been changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5449,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A Windows Filtering Platform provider context has been changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5450,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A Windows Filtering Platform sublayer has been changed.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5451,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An IPsec Quick Mode security association was established.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5452,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An IPsec Quick Mode security association ended.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5456,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"PAStore Engine applied Active Directory storage IPsec policy on the computer.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5457,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"PAStore Engine failed to apply Active Directory storage IPsec policy on the computer.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5458,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"PAStore Engine applied locally cached copy of Active Directory storage IPsec policy on the computer.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5459,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"PAStore Engine failed to apply locally cached copy of Active Directory storage IPsec policy on the computer.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5460,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"PAStore Engine applied local registry storage IPsec policy on the computer.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5461,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"PAStore Engine failed to apply local registry storage IPsec policy on the computer.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5462,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"PAStore Engine failed to apply some rules of the active IPsec policy on the computer. Use the IP Security Monitor snap-in to diagnose the problem.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5463,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"PAStore Engine polled for changes to the active IPsec policy and detected no changes.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5464,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"PAStore Engine polled for changes to the active IPsec policy, detected changes, and applied them to IPsec Services.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5465,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"PAStore Engine received a control for forced reloading of IPsec policy and processed the control successfully.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5466,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory cannot be reached, and will use the cached copy of the Active Directory IPsec policy instead. Any changes made to the Active Directory IPsec policy since the last poll could not be applied.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5467,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, and found no changes to the policy. The cached copy of the Active Directory IPsec policy is no longer being used.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5468,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, found changes to the policy, and applied those changes. The cached copy of the Active Directory IPsec policy is no longer being used.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5471,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"PAStore Engine loaded local storage IPsec policy on the computer.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5472,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"PAStore Engine failed to load local storage IPsec policy on the computer.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5473,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"PAStore Engine loaded directory storage IPsec policy on the computer.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5474,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"PAStore Engine failed to load directory storage IPsec policy on the computer.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5477,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"PAStore Engine failed to add quick mode filter.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5479,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"IPsec Services has been shut down successfully. The shutdown of IPsec Services can put the computer at greater risk of network attack or expose the computer to potential security risks.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5632,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A request was made to authenticate to a wireless network.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5633,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A request was made to authenticate to a wired network.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5712,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A Remote Procedure Call (RPC) was attempted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5888,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An object in the COM+ Catalog was modified.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5889,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An object was deleted from the COM+ Catalog.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5890,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An object was added to the COM+ Catalog.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 6008,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The previous system shutdown was unexpected\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 6144,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Security policy in the Group Policy objects has been applied successfully.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 6272,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Network Policy Server granted access to a user.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": \"N/A\",\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"A handle to an object was requested.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": \"N/A\",\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Object open for delete\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": \"N/A\",\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"User Account Type Changed\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": \"N/A\",\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"IPsec policy agent started\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": \"N/A\",\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"IPsec policy agent disabled\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": \"N/A\",\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"IPsec policy agent\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": \"N/A\",\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"IPsec policy agent encountered a potential serious failure\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 24577,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Encryption of volume started\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 24578,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Encryption of volume stopped\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 24579,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Encryption of volume completed\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 24580,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Decryption of volume started\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 24581,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Decryption of volume stopped\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 24582,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Decryption of volume completed\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 24583,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Conversion worker thread for volume started\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 24584,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Conversion worker thread for volume temporarily stopped\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 24588,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"The conversion operation on volume %2 encountered a bad sector error. Please validate the data on this volume\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 24595,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Volume %2 contains bad clusters. These clusters will be skipped during conversion.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 24621,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"Initial state check: Rolling volume conversion transaction on %2.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5049,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"An IPsec Security Association was deleted.\"\r\n  },\r\n  {\r\n    \"Current Windows Event ID\": 5478,\r\n    \"Potential Criticality\": \"Low\",\r\n    \"Event Summary\": \"IPsec Services has started successfully.\"\r\n  }\r\n]);\r\nprint msft_ids\r\n| mv-expand print_0\r\n| project EventID = tostring(print_0.[\"Current Windows Event ID\"]), Criticality = tostring(print_0.[\"Potential Criticality\"]), Description = tostring(print_0.[\"Event Summary\"])\r\n| where Criticality in~ ({Criticality})\r\n| distinct toint(EventID)\r\n| where isnotempty(EventID)\r\n| order by EventID asc\r\n",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "id": "96c914b3-4eea-468e-b654-d8dba78e2cc5",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "ManualEventsMsft",
                                    "type": 9,
                                    "multiSelect": true,
                                    "quote": "'",
                                    "delimiter": ",",
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "label": "Manual Events"
                                  },
                                  {
                                    "version": "KqlParameterItem/1.0",
                                    "name": "MSFTExclude",
                                    "label": "Excluded Events",
                                    "type": 9,
                                    "multiSelect": true,
                                    "quote": "'",
                                    "delimiter": ",",
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "id": "b29cf62b-85a1-4d63-8269-bfb0769db5b7"
                                  },
                                  {
                                    "id": "2a94f1ff-9242-4de9-877c-6d35def28c3b",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "parseManualMsft",
                                    "type": 1,
                                    "query": "let manualIds = \"{ManualEventsMsft}\";\r\nprint ids=manualIds\r\n| project ids = todynamic(strcat('[', replace_regex(ids,\"\\'\",\"\"),']'))\r\n| mv-expand ids\r\n| project ids = toint(ids)",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "version": "KqlParameterItem/1.0",
                                    "name": "parseExcludeMsft",
                                    "type": 1,
                                    "query": "let manualIds = \"{MSFTExclude}\";\r\nprint ids=manualIds\r\n| project ids = todynamic(strcat('[', replace_regex(ids,\"\\'\",\"\"),']'))\r\n| mv-expand ids\r\n| project ids = toint(ids)",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces",
                                    "id": "3489b21c-3ac6-4586-9c86-05ed80fc5a82"
                                  },
                                  {
                                    "id": "b0b836f3-feb2-4455-858c-b7e4c6734b90",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "mergedMsft",
                                    "type": 1,
                                    "query": "let manual_ids = () {\r\n    print ids=todynamic(\"{parseManualMsft}\")\r\n    | mvexpand ids\r\n    | project ids = toint(ids)\r\n};\r\nlet exclude_ids = () {\r\n    print ids=todynamic(\"{parseExcludeMsft}\")\r\n    | mvexpand ids\r\n    | project ids = toint(ids)\r\n};\r\nlet tierIds = () {\r\n    print ids = todynamic(\"{IngestArray}\")\r\n    | mvexpand ids\r\n    | project ids = toint(ids)\r\n};\r\nlet msftIds = () {\r\n    print  ids=todynamic('{msftIds}')\r\n    | mv-expand ids\r\n    | project ids = toint(ids)\r\n};\r\nunion manual_ids, tierIds, msftIds\r\n| where ids !in (exclude_ids)\r\n| where isnotempty(ids)\r\n| summarize by ids\r\n| sort by ids asc",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "id": "4813de88-4b1d-4dd2-9e0d-430d2976320e",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "generatedJSONMsft",
                                    "type": 1,
                                    "query": "// Referenced merged array\r\nlet generated = () {\r\n    print merged=\"{mergedMsft:escapejson}\"\r\n    | extend merged=todynamic(merged)\r\n    | mvexpand merged\r\n    | top 100 by toint(merged) asc\r\n    | extend merged = tostring(strcat(\"(EventID=\",merged,\")\"))\r\n    | sort by tolong(merged) asc\r\n    | extend index=row_rank(merged)\r\n    | summarize merged=makeset(merged) by (index/10)\r\n    | extend concat= strcat_array(merged,\" or \")\r\n    | project p = strcat(\"Security!*[System[\",concat,\"]]\")\r\n    | summarize makeset(p)\r\n};\r\ngenerated",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "id": "6a16dcf7-bb09-4e6c-ba68-5e8b510e02e9",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "MSFTDCR2",
                                    "type": 1,
                                    "query": "let Count = print merged=\"{mergedMsft:escapejson}\"\r\n    | extend merged=todynamic(merged)\r\n    | mvexpand merged\r\n    | summarize count()\r\n    | extend Counter = toint(count_);\r\nlet Check =\r\n    Count\r\n    | extend Check = iff(Counter <= 100, 'DCR not needed', 'DCR needed')\r\n    | extend Math = Counter - 100\r\n    | extend diff = iff(Math < 0 or Math > 100, 'New DCR will not work', array_split(todynamic(\"{mergedMsft:escapejson}\"), 100)[1])\r\n    | extend diff = todynamic(diff)\r\n    | mv-expand diff\r\n    | project toint(diff)\r\n    | top 100 by diff asc\r\n    | summarize Array = make_set(diff);\r\nlet Configure = (Array:dynamic) { print Array\r\n    | extend Array = todynamic(Array)\r\n    | mv-expand Array\r\n    | extend merged = tostring(strcat(\"(EventID=\",Array,\")\"))\r\n    | sort by tolong(merged) asc\r\n    | extend index=row_rank(merged)\r\n    | summarize merged=makeset(merged) by (index/10)\r\n    | extend concat= strcat_array(merged,\" or \")\r\n    | project p = iff(Array == 'New DCR will not work', 'New DCR will not work', strcat(\"Security!*[System[\",concat,\"]]\"))\r\n    | summarize make_set_if(p, p != 'New DCR will not work')\r\n    };\r\nConfigure(toscalar(Check))\r\n| extend set_p = iff(set_p == '[]', 'Blank', set_p)",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "id": "c9103ea3-3908-4f4b-8303-1ba558a073f0",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "MSFTDCR3",
                                    "type": 1,
                                    "query": "let Count = print merged=\"{mergedMsft:escapejson}\"\r\n    | extend merged=todynamic(merged)\r\n    | mvexpand merged\r\n    | summarize count()\r\n    | extend Counter = toint(count_);\r\nlet Check =\r\n    Count\r\n    | extend Check = iff(Counter <= 100, 'DCR not needed', 'DCR needed')\r\n    | extend Math = Counter - 100\r\n    | extend diff = iff(Math < 0 or Math > 100, 'New DCR will not work', array_split(todynamic(\"{mergedMsft:escapejson}\"), 200)[1])\r\n    | extend diff = todynamic(diff)\r\n    | mv-expand diff\r\n    | project toint(diff)\r\n    | top 100 by diff asc\r\n    | summarize Array = make_set(diff);\r\nlet Configure = (Array:dynamic) { print Array\r\n    | extend Array = todynamic(Array)\r\n    | mv-expand Array\r\n    | extend merged = tostring(strcat(\"(EventID=\",Array,\")\"))\r\n    | sort by tolong(merged) asc\r\n    | extend index=row_rank(merged)\r\n    | summarize merged=makeset(merged) by (index/10)\r\n    | extend concat= strcat_array(merged,\" or \")\r\n    | project p = iff(Array == 'New DCR will not work', 'New DCR will not work', strcat(\"Security!*[System[\",concat,\"]]\"))\r\n    | summarize make_set_if(p, p != 'New DCR will not work')\r\n    };\r\nConfigure(toscalar(Check))\r\n| extend set_p = iff(set_p == '[]', 'Blank', set_p)",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "id": "22ec2adc-7c70-4be4-883b-429d115bd2ed",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "MSFTDCR4",
                                    "type": 1,
                                    "query": "let Count = print merged=\"{mergedMsft:escapejson}\"\r\n    | extend merged=todynamic(merged)\r\n    | mvexpand merged\r\n    | summarize count()\r\n    | extend Counter = toint(count_);\r\nlet Check =\r\n    Count\r\n    | extend Check = iff(Counter <= 100, 'DCR not needed', 'DCR needed')\r\n    | extend Math = Counter - 100\r\n    | extend diff = iff(Math < 0 or Math > 100, 'New DCR will not work', array_split(todynamic(\"{mergedMsft:escapejson}\"), 300)[1])\r\n    | extend diff = todynamic(diff)\r\n    | mv-expand diff\r\n    | project toint(diff)\r\n    | top 100 by diff asc\r\n    | summarize Array = make_set(diff);\r\nlet Configure = (Array:dynamic) { print Array\r\n    | extend Array = todynamic(Array)\r\n    | mv-expand Array\r\n    | extend merged = tostring(strcat(\"(EventID=\",Array,\")\"))\r\n    | sort by tolong(merged) asc\r\n    | extend index=row_rank(merged)\r\n    | summarize merged=makeset(merged) by (index/10)\r\n    | extend concat= strcat_array(merged,\" or \")\r\n    | project p = iff(Array == 'New DCR will not work', 'New DCR will not work', strcat(\"Security!*[System[\",concat,\"]]\"))\r\n    | summarize make_set_if(p, p != 'New DCR will not work')\r\n    };\r\nConfigure(toscalar(Check))\r\n| extend set_p = iff(set_p == '[]', 'Blank', set_p)",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  }
                                ],
                                "style": "above",
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces"
                              },
                              "conditionalVisibility": {
                                "parameterName": "Logtype",
                                "comparison": "isEqualTo",
                                "value": "WE"
                              },
                              "name": "Merged Set - Copy - Copy"
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "### Help\r\n\r\nThis section will list the current configured events that will have xPath generated. The events listed are the events that will be configured within the DCR when it is deployed. They are determined based on the input selected above. </br>\r\n\r\nDCR's have a limit of 100 objects within its configuration. If 100 is exceeded, additional DCR's will need to be created in order to compensate for the remaining event IDs. If 100 is exceeded, this section will highlight such and extra xPath will be generated for the remaining event IDs. If 2 DCR's are not enough, a third will be made. Each new DCR will have a button at the bottom of the screen when ready.",
                                "style": "info"
                              },
                              "conditionalVisibility": {
                                "parameterName": "Help",
                                "comparison": "isEqualTo",
                                "value": "Yes"
                              },
                              "name": "Events"
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "### Manually Entered IDs: \r\nEventIDs: {parseManual} </br>\r\n\r\n### Excluded IDs:\r\nEventIDs: {parseExclude} </br>\r\n\r\n### Full List of Manual and NSA IDs: \r\nEventIDs: {merged}</br>\r\n\r\n\r\n"
                              },
                              "conditionalVisibilities": [
                                {
                                  "parameterName": "Datatype",
                                  "comparison": "isEqualTo",
                                  "value": "Windows"
                                },
                                {
                                  "parameterName": "Logtype",
                                  "comparison": "isEqualTo",
                                  "value": "NSA"
                                }
                              ],
                              "name": "NSA"
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "### Manually Entered IDs:\r\nEventIDs: {parseManualMitre} </br>\r\n\r\n### Excluded IDs:\r\nEventIDs: {parseExcludeMitre} </br>\r\n\r\n### Full List of Manual and MITRE IDs:\r\nEventIDs: {mergedMitre} <br>\r\n"
                              },
                              "conditionalVisibilities": [
                                {
                                  "parameterName": "Datatype",
                                  "comparison": "isEqualTo",
                                  "value": "Windows"
                                },
                                {
                                  "parameterName": "Logtype",
                                  "comparison": "isEqualTo",
                                  "value": "MITRE"
                                }
                              ],
                              "name": "MITRE"
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "### Manually Entered IDs:\r\nEventIDs: {parseManualMsft} </br>\r\n\r\n### Excluded IDs:\r\nEventIDs: {parseExcludeMsft} </br>\r\n\r\n### Full List of Manual and Recommended IDs:\r\nEventIDs: {mergedMsft} <br>\r\n\r\n"
                              },
                              "conditionalVisibilities": [
                                {
                                  "parameterName": "Datatype",
                                  "comparison": "isEqualTo",
                                  "value": "Windows"
                                },
                                {
                                  "parameterName": "Logtype",
                                  "comparison": "isEqualTo",
                                  "value": "WE"
                                }
                              ],
                              "name": "Recomm"
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "let IDCount = '{merged}';\r\nprint IDCount\r\n| mv-expand Test = todynamic(print_0)\r\n| summarize count() by print_0\r\n| extend count_ = case(count_ >= 100 and count_ <= 200, strcat('DCR count limit reached. Consider spltting the array into one DCR with 100 events and one with ', tostring((count_-100)), ' events.'),\r\n                    count_ >= 200 and count_ <=300, strcat('DCR count limit reached. Consider filtering the log criticality or spltting the array into two DCRs with 100 events and one with ', tostring((count_-200)), ' events.'),\r\n                    count_ >= 300 and count_ <=400, strcat('DCR count limit reached. Consider filtering the log criticality or spltting the array into three DCRs with 100 events and one with ', tostring((count_-300)), ' events.'),\r\n                    tostring(count_))\r\n| project-away print_0",
                                "size": 4,
                                "title": "Number of Distinct IDs Selected for NSA DCR",
                                "timeContext": {
                                  "durationMs": 86400000
                                },
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "crossComponentResources": [
                                  "{Workspace}"
                                ],
                                "visualization": "card",
                                "tileSettings": {
                                  "titleContent": {},
                                  "leftContent": {
                                    "columnMatch": "Count"
                                  },
                                  "showBorder": false
                                },
                                "textSettings": {
                                  "style": "bignumber"
                                }
                              },
                              "customWidth": "33",
                              "conditionalVisibility": {
                                "parameterName": "Logtype",
                                "comparison": "isEqualTo",
                                "value": "NSA"
                              },
                              "name": "Count - NSA"
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "let IDCount = '{mergedMitre}';\r\nprint IDCount\r\n| mv-expand Test = todynamic(print_0)\r\n| summarize count() by print_0\r\n| project-away print_0\r\n| extend count_ =  case(count_ >= 100 and count_ <= 200, strcat('DCR count limit reached. Consider spltting the array into one DCR with 100 events and one with ', tostring((count_-100)), ' events.'),\r\n                    count_ >= 200 and count_ <=300, strcat('DCR count limit reached. Consider filtering the log criticality or spltting the array into two DCRs with 100 events and one with ', tostring((count_-200)), ' events.'),\r\n                    count_ >= 300 and count_ <=400, strcat('DCR count limit reached. Consider filtering the log criticality or spltting the array into three DCRs with 100 events and one with ', tostring((count_-300)), ' events.'),\r\n                    tostring(count_))",
                                "size": 4,
                                "title": "Number of Distinct IDs Selected for MITRE DCR",
                                "timeContext": {
                                  "durationMs": 86400000
                                },
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "crossComponentResources": [
                                  "{Workspace}"
                                ],
                                "visualization": "card",
                                "tileSettings": {
                                  "titleContent": {},
                                  "leftContent": {
                                    "columnMatch": "Count"
                                  },
                                  "showBorder": false
                                },
                                "textSettings": {
                                  "style": "bignumber"
                                }
                              },
                              "customWidth": "33",
                              "conditionalVisibility": {
                                "parameterName": "Logtype",
                                "comparison": "isEqualTo",
                                "value": "MITRE"
                              },
                              "name": "Count - MITRE"
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "let IDCount = '{mergedMsft}';\r\nprint IDCount\r\n| mv-expand Test = todynamic(print_0)\r\n| summarize count() by print_0\r\n| project-away print_0\r\n| extend count_ = case(count_ >= 100 and count_ <= 200, strcat('DCR count limit reached. Consider splitting the array into one DCR with 100 events and one with ', tostring((count_-100)), ' events.'),\r\n                    count_ >= 200 and count_ <=300, strcat('DCR count limit reached. Consider filtering the log criticality or spltting the array into two DCRs with 100 events and one with ', tostring((count_-200)), ' events.'),\r\n                    count_ >= 300 and count_ <=400, strcat('DCR count limit reached. Consider filtering the log criticality or spltting the array into three DCRs with 100 events and one with ', tostring((count_-300)), ' events.'),\r\n                    tostring(count_))",
                                "size": 4,
                                "title": "Number of Distinct IDs Selected for Recommended ID DCR",
                                "timeContext": {
                                  "durationMs": 86400000
                                },
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "crossComponentResources": [
                                  "{Workspace}"
                                ],
                                "visualization": "card",
                                "tileSettings": {
                                  "titleContent": {},
                                  "leftContent": {
                                    "columnMatch": "Count"
                                  },
                                  "showBorder": false
                                },
                                "textSettings": {
                                  "style": "bignumber"
                                }
                              },
                              "customWidth": "33",
                              "conditionalVisibility": {
                                "parameterName": "Logtype",
                                "comparison": "isEqualTo",
                                "value": "WE"
                              },
                              "name": "Count - MSFT"
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "### Help\r\n\r\nThis section lists the events that were pulled from the public NSA list. The value here is that every event is listed in order to reflect what will be collected and what it aligns with. This is meant to just be used as a reference for learning and checking before deploying a DCR.",
                                "style": "info"
                              },
                              "conditionalVisibilities": [
                                {
                                  "parameterName": "Logtype",
                                  "comparison": "isEqualTo",
                                  "value": "NSA"
                                },
                                {
                                  "parameterName": "Help",
                                  "comparison": "isEqualTo",
                                  "value": "Yes"
                                }
                              ],
                              "name": "NSAEvent"
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "// First Parse the NSA JSON\r\nprint events=todynamic({nsaRecommendedEvents:parsejson})\r\n| extend events = events['Recommended Events to Collect']\r\n// First we pivot the data\r\n| mv-apply events on (\r\n    extend Category = tostring(bag_keys(events)[0])\r\n    | extend description = events[Category].description\r\n    | extend events = events[Category].events\r\n)\r\n| mv-apply events on (\r\n    extend eventName = tostring(bag_keys(events)[0])\r\n    | extend eventId = tostring(bag_keys(events[eventName])[0])\r\n    | extend properties = events[eventName][eventId]\r\n    | project-away events\r\n)\r\n| evaluate bag_unpack(properties)\r\n// group up all events\r\n//| summarize events=makelist(eventId) by Category\r\n//| extend events = replace_regex(tostring(events), @'\"','')",
                                "size": 0,
                                "showAnalytics": true,
                                "title": "Analyzing the NSA Event Recommendations",
                                "timeContext": {
                                  "durationMs": 86400000
                                },
                                "showExportToExcel": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "crossComponentResources": [
                                  "{Workspace}"
                                ],
                                "visualization": "table",
                                "gridSettings": {
                                  "filter": true,
                                  "sortBy": [
                                    {
                                      "itemKey": "Category",
                                      "sortOrder": 1
                                    }
                                  ]
                                },
                                "sortBy": [
                                  {
                                    "itemKey": "Category",
                                    "sortOrder": 1
                                  }
                                ]
                              },
                              "conditionalVisibility": {
                                "parameterName": "Logtype",
                                "comparison": "isEqualTo",
                                "value": "NSA"
                              },
                              "name": "Analyzing the NSA Event Recommendations - Copy"
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "### Help\r\n\r\nThis section lists the events that are aligned with the different MITRE tactics. The value here is that every event is listed in order to reflect what will be collected and what it aligns with. This is meant to just be used as a reference for learning and checking before deploying a DCR.",
                                "style": "info"
                              },
                              "conditionalVisibilities": [
                                {
                                  "parameterName": "Logtype",
                                  "comparison": "isEqualTo",
                                  "value": "MITRE"
                                },
                                {
                                  "parameterName": "Help",
                                  "comparison": "isEqualTo",
                                  "value": "Yes"
                                }
                              ],
                              "name": "MITREEvents"
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "{\"version\":\"1.0.0\",\"content\":\"[\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"Antivirus\\\",\\r\\n        \\\"Technique\\\":  \\\"Antivirus\\\",\\r\\n        \\\"Description\\\":  \\\"Defender: antivirus not up to date\\\",\\r\\n        \\\"Event IDs\\\":  \\\"1151\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"Antivirus\\\",\\r\\n        \\\"Technique\\\":  \\\"Antivirus\\\",\\r\\n        \\\"Description\\\":  \\\"Defender: massive malware outbreak detected on multiple hosts\\\",\\r\\n        \\\"Event IDs\\\":  \\\"1116\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"Antivirus\\\",\\r\\n        \\\"Technique\\\":  \\\"Antivirus\\\",\\r\\n        \\\"Description\\\":  \\\"Defender: massive malwares detected on a single host\\\",\\r\\n        \\\"Event IDs\\\":  \\\"1116\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0001-Initial access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1078.002-Valid accounts-Domain accounts\\\",\\r\\n        \\\"Description\\\":  \\\"Login denied due to account policy restrictions\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4625\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0001-Initial access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1078.002-Valid accounts-Domain accounts\\\",\\r\\n        \\\"Description\\\":  \\\"Login failure from a single source with a disabled account\\\",\\r\\n        \\\"Event IDs\\\":  \\\"33205\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0001-Initial access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1078.002-Valid accounts-Domain accounts\\\",\\r\\n        \\\"Description\\\":  \\\"Success login on OpenSSH server\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4624/4\\\",\\r\\n        \\\"Threat Details\\\":  \\\"SSH server\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0001-Initial access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1078-Valid accounts\\\",\\r\\n        \\\"Description\\\":  \\\"RDP reconnaissance with valid credentials performed to multiple hosts\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4624/1149\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0002-Execution\\\",\\r\\n        \\\"Technique\\\":  \\\"T1047-Windows Management Instrumentation\\\",\\r\\n        \\\"Description\\\":  \\\"Impacket WMIexec process execution\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"WMIexec\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0002-Execution\\\",\\r\\n        \\\"Technique\\\":  \\\"T1053.005-Scheduled Task\\\",\\r\\n        \\\"Description\\\":  \\\"Interactive shell triggered by scheduled task (at, deprecated)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0002-Execution\\\",\\r\\n        \\\"Technique\\\":  \\\"T1053.005-Scheduled Task\\\",\\r\\n        \\\"Description\\\":  \\\"Persistent scheduled task with SYSTEM privileges creation\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0002-Execution\\\",\\r\\n        \\\"Technique\\\":  \\\"T1053.005-Scheduled Task\\\",\\r\\n        \\\"Description\\\":  \\\"Remote schedule task creation via named pipes\\\",\\r\\n        \\\"Event IDs\\\":  \\\"5145\\\",\\r\\n        \\\"Threat Details\\\":  \\\"Atexec\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0002-Execution\\\",\\r\\n        \\\"Technique\\\":  \\\"T1053.005-Scheduled Task\\\",\\r\\n        \\\"Description\\\":  \\\"Schedule task created and deleted in a short period of time\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4698-4699\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0002-Execution\\\",\\r\\n        \\\"Technique\\\":  \\\"T1053.005-Scheduled Task\\\",\\r\\n        \\\"Description\\\":  \\\"Schedule task created with suspicious arguments\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4698\\\",\\r\\n        \\\"Threat Details\\\":  \\\"Atexec\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0002-Execution\\\",\\r\\n        \\\"Technique\\\":  \\\"T1053.005-Scheduled Task\\\",\\r\\n        \\\"Description\\\":  \\\"Schedule task fastly created and deleted\\\",\\r\\n        \\\"Event IDs\\\":  \\\"46,984,699\\\",\\r\\n        \\\"Threat Details\\\":  \\\"Atexec\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0002-Execution\\\",\\r\\n        \\\"Technique\\\":  \\\"T1053.005-Scheduled Task\\\",\\r\\n        \\\"Description\\\":  \\\"Scheduled task creation\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0002-Execution\\\",\\r\\n        \\\"Technique\\\":  \\\"T1059.001-Command and Scripting Interpreter: PowerShell\\\",\\r\\n        \\\"Description\\\":  \\\"Encoded PowerShell payload deployed\\\",\\r\\n        \\\"Event IDs\\\":  \\\"800/4103/4104\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0002-Execution\\\",\\r\\n        \\\"Technique\\\":  \\\"T1059.001-Command and Scripting Interpreter: PowerShell\\\",\\r\\n        \\\"Description\\\":  \\\"Interactive PipeShell over SMB named pipe\\\",\\r\\n        \\\"Event IDs\\\":  \\\"800/4103/4104\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0002-Execution\\\",\\r\\n        \\\"Technique\\\":  \\\"T1059.001-Command and Scripting Interpreter: PowerShell\\\",\\r\\n        \\\"Description\\\":  \\\"Payload downloaded via PowerShell\\\",\\r\\n        \\\"Event IDs\\\":  \\\"800/4103/4104\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0002-Execution\\\",\\r\\n        \\\"Technique\\\":  \\\"T1059.003-Windows Command Shell\\\",\\r\\n        \\\"Description\\\":  \\\"Encoded PowerShell payload deployed via process execution\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0002-Execution\\\",\\r\\n        \\\"Technique\\\":  \\\"T1059.003-Windows Command Shell\\\",\\r\\n        \\\"Description\\\":  \\\"SQL Server payload injectection for reverse shell (MSF)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0002-Execution\\\",\\r\\n        \\\"Technique\\\":  \\\"T1204-User execution\\\",\\r\\n        \\\"Description\\\":  \\\"Edge abuse for payload download via console\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0002-Execution\\\",\\r\\n        \\\"Technique\\\":  \\\"T1204-User execution\\\",\\r\\n        \\\"Description\\\":  \\\"Edge/Chrome headless feature abuse for payload download\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0002-Execution\\\",\\r\\n        \\\"Technique\\\":  \\\"T1569.002-Service Execution\\\",\\r\\n        \\\"Description\\\":  \\\"PSexec installation detected\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0002-Execution\\\",\\r\\n        \\\"Technique\\\":  \\\"T1569.002-Service Execution\\\",\\r\\n        \\\"Description\\\":  \\\"Service massive failures (native)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"7000/7009\\\",\\r\\n        \\\"Threat Details\\\":  \\\"Tchopper\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0002-Execution\\\",\\r\\n        \\\"Technique\\\":  \\\"T1569.002-Service Execution\\\",\\r\\n        \\\"Description\\\":  \\\"Service massive installation (native)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"7045/4697\\\",\\r\\n        \\\"Threat Details\\\":  \\\"Tchopper\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0002-Execution\\\",\\r\\n        \\\"Technique\\\":  \\\"T1569.002-Service Execution\\\",\\r\\n        \\\"Description\\\":  \\\"Service massive remote creation via named pipes (native)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"5145\\\",\\r\\n        \\\"Threat Details\\\":  \\\"Tchopper\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1078.002-Valid accounts-Domain accounts\\\",\\r\\n        \\\"Description\\\":  \\\"Account renamed to ?admin? (or likely)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4781\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098.xxx-Account manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"Computer account created with privileges\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4741\\\",\\r\\n        \\\"Threat Details\\\":  \\\"CVE-2021-42278/42287 \\\\u0026 SAM-the-admin\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098.xxx-Account manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"Computer account renamed without a trailing $\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4781\\\",\\r\\n        \\\"Threat Details\\\":  \\\"CVE-2021-42278/42287 \\\\u0026 SAM-the-admin\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098.xxx-Account Manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"High risk domain group membership change\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4728/4756\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098.xxx-Account Manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"High risk local-domain local group membership change\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4732\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098.xxx-Account manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"Host delegation settings changed for potential abuse (any protocol)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4742\\\",\\r\\n        \\\"Threat Details\\\":  \\\"Rubeus\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098.xxx-Account manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"Host delegation settings changed for potential abuse (any service, Kerberos only)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4742\\\",\\r\\n        \\\"Threat Details\\\":  \\\"Rubeus\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098.xxx-Account manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"Host delegation settings changed for potential abuse (Kerberos only)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4742\\\",\\r\\n        \\\"Threat Details\\\":  \\\"Rubeus\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098.xxx-Account Manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"Medium risk local-domain local group membership change\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4732\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098.xxx-Account Manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"Member added and removed from a group by a user account in a short period of time\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4728/29,4756/57,4732/33\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098.xxx-Account manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"Member added to a built-in Exchange security group\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4756\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098.xxx-Account Manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"Member added to a group by the same account\\\",\\r\\n        \\\"Event IDs\\\":  \\\"472,847,564,732\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098.xxx-Account Manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"Member added to a local group by a user account\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4732\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098.xxx-Account manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"Member added to DNSadmin group for DLL abuse\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4732\\\",\\r\\n        \\\"Threat Details\\\":  \\\"DNS DLL abuse\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098.xxx-Account manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"New admin (or likely) created by a non administrative account\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4720\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098.xxx-Account manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"SPN modification of a computer account (Directory Services)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"5136\\\",\\r\\n        \\\"Threat Details\\\":  \\\"DCShadow\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098.xxx-Account manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"SPN modification of a computer account\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4742\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098.xxx-Account manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"SPN modification of a computer account\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4742\\\",\\r\\n        \\\"Threat Details\\\":  \\\"DCShadow\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098.xxx-Account manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"SPN modification of a user account\\\",\\r\\n        \\\"Event IDs\\\":  \\\"5136\\\",\\r\\n        \\\"Threat Details\\\":  \\\"Kerberoasting\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098.xxx-Account manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"SQL Server: new member added to a database role\\\",\\r\\n        \\\"Event IDs\\\":  \\\"33205\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098.xxx-Account manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"SQL Server: new member added to server role\\\",\\r\\n        \\\"Event IDs\\\":  \\\"33205\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098.xxx-Account manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"User account created and/or set with reversible encryption detected\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4738\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098.xxx-Account manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"User account marked as ?sensitive and cannot be delegated? its had protection removed\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4738\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098.xxx-Account manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"User account set to not require Kerberos pre-authentication\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4738\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098.xxx-Account manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"User account set to use Kerberos DES encryption\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4738\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098.xxx-Account manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"User account with password set to never expire detected\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4738\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098.xxx-Account manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"User account with password set to not require detected\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4738\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098.xxx-Account manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"User password change using current hash password ? ChangeNTLM\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4723\\\",\\r\\n        \\\"Threat Details\\\":  \\\"Mimikatz\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098.xxx-Account manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"User password change without previous password known ? SetNTLM\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4724\\\",\\r\\n        \\\"Threat Details\\\":  \\\"Mimikatz\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098.xxx-Account Manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"User performing massive group membership changes on multiple differents groups\\\",\\r\\n        \\\"Event IDs\\\":  \\\"47,284,756\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098-Account Manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"Disabled guest or builtin account activated\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4722\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1098-Account Manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"SPN added to an account (command)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688/1\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1136.001-Create account-Local account\\\",\\r\\n        \\\"Description\\\":  \\\"Hidden account creation (with fast deletion)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4720/4726\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1136.001-Create account-Local account\\\",\\r\\n        \\\"Description\\\":  \\\"Local user account created on a single host\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4720\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1136.001-Create account-Local account\\\",\\r\\n        \\\"Description\\\":  \\\"SQL Server: disabled SA account enabled\\\",\\r\\n        \\\"Event IDs\\\":  \\\"33205\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1136.002-Create account-Domain account\\\",\\r\\n        \\\"Description\\\":  \\\"Computer account created and deleted in a short period of time\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4741/4743\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1136.002-Create account-Domain account\\\",\\r\\n        \\\"Description\\\":  \\\"User account created and deleted in a short period of time\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4720/4726\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1136.002-Create account-Domain account\\\",\\r\\n        \\\"Description\\\":  \\\"User account creation disguised in a computer account\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4720/4781\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1136-Create account\\\",\\r\\n        \\\"Description\\\":  \\\"User creation via commandline\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1505.001-SQL Stored Procedures\\\",\\r\\n        \\\"Description\\\":  \\\"SQL lateral movement with CLR\\\",\\r\\n        \\\"Event IDs\\\":  \\\"15457\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1505.001-SQL Stored Procedures\\\",\\r\\n        \\\"Description\\\":  \\\"SQL Server xp_cmdshell procedure activated\\\",\\r\\n        \\\"Event IDs\\\":  \\\"18457\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1505.001-SQL Stored Procedures\\\",\\r\\n        \\\"Description\\\":  \\\"SQL Server: sqlcmd \\\\u0026 ossql utilities abuse\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1505.001-SQL Stored Procedures\\\",\\r\\n        \\\"Description\\\":  \\\"SQL Server: started in single mode for password recovery\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1505.002-Server Software Component: Transport Agent\\\",\\r\\n        \\\"Description\\\":  \\\"Exchange transport agent injection via configuration file\\\",\\r\\n        \\\"Event IDs\\\":  \\\"11\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1505.002-Server Software Component: Transport Agent\\\",\\r\\n        \\\"Description\\\":  \\\"Exchange transport agent installation artifacts\\\",\\r\\n        \\\"Event IDs\\\":  \\\"6-Jan\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1543.003-Create or Modify System Process-Windows Service\\\",\\r\\n        \\\"Description\\\":  \\\"Encoded PowerShell payload deployed via service installation\\\",\\r\\n        \\\"Event IDs\\\":  \\\"7045/4697\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1543.003-Create or Modify System Process-Windows Service\\\",\\r\\n        \\\"Description\\\":  \\\"Impacket SMBexec service registration (native)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"7045/4697\\\",\\r\\n        \\\"Threat Details\\\":  \\\"SMBexec\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1543.003-Create or Modify System Process-Windows Service\\\",\\r\\n        \\\"Description\\\":  \\\"Mimikatz service driver installation detected\\\",\\r\\n        \\\"Event IDs\\\":  \\\"7045/4697\\\",\\r\\n        \\\"Threat Details\\\":  \\\"Mimikatz\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1543.003-Create or Modify System Process-Windows Service\\\",\\r\\n        \\\"Description\\\":  \\\"Service abuse with backdoored ?command failure? (PowerShell)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"800/4103/4104\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1543.003-Create or Modify System Process-Windows Service\\\",\\r\\n        \\\"Description\\\":  \\\"Service abuse with backdoored ?command failure? (registry)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688/1\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1543.003-Create or Modify System Process-Windows Service\\\",\\r\\n        \\\"Description\\\":  \\\"Service abuse with backdoored ?command failure? (service)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688/1\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1543.003-Create or Modify System Process-Windows Service\\\",\\r\\n        \\\"Description\\\":  \\\"Service abuse with malicious ImagePath (PowerShell)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"800/4103/4104\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1543.003-Create or Modify System Process-Windows Service\\\",\\r\\n        \\\"Description\\\":  \\\"Service abuse with malicious ImagePath (registry)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688/1\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1543.003-Create or Modify System Process-Windows Service\\\",\\r\\n        \\\"Description\\\":  \\\"Service abuse with malicious ImagePath (service)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688/1\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1543.003-Create or Modify System Process-Windows Service\\\",\\r\\n        \\\"Description\\\":  \\\"Service created for RDP session hijack\\\",\\r\\n        \\\"Event IDs\\\":  \\\"7045/4697\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1543.003-Create or Modify System Process-Windows Service\\\",\\r\\n        \\\"Description\\\":  \\\"Service creation (command)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1543.003-Create or Modify System Process-Windows Service\\\",\\r\\n        \\\"Description\\\":  \\\"Service creation (PowerShell)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"800/4103/4104\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1546.003-Windows Management Instrumentation Event Subscription\\\",\\r\\n        \\\"Description\\\":  \\\"System crash behavior manipulation (registry)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"13\\\",\\r\\n        \\\"Threat Details\\\":  \\\"WMImplant\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1546.003-Windows Management Instrumentation Event Subscription\\\",\\r\\n        \\\"Description\\\":  \\\"WMI registration (PowerShell)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"800/4103/4104\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1546.003-Windows Management Instrumentation Event Subscription\\\",\\r\\n        \\\"Description\\\":  \\\"WMI registration\\\",\\r\\n        \\\"Event IDs\\\":  \\\"19,20,21\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1546.007-Netsh Helper DLL\\\",\\r\\n        \\\"Description\\\":  \\\"Netsh helper DLL command abuse\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1546.007-Netsh Helper DLL\\\",\\r\\n        \\\"Description\\\":  \\\"Netsh helper DLL registry abuse\\\",\\r\\n        \\\"Event IDs\\\":  \\\"13-Dec\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1546-Event Triggered Execution\\\",\\r\\n        \\\"Description\\\":  \\\"AdminSDHolder container permissions modified\\\",\\r\\n        \\\"Event IDs\\\":  \\\"5136\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1546-Event Triggered Execution\\\",\\r\\n        \\\"Description\\\":  \\\"localizationDisplayId attribute abuse for backdoor introduction\\\",\\r\\n        \\\"Event IDs\\\":  \\\"5136\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1547.008-Boot or Logon Autostart Execution: LSASS Driver\\\",\\r\\n        \\\"Description\\\":  \\\"win-os-security package (SSP) loaded into LSA (native)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4622\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1574.002-DLL Side-Loading\\\",\\r\\n        \\\"Description\\\":  \\\"DNS DLL ?serverlevelplugindll? command execution (+registry set)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"13-Jan\\\",\\r\\n        \\\"Threat Details\\\":  \\\"DNS DLL abuse\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1574.002-DLL Side-Loading\\\",\\r\\n        \\\"Description\\\":  \\\"Failed DLL loaded by DNS server\\\",\\r\\n        \\\"Event IDs\\\":  \\\"150\\\",\\r\\n        \\\"Threat Details\\\":  \\\"DNS DLL abuse\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1574.002-DLL Side-Loading\\\",\\r\\n        \\\"Description\\\":  \\\"Success DLL loaded by DNS server\\\",\\r\\n        \\\"Event IDs\\\":  \\\"770\\\",\\r\\n        \\\"Threat Details\\\":  \\\"DNS DLL abuse\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1574.010-Hijack execution flow: service file permissions weakness\\\",\\r\\n        \\\"Description\\\":  \\\"Service permissions modified (registry)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0003-Persistence\\\",\\r\\n        \\\"Technique\\\":  \\\"T1574.010-Hijack execution flow: service file permissions weakness\\\",\\r\\n        \\\"Description\\\":  \\\"Service permissions modified (service)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0004-Privilege Escalation\\\",\\r\\n        \\\"Technique\\\":  \\\"T1068-Exploitation for Privilege Escalation\\\",\\r\\n        \\\"Description\\\":  \\\"Privilege SeMachineAccountPrivilege abuse\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4673\\\",\\r\\n        \\\"Threat Details\\\":  \\\"CVE-2021-42278/42287 \\\\u0026 SAM-the-admin\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0004-Privilege Escalation\\\",\\r\\n        \\\"Technique\\\":  \\\"T1134.001- Access Token Manipulation: Token Impersonation/Theft\\\",\\r\\n        \\\"Description\\\":  \\\"Anonymous login\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4624/4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"RottenPotatoNG\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0004-Privilege Escalation\\\",\\r\\n        \\\"Technique\\\":  \\\"T1134.002- Access Token Manipulation: Create Process with Token\\\",\\r\\n        \\\"Description\\\":  \\\"Privilege escalation via runas (command)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688/4648/4624\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0004-Privilege Escalation\\\",\\r\\n        \\\"Technique\\\":  \\\"T1134.002- Access Token Manipulation: Create Process with Token\\\",\\r\\n        \\\"Description\\\":  \\\"Privilege escalation via RunasCS\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0004-Privilege Escalation\\\",\\r\\n        \\\"Technique\\\":  \\\"T1134-Access Token Manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"New access rights granted to an account by a standard user\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4717\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0004-Privilege Escalation\\\",\\r\\n        \\\"Technique\\\":  \\\"T1134-Access Token Manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"User right granted to an account by a standard user\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4704\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0004-Privilege Escalation\\\",\\r\\n        \\\"Technique\\\":  \\\"T1484.001-Domain Policy Modification-Group Policy Modification\\\",\\r\\n        \\\"Description\\\":  \\\"Modification of a sensitive Group Policy\\\",\\r\\n        \\\"Event IDs\\\":  \\\"5136\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0004-Privilege Escalation\\\",\\r\\n        \\\"Technique\\\":  \\\"T1543.003-Create or Modify System Process-Windows Service\\\",\\r\\n        \\\"Description\\\":  \\\"PSexec service installation detected\\\",\\r\\n        \\\"Event IDs\\\":  \\\"7045/4697\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0004-Privilege Escalation\\\",\\r\\n        \\\"Technique\\\":  \\\"T1546.008-Event Triggered Execution: Accessibility Features\\\",\\r\\n        \\\"Description\\\":  \\\"CMD executed by stickey key and detected via hash\\\",\\r\\n        \\\"Event IDs\\\":  \\\"1\\\",\\r\\n        \\\"Threat Details\\\":  \\\"Sticky key\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0004-Privilege Escalation\\\",\\r\\n        \\\"Technique\\\":  \\\"T1546.008-Event Triggered Execution: Accessibility Features\\\",\\r\\n        \\\"Description\\\":  \\\"Sticky key called CMD via command execution\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688/1\\\",\\r\\n        \\\"Threat Details\\\":  \\\"Sticky key\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0004-Privilege Escalation\\\",\\r\\n        \\\"Technique\\\":  \\\"T1546.008-Event Triggered Execution: Accessibility Features\\\",\\r\\n        \\\"Description\\\":  \\\"Sticky key failed sethc replacement by CMD\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4656\\\",\\r\\n        \\\"Threat Details\\\":  \\\"Sticky key\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0004-Privilege Escalation\\\",\\r\\n        \\\"Technique\\\":  \\\"T1546.008-Event Triggered Execution: Accessibility Features\\\",\\r\\n        \\\"Description\\\":  \\\"Sticky key file created from CMD copy\\\",\\r\\n        \\\"Event IDs\\\":  \\\"11\\\",\\r\\n        \\\"Threat Details\\\":  \\\"Sticky key\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0004-Privilege Escalation\\\",\\r\\n        \\\"Technique\\\":  \\\"T1546.008-Event Triggered Execution: Accessibility Features\\\",\\r\\n        \\\"Description\\\":  \\\"Sticky key IFEO command for registry change\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"Sticky key\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0004-Privilege Escalation\\\",\\r\\n        \\\"Technique\\\":  \\\"T1546.008-Event Triggered Execution: Accessibility Features\\\",\\r\\n        \\\"Description\\\":  \\\"Sticky key IFEO registry changed\\\",\\r\\n        \\\"Event IDs\\\":  \\\"13-Dec\\\",\\r\\n        \\\"Threat Details\\\":  \\\"Sticky key\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0004-Privilege Escalation\\\",\\r\\n        \\\"Technique\\\":  \\\"T1547.010-Port Monitors\\\",\\r\\n        \\\"Description\\\":  \\\"Print spooler privilege escalation via printer added\\\",\\r\\n        \\\"Event IDs\\\":  \\\"800/4103/4104\\\",\\r\\n        \\\"Threat Details\\\":  \\\"PrintNightmare (CVE-2021-1675 / CVE-2021-34527)\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0004-Privilege Escalation\\\",\\r\\n        \\\"Technique\\\":  \\\"T1574.002-DLL Side-Loading\\\",\\r\\n        \\\"Description\\\":  \\\"External printer mapped\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688/4648\\\",\\r\\n        \\\"Threat Details\\\":  \\\"PrintNightmare (CVE-2021-1675 / CVE-2021-34527)\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0004-Privilege Escalation\\\",\\r\\n        \\\"Technique\\\":  \\\"T1574.002-DLL Side-Loading\\\",\\r\\n        \\\"Description\\\":  \\\"Printer spool driver from Mimikatz installed\\\",\\r\\n        \\\"Event IDs\\\":  \\\"808 / 354 / 321\\\",\\r\\n        \\\"Threat Details\\\":  \\\"PrintNightmare (CVE-2021-1675 / CVE-2021-34527)\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0004-Privilege Escalation\\\",\\r\\n        \\\"Technique\\\":  \\\"T1574.002-DLL Side-Loading\\\",\\r\\n        \\\"Description\\\":  \\\"proxi\\\",\\r\\n        \\\"Event IDs\\\":  \\\"6416\\\",\\r\\n        \\\"Threat Details\\\":  \\\"PrintNightmare (CVE-2021-1675 / CVE-2021-34527)\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0004-Privilege Escalation\\\",\\r\\n        \\\"Technique\\\":  \\\"T1574.002-DLL Side-Loading\\\",\\r\\n        \\\"Description\\\":  \\\"Spool process spawned a CMD shell\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688/1\\\",\\r\\n        \\\"Threat Details\\\":  \\\"PrintNightmare (CVE-2021-1675 / CVE-2021-34527)\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1027-Obfuscated Files or Information\\\",\\r\\n        \\\"Description\\\":  \\\"Payload obfuscated transfer via service name\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"Tchopper\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1070.001-Indicator Removal on Host\\\",\\r\\n        \\\"Description\\\":  \\\"Event log file(s) cleared\\\",\\r\\n        \\\"Event IDs\\\":  \\\"104/1102\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1070.001-Indicator Removal on Host\\\",\\r\\n        \\\"Description\\\":  \\\"Tentative of clearing event log file(s) detected (command)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1070.001-Indicator Removal on Host\\\",\\r\\n        \\\"Description\\\":  \\\"Tentative of clearing event log file(s) detected (PowerShell)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"800/4103/4104\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1070.001-Indicator Removal on Host\\\",\\r\\n        \\\"Description\\\":  \\\"Tentative of clearing event log file(s) detected (wmi)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1070.006-Timestomp\\\",\\r\\n        \\\"Description\\\":  \\\"System time changed\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4616\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1070.xxx-Audit policy disabled\\\",\\r\\n        \\\"Description\\\":  \\\"Audit policy disabled\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4719\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1070.xxx-Audit policy disabled\\\",\\r\\n        \\\"Description\\\":  \\\"Domain policy changed on one or multiple hosts\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4739\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1070.xxx-Audit policy disabled\\\",\\r\\n        \\\"Description\\\":  \\\"Membership of a special group updated\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4908\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1070.xxx-Audit policy disabled\\\",\\r\\n        \\\"Description\\\":  \\\"SQL Server: Audit object deleted\\\",\\r\\n        \\\"Event IDs\\\":  \\\"33205\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1070.xxx-Audit policy disabled\\\",\\r\\n        \\\"Description\\\":  \\\"SQL Server: Audit object disabled\\\",\\r\\n        \\\"Event IDs\\\":  \\\"33205\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1070.xxx-Audit policy disabled\\\",\\r\\n        \\\"Description\\\":  \\\"SQL Server: Audit specifications deleted\\\",\\r\\n        \\\"Event IDs\\\":  \\\"33205\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1070.xxx-Audit policy disabled\\\",\\r\\n        \\\"Description\\\":  \\\"SQL Server: Audit specifications disabled\\\",\\r\\n        \\\"Event IDs\\\":  \\\"33205\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1070.xxx-Audit policy disabled\\\",\\r\\n        \\\"Description\\\":  \\\"SQL Server: Database audit specifications deleted\\\",\\r\\n        \\\"Event IDs\\\":  \\\"33205\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1070.xxx-Audit policy disabled\\\",\\r\\n        \\\"Description\\\":  \\\"SQL Server: Database audit specifications disabled\\\",\\r\\n        \\\"Event IDs\\\":  \\\"33205\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1070.xxx-Audit policy disabled\\\",\\r\\n        \\\"Description\\\":  \\\"Tentative of disabling or clearing audit policy by commandline\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1078.002-Valid accounts-Domain accounts\\\",\\r\\n        \\\"Description\\\":  \\\"Login from a user member of a ?special group? detected (special logon)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4964\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1112-Modify registry\\\",\\r\\n        \\\"Description\\\":  \\\"Impacket SMBexec service registration (registry)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"13\\\",\\r\\n        \\\"Threat Details\\\":  \\\"SMBexec\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1197-BITS job\\\",\\r\\n        \\\"Description\\\":  \\\"Command execution related to a suspicious BITS activity detected\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1197-BITS job\\\",\\r\\n        \\\"Description\\\":  \\\"Command execution related to a suspicious BITS activity detected\\\",\\r\\n        \\\"Event IDs\\\":  \\\"800/4103/4104\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1197-BITS job\\\",\\r\\n        \\\"Description\\\":  \\\"High amount of data downloaded via BITS\\\",\\r\\n        \\\"Event IDs\\\":  \\\"60\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1207-Rogue domain controller\\\",\\r\\n        \\\"Description\\\":  \\\"New fake domain controller registration\\\",\\r\\n        \\\"Event IDs\\\":  \\\"5137 / 5141\\\",\\r\\n        \\\"Threat Details\\\":  \\\"DCShadow\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1207-Rogue domain controller\\\",\\r\\n        \\\"Description\\\":  \\\"Sensitive attributes accessed\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4662\\\",\\r\\n        \\\"Threat Details\\\":  \\\"DCShadow\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1222.001-File and Directory Permissions Modification\\\",\\r\\n        \\\"Description\\\":  \\\"Computer account modifying AD permissions\\\",\\r\\n        \\\"Event IDs\\\":  \\\"5136\\\",\\r\\n        \\\"Threat Details\\\":  \\\"PrivExchange\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1222.001-File and Directory Permissions Modification\\\",\\r\\n        \\\"Description\\\":  \\\"Network share permissions changed\\\",\\r\\n        \\\"Event IDs\\\":  \\\"5143\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1222.001-File and Directory Permissions Modification\\\",\\r\\n        \\\"Description\\\":  \\\"OCSP security settings changed\\\",\\r\\n        \\\"Event IDs\\\":  \\\"5124(OCSP)\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1222.001-File and Directory Permissions Modification\\\",\\r\\n        \\\"Description\\\":  \\\"Permissions changed on a GPO\\\",\\r\\n        \\\"Event IDs\\\":  \\\"5136\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1222.001-File and Directory Permissions Modification\\\",\\r\\n        \\\"Description\\\":  \\\"Sensitive GUID related to ?Replicate directory changes? detected\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4662\\\",\\r\\n        \\\"Threat Details\\\":  \\\"DCSync\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1553.003- Subvert Trust Controls: SIP and Trust Provider Hijacking\\\",\\r\\n        \\\"Description\\\":  \\\"\\\",\\r\\n        \\\"Event IDs\\\":  \\\"13-Dec\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1562.001-Impair Defenses-Disable or modify tools\\\",\\r\\n        \\\"Description\\\":  \\\"Defender: critical security component disabled (command)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688/1\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1562.001-Impair Defenses-Disable or modify tools\\\",\\r\\n        \\\"Description\\\":  \\\"Defender: critical security component disabled (PowerShell)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"800/4103/4104\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1562.001-Impair Defenses-Disable or modify tools\\\",\\r\\n        \\\"Description\\\":  \\\"Defender: default action set to allow any threat (PowerShell)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"800/4103/4104\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1562.001-Impair Defenses-Disable or modify tools\\\",\\r\\n        \\\"Description\\\":  \\\"Defender: exclusion added (native)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"5007\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1562.001-Impair Defenses-Disable or modify tools\\\",\\r\\n        \\\"Description\\\":  \\\"Defender: exclusion added (PowerShell)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"800/4103/4104\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1562.001-Impair Defenses-Disable or modify tools\\\",\\r\\n        \\\"Description\\\":  \\\"Defender: service component status disabled (Registry via Sysmon)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"13\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1562.004-Disable or Modify System Firewall\\\",\\r\\n        \\\"Description\\\":  \\\"Firewall deactivation (cmd)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1562.004-Disable or Modify System Firewall\\\",\\r\\n        \\\"Description\\\":  \\\"Firewall deactivation (firewall)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"2003/4950\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1562.004-Disable or Modify System Firewall\\\",\\r\\n        \\\"Description\\\":  \\\"Firewall deactivation (PowerShell)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"800/4103/4104\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1562.004-Disable/modify firewall (rule)\\\",\\r\\n        \\\"Description\\\":  \\\"Any/any firewall rule created\\\",\\r\\n        \\\"Event IDs\\\":  \\\"2004\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1562.004-Disable/modify firewall (rule)\\\",\\r\\n        \\\"Description\\\":  \\\"Firewall rule created by a suspicious command (netsh.exe, wmiprvse.exe)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"2004\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1562.004-Disable/modify firewall (rule)\\\",\\r\\n        \\\"Description\\\":  \\\"Firewall rule created by a user account\\\",\\r\\n        \\\"Event IDs\\\":  \\\"2004\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1562.004-Disable/modify firewall (rule)\\\",\\r\\n        \\\"Description\\\":  \\\"OpenSSH server firewall configuration (command)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688/1\\\",\\r\\n        \\\"Threat Details\\\":  \\\"SSH server\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1562.004-Disable/modify firewall (rule)\\\",\\r\\n        \\\"Description\\\":  \\\"OpenSSH server firewall configuration (firewall)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"2004\\\",\\r\\n        \\\"Threat Details\\\":  \\\"SSH server\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1562.004-Disable/modify firewall (rule)\\\",\\r\\n        \\\"Description\\\":  \\\"OpenSSH server firewall configuration (PowerShell)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"800/4103/4104\\\",\\r\\n        \\\"Threat Details\\\":  \\\"SSH server\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0005-Defense Evasion\\\",\\r\\n        \\\"Technique\\\":  \\\"T1564.006-Hide Artifacts: Run Virtual Instance\\\",\\r\\n        \\\"Description\\\":  \\\"WSL for Windows installation detected\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1003.001-Credential dumping: LSASS\\\",\\r\\n        \\\"Description\\\":  \\\"LSASS credential dump with LSASSY (kernel)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4656/4663\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1003.001-Credential dumping: LSASS\\\",\\r\\n        \\\"Description\\\":  \\\"LSASS credential dump with LSASSY (PowerShell)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"800/4103/4104\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1003.001-Credential dumping: LSASS\\\",\\r\\n        \\\"Description\\\":  \\\"LSASS credential dump with LSASSY (process)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688/1\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1003.001-Credential dumping: LSASS\\\",\\r\\n        \\\"Description\\\":  \\\"LSASS credential dump with LSASSY (share)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"5145\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1003.001-Credential dumping: LSASS\\\",\\r\\n        \\\"Description\\\":  \\\"LSASS credentials dump via Task Manager (file)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"11\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1003.001-Credential dumping: LSASS\\\",\\r\\n        \\\"Description\\\":  \\\"LSASS dump indicator via Task Manager access\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1003.001-Credential dumping: LSASS\\\",\\r\\n        \\\"Description\\\":  \\\"LSASS process accessed by a non system account\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4656/4663\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1003.001-Credential dumping: LSASS\\\",\\r\\n        \\\"Description\\\":  \\\"SAM database user credential dump\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4661\\\",\\r\\n        \\\"Threat Details\\\":  \\\"Mimikatz\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1003.002-Security Account Manager\\\",\\r\\n        \\\"Description\\\":  \\\"Password dump over SMB ADMIN$\\\",\\r\\n        \\\"Event IDs\\\":  \\\"5145\\\",\\r\\n        \\\"Threat Details\\\":  \\\"Secretdump\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1003.002-Security Account Manager\\\",\\r\\n        \\\"Description\\\":  \\\"SAM database access during DCshadow\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4661\\\",\\r\\n        \\\"Threat Details\\\":  \\\"DCShadow\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1003.003-NTDS\\\",\\r\\n        \\\"Description\\\":  \\\"IFM created\\\",\\r\\n        \\\"Event IDs\\\":  \\\"325/327\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1003.003-NTDS\\\",\\r\\n        \\\"Description\\\":  \\\"IFM created from command line\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1003.003-OS Credential-Dumping NTDS\\\",\\r\\n        \\\"Description\\\":  \\\"DSRM configuration changed (Reg via command)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1003.003-OS Credential-Dumping NTDS\\\",\\r\\n        \\\"Description\\\":  \\\"DSRM configuration changed (Reg via PowerShell)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"800/4103/4104\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1003.003-OS Credential-Dumping NTDS\\\",\\r\\n        \\\"Description\\\":  \\\"DSRM password reset\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4794\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1003.006-DCSync\\\",\\r\\n        \\\"Description\\\":  \\\"Member added to a sensitive Exchange security group to perform DCsync attack\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4756\\\",\\r\\n        \\\"Threat Details\\\":  \\\"DCSync\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1003-Credential dumping\\\",\\r\\n        \\\"Description\\\":  \\\"Backdoor introduction via registry permission change through WMI (DAMP)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4674\\\",\\r\\n        \\\"Threat Details\\\":  \\\"DAMP\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1003-Credential dumping\\\",\\r\\n        \\\"Description\\\":  \\\"Diskshadow abuse\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1003-Credential dumping\\\",\\r\\n        \\\"Description\\\":  \\\"Wdigest authentication enabled (Reg via command)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1003-Credential dumping\\\",\\r\\n        \\\"Description\\\":  \\\"Wdigest authentication enabled (Reg via Sysmon)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"13-Dec\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1040-Network sniffing\\\",\\r\\n        \\\"Description\\\":  \\\"Windows native sniffing tool Pktmon usage\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1110.xxx-Brut force\\\",\\r\\n        \\\"Description\\\":  \\\"Brutforce enumeration on Windows OpenSSH server with non existing user\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4625/4\\\",\\r\\n        \\\"Threat Details\\\":  \\\"SSH server\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1110.xxx-Brut force\\\",\\r\\n        \\\"Description\\\":  \\\"Brutforce on Windows OpenSSH server with valid user\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4625/4\\\",\\r\\n        \\\"Threat Details\\\":  \\\"SSH server\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1110.xxx-Brut force\\\",\\r\\n        \\\"Description\\\":  \\\"Kerberos brutforce enumeration with existing/unexsting users (Kerbrute)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4771/4768\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1110.xxx-Brut force\\\",\\r\\n        \\\"Description\\\":  \\\"Kerberos brutforce with not existing users\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4771/4768\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1110.xxx-Brut force\\\",\\r\\n        \\\"Description\\\":  \\\"Login failure from a single source with different non existing accounts\\\",\\r\\n        \\\"Event IDs\\\":  \\\"33205\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1552.004-Unsecured Credentials-Private Keys\\\",\\r\\n        \\\"Description\\\":  \\\"Unknown application accessing certificate private key detected\\\",\\r\\n        \\\"Event IDs\\\":  \\\"70(CAPI2)\\\",\\r\\n        \\\"Threat Details\\\":  \\\"Mimikatz\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1555.003-Credentials from Password Stores: Credentials from Web Browsers\\\",\\r\\n        \\\"Description\\\":  \\\"User browser credentials dump via network share\\\",\\r\\n        \\\"Event IDs\\\":  \\\"5145\\\",\\r\\n        \\\"Threat Details\\\":  \\\"DonPapi, Lazagne\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1555.004-Windows Credential Manager\\\",\\r\\n        \\\"Description\\\":  \\\"Credentials (protected by DPAPI) dump via network share\\\",\\r\\n        \\\"Event IDs\\\":  \\\"5145\\\",\\r\\n        \\\"Threat Details\\\":  \\\"DonPapi, Lazagne\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1555-Credentials from Password Stores\\\",\\r\\n        \\\"Description\\\":  \\\"Suspicious Active Directory DPAPI attributes accessed\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4662\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1555-Credentials from Password Stores\\\",\\r\\n        \\\"Description\\\":  \\\"User files dump via network share\\\",\\r\\n        \\\"Event IDs\\\":  \\\"5145\\\",\\r\\n        \\\"Threat Details\\\":  \\\"DonPapi, Lazagne\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1557.001-MiM:LLMNR/NBT-NS Poisoning and SMB Relay\\\",\\r\\n        \\\"Description\\\":  \\\"Discovery for print spooler bug abuse via named pipe\\\",\\r\\n        \\\"Event IDs\\\":  \\\"5145\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1558.001-Golden Ticket\\\",\\r\\n        \\\"Description\\\":  \\\"Kerberos TGS ticket request related to a potential Golden ticket\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4769\\\",\\r\\n        \\\"Threat Details\\\":  \\\"Golden ticket\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1558.001-Golden Ticket\\\",\\r\\n        \\\"Description\\\":  \\\"SMB Admin share accessed with a forged Golden ticket\\\",\\r\\n        \\\"Event IDs\\\":  \\\"5140/5145\\\",\\r\\n        \\\"Threat Details\\\":  \\\"Golden ticket\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1558.001-Golden Ticket\\\",\\r\\n        \\\"Description\\\":  \\\"Success login impersonation with forged Golden ticket\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4624\\\",\\r\\n        \\\"Threat Details\\\":  \\\"Golden ticket\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1558.003-Kerberoasting\\\",\\r\\n        \\\"Description\\\":  \\\"KerberOAST ticket (TGS) request detected (low encryption)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4769\\\",\\r\\n        \\\"Threat Details\\\":  \\\"Kerberoast\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1558.004-Steal or Forge Kerberos Tickets: AS-REP Roasting\\\",\\r\\n        \\\"Description\\\":  \\\"Kerberos AS-REP Roasting ticket request detected\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4768\\\",\\r\\n        \\\"Threat Details\\\":  \\\"AS-REP Roasting\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1558-Steal or Forge Kerberos Tickets\\\",\\r\\n        \\\"Description\\\":  \\\"Kerberos ticket without a trailing $\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4768-4769\\\",\\r\\n        \\\"Threat Details\\\":  \\\"CVE-2021-42278/42287 \\\\u0026 SAM-the-admin\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0006-Credential Access\\\",\\r\\n        \\\"Technique\\\":  \\\"T1558-Steal or Forge Kerberos Tickets\\\",\\r\\n        \\\"Description\\\":  \\\"Suspicious Kerberos proxiable ticket\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4768\\\",\\r\\n        \\\"Threat Details\\\":  \\\"CVE-2021-42278/42287 \\\\u0026 SAM-the-admin\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0007-Discovery\\\",\\r\\n        \\\"Technique\\\":  \\\"T1016-System Network Configuration Discovery\\\",\\r\\n        \\\"Description\\\":  \\\"Firewall configuration enumerated (command)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0007-Discovery\\\",\\r\\n        \\\"Technique\\\":  \\\"T1016-System Network Configuration Discovery\\\",\\r\\n        \\\"Description\\\":  \\\"Firewall configuration enumerated (PowerShell)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"800/4103/4104\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0007-Discovery\\\",\\r\\n        \\\"Technique\\\":  \\\"T1016-System Network Configuration Discovery\\\",\\r\\n        \\\"Description\\\":  \\\"Tentative of zone transfer from a non DNS server detected\\\",\\r\\n        \\\"Event IDs\\\":  \\\"6004(DNSserver)\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0007-Discovery\\\",\\r\\n        \\\"Technique\\\":  \\\"T1018-Remote System Discovery\\\",\\r\\n        \\\"Description\\\":  \\\"DNS hosts file accessed via network share\\\",\\r\\n        \\\"Event IDs\\\":  \\\"5145\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0007-Discovery\\\",\\r\\n        \\\"Technique\\\":  \\\"T1046-Network Service Scanning\\\",\\r\\n        \\\"Description\\\":  \\\"RDP discovery performed on multiple hosts\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4625/131\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0007-Discovery\\\",\\r\\n        \\\"Technique\\\":  \\\"T1046-Network Service Scanning\\\",\\r\\n        \\\"Description\\\":  \\\"Suspicious anonymous login\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4624\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0007-Discovery\\\",\\r\\n        \\\"Technique\\\":  \\\"T1069.001-Discovery domain groups\\\",\\r\\n        \\\"Description\\\":  \\\"Local domain group enumeration via RID brutforce\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4661\\\",\\r\\n        \\\"Threat Details\\\":  \\\"CrackMapExec\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0007-Discovery\\\",\\r\\n        \\\"Technique\\\":  \\\"T1069.001-Discovery local groups\\\",\\r\\n        \\\"Description\\\":  \\\"Remote local administrator group enumerated\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4799\\\",\\r\\n        \\\"Threat Details\\\":  \\\"SharpHound\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0007-Discovery\\\",\\r\\n        \\\"Technique\\\":  \\\"T1069.002-Discovery domain groups\\\",\\r\\n        \\\"Description\\\":  \\\"Domain group enumeration\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4661\\\",\\r\\n        \\\"Threat Details\\\":  \\\"CrackMapExec\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0007-Discovery\\\",\\r\\n        \\\"Technique\\\":  \\\"T1069.002-Discovery domain groups\\\",\\r\\n        \\\"Description\\\":  \\\"Honeypot object (container, computer, group, user) enumerated\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4662\\\",\\r\\n        \\\"Threat Details\\\":  \\\"SharpHound\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0007-Discovery\\\",\\r\\n        \\\"Technique\\\":  \\\"T1069.002-Discovery domain groups\\\",\\r\\n        \\\"Description\\\":  \\\"Massive SAM domain users \\\\u0026 groups discovery\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4661\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0007-Discovery\\\",\\r\\n        \\\"Technique\\\":  \\\"T1069.002-Discovery domain groups\\\",\\r\\n        \\\"Description\\\":  \\\"Sensitive SAM domain user \\\\u0026 groups discovery\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4661\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0007-Discovery\\\",\\r\\n        \\\"Technique\\\":  \\\"T1069-Permission Groups Discovery\\\",\\r\\n        \\\"Description\\\":  \\\"Group discovery via commandline\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0007-Discovery\\\",\\r\\n        \\\"Technique\\\":  \\\"T1069-Permission Groups Discovery\\\",\\r\\n        \\\"Description\\\":  \\\"Group discovery via PowerShell\\\",\\r\\n        \\\"Event IDs\\\":  \\\"800/4103/4104\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0007-Discovery\\\",\\r\\n        \\\"Technique\\\":  \\\"T1082-System Information Discovery\\\",\\r\\n        \\\"Description\\\":  \\\"Audit policy settings collection\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0007-Discovery\\\",\\r\\n        \\\"Technique\\\":  \\\"T1087.002-Domain Account discovery\\\",\\r\\n        \\\"Description\\\":  \\\"Active Directory PowerShell module called from a non administrative host\\\",\\r\\n        \\\"Event IDs\\\":  \\\"600\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0007-Discovery\\\",\\r\\n        \\\"Technique\\\":  \\\"T1087.002-Domain Account discovery\\\",\\r\\n        \\\"Description\\\":  \\\"Single source performing host enumeration over Kerberos ticket (TGS) detected\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4769\\\",\\r\\n        \\\"Threat Details\\\":  \\\"SharpHound\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0007-Discovery\\\",\\r\\n        \\\"Technique\\\":  \\\"T1087-Account discovery\\\",\\r\\n        \\\"Description\\\":  \\\"SPN enumeration (command)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688/1\\\",\\r\\n        \\\"Threat Details\\\":  \\\"Kerberoast\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0007-Discovery\\\",\\r\\n        \\\"Technique\\\":  \\\"T1087-Account discovery\\\",\\r\\n        \\\"Description\\\":  \\\"SPN enumeration (PowerShell)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"800/4103/4104\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0007-Discovery\\\",\\r\\n        \\\"Technique\\\":  \\\"T1087-Account discovery\\\",\\r\\n        \\\"Description\\\":  \\\"User enumeration via commandline\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0007-Discovery\\\",\\r\\n        \\\"Technique\\\":  \\\"T1135-Network Share Discovery\\\",\\r\\n        \\\"Description\\\":  \\\"Host performing advanced named pipes enumeration on different hosts via SMB\\\",\\r\\n        \\\"Event IDs\\\":  \\\"5145\\\",\\r\\n        \\\"Threat Details\\\":  \\\"SharpHound\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0007-Discovery\\\",\\r\\n        \\\"Technique\\\":  \\\"T1135-Network Share Discovery\\\",\\r\\n        \\\"Description\\\":  \\\"Network share discovery and/or connection via commandline\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0007-Discovery\\\",\\r\\n        \\\"Technique\\\":  \\\"T1135-Network Share Discovery\\\",\\r\\n        \\\"Description\\\":  \\\"Network share manipulation via commandline\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0007-Discovery\\\",\\r\\n        \\\"Technique\\\":  \\\"T1201-Password Policy Discovery\\\",\\r\\n        \\\"Description\\\":  \\\"Domain password policy enumeration\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4661\\\",\\r\\n        \\\"Threat Details\\\":  \\\"CrackMapExec\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0007-Discovery\\\",\\r\\n        \\\"Technique\\\":  \\\"T1201-Password Policy Discovery\\\",\\r\\n        \\\"Description\\\":  \\\"Password policy discovery via commandline\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0007-Discovery\\\",\\r\\n        \\\"Technique\\\":  \\\"T1482-Domain Trust Discovery\\\",\\r\\n        \\\"Description\\\":  \\\"Active Directory Forest PowerShell class called from a non administrative host\\\",\\r\\n        \\\"Event IDs\\\":  \\\"800/4103/4104\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0008-Lateral Movement\\\",\\r\\n        \\\"Technique\\\":  \\\"T1021.001-Remote Desktop Protocol\\\",\\r\\n        \\\"Description\\\":  \\\"Denied RDP login with valid credentials\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4825\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0008-Lateral Movement\\\",\\r\\n        \\\"Technique\\\":  \\\"T1021.002-SMB Windows Admin Shares\\\",\\r\\n        \\\"Description\\\":  \\\"Admin share accessed via SMB (basic)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"5140/5145\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0008-Lateral Movement\\\",\\r\\n        \\\"Technique\\\":  \\\"T1021.002-SMB Windows Admin Shares\\\",\\r\\n        \\\"Description\\\":  \\\"Impacket WMIexec execution via SMB admin share\\\",\\r\\n        \\\"Event IDs\\\":  \\\"5145\\\",\\r\\n        \\\"Threat Details\\\":  \\\"WMIexec\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0008-Lateral Movement\\\",\\r\\n        \\\"Technique\\\":  \\\"T1021.002-SMB Windows Admin Shares\\\",\\r\\n        \\\"Description\\\":  \\\"Lateral movement by mounting a network share ? net use (command)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688/4648\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0008-Lateral Movement\\\",\\r\\n        \\\"Technique\\\":  \\\"T1021.002-SMB Windows Admin Shares\\\",\\r\\n        \\\"Description\\\":  \\\"Multiple failed attempt to network share\\\",\\r\\n        \\\"Event IDs\\\":  \\\"5140/5145\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0008-Lateral Movement\\\",\\r\\n        \\\"Technique\\\":  \\\"T1021.002-SMB Windows Admin Shares\\\",\\r\\n        \\\"Description\\\":  \\\"New file share created on a host\\\",\\r\\n        \\\"Event IDs\\\":  \\\"5142\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0008-Lateral Movement\\\",\\r\\n        \\\"Technique\\\":  \\\"T1021.002-SMB Windows Admin Shares\\\",\\r\\n        \\\"Description\\\":  \\\"Psexec remote execution via SMB\\\",\\r\\n        \\\"Event IDs\\\":  \\\"5145\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0008-Lateral Movement\\\",\\r\\n        \\\"Technique\\\":  \\\"T1021.002-SMB Windows Admin Shares\\\",\\r\\n        \\\"Description\\\":  \\\"Remote service creation over SMB\\\",\\r\\n        \\\"Event IDs\\\":  \\\"5145\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0008-Lateral Movement\\\",\\r\\n        \\\"Technique\\\":  \\\"T1021.002-SMB Windows Admin Shares\\\",\\r\\n        \\\"Description\\\":  \\\"Remote shell execuction via SMB admin share\\\",\\r\\n        \\\"Event IDs\\\":  \\\"5145\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0008-Lateral Movement\\\",\\r\\n        \\\"Technique\\\":  \\\"T1021.002-SMB Windows Admin Shares\\\",\\r\\n        \\\"Description\\\":  \\\"Shared printer creation\\\",\\r\\n        \\\"Event IDs\\\":  \\\"5142\\\",\\r\\n        \\\"Threat Details\\\":  \\\"PrintNightmare (CVE-2021-1675 / CVE-2021-34527)\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0008-Lateral Movement\\\",\\r\\n        \\\"Technique\\\":  \\\"T1021.003-DCOM\\\",\\r\\n        \\\"Description\\\":  \\\"DCOM lateral movement (via MMC20)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4104\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0008-Lateral Movement\\\",\\r\\n        \\\"Technique\\\":  \\\"T1021.003-DCOM\\\",\\r\\n        \\\"Description\\\":  \\\"DCOMexec privilege abuse\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4674\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0008-Lateral Movement\\\",\\r\\n        \\\"Technique\\\":  \\\"T1021.003-DCOM\\\",\\r\\n        \\\"Description\\\":  \\\"DCOMexec process abuse via MMC\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0008-Lateral Movement\\\",\\r\\n        \\\"Technique\\\":  \\\"T1021.004-Remote services: SSH\\\",\\r\\n        \\\"Description\\\":  \\\"OpenSSH native server feature installation\\\",\\r\\n        \\\"Event IDs\\\":  \\\"800/4103/4104\\\",\\r\\n        \\\"Threat Details\\\":  \\\"SSH server\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0008-Lateral Movement\\\",\\r\\n        \\\"Technique\\\":  \\\"T1021.004-Remote services: SSH\\\",\\r\\n        \\\"Description\\\":  \\\"OpenSSH server for Windows activation/configuration detected\\\",\\r\\n        \\\"Event IDs\\\":  \\\"800/4103/4104\\\",\\r\\n        \\\"Threat Details\\\":  \\\"SSH server\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0008-Lateral Movement\\\",\\r\\n        \\\"Technique\\\":  \\\"T1021.006-Windows Remote Management\\\",\\r\\n        \\\"Description\\\":  \\\"WinRM listening service reconnaissance\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4656\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0008-Lateral Movement\\\",\\r\\n        \\\"Technique\\\":  \\\"T1550.002-Use Alternate Authentication Material: Pass the Hash\\\",\\r\\n        \\\"Description\\\":  \\\"LSASS dump via process access\\\",\\r\\n        \\\"Event IDs\\\":  \\\"10\\\",\\r\\n        \\\"Threat Details\\\":  \\\"Mimikatz\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0008-Lateral Movement\\\",\\r\\n        \\\"Technique\\\":  \\\"T1550.002-Use Alternate Authentication Material: Pass the Hash\\\",\\r\\n        \\\"Description\\\":  \\\"Pass-the-hash login\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4624\\\",\\r\\n        \\\"Threat Details\\\":  \\\"Mimikatz\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0008-Lateral Movement\\\",\\r\\n        \\\"Technique\\\":  \\\"T1563.002-RDP hijacking\\\",\\r\\n        \\\"Description\\\":  \\\"RDP session hijack via TSCON abuse command\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0009-Collection\\\",\\r\\n        \\\"Technique\\\":  \\\"T1125-Video capture\\\",\\r\\n        \\\"Description\\\":  \\\"RDP shadow session started (registry)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"13\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0011-Command and control\\\",\\r\\n        \\\"Technique\\\":  \\\"T1572-Protocol tunneling\\\",\\r\\n        \\\"Description\\\":  \\\"RDP tunneling configuration enabled for port forwarding\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0040-Impact\\\",\\r\\n        \\\"Technique\\\":  \\\"T1490-Inhibit System Recovery\\\",\\r\\n        \\\"Description\\\":  \\\"VSS backup deletion (PowerShell)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"800/4103/4104\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0040-Impact\\\",\\r\\n        \\\"Technique\\\":  \\\"T1490-Inhibit System Recovery\\\",\\r\\n        \\\"Description\\\":  \\\"VSS backup deletion (WMI)\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0040-Impact\\\",\\r\\n        \\\"Technique\\\":  \\\"T1490-Inhibit System Recovery\\\",\\r\\n        \\\"Description\\\":  \\\"Windows native backup deletion\\\",\\r\\n        \\\"Event IDs\\\":  \\\"4688\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    },\\r\\n    {\\r\\n        \\\"Tactic\\\":  \\\"TA0040-Impact\\\",\\r\\n        \\\"Technique\\\":  \\\"T1565-Data manipulation\\\",\\r\\n        \\\"Description\\\":  \\\"DNS hosts file modified\\\",\\r\\n        \\\"Event IDs\\\":  \\\"11\\\",\\r\\n        \\\"Threat Details\\\":  \\\"\\\"\\r\\n    }\\r\\n]\\r\\n\",\"transformers\":null}",
                                "size": 0,
                                "title": "MITRE Event ID Mapping",
                                "queryType": 8,
                                "gridSettings": {
                                  "filter": true
                                }
                              },
                              "conditionalVisibility": {
                                "parameterName": "Logtype",
                                "comparison": "isEqualTo",
                                "value": "MITRE"
                              },
                              "name": "query - 4"
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "### Help\r\n\r\nThis section lists the events that are aligned with the recommended Windows event IDs as highlighted in Appendix L. Each log has a criticality level that can be configured within the drop down. The value here is that every event is listed in order to reflect what will be collected and what it aligns with. This is meant to just be used as a reference for learning and checking before deploying a DCR.",
                                "style": "info"
                              },
                              "conditionalVisibilities": [
                                {
                                  "parameterName": "Logtype",
                                  "comparison": "isEqualTo",
                                  "value": "WE"
                                },
                                {
                                  "parameterName": "Help",
                                  "comparison": "isEqualTo",
                                  "value": "Yes"
                                }
                              ],
                              "name": "WEEvents"
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "{\"version\":\"1.0.0\",\"content\":\"[\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4618,\\r\\n    \\\"Potential Criticality\\\": \\\"High\\\",\\r\\n    \\\"Event Summary\\\": \\\"A monitored security event pattern has occurred.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4649,\\r\\n    \\\"Potential Criticality\\\": \\\"High\\\",\\r\\n    \\\"Event Summary\\\": \\\"A replay attack was detected. May be a harmless false positive due to misconfiguration error.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4719,\\r\\n    \\\"Potential Criticality\\\": \\\"High\\\",\\r\\n    \\\"Event Summary\\\": \\\"System audit policy was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4765,\\r\\n    \\\"Potential Criticality\\\": \\\"High\\\",\\r\\n    \\\"Event Summary\\\": \\\"SID History was added to an account.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4766,\\r\\n    \\\"Potential Criticality\\\": \\\"High\\\",\\r\\n    \\\"Event Summary\\\": \\\"An attempt to add SID History to an account failed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4794,\\r\\n    \\\"Potential Criticality\\\": \\\"High\\\",\\r\\n    \\\"Event Summary\\\": \\\"An attempt was made to set the Directory Services Restore Mode.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4897,\\r\\n    \\\"Potential Criticality\\\": \\\"High\\\",\\r\\n    \\\"Event Summary\\\": \\\"Role separation enabled:\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4964,\\r\\n    \\\"Potential Criticality\\\": \\\"High\\\",\\r\\n    \\\"Event Summary\\\": \\\"Special groups have been assigned to a new logon.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5124,\\r\\n    \\\"Potential Criticality\\\": \\\"High\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security setting was updated on the OCSP Responder Service\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": \\\"N/A\\\",\\r\\n    \\\"Potential Criticality\\\": \\\"Medium to High\\\",\\r\\n    \\\"Event Summary\\\": \\\"Possible denial-of-service (DoS) attack\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 1102,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium to High\\\",\\r\\n    \\\"Event Summary\\\": \\\"The audit log was cleared\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4621,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Administrator recovered system from CrashOnAuditFail. Users who are not administrators will now be allowed to log on. Some auditable activity might not have been recorded.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4675,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"SIDs were filtered.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4692,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Backup of data protection master key was attempted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4693,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Recovery of data protection master key was attempted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4706,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"A new trust was created to a domain.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4713,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Kerberos policy was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4714,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Encrypted data recovery policy was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4715,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"The audit policy (SACL) on an object was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4716,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Trusted domain information was modified.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4724,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"An attempt was made to reset an account's password.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4727,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-enabled global group was created.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4735,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-enabled local group was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4737,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-enabled global group was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4739,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Domain Policy was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4754,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-enabled universal group was created.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4755,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-enabled universal group was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4764,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-disabled group was deleted\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4764,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"A group's type was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4780,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"The ACL was set on accounts which are members of administrators groups.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4816,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"RPC detected an integrity violation while decrypting an incoming message.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4865,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"A trusted forest information entry was added.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4866,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"A trusted forest information entry was removed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4867,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"A trusted forest information entry was modified.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4868,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"The certificate manager denied a pending certificate request.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4870,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services revoked a certificate.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4882,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"The security permissions for Certificate Services changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4885,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"The audit filter for Certificate Services changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4890,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"The certificate manager settings for Certificate Services changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4892,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"A property of Certificate Services changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4896,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"One or more rows have been deleted from the certificate database.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4906,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"The CrashOnAuditFail value has changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4907,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Auditing settings on object were changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4908,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Special Groups Logon table modified.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4912,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Per User Audit Policy was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4960,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec dropped an inbound packet that failed an integrity check. If this problem persists, it could indicate a network issue or that packets are being modified in transit to this computer. Verify that the packets sent from the remote computer are the same as those received by this computer. This error might also indicate interoperability problems with other IPsec implementations.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4961,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec dropped an inbound packet that failed a replay check. If this problem persists, it could indicate a replay attack against this computer.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4962,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec dropped an inbound packet that failed a replay check. The inbound packet had too low a sequence number to ensure it was not a replay.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4963,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec dropped an inbound clear text packet that should have been secured. This is usually due to the remote computer changing its IPsec policy without informing this computer. This could also be a spoofing attack attempt.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4965,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec received a packet from a remote computer with an incorrect Security Parameter Index (SPI). This is usually caused by malfunctioning hardware that is corrupting packets. If these errors persist, verify that the packets sent from the remote computer are the same as those received by this computer. This error may also indicate interoperability problems with other IPsec implementations. In that case, if connectivity is not impeded, then these events can be ignored.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4976,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"During Main Mode negotiation, IPsec received an invalid negotiation packet. If this problem persists, it could indicate a network issue or an attempt to modify or replay this negotiation.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4977,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"During Quick Mode negotiation, IPsec received an invalid negotiation packet. If this problem persists, it could indicate a network issue or an attempt to modify or replay this negotiation.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4978,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"During Extended Mode negotiation, IPsec received an invalid negotiation packet. If this problem persists, it could indicate a network issue or an attempt to modify or replay this negotiation.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4983,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"An IPsec Extended Mode negotiation failed. The corresponding Main Mode security association has been deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4984,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"An IPsec Extended Mode negotiation failed. The corresponding Main Mode security association has been deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5027,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Firewall Service was unable to retrieve the security policy from the local storage. The service will continue enforcing the current policy.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5028,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Firewall Service was unable to parse the new security policy. The service will continue with currently enforced policy.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5029,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Firewall Service failed to initialize the driver. The service will continue to enforce the current policy.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5030,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Firewall Service failed to start.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5035,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Firewall Driver failed to start.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5037,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Firewall Driver detected critical runtime error. Terminating.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5038,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5120,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"OCSP Responder Service Started\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5121,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"OCSP Responder Service Stopped\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5122,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"A configuration entry changed in OCSP Responder Service\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5123,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"A configuration entry changed in OCSP Responder Service\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5376,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Credential Manager credentials were backed up.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5377,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Credential Manager credentials were restored from a backup.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5453,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"An IPsec negotiation with a remote computer failed because the IKE and AuthIP IPsec Keying Modules (IKEEXT) service is not started.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5480,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec Services failed to get the complete list of network interfaces on the computer. This poses a potential security risk because some of the network interfaces may not get the protection provided by the applied IPsec filters. Use the IP Security Monitor snap-in to diagnose the problem.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5483,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec Services failed to initialize RPC server. IPsec Services could not be started.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5484,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec Services has experienced a critical failure and has been shut down. The shutdown of IPsec Services can put the computer at greater risk of network attack or expose the computer to potential security risks.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5485,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec Services failed to process some IPsec filters on a plug-and-play event for network interfaces. This poses a potential security risk because some of the network interfaces may not get the protection provided by the applied IPsec filters. Use the IP Security Monitor snap-in to diagnose the problem.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5827,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Netlogon service denied a vulnerable Netlogon secure channel connection from a machine account.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5828,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Netlogon service denied a vulnerable Netlogon secure channel connection using a trust account.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 6145,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"One or more errors occurred while processing security policy in the Group Policy objects.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 6273,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Network Policy Server denied access to a user.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 6274,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Network Policy Server discarded the request for a user.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 6275,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Network Policy Server discarded the accounting request for a user.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 6276,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Network Policy Server quarantined a user.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 6277,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 6278,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Network Policy Server granted full access to a user because the host met the defined health policy.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 6279,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Network Policy Server locked the user account due to repeated failed authentication attempts.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 6280,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Network Policy Server unlocked the user account.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": \\\"-\\\",\\r\\n    \\\"Legacy Windows Event ID\\\": 640,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"General account database changed\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": \\\"-\\\",\\r\\n    \\\"Legacy Windows Event ID\\\": 619,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Quality of Service Policy changed\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 24586,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"An error was encountered converting volume\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 24592,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"An attempt to automatically restart conversion on volume %2 failed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 24593,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Metadata write: Volume %2 returning errors while trying to modify metadata. If failures continue, decrypt volume\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 24594,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Metadata rebuild: An attempt to write a copy of metadata on volume %2 failed and may appear as disk corruption. If failures continue, decrypt volume.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4608,\\r\\n    \\\"Legacy Windows Event ID\\\": 512,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Windows is starting up.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4609,\\r\\n    \\\"Legacy Windows Event ID\\\": 513,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Windows is shutting down.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4610,\\r\\n    \\\"Legacy Windows Event ID\\\": 514,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An authentication package has been loaded by the Local Security Authority.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4611,\\r\\n    \\\"Legacy Windows Event ID\\\": 515,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A trusted logon process has been registered with the Local Security Authority.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4612,\\r\\n    \\\"Legacy Windows Event ID\\\": 516,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4614,\\r\\n    \\\"Legacy Windows Event ID\\\": 518,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A notification package has been loaded by the Security Account Manager.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4615,\\r\\n    \\\"Legacy Windows Event ID\\\": 519,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Invalid use of LPC port.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4616,\\r\\n    \\\"Legacy Windows Event ID\\\": 520,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The system time was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4622,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security package has been loaded by the Local Security Authority.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4624,\\r\\n    \\\"Legacy Windows Event ID\\\": \\\"528,540\\\",\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An account was successfully logged on.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4625,\\r\\n    \\\"Legacy Windows Event ID\\\": \\\"529-537,539\\\",\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An account failed to log on.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4634,\\r\\n    \\\"Legacy Windows Event ID\\\": 538,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An account was logged off.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4646,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"IKE DoS-prevention mode started.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4647,\\r\\n    \\\"Legacy Windows Event ID\\\": 551,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"User initiated logoff.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4648,\\r\\n    \\\"Legacy Windows Event ID\\\": 552,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A logon was attempted using explicit credentials.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4650,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An IPsec Main Mode security association was established. Extended Mode was not enabled. Certificate authentication was not used.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4651,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An IPsec Main Mode security association was established. Extended Mode was not enabled. A certificate was used for authentication.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4652,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An IPsec Main Mode negotiation failed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4653,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An IPsec Main Mode negotiation failed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4654,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An IPsec Quick Mode negotiation failed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4655,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An IPsec Main Mode security association ended.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4656,\\r\\n    \\\"Legacy Windows Event ID\\\": 560,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A handle to an object was requested.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4657,\\r\\n    \\\"Legacy Windows Event ID\\\": 567,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A registry value was modified.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4658,\\r\\n    \\\"Legacy Windows Event ID\\\": 562,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The handle to an object was closed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4659,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A handle to an object was requested with intent to delete.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4660,\\r\\n    \\\"Legacy Windows Event ID\\\": 564,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An object was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4661,\\r\\n    \\\"Legacy Windows Event ID\\\": 565,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A handle to an object was requested.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4662,\\r\\n    \\\"Legacy Windows Event ID\\\": 566,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An operation was performed on an object.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4663,\\r\\n    \\\"Legacy Windows Event ID\\\": 567,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An attempt was made to access an object.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4664,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An attempt was made to create a hard link.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4665,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An attempt was made to create an application client context.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4666,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An application attempted an operation:\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4667,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An application client context was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4668,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An application was initialized.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4670,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Permissions on an object were changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4671,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An application attempted to access a blocked ordinal through the TBS.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4672,\\r\\n    \\\"Legacy Windows Event ID\\\": 576,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Special privileges assigned to new logon.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4673,\\r\\n    \\\"Legacy Windows Event ID\\\": 577,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A privileged service was called.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4674,\\r\\n    \\\"Legacy Windows Event ID\\\": 578,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An operation was attempted on a privileged object.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4688,\\r\\n    \\\"Legacy Windows Event ID\\\": 592,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A new process has been created.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4689,\\r\\n    \\\"Legacy Windows Event ID\\\": 593,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A process has exited.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4690,\\r\\n    \\\"Legacy Windows Event ID\\\": 594,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An attempt was made to duplicate a handle to an object.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4691,\\r\\n    \\\"Legacy Windows Event ID\\\": 595,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Indirect access to an object was requested.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4694,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Protection of auditable protected data was attempted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4695,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Unprotection of auditable protected data was attempted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4696,\\r\\n    \\\"Legacy Windows Event ID\\\": 600,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A primary token was assigned to process.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4697,\\r\\n    \\\"Legacy Windows Event ID\\\": 601,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Attempt to install a service\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4698,\\r\\n    \\\"Legacy Windows Event ID\\\": 602,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A scheduled task was created.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4699,\\r\\n    \\\"Legacy Windows Event ID\\\": 602,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A scheduled task was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4700,\\r\\n    \\\"Legacy Windows Event ID\\\": 602,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A scheduled task was enabled.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4701,\\r\\n    \\\"Legacy Windows Event ID\\\": 602,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A scheduled task was disabled.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4702,\\r\\n    \\\"Legacy Windows Event ID\\\": 602,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A scheduled task was updated.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4704,\\r\\n    \\\"Legacy Windows Event ID\\\": 608,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A user right was assigned.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4705,\\r\\n    \\\"Legacy Windows Event ID\\\": 609,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A user right was removed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4707,\\r\\n    \\\"Legacy Windows Event ID\\\": 611,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A trust to a domain was removed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4709,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec Services was started.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4710,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec Services was disabled.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4711,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"May contain any one of the following: PAStore Engine applied locally cached copy of Active Directory storage IPsec policy on the computer. PAStore Engine applied Active Directory storage IPsec policy on the computer. PAStore Engine applied local registry storage IPsec policy on the computer. PAStore Engine failed to apply locally cached copy of Active Directory storage IPsec policy on the computer. PAStore Engine failed to apply Active Directory storage IPsec policy on the computer. PAStore Engine failed to apply local registry storage IPsec policy on the computer. PAStore Engine failed to apply some rules of the active IPsec policy on the computer. PAStore Engine failed to load directory storage IPsec policy on the computer. PAStore Engine loaded directory storage IPsec policy on the computer. PAStore Engine failed to load local storage IPsec policy on the computer. PAStore Engine loaded local storage IPsec policy on the computer.PAStore Engine polled for changes to the active IPsec policy and detected no changes.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4712,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec Services encountered a potentially serious failure.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4717,\\r\\n    \\\"Legacy Windows Event ID\\\": 621,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"System security access was granted to an account.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4718,\\r\\n    \\\"Legacy Windows Event ID\\\": 622,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"System security access was removed from an account.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4720,\\r\\n    \\\"Legacy Windows Event ID\\\": 624,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A user account was created.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4722,\\r\\n    \\\"Legacy Windows Event ID\\\": 626,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A user account was enabled.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4723,\\r\\n    \\\"Legacy Windows Event ID\\\": 627,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An attempt was made to change an account's password.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4725,\\r\\n    \\\"Legacy Windows Event ID\\\": 629,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A user account was disabled.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4726,\\r\\n    \\\"Legacy Windows Event ID\\\": 630,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A user account was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4728,\\r\\n    \\\"Legacy Windows Event ID\\\": 632,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was added to a security-enabled global group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4729,\\r\\n    \\\"Legacy Windows Event ID\\\": 633,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was removed from a security-enabled global group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4730,\\r\\n    \\\"Legacy Windows Event ID\\\": 634,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-enabled global group was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4731,\\r\\n    \\\"Legacy Windows Event ID\\\": 635,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-enabled local group was created.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4732,\\r\\n    \\\"Legacy Windows Event ID\\\": 636,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was added to a security-enabled local group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4733,\\r\\n    \\\"Legacy Windows Event ID\\\": 637,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was removed from a security-enabled local group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4734,\\r\\n    \\\"Legacy Windows Event ID\\\": 638,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-enabled local group was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4738,\\r\\n    \\\"Legacy Windows Event ID\\\": 642,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A user account was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4740,\\r\\n    \\\"Legacy Windows Event ID\\\": 644,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A user account was locked out.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4741,\\r\\n    \\\"Legacy Windows Event ID\\\": 645,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A computer account was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4742,\\r\\n    \\\"Legacy Windows Event ID\\\": 646,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A computer account was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4743,\\r\\n    \\\"Legacy Windows Event ID\\\": 647,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A computer account was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4744,\\r\\n    \\\"Legacy Windows Event ID\\\": 648,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-disabled local group was created.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4745,\\r\\n    \\\"Legacy Windows Event ID\\\": 649,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-disabled local group was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4746,\\r\\n    \\\"Legacy Windows Event ID\\\": 650,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was added to a security-disabled local group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4747,\\r\\n    \\\"Legacy Windows Event ID\\\": 651,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was removed from a security-disabled local group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4748,\\r\\n    \\\"Legacy Windows Event ID\\\": 652,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-disabled local group was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4749,\\r\\n    \\\"Legacy Windows Event ID\\\": 653,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-disabled global group was created.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4750,\\r\\n    \\\"Legacy Windows Event ID\\\": 654,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-disabled global group was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4751,\\r\\n    \\\"Legacy Windows Event ID\\\": 655,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was added to a security-disabled global group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4752,\\r\\n    \\\"Legacy Windows Event ID\\\": 656,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was removed from a security-disabled global group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4753,\\r\\n    \\\"Legacy Windows Event ID\\\": 657,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-disabled global group was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4756,\\r\\n    \\\"Legacy Windows Event ID\\\": 660,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was added to a security-enabled universal group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4757,\\r\\n    \\\"Legacy Windows Event ID\\\": 661,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was removed from a security-enabled universal group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4758,\\r\\n    \\\"Legacy Windows Event ID\\\": 662,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-enabled universal group was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4759,\\r\\n    \\\"Legacy Windows Event ID\\\": 663,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-disabled universal group was created.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4760,\\r\\n    \\\"Legacy Windows Event ID\\\": 664,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-disabled universal group was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4761,\\r\\n    \\\"Legacy Windows Event ID\\\": 665,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was added to a security-disabled universal group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4762,\\r\\n    \\\"Legacy Windows Event ID\\\": 666,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was removed from a security-disabled universal group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4767,\\r\\n    \\\"Legacy Windows Event ID\\\": 671,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A user account was unlocked.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4768,\\r\\n    \\\"Legacy Windows Event ID\\\": \\\"672,676\\\",\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A Kerberos authentication ticket (TGT) was requested.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4769,\\r\\n    \\\"Legacy Windows Event ID\\\": 673,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A Kerberos service ticket was requested.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4770,\\r\\n    \\\"Legacy Windows Event ID\\\": 674,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A Kerberos service ticket was renewed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4771,\\r\\n    \\\"Legacy Windows Event ID\\\": 675,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Kerberos pre-authentication failed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4772,\\r\\n    \\\"Legacy Windows Event ID\\\": 672,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A Kerberos authentication ticket request failed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4774,\\r\\n    \\\"Legacy Windows Event ID\\\": 678,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An account was mapped for logon.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4775,\\r\\n    \\\"Legacy Windows Event ID\\\": 679,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An account could not be mapped for logon.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4776,\\r\\n    \\\"Legacy Windows Event ID\\\": \\\"680,681\\\",\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The domain controller attempted to validate the credentials for an account.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4777,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The domain controller failed to validate the credentials for an account.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4778,\\r\\n    \\\"Legacy Windows Event ID\\\": 682,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A session was reconnected to a Window Station.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4779,\\r\\n    \\\"Legacy Windows Event ID\\\": 683,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A session was disconnected from a Window Station.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4781,\\r\\n    \\\"Legacy Windows Event ID\\\": 685,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The name of an account was changed:\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4782,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The password hash an account was accessed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4783,\\r\\n    \\\"Legacy Windows Event ID\\\": 667,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A basic application group was created.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4784,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A basic application group was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4785,\\r\\n    \\\"Legacy Windows Event ID\\\": 689,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was added to a basic application group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4786,\\r\\n    \\\"Legacy Windows Event ID\\\": 690,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was removed from a basic application group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4787,\\r\\n    \\\"Legacy Windows Event ID\\\": 691,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A nonmember was added to a basic application group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4788,\\r\\n    \\\"Legacy Windows Event ID\\\": 692,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A nonmember was removed from a basic application group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4789,\\r\\n    \\\"Legacy Windows Event ID\\\": 693,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A basic application group was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4790,\\r\\n    \\\"Legacy Windows Event ID\\\": 694,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An LDAP query group was created.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4793,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Password Policy Checking API was called.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4800,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The workstation was locked.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4801,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The workstation was unlocked.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4802,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The screen saver was invoked.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4803,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The screen saver was dismissed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4864,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A namespace collision was detected.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4869,\\r\\n    \\\"Legacy Windows Event ID\\\": 773,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services received a resubmitted certificate request.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4871,\\r\\n    \\\"Legacy Windows Event ID\\\": 775,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services received a request to publish the certificate revocation list (CRL).\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4872,\\r\\n    \\\"Legacy Windows Event ID\\\": 776,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services published the certificate revocation list (CRL).\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4873,\\r\\n    \\\"Legacy Windows Event ID\\\": 777,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A certificate request extension changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4874,\\r\\n    \\\"Legacy Windows Event ID\\\": 778,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"One or more certificate request attributes changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4875,\\r\\n    \\\"Legacy Windows Event ID\\\": 779,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services received a request to shut down.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4876,\\r\\n    \\\"Legacy Windows Event ID\\\": 780,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services backup started.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4877,\\r\\n    \\\"Legacy Windows Event ID\\\": 781,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services backup completed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4878,\\r\\n    \\\"Legacy Windows Event ID\\\": 782,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services restore started.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4879,\\r\\n    \\\"Legacy Windows Event ID\\\": 783,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services restore completed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4880,\\r\\n    \\\"Legacy Windows Event ID\\\": 784,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services started.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4881,\\r\\n    \\\"Legacy Windows Event ID\\\": 785,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services stopped.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4883,\\r\\n    \\\"Legacy Windows Event ID\\\": 787,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services retrieved an archived key.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4884,\\r\\n    \\\"Legacy Windows Event ID\\\": 788,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services imported a certificate into its database.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4886,\\r\\n    \\\"Legacy Windows Event ID\\\": 790,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services received a certificate request.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4887,\\r\\n    \\\"Legacy Windows Event ID\\\": 791,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services approved a certificate request and issued a certificate.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4888,\\r\\n    \\\"Legacy Windows Event ID\\\": 792,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services denied a certificate request.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4889,\\r\\n    \\\"Legacy Windows Event ID\\\": 793,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services set the status of a certificate request to pending.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4891,\\r\\n    \\\"Legacy Windows Event ID\\\": 795,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A configuration entry changed in Certificate Services.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4893,\\r\\n    \\\"Legacy Windows Event ID\\\": 797,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services archived a key.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4894,\\r\\n    \\\"Legacy Windows Event ID\\\": 798,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services imported and archived a key.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4895,\\r\\n    \\\"Legacy Windows Event ID\\\": 799,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services published the CA certificate to Active Directory Domain Services.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4898,\\r\\n    \\\"Legacy Windows Event ID\\\": 802,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services loaded a template.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4902,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Per-user audit policy table was created.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4904,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An attempt was made to register a security event source.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4905,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An attempt was made to unregister a security event source.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4909,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The local policy settings for the TBS were changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4910,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Group Policy settings for the TBS were changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4928,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An Active Directory replica source naming context was established.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4929,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An Active Directory replica source naming context was removed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4930,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An Active Directory replica source naming context was modified.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4931,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An Active Directory replica destination naming context was modified.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4932,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Synchronization of a replica of an Active Directory naming context has begun.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4933,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Synchronization of a replica of an Active Directory naming context has ended.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4934,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Attributes of an Active Directory object were replicated.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4935,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Replication failure begins.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4936,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Replication failure ends.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4937,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A lingering object was removed from a replica.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4944,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The following policy was active when the Windows Firewall started.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4945,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A rule was listed when the Windows Firewall started.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4946,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A change has been made to Windows Firewall exception list. A rule was added.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4947,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A change has been made to Windows Firewall exception list. A rule was modified.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4948,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A change has been made to Windows Firewall exception list. A rule was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4949,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Windows Firewall settings were restored to the default values.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4950,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A Windows Firewall setting has changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4951,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A rule has been ignored because its major version number was not recognized by Windows Firewall.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4952,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Parts of a rule have been ignored because its minor version number was not recognized by Windows Firewall. The other parts of the rule will be enforced.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4953,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A rule has been ignored by Windows Firewall because it could not parse the rule.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4954,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Windows Firewall Group Policy settings have changed. The new settings have been applied.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4956,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Windows Firewall has changed the active profile.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4957,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Windows Firewall did not apply the following rule:\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4958,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Windows Firewall did not apply the following rule because the rule referred to items not configured on this computer:\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4979,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec Main Mode and Extended Mode security associations were established.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4980,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec Main Mode and Extended Mode security associations were established.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4981,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec Main Mode and Extended Mode security associations were established.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4982,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec Main Mode and Extended Mode security associations were established.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4985,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The state of a transaction has changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5024,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Firewall Service has started successfully.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5025,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Firewall Service has been stopped.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5031,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Firewall Service blocked an application from accepting incoming connections on the network.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5032,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5033,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Firewall Driver has started successfully.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5034,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Firewall Driver has been stopped.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5039,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A registry key was virtualized.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5040,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A change has been made to IPsec settings. An Authentication Set was added.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5041,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A change has been made to IPsec settings. An Authentication Set was modified.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5042,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A change has been made to IPsec settings. An Authentication Set was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5043,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A change has been made to IPsec settings. A Connection Security Rule was added.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5044,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A change has been made to IPsec settings. A Connection Security Rule was modified.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5045,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A change has been made to IPsec settings. A Connection Security Rule was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5046,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A change has been made to IPsec settings. A Crypto Set was added.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5047,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A change has been made to IPsec settings. A Crypto Set was modified.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5048,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A change has been made to IPsec settings. A Crypto Set was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5050,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An attempt to programmatically disable the Windows Firewall using a call to InetFwProfile.FirewallEnabled(False)\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5051,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A file was virtualized.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5056,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A cryptographic self test was performed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5057,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A cryptographic primitive operation failed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5058,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Key file operation.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5059,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Key migration operation.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5060,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Verification operation failed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5061,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Cryptographic operation.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5062,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A kernel-mode cryptographic self test was performed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5063,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A cryptographic provider operation was attempted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5064,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A cryptographic context operation was attempted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5065,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A cryptographic context modification was attempted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5066,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A cryptographic function operation was attempted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5067,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A cryptographic function modification was attempted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5068,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A cryptographic function provider operation was attempted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5069,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A cryptographic function property operation was attempted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5070,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A cryptographic function property modification was attempted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5125,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A request was submitted to the OCSP Responder Service\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5126,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Signing Certificate was automatically updated by the OCSP Responder Service\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5127,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The OCSP Revocation Provider successfully updated the revocation information\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5136,\\r\\n    \\\"Legacy Windows Event ID\\\": 566,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A directory service object was modified.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5137,\\r\\n    \\\"Legacy Windows Event ID\\\": 566,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A directory service object was created.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5138,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A directory service object was undeleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5139,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A directory service object was moved.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5140,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A network share object was accessed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5141,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A directory service object was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5152,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Filtering Platform blocked a packet.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5153,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A more restrictive Windows Filtering Platform filter has blocked a packet.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5154,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5155,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5156,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Filtering Platform has allowed a connection.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5157,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Filtering Platform has blocked a connection.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5158,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Filtering Platform has permitted a bind to a local port.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5159,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Filtering Platform has blocked a bind to a local port.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5378,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The requested credentials delegation was disallowed by policy.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5440,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The following callout was present when the Windows Filtering Platform Base Filtering Engine started.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5441,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The following filter was present when the Windows Filtering Platform Base Filtering Engine started.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5442,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The following provider was present when the Windows Filtering Platform Base Filtering Engine started.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5443,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The following provider context was present when the Windows Filtering Platform Base Filtering Engine started.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5444,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The following sublayer was present when the Windows Filtering Platform Base Filtering Engine started.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5446,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A Windows Filtering Platform callout has been changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5447,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A Windows Filtering Platform filter has been changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5448,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A Windows Filtering Platform provider has been changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5449,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A Windows Filtering Platform provider context has been changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5450,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A Windows Filtering Platform sublayer has been changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5451,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An IPsec Quick Mode security association was established.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5452,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An IPsec Quick Mode security association ended.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5456,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine applied Active Directory storage IPsec policy on the computer.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5457,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine failed to apply Active Directory storage IPsec policy on the computer.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5458,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine applied locally cached copy of Active Directory storage IPsec policy on the computer.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5459,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine failed to apply locally cached copy of Active Directory storage IPsec policy on the computer.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5460,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine applied local registry storage IPsec policy on the computer.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5461,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine failed to apply local registry storage IPsec policy on the computer.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5462,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine failed to apply some rules of the active IPsec policy on the computer. Use the IP Security Monitor snap-in to diagnose the problem.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5463,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine polled for changes to the active IPsec policy and detected no changes.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5464,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine polled for changes to the active IPsec policy, detected changes, and applied them to IPsec Services.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5465,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine received a control for forced reloading of IPsec policy and processed the control successfully.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5466,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory cannot be reached, and will use the cached copy of the Active Directory IPsec policy instead. Any changes made to the Active Directory IPsec policy since the last poll could not be applied.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5467,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, and found no changes to the policy. The cached copy of the Active Directory IPsec policy is no longer being used.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5468,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, found changes to the policy, and applied those changes. The cached copy of the Active Directory IPsec policy is no longer being used.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5471,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine loaded local storage IPsec policy on the computer.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5472,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine failed to load local storage IPsec policy on the computer.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5473,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine loaded directory storage IPsec policy on the computer.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5474,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine failed to load directory storage IPsec policy on the computer.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5477,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine failed to add quick mode filter.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5479,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec Services has been shut down successfully. The shutdown of IPsec Services can put the computer at greater risk of network attack or expose the computer to potential security risks.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5632,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A request was made to authenticate to a wireless network.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5633,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A request was made to authenticate to a wired network.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5712,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A Remote Procedure Call (RPC) was attempted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5888,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An object in the COM+ Catalog was modified.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5889,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An object was deleted from the COM+ Catalog.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5890,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An object was added to the COM+ Catalog.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 6008,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The previous system shutdown was unexpected\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 6144,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Security policy in the Group Policy objects has been applied successfully.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 6272,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Network Policy Server granted access to a user.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": \\\"N/A\\\",\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A handle to an object was requested.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": \\\"N/A\\\",\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Object open for delete\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": \\\"N/A\\\",\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"User Account Type Changed\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": \\\"N/A\\\",\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec policy agent started\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": \\\"N/A\\\",\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec policy agent disabled\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": \\\"N/A\\\",\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec policy agent\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": \\\"N/A\\\",\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec policy agent encountered a potential serious failure\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 24577,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Encryption of volume started\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 24578,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Encryption of volume stopped\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 24579,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Encryption of volume completed\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 24580,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Decryption of volume started\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 24581,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Decryption of volume stopped\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 24582,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Decryption of volume completed\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 24583,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Conversion worker thread for volume started\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 24584,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Conversion worker thread for volume temporarily stopped\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 24588,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The conversion operation on volume %2 encountered a bad sector error. Please validate the data on this volume\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 24595,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Volume %2 contains bad clusters. These clusters will be skipped during conversion.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 24621,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Initial state check: Rolling volume conversion transaction on %2.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5049,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An IPsec Security Association was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5478,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec Services has started successfully.\\\"\\r\\n  }\\r\\n]\",\"transformers\":null}",
                                "size": 0,
                                "title": "Recommended Event IDs",
                                "showRefreshButton": true,
                                "showExportToExcel": true,
                                "queryType": 8,
                                "gridSettings": {
                                  "formatters": [
                                    {
                                      "columnMatch": "Legacy Windows Event ID",
                                      "formatter": 5
                                    }
                                  ],
                                  "rowLimit": 1000,
                                  "filter": true
                                }
                              },
                              "conditionalVisibility": {
                                "parameterName": "Logtype",
                                "comparison": "isEqualTo",
                                "value": "WE"
                              },
                              "name": "query - 14"
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "### Help\r\n\r\nThe events listed below are part of an ongoing MSTIC project that highlights logs and events that are related. This is meant to highlight potentially valuable events to ingest outside of the events configured above.\r\n\r\nFor more information on MSTIC, please see https://www.microsoft.com/security/blog/microsoft-security-intelligence/",
                                "style": "info"
                              },
                              "conditionalVisibility": {
                                "parameterName": "Help",
                                "comparison": "isEqualTo",
                                "value": "Yes"
                              },
                              "name": "OSSEM"
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "let OSSEM = externaldata(DataSource:string, Component:string, Source:string, Relationship:string, Target:string, OSSEMID:string, EventID:string, EventName:string, EventPlatform:string, LogSource:string, Filter:string, AuditCategory:string, SubCategory:string, Channel:string, EnableCommands:string, GPOAuditPolicy:string)[\r\n@'https://raw.githubusercontent.com/OTRF/OSSEM-DM/main/use-cases/mitre_attack/attack_events_mapping.csv'\r\n] with(format=\"csv\");\r\nOSSEM\r\n| where EventName !has 'linux' and EventName !has 'cloudtrail'",
                                "size": 2,
                                "title": "Potential Related Logs to Consider",
                                "timeContext": {
                                  "durationMs": 86400000
                                },
                                "showRefreshButton": true,
                                "showExportToExcel": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "crossComponentResources": [
                                  "{Workspace}"
                                ],
                                "gridSettings": {
                                  "formatters": [
                                    {
                                      "columnMatch": "$gen_group",
                                      "formatter": 0,
                                      "formatOptions": {
                                        "customColumnWidthSetting": "80.4286ch"
                                      }
                                    },
                                    {
                                      "columnMatch": "$gen_group",
                                      "formatter": 0,
                                      "formatOptions": {
                                        "customColumnWidthSetting": "80.4286ch"
                                      }
                                    }
                                  ],
                                  "rowLimit": 2000,
                                  "filter": true,
                                  "hierarchySettings": {
                                    "treeType": 1,
                                    "groupBy": [
                                      "LogSource",
                                      "EventName"
                                    ]
                                  }
                                }
                              },
                              "name": "query - 7"
                            }
                          ],
                          "exportParameters": true
                        },
                        "name": "WinEventIds"
                      },
                      {
                        "type": 1,
                        "content": {
                          "json": "### Help\r\n\r\nThis section allows for the naming of the newly configured DCR. This will be the name that the DCR takes on once it is created. In the event that multiple DCRs are required to cover all of the selected event IDs above, a second or third name box and deploy button will appear as needed.",
                          "style": "info"
                        },
                        "conditionalVisibility": {
                          "parameterName": "Help",
                          "comparison": "isEqualTo",
                          "value": "Yes"
                        },
                        "name": "CreateDCR"
                      },
                      {
                        "type": 9,
                        "content": {
                          "version": "KqlParameterItem/1.0",
                          "crossComponentResources": [
                            "{subscriptionId}"
                          ],
                          "parameters": [
                            {
                              "id": "47eb961c-27ac-42df-aa52-8ad9aa948312",
                              "version": "KqlParameterItem/1.0",
                              "name": "DeployWorkspace",
                              "label": "Deploy to Workspace",
                              "type": 5,
                              "query": "resources\r\n| where type == 'microsoft.operationalinsights/workspaces'\r\n| project id, name\r\n| order by name asc",
                              "crossComponentResources": [
                                "{subscriptionId}"
                              ],
                              "typeSettings": {
                                "additionalResourceOptions": []
                              },
                              "timeContext": {
                                "durationMs": 86400000
                              },
                              "queryType": 1,
                              "resourceType": "microsoft.resourcegraph/resources",
                              "value": null
                            },
                            {
                              "id": "a665804c-8d16-488d-9e4e-2a86ce795cde",
                              "version": "KqlParameterItem/1.0",
                              "name": "DWLocation",
                              "type": 1,
                              "query": "resources\r\n| where id has '{DeployWorkspace}'\r\n| project location",
                              "crossComponentResources": [
                                "{subscriptionId}"
                              ],
                              "isHiddenWhenLocked": true,
                              "timeContext": {
                                "durationMs": 86400000
                              },
                              "queryType": 1,
                              "resourceType": "microsoft.resourcegraph/resources"
                            },
                            {
                              "id": "5f4b913e-5fa9-49b3-8d9d-29670ea614bc",
                              "version": "KqlParameterItem/1.0",
                              "name": "DCE",
                              "type": 5,
                              "query": "resources\r\n| where type has 'Microsoft.Insights/dataCollectionEndpoints'\r\n| where location == '{DWLocation}'\r\n| project id, name\r\n| order by tolower(name) asc",
                              "crossComponentResources": [
                                "{subscriptionId}"
                              ],
                              "typeSettings": {
                                "additionalResourceOptions": [],
                                "showDefault": false
                              },
                              "timeContext": {
                                "durationMs": 86400000
                              },
                              "queryType": 1,
                              "resourceType": "microsoft.resourcegraph/resources",
                              "value": null
                            }
                          ],
                          "style": "above",
                          "queryType": 1,
                          "resourceType": "microsoft.resourcegraph/resources"
                        },
                        "name": "parameters - 15"
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "crossComponentResources": [
                                  "{subscriptionId}"
                                ],
                                "parameters": [
                                  {
                                    "id": "fc4dbf09-af20-40e4-a62a-0d6fd4e9ed8e",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "DCRName",
                                    "label": "DCR Name",
                                    "type": 1,
                                    "isRequired": true,
                                    "value": "",
                                    "timeContext": {
                                      "durationMs": 86400000
                                    }
                                  }
                                ],
                                "style": "above",
                                "queryType": 1,
                                "resourceType": "microsoft.resourcegraph/resources"
                              },
                              "customWidth": "10",
                              "name": "parameters - 0"
                            },
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "parameters": [
                                  {
                                    "id": "3cfb65d3-6b97-4c45-981c-0aa503ca3edd",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "DCR2Name",
                                    "label": "Second DCR Name",
                                    "type": 1,
                                    "isRequired": true,
                                    "value": "",
                                    "timeContext": {
                                      "durationMs": 86400000
                                    }
                                  }
                                ],
                                "style": "above",
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces"
                              },
                              "customWidth": "10",
                              "conditionalVisibility": {
                                "parameterName": "NSADCR2",
                                "comparison": "isNotEqualTo",
                                "value": "Blank"
                              },
                              "name": "parameters - 0 - Copy"
                            },
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "crossComponentResources": [
                                  "{subscriptionId}"
                                ],
                                "parameters": [
                                  {
                                    "id": "c30e325e-4bf1-40a0-9631-3ec7e9cce7fc",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "DCR3Name",
                                    "label": "Third DCR Name",
                                    "type": 1,
                                    "isRequired": true,
                                    "value": "NSAtest3",
                                    "timeContext": {
                                      "durationMs": 86400000
                                    }
                                  }
                                ],
                                "style": "above",
                                "queryType": 1,
                                "resourceType": "microsoft.resourcegraph/resources"
                              },
                              "customWidth": "80",
                              "conditionalVisibility": {
                                "parameterName": "NSADCR3",
                                "comparison": "isNotEqualTo",
                                "value": "Blank"
                              },
                              "name": "parameters - 0 - Copy - Copy"
                            },
                            {
                              "type": 11,
                              "content": {
                                "version": "LinkItem/1.0",
                                "style": "list",
                                "links": [
                                  {
                                    "id": "1e056a8d-d856-453b-9ae5-c574e36ebbdf",
                                    "linkTarget": "ArmAction",
                                    "linkLabel": "Deploy DCR",
                                    "style": "primary",
                                    "linkIsContextBlade": true,
                                    "armActionContext": {
                                      "path": "{subscriptionId}/resourceGroups/{DeployWorkspace:resourceGroup}/providers/Microsoft.Insights/dataCollectionRules/{DCRName}?api-version=2021-09-01-preview",
                                      "headers": [],
                                      "params": [],
                                      "body": "{\r\n    \"location\": \"{DWLocation}\",\r\n    \"properties\": {\r\n      \"dataCollectionEndpointId\": \"{DCE}\",\r\n      \"dataSources\": {\r\n        \"windowsEventLogs\": [\r\n          {\r\n            \"name\": \"eventLogsDataSource\",\r\n            \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n            ],\r\n            \"xPathQueries\": \r\n              {generatedJSON}\r\n            \r\n          }\r\n        ]\r\n      },\r\n      \"destinations\": {\r\n        \"logAnalytics\": [\r\n          {\r\n            \"workspaceResourceId\": \"{DeployWorkspace}\",\r\n            \"name\": \"{DeployWorkspace:name}\"\r\n          }\r\n        ]\r\n      },\r\n      \"dataFlows\": [\r\n        {\r\n          \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n          ],\r\n          \"destinations\": [\r\n            \"{DeployWorkspace:name}\"\r\n          ]\r\n        }\r\n      ]\r\n    }\r\n  }",
                                      "httpMethod": "PUT",
                                      "title": "Deploying New Windows DCR {DCRName}",
                                      "description": "This action will deploy DCR {DCRName} to {DeployWorkspace}\n\nThe EventsIDs to be collected are\n\n{merged}",
                                      "runLabel": "Deploy DCR"
                                    }
                                  }
                                ]
                              },
                              "customWidth": "10",
                              "name": "links - 2"
                            },
                            {
                              "type": 11,
                              "content": {
                                "version": "LinkItem/1.0",
                                "style": "list",
                                "links": [
                                  {
                                    "id": "65298513-c41b-49bb-bc8b-db3dca4b6b9e",
                                    "linkTarget": "ArmAction",
                                    "linkLabel": "Deploy Second DCR",
                                    "style": "primary",
                                    "linkIsContextBlade": true,
                                    "armActionContext": {
                                      "path": "{subscriptionId}/resourceGroups/{DeployWorkspace:resourceGroup}/providers/Microsoft.Insights/dataCollectionRules/{DCR2Name}?api-version=2021-09-01-preview",
                                      "headers": [],
                                      "params": [],
                                      "body": "{\r\n    \"location\": \"{DWLocation}\",\r\n    \"properties\": {\r\n      \"dataCollectionEndpointId\": \"{DCE}\",\r\n      \"dataSources\": {\r\n        \"windowsEventLogs\": [\r\n          {\r\n            \"name\": \"eventLogsDataSource\",\r\n            \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n            ],\r\n            \"xPathQueries\": \r\n              {NSADCR2}\r\n            \r\n          }\r\n        ]\r\n      },\r\n      \"destinations\": {\r\n        \"logAnalytics\": [\r\n          {\r\n            \"workspaceResourceId\": \"{DeployWorkspace}\",\r\n            \"name\": \"{DeployWorkspace:name}\"\r\n          }\r\n        ]\r\n      },\r\n      \"dataFlows\": [\r\n        {\r\n          \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n          ],\r\n          \"destinations\": [\r\n            \"{DeployWorkspace:name}\"\r\n          ]\r\n        }\r\n      ]\r\n    }\r\n  }",
                                      "httpMethod": "PUT",
                                      "title": "Deploying New Windows DCR {DCR2Name}",
                                      "description": "This action will deploy DCR {DCR2Name} to {DeployWorkspace}\n\nThe EventsIDs to be collected are\n\n{NSADCR2}",
                                      "runLabel": "Deploy DCR"
                                    }
                                  }
                                ]
                              },
                              "customWidth": "10",
                              "conditionalVisibility": {
                                "parameterName": "NSADCR2",
                                "comparison": "isNotEqualTo",
                                "value": "Blank"
                              },
                              "name": "NSA2"
                            },
                            {
                              "type": 11,
                              "content": {
                                "version": "LinkItem/1.0",
                                "style": "list",
                                "links": [
                                  {
                                    "id": "4a7e3161-1f30-42ea-bc8c-79a60c901e8c",
                                    "linkTarget": "ArmAction",
                                    "linkLabel": "Deploy Third DCR",
                                    "style": "primary",
                                    "linkIsContextBlade": true,
                                    "armActionContext": {
                                      "path": "{subscriptionId}/resourceGroups/{DeployWorkspace:resourceGroup}/providers/Microsoft.Insights/dataCollectionRules/{DCR3Name}?api-version=2021-09-01-preview",
                                      "headers": [],
                                      "params": [],
                                      "body": "{\r\n    \"location\": \"{DWLocation}\",\r\n    \"properties\": {\r\n      \"dataCollectionEndpointId\": \"{DCE}\",\r\n      \"dataSources\": {\r\n        \"windowsEventLogs\": [\r\n          {\r\n            \"name\": \"eventLogsDataSource\",\r\n            \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n            ],\r\n            \"xPathQueries\": \r\n              {NSADCR3}\r\n            \r\n          }\r\n        ]\r\n      },\r\n      \"destinations\": {\r\n        \"logAnalytics\": [\r\n          {\r\n            \"workspaceResourceId\": \"{DeployWorkspace}\",\r\n            \"name\": \"{DeployWorkspace:name}\"\r\n          }\r\n        ]\r\n      },\r\n      \"dataFlows\": [\r\n        {\r\n          \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n          ],\r\n          \"destinations\": [\r\n            \"{DeployWorkspace:name}\"\r\n          ]\r\n        }\r\n      ]\r\n    }\r\n  }",
                                      "httpMethod": "PUT",
                                      "title": "Deploying New Windows DCR {DCR3Name}",
                                      "description": "This action will deploy DCR {DCR3Name} to {DeployWorkspace}\n\nThe EventsIDs to be collected are\n\n{NSADCR3}",
                                      "runLabel": "Deploy DCR"
                                    }
                                  }
                                ]
                              },
                              "customWidth": "10",
                              "conditionalVisibility": {
                                "parameterName": "NSADCR3",
                                "comparison": "isNotEqualTo",
                                "value": "Blank"
                              },
                              "name": "NSA2 - Copy"
                            }
                          ]
                        },
                        "conditionalVisibility": {
                          "parameterName": "Logtype",
                          "comparison": "isEqualTo",
                          "value": "NSA"
                        },
                        "name": "NSA DCR"
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "crossComponentResources": [
                                  "{subscriptionId}"
                                ],
                                "parameters": [
                                  {
                                    "id": "fc4dbf09-af20-40e4-a62a-0d6fd4e9ed8e",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "DCRName",
                                    "label": "DCR Name",
                                    "type": 1,
                                    "isRequired": true,
                                    "value": "",
                                    "timeContext": {
                                      "durationMs": 86400000
                                    }
                                  }
                                ],
                                "style": "above",
                                "queryType": 1,
                                "resourceType": "microsoft.resourcegraph/resources"
                              },
                              "customWidth": "10",
                              "name": "parameters - 0"
                            },
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "crossComponentResources": [
                                  "{subscriptionId}"
                                ],
                                "parameters": [
                                  {
                                    "id": "be3b1230-d680-4f2d-a87b-22249d2ea886",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "DCR2Name",
                                    "label": "Second DCR Name",
                                    "type": 1,
                                    "isRequired": true,
                                    "value": "",
                                    "timeContext": {
                                      "durationMs": 86400000
                                    }
                                  }
                                ],
                                "style": "above",
                                "queryType": 1,
                                "resourceType": "microsoft.resourcegraph/resources"
                              },
                              "customWidth": "10",
                              "conditionalVisibility": {
                                "parameterName": "MITREDCR2",
                                "comparison": "isNotEqualTo",
                                "value": "Blank"
                              },
                              "name": "parameters - 0 - Copy"
                            },
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "crossComponentResources": [
                                  "{subscriptionId}"
                                ],
                                "parameters": [
                                  {
                                    "id": "4aa55f00-f47f-47b6-82f1-81261974488e",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "DCR3Name",
                                    "label": "Third DCR Name",
                                    "type": 1,
                                    "isRequired": true,
                                    "value": "Test5",
                                    "timeContext": {
                                      "durationMs": 86400000
                                    }
                                  }
                                ],
                                "style": "above",
                                "queryType": 1,
                                "resourceType": "microsoft.resourcegraph/resources"
                              },
                              "customWidth": "80",
                              "conditionalVisibility": {
                                "parameterName": "MITREDCR3",
                                "comparison": "isNotEqualTo",
                                "value": "Blank"
                              },
                              "name": "parameters - 0 - Copy - Copy"
                            },
                            {
                              "type": 11,
                              "content": {
                                "version": "LinkItem/1.0",
                                "style": "list",
                                "links": [
                                  {
                                    "id": "1e056a8d-d856-453b-9ae5-c574e36ebbdf",
                                    "linkTarget": "ArmAction",
                                    "linkLabel": "Deploy DCR",
                                    "style": "primary",
                                    "linkIsContextBlade": true,
                                    "armActionContext": {
                                      "path": "{subscriptionId}/resourceGroups/{DeployWorkspace:resourceGroup}/providers/Microsoft.Insights/dataCollectionRules/{DCRName}?api-version=2021-09-01-preview",
                                      "headers": [],
                                      "params": [],
                                      "body": "{\r\n    \"location\": \"{DWLocation}\",\r\n    \"properties\": {\r\n      \"dataCollectionEndpointId\": \"{DCE}\",\r\n      \"dataSources\": {\r\n        \"windowsEventLogs\": [\r\n          {\r\n            \"name\": \"eventLogsDataSource\",\r\n            \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n            ],\r\n            \"xPathQueries\": \r\n              {generatedJSONMitre}\r\n            \r\n          }\r\n        ]\r\n      },\r\n      \"destinations\": {\r\n        \"logAnalytics\": [\r\n          {\r\n            \"workspaceResourceId\": \"{DeployWorkspace}\",\r\n            \"name\": \"{DeployWorkspace:name}\"\r\n          }\r\n        ]\r\n      },\r\n      \"dataFlows\": [\r\n        {\r\n          \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n          ],\r\n          \"destinations\": [\r\n            \"{DeployWorkspace:name}\"\r\n          ]\r\n        }\r\n      ]\r\n    }\r\n  }",
                                      "httpMethod": "PUT",
                                      "title": "Deploying New Windows DCR {DCRName}",
                                      "description": "This action will deploy DCR {DCRName} to {DeployWorkspace}\n\nThe EventsIDs to be collected are\n\n{mergedMitre}",
                                      "runLabel": "Deploy DCR"
                                    }
                                  }
                                ]
                              },
                              "customWidth": "10",
                              "name": "links - 2"
                            },
                            {
                              "type": 11,
                              "content": {
                                "version": "LinkItem/1.0",
                                "style": "list",
                                "links": [
                                  {
                                    "id": "7410ff3d-e9af-48f6-a85a-d5bef8ab65d1",
                                    "linkTarget": "ArmAction",
                                    "linkLabel": "Deploy Second DCR",
                                    "style": "primary",
                                    "linkIsContextBlade": true,
                                    "armActionContext": {
                                      "path": "{subscriptionId}/resourceGroups/{DeployWorkspace:resourceGroup}/providers/Microsoft.Insights/dataCollectionRules/{DCR2Name}?api-version=2021-09-01-preview",
                                      "headers": [],
                                      "params": [],
                                      "body": "{\r\n    \"location\": \"{DWLocation}\",\r\n    \"properties\": {\r\n      \"dataCollectionEndpointId\": \"{DCE}\",\r\n      \"dataSources\": {\r\n        \"windowsEventLogs\": [\r\n          {\r\n            \"name\": \"eventLogsDataSource\",\r\n            \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n            ],\r\n            \"xPathQueries\": \r\n              {MITREDCR2}\r\n            \r\n          }\r\n        ]\r\n      },\r\n      \"destinations\": {\r\n        \"logAnalytics\": [\r\n          {\r\n            \"workspaceResourceId\": \"{DeployWorkspace}\",\r\n            \"name\": \"{DeployWorkspace:name}\"\r\n          }\r\n        ]\r\n      },\r\n      \"dataFlows\": [\r\n        {\r\n          \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n          ],\r\n          \"destinations\": [\r\n            \"{DeployWorkspace:name}\"\r\n          ]\r\n        }\r\n      ]\r\n    }\r\n  }",
                                      "httpMethod": "PUT",
                                      "title": "Deploying New Windows DCR {DCR2Name}",
                                      "description": "This action will deploy DCR {DCR2Name} to {DeployWorkspace}\n\nThe EventsIDs to be collected are\n\n{MITREDCR2}",
                                      "runLabel": "Deploy DCR"
                                    }
                                  }
                                ]
                              },
                              "customWidth": "10",
                              "conditionalVisibility": {
                                "parameterName": "MITREDCR2",
                                "comparison": "isNotEqualTo",
                                "value": "Blank"
                              },
                              "name": "links - 2 - Copy"
                            },
                            {
                              "type": 11,
                              "content": {
                                "version": "LinkItem/1.0",
                                "style": "list",
                                "links": [
                                  {
                                    "id": "37cb7a50-b0b1-4d73-9701-29b3614c19a7",
                                    "linkTarget": "ArmAction",
                                    "linkLabel": "Deploy Third DCR",
                                    "style": "primary",
                                    "linkIsContextBlade": true,
                                    "armActionContext": {
                                      "path": "{subscriptionId}/resourceGroups/{DeployWorkspace:resourceGroup}/providers/Microsoft.Insights/dataCollectionRules/{DCR3Name}?api-version=2021-09-01-preview",
                                      "headers": [],
                                      "params": [],
                                      "body": "{\r\n    \"location\": \"{DWLocation}\",\r\n    \"properties\": {\r\n      \"dataCollectionEndpointId\": \"{DCE}\",\r\n      \"dataSources\": {\r\n        \"windowsEventLogs\": [\r\n          {\r\n            \"name\": \"eventLogsDataSource\",\r\n            \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n            ],\r\n            \"xPathQueries\": \r\n              {MITREDCR3}\r\n            \r\n          }\r\n        ]\r\n      },\r\n      \"destinations\": {\r\n        \"logAnalytics\": [\r\n          {\r\n            \"workspaceResourceId\": \"{DeployWorkspace}\",\r\n            \"name\": \"{DeployWorkspace:name}\"\r\n          }\r\n        ]\r\n      },\r\n      \"dataFlows\": [\r\n        {\r\n          \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n          ],\r\n          \"destinations\": [\r\n            \"{DeployWorkspace:name}\"\r\n          ]\r\n        }\r\n      ]\r\n    }\r\n  }",
                                      "httpMethod": "PUT",
                                      "title": "Deploying New Windows DCR {DCR3Name}",
                                      "description": "This action will deploy DCR {DCR3Name} to {DeployWorkspace}\n\nThe EventsIDs to be collected are\n\n{MITREDCR3}",
                                      "runLabel": "Deploy DCR"
                                    }
                                  }
                                ]
                              },
                              "customWidth": "10",
                              "conditionalVisibility": {
                                "parameterName": "MITREDCR3",
                                "comparison": "isNotEqualTo",
                                "value": "Blank"
                              },
                              "name": "links - 2 - Copy - Copy"
                            }
                          ]
                        },
                        "conditionalVisibility": {
                          "parameterName": "Logtype",
                          "comparison": "isEqualTo",
                          "value": "MITRE"
                        },
                        "name": "MITRE DCR"
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "crossComponentResources": [
                                  "{subscriptionId}"
                                ],
                                "parameters": [
                                  {
                                    "id": "fc4dbf09-af20-40e4-a62a-0d6fd4e9ed8e",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "DCRName",
                                    "label": "DCR Name",
                                    "type": 1,
                                    "isRequired": true,
                                    "value": "",
                                    "timeContext": {
                                      "durationMs": 86400000
                                    }
                                  }
                                ],
                                "style": "above",
                                "queryType": 1,
                                "resourceType": "microsoft.resourcegraph/resources"
                              },
                              "customWidth": "10",
                              "name": "parameters - 0"
                            },
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "crossComponentResources": [
                                  "{subscriptionId}"
                                ],
                                "parameters": [
                                  {
                                    "id": "be3b1230-d680-4f2d-a87b-22249d2ea886",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "DCR2Name",
                                    "label": "Second DCR Name",
                                    "type": 1,
                                    "isRequired": true,
                                    "value": "",
                                    "timeContext": {
                                      "durationMs": 86400000
                                    }
                                  }
                                ],
                                "style": "above",
                                "queryType": 1,
                                "resourceType": "microsoft.resourcegraph/resources"
                              },
                              "customWidth": "10",
                              "conditionalVisibility": {
                                "parameterName": "MSFTDCR2",
                                "comparison": "isNotEqualTo",
                                "value": "Blank"
                              },
                              "name": "parameters - 0 - Copy"
                            },
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "crossComponentResources": [
                                  "{subscriptionId}"
                                ],
                                "parameters": [
                                  {
                                    "id": "4aa55f00-f47f-47b6-82f1-81261974488e",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "DCR3Name",
                                    "label": "Third DCR Name",
                                    "type": 1,
                                    "isRequired": true,
                                    "value": "",
                                    "timeContext": {
                                      "durationMs": 86400000
                                    }
                                  }
                                ],
                                "style": "above",
                                "queryType": 1,
                                "resourceType": "microsoft.resourcegraph/resources"
                              },
                              "customWidth": "10",
                              "conditionalVisibility": {
                                "parameterName": "MSFTDCR3",
                                "comparison": "isNotEqualTo",
                                "value": "Blank"
                              },
                              "name": "parameters - 0 - Copy - Copy"
                            },
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "crossComponentResources": [
                                  "{subscriptionId}"
                                ],
                                "parameters": [
                                  {
                                    "id": "94235ed9-ef74-4a4b-90d5-e5462719b705",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "DCR4Name",
                                    "label": "Fourth DCR Name",
                                    "type": 1,
                                    "isRequired": true,
                                    "value": "",
                                    "timeContext": {
                                      "durationMs": 86400000
                                    }
                                  }
                                ],
                                "style": "above",
                                "queryType": 1,
                                "resourceType": "microsoft.resourcegraph/resources"
                              },
                              "customWidth": "70",
                              "conditionalVisibility": {
                                "parameterName": "MSFTDCR4",
                                "comparison": "isNotEqualTo",
                                "value": "Blank"
                              },
                              "name": "parameters - 0 - Copy - Copy - Copy"
                            },
                            {
                              "type": 11,
                              "content": {
                                "version": "LinkItem/1.0",
                                "style": "list",
                                "links": [
                                  {
                                    "id": "1e056a8d-d856-453b-9ae5-c574e36ebbdf",
                                    "linkTarget": "ArmAction",
                                    "linkLabel": "Deploy DCR",
                                    "style": "primary",
                                    "linkIsContextBlade": true,
                                    "armActionContext": {
                                      "path": "{subscriptionId}/resourceGroups/{DeployWorkspace:resourceGroup}/providers/Microsoft.Insights/dataCollectionRules/{DCRName}?api-version=2021-09-01-preview",
                                      "headers": [],
                                      "params": [],
                                      "body": "{\r\n    \"location\": \"{DWLocation}\",\r\n    \"properties\": {\r\n      \"dataCollectionEndpointId\": \"{DCE}\",\r\n      \"dataSources\": {\r\n        \"windowsEventLogs\": [\r\n          {\r\n            \"name\": \"eventLogsDataSource\",\r\n            \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n            ],\r\n            \"xPathQueries\": \r\n              {generatedJSONMsft}\r\n            \r\n          }\r\n        ]\r\n      },\r\n      \"destinations\": {\r\n        \"logAnalytics\": [\r\n          {\r\n            \"workspaceResourceId\": \"{DeployWorkspace}\",\r\n            \"name\": \"{DeployWorkspace:name}\"\r\n          }\r\n        ]\r\n      },\r\n      \"dataFlows\": [\r\n        {\r\n          \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n          ],\r\n          \"destinations\": [\r\n            \"{DeployWorkspace:name}\"\r\n          ]\r\n        }\r\n      ]\r\n    }\r\n  }",
                                      "httpMethod": "PUT",
                                      "title": "Deploying New Windows DCR {DCRName}",
                                      "description": "This action will deploy DCR {DCRName} to {DeployWorkspace}\n\nThe EventsIDs to be collected are\n\n{generatedJSONMsft}",
                                      "runLabel": "Deploy DCR"
                                    }
                                  }
                                ]
                              },
                              "customWidth": "10",
                              "name": "links - 2"
                            },
                            {
                              "type": 11,
                              "content": {
                                "version": "LinkItem/1.0",
                                "style": "list",
                                "links": [
                                  {
                                    "id": "7410ff3d-e9af-48f6-a85a-d5bef8ab65d1",
                                    "linkTarget": "ArmAction",
                                    "linkLabel": "Deploy Second DCR",
                                    "style": "primary",
                                    "linkIsContextBlade": true,
                                    "armActionContext": {
                                      "path": "{subscriptionId}/resourceGroups/{DeployWorkspace:resourceGroup}/providers/Microsoft.Insights/dataCollectionRules/{DCR2Name}?api-version=2021-09-01-preview",
                                      "headers": [],
                                      "params": [],
                                      "body": "{\r\n    \"location\": \"{DWLocation}\",\r\n    \"properties\": {\r\n      \"dataCollectionEndpointId\": \"{DCE}\",\r\n      \"dataSources\": {\r\n        \"windowsEventLogs\": [\r\n          {\r\n            \"name\": \"eventLogsDataSource\",\r\n            \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n            ],\r\n            \"xPathQueries\": \r\n              {MSFTDCR2}\r\n            \r\n          }\r\n        ]\r\n      },\r\n      \"destinations\": {\r\n        \"logAnalytics\": [\r\n          {\r\n            \"workspaceResourceId\": \"{DeployWorkspace}\",\r\n            \"name\": \"{DeployWorkspace:name}\"\r\n          }\r\n        ]\r\n      },\r\n      \"dataFlows\": [\r\n        {\r\n          \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n          ],\r\n          \"destinations\": [\r\n            \"{DeployWorkspace:name}\"\r\n          ]\r\n        }\r\n      ]\r\n    }\r\n  }",
                                      "httpMethod": "PUT",
                                      "title": "Deploying New Windows DCR {DCR2Name}",
                                      "description": "This action will deploy DCR {DCR2Name} to {DeployWorkspace}\n\nThe EventsIDs to be collected are\n\n{MSFTDCR2}",
                                      "runLabel": "Deploy DCR"
                                    }
                                  }
                                ]
                              },
                              "customWidth": "10",
                              "conditionalVisibility": {
                                "parameterName": "MSFTDCR2",
                                "comparison": "isNotEqualTo",
                                "value": "Blank"
                              },
                              "name": "links - 2 - Copy"
                            },
                            {
                              "type": 11,
                              "content": {
                                "version": "LinkItem/1.0",
                                "style": "list",
                                "links": [
                                  {
                                    "id": "37cb7a50-b0b1-4d73-9701-29b3614c19a7",
                                    "linkTarget": "ArmAction",
                                    "linkLabel": "Deploy Third DCR",
                                    "style": "primary",
                                    "linkIsContextBlade": true,
                                    "armActionContext": {
                                      "path": "{subscriptionId}/resourceGroups/{DeployWorkspace:resourceGroup}/providers/Microsoft.Insights/dataCollectionRules/{DCR3Name}?api-version=2021-09-01-preview",
                                      "headers": [],
                                      "params": [],
                                      "body": "{\r\n    \"location\": \"{DWLocation}\",\r\n    \"properties\": {\r\n      \"dataCollectionEndpointId\": \"{DCE}\",\r\n      \"dataSources\": {\r\n        \"windowsEventLogs\": [\r\n          {\r\n            \"name\": \"eventLogsDataSource\",\r\n            \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n            ],\r\n            \"xPathQueries\": \r\n              {MSFTDCR3}\r\n            \r\n          }\r\n        ]\r\n      },\r\n      \"destinations\": {\r\n        \"logAnalytics\": [\r\n          {\r\n            \"workspaceResourceId\": \"{DeployWorkspace}\",\r\n            \"name\": \"{DeployWorkspace:name}\"\r\n          }\r\n        ]\r\n      },\r\n      \"dataFlows\": [\r\n        {\r\n          \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n          ],\r\n          \"destinations\": [\r\n            \"{DeployWorkspace:name}\"\r\n          ]\r\n        }\r\n      ]\r\n    }\r\n  }",
                                      "httpMethod": "PUT",
                                      "title": "Deploying New Windows DCR {DCR3Name}",
                                      "description": "This action will deploy DCR {DCR3Name} to {DeployWorkspace}\n\nThe EventsIDs to be collected are\n\n{MSFTDCR3}",
                                      "runLabel": "Deploy DCR"
                                    }
                                  }
                                ]
                              },
                              "customWidth": "10",
                              "conditionalVisibility": {
                                "parameterName": "MSFTDCR3",
                                "comparison": "isNotEqualTo",
                                "value": "Blank"
                              },
                              "name": "links - 2 - Copy - Copy"
                            },
                            {
                              "type": 11,
                              "content": {
                                "version": "LinkItem/1.0",
                                "style": "list",
                                "links": [
                                  {
                                    "id": "c409542b-1e7c-45f0-81d0-6fde97fcdafb",
                                    "linkTarget": "ArmAction",
                                    "linkLabel": "Deploy Fourth DCR",
                                    "style": "primary",
                                    "linkIsContextBlade": true,
                                    "armActionContext": {
                                      "path": "{subscriptionId}/resourceGroups/{DeployWorkspace:resourceGroup}/providers/Microsoft.Insights/dataCollectionRules/{DCR4Name}?api-version=2021-09-01-preview",
                                      "headers": [],
                                      "params": [],
                                      "body": "{\r\n    \"location\": \"{DWLocation}\",\r\n    \"properties\": {\r\n      \"dataCollectionEndpointId\": \"{DCE}\",\r\n      \"dataSources\": {\r\n        \"windowsEventLogs\": [\r\n          {\r\n            \"name\": \"eventLogsDataSource\",\r\n            \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n            ],\r\n            \"xPathQueries\": \r\n              {MSFTDCR4}\r\n            \r\n          }\r\n        ]\r\n      },\r\n      \"destinations\": {\r\n        \"logAnalytics\": [\r\n          {\r\n            \"workspaceResourceId\": \"{DeployWorkspace}\",\r\n            \"name\": \"{DeployWorkspace:name}\"\r\n          }\r\n        ]\r\n      },\r\n      \"dataFlows\": [\r\n        {\r\n          \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n          ],\r\n          \"destinations\": [\r\n            \"{DeployWorkspace:name}\"\r\n          ]\r\n        }\r\n      ]\r\n    }\r\n  }",
                                      "httpMethod": "PUT",
                                      "title": "Deploying New Windows DCR {DCR4Name}",
                                      "description": "This action will deploy DCR {DCR4Name} to {DeployWorkspace}\n\nThe EventsIDs to be collected are\n\n{MSFTDCR4}",
                                      "runLabel": "Deploy DCR"
                                    }
                                  }
                                ]
                              },
                              "customWidth": "10",
                              "conditionalVisibility": {
                                "parameterName": "MSFTDCR4",
                                "comparison": "isNotEqualTo",
                                "value": "Blank"
                              },
                              "name": "links - 2 - Copy - Copy - Copy"
                            }
                          ]
                        },
                        "conditionalVisibility": {
                          "parameterName": "Logtype",
                          "comparison": "isEqualTo",
                          "value": "WE"
                        },
                        "name": "RecommDCR"
                      }
                    ]
                  },
                  "conditionalVisibilities": [
                    {
                      "parameterName": "Tab",
                      "comparison": "isEqualTo",
                      "value": "1"
                    },
                    {
                      "parameterName": "Datatype",
                      "comparison": "isEqualTo",
                      "value": "Windows"
                    }
                  ],
                  "name": "WindowsDCR"
                },
                {
                  "type": 9,
                  "content": {
                    "version": "KqlParameterItem/1.0",
                    "parameters": [
                      {
                        "id": "1e0ab773-f754-4ea6-a2d6-eed51e8cd13e",
                        "version": "KqlParameterItem/1.0",
                        "name": "UEBAEssentials",
                        "type": 1,
                        "query": "let ueba = datatable(EventID:int)[4720, 4722, 4723, 4724, 4725, 4726, 4728, 4740, 4624, 4625, 4672, 4732, 4756, 4756, 4767,];\r\nueba\r\n| order by EventID asc",
                        "isHiddenWhenLocked": true,
                        "timeContext": {
                          "durationMs": 86400000
                        },
                        "queryType": 0,
                        "resourceType": "microsoft.operationalinsights/workspaces"
                      },
                      {
                        "id": "bbe92878-9d9c-454d-94b2-c5c03f202c35",
                        "version": "KqlParameterItem/1.0",
                        "name": "AREssentials",
                        "type": 1,
                        "query": "let ar = datatable(EventID:int)[4624, 4625, 4656, 4662, 4663, 4688, 4722, 4723,4725, 4731, 4732, 4733, 4724, 4728, 4729,4756, 4757,4769, 4738, 501, 412, 5156, 18, 3, 5136, 7, 1, 17,11, 7045, 10, 5136, 5145, 4754, 4727, 4657, 13, 4697, 4698, 4699, 4700, 4701, 4702,1102, 1006, 1009, 1116, 1119, 4670, 4720];\r\nar\r\n| order by EventID asc",
                        "isHiddenWhenLocked": true,
                        "timeContext": {
                          "durationMs": 86400000
                        },
                        "queryType": 0,
                        "resourceType": "microsoft.operationalinsights/workspaces"
                      },
                      {
                        "version": "KqlParameterItem/1.0",
                        "name": "HuntingEssentials",
                        "type": 1,
                        "query": "let ar = datatable(EventID:int)[4624, 4625, 4688, 4720, 4723, 4724, 4726, 4727, 4728, 4729, 4731, 4732, 4733, 4740, 4746, 4747, 4751, 4752, 4754, 4756, 4761, 4762, 4769, 4776, 7045];\r\nar\r\n| order by EventID asc",
                        "isHiddenWhenLocked": true,
                        "timeContext": {
                          "durationMs": 86400000
                        },
                        "queryType": 0,
                        "resourceType": "microsoft.operationalinsights/workspaces",
                        "id": "3942b6cf-dd5b-4139-95a9-ea41e2e74047"
                      }
                    ],
                    "style": "pills",
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces"
                  },
                  "name": "parameters - 6"
                },
                {
                  "type": 12,
                  "content": {
                    "version": "NotebookGroup/1.0",
                    "groupType": "editable",
                    "items": [
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "title": "Create a Custom Table",
                          "expandable": true,
                          "items": [
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "crossComponentResources": [
                                  "{subscriptionId}"
                                ],
                                "parameters": [
                                  {
                                    "id": "b932de02-219a-4aaf-a88b-8ba1743ef41c",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "TableName",
                                    "type": 1,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "value": "EventHubTest2"
                                  },
                                  {
                                    "id": "a1549def-4c92-44d4-8047-866bafb0599b",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "WSRetention",
                                    "type": 1,
                                    "query": "resources\r\n| where id == '{Workspace}'\r\n| project properties.retentionInDays",
                                    "crossComponentResources": [
                                      "{subscriptionId}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "queryType": 1,
                                    "resourceType": "microsoft.resourcegraph/resources"
                                  }
                                ],
                                "style": "above",
                                "queryType": 1,
                                "resourceType": "microsoft.resourcegraph/resources"
                              },
                              "name": "parameters - 2"
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "### Useful Information\r\n\r\nThis step will create a new custom table that will ingest the data from the configured Event Hub. This table will require:\r\n1. A name\r\n2. Columns of the table\r\n- If the columns are known, they can be entered. By default, the columns will be TimeGenerated, RawData, and Properties. The data will then need to be parsed at ingestion time.\r\n3. Table retention\r\n\r\nBelow are values that can be used within the template. \r\n\r\n#### New Table Name: {TableName} </br>\r\n#### Selected Workspace Retention: {WSRetention}\r\n*When using Microsoft Sentinel, retention can be set to 90 days without extra cost. If the selected workspace has retention under 90 days, it can be increased to 90 days without extra cost.*\r\n\r\n*Note*: totalRetentionInDays represents the *total* number of days the data will exist in the workspace. </br> archiveRetentionInDays will be difference value found by using totalRetentionInDays - retentionInDays",
                                "style": "upsell"
                              },
                              "customWidth": "10",
                              "name": "text - 3"
                            },
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "parameters": [
                                  {
                                    "id": "1a45ac0c-5919-4d55-a1b2-8ae429ed6b19",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "Template",
                                    "type": 1,
                                    "typeSettings": {
                                      "multiLineText": true,
                                      "editorLanguage": "json",
                                      "multiLineHeight": 30
                                    },
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "value": "{\r\n    \"properties\": {\r\n        \"schema\": {\r\n            \"name\": \"EventHubTest2_CL\",\r\n            \"columns\": [\r\n                {\r\n                    \"name\": \"TimeGenerated\",\r\n                    \"type\": \"datetime\",\r\n                    \"description\": \"The time at which the data was ingested.\"\r\n                },\r\n                {\r\n                    \"name\": \"RawData\",\r\n                    \"type\": \"string\",\r\n                    \"description\": \"Body of the event.\"\r\n                },\r\n                {\r\n                    \"name\": \"Properties\",\r\n                    \"type\": \"dynamic\",\r\n                    \"description\": \"Additional message properties.\"\r\n                }\r\n            ]\r\n        },\r\n\t\t\"provisioningState\": \"Succeeded\",\r\n\t\t\"retentionInDays\": 90,\r\n\t\t\"totalRetentionInDays\": 90,\r\n\t\t\"archiveRetentionInDays\": 0,\r\n\t\t\"plan\": \"Analytics\"\r\n    }\r\n}"
                                  }
                                ],
                                "style": "above",
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces"
                              },
                              "customWidth": "90",
                              "name": "parameters - 1"
                            },
                            {
                              "type": 11,
                              "content": {
                                "version": "LinkItem/1.0",
                                "style": "paragraph",
                                "links": [
                                  {
                                    "id": "17a15e27-332e-45c9-8aab-2fab13bc7733",
                                    "linkTarget": "ArmAction",
                                    "linkLabel": "Deploy Table",
                                    "style": "primary",
                                    "linkIsContextBlade": true,
                                    "armActionContext": {
                                      "path": "{Workspace}/tables/{TableName}_CL?api-version=2022-10-01",
                                      "headers": [],
                                      "params": [],
                                      "body": "{Template}",
                                      "httpMethod": "PUT",
                                      "title": "Create Table Called {TableName}?",
                                      "description": "This action will create a new custom table based on the template below. Please confirm the name and columns are all the desired values.\n\n```json\n{Template}\n```\n-------\n### Populated Value\n```\nTable Name: {TableName}\n```",
                                      "runLabel": "Create Table"
                                    }
                                  },
                                  {
                                    "id": "abb0b9c4-4628-4a2e-a019-a28484b75c18",
                                    "linkTarget": "OpenBlade",
                                    "linkLabel": "Confirm Table Creation",
                                    "style": "primary",
                                    "linkIsContextBlade": true,
                                    "bladeOpenContext": {
                                      "bladeName": "TablesBlade",
                                      "extensionName": "Microsoft_OperationsManagementSuite_Workspace",
                                      "bladeJsonParameters": "{\r\n    \"workspaceResourceId\": \"{Workspace}\"\r\n}"
                                    }
                                  }
                                ]
                              },
                              "name": "links - 2"
                            }
                          ],
                          "exportParameters": true
                        },
                        "name": "Step One",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "title": "Create or Fetch Data Collection Components",
                          "expandable": true,
                          "expanded": true,
                          "items": [
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "parameters": [
                                  {
                                    "id": "ba661c91-0525-49e6-b9b4-3332cc7b8334",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "DCEExist",
                                    "label": "Data Collection Endpoint Exists?",
                                    "type": 10,
                                    "isRequired": true,
                                    "typeSettings": {
                                      "additionalResourceOptions": []
                                    },
                                    "jsonData": "[\"Yes\", \"No\"]",
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "value": "Yes"
                                  }
                                ],
                                "style": "formVertical",
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces"
                              },
                              "name": "parameters - 0"
                            },
                            {
                              "type": 11,
                              "content": {
                                "version": "LinkItem/1.0",
                                "style": "list",
                                "links": [
                                  {
                                    "id": "4183cdb6-55d9-41d0-8113-94a566c156ff",
                                    "linkTarget": "OpenBlade",
                                    "linkLabel": "Create Data Collection Endpoint",
                                    "style": "primary",
                                    "linkIsContextBlade": true,
                                    "bladeOpenContext": {
                                      "bladeName": "CreateDataCollectionEndpointViewModel",
                                      "extensionName": "Microsoft_Azure_Monitoring",
                                      "bladeParameters": []
                                    }
                                  }
                                ]
                              },
                              "conditionalVisibility": {
                                "parameterName": "DCEExist",
                                "comparison": "isEqualTo",
                                "value": "No"
                              },
                              "name": "links - 1"
                            },
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "crossComponentResources": [
                                  "{subscriptionId}"
                                ],
                                "parameters": [
                                  {
                                    "id": "5447d679-515a-4483-9329-687f2d40f508",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "SelectedDCE",
                                    "label": "Select Data Collection Endpoint",
                                    "type": 5,
                                    "query": "resources\r\n| where type == \"microsoft.insights/datacollectionendpoints\"\r\n| where location == '{WSLocation}'\r\n| project id, name",
                                    "crossComponentResources": [
                                      "{subscriptionId}"
                                    ],
                                    "typeSettings": {
                                      "additionalResourceOptions": [],
                                      "showDefault": false
                                    },
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 1,
                                    "resourceType": "microsoft.resourcegraph/resources",
                                    "value": ""
                                  }
                                ],
                                "style": "formVertical",
                                "queryType": 1,
                                "resourceType": "microsoft.resourcegraph/resources"
                              },
                              "conditionalVisibility": {
                                "parameterName": "DCEExist",
                                "comparison": "isEqualTo",
                                "value": "Yes"
                              },
                              "name": "parameters - 2"
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "---------------------"
                              },
                              "name": "text - 3"
                            },
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "parameters": [
                                  {
                                    "id": "ba661c91-0525-49e6-b9b4-3332cc7b8334",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "DCRExist",
                                    "label": "Data Collection Rule Exists?",
                                    "type": 10,
                                    "isRequired": true,
                                    "typeSettings": {
                                      "additionalResourceOptions": [],
                                      "showDefault": false
                                    },
                                    "jsonData": "[\"Yes\", \"No\"]",
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "value": "No"
                                  }
                                ],
                                "style": "formVertical",
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces"
                              },
                              "name": "parameters - 0"
                            },
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "parameters": [
                                  {
                                    "id": "651e895c-ab16-4a82-b514-e990a628dfb9",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "newDCRName",
                                    "type": 1,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "value": "EventHubTest1",
                                    "label": "New DCR Name"
                                  },
                                  {
                                    "id": "13fb1c40-adb5-4247-9ef7-60180ff4dd84",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "RGLocation",
                                    "type": 1,
                                    "query": "resources\r\n| where type == 'microsoft.operationalinsights/workspaces'\r\n| where id == '{Workspace}'\r\n| project location",
                                    "crossComponentResources": [
                                      "{subscriptionId}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 1,
                                    "resourceType": "microsoft.resourcegraph/resources"
                                  }
                                ],
                                "style": "above",
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces"
                              },
                              "name": "parameters - 14"
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "### Useful Information\r\n\r\nThis step will create a new data collection rule if one does not exist already. The following template will require:\r\n1. A name\r\n2. The location of the resource group/workspace\r\n3. The resource path for the desired data collection endpoint\r\n4. The columns that the DCR should expect for the table. This can be copied from the custom table step\r\n5. The consumer group of the Event Hub. If this is unknown, this can be left as $Default\r\n6. The resource path of the workspace that will ingest the data\r\n\r\nIf there is an existing DCR that should be used, set the toggle value to yes, select the DCR, and click modify to open the template to make the required changes.\r\n\r\nPlease enter the following values in the template to the right next to their corresponding key values: </br>\r\n\r\n#### Name: {newDCRName} </br>\r\n#### Location: {RGLocation}</br>\r\n#### DCE ID: {SelectedDCE} </br>\r\n#### Workspace: {Workspace} </br>\r\n#### New Table Name: Custom-{TableName}_CL\r\n",
                                "style": "upsell"
                              },
                              "customWidth": "20",
                              "conditionalVisibility": {
                                "parameterName": "DCRExist",
                                "comparison": "isEqualTo",
                                "value": "No"
                              },
                              "name": "text - 12"
                            },
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "crossComponentResources": [
                                  "{subscriptionId}"
                                ],
                                "parameters": [
                                  {
                                    "id": "3ca255ff-df6e-4c4d-9df0-20490185b989",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "ADCR",
                                    "label": "Event Hub DCR",
                                    "type": 1,
                                    "typeSettings": {
                                      "multiLineText": true,
                                      "editorLanguage": "json",
                                      "multiLineHeight": 40
                                    },
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "value": "{\r\n\t\"type\": \"Microsoft.Insights/dataCollectionRules\",\r\n\t\"name\": \"PUT NAME HERE\",\r\n\t\"location\": \"eastus\",\r\n\t\"identity\": {\r\n\t\t\t\"type\": \"systemAssigned\"\r\n\t\t},\r\n\t\"properties\": {\r\n\t\t\"dataCollectionEndpointId\": \"PUT DCE ID HERE\",\r\n\t\t\"streamDeclarations\": {\r\n\t\t\t\"Custom-EventHubStream\": {\r\n\t\t\t\t\"columns\": [\r\n\t\t{\r\n\t\t\t\"name\": \"TimeGenerated\",\r\n\t\t\t\"type\": \"datetime\"\r\n\t\t},\r\n\t\t{\r\n\t\t\t\"name\": \"RawData\",\r\n\t\t\t\"type\": \"string\"\r\n\t\t},\r\n\t\t{\r\n\t\t\t\"name\": \"Properties\",\r\n\t\t\t\"type\": \"dynamic\"\r\n\t\t}\r\n\t]\r\n\t\t\t}\r\n\t\t},\r\n\t\t\"dataSources\": {\r\n\t\t\t\"dataImports\": {\r\n\t\t\t\t\t\"eventHub\": {\r\n\t\t\t\t\t\t\t\"consumerGroup\": \"$Default\",\r\n\t\t\t\t\t\t\t\"stream\": \"Custom-EventHubStream\",\r\n\t\t\t\t\t\t\t\"name\": \"EventHubDataSource\"\r\n\t\t\t\t\t\t\t\t\t\t\t\t\t}\r\n\t\t\t\t\t\t\t\t\t}\r\n\t\t},\r\n\t\t\"destinations\": {\r\n\t\t\t\"logAnalytics\": [\r\n\t\t\t\t{\r\n\t\t\t\t\t\"workspaceResourceId\": \"PUT WORKSPACE ID HERE\",\r\n\t\t\t\t\t\"name\": \"Destination\"\r\n\t\t\t\t}\r\n\t\t\t]\r\n\t\t},\r\n\t\t\"dataFlows\": [\r\n\t\t\t{\r\n\t\t\t\t\"streams\": [\r\n\t\t\t\t\t\"Custom-EventHubStream\"\r\n\t\t\t\t],\r\n\t\t\t\t\"destinations\": [\r\n\t\t\t\t\t\"Destination\"\r\n\t\t\t\t],\r\n\t\t\t\t\"transformKql\": \"source\",\r\n\t\t\t\t\"outputStream\": \"Custom-PUTTABLENAMEHERE_CL\"\r\n\t\t\t}\r\n\t\t]\r\n\t}\r\n}\r\n"
                                  }
                                ],
                                "style": "above",
                                "queryType": 1,
                                "resourceType": "microsoft.resourcegraph/resources"
                              },
                              "customWidth": "80",
                              "conditionalVisibility": {
                                "parameterName": "DCRExist",
                                "comparison": "isEqualTo",
                                "value": "No"
                              },
                              "name": "parameters - 11"
                            },
                            {
                              "type": 11,
                              "content": {
                                "version": "LinkItem/1.0",
                                "style": "paragraph",
                                "links": [
                                  {
                                    "id": "5f2d254b-0ca2-45c5-95d1-f4ebdade7b98",
                                    "linkTarget": "ArmAction",
                                    "linkLabel": "Deploy New DCR",
                                    "style": "primary",
                                    "linkIsContextBlade": true,
                                    "armActionContext": {
                                      "path": "/subscriptions/{Workspace:subscriptionId}/resourcegroups/{Workspace:resourceGroup}/providers/Microsoft.Insights/dataCollectionRules/{newDCRName}?api-version=2022-06-01",
                                      "headers": [],
                                      "params": [],
                                      "body": "{ADCR}",
                                      "httpMethod": "PUT",
                                      "title": "Create New Data Collection Rule{newDCRName}",
                                      "description": "```json\n{ADCR}\n```\n-----------------------------\n### Populated Values\n```\nNew DCR Name: {newDCRName}\nLocation: {RGLocation}\nDCE ID: {SelectedDCE}\nEvent Hub Consumer Group: {EHCG}\nWorkspace: {Workspace}\nNew Table Name: {TableName}\n```",
                                      "runLabel": "Deploy DCR"
                                    }
                                  },
                                  {
                                    "id": "2aecc518-b5f0-4934-b597-5348caba1d7d",
                                    "linkTarget": "OpenBlade",
                                    "linkLabel": "Confirm DCR Creation",
                                    "style": "primary",
                                    "linkIsContextBlade": true,
                                    "bladeOpenContext": {
                                      "bladeName": "AzureMonitoringBrowseBlade",
                                      "extensionName": "Microsoft_Azure_Monitoring",
                                      "bladeJsonParameters": "{\n  \"menuId\": \"dataCollectionRules\"\n}"
                                    }
                                  }
                                ]
                              },
                              "conditionalVisibility": {
                                "parameterName": "DCRExist",
                                "comparison": "isEqualTo",
                                "value": "No"
                              },
                              "name": "links - 13"
                            },
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "crossComponentResources": [
                                  "{subscriptionId}"
                                ],
                                "parameters": [
                                  {
                                    "id": "5447d679-515a-4483-9329-687f2d40f508",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "SelectedDCR",
                                    "label": "Select Data Collection Rule",
                                    "type": 5,
                                    "query": "resources\r\n| where type == \"microsoft.insights/datacollectionrules\"\r\n| extend DataCollectionEndpoint = properties.dataCollectionEndpointId\r\n| where DataCollectionEndpoint == '{SelectedDCE}'\r\n| project id, name = tolower(name)\r\n| order by name asc",
                                    "crossComponentResources": [
                                      "{subscriptionId}"
                                    ],
                                    "typeSettings": {
                                      "additionalResourceOptions": [],
                                      "showDefault": false
                                    },
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 1,
                                    "resourceType": "microsoft.resourcegraph/resources",
                                    "value": null
                                  }
                                ],
                                "style": "formVertical",
                                "queryType": 1,
                                "resourceType": "microsoft.resourcegraph/resources"
                              },
                              "conditionalVisibility": {
                                "parameterName": "DCRExist",
                                "comparison": "isEqualTo",
                                "value": "Yes"
                              },
                              "name": "parameters - 2"
                            },
                            {
                              "type": 11,
                              "content": {
                                "version": "LinkItem/1.0",
                                "style": "paragraph",
                                "links": [
                                  {
                                    "id": "97716920-b7f4-42a3-8d8d-787351196385",
                                    "cellValue": "Value2",
                                    "linkTarget": "parameter",
                                    "linkLabel": "Modify DCR",
                                    "subTarget": "Set",
                                    "style": "primary"
                                  },
                                  {
                                    "id": "8806092d-9486-4ebf-9f7a-10ca0467423e",
                                    "cellValue": "Value2",
                                    "linkTarget": "parameter",
                                    "linkLabel": "Done",
                                    "subTarget": "Done",
                                    "style": "primary"
                                  }
                                ]
                              },
                              "conditionalVisibility": {
                                "parameterName": "DCRExist",
                                "comparison": "isEqualTo",
                                "value": "Yes"
                              },
                              "name": "links - 7"
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "### Currently Modifying: {SelectedDCR:name}"
                              },
                              "conditionalVisibilities": [
                                {
                                  "parameterName": "Value2",
                                  "comparison": "isEqualTo",
                                  "value": "Set"
                                },
                                {
                                  "parameterName": "DCRExist",
                                  "comparison": "isEqualTo",
                                  "value": "Yes"
                                }
                              ],
                              "name": "text - 18"
                            },
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "parameters": [
                                  {
                                    "id": "5371804f-914f-43c3-a63c-e68bee8c5d1a",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "Properties",
                                    "type": 1,
                                    "query": "{\"version\":\"ARMEndpoint/1.0\",\"data\":null,\"headers\":[],\"method\":\"GET\",\"path\":\"{SelectedDCR}?api-version=2022-06-01\",\"urlParams\":[],\"batchDisabled\":false,\"transformers\":null}",
                                    "isHiddenWhenLocked": true,
                                    "typeSettings": {
                                      "multiLineText": true,
                                      "editorLanguage": "text"
                                    },
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 12
                                  },
                                  {
                                    "id": "95eac5ff-ed08-46aa-9e0e-a0949729dc39",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "DCRG",
                                    "type": 1,
                                    "query": "print '{SelectedDCR}'\r\n| extend holder = split(tostring('{SelectedDCR}'), '/')\r\n| project RG = strcat( '/', holder[1],'/', holder[2], '/', holder[3], '/', holder[4])\r\n",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  }
                                ],
                                "style": "pills",
                                "queryType": 12
                              },
                              "conditionalVisibility": {
                                "parameterName": "1",
                                "comparison": "isEqualTo",
                                "value": "2"
                              },
                              "name": "parameters - 18"
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "### Useful Information\r\n\r\nIf modifying an existing DCR to be used for an assocation, please add the following values: </br>\r\n\r\n#### Managed Identity:\r\nInsert the following JSON into the template after apiVersion and before properties. \r\n```\r\n\"identity\": {\r\n                             \"type\": \"systemAssigned\"\r\n              },\r\n```\r\n#### Event Hub Data Source\r\nEnter the following JSON after streamDeclarations and before destinations. \r\n```\r\n\"dataSources\": {\r\n\t\t\"dataImports\": {\r\n\t\t\t\t\"eventHub\": {\r\n\t\t\t\t\t\t\"consumerGroup\": \"Consumer group or leave as $Default\",\r\n\t\t\t\t\t\t\"stream\": \"Enter stream name for the DCR here\",\r\n\t\t\t\t\t\t\"name\": \"EventHubStream\"\r\n\t\t\t\t\t\t\t\t\t\t\t\t}\r\n\t\t\t\t\t\t\t\t}\r\n\t\t\t},\r\n```\r\n\r\n",
                                "style": "upsell"
                              },
                              "customWidth": "30",
                              "conditionalVisibilities": [
                                {
                                  "parameterName": "Value2",
                                  "comparison": "isEqualTo",
                                  "value": "Set"
                                },
                                {
                                  "parameterName": "DCExist",
                                  "comparison": "isEqualTo",
                                  "value": "Yes"
                                }
                              ],
                              "name": "text - 15"
                            },
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "crossComponentResources": [
                                  "{Workspace}"
                                ],
                                "parameters": [
                                  {
                                    "id": "936488d4-1392-45e3-a54b-37ae76988a97",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "template2",
                                    "label": "Template",
                                    "type": 1,
                                    "isRequired": true,
                                    "isGlobal": true,
                                    "query": "print test = dynamic({Properties})\r\n",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "typeSettings": {
                                      "multiLineText": true,
                                      "editorLanguage": "json",
                                      "multiLineHeight": 40,
                                      "preFormatJsonData": true
                                    },
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces",
                                    "value": null
                                  }
                                ],
                                "style": "above",
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces"
                              },
                              "customWidth": "70",
                              "conditionalVisibilities": [
                                {
                                  "parameterName": "Value2",
                                  "comparison": "isEqualTo",
                                  "value": "Set"
                                },
                                {
                                  "parameterName": "DCRExist",
                                  "comparison": "isEqualTo",
                                  "value": "Yes"
                                }
                              ],
                              "name": "parameters - 8"
                            },
                            {
                              "type": 11,
                              "content": {
                                "version": "LinkItem/1.0",
                                "style": "paragraph",
                                "links": [
                                  {
                                    "id": "472428e4-3a55-4b8a-a940-23b0272eec06",
                                    "cellValue": "",
                                    "linkTarget": "OpenBlade",
                                    "linkLabel": "Write Transformation KQL",
                                    "subTarget": "logs",
                                    "style": "primary",
                                    "linkIsContextBlade": true,
                                    "bladeOpenContext": {
                                      "bladeName": "LogsBlade",
                                      "extensionName": "Microsoft_Azure_Monitoring_Logs",
                                      "bladeParameters": [
                                        {
                                          "name": "resourceId",
                                          "source": "static",
                                          "value": "{workspace}"
                                        },
                                        {
                                          "name": "source",
                                          "source": "static",
                                          "value": "LogsBlade.AnalyticsShareLinkToQuery"
                                        }
                                      ]
                                    }
                                  },
                                  {
                                    "id": "57580a59-508e-47e4-8646-6b08ef65d835",
                                    "linkTarget": "ArmAction",
                                    "linkLabel": "Deploy Update",
                                    "style": "primary",
                                    "linkIsContextBlade": true,
                                    "armActionContext": {
                                      "path": "{DCRG}/providers/Microsoft.Insights/dataCollectionRules/{SelectedDCR:name}?api-version=2021-09-01-preview",
                                      "headers": [],
                                      "params": [],
                                      "body": "{template2}",
                                      "httpMethod": "PUT",
                                      "title": "Update Data Collection Rule: {name}",
                                      "description": "### You are about to commit changes to DCR {name}. Please confirm the changes you have made are valid and are the intended changes that you would like to push. This API will be redeploying the ARM template for this DCR. Connected machines will not be dropped.\r\n",
                                      "runLabel": "Update DCR"
                                    }
                                  }
                                ]
                              },
                              "conditionalVisibilities": [
                                {
                                  "parameterName": "Value2",
                                  "comparison": "isEqualTo",
                                  "value": "Set"
                                },
                                {
                                  "parameterName": "DCRExist",
                                  "comparison": "isEqualTo",
                                  "value": "Yes"
                                }
                              ],
                              "name": "links - 9"
                            }
                          ],
                          "exportParameters": true
                        },
                        "name": "Step Two",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "title": "Assign Permissions",
                          "expandable": true,
                          "expanded": true,
                          "items": [
                            {
                              "type": 1,
                              "content": {
                                "json": "### Useful Information\r\n\r\nThis step will provide the DCR that was chosen for Event Hub ingestion and will assign permissions to it to allow for ingestion to occur. The button below will open the selected Event Hub and allow for a role to be assigned. The role required for the DCR is the *Azure Event Hubs Data Receiver* role. </br>\r\n\r\nNote: In order to grant the permission, the user creating the assignment will need *Microsoft.Authorization/* permissions on the resource. </br>\r\n\r\nIf the DCR does not appear in the search, please confirm that a system managed identity has been enabled and given to it. This should have been done in the step above.",
                                "style": "upsell"
                              },
                              "name": "text - 2"
                            },
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "crossComponentResources": [
                                  "{subscriptionId}"
                                ],
                                "parameters": [
                                  {
                                    "id": "74640dbe-121c-4a09-9e82-2ab05f09cb97",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "SelectedEH",
                                    "label": "Select Event Hub",
                                    "type": 5,
                                    "query": "resources\r\n| where type == \"microsoft.eventhub/namespaces\"\r\n| project id, name",
                                    "crossComponentResources": [
                                      "{subscriptionId}"
                                    ],
                                    "typeSettings": {
                                      "additionalResourceOptions": [],
                                      "showDefault": false
                                    },
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 1,
                                    "resourceType": "microsoft.resourcegraph/resources",
                                    "value": ""
                                  }
                                ],
                                "style": "above",
                                "queryType": 1,
                                "resourceType": "microsoft.resourcegraph/resources"
                              },
                              "customWidth": "50",
                              "name": "parameters - 2"
                            },
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "crossComponentResources": [
                                  "{subscriptionId}"
                                ],
                                "parameters": [
                                  {
                                    "id": "4a19d07b-62da-458e-8cd3-9a760d205948",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "SelectedDCR2",
                                    "label": "Select DCR",
                                    "type": 5,
                                    "query": "resources\r\n| where type == \"microsoft.insights/datacollectionrules\"\r\n| extend DataCollectionEndpoint = properties.dataCollectionEndpointId\r\n| where DataCollectionEndpoint == '{SelectedDCE}'\r\n| project id, name = tolower(name)\r\n| order by name asc",
                                    "crossComponentResources": [
                                      "{subscriptionId}"
                                    ],
                                    "typeSettings": {
                                      "additionalResourceOptions": [],
                                      "showDefault": false
                                    },
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 1,
                                    "resourceType": "microsoft.resourcegraph/resources",
                                    "value": ""
                                  }
                                ],
                                "style": "above",
                                "queryType": 1,
                                "resourceType": "microsoft.resourcegraph/resources"
                              },
                              "customWidth": "50",
                              "name": "parameters - 2 - Copy"
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "---------------------------------------------------------"
                              },
                              "name": "text - 3"
                            },
                            {
                              "type": 11,
                              "content": {
                                "version": "LinkItem/1.0",
                                "style": "paragraph",
                                "links": [
                                  {
                                    "id": "d49c80e7-5d6a-4710-9d21-5283d2f0f134",
                                    "cellValue": "{SelectedEH}",
                                    "linkTarget": "Resource",
                                    "linkLabel": "Open Event Hub",
                                    "subTarget": "users",
                                    "style": "primary",
                                    "linkIsContextBlade": true
                                  }
                                ]
                              },
                              "customWidth": "50",
                              "name": "links - 3"
                            },
                            {
                              "type": 11,
                              "content": {
                                "version": "LinkItem/1.0",
                                "style": "paragraph",
                                "links": [
                                  {
                                    "id": "a6987f86-8e98-4721-800d-904c9569b0fa",
                                    "cellValue": "{SelectedDCR2}",
                                    "linkTarget": "Resource",
                                    "linkLabel": "Open DCR",
                                    "subTarget": "users",
                                    "style": "primary",
                                    "linkIsContextBlade": true
                                  }
                                ]
                              },
                              "customWidth": "50",
                              "name": "links - 3 - Copy"
                            }
                          ],
                          "exportParameters": true
                        },
                        "name": "Step Three",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "title": "Create Association",
                          "expandable": true,
                          "expanded": true,
                          "items": [
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "parameters": [
                                  {
                                    "id": "186555cb-f0f2-4a7f-b0d0-7f505c4886da",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "AEHName",
                                    "type": 1,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "value": "Association1",
                                    "label": "Association Name"
                                  }
                                ],
                                "style": "above",
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces"
                              },
                              "name": "parameters - 3"
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "### Final Check\r\n\r\nThis is the final step in configuring ingestion via Event Hub. Please review the configuration that has been done thus far. The following information can be used to do a quick check but the preceding steps can be revisited. </br>\r\n\r\n#### New Table: {TableName} </br>\r\n#### Data Collection Endpoint: {SelectedDCE} </br>\r\n#### Data Collection Rule: {SelectedDCR2} </br>\r\n#### Event Hub: {SelectedEH} </br>\r\n---------------------------------------------\r\n### Information Passed for Creation of Association\r\n\r\n#### Association Name: {AEHName} </br>\r\n#### Scope: {SelectedEH} </br>\r\n#### DCR ID: {SelectedDCR2} </br>",
                                "style": "warning"
                              },
                              "name": "text - 2"
                            },
                            {
                              "type": 11,
                              "content": {
                                "version": "LinkItem/1.0",
                                "style": "paragraph",
                                "links": [
                                  {
                                    "id": "b0ac7397-612e-475f-a0b2-fc22af566942",
                                    "linkTarget": "ArmAction",
                                    "linkLabel": "Create Association",
                                    "style": "primary",
                                    "linkIsContextBlade": true,
                                    "armActionContext": {
                                      "path": "{SelectedEH}/providers/Microsoft.Insights/dataCollectionRuleAssociations/{AEHName}?api-version=2021-09-01-preview",
                                      "headers": [],
                                      "params": [],
                                      "body": "{\r\n      \"scope\": \"{SelectedEH}\",\r\n      \"name\": \"{AEHName}\",\r\n      \"properties\": {\r\n        \"description\": \"Association of data collection rule. Deleting this association will break the data collection for this event hub.\",\r\n        \"dataCollectionRuleId\": \"{SelectedDCR2}\"\r\n      }\r\n}\r\n",
                                      "httpMethod": "PUT",
                                      "title": "Create Association Between {SelectedEH:name} and {SelectedDCR:name}?",
                                      "description": "The template to deploy is the following. Please confirm that all values are set correctly.\n\n```json\n{\n      \"type\": \"Microsoft.Insights/dataCollectionRuleAssociations\",\n      \"scope\": \"{SelectedEH}\",\n      \"name\": \"{AEHName}\",\n      \"properties\": {\n        \"description\": \"Association of data collection rule. Deleting this association will break the data collection for this event hub.\",\n        \"dataCollectionRuleId\": \"{SelectedDCR2}\"\n      }\n}\n```",
                                      "runLabel": "Create Association"
                                    }
                                  }
                                ]
                              },
                              "name": "links - 1"
                            }
                          ]
                        },
                        "name": "Step Four",
                        "styleSettings": {
                          "showBorder": true
                        }
                      }
                    ]
                  },
                  "conditionalVisibilities": [
                    {
                      "parameterName": "Datatype",
                      "comparison": "isEqualTo",
                      "value": "EH"
                    },
                    {
                      "parameterName": "Tab",
                      "comparison": "isEqualTo",
                      "value": "1"
                    }
                  ],
                  "name": "Event Hub"
                },
                {
                  "type": 12,
                  "content": {
                    "version": "NotebookGroup/1.0",
                    "groupType": "editable",
                    "items": [
                      {
                        "type": 9,
                        "content": {
                          "version": "KqlParameterItem/1.0",
                          "parameters": [
                            {
                              "id": "6db21dd5-5ea5-4933-929e-34e15bf0d51e",
                              "version": "KqlParameterItem/1.0",
                              "name": "IngestionTier",
                              "label": "Ingestion Tier",
                              "type": 10,
                              "isRequired": true,
                              "value": "Common",
                              "typeSettings": {
                                "additionalResourceOptions": [],
                                "showDefault": false
                              },
                              "jsonData": "[\"None\", \"Minimal\", \"Common\"]",
                              "timeContext": {
                                "durationMs": 86400000
                              }
                            }
                          ],
                          "style": "above",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces"
                        },
                        "name": "parameters - 6"
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 1,
                              "content": {
                                "json": "### Help\r\n\r\nThe Essentials area is designed to configure a DCR for either UEBA, Analytic Rules, and Hunting based on event IDs used within those features. The goal is to deploy a DCR for either feature that will enable for the features to work properly. If looking to add more event IDs, either set an ingestion tier above or manually enter the event IDs in the space below.",
                                "style": "info"
                              },
                              "conditionalVisibility": {
                                "parameterName": "Datatype",
                                "comparison": "isEqualTo",
                                "value": "Essentials"
                              },
                              "name": "Essentials"
                            },
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "crossComponentResources": [
                                  "{Workspace}"
                                ],
                                "parameters": [
                                  {
                                    "id": "635fce4f-0b3b-484c-a9f1-cd622e35d2cc",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "MinimalEvents",
                                    "type": 1,
                                    "query": "let Minimal = datatable(EventID:int)[1102, 4624, 4625, 4657, 4663, 4688, 4700, 4702, 4719, 4720, 4722, 4723, 4724, 4727, 4728, 4732, 4735, 4737, 4739, 4740, 4754, 4755, 4756, 4767, 4799, 4825, 4946, 4948, 4956, 5024, 5033, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8222];\r\nMinimal",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "id": "39ec786d-9769-4441-84a4-71e4722839ab",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "CommonEvents",
                                    "type": 1,
                                    "query": "let Common = datatable(EventID:int)[1, 299, 300, 324, 340, 403, 404, 410, 411, 412, 413, 431, 500, 501, 1100, 1102, 1107, 1108, 4608, 4610, 4611, 4614, 4622, 4624, 4625, 4634, 4647, 4648, 4649, 4657, 4661, 4662, 4663, 4665, 4666, 4667, 4688, 4670, 4672, 4673, 4674, 4675, 4689, 4697, 4700, 4702, 4704, 4705, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4733, 4732, 4735, 4737, 4738, 4739, 4740, 4742, 4744, 4745, 4746, 4750, 4751, 4752, 4754, 4755, 4756, 4757, 4760, 4761, 4762, 4764, 4767, 4768, 4771, 4774, 4778, 4779, 4781, 4793, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4825, 4826, 4870, 4886, 4887, 4888, 4893, 4898, 4902, 4904, 4905, 4907, 4931, 4932, 4933, 4946, 4948, 4956, 4985, 5024, 5033, 5059, 5136, 5137, 5140, 5145, 5632, 6144, 6145, 6272, 6273, 6278, 6416, 6423, 6424, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8222, 26401, 30004];\r\nCommon",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "id": "6797a90e-08cf-4ccf-8abb-a5b0f25080f5",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "IngestArray",
                                    "type": 1,
                                    "query": "let test1 = case('{IngestionTier}' == 'Minimal', dynamic('{MinimalEvents}'),\r\n                '{IngestionTier}' == 'Common', dynamic('{CommonEvents}'),\r\n                dynamic([]));\r\nprint test1",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  }
                                ],
                                "style": "pills",
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces"
                              },
                              "name": "parameters - 8"
                            },
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "crossComponentResources": [
                                  "{Workspace}"
                                ],
                                "parameters": [
                                  {
                                    "id": "6079823a-de73-4e2b-9646-aeb37d4e4b48",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "uebaIds",
                                    "type": 1,
                                    "query": "print '{UEBAEssentials}'",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "id": "d9c8b4c7-6ef0-4b03-a16e-025d4173450b",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "ManualEventsUEBA",
                                    "type": 9,
                                    "multiSelect": true,
                                    "quote": "'",
                                    "delimiter": ",",
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "label": "Manual Events"
                                  },
                                  {
                                    "version": "KqlParameterItem/1.0",
                                    "name": "ExcludeUEBA",
                                    "label": "Excluded Events",
                                    "type": 9,
                                    "multiSelect": true,
                                    "quote": "'",
                                    "delimiter": ",",
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "id": "92ca57fd-7a20-467f-964f-55b640da4db4"
                                  },
                                  {
                                    "id": "df2785ed-52c6-4aee-ac01-c6cbdbc1a06e",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "parseManualUEBA",
                                    "type": 1,
                                    "query": "let manualIds = \"{ManualEventsUEBA}\";\r\nprint ids=manualIds\r\n| project ids = todynamic(strcat('[', replace_regex(ids,\"\\'\",\"\"),']'))\r\n| mv-expand ids\r\n| project ids = toint(ids)",
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "version": "KqlParameterItem/1.0",
                                    "name": "parseExcludeUEBA",
                                    "type": 1,
                                    "query": "let manualIds = \"{ExcludeUEBA}\";\r\nprint ids=manualIds\r\n| project ids = todynamic(strcat('[', replace_regex(ids,\"\\'\",\"\"),']'))\r\n| mv-expand ids\r\n| project ids = toint(ids)",
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces",
                                    "id": "ddb90aad-afab-4d58-bc8c-147142902e67"
                                  },
                                  {
                                    "id": "0a5d6d8f-7b8f-4c56-8515-3ac94d679f5d",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "mergedUEBA",
                                    "type": 1,
                                    "query": "let manual_ids = () {\r\n    print ids=todynamic(\"{parseManualUEBA}\")\r\n    | mvexpand ids\r\n    | project ids = toint(ids)\r\n};\r\nlet exclude_ids = () {\r\n    print ids=todynamic(\"{parseExcludeUEBA}\")\r\n    | mvexpand ids\r\n    | project ids = toint(ids)\r\n};\r\nlet tierIds = () {\r\n    print ids = todynamic(\"{IngestArray}\")\r\n    | mvexpand ids\r\n    | project ids = toint(ids)\r\n};\r\nlet uebaIds = () {\r\n    print  ids=todynamic('{uebaIds}')\r\n    | mv-expand ids\r\n    | project ids = toint(ids)\r\n};\r\nunion manual_ids, tierIds, uebaIds\r\n| where ids !in (exclude_ids)\r\n| where isnotempty(ids)\r\n| summarize by ids\r\n| sort by ids asc",
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "id": "088873b1-b01e-4d65-bff8-0c50dc997953",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "generatedJSONUEBA",
                                    "type": 1,
                                    "query": "// Referenced merged array\r\nlet generated = () {\r\n    print merged=\"{mergedUEBA:escapejson}\"\r\n    | extend merged=todynamic(merged)\r\n    | mvexpand merged\r\n    | top 100 by toint(merged) asc\r\n    | extend merged = tostring(strcat(\"(EventID=\",merged,\")\"))\r\n    | sort by tolong(merged) asc\r\n    | extend index=row_rank(merged)\r\n    | summarize merged=makeset(merged) by (index/10)\r\n    | extend concat= strcat_array(merged,\" or \")\r\n    | project p = strcat(\"Security!*[System[\",concat,\"]]\")\r\n    | summarize makeset(p)\r\n};\r\ngenerated",
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "id": "7084e8ec-ff16-47a1-a16b-b3605092c300",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "UEBADCR2",
                                    "type": 1,
                                    "query": "let Count = print merged=\"{mergedUEBA:escapejson}\"\r\n    | extend merged=todynamic(merged)\r\n    | mvexpand merged\r\n    | summarize count()\r\n    | extend Counter = toint(count_);\r\nlet Check =\r\n    Count\r\n    | extend Check = iff(Counter <= 100, 'DCR not needed', 'DCR needed')\r\n    | extend Math = Counter - 100\r\n    | extend diff = iff(Math < 0 or Math > 100, 'New DCR will not work', array_split(todynamic(\"{mergedUEBA:escapejson}\"), 100)[1])\r\n    | extend diff = todynamic(diff)\r\n    | mv-expand diff\r\n    | project toint(diff)\r\n    | top 100 by diff asc\r\n    | summarize Array = make_set(diff);\r\nlet Configure = (Array:dynamic) { print Array\r\n    | extend Array = todynamic(Array)\r\n    | mv-expand Array\r\n    | extend merged = tostring(strcat(\"(EventID=\",Array,\")\"))\r\n    | sort by tolong(merged) asc\r\n    | extend index=row_rank(merged)\r\n    | summarize merged=makeset(merged) by (index/10)\r\n    | extend concat= strcat_array(merged,\" or \")\r\n    | project p = iff(Array == 'New DCR will not work', 'New DCR will not work', strcat(\"Security!*[System[\",concat,\"]\"))\r\n    | summarize make_set_if(p, p != 'New DCR will not work')\r\n    };\r\nConfigure(toscalar(Check))\r\n| extend set_p = iff(set_p == '[]', 'Blank', set_p)",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  }
                                ],
                                "style": "above",
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces"
                              },
                              "conditionalVisibility": {
                                "parameterName": "Essentialtype",
                                "comparison": "isEqualTo",
                                "value": "UEBA"
                              },
                              "name": "Merged Set"
                            },
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "parameters": [
                                  {
                                    "id": "f2c1b60a-8461-4d02-a7ef-39e2bd4d3fd6",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "arIds",
                                    "type": 1,
                                    "query": "print '{AREssentials}'",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "id": "0e5e8493-a476-415b-978d-958c441cf95e",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "ManualEventsAR",
                                    "type": 9,
                                    "multiSelect": true,
                                    "quote": "'",
                                    "delimiter": ",",
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "label": "Manual Events"
                                  },
                                  {
                                    "version": "KqlParameterItem/1.0",
                                    "name": "ExcludeAR",
                                    "label": "Excluded Events",
                                    "type": 9,
                                    "multiSelect": true,
                                    "quote": "'",
                                    "delimiter": ",",
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "id": "9bfc4405-d9a8-4810-a12c-53d24254e5e8"
                                  },
                                  {
                                    "id": "7e90a02e-8fe4-4230-a481-b96fe99b1447",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "parseManualAR",
                                    "type": 1,
                                    "query": "let manualIds = \"{ManualEventsAR}\";\r\nprint ids=manualIds\r\n| project ids = todynamic(strcat('[', replace_regex(ids,\"\\'\",\"\"),']'))\r\n| mv-expand ids\r\n| project ids = toint(ids)",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "version": "KqlParameterItem/1.0",
                                    "name": "parseExcludeAR",
                                    "type": 1,
                                    "query": "let manualIds = \"{ExcludeAR}\";\r\nprint ids=manualIds\r\n| project ids = todynamic(strcat('[', replace_regex(ids,\"\\'\",\"\"),']'))\r\n| mv-expand ids\r\n| project ids = toint(ids)",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces",
                                    "id": "06fbaf0d-0c3d-4b23-be9b-d2e2655ac9e8"
                                  },
                                  {
                                    "id": "16384634-2db8-4235-8930-7cd467fb6a18",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "mergedAR",
                                    "type": 1,
                                    "query": "let manual_ids = () {\r\n    print ids=todynamic(\"{parseManualAR}\")\r\n    | mvexpand ids\r\n    | project ids = toint(ids)\r\n};\r\nlet exclude_ids = () {\r\n    print ids=todynamic(\"{parseExcludeAR}\")\r\n    | mvexpand ids\r\n    | project ids = toint(ids)\r\n};\r\nlet tierIds = () {\r\n    print ids = todynamic(\"{IngestArray}\")\r\n    | mvexpand ids\r\n    | project ids = toint(ids)\r\n};\r\nlet arIds = () {\r\n    print  ids=todynamic('{arIds}')\r\n    | mv-expand ids\r\n    | project ids = toint(ids)\r\n};\r\nunion manual_ids, tierIds, arIds\r\n| where ids !in (exclude_ids)\r\n| where isnotempty(ids)\r\n| summarize by ids\r\n| sort by ids asc",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "id": "9b0c1c80-cc90-4de7-b29b-d8139a05d4b6",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "generatedJSONAR",
                                    "type": 1,
                                    "query": "// Referenced merged array\r\nlet generated = () {\r\n    print merged=\"{mergedAR:escapejson}\"\r\n    | extend merged=todynamic(merged)\r\n    | mvexpand merged\r\n    | top 100 by toint(merged) asc\r\n    | extend merged = tostring(strcat(\"(EventID=\",merged,\")\"))\r\n    | sort by tolong(merged) asc\r\n    | extend index=row_rank(merged)\r\n    | summarize merged=makeset(merged) by (index/10)\r\n    | extend concat= strcat_array(merged,\" or \")\r\n    | project p = strcat(\"Security!*[System[\",concat,\"]]\")\r\n    | summarize makeset(p)\r\n};\r\ngenerated",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "id": "e44a4157-78b2-4b56-b910-417f86fe35e6",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "ARDCR2",
                                    "type": 1,
                                    "query": "let Count = print merged=\"{mergedAR:escapejson}\"\r\n    | extend merged=todynamic(merged)\r\n    | mvexpand merged\r\n    | summarize count()\r\n    | extend Counter = toint(count_);\r\nlet Check =\r\n    Count\r\n    | extend Check = iff(Counter <= 100, 'DCR not needed', 'DCR needed')\r\n    | extend Math = Counter - 100\r\n    | extend diff = iff(Math < 0 or Math > 100, 'New DCR will not work', array_split(todynamic(\"{mergedAR:escapejson}\"), 100)[1])\r\n    | extend diff = todynamic(diff)\r\n    | mv-expand diff\r\n    | project toint(diff)\r\n    | top 100 by diff asc\r\n    | summarize Array = make_set(diff);\r\nlet Configure = (Array:dynamic) { print Array\r\n    | extend Array = todynamic(Array)\r\n    | mv-expand Array\r\n    | extend merged = tostring(strcat(\"(EventID=\",Array,\")\"))\r\n    | sort by tolong(merged) asc\r\n    | extend index=row_rank(merged)\r\n    | summarize merged=makeset(merged) by (index/10)\r\n    | extend concat= strcat_array(merged,\" or \")\r\n    | project p = iff(Array == 'New DCR will not work', 'New DCR will not work', strcat(\"Security!*[System[\",concat,\"]\"))\r\n    | summarize make_set_if(p, p != 'New DCR will not work')\r\n    };\r\nConfigure(toscalar(Check))\r\n| extend set_p = iff(set_p == '[]', 'Blank', set_p)",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  }
                                ],
                                "style": "above",
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces"
                              },
                              "conditionalVisibility": {
                                "parameterName": "Essentialtype",
                                "comparison": "isEqualTo",
                                "value": "AR"
                              },
                              "name": "Merged Set - Copy"
                            },
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "crossComponentResources": [
                                  "{Workspace}"
                                ],
                                "parameters": [
                                  {
                                    "id": "d3338f3c-7cc7-4121-b348-ce3918d0d7ea",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "huntIds",
                                    "type": 1,
                                    "query": "print '{HuntingEssentials}'",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "id": "6f7659cf-10c2-4cab-a451-cac8c9cf668a",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "ManualEventsHUNT",
                                    "type": 9,
                                    "multiSelect": true,
                                    "quote": "'",
                                    "delimiter": ",",
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "label": "Manual Events"
                                  },
                                  {
                                    "version": "KqlParameterItem/1.0",
                                    "name": "ExcludeHUNT",
                                    "label": "Excluded Events",
                                    "type": 9,
                                    "multiSelect": true,
                                    "quote": "'",
                                    "delimiter": ",",
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "id": "22a2a4f8-c74f-4ee3-b4bd-6c09d2051302"
                                  },
                                  {
                                    "id": "3ad85c7f-7539-4a49-a771-285b6f0e71c7",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "parseManualHUNT",
                                    "type": 1,
                                    "query": "let manualIds = \"{ManualEventsHUNT}\";\r\nprint ids=manualIds\r\n| project ids = todynamic(strcat('[', replace_regex(ids,\"\\'\",\"\"),']'))\r\n| mv-expand ids\r\n| project ids = toint(ids)",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "id": "965a59e4-4c80-4c83-974e-6703f8cced98",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "parseExcludeHUNT",
                                    "type": 1,
                                    "query": "let manualIds = \"{ExcludeHUNT}\";\r\nprint ids=manualIds\r\n| project ids = todynamic(strcat('[', replace_regex(ids,\"\\'\",\"\"),']'))\r\n| mv-expand ids\r\n| project ids = toint(ids)",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "id": "3737a5b1-21ad-4a06-b149-afddfcd5f776",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "mergedHUNT",
                                    "type": 1,
                                    "query": "let manual_ids = () {\r\n    print ids=todynamic(\"{parseManualHUNT}\")\r\n    | mvexpand ids\r\n    | project ids = toint(ids)\r\n};\r\nlet exclude_ids = () {\r\n    print ids=todynamic(\"{parseExcludeHUNT}\")\r\n    | mvexpand ids\r\n    | project ids = toint(ids)\r\n};\r\nlet tierIds = () {\r\n    print ids = todynamic(\"{IngestArray}\")\r\n    | mvexpand ids\r\n    | project ids = toint(ids)\r\n};\r\nlet huntIds = () {\r\n    print  ids=todynamic('{huntIds}')\r\n    | mv-expand ids\r\n    | project ids = toint(ids)\r\n};\r\nunion manual_ids, tierIds, huntIds\r\n| where ids !in (exclude_ids)\r\n| where isnotempty(ids)\r\n| summarize by ids\r\n| sort by ids asc",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "id": "9dc70a0d-2ced-4f56-abd6-b7ffcb6d102b",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "generatedJSONHUNT",
                                    "type": 1,
                                    "query": "// Referenced merged array\r\nlet generated = () {\r\n    print merged=\"{mergedHUNT:escapejson}\"\r\n    | extend merged=todynamic(merged)\r\n    | mvexpand merged\r\n    | top 100 by toint(merged) asc\r\n    | extend merged = tostring(strcat(\"(EventID=\",merged,\")\"))\r\n    | sort by tolong(merged) asc\r\n    | extend index=row_rank(merged)\r\n    | summarize merged=makeset(merged) by (index/10)\r\n    | extend concat= strcat_array(merged,\" or \")\r\n    | project p = strcat(\"Security!*[System[\",concat,\"]]\")\r\n    | summarize makeset(p)\r\n};\r\ngenerated",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  },
                                  {
                                    "id": "5f261146-02e9-4d7d-b9db-cabee63cd823",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "HUNTDCR2",
                                    "type": 1,
                                    "query": "let Count = print merged=\"{mergedHUNT:escapejson}\"\r\n    | extend merged=todynamic(merged)\r\n    | mvexpand merged\r\n    | summarize count()\r\n    | extend Counter = toint(count_);\r\nlet Check =\r\n    Count\r\n    | extend Check = iff(Counter <= 100, 'DCR not needed', 'DCR needed')\r\n    | extend Math = Counter - 100\r\n    | extend diff = iff(Math < 0 or Math > 100, 'New DCR will not work', array_split(todynamic(\"{mergedHUNT:escapejson}\"), 100)[1])\r\n    | extend diff = todynamic(diff)\r\n    | mv-expand diff\r\n    | project toint(diff)\r\n    | top 100 by diff asc\r\n    | summarize Array = make_set(diff);\r\nlet Configure = (Array:dynamic) { print Array\r\n    | extend Array = todynamic(Array)\r\n    | mv-expand Array\r\n    | extend merged = tostring(strcat(\"(EventID=\",Array,\")\"))\r\n    | sort by tolong(merged) asc\r\n    | extend index=row_rank(merged)\r\n    | summarize merged=makeset(merged) by (index/10)\r\n    | extend concat= strcat_array(merged,\" or \")\r\n    | project p = iff(Array == 'New DCR will not work', 'New DCR will not work', strcat(\"Security!*[System[\",concat,\"]\"))\r\n    | summarize make_set_if(p, p != 'New DCR will not work')\r\n    };\r\nConfigure(toscalar(Check))\r\n| extend set_p = iff(set_p == '[]', 'Blank', set_p)",
                                    "crossComponentResources": [
                                      "{Workspace}"
                                    ],
                                    "isHiddenWhenLocked": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  }
                                ],
                                "style": "above",
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces"
                              },
                              "conditionalVisibility": {
                                "parameterName": "Essentialtype",
                                "comparison": "isEqualTo",
                                "value": "Hunting"
                              },
                              "name": "Merged Set - Copy - Copy"
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "### Manually Entered IDs: \r\nEventIDs: {parseManualUEBA} </br>\r\n\r\n### Excluded IDs:\r\nEventIDs: {parseExcludeUEBA} </br>\r\n\r\n### Full List of Manual and UEBA IDs: \r\nEventIDs: {mergedUEBA}</br>\r\n\r\n\r\n"
                              },
                              "conditionalVisibility": {
                                "parameterName": "Essentialtype",
                                "comparison": "isEqualTo",
                                "value": "UEBA"
                              },
                              "name": "text - 2"
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "### Manually Entered IDs:\r\nEventIDs: {parseManualAR} </br>\r\n\r\n### Excluded IDs: \r\nEventIDs: {parseExcludeAR} </br>\r\n\r\n### Full List of Manual and Analytic Rule IDs:\r\nEventIDs: {mergedAR} <br>\r\n\r\n"
                              },
                              "conditionalVisibility": {
                                "parameterName": "Essentialtype",
                                "comparison": "isEqualTo",
                                "value": "AR"
                              },
                              "name": "text - 9"
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "### Manually Entered IDs:\r\nEventIDs: {parseManualHUNT} </br>\r\n\r\n### Excluded IDs: \r\nEventIDs: {parseExcludeHUNT} </br>\r\n\r\n### Full List of Manual and Hunting IDs:\r\nEventIDs: {mergedHUNT} <br>\r\n\r\n"
                              },
                              "conditionalVisibility": {
                                "parameterName": "Essentialtype",
                                "comparison": "isEqualTo",
                                "value": "Hunting"
                              },
                              "name": "text - 9 - Copy"
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "let IDCount = '{mergedUEBA}';\r\nprint IDCount\r\n| mv-expand Test = todynamic(print_0)\r\n| summarize count() by print_0\r\n| extend count_ = case(count_ >= 100 and count_ <= 200, strcat('DCR count limit reached. Consider spltting the array into one DCR with 100 events and one with ', tostring((count_-100)), ' events.'),\r\n                    count_ >= 200 and count_ <=300, strcat('DCR count limit reached. Consider filtering the log criticality or spltting the array into two DCRs with 100 events and one with ', tostring((count_-200)), ' events.'),\r\n                    count_ >= 300 and count_ <=400, strcat('DCR count limit reached. Consider filtering the log criticality or spltting the array into three DCRs with 100 events and one with ', tostring((count_-300)), ' events.'),\r\n                    tostring(count_))\r\n| project-away print_0",
                                "size": 4,
                                "title": "Number of Distinct IDs Selected for UEBA DCR",
                                "timeContext": {
                                  "durationMs": 86400000
                                },
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "crossComponentResources": [
                                  "{Workspace}"
                                ],
                                "visualization": "card",
                                "tileSettings": {
                                  "titleContent": {},
                                  "leftContent": {
                                    "columnMatch": "Count"
                                  },
                                  "showBorder": false
                                },
                                "textSettings": {
                                  "style": "bignumber"
                                }
                              },
                              "customWidth": "33",
                              "conditionalVisibility": {
                                "parameterName": "Essentialtype",
                                "comparison": "isEqualTo",
                                "value": "UEBA"
                              },
                              "name": "query - 7"
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "let IDCount = '{mergedAR}';\r\nprint IDCount\r\n| mv-expand Test = todynamic(print_0)\r\n| summarize count() by print_0\r\n| extend count_ = case(count_ >= 100 and count_ <= 200, strcat('DCR count limit reached. Consider spltting the array into one DCR with 100 events and one with ', tostring((count_-100)), ' events.'),\r\n                    count_ >= 200 and count_ <=300, strcat('DCR count limit reached. Consider filtering the log criticality or spltting the array into two DCRs with 100 events and one with ', tostring((count_-200)), ' events.'),\r\n                    count_ >= 300 and count_ <=400, strcat('DCR count limit reached. Consider filtering the log criticality or spltting the array into three DCRs with 100 events and one with ', tostring((count_-300)), ' events.'),\r\n                    tostring(count_))\r\n| project-away print_0",
                                "size": 4,
                                "title": "Number of Distinct IDs Selected for Analytic Rule DCR",
                                "timeContext": {
                                  "durationMs": 86400000
                                },
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "crossComponentResources": [
                                  "{Workspace}"
                                ],
                                "visualization": "card",
                                "tileSettings": {
                                  "titleContent": {},
                                  "leftContent": {
                                    "columnMatch": "Count"
                                  },
                                  "showBorder": false
                                },
                                "textSettings": {
                                  "style": "bignumber"
                                }
                              },
                              "customWidth": "33",
                              "conditionalVisibility": {
                                "parameterName": "Essentialtype",
                                "comparison": "isEqualTo",
                                "value": "AR"
                              },
                              "name": "query - 7 - Copy"
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "let IDCount = '{mergedHUNT}';\r\nprint IDCount\r\n| mv-expand Test = todynamic(print_0)\r\n| summarize count() by print_0\r\n| extend count_ = case(count_ >= 100 and count_ <= 200, strcat('DCR count limit reached. Consider spltting the array into one DCR with 100 events and one with ', tostring((count_-100)), ' events.'),\r\n                    count_ >= 200 and count_ <=300, strcat('DCR count limit reached. Consider filtering the log criticality or spltting the array into two DCRs with 100 events and one with ', tostring((count_-200)), ' events.'),\r\n                    count_ >= 300 and count_ <=400, strcat('DCR count limit reached. Consider filtering the log criticality or spltting the array into three DCRs with 100 events and one with ', tostring((count_-300)), ' events.'),\r\n                    tostring(count_))\r\n| project-away print_0",
                                "size": 4,
                                "title": "Number of Distinct IDs Selected for Hunting DCR",
                                "timeContext": {
                                  "durationMs": 86400000
                                },
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "crossComponentResources": [
                                  "{Workspace}"
                                ],
                                "visualization": "card",
                                "tileSettings": {
                                  "titleContent": {},
                                  "leftContent": {
                                    "columnMatch": "Count"
                                  },
                                  "showBorder": false
                                },
                                "textSettings": {
                                  "style": "bignumber"
                                }
                              },
                              "customWidth": "33",
                              "conditionalVisibility": {
                                "parameterName": "Essentialtype",
                                "comparison": "isEqualTo",
                                "value": "Hunting"
                              },
                              "name": "query - 7 - Copy - Copy"
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "{\"version\":\"1.0.0\",\"content\":\"[\\r\\n\\t  {  \\\"Current Windows Event ID\\\": 4624,\\r\\n    \\\"Legacy Windows Event ID\\\": \\\"528,540\\\",\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An account was successfully logged on.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4625,\\r\\n    \\\"Legacy Windows Event ID\\\": \\\"529-537,539\\\",\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An account failed to log on.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4672,\\r\\n    \\\"Legacy Windows Event ID\\\": 576,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Special privileges assigned to new logon.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4720,\\r\\n    \\\"Legacy Windows Event ID\\\": 624,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A user account was created.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4722,\\r\\n    \\\"Legacy Windows Event ID\\\": 626,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A user account was enabled.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4723,\\r\\n    \\\"Legacy Windows Event ID\\\": 627,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An attempt was made to change an account's password.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4724,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"An attempt was made to reset an account's password.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4725,\\r\\n    \\\"Legacy Windows Event ID\\\": 629,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A user account was disabled.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4726,\\r\\n    \\\"Legacy Windows Event ID\\\": 630,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A user account was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4728,\\r\\n    \\\"Legacy Windows Event ID\\\": 632,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was added to a security-enabled global group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4732,\\r\\n    \\\"Legacy Windows Event ID\\\": 636,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was added to a security-enabled local group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4740,\\r\\n    \\\"Legacy Windows Event ID\\\": 644,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A user account was locked out.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4756,\\r\\n    \\\"Legacy Windows Event ID\\\": 660,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was added to a security-enabled universal group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4767,\\r\\n    \\\"Legacy Windows Event ID\\\": 671,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A user account was unlocked.\\\"\\r\\n  }\\r\\n\\r\\n]\",\"transformers\":null}",
                                "size": 0,
                                "title": "Relevant Event IDs for UEBA",
                                "queryType": 8,
                                "gridSettings": {
                                  "filter": true
                                }
                              },
                              "conditionalVisibility": {
                                "parameterName": "Essentialtype",
                                "comparison": "isEqualTo",
                                "value": "UEBA"
                              },
                              "name": "UEBAEvents"
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "{\"version\":\"1.0.0\",\"content\":\"[\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4618,\\r\\n    \\\"Potential Criticality\\\": \\\"High\\\",\\r\\n    \\\"Event Summary\\\": \\\"A monitored security event pattern has occurred.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4649,\\r\\n    \\\"Potential Criticality\\\": \\\"High\\\",\\r\\n    \\\"Event Summary\\\": \\\"A replay attack was detected. May be a harmless false positive due to misconfiguration error.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4719,\\r\\n    \\\"Potential Criticality\\\": \\\"High\\\",\\r\\n    \\\"Event Summary\\\": \\\"System audit policy was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4765,\\r\\n    \\\"Potential Criticality\\\": \\\"High\\\",\\r\\n    \\\"Event Summary\\\": \\\"SID History was added to an account.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4766,\\r\\n    \\\"Potential Criticality\\\": \\\"High\\\",\\r\\n    \\\"Event Summary\\\": \\\"An attempt to add SID History to an account failed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4794,\\r\\n    \\\"Potential Criticality\\\": \\\"High\\\",\\r\\n    \\\"Event Summary\\\": \\\"An attempt was made to set the Directory Services Restore Mode.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4897,\\r\\n    \\\"Potential Criticality\\\": \\\"High\\\",\\r\\n    \\\"Event Summary\\\": \\\"Role separation enabled:\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4964,\\r\\n    \\\"Potential Criticality\\\": \\\"High\\\",\\r\\n    \\\"Event Summary\\\": \\\"Special groups have been assigned to a new logon.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5124,\\r\\n    \\\"Potential Criticality\\\": \\\"High\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security setting was updated on the OCSP Responder Service\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": \\\"N/A\\\",\\r\\n    \\\"Potential Criticality\\\": \\\"Medium to High\\\",\\r\\n    \\\"Event Summary\\\": \\\"Possible denial-of-service (DoS) attack\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 1102,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium to High\\\",\\r\\n    \\\"Event Summary\\\": \\\"The audit log was cleared\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4621,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Administrator recovered system from CrashOnAuditFail. Users who are not administrators will now be allowed to log on. Some auditable activity might not have been recorded.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4675,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"SIDs were filtered.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4692,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Backup of data protection master key was attempted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4693,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Recovery of data protection master key was attempted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4706,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"A new trust was created to a domain.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4713,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Kerberos policy was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4714,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Encrypted data recovery policy was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4715,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"The audit policy (SACL) on an object was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4716,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Trusted domain information was modified.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4724,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"An attempt was made to reset an account's password.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4727,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-enabled global group was created.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4735,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-enabled local group was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4737,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-enabled global group was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4739,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Domain Policy was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4754,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-enabled universal group was created.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4755,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-enabled universal group was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4764,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-disabled group was deleted\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4764,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"A group's type was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4780,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"The ACL was set on accounts which are members of administrators groups.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4816,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"RPC detected an integrity violation while decrypting an incoming message.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4865,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"A trusted forest information entry was added.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4866,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"A trusted forest information entry was removed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4867,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"A trusted forest information entry was modified.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4868,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"The certificate manager denied a pending certificate request.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4870,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services revoked a certificate.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4882,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"The security permissions for Certificate Services changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4885,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"The audit filter for Certificate Services changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4890,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"The certificate manager settings for Certificate Services changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4892,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"A property of Certificate Services changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4896,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"One or more rows have been deleted from the certificate database.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4906,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"The CrashOnAuditFail value has changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4907,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Auditing settings on object were changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4908,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Special Groups Logon table modified.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4912,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Per User Audit Policy was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4960,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec dropped an inbound packet that failed an integrity check. If this problem persists, it could indicate a network issue or that packets are being modified in transit to this computer. Verify that the packets sent from the remote computer are the same as those received by this computer. This error might also indicate interoperability problems with other IPsec implementations.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4961,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec dropped an inbound packet that failed a replay check. If this problem persists, it could indicate a replay attack against this computer.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4962,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec dropped an inbound packet that failed a replay check. The inbound packet had too low a sequence number to ensure it was not a replay.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4963,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec dropped an inbound clear text packet that should have been secured. This is usually due to the remote computer changing its IPsec policy without informing this computer. This could also be a spoofing attack attempt.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4965,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec received a packet from a remote computer with an incorrect Security Parameter Index (SPI). This is usually caused by malfunctioning hardware that is corrupting packets. If these errors persist, verify that the packets sent from the remote computer are the same as those received by this computer. This error may also indicate interoperability problems with other IPsec implementations. In that case, if connectivity is not impeded, then these events can be ignored.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4976,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"During Main Mode negotiation, IPsec received an invalid negotiation packet. If this problem persists, it could indicate a network issue or an attempt to modify or replay this negotiation.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4977,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"During Quick Mode negotiation, IPsec received an invalid negotiation packet. If this problem persists, it could indicate a network issue or an attempt to modify or replay this negotiation.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4978,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"During Extended Mode negotiation, IPsec received an invalid negotiation packet. If this problem persists, it could indicate a network issue or an attempt to modify or replay this negotiation.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4983,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"An IPsec Extended Mode negotiation failed. The corresponding Main Mode security association has been deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4984,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"An IPsec Extended Mode negotiation failed. The corresponding Main Mode security association has been deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5027,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Firewall Service was unable to retrieve the security policy from the local storage. The service will continue enforcing the current policy.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5028,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Firewall Service was unable to parse the new security policy. The service will continue with currently enforced policy.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5029,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Firewall Service failed to initialize the driver. The service will continue to enforce the current policy.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5030,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Firewall Service failed to start.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5035,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Firewall Driver failed to start.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5037,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Firewall Driver detected critical runtime error. Terminating.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5038,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5120,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"OCSP Responder Service Started\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5121,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"OCSP Responder Service Stopped\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5122,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"A configuration entry changed in OCSP Responder Service\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5123,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"A configuration entry changed in OCSP Responder Service\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5376,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Credential Manager credentials were backed up.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5377,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Credential Manager credentials were restored from a backup.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5453,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"An IPsec negotiation with a remote computer failed because the IKE and AuthIP IPsec Keying Modules (IKEEXT) service is not started.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5480,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec Services failed to get the complete list of network interfaces on the computer. This poses a potential security risk because some of the network interfaces may not get the protection provided by the applied IPsec filters. Use the IP Security Monitor snap-in to diagnose the problem.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5483,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec Services failed to initialize RPC server. IPsec Services could not be started.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5484,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec Services has experienced a critical failure and has been shut down. The shutdown of IPsec Services can put the computer at greater risk of network attack or expose the computer to potential security risks.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5485,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec Services failed to process some IPsec filters on a plug-and-play event for network interfaces. This poses a potential security risk because some of the network interfaces may not get the protection provided by the applied IPsec filters. Use the IP Security Monitor snap-in to diagnose the problem.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5827,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Netlogon service denied a vulnerable Netlogon secure channel connection from a machine account.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5828,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Netlogon service denied a vulnerable Netlogon secure channel connection using a trust account.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 6145,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"One or more errors occurred while processing security policy in the Group Policy objects.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 6273,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Network Policy Server denied access to a user.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 6274,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Network Policy Server discarded the request for a user.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 6275,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Network Policy Server discarded the accounting request for a user.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 6276,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Network Policy Server quarantined a user.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 6277,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 6278,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Network Policy Server granted full access to a user because the host met the defined health policy.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 6279,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Network Policy Server locked the user account due to repeated failed authentication attempts.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 6280,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Network Policy Server unlocked the user account.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": \\\"-\\\",\\r\\n    \\\"Legacy Windows Event ID\\\": 640,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"General account database changed\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": \\\"-\\\",\\r\\n    \\\"Legacy Windows Event ID\\\": 619,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Quality of Service Policy changed\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 24586,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"An error was encountered converting volume\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 24592,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"An attempt to automatically restart conversion on volume %2 failed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 24593,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Metadata write: Volume %2 returning errors while trying to modify metadata. If failures continue, decrypt volume\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 24594,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"Metadata rebuild: An attempt to write a copy of metadata on volume %2 failed and may appear as disk corruption. If failures continue, decrypt volume.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4608,\\r\\n    \\\"Legacy Windows Event ID\\\": 512,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Windows is starting up.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4609,\\r\\n    \\\"Legacy Windows Event ID\\\": 513,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Windows is shutting down.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4610,\\r\\n    \\\"Legacy Windows Event ID\\\": 514,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An authentication package has been loaded by the Local Security Authority.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4611,\\r\\n    \\\"Legacy Windows Event ID\\\": 515,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A trusted logon process has been registered with the Local Security Authority.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4612,\\r\\n    \\\"Legacy Windows Event ID\\\": 516,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4614,\\r\\n    \\\"Legacy Windows Event ID\\\": 518,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A notification package has been loaded by the Security Account Manager.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4615,\\r\\n    \\\"Legacy Windows Event ID\\\": 519,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Invalid use of LPC port.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4616,\\r\\n    \\\"Legacy Windows Event ID\\\": 520,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The system time was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4622,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security package has been loaded by the Local Security Authority.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4624,\\r\\n    \\\"Legacy Windows Event ID\\\": \\\"528,540\\\",\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An account was successfully logged on.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4625,\\r\\n    \\\"Legacy Windows Event ID\\\": \\\"529-537,539\\\",\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An account failed to log on.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4634,\\r\\n    \\\"Legacy Windows Event ID\\\": 538,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An account was logged off.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4646,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"IKE DoS-prevention mode started.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4647,\\r\\n    \\\"Legacy Windows Event ID\\\": 551,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"User initiated logoff.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4648,\\r\\n    \\\"Legacy Windows Event ID\\\": 552,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A logon was attempted using explicit credentials.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4650,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An IPsec Main Mode security association was established. Extended Mode was not enabled. Certificate authentication was not used.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4651,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An IPsec Main Mode security association was established. Extended Mode was not enabled. A certificate was used for authentication.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4652,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An IPsec Main Mode negotiation failed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4653,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An IPsec Main Mode negotiation failed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4654,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An IPsec Quick Mode negotiation failed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4655,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An IPsec Main Mode security association ended.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4656,\\r\\n    \\\"Legacy Windows Event ID\\\": 560,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A handle to an object was requested.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4657,\\r\\n    \\\"Legacy Windows Event ID\\\": 567,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A registry value was modified.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4658,\\r\\n    \\\"Legacy Windows Event ID\\\": 562,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The handle to an object was closed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4659,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A handle to an object was requested with intent to delete.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4660,\\r\\n    \\\"Legacy Windows Event ID\\\": 564,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An object was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4661,\\r\\n    \\\"Legacy Windows Event ID\\\": 565,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A handle to an object was requested.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4662,\\r\\n    \\\"Legacy Windows Event ID\\\": 566,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An operation was performed on an object.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4663,\\r\\n    \\\"Legacy Windows Event ID\\\": 567,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An attempt was made to access an object.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4664,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An attempt was made to create a hard link.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4665,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An attempt was made to create an application client context.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4666,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An application attempted an operation:\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4667,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An application client context was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4668,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An application was initialized.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4670,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Permissions on an object were changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4671,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An application attempted to access a blocked ordinal through the TBS.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4672,\\r\\n    \\\"Legacy Windows Event ID\\\": 576,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Special privileges assigned to new logon.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4673,\\r\\n    \\\"Legacy Windows Event ID\\\": 577,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A privileged service was called.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4674,\\r\\n    \\\"Legacy Windows Event ID\\\": 578,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An operation was attempted on a privileged object.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4688,\\r\\n    \\\"Legacy Windows Event ID\\\": 592,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A new process has been created.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4689,\\r\\n    \\\"Legacy Windows Event ID\\\": 593,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A process has exited.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4690,\\r\\n    \\\"Legacy Windows Event ID\\\": 594,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An attempt was made to duplicate a handle to an object.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4691,\\r\\n    \\\"Legacy Windows Event ID\\\": 595,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Indirect access to an object was requested.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4694,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Protection of auditable protected data was attempted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4695,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Unprotection of auditable protected data was attempted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4696,\\r\\n    \\\"Legacy Windows Event ID\\\": 600,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A primary token was assigned to process.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4697,\\r\\n    \\\"Legacy Windows Event ID\\\": 601,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Attempt to install a service\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4698,\\r\\n    \\\"Legacy Windows Event ID\\\": 602,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A scheduled task was created.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4699,\\r\\n    \\\"Legacy Windows Event ID\\\": 602,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A scheduled task was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4700,\\r\\n    \\\"Legacy Windows Event ID\\\": 602,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A scheduled task was enabled.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4701,\\r\\n    \\\"Legacy Windows Event ID\\\": 602,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A scheduled task was disabled.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4702,\\r\\n    \\\"Legacy Windows Event ID\\\": 602,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A scheduled task was updated.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4704,\\r\\n    \\\"Legacy Windows Event ID\\\": 608,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A user right was assigned.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4705,\\r\\n    \\\"Legacy Windows Event ID\\\": 609,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A user right was removed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4707,\\r\\n    \\\"Legacy Windows Event ID\\\": 611,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A trust to a domain was removed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4709,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec Services was started.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4710,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec Services was disabled.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4711,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"May contain any one of the following: PAStore Engine applied locally cached copy of Active Directory storage IPsec policy on the computer. PAStore Engine applied Active Directory storage IPsec policy on the computer. PAStore Engine applied local registry storage IPsec policy on the computer. PAStore Engine failed to apply locally cached copy of Active Directory storage IPsec policy on the computer. PAStore Engine failed to apply Active Directory storage IPsec policy on the computer. PAStore Engine failed to apply local registry storage IPsec policy on the computer. PAStore Engine failed to apply some rules of the active IPsec policy on the computer. PAStore Engine failed to load directory storage IPsec policy on the computer. PAStore Engine loaded directory storage IPsec policy on the computer. PAStore Engine failed to load local storage IPsec policy on the computer. PAStore Engine loaded local storage IPsec policy on the computer.PAStore Engine polled for changes to the active IPsec policy and detected no changes.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4712,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec Services encountered a potentially serious failure.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4717,\\r\\n    \\\"Legacy Windows Event ID\\\": 621,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"System security access was granted to an account.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4718,\\r\\n    \\\"Legacy Windows Event ID\\\": 622,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"System security access was removed from an account.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4720,\\r\\n    \\\"Legacy Windows Event ID\\\": 624,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A user account was created.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4722,\\r\\n    \\\"Legacy Windows Event ID\\\": 626,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A user account was enabled.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4723,\\r\\n    \\\"Legacy Windows Event ID\\\": 627,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An attempt was made to change an account's password.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4725,\\r\\n    \\\"Legacy Windows Event ID\\\": 629,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A user account was disabled.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4726,\\r\\n    \\\"Legacy Windows Event ID\\\": 630,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A user account was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4728,\\r\\n    \\\"Legacy Windows Event ID\\\": 632,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was added to a security-enabled global group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4729,\\r\\n    \\\"Legacy Windows Event ID\\\": 633,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was removed from a security-enabled global group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4730,\\r\\n    \\\"Legacy Windows Event ID\\\": 634,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-enabled global group was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4731,\\r\\n    \\\"Legacy Windows Event ID\\\": 635,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-enabled local group was created.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4732,\\r\\n    \\\"Legacy Windows Event ID\\\": 636,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was added to a security-enabled local group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4733,\\r\\n    \\\"Legacy Windows Event ID\\\": 637,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was removed from a security-enabled local group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4734,\\r\\n    \\\"Legacy Windows Event ID\\\": 638,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-enabled local group was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4738,\\r\\n    \\\"Legacy Windows Event ID\\\": 642,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A user account was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4740,\\r\\n    \\\"Legacy Windows Event ID\\\": 644,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A user account was locked out.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4741,\\r\\n    \\\"Legacy Windows Event ID\\\": 645,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A computer account was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4742,\\r\\n    \\\"Legacy Windows Event ID\\\": 646,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A computer account was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4743,\\r\\n    \\\"Legacy Windows Event ID\\\": 647,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A computer account was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4744,\\r\\n    \\\"Legacy Windows Event ID\\\": 648,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-disabled local group was created.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4745,\\r\\n    \\\"Legacy Windows Event ID\\\": 649,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-disabled local group was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4746,\\r\\n    \\\"Legacy Windows Event ID\\\": 650,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was added to a security-disabled local group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4747,\\r\\n    \\\"Legacy Windows Event ID\\\": 651,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was removed from a security-disabled local group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4748,\\r\\n    \\\"Legacy Windows Event ID\\\": 652,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-disabled local group was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4749,\\r\\n    \\\"Legacy Windows Event ID\\\": 653,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-disabled global group was created.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4750,\\r\\n    \\\"Legacy Windows Event ID\\\": 654,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-disabled global group was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4751,\\r\\n    \\\"Legacy Windows Event ID\\\": 655,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was added to a security-disabled global group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4752,\\r\\n    \\\"Legacy Windows Event ID\\\": 656,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was removed from a security-disabled global group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4753,\\r\\n    \\\"Legacy Windows Event ID\\\": 657,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-disabled global group was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4756,\\r\\n    \\\"Legacy Windows Event ID\\\": 660,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was added to a security-enabled universal group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4757,\\r\\n    \\\"Legacy Windows Event ID\\\": 661,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was removed from a security-enabled universal group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4758,\\r\\n    \\\"Legacy Windows Event ID\\\": 662,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-enabled universal group was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4759,\\r\\n    \\\"Legacy Windows Event ID\\\": 663,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-disabled universal group was created.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4760,\\r\\n    \\\"Legacy Windows Event ID\\\": 664,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-disabled universal group was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4761,\\r\\n    \\\"Legacy Windows Event ID\\\": 665,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was added to a security-disabled universal group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4762,\\r\\n    \\\"Legacy Windows Event ID\\\": 666,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was removed from a security-disabled universal group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4767,\\r\\n    \\\"Legacy Windows Event ID\\\": 671,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A user account was unlocked.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4768,\\r\\n    \\\"Legacy Windows Event ID\\\": \\\"672,676\\\",\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A Kerberos authentication ticket (TGT) was requested.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4769,\\r\\n    \\\"Legacy Windows Event ID\\\": 673,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A Kerberos service ticket was requested.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4770,\\r\\n    \\\"Legacy Windows Event ID\\\": 674,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A Kerberos service ticket was renewed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4771,\\r\\n    \\\"Legacy Windows Event ID\\\": 675,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Kerberos pre-authentication failed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4772,\\r\\n    \\\"Legacy Windows Event ID\\\": 672,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A Kerberos authentication ticket request failed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4774,\\r\\n    \\\"Legacy Windows Event ID\\\": 678,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An account was mapped for logon.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4775,\\r\\n    \\\"Legacy Windows Event ID\\\": 679,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An account could not be mapped for logon.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4776,\\r\\n    \\\"Legacy Windows Event ID\\\": \\\"680,681\\\",\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The domain controller attempted to validate the credentials for an account.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4777,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The domain controller failed to validate the credentials for an account.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4778,\\r\\n    \\\"Legacy Windows Event ID\\\": 682,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A session was reconnected to a Window Station.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4779,\\r\\n    \\\"Legacy Windows Event ID\\\": 683,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A session was disconnected from a Window Station.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4781,\\r\\n    \\\"Legacy Windows Event ID\\\": 685,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The name of an account was changed:\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4782,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The password hash an account was accessed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4783,\\r\\n    \\\"Legacy Windows Event ID\\\": 667,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A basic application group was created.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4784,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A basic application group was changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4785,\\r\\n    \\\"Legacy Windows Event ID\\\": 689,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was added to a basic application group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4786,\\r\\n    \\\"Legacy Windows Event ID\\\": 690,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was removed from a basic application group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4787,\\r\\n    \\\"Legacy Windows Event ID\\\": 691,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A nonmember was added to a basic application group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4788,\\r\\n    \\\"Legacy Windows Event ID\\\": 692,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A nonmember was removed from a basic application group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4789,\\r\\n    \\\"Legacy Windows Event ID\\\": 693,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A basic application group was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4790,\\r\\n    \\\"Legacy Windows Event ID\\\": 694,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An LDAP query group was created.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4793,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Password Policy Checking API was called.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4800,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The workstation was locked.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4801,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The workstation was unlocked.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4802,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The screen saver was invoked.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4803,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The screen saver was dismissed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4864,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A namespace collision was detected.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4869,\\r\\n    \\\"Legacy Windows Event ID\\\": 773,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services received a resubmitted certificate request.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4871,\\r\\n    \\\"Legacy Windows Event ID\\\": 775,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services received a request to publish the certificate revocation list (CRL).\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4872,\\r\\n    \\\"Legacy Windows Event ID\\\": 776,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services published the certificate revocation list (CRL).\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4873,\\r\\n    \\\"Legacy Windows Event ID\\\": 777,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A certificate request extension changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4874,\\r\\n    \\\"Legacy Windows Event ID\\\": 778,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"One or more certificate request attributes changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4875,\\r\\n    \\\"Legacy Windows Event ID\\\": 779,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services received a request to shut down.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4876,\\r\\n    \\\"Legacy Windows Event ID\\\": 780,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services backup started.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4877,\\r\\n    \\\"Legacy Windows Event ID\\\": 781,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services backup completed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4878,\\r\\n    \\\"Legacy Windows Event ID\\\": 782,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services restore started.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4879,\\r\\n    \\\"Legacy Windows Event ID\\\": 783,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services restore completed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4880,\\r\\n    \\\"Legacy Windows Event ID\\\": 784,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services started.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4881,\\r\\n    \\\"Legacy Windows Event ID\\\": 785,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services stopped.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4883,\\r\\n    \\\"Legacy Windows Event ID\\\": 787,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services retrieved an archived key.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4884,\\r\\n    \\\"Legacy Windows Event ID\\\": 788,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services imported a certificate into its database.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4886,\\r\\n    \\\"Legacy Windows Event ID\\\": 790,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services received a certificate request.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4887,\\r\\n    \\\"Legacy Windows Event ID\\\": 791,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services approved a certificate request and issued a certificate.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4888,\\r\\n    \\\"Legacy Windows Event ID\\\": 792,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services denied a certificate request.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4889,\\r\\n    \\\"Legacy Windows Event ID\\\": 793,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services set the status of a certificate request to pending.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4891,\\r\\n    \\\"Legacy Windows Event ID\\\": 795,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A configuration entry changed in Certificate Services.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4893,\\r\\n    \\\"Legacy Windows Event ID\\\": 797,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services archived a key.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4894,\\r\\n    \\\"Legacy Windows Event ID\\\": 798,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services imported and archived a key.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4895,\\r\\n    \\\"Legacy Windows Event ID\\\": 799,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services published the CA certificate to Active Directory Domain Services.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4898,\\r\\n    \\\"Legacy Windows Event ID\\\": 802,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Certificate Services loaded a template.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4902,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Per-user audit policy table was created.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4904,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An attempt was made to register a security event source.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4905,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An attempt was made to unregister a security event source.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4909,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The local policy settings for the TBS were changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4910,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Group Policy settings for the TBS were changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4928,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An Active Directory replica source naming context was established.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4929,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An Active Directory replica source naming context was removed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4930,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An Active Directory replica source naming context was modified.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4931,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An Active Directory replica destination naming context was modified.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4932,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Synchronization of a replica of an Active Directory naming context has begun.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4933,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Synchronization of a replica of an Active Directory naming context has ended.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4934,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Attributes of an Active Directory object were replicated.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4935,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Replication failure begins.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4936,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Replication failure ends.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4937,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A lingering object was removed from a replica.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4944,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The following policy was active when the Windows Firewall started.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4945,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A rule was listed when the Windows Firewall started.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4946,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A change has been made to Windows Firewall exception list. A rule was added.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4947,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A change has been made to Windows Firewall exception list. A rule was modified.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4948,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A change has been made to Windows Firewall exception list. A rule was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4949,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Windows Firewall settings were restored to the default values.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4950,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A Windows Firewall setting has changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4951,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A rule has been ignored because its major version number was not recognized by Windows Firewall.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4952,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Parts of a rule have been ignored because its minor version number was not recognized by Windows Firewall. The other parts of the rule will be enforced.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4953,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A rule has been ignored by Windows Firewall because it could not parse the rule.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4954,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Windows Firewall Group Policy settings have changed. The new settings have been applied.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4956,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Windows Firewall has changed the active profile.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4957,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Windows Firewall did not apply the following rule:\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4958,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Windows Firewall did not apply the following rule because the rule referred to items not configured on this computer:\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4979,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec Main Mode and Extended Mode security associations were established.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4980,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec Main Mode and Extended Mode security associations were established.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4981,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec Main Mode and Extended Mode security associations were established.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4982,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec Main Mode and Extended Mode security associations were established.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4985,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The state of a transaction has changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5024,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Firewall Service has started successfully.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5025,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Firewall Service has been stopped.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5031,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Firewall Service blocked an application from accepting incoming connections on the network.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5032,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5033,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Firewall Driver has started successfully.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5034,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Firewall Driver has been stopped.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5039,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A registry key was virtualized.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5040,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A change has been made to IPsec settings. An Authentication Set was added.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5041,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A change has been made to IPsec settings. An Authentication Set was modified.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5042,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A change has been made to IPsec settings. An Authentication Set was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5043,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A change has been made to IPsec settings. A Connection Security Rule was added.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5044,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A change has been made to IPsec settings. A Connection Security Rule was modified.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5045,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A change has been made to IPsec settings. A Connection Security Rule was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5046,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A change has been made to IPsec settings. A Crypto Set was added.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5047,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A change has been made to IPsec settings. A Crypto Set was modified.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5048,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A change has been made to IPsec settings. A Crypto Set was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5050,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An attempt to programmatically disable the Windows Firewall using a call to InetFwProfile.FirewallEnabled(False)\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5051,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A file was virtualized.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5056,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A cryptographic self test was performed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5057,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A cryptographic primitive operation failed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5058,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Key file operation.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5059,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Key migration operation.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5060,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Verification operation failed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5061,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Cryptographic operation.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5062,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A kernel-mode cryptographic self test was performed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5063,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A cryptographic provider operation was attempted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5064,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A cryptographic context operation was attempted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5065,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A cryptographic context modification was attempted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5066,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A cryptographic function operation was attempted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5067,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A cryptographic function modification was attempted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5068,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A cryptographic function provider operation was attempted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5069,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A cryptographic function property operation was attempted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5070,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A cryptographic function property modification was attempted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5125,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A request was submitted to the OCSP Responder Service\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5126,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Signing Certificate was automatically updated by the OCSP Responder Service\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5127,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The OCSP Revocation Provider successfully updated the revocation information\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5136,\\r\\n    \\\"Legacy Windows Event ID\\\": 566,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A directory service object was modified.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5137,\\r\\n    \\\"Legacy Windows Event ID\\\": 566,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A directory service object was created.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5138,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A directory service object was undeleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5139,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A directory service object was moved.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5140,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A network share object was accessed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5141,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A directory service object was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5152,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Filtering Platform blocked a packet.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5153,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A more restrictive Windows Filtering Platform filter has blocked a packet.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5154,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5155,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5156,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Filtering Platform has allowed a connection.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5157,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Filtering Platform has blocked a connection.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5158,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Filtering Platform has permitted a bind to a local port.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5159,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The Windows Filtering Platform has blocked a bind to a local port.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5378,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The requested credentials delegation was disallowed by policy.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5440,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The following callout was present when the Windows Filtering Platform Base Filtering Engine started.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5441,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The following filter was present when the Windows Filtering Platform Base Filtering Engine started.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5442,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The following provider was present when the Windows Filtering Platform Base Filtering Engine started.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5443,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The following provider context was present when the Windows Filtering Platform Base Filtering Engine started.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5444,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The following sublayer was present when the Windows Filtering Platform Base Filtering Engine started.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5446,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A Windows Filtering Platform callout has been changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5447,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A Windows Filtering Platform filter has been changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5448,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A Windows Filtering Platform provider has been changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5449,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A Windows Filtering Platform provider context has been changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5450,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A Windows Filtering Platform sublayer has been changed.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5451,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An IPsec Quick Mode security association was established.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5452,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An IPsec Quick Mode security association ended.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5456,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine applied Active Directory storage IPsec policy on the computer.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5457,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine failed to apply Active Directory storage IPsec policy on the computer.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5458,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine applied locally cached copy of Active Directory storage IPsec policy on the computer.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5459,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine failed to apply locally cached copy of Active Directory storage IPsec policy on the computer.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5460,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine applied local registry storage IPsec policy on the computer.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5461,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine failed to apply local registry storage IPsec policy on the computer.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5462,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine failed to apply some rules of the active IPsec policy on the computer. Use the IP Security Monitor snap-in to diagnose the problem.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5463,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine polled for changes to the active IPsec policy and detected no changes.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5464,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine polled for changes to the active IPsec policy, detected changes, and applied them to IPsec Services.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5465,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine received a control for forced reloading of IPsec policy and processed the control successfully.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5466,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory cannot be reached, and will use the cached copy of the Active Directory IPsec policy instead. Any changes made to the Active Directory IPsec policy since the last poll could not be applied.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5467,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, and found no changes to the policy. The cached copy of the Active Directory IPsec policy is no longer being used.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5468,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, found changes to the policy, and applied those changes. The cached copy of the Active Directory IPsec policy is no longer being used.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5471,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine loaded local storage IPsec policy on the computer.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5472,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine failed to load local storage IPsec policy on the computer.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5473,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine loaded directory storage IPsec policy on the computer.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5474,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine failed to load directory storage IPsec policy on the computer.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5477,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"PAStore Engine failed to add quick mode filter.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5479,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec Services has been shut down successfully. The shutdown of IPsec Services can put the computer at greater risk of network attack or expose the computer to potential security risks.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5632,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A request was made to authenticate to a wireless network.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5633,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A request was made to authenticate to a wired network.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5712,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A Remote Procedure Call (RPC) was attempted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5888,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An object in the COM+ Catalog was modified.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5889,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An object was deleted from the COM+ Catalog.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5890,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An object was added to the COM+ Catalog.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 6008,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The previous system shutdown was unexpected\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 6144,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Security policy in the Group Policy objects has been applied successfully.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 6272,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Network Policy Server granted access to a user.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": \\\"N/A\\\",\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A handle to an object was requested.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": \\\"N/A\\\",\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Object open for delete\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": \\\"N/A\\\",\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"User Account Type Changed\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": \\\"N/A\\\",\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec policy agent started\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": \\\"N/A\\\",\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec policy agent disabled\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": \\\"N/A\\\",\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec policy agent\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": \\\"N/A\\\",\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec policy agent encountered a potential serious failure\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 24577,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Encryption of volume started\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 24578,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Encryption of volume stopped\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 24579,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Encryption of volume completed\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 24580,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Decryption of volume started\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 24581,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Decryption of volume stopped\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 24582,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Decryption of volume completed\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 24583,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Conversion worker thread for volume started\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 24584,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Conversion worker thread for volume temporarily stopped\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 24588,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The conversion operation on volume %2 encountered a bad sector error. Please validate the data on this volume\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 24595,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Volume %2 contains bad clusters. These clusters will be skipped during conversion.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 24621,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"Initial state check: Rolling volume conversion transaction on %2.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5049,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An IPsec Security Association was deleted.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 5478,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"IPsec Services has started successfully.\\\"\\r\\n  }\\r\\n]\",\"transformers\":null}",
                                "size": 0,
                                "title": "Relevant Event IDs for Analytic Rules",
                                "queryType": 8,
                                "gridSettings": {
                                  "rowLimit": 1000,
                                  "filter": true
                                }
                              },
                              "conditionalVisibility": {
                                "parameterName": "Essentialtype",
                                "comparison": "isEqualTo",
                                "value": "AR"
                              },
                              "name": "AREvents"
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "{\"version\":\"1.0.0\",\"content\":\"[\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4624,\\r\\n    \\\"Legacy Windows Event ID\\\": \\\"528,540\\\",\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An account was successfully logged on.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4625,\\r\\n    \\\"Legacy Windows Event ID\\\": \\\"529-537,539\\\",\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An account failed to log on.\\\"\\r\\n  },\\t\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4688,\\r\\n    \\\"Legacy Windows Event ID\\\": 592,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A new process has been created.\\\"\\r\\n  },\\t\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4720,\\r\\n    \\\"Legacy Windows Event ID\\\": 624,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A user account was created.\\\"\\r\\n  },\\t\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4723,\\r\\n    \\\"Legacy Windows Event ID\\\": 627,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"An attempt was made to change an account's password.\\\"\\r\\n  },\\t\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4724,\\r\\n    \\\"Legacy Windows Event ID\\\": 628,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"An attempt was made to reset an account's password.\\\"\\r\\n  },\\t\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4726,\\r\\n    \\\"Legacy Windows Event ID\\\": 630,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A user account was deleted.\\\"\\r\\n  },\\t\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4727,\\r\\n    \\\"Legacy Windows Event ID\\\": 631,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-enabled global group was created.\\\"\\r\\n  },\\t\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4728,\\r\\n    \\\"Legacy Windows Event ID\\\": 632,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was added to a security-enabled global group.\\\"\\r\\n  },\\r\\n    {\\r\\n    \\\"Current Windows Event ID\\\": 4729,\\r\\n    \\\"Legacy Windows Event ID\\\": 633,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was removed from a security-enabled global group.\\\"\\r\\n  },\\t\\r\\n    {\\r\\n    \\\"Current Windows Event ID\\\": 4731,\\r\\n    \\\"Legacy Windows Event ID\\\": 635,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-enabled local group was created.\\\"\\r\\n  },\\t\\r\\n    {\\r\\n    \\\"Current Windows Event ID\\\": 4732,\\r\\n    \\\"Legacy Windows Event ID\\\": 636,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was added to a security-enabled local group.\\\"\\r\\n  },\\t\\r\\n    {\\r\\n    \\\"Current Windows Event ID\\\": 4733,\\r\\n    \\\"Legacy Windows Event ID\\\": 637,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was removed from a security-enabled local group.\\\"\\r\\n  },\\t\\r\\n    {\\r\\n    \\\"Current Windows Event ID\\\": 4740,\\r\\n    \\\"Legacy Windows Event ID\\\": 644,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A user account was locked out.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4746,\\r\\n    \\\"Legacy Windows Event ID\\\": 650,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was added to a security-disabled local group.\\\"\\r\\n  },\\t\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4747,\\r\\n    \\\"Legacy Windows Event ID\\\": 651,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was removed from a security-disabled local group.\\\"\\r\\n  },\\t\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4751,\\r\\n    \\\"Legacy Windows Event ID\\\": 655,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was added to a security-disabled global group.\\\"\\r\\n  },\\t\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4752,\\r\\n    \\\"Legacy Windows Event ID\\\": 656,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was removed from a security-disabled global group.\\\"\\r\\n  },\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4754,\\r\\n    \\\"Legacy Windows Event ID\\\": 658,\\r\\n    \\\"Potential Criticality\\\": \\\"Medium\\\",\\r\\n    \\\"Event Summary\\\": \\\"A security-enabled universal group was created.\\\"\\r\\n  },\\t\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4756,\\r\\n    \\\"Legacy Windows Event ID\\\": 660,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was added to a security-enabled universal group.\\\"\\r\\n  },\\t\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4761,\\r\\n    \\\"Legacy Windows Event ID\\\": 665,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was added to a security-disabled universal group.\\\"\\r\\n  },\\t\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4762,\\r\\n    \\\"Legacy Windows Event ID\\\": 666,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A member was removed from a security-disabled universal group.\\\"\\r\\n  },\\t\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4769,\\r\\n    \\\"Legacy Windows Event ID\\\": 673,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A Kerberos service ticket was requested.\\\"\\r\\n  },\\t\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 4776,\\r\\n    \\\"Legacy Windows Event ID\\\": \\\"680,681\\\",\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"The domain controller attempted to validate the credentials for an account.\\\"\\r\\n  },\\t\\r\\n  {\\r\\n    \\\"Current Windows Event ID\\\": 7045,\\r\\n    \\\"Potential Criticality\\\": \\\"Low\\\",\\r\\n    \\\"Event Summary\\\": \\\"A new service was installed by the user indicated in the subject.\\\"\\r\\n  }\\r\\n]\",\"transformers\":null}",
                                "size": 0,
                                "title": "Relevant Event IDs for Hunting",
                                "queryType": 8,
                                "gridSettings": {
                                  "rowLimit": 1000,
                                  "filter": true,
                                  "sortBy": [
                                    {
                                      "itemKey": "Current Windows Event ID",
                                      "sortOrder": 1
                                    }
                                  ]
                                },
                                "sortBy": [
                                  {
                                    "itemKey": "Current Windows Event ID",
                                    "sortOrder": 1
                                  }
                                ]
                              },
                              "conditionalVisibility": {
                                "parameterName": "Essentialtype",
                                "comparison": "isEqualTo",
                                "value": "Hunting"
                              },
                              "name": "HuntEvents - Copy"
                            }
                          ],
                          "exportParameters": true
                        },
                        "name": "Essentials"
                      },
                      {
                        "type": 9,
                        "content": {
                          "version": "KqlParameterItem/1.0",
                          "parameters": [
                            {
                              "id": "47eb961c-27ac-42df-aa52-8ad9aa948312",
                              "version": "KqlParameterItem/1.0",
                              "name": "DeployWorkspace",
                              "label": "Deploy to Workspace",
                              "type": 5,
                              "query": "resources\r\n| where type == 'microsoft.operationalinsights/workspaces'\r\n| project id, name\r\n| order by name asc",
                              "crossComponentResources": [
                                "{subscriptionId}"
                              ],
                              "typeSettings": {
                                "additionalResourceOptions": []
                              },
                              "timeContext": {
                                "durationMs": 86400000
                              },
                              "queryType": 1,
                              "resourceType": "microsoft.resourcegraph/resources",
                              "value": null
                            },
                            {
                              "id": "a665804c-8d16-488d-9e4e-2a86ce795cde",
                              "version": "KqlParameterItem/1.0",
                              "name": "DWLocation",
                              "type": 1,
                              "query": "resources\r\n| where id has '{DeployWorkspace}'\r\n| project location",
                              "crossComponentResources": [
                                "{subscriptionId}"
                              ],
                              "isHiddenWhenLocked": true,
                              "timeContext": {
                                "durationMs": 86400000
                              },
                              "queryType": 1,
                              "resourceType": "microsoft.resourcegraph/resources"
                            },
                            {
                              "id": "5f4b913e-5fa9-49b3-8d9d-29670ea614bc",
                              "version": "KqlParameterItem/1.0",
                              "name": "DCE",
                              "type": 5,
                              "query": "resources\r\n| where type has 'Microsoft.Insights/dataCollectionEndpoints'\r\n| where location == '{DWLocation}'\r\n| project id, name\r\n| order by tolower(name) asc",
                              "crossComponentResources": [
                                "{subscriptionId}"
                              ],
                              "typeSettings": {
                                "additionalResourceOptions": [],
                                "showDefault": false
                              },
                              "timeContext": {
                                "durationMs": 86400000
                              },
                              "queryType": 1,
                              "resourceType": "microsoft.resourcegraph/resources",
                              "value": null
                            }
                          ],
                          "style": "above",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces"
                        },
                        "name": "parameters - 15"
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "parameters": [
                                  {
                                    "id": "33f9ca01-5f0b-4bcf-b89e-2dee06aa0f34",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "DCRName",
                                    "type": 1,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "value": "",
                                    "label": "DCR Name"
                                  }
                                ],
                                "style": "above",
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces"
                              },
                              "customWidth": "10",
                              "name": "parameters - 2"
                            },
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "parameters": [
                                  {
                                    "id": "005ffe63-0900-4006-808d-9d2714eb6967",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "DCR2Name",
                                    "type": 1,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "value": "",
                                    "label": "Second DCR Name"
                                  }
                                ],
                                "style": "above",
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces"
                              },
                              "customWidth": "90",
                              "conditionalVisibility": {
                                "parameterName": "UEBADCR2",
                                "comparison": "isNotEqualTo",
                                "value": "Blank"
                              },
                              "name": "parameters - 3"
                            },
                            {
                              "type": 11,
                              "content": {
                                "version": "LinkItem/1.0",
                                "style": "list",
                                "links": [
                                  {
                                    "id": "1e056a8d-d856-453b-9ae5-c574e36ebbdf",
                                    "linkTarget": "ArmAction",
                                    "linkLabel": "Deploy DCR",
                                    "style": "primary",
                                    "linkIsContextBlade": true,
                                    "armActionContext": {
                                      "path": "{subscriptionId}/resourceGroups/{DeployWorkspace:resourceGroup}/providers/Microsoft.Insights/dataCollectionRules/{DCRName}?api-version=2021-09-01-preview",
                                      "headers": [],
                                      "params": [],
                                      "body": "{\r\n    \"location\": \"{DWLocation}\",\r\n    \"properties\": {\r\n      \"dataCollectionEndpointId\": \"{DCE}\",\r\n      \"dataSources\": {\r\n        \"windowsEventLogs\": [\r\n          {\r\n            \"name\": \"eventLogsDataSource\",\r\n            \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n            ],\r\n            \"xPathQueries\": \r\n              {generatedJSONUEBA}\r\n            \r\n          }\r\n        ]\r\n      },\r\n      \"destinations\": {\r\n        \"logAnalytics\": [\r\n          {\r\n            \"workspaceResourceId\": \"{DeployWorkspace}\",\r\n            \"name\": \"{DeployWorkspace:name}\"\r\n          }\r\n        ]\r\n      },\r\n      \"dataFlows\": [\r\n        {\r\n          \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n          ],\r\n          \"destinations\": [\r\n            \"{DeployWorkspace:name}\"\r\n          ]\r\n        }\r\n      ]\r\n    }\r\n  }",
                                      "httpMethod": "PUT",
                                      "title": "Deploying New Windows DCR {DCRName}",
                                      "description": "This action will deploy DCR {DCRName} to {DeployWorkspace}\n\nThe EventsIDs to be collected are\n\n{generatedJSONUEBA}",
                                      "runLabel": "Deploy DCR"
                                    }
                                  }
                                ]
                              },
                              "customWidth": "10",
                              "name": "links - 2"
                            },
                            {
                              "type": 11,
                              "content": {
                                "version": "LinkItem/1.0",
                                "style": "list",
                                "links": [
                                  {
                                    "id": "c15b62b2-e5ac-45fe-b065-efdd889bd212",
                                    "linkTarget": "ArmAction",
                                    "linkLabel": "Deploy Second DCR",
                                    "style": "primary",
                                    "linkIsContextBlade": true,
                                    "armActionContext": {
                                      "path": "{subscriptionId}/resourceGroups/{DeployWorkspace:resourceGroup}/providers/Microsoft.Insights/dataCollectionRules/{DCR2Name}?api-version=2021-09-01-preview",
                                      "headers": [],
                                      "params": [],
                                      "body": "{\r\n    \"location\": \"{DWLocation}\",\r\n    \"properties\": {\r\n     \"dataCollectionEndpointId\": \"{DCE}\",\r\n      \"dataSources\": {\r\n        \"windowsEventLogs\": [\r\n          {\r\n            \"name\": \"eventLogsDataSource\",\r\n            \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n            ],\r\n            \"xPathQueries\": \r\n              {UEBADCR2}\r\n            \r\n          }\r\n        ]\r\n      },\r\n      \"destinations\": {\r\n        \"logAnalytics\": [\r\n          {\r\n            \"workspaceResourceId\": \"{DeployWorkspace}\",\r\n            \"name\": \"{DeployWorkspace:name}\"\r\n          }\r\n        ]\r\n      },\r\n      \"dataFlows\": [\r\n        {\r\n          \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n          ],\r\n          \"destinations\": [\r\n            \"{DeployWorkspace:name}\"\r\n          ]\r\n        }\r\n      ]\r\n    }\r\n  }",
                                      "httpMethod": "PUT",
                                      "title": "Deploying New Windows DCR {DCR2Name}",
                                      "description": "This action will deploy DCR {DCR2Name} to {DeployWorkspace}\n\nThe EventsIDs to be collected are\n\n{UEBADCR2}",
                                      "runLabel": "Deploy DCR"
                                    }
                                  }
                                ]
                              },
                              "customWidth": "10",
                              "conditionalVisibility": {
                                "parameterName": "ARDCR2",
                                "comparison": "isNotEqualTo",
                                "value": "Blank"
                              },
                              "name": "links - 2 - Copy"
                            }
                          ]
                        },
                        "conditionalVisibility": {
                          "parameterName": "Essentialtype",
                          "comparison": "isEqualTo",
                          "value": "UEBA"
                        },
                        "name": "UEBA DCR"
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "crossComponentResources": [
                                  "{subscriptionId}"
                                ],
                                "parameters": [
                                  {
                                    "id": "fc4dbf09-af20-40e4-a62a-0d6fd4e9ed8e",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "DCRName",
                                    "label": "DCR Name",
                                    "type": 1,
                                    "isRequired": true,
                                    "value": "",
                                    "timeContext": {
                                      "durationMs": 86400000
                                    }
                                  }
                                ],
                                "style": "above",
                                "queryType": 1,
                                "resourceType": "microsoft.resourcegraph/resources"
                              },
                              "customWidth": "10",
                              "name": "parameters - 0"
                            },
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "parameters": [
                                  {
                                    "id": "deae5522-1800-4e48-ae09-1d11a496fe48",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "DCR2Name",
                                    "type": 1,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "value": "",
                                    "label": "Second DCR Name"
                                  }
                                ],
                                "style": "above",
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces"
                              },
                              "customWidth": "90",
                              "conditionalVisibility": {
                                "parameterName": "ARDCR2",
                                "comparison": "isNotEqualTo",
                                "value": "Blank"
                              },
                              "name": "parameters - 2"
                            },
                            {
                              "type": 11,
                              "content": {
                                "version": "LinkItem/1.0",
                                "style": "list",
                                "links": [
                                  {
                                    "id": "1e056a8d-d856-453b-9ae5-c574e36ebbdf",
                                    "linkTarget": "ArmAction",
                                    "linkLabel": "Deploy DCR",
                                    "style": "primary",
                                    "linkIsContextBlade": true,
                                    "armActionContext": {
                                      "path": "{subscriptionId}/resourceGroups/{DeployWorkspace:resourceGroup}/providers/Microsoft.Insights/dataCollectionRules/{DCRName}?api-version=2021-09-01-preview",
                                      "headers": [],
                                      "params": [],
                                      "body": "{\r\n    \"location\": \"{DWLocation}\",\r\n    \"properties\": {\r\n      \"dataCollectionEndpointId\": \"{DCE}\",\r\n      \"dataSources\": {\r\n        \"windowsEventLogs\": [\r\n          {\r\n            \"name\": \"eventLogsDataSource\",\r\n            \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n            ],\r\n            \"xPathQueries\": \r\n              {generatedJSONAR}\r\n            \r\n          }\r\n        ]\r\n      },\r\n      \"destinations\": {\r\n        \"logAnalytics\": [\r\n          {\r\n            \"workspaceResourceId\": \"{DeployWorkspace}\",\r\n            \"name\": \"{DeployWorkspace:name}\"\r\n          }\r\n        ]\r\n      },\r\n      \"dataFlows\": [\r\n        {\r\n          \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n          ],\r\n          \"destinations\": [\r\n            \"{DeployWorkspace:name}\"\r\n          ]\r\n        }\r\n      ]\r\n    }\r\n  }",
                                      "httpMethod": "PUT",
                                      "title": "Deploying New Windows DCR {DCRName}",
                                      "description": "This action will deploy DCR {DCRName} to {DeployWorkspace}\n\nThe EventsIDs to be collected are\n\n{generatedJSONAR}",
                                      "runLabel": "Deploy DCR"
                                    }
                                  }
                                ]
                              },
                              "customWidth": "10",
                              "name": "links - 2"
                            },
                            {
                              "type": 11,
                              "content": {
                                "version": "LinkItem/1.0",
                                "style": "list",
                                "links": [
                                  {
                                    "id": "a0e14128-e49f-4e67-b1f2-21624d9e9d1e",
                                    "linkTarget": "ArmAction",
                                    "linkLabel": "Deploy Second DCR",
                                    "style": "primary",
                                    "linkIsContextBlade": true,
                                    "armActionContext": {
                                      "path": "{subscriptionId}/resourceGroups/{DeployWorkspace:resourceGroup}/providers/Microsoft.Insights/dataCollectionRules/{DCR2Name}?api-version=2021-09-01-preview",
                                      "headers": [],
                                      "params": [],
                                      "body": "{\r\n    \"location\": \"{DWLocation}\",\r\n    \"properties\": {\r\n      \"dataCollectionEndpointId\": \"{DCE}\",\r\n      \"dataSources\": {\r\n        \"windowsEventLogs\": [\r\n          {\r\n            \"name\": \"eventLogsDataSource\",\r\n            \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n            ],\r\n            \"xPathQueries\": \r\n              {ARDCR2}\r\n            \r\n          }\r\n        ]\r\n      },\r\n      \"destinations\": {\r\n        \"logAnalytics\": [\r\n          {\r\n            \"workspaceResourceId\": \"{DeployWorkspace}\",\r\n            \"name\": \"{DeployWorkspace:name}\"\r\n          }\r\n        ]\r\n      },\r\n      \"dataFlows\": [\r\n        {\r\n          \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n          ],\r\n          \"destinations\": [\r\n            \"{DeployWorkspace:name}\"\r\n          ]\r\n        }\r\n      ]\r\n    }\r\n  }",
                                      "httpMethod": "PUT",
                                      "title": "Deploying New Windows DCR {DCR2Name}",
                                      "description": "This action will deploy DCR {DCR2Name} to {DeployWorkspace}\n\nThe EventsIDs to be collected are\n\n{ARDCR2}",
                                      "runLabel": "Deploy DCR"
                                    }
                                  }
                                ]
                              },
                              "customWidth": "90",
                              "conditionalVisibility": {
                                "parameterName": "ARDCR2",
                                "comparison": "isNotEqualTo",
                                "value": "Blank"
                              },
                              "name": "links - 2 - Copy"
                            }
                          ]
                        },
                        "conditionalVisibility": {
                          "parameterName": "Essentialtype",
                          "comparison": "isEqualTo",
                          "value": "AR"
                        },
                        "name": "AR DCR"
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "crossComponentResources": [
                                  "{subscriptionId}"
                                ],
                                "parameters": [
                                  {
                                    "id": "fc4dbf09-af20-40e4-a62a-0d6fd4e9ed8e",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "DCRName",
                                    "label": "DCR Name",
                                    "type": 1,
                                    "isRequired": true,
                                    "value": "Hunt1",
                                    "timeContext": {
                                      "durationMs": 86400000
                                    }
                                  }
                                ],
                                "style": "above",
                                "queryType": 1,
                                "resourceType": "microsoft.resourcegraph/resources"
                              },
                              "customWidth": "10",
                              "name": "parameters - 0"
                            },
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "parameters": [
                                  {
                                    "id": "deae5522-1800-4e48-ae09-1d11a496fe48",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "DCR2Name",
                                    "type": 1,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "value": "Hunt2",
                                    "label": "Second DCR Name"
                                  }
                                ],
                                "style": "above",
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces"
                              },
                              "customWidth": "90",
                              "conditionalVisibility": {
                                "parameterName": "ARDCR2",
                                "comparison": "isNotEqualTo",
                                "value": "Blank"
                              },
                              "name": "parameters - 2"
                            },
                            {
                              "type": 11,
                              "content": {
                                "version": "LinkItem/1.0",
                                "style": "list",
                                "links": [
                                  {
                                    "id": "1e056a8d-d856-453b-9ae5-c574e36ebbdf",
                                    "linkTarget": "ArmAction",
                                    "linkLabel": "Deploy DCR",
                                    "style": "primary",
                                    "linkIsContextBlade": true,
                                    "armActionContext": {
                                      "path": "{subscriptionId}/resourceGroups/{DeployWorkspace:resourceGroup}/providers/Microsoft.Insights/dataCollectionRules/{DCRName}?api-version=2021-09-01-preview",
                                      "headers": [],
                                      "params": [],
                                      "body": "{\r\n    \"location\": \"{DWLocation}\",\r\n    \"properties\": {\r\n      \"dataCollectionEndpointId\": \"{DCE}\",\r\n      \"dataSources\": {\r\n        \"windowsEventLogs\": [\r\n          {\r\n            \"name\": \"eventLogsDataSource\",\r\n            \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n            ],\r\n            \"xPathQueries\": \r\n              {generatedJSONAR}\r\n            \r\n          }\r\n        ]\r\n      },\r\n      \"destinations\": {\r\n        \"logAnalytics\": [\r\n          {\r\n            \"workspaceResourceId\": \"{DeployWorkspace}\",\r\n            \"name\": \"{DeployWorkspace:name}\"\r\n          }\r\n        ]\r\n      },\r\n      \"dataFlows\": [\r\n        {\r\n          \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n          ],\r\n          \"destinations\": [\r\n            \"{DeployWorkspace:name}\"\r\n          ]\r\n        }\r\n      ]\r\n    }\r\n  }",
                                      "httpMethod": "PUT",
                                      "title": "Deploying New Windows DCR {DCRName}",
                                      "description": "This action will deploy DCR {DCRName} to {DeployWorkspace}\n\nThe EventsIDs to be collected are\n\n{generatedJSONAR}",
                                      "runLabel": "Deploy DCR"
                                    }
                                  }
                                ]
                              },
                              "customWidth": "10",
                              "name": "links - 2"
                            },
                            {
                              "type": 11,
                              "content": {
                                "version": "LinkItem/1.0",
                                "style": "list",
                                "links": [
                                  {
                                    "id": "a0e14128-e49f-4e67-b1f2-21624d9e9d1e",
                                    "linkTarget": "ArmAction",
                                    "linkLabel": "Deploy Second DCR",
                                    "style": "primary",
                                    "linkIsContextBlade": true,
                                    "armActionContext": {
                                      "path": "{subscriptionId}/resourceGroups/{DeployWorkspace:resourceGroup}/providers/Microsoft.Insights/dataCollectionRules/{DCR2Name}?api-version=2021-09-01-preview",
                                      "headers": [],
                                      "params": [],
                                      "body": "{\r\n    \"location\": \"{DWLocation}\",\r\n    \"properties\": {\r\n      \"dataCollectionEndpointId\": \"{DCE}\",\r\n      \"dataSources\": {\r\n        \"windowsEventLogs\": [\r\n          {\r\n            \"name\": \"eventLogsDataSource\",\r\n            \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n            ],\r\n            \"xPathQueries\": \r\n              {ARDCR2}\r\n            \r\n          }\r\n        ]\r\n      },\r\n      \"destinations\": {\r\n        \"logAnalytics\": [\r\n          {\r\n            \"workspaceResourceId\": \"{DeployWorkspace}\",\r\n            \"name\": \"{DeployWorkspace:name}\"\r\n          }\r\n        ]\r\n      },\r\n      \"dataFlows\": [\r\n        {\r\n          \"streams\": [\r\n              \"Microsoft-SecurityEvent\"\r\n          ],\r\n          \"destinations\": [\r\n            \"{DeployWorkspace:name}\"\r\n          ]\r\n        }\r\n      ]\r\n    }\r\n  }",
                                      "httpMethod": "PUT",
                                      "title": "Deploying New Windows DCR {DCR2Name}",
                                      "description": "This action will deploy DCR {DCR2Name} to {DeployWorkspace}\n\nThe EventsIDs to be collected are\n\n{ARDCR2}",
                                      "runLabel": "Deploy DCR"
                                    }
                                  }
                                ]
                              },
                              "customWidth": "90",
                              "conditionalVisibility": {
                                "parameterName": "ARDCR2",
                                "comparison": "isNotEqualTo",
                                "value": "Blank"
                              },
                              "name": "links - 2 - Copy"
                            }
                          ]
                        },
                        "conditionalVisibility": {
                          "parameterName": "Essentialtype",
                          "comparison": "isEqualTo",
                          "value": "Hunting"
                        },
                        "name": "Hunting DCR - Copy"
                      }
                    ]
                  },
                  "conditionalVisibilities": [
                    {
                      "parameterName": "Tab",
                      "comparison": "isEqualTo",
                      "value": "1"
                    },
                    {
                      "parameterName": "Datatype",
                      "comparison": "isEqualTo",
                      "value": "Essentials"
                    }
                  ],
                  "name": "Essentials"
                }
              ]
            },
            "conditionalVisibility": {
              "parameterName": "GroupTab",
              "comparison": "isNotEqualTo",
              "value": "docs"
            },
            "name": "New DCR"
          }
        ]
      },
      "conditionalVisibility": {
        "parameterName": "Tab",
        "comparison": "isEqualTo",
        "value": "1"
      },
      "name": "Identify and Deploy - Group"
    },
    {
      "type": 11,
      "content": {
        "version": "LinkItem/1.0",
        "style": "tabs",
        "links": [
          {
            "id": "3c4eb185-d763-4b67-93c6-ac796dd0f849",
            "cellValue": "Tab2",
            "linkTarget": "parameter",
            "linkLabel": "List of Configured DCRs",
            "subTarget": "1",
            "style": "link"
          },
          {
            "id": "119aaff0-5774-4508-a58b-22d233364819",
            "cellValue": "Tab2",
            "linkTarget": "parameter",
            "linkLabel": "DCRs Listed By Workspace",
            "subTarget": "2",
            "style": "link"
          }
        ]
      },
      "conditionalVisibility": {
        "parameterName": "Tab",
        "comparison": "isEqualTo",
        "value": "2"
      },
      "name": "Configure DCR Tab"
    },
    {
      "type": 1,
      "content": {
        "json": "### Help\r\nThis tab is dedicated to listing existing DCRs with all of their details. It also allows for you to make changes to the DCR and deploy those changes without having to leave the workbook. </br>\r\n\r\nThe listed DCRs below contain: </br>\r\n- The DCR name with a link to the resource\r\n- The rule type (Windows, Linux, Custom, etc.)\r\n- DCR location\r\n- If Syslog is configured and a link to a summary of the configuration\r\n- If Windows events are configured and a link to a summary of the configuration\r\n- If Security events are configured and a link to a summary of the configuration\r\n- If the DCR is pointing to a data collection endpoint (DCE) with a link to the resource\r\n- If the DCR contains a KQL transformation rule with a link to a summary of the KQL\r\n- The worksapce that the DCR is pointing to with a link to the resource.\r\n\r\nThis list should be used to review existing collection rules, evaluate if there are duplicate rules, and monitor existing rules to track ongoing ingestion.",
        "style": "info"
      },
      "conditionalVisibilities": [
        {
          "parameterName": "Help",
          "comparison": "isEqualTo",
          "value": "Yes"
        },
        {
          "parameterName": "Tab",
          "comparison": "isEqualTo",
          "value": "2"
        }
      ],
      "name": "text - 17"
    },
    {
      "type": 11,
      "content": {
        "version": "LinkItem/1.0",
        "style": "toolbar",
        "links": [
          {
            "id": "f8bc3e2b-3b0a-4017-876c-578c92b1ce48",
            "cellValue": "{selectedRule:$.properties}",
            "linkTarget": "CellDetails",
            "linkLabel": "Properties",
            "postText": "View DCR Rule properties",
            "style": "link",
            "icon": "Properties",
            "linkIsContextBlade": true,
            "bladeOpenContext": {
              "bladeName": "DataSourcePickerViewModel",
              "extensionName": "Microsoft_Azure_Monitoring",
              "bladeParameters": [
                {
                  "name": "initialDataSources",
                  "source": "static",
                  "value": "[]"
                },
                {
                  "name": "initialDataFlows",
                  "source": "static",
                  "value": "[]"
                },
                {
                  "name": "initialDestinations",
                  "source": "static",
                  "value": "[]"
                },
                {
                  "name": "initialBasicPerfCounters",
                  "source": "static",
                  "value": "[]"
                },
                {
                  "name": "initialCustomPerfCounters",
                  "source": "static",
                  "value": "[]"
                },
                {
                  "name": "initialSelectedEventLogsMap",
                  "source": "static",
                  "value": "[]"
                },
                {
                  "name": "initialCustomEventLogs",
                  "source": "static",
                  "value": "[]"
                },
                {
                  "name": "initialSysLogsMapping",
                  "source": "static",
                  "value": "[]"
                },
                {
                  "name": "hasDceConfigs",
                  "source": "static",
                  "value": "[]"
                }
              ]
            }
          },
          {
            "id": "cebb8688-2f90-4839-826c-c922b572e198",
            "cellValue": "{selectedRule:$.id}",
            "linkTarget": "Resource",
            "linkLabel": "Export Template",
            "subTarget": "exporttemplate",
            "postText": "Export ARM Template",
            "style": "link",
            "icon": "Download",
            "bladeOpenContext": {
              "bladeName": "subscriptions",
              "extensionName": "resource",
              "bladeParameters": [
                {
                  "name": "b43c0ddd-0ded-47c6-b1f7-e0a875272452",
                  "source": "static",
                  "value": "resourceGroups"
                },
                {
                  "name": "SKYSERVER-RG",
                  "source": "static",
                  "value": "providers"
                },
                {
                  "name": "Microsoft.Insights",
                  "source": "static",
                  "value": "dataCollectionRules"
                },
                {
                  "name": "Syslog_DCR",
                  "source": "static",
                  "value": "exporttemplate"
                }
              ]
            }
          }
        ]
      },
      "conditionalVisibility": {
        "parameterName": "Tab",
        "comparison": "isEqualTo",
        "value": "2"
      },
      "name": "links - 4",
      "styleSettings": {
        "margin": "20px 0px 0px 0px"
      }
    },
    {
      "type": 3,
      "content": {
        "version": "KqlItem/1.0",
        "query": "{\"version\":\"ARMEndpoint/1.0\",\"data\":null,\"headers\":[],\"method\":\"GET\",\"path\":\"{subscriptionId}/providers/Microsoft.Insights/dataCollectionRules\",\"urlParams\":[{\"key\":\"api-version\",\"value\":\"2021-09-01-preview\"}],\"batchDisabled\":false,\"transformers\":[{\"type\":\"jsonpath\",\"settings\":{\"tablePath\":\"$.value\",\"columns\":[{\"path\":\"id\",\"columnid\":\"id\"},{\"path\":\"$\",\"columnid\":\"properties\"},{\"path\":\"kind\",\"columnid\":\"kind\"},{\"path\":\"location\",\"columnid\":\"location\"},{\"path\":\"properties.provisioningState\",\"columnid\":\"provisioningState\"},{\"path\":\"name\",\"columnid\":\"name\"},{\"path\":\"properties.dataSources.syslog\",\"columnid\":\"syslog\"},{\"path\":\"properties.dataSources.windowsEventLogs[*]\",\"columnid\":\"windowsEventLogs\"},{\"path\":\"properties.dataSources.windowsEventLogs[*].streams[?(@ ==\\\"Microsoft-SecurityEvent\\\")]\",\"columnid\":\"securityEvents\"},{\"path\":\"properties.dataCollectionEndpointId\",\"columnid\":\"dataCollectionEndpointId\"},{\"path\":\"properties.dataFlows[?(@.transformKql != \\\"source\\\")].transformKql\",\"columnid\":\"transformKql\"},{\"path\":\"properties.destinations\",\"columnid\":\"destinations\"},{\"path\":\"properties.dataFlows[*].transformKql\",\"columnid\":\"queries\"},{\"path\":\"properties.dataSources\",\"columnid\":\"dataSources\"},{\"path\":\"properties.dataFlows\",\"columnid\":\"dataFlows\"},{\"path\":\"description\",\"columnid\":\"description\"},{\"path\":\"properties.destinations.logAnalytics.*.name\",\"columnid\":\"destinationName\"},{\"path\":\"systemData.lastModifiedBy\",\"columnid\":\"lastModifiedBy\"},{\"path\":\"properties.destinations.logAnalytics.*.workspaceResourceId\",\"columnid\":\"workspaceResourceId\"}]}}]}",
        "size": 2,
        "title": "List of Currently Configured Data Collection Rules",
        "showRefreshButton": true,
        "exportedParameters": [
          {
            "parameterName": "selectedRule"
          },
          {
            "fieldName": "destinationName",
            "parameterName": "destinationName",
            "parameterType": 1
          },
          {
            "fieldName": "",
            "parameterName": "resourceGroupName",
            "parameterType": 1
          },
          {
            "fieldName": "workspaceResourceId",
            "parameterName": "workspace",
            "parameterType": 5
          },
          {
            "fieldName": "properties",
            "parameterName": "properties",
            "parameterType": 1
          },
          {
            "fieldName": "name",
            "parameterName": "name",
            "parameterType": 1
          },
          {
            "fieldName": "location",
            "parameterName": "location",
            "parameterType": 1
          },
          {
            "fieldName": "Rule Type",
            "parameterName": "kind",
            "parameterType": 1
          },
          {
            "parameterType": 1
          },
          {
            "fieldName": "id",
            "parameterName": "id",
            "parameterType": 1
          }
        ],
        "showExportToExcel": true,
        "exportToExcelOptions": "all",
        "queryType": 12,
        "gridSettings": {
          "formatters": [
            {
              "columnMatch": "id",
              "formatter": 13,
              "formatOptions": {
                "linkColumn": "id",
                "linkTarget": "Resource",
                "linkIsContextBlade": true,
                "showIcon": true
              }
            },
            {
              "columnMatch": "properties",
              "formatter": 7,
              "formatOptions": {
                "linkTarget": "CellDetails",
                "linkLabel": "📋",
                "linkIsContextBlade": true,
                "customColumnWidthSetting": "5ch"
              }
            },
            {
              "columnMatch": "kind",
              "formatter": 18,
              "formatOptions": {
                "thresholdsOptions": "icons",
                "thresholdsGrid": [
                  {
                    "operator": "is Empty",
                    "representation": "Capture",
                    "text": "{0}{1} Custom"
                  },
                  {
                    "operator": "contains",
                    "thresholdValue": "Linux",
                    "representation": "Console",
                    "text": "{0}{1}"
                  },
                  {
                    "operator": "contains",
                    "thresholdValue": "Windows",
                    "representation": "Initial_Access",
                    "text": "{0}{1}"
                  },
                  {
                    "operator": "contains",
                    "thresholdValue": "WorkspaceTransforms",
                    "representation": "Persistence",
                    "text": "{0}{1}"
                  },
                  {
                    "operator": "Default",
                    "thresholdValue": null,
                    "representation": "success",
                    "text": "{0}{1}"
                  }
                ],
                "customColumnWidthSetting": "17ch"
              }
            },
            {
              "columnMatch": "location",
              "formatter": 17,
              "formatOptions": {
                "customColumnWidthSetting": "94px"
              }
            },
            {
              "columnMatch": "provisioningState",
              "formatter": 18,
              "formatOptions": {
                "thresholdsOptions": "icons",
                "thresholdsGrid": [
                  {
                    "operator": "contains",
                    "thresholdValue": "succeeded",
                    "representation": "success",
                    "text": "{0}{1}"
                  },
                  {
                    "operator": "Default",
                    "thresholdValue": null,
                    "representation": "success",
                    "text": "{0}{1}"
                  }
                ],
                "customColumnWidthSetting": "17ch"
              },
              "numberFormat": {
                "unit": 0,
                "options": {
                  "style": "decimal"
                }
              }
            },
            {
              "columnMatch": "name",
              "formatter": 5
            },
            {
              "columnMatch": "syslog",
              "formatter": 18,
              "formatOptions": {
                "linkTarget": "CellDetails",
                "subTarget": "2",
                "linkIsContextBlade": true,
                "thresholdsOptions": "icons",
                "thresholdsGrid": [
                  {
                    "operator": "is Empty",
                    "representation": "cancelled",
                    "text": "Not Configured"
                  },
                  {
                    "operator": "Default",
                    "thresholdValue": null,
                    "representation": "success",
                    "text": "Enabled"
                  }
                ],
                "bladeOpenContext": {
                  "bladeName": "DataCollectionRulesDataSourceManagementViewModel",
                  "extensionName": "Microsoft_Azure_Monitoring",
                  "bladeParameters": [
                    {
                      "name": "id",
                      "source": "column",
                      "value": "id"
                    }
                  ]
                },
                "customColumnWidthSetting": "20ch"
              }
            },
            {
              "columnMatch": "windowsEventLogs",
              "formatter": 18,
              "formatOptions": {
                "linkTarget": "CellDetails",
                "linkIsContextBlade": true,
                "thresholdsOptions": "icons",
                "thresholdsGrid": [
                  {
                    "operator": "is Empty",
                    "representation": "cancelled",
                    "text": "Not Configured"
                  },
                  {
                    "operator": "Default",
                    "thresholdValue": null,
                    "representation": "success",
                    "text": "Configured"
                  }
                ],
                "customColumnWidthSetting": "20ch"
              }
            },
            {
              "columnMatch": "securityEvents",
              "formatter": 18,
              "formatOptions": {
                "linkColumn": "windowsEventLogs",
                "linkTarget": "CellDetails",
                "linkIsContextBlade": true,
                "thresholdsOptions": "icons",
                "thresholdsGrid": [
                  {
                    "operator": "is Empty",
                    "representation": "cancelled",
                    "text": "Not Configured"
                  },
                  {
                    "operator": "Default",
                    "thresholdValue": null,
                    "representation": "success",
                    "text": "Configured"
                  }
                ],
                "customColumnWidthSetting": "20ch"
              }
            },
            {
              "columnMatch": "customEvents",
              "formatter": 18,
              "formatOptions": {
                "linkTarget": "CellDetails",
                "linkIsContextBlade": true,
                "thresholdsOptions": "icons",
                "thresholdsGrid": [
                  {
                    "operator": "is Empty",
                    "representation": "cancelled",
                    "text": "Not Configured"
                  },
                  {
                    "operator": "Default",
                    "thresholdValue": null,
                    "representation": "success",
                    "text": "Configured"
                  }
                ],
                "customColumnWidthSetting": "20ch"
              }
            },
            {
              "columnMatch": "dataCollectionEndpointId",
              "formatter": 18,
              "formatOptions": {
                "linkTarget": "Resource",
                "linkIsContextBlade": true,
                "thresholdsOptions": "icons",
                "thresholdsGrid": [
                  {
                    "operator": "is Empty",
                    "representation": "cancelled",
                    "text": "Not Configured"
                  },
                  {
                    "operator": "Default",
                    "thresholdValue": null,
                    "representation": "success",
                    "text": "Configured"
                  }
                ],
                "customColumnWidthSetting": "21.7143ch"
              }
            },
            {
              "columnMatch": "transformKql",
              "formatter": 18,
              "formatOptions": {
                "linkColumn": "queries",
                "linkTarget": "CellDetails",
                "linkIsContextBlade": true,
                "thresholdsOptions": "icons",
                "thresholdsGrid": [
                  {
                    "operator": "is Empty",
                    "representation": "stopped",
                    "text": "Not Configured"
                  },
                  {
                    "operator": "contains",
                    "thresholdValue": "Workspace",
                    "representation": "success",
                    "text": "Ingestion KQL"
                  },
                  {
                    "operator": "Default",
                    "thresholdValue": null,
                    "representation": "success",
                    "text": "Custom KQL"
                  }
                ],
                "bladeOpenContext": {
                  "bladeName": "CreateMicrosoftTableTransformBlade",
                  "extensionName": "Microsoft_OperationsManagementSuite_Workspace",
                  "bladeJsonParameters": "{\r\n\t\"workspaceResourceId\" : \"{workspace}\",\r\n\t\"providers\" : \"microsoft.operationalinsights\",\r\n\t\"table\" : { \r\n\t\t\"name\" : \"{selectedTableName}\",\r\n\t\t\"description\":\"Security events collected from windows machines by Azure Security Center or Azure Sentinel.\",\r\n\t\t\"hasData\":true,\r\n\t\t\"tableType\":\"Microsoft\",\r\n\t\t\"tableAPIState\":\"Any\",\r\n\t\t\"solutions\":[\"Security and Audit\",\"Microsoft Sentinel\"],\r\n\t\t\"categories\":[\"Security\"],\r\n\t\t\"retentionInDaysAsDefault\":false,\r\n\t\t\"totalRetentionInDaysAsDefault\":false,\r\n\t\t\"isEditTransformationEnabled\":true,\r\n\t\t\"isCreateTransformationEnabled\":true\r\n\t},\r\n\t\"isMicrosoftTable\" : true,\r\n\t\"isMigrationRequired\" : false\r\n}"
                },
                "customColumnWidthSetting": "22ch"
              }
            },
            {
              "columnMatch": "destinations",
              "formatter": 5
            },
            {
              "columnMatch": "queries",
              "formatter": 5
            },
            {
              "columnMatch": "dataSources",
              "formatter": 5
            },
            {
              "columnMatch": "dataFlows",
              "formatter": 5,
              "formatOptions": {
                "aggregation": "Sum"
              }
            },
            {
              "columnMatch": "description",
              "formatter": 5
            },
            {
              "columnMatch": "destinationName",
              "formatter": 5
            },
            {
              "columnMatch": "lastModifiedBy",
              "formatter": 5
            },
            {
              "columnMatch": "workspaceResourceId",
              "formatter": 13,
              "formatOptions": {
                "linkTarget": "Resource",
                "showIcon": true,
                "customColumnWidthSetting": "16.8571ch"
              }
            },
            {
              "columnMatch": "StepTab",
              "formatter": 5
            }
          ],
          "rowLimit": 1000,
          "filter": true,
          "sortBy": [
            {
              "itemKey": "$gen_link_id_0",
              "sortOrder": 1
            }
          ],
          "labelSettings": [
            {
              "columnId": "id",
              "label": "Data Collection Rule"
            },
            {
              "columnId": "properties",
              "label": " "
            },
            {
              "columnId": "kind",
              "label": "Rule Type"
            },
            {
              "columnId": "location",
              "label": "Location"
            },
            {
              "columnId": "provisioningState",
              "label": "Provisioned",
              "comment": "State of configuration "
            },
            {
              "columnId": "syslog",
              "label": "Syslog"
            },
            {
              "columnId": "windowsEventLogs",
              "label": "Windows Events"
            },
            {
              "columnId": "securityEvents",
              "label": "Security Events"
            },
            {
              "columnId": "dataCollectionEndpointId",
              "label": "Collection Endpoint"
            },
            {
              "columnId": "transformKql",
              "label": "Ingestion Transform"
            },
            {
              "columnId": "destinations",
              "label": "Destinations"
            },
            {
              "columnId": "workspaceResourceId",
              "label": "Workspace"
            }
          ]
        },
        "sortBy": [
          {
            "itemKey": "$gen_link_id_0",
            "sortOrder": 1
          }
        ]
      },
      "conditionalVisibilities": [
        {
          "parameterName": "Tab2",
          "comparison": "isEqualTo",
          "value": "1"
        },
        {
          "parameterName": "Tab",
          "comparison": "isEqualTo",
          "value": "2"
        }
      ],
      "name": "Select Existing DCR",
      "styleSettings": {
        "showBorder": true
      }
    },
    {
      "type": 1,
      "content": {
        "json": "### Help and Guide\r\n\r\nThis section of the tab is meant to allow users to modify the selected DCR. The below JSON editor contains the configuration of the DCR. Make the changes either in the editor or in an external editor. When finished, click 'Deploy Update' to update the DCR. The button will run an API call to write the changes to the resource.",
        "style": "info"
      },
      "conditionalVisibilities": [
        {
          "parameterName": "Help",
          "comparison": "isEqualTo",
          "value": "Yes"
        },
        {
          "parameterName": "Tab",
          "comparison": "isEqualTo",
          "value": "2"
        },
        {
          "parameterName": "Tab2",
          "comparison": "isNotEqualTo",
          "value": "2"
        }
      ],
      "name": "text - 19"
    },
    {
      "type": 11,
      "content": {
        "version": "LinkItem/1.0",
        "style": "paragraph",
        "links": [
          {
            "id": "97716920-b7f4-42a3-8d8d-787351196385",
            "cellValue": "Value",
            "linkTarget": "parameter",
            "linkLabel": "Modify DCR",
            "subTarget": "Set",
            "style": "primary"
          },
          {
            "id": "8806092d-9486-4ebf-9f7a-10ca0467423e",
            "cellValue": "Value",
            "linkTarget": "parameter",
            "linkLabel": "Done",
            "subTarget": "Done",
            "style": "primary"
          }
        ]
      },
      "conditionalVisibilities": [
        {
          "parameterName": "Tab",
          "comparison": "isEqualTo",
          "value": "2"
        },
        {
          "parameterName": "Tab2",
          "comparison": "isEqualTo",
          "value": "1"
        }
      ],
      "name": "links - 7"
    },
    {
      "type": 1,
      "content": {
        "json": "### Currently Modifying: {name}"
      },
      "conditionalVisibilities": [
        {
          "parameterName": "Value",
          "comparison": "isEqualTo",
          "value": "Set"
        },
        {
          "parameterName": "Tab",
          "comparison": "isEqualTo",
          "value": "2"
        }
      ],
      "name": "text - 18"
    },
    {
      "type": 9,
      "content": {
        "version": "KqlParameterItem/1.0",
        "crossComponentResources": [
          "{workspace}"
        ],
        "parameters": [
          {
            "id": "5371804f-914f-43c3-a63c-e68bee8c5d1a",
            "version": "KqlParameterItem/1.0",
            "name": "Properties",
            "type": 1,
            "query": "print rule=dynamic({selectedRule})\r\n| evaluate bag_unpack(rule)\r\n| extend type = column_ifexists(\"kind\",\"Custom\")\r\n| project todynamic(properties)\r\n| evaluate bag_unpack(properties)\r\n| project-away etag, type, name,systemData\r\n| project properties = pack_all()\r\n\r\n",
            "isHiddenWhenLocked": true,
            "typeSettings": {
              "multiLineText": true,
              "editorLanguage": "text"
            },
            "timeContext": {
              "durationMs": 86400000
            },
            "queryType": 0,
            "resourceType": "microsoft.operationalinsights/workspaces"
          },
          {
            "id": "95eac5ff-ed08-46aa-9e0e-a0949729dc39",
            "version": "KqlParameterItem/1.0",
            "name": "DCRG",
            "type": 1,
            "query": "print '{id}'\r\n| extend holder = split(tostring('{id}'), '/')\r\n| project RG = strcat( '/', holder[1],'/', holder[2], '/', holder[3], '/', holder[4])\r\n",
            "crossComponentResources": [
              "{workspace}"
            ],
            "isHiddenWhenLocked": true,
            "queryType": 0,
            "resourceType": "microsoft.operationalinsights/workspaces"
          }
        ],
        "style": "pills",
        "queryType": 0,
        "resourceType": "microsoft.operationalinsights/workspaces"
      },
      "conditionalVisibility": {
        "parameterName": "1",
        "comparison": "isEqualTo",
        "value": "2"
      },
      "name": "parameters - 18"
    },
    {
      "type": 9,
      "content": {
        "version": "KqlParameterItem/1.0",
        "parameters": [
          {
            "id": "936488d4-1392-45e3-a54b-37ae76988a97",
            "version": "KqlParameterItem/1.0",
            "name": "template",
            "label": "DCRTemplate",
            "type": 1,
            "isRequired": true,
            "isGlobal": true,
            "query": "print test = dynamic({Properties})\r\n",
            "typeSettings": {
              "multiLineText": true,
              "editorLanguage": "json",
              "multiLineHeight": 40,
              "preFormatJsonData": true
            },
            "timeContext": {
              "durationMs": 86400000
            },
            "queryType": 0,
            "resourceType": "microsoft.operationalinsights/workspaces",
            "value": null
          }
        ],
        "style": "above",
        "queryType": 0,
        "resourceType": "microsoft.operationalinsights/workspaces"
      },
      "conditionalVisibilities": [
        {
          "parameterName": "Value",
          "comparison": "isEqualTo",
          "value": "Set"
        },
        {
          "parameterName": "Tab2",
          "comparison": "isEqualTo",
          "value": "1"
        },
        {
          "parameterName": "Tab",
          "comparison": "isEqualTo",
          "value": "2"
        }
      ],
      "name": "parameters - 8"
    },
    {
      "type": 11,
      "content": {
        "version": "LinkItem/1.0",
        "style": "paragraph",
        "links": [
          {
            "id": "472428e4-3a55-4b8a-a940-23b0272eec06",
            "cellValue": "",
            "linkTarget": "OpenBlade",
            "linkLabel": "Write Transformation KQL",
            "subTarget": "logs",
            "style": "primary",
            "linkIsContextBlade": true,
            "bladeOpenContext": {
              "bladeName": "LogsBlade",
              "extensionName": "Microsoft_Azure_Monitoring_Logs",
              "bladeParameters": [
                {
                  "name": "resourceId",
                  "source": "static",
                  "value": "{workspace}"
                },
                {
                  "name": "source",
                  "source": "static",
                  "value": "LogsBlade.AnalyticsShareLinkToQuery"
                }
              ]
            }
          },
          {
            "id": "57580a59-508e-47e4-8646-6b08ef65d835",
            "linkTarget": "ArmAction",
            "linkLabel": "Deploy Update",
            "style": "primary",
            "linkIsContextBlade": true,
            "armActionContext": {
              "path": "{DCRG}/providers/Microsoft.Insights/dataCollectionRules/{name}?api-version=2021-09-01-preview",
              "headers": [],
              "params": [],
              "body": "{template}",
              "httpMethod": "PUT",
              "title": "Update Data Collection Rule: {name}",
              "description": "### You are about to commit changes to DCR {name}. Please confirm the changes you have made are valid and are the intended changes that you would like to push. This API will be redeploying the ARM template for this DCR. Connected machines will not be dropped.\r\n",
              "runLabel": "Update DCR"
            }
          }
        ]
      },
      "conditionalVisibilities": [
        {
          "parameterName": "Value",
          "comparison": "isEqualTo",
          "value": "Set"
        },
        {
          "parameterName": "Tab2",
          "comparison": "isEqualTo",
          "value": "1"
        },
        {
          "parameterName": "Tab",
          "comparison": "isEqualTo",
          "value": "2"
        }
      ],
      "name": "links - 9"
    },
    {
      "type": 1,
      "content": {
        "json": "### Help\r\n\r\nThis view within the tab is meant to highlight which workspaces currently have one or more DCR's sending data to them. This data should be reviewed in order to monitor which workpaces are ingesting data and if there are duplicates within the data.",
        "style": "info"
      },
      "conditionalVisibilities": [
        {
          "parameterName": "Tab",
          "comparison": "isEqualTo",
          "value": "2"
        },
        {
          "parameterName": "Tab2",
          "comparison": "isEqualTo",
          "value": "2"
        }
      ],
      "name": "text - 20"
    },
    {
      "type": 12,
      "content": {
        "version": "NotebookGroup/1.0",
        "groupType": "editable",
        "items": [
          {
            "type": 1,
            "content": {
              "json": "## Configure Data Collection Rule (DCR)\r\nThe most simplist way to explain a DCR is it manages the data flow from data sources to log analytics\r\n\r\nData Collection Rules (DCRs) define the data collection process in Azure Monitor. DCRs specify what data should be collected, how to transform that data, and where to send that data. Some DCRs will be created and managed by Azure Monitor to collect a specific set of data to enable insights and visualizations. You may also create your own DCRs to define the set of data required for other scenarios.\r\n\r\n- [Data collection rules in Azure Monitor](https://docs.microsoft.com/azure/azure-monitor/essentials/data-collection-rule-overview)\r\n\r\nDecide if you want to create a new rule from scratch or copy an existing rule and change some parameters."
            },
            "conditionalVisibilities": [
              {
                "parameterName": "Help",
                "comparison": "isEqualTo",
                "value": "Yes"
              },
              {
                "parameterName": "Tab2",
                "comparison": "isEqualTo",
                "value": "1"
              }
            ],
            "name": "text - 5"
          },
          {
            "type": 1,
            "content": {
              "json": "No DCR rule selected to copy!",
              "style": "warning"
            },
            "conditionalVisibilities": [
              {
                "parameterName": "CopyRule",
                "comparison": "isEqualTo",
                "value": "Yes"
              },
              {
                "parameterName": "selectedRule",
                "comparison": "isEqualTo"
              }
            ],
            "name": "Warning - No Rule selected"
          },
          {
            "type": 3,
            "content": {
              "version": "KqlItem/1.0",
              "query": "print rule=todynamic(\"{selectedRule:escapejson}\")\r\n| evaluate bag_unpack(rule)\r\n| extend dataFlows = todynamic(dataFlows)\r\n| extend kqlQueries = array_length(dataFlows)\r\n| extend destinations = todynamic(destinations)\r\n// Filter dataflows if a specific dataflow is selected\r\n| mv-apply dataFlows on\r\n(\r\n    where dataFlows.streams contains \"{selectedStream}\" or isempty(\"{selectedStream}\")\r\n    | summarize dataFlows=make_set(dataFlows)\r\n)\r\n//| where dataFlows.streams contains \"{selectedStream}\" or isempty(\"{selectedStream}\")",
              "size": 4,
              "title": "Selected Rule",
              "timeContext": {
                "durationMs": 86400000
              },
              "exportToExcelOptions": "all",
              "queryType": 0,
              "resourceType": "microsoft.operationalinsights/workspaces"
            },
            "conditionalVisibility": {
              "parameterName": "Tab2",
              "comparison": "isEqualTo",
              "value": "1"
            },
            "name": "Selected Rule"
          },
          {
            "type": 3,
            "content": {
              "version": "KqlItem/1.0",
              "query": "{\"version\":\"ARMEndpoint/1.0\",\"data\":null,\"headers\":[],\"method\":\"GET\",\"path\":\"{subscriptionId}/providers/Microsoft.OperationalInsights/workspaces\",\"urlParams\":[{\"key\":\"api-version\",\"value\":\"2021-12-01-preview\"}],\"batchDisabled\":false,\"transformers\":[{\"type\":\"jsonpath\",\"settings\":{\"tablePath\":\"$.value[?(@.properties.defaultDataCollectionRuleResourceId)]\",\"columns\":[{\"path\":\"id\",\"columnid\":\"id\"},{\"path\":\"name\",\"columnid\":\"name\"},{\"path\":\"location\",\"columnid\":\"location\"},{\"path\":\"properties.defaultDataCollectionRuleResourceId\",\"columnid\":\"dcrRuleId\"}]}}]}",
              "size": 0,
              "title": "Workspaces with Default DCR Configured",
              "queryType": 12,
              "gridSettings": {
                "formatters": [
                  {
                    "columnMatch": "id",
                    "formatter": 13,
                    "formatOptions": {
                      "linkTarget": "Resource",
                      "linkIsContextBlade": true,
                      "showIcon": true
                    }
                  },
                  {
                    "columnMatch": "dcrRuleId",
                    "formatter": 13,
                    "formatOptions": {
                      "linkTarget": "Resource",
                      "linkIsContextBlade": true,
                      "showIcon": true
                    }
                  }
                ]
              }
            },
            "conditionalVisibility": {
              "parameterName": "Tab2",
              "comparison": "isEqualTo",
              "value": "2"
            },
            "name": "Workspaces - DCR Configured"
          }
        ]
      },
      "conditionalVisibilities": [
        {
          "parameterName": "Tab",
          "comparison": "isEqualTo",
          "value": "2"
        },
        {
          "parameterName": "Tab2",
          "comparison": "isEqualTo",
          "value": "2"
        }
      ],
      "name": "Configure DCR",
      "styleSettings": {
        "padding": "15px 0px 0px 0px"
      }
    },
    {
      "type": 3,
      "content": {
        "version": "KqlItem/1.0",
        "query": "// Get data collection rules\r\nResources\r\n| where type == \"microsoft.insights/datacollectionrules\"\r\n| extend type = iff(kind==\"\",\"Custom\",kind)\r\n| project id, type, location, resourceGroup, properties\r\n| extend dataFlows = array_length(properties.dataFlows), destinations = array_length(properties.destinations.logAnalytics)\r\n| mv-expand destinations = properties.destinations.logAnalytics\r\n| extend workspaceResourceId = tolower(tostring(destinations.workspaceResourceId))\r\n| extend dataFlows = properties.dataFlows, WorkspaceName = split(workspaceResourceId, '/')[8]\r\n| mvexpand dataFlows\r\n| mvexpand dataFlows.destinations, dataFlows.streams",
        "size": 2,
        "title": "Related DCRs streaming to same workspace destination",
        "showRefreshButton": true,
        "exportFieldName": "workspaceResourceId",
        "exportParameterName": "workspace",
        "showExportToExcel": true,
        "exportToExcelOptions": "all",
        "queryType": 1,
        "resourceType": "microsoft.resourcegraph/resources",
        "crossComponentResources": [
          "{subscriptionId}"
        ],
        "gridSettings": {
          "formatters": [
            {
              "columnMatch": "Group",
              "formatter": 1
            },
            {
              "columnMatch": "location",
              "formatter": 17
            },
            {
              "columnMatch": "resourceGroup",
              "formatter": 1
            },
            {
              "columnMatch": "workspaceResourceId",
              "formatter": 13,
              "formatOptions": {
                "linkTarget": null,
                "showIcon": true
              }
            },
            {
              "columnMatch": "Workspace",
              "formatter": 1
            },
            {
              "columnMatch": "name",
              "formatter": 5
            },
            {
              "columnMatch": "tenantId",
              "formatter": 5
            },
            {
              "columnMatch": "subscriptionId",
              "formatter": 5
            },
            {
              "columnMatch": "managedBy",
              "formatter": 5
            }
          ],
          "rowLimit": 2000,
          "filter": true,
          "hierarchySettings": {
            "treeType": 1,
            "groupBy": [
              "WorkspaceName"
            ],
            "expandTopLevel": true,
            "finalBy": "resourceGroup"
          }
        },
        "sortBy": []
      },
      "conditionalVisibilities": [
        {
          "parameterName": "Tab",
          "comparison": "isEqualTo",
          "value": "2"
        },
        {
          "parameterName": "Tab2",
          "comparison": "isEqualTo",
          "value": "2"
        }
      ],
      "name": "List of DCR by Workspace"
    },
    {
      "type": 1,
      "content": {
        "json": "No Data Collection Rule selected. Please select a DCR in order to evaluate the data flow.",
        "style": "warning"
      },
      "conditionalVisibilities": [
        {
          "parameterName": "selectedRule",
          "comparison": "isEqualTo"
        },
        {
          "parameterName": "Tab",
          "comparison": "isEqualTo",
          "value": "3"
        }
      ],
      "name": "No Data Collection Rule Selected",
      "styleSettings": {
        "margin": "20px 0px 0px 0px",
        "padding": "20px"
      }
    },
    {
      "type": 12,
      "content": {
        "version": "NotebookGroup/1.0",
        "groupType": "editable",
        "items": [
          {
            "type": 11,
            "content": {
              "version": "LinkItem/1.0",
              "style": "tabs",
              "links": [
                {
                  "id": "312be255-e187-4d00-901f-6085abbbc69b",
                  "cellValue": "Tab4",
                  "linkTarget": "parameter",
                  "linkLabel": "Related Workbooks",
                  "subTarget": "1",
                  "style": "link"
                },
                {
                  "id": "35385755-6457-4793-a294-7dacf25d7f47",
                  "cellValue": "Tab4",
                  "linkTarget": "parameter",
                  "linkLabel": "Helpful Tools",
                  "subTarget": "2",
                  "style": "link"
                }
              ]
            },
            "name": "links - 5"
          },
          {
            "type": 9,
            "content": {
              "version": "KqlParameterItem/1.0",
              "parameters": [
                {
                  "id": "a9b3932a-e140-498f-97f4-da4ffcad5a4a",
                  "version": "KqlParameterItem/1.0",
                  "name": "selectedWorkbook",
                  "label": "Select Workbook",
                  "type": 2,
                  "isGlobal": true,
                  "query": "{\"version\":\"1.0.0\",\"content\":\"[\\r\\n    {\\\"value\\\": \\\"WorkspaceUsage.json\\\", \\\"label\\\": \\\"Workspace Usage Report\\\", \\\"tags\\\": [\\\"usage\\\"]},\\r\\n\\t{\\\"value\\\": \\\"AMAmigrationTracker.json\\\", \\\"label\\\": \\\"AMA Agent - Migration Tracker\\\", \\\"tags\\\" : [\\\"migration\\\", \\\"Agents\\\", \\\"deployment\\\"]},\\r\\n\\t{\\\"value\\\": \\\"MicrosoftSentinelDeploymentandMigrationTracker.json\\\", \\\"label\\\": \\\"Sentinel Deployments and Migration Tracker\\\", \\\"tags\\\": [\\\"migration\\\",\\\"deployment\\\"]},\\r\\n\\t{\\\"value\\\": \\\"ArchivingBasicLogsRetention.json\\\", \\\"label\\\": \\\"Archiving and Basic Logs Retention\\\", \\\"tags\\\": [\\\"retention\\\",\\\"archiving\\\",\\\"basic logs\\\"]}\\r\\n]\",\"transformers\":null}",
                  "typeSettings": {
                    "additionalResourceOptions": [],
                    "showDefault": false
                  },
                  "timeContext": {
                    "durationMs": 86400000
                  },
                  "queryType": 8,
                  "value": "AMAmigrationTracker.json"
                },
                {
                  "id": "1772f659-c2b1-4882-a26b-63feb82ab734",
                  "version": "KqlParameterItem/1.0",
                  "name": "WorkbookRenderWhere",
                  "label": "Where to Open",
                  "type": 10,
                  "description": "Select the area where to render the selected workbook",
                  "isRequired": true,
                  "isGlobal": true,
                  "typeSettings": {
                    "additionalResourceOptions": [],
                    "showDefault": false
                  },
                  "jsonData": "[\"Context Pane\",\"Tab\",\"Full Screen\", \"Close Workbook\"]",
                  "value": "Context Pane"
                },
                {
                  "id": "49ce5797-eb8c-4616-94a6-14b9a92606b4",
                  "version": "KqlParameterItem/1.0",
                  "name": "templateBaseUrl",
                  "type": 1,
                  "isHiddenWhenLocked": true,
                  "criteriaData": [
                    {
                      "criteriaContext": {
                        "operator": "Default",
                        "resultValType": "static",
                        "resultVal": "https://securityinsights.hosting.portal.azure.net/securityinsights/Content/Workbooks"
                      }
                    }
                  ]
                }
              ],
              "style": "above",
              "queryType": 0,
              "resourceType": "microsoft.operationalinsights/workspaces"
            },
            "conditionalVisibility": {
              "parameterName": "Tab4",
              "comparison": "isEqualTo",
              "value": "1"
            },
            "name": "parameters - 3"
          },
          {
            "type": 11,
            "content": {
              "version": "LinkItem/1.0",
              "style": "nav",
              "links": [
                {
                  "id": "6587fa50-dc9c-46b7-ba95-b2b48b6c9733",
                  "cellValue": "{templateBaseUrl}/{selectedWorkbook}",
                  "linkTarget": "WorkbookTemplate",
                  "linkLabel": "Open Workbook",
                  "preText": "📘",
                  "style": "secondary",
                  "linkIsContextBlade": true,
                  "workbookContext": {
                    "componentIdSource": "workbook",
                    "resourceIdsSource": "workbook",
                    "templateIdSource": "cell",
                    "typeSource": "static",
                    "type": "sentinel",
                    "gallerySource": "static",
                    "gallery": "sentinel",
                    "locationSource": "workbook",
                    "passSpecificParams": true,
                    "templateParameters": [
                      {
                        "name": "Workspace",
                        "source": "parameter",
                        "value": "workspace"
                      },
                      {
                        "name": "Subscription",
                        "source": "parameter",
                        "value": "subscriptionId"
                      },
                      {
                        "name": "subscriptionId",
                        "source": "parameter",
                        "value": "subscriptionId"
                      },
                      {
                        "name": "resourceGroup",
                        "source": "parameter",
                        "value": "resourceGroup"
                      }
                    ]
                  }
                }
              ]
            },
            "conditionalVisibilities": [
              {
                "parameterName": "WorkbookRenderWhere",
                "comparison": "isEqualTo",
                "value": "Context Pane"
              },
              {
                "parameterName": "Tab4",
                "comparison": "isEqualTo",
                "value": "1"
              }
            ],
            "name": "links - 4"
          },
          {
            "type": 12,
            "content": {
              "version": "NotebookGroup/1.0",
              "groupType": "editable",
              "items": [
                {
                  "type": 12,
                  "content": {
                    "version": "NotebookGroup/1.0",
                    "groupType": "template",
                    "loadFromTemplateId": "https://securityinsights.hosting.portal.azure.net/securityinsights/Content/Workbooks/AMAmigrationTracker.json",
                    "items": []
                  },
                  "conditionalVisibility": {
                    "parameterName": "selectedWorkbook",
                    "comparison": "isEqualTo",
                    "value": "AMAmigrationTracker.json"
                  },
                  "name": "AMA Migration Tracker"
                },
                {
                  "type": 12,
                  "content": {
                    "version": "NotebookGroup/1.0",
                    "groupType": "template",
                    "loadFromTemplateId": "https://securityinsights.hosting.portal.azure.net/securityinsights/Content/Workbooks/MicrosoftSentinelDeploymentandMigrationTracker.json",
                    "items": []
                  },
                  "conditionalVisibility": {
                    "parameterName": "selectedWorkbook",
                    "comparison": "isEqualTo",
                    "value": "MicrosoftSentinelDeploymentandMigrationTracker.json"
                  },
                  "name": "Microosft Sentinel Deployment and Migration Tracker"
                },
                {
                  "type": 12,
                  "content": {
                    "version": "NotebookGroup/1.0",
                    "groupType": "template",
                    "loadFromTemplateId": "https://securityinsights.hosting.portal.azure.net/securityinsights/Content/Workbooks/WorkspaceUsage.json",
                    "items": []
                  },
                  "conditionalVisibility": {
                    "parameterName": "selectedWorkbook",
                    "comparison": "isEqualTo",
                    "value": "WorkspaceUsage.json"
                  },
                  "name": "Microosft Sentinel Deployment and Migration Tracker - Copy"
                }
              ]
            },
            "conditionalVisibility": {
              "parameterName": "WorkbookRenderWhere",
              "comparison": "isEqualTo",
              "value": "Tab"
            },
            "name": "Workbook Tabs Group"
          },
          {
            "type": 11,
            "content": {
              "version": "LinkItem/1.0",
              "style": "nav",
              "links": [
                {
                  "id": "023a9468-b62b-479e-8cbe-d1f2d4c90303",
                  "cellValue": "{templateBaseUrl}/{selectedWorkbook}",
                  "linkTarget": "WorkbookTemplate",
                  "linkLabel": "Open Workbook",
                  "preText": "📘",
                  "style": "secondary",
                  "workbookContext": {
                    "componentIdSource": "workbook",
                    "resourceIdsSource": "workbook",
                    "templateIdSource": "cell",
                    "typeSource": "static",
                    "type": "sentinel",
                    "gallerySource": "static",
                    "gallery": "sentinel",
                    "locationSource": "workbook",
                    "passSpecificParams": true,
                    "templateParameters": [
                      {
                        "name": "Workspace",
                        "source": "parameter",
                        "value": "workspace"
                      },
                      {
                        "name": "Subscription",
                        "source": "parameter",
                        "value": "subscriptionId"
                      },
                      {
                        "name": "subscriptionId",
                        "source": "parameter",
                        "value": "subscriptionId"
                      },
                      {
                        "name": "resourceGroup",
                        "source": "parameter",
                        "value": "resourceGroup"
                      }
                    ]
                  }
                }
              ]
            },
            "conditionalVisibilities": [
              {
                "parameterName": "WorkbookRenderWhere",
                "comparison": "isEqualTo",
                "value": "Full Screen"
              },
              {
                "parameterName": "Tab4",
                "comparison": "isEqualTo",
                "value": "1"
              }
            ],
            "name": "Open Workbook - Full Screen"
          },
          {
            "type": 1,
            "content": {
              "json": "### Helpful Resources\r\n- [Azure Github](https://www.github.com/Azure/Azure-Sentinel)\r\n- [Javiersoriano - Microsoft Sentinel DCR Ingestion Time Transformation Library](https://github.com/javiersoriano/sentinel-transformations-library)\r\n- [DCR Config Generator (PowerShell Script)](https://docs.microsoft.com/azure/azure-monitor/agents/azure-monitor-agent-migration-tools)\r\n- For auditing DCRs that were changed, leverage either [Activity Logs](https://learn.microsoft.com/azure/azure-monitor/essentials/activity-log?tabs=powershell) or [Resource Logs](https://learn.microsoft.com/azure/azure-monitor/essentials/resource-logs)"
            },
            "conditionalVisibility": {
              "parameterName": "Tab4",
              "comparison": "isEqualTo",
              "value": "2"
            },
            "name": "Helpful Tools"
          }
        ]
      },
      "conditionalVisibility": {
        "parameterName": "Tab",
        "comparison": "isEqualTo",
        "value": "4"
      },
      "name": "Helpful Tools"
    },
    {
      "type": 12,
      "content": {
        "version": "NotebookGroup/1.0",
        "groupType": "editable",
        "items": [
          {
            "type": 1,
            "content": {
              "json": "-------------------------------------------------------"
            },
            "name": "text - 4"
          },
          {
            "type": 9,
            "content": {
              "version": "KqlParameterItem/1.0",
              "parameters": [
                {
                  "id": "73ea1c25-4890-423c-ace8-1fda7e3729ce",
                  "version": "KqlParameterItem/1.0",
                  "name": "dcrlist",
                  "type": 1,
                  "query": "{\"version\":\"ARMEndpoint/1.0\",\"data\":null,\"headers\":[],\"method\":\"GET\",\"path\":\"{subscriptionId}/providers/Microsoft.Insights/dataCollectionRules\",\"urlParams\":[{\"key\":\"api-version\",\"value\":\"2021-09-01-preview\"}],\"batchDisabled\":false,\"transformers\":null}",
                  "isHiddenWhenLocked": true,
                  "timeContext": {
                    "durationMs": 86400000
                  },
                  "queryType": 12
                },
                {
                  "id": "e49ff56f-1665-4a2e-9bcb-a2af99e8f070",
                  "version": "KqlParameterItem/1.0",
                  "name": "TimeRange",
                  "type": 4,
                  "typeSettings": {
                    "selectableValues": [
                      {
                        "durationMs": 1800000
                      },
                      {
                        "durationMs": 3600000
                      },
                      {
                        "durationMs": 14400000
                      },
                      {
                        "durationMs": 43200000
                      },
                      {
                        "durationMs": 86400000
                      },
                      {
                        "durationMs": 172800000
                      },
                      {
                        "durationMs": 604800000
                      },
                      {
                        "durationMs": 1209600000
                      },
                      {
                        "durationMs": 2592000000
                      },
                      {
                        "durationMs": 5184000000
                      },
                      {
                        "durationMs": 7776000000
                      }
                    ]
                  },
                  "timeContext": {
                    "durationMs": 86400000
                  },
                  "value": {
                    "durationMs": 2592000000
                  }
                }
              ],
              "style": "above",
              "queryType": 0,
              "resourceType": "microsoft.operationalinsights/workspaces"
            },
            "name": "parameters - 0"
          },
          {
            "type": 1,
            "content": {
              "json": "### Help\r\n\r\nThis section is meant to highlight the DCRs that currently exist, where they are reporting data to, and which events they are collecting. The goal is to higlight that there may be DCRs that are duplicated data based on their configuration. \r\n\r\nTo review, click on each group title to expand the content. Each group will contain a list of workspaces that can be expanded. These drop-downs will show a list of event IDs that are configured in DCRs and which DCRs contain the event ID.\r\n\r\nPlease keep in mind that there may be logs for security events, syslog, CEF, or custom logs that are being ingested via MMA and not AMA, as well as the legacy ingestion API instead of the new Azure Monitor ingestion API.\r\n\r\n#### _Note_: Data Collection Rule templates do not contain which machines are provisioned by that DCR. This is not available today. Until that data is available, it will not possible to highlight which machines are sending logs twice via 2 or more DCRs.",
              "style": "info"
            },
            "conditionalVisibility": {
              "parameterName": "Help",
              "comparison": "isEqualTo",
              "value": "Yes"
            },
            "name": "text - 3"
          },
          {
            "type": 12,
            "content": {
              "version": "NotebookGroup/1.0",
              "groupType": "editable",
              "title": "Security Events",
              "expandable": true,
              "items": [
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "print DCRs = dynamic({dcrlist})\r\n| evaluate bag_unpack(DCRs)\r\n| mv-expand value\r\n| evaluate bag_unpack(value)\r\n| where kind has 'windows'\r\n| project DCR = split(id, '/').[8], test = properties.dataSources.windowsEventLogs[0].xPathQueries, Workspace = tostring(split(tostring(properties.destinations.logAnalytics.[0].workspaceResourceId), '/')[8])\r\n| where test has 'EventID=' and test !has'level='\r\n| extend test = replace_string(tostring(test), ')', ',')\r\n| extend test2 = replace_regex(tostring(test), '[^0-9,]+', '')\r\n| extend test2 = trim_end(',', test2)\r\n| extend test2 = strcat('[', test2, ']')\r\n| mv-expand test3 = split(test2, ',')\r\n| extend test3 = replace_string(tostring(test3), '[', '')\r\n| extend EventID = replace_string(tostring(test3), ']', '')\r\n| summarize DCRs = make_list(DCR) by tostring(Workspace), tostring(EventID)\r\n",
                    "size": 2,
                    "title": "Events Collected via DCRs to Workspaces",
                    "timeContextFromParameter": "TimeRange",
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "crossComponentResources": [
                      "{Workspace}"
                    ],
                    "gridSettings": {
                      "formatters": [
                        {
                          "columnMatch": "Group",
                          "formatter": 1
                        },
                        {
                          "columnMatch": "Workspace",
                          "formatter": 1
                        },
                        {
                          "columnMatch": "DCRs",
                          "formatter": 0,
                          "formatOptions": {
                            "customColumnWidthSetting": "255.2857ch"
                          }
                        },
                        {
                          "columnMatch": "Destination",
                          "formatter": 13,
                          "formatOptions": {
                            "linkTarget": "Resource",
                            "showIcon": true
                          }
                        }
                      ],
                      "rowLimit": 2000,
                      "filter": true,
                      "hierarchySettings": {
                        "treeType": 1,
                        "groupBy": [
                          "Workspace"
                        ]
                      }
                    },
                    "sortBy": []
                  },
                  "customWidth": "70",
                  "name": "query - 1"
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "SecurityEvent\r\n| where _IsBillable == true \r\n| summarize GBytes = sum(_BilledSize)/(1024*1024*1024) by EventID, Computer\r\n| order by GBytes desc",
                    "size": 0,
                    "title": "Ingestion per GB Per Event ID in {Workspace:name}",
                    "timeContextFromParameter": "TimeRange",
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "crossComponentResources": [
                      "{Workspace}"
                    ],
                    "gridSettings": {
                      "rowLimit": 2000,
                      "filter": true
                    }
                  },
                  "customWidth": "30",
                  "name": "query - 2"
                },
                {
                  "type": 1,
                  "content": {
                    "json": "----------------------------------------"
                  },
                  "name": "text - 6"
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "print DCRs = dynamic({dcrlist})\r\n| evaluate bag_unpack(DCRs)\r\n| mv-expand value\r\n| evaluate bag_unpack(value)\r\n| where kind has 'windows'\r\n| extend Workspace = tolower(tostring(split(tostring(properties.destinations.logAnalytics.[0].workspaceResourceId), '/')[8])), RG = tolower(tostring(split(tostring(id), '/')[4]))\r\n| summarize by DCRName = name, RG, Workspace\r\n",
                    "size": 0,
                    "showAnalytics": true,
                    "title": "DCRs Per Workspace",
                    "timeContextFromParameter": "TimeRange",
                    "showRefreshButton": true,
                    "exportedParameters": [
                      {
                        "fieldName": "DCRName",
                        "parameterName": "DCRName",
                        "parameterType": 1
                      },
                      {
                        "fieldName": "RG",
                        "parameterName": "RG",
                        "parameterType": 1
                      }
                    ],
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "crossComponentResources": [
                      "{Workspace}"
                    ],
                    "gridSettings": {
                      "formatters": [
                        {
                          "columnMatch": "Group",
                          "formatter": 1
                        }
                      ],
                      "rowLimit": 10000,
                      "filter": true,
                      "hierarchySettings": {
                        "treeType": 1,
                        "groupBy": [
                          "Workspace"
                        ]
                      },
                      "sortBy": [
                        {
                          "itemKey": "$gen_count_$gen_group_0",
                          "sortOrder": 1
                        }
                      ]
                    },
                    "sortBy": [
                      {
                        "itemKey": "$gen_count_$gen_group_0",
                        "sortOrder": 1
                      }
                    ]
                  },
                  "customWidth": "50",
                  "name": "query - 3"
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "{\"version\":\"ARMEndpoint/1.0\",\"data\":null,\"headers\":[],\"method\":\"GET\",\"path\":\"{subscriptionId}/resourceGroups/{RG}/providers/Microsoft.Insights/dataCollectionRules/{DCRName}/associations\",\"urlParams\":[{\"key\":\"api-version\",\"value\":\"2019-11-01-preview\"}],\"batchDisabled\":false,\"transformers\":[{\"type\":\"jsonpath\",\"settings\":{\"tablePath\":\"$.value\",\"columns\":[{\"path\":\"id\",\"columnid\":\"VMs\",\"columnType\":\"string\",\"substringRegexMatch\":\"(\\\\/subscriptions.*)(\\\\/providers.*|Providers.*)\",\"substringReplace\":\"$1\"}]}}]}",
                    "size": 4,
                    "title": "VMs associated to the selected DCR",
                    "noDataMessage": "No VMs found or no DCR selected above",
                    "queryType": 12
                  },
                  "customWidth": "50",
                  "name": "query - 18"
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "SecurityEvent\r\n| where _IsBillable == true\r\n| summarize GBytes = sum(_BilledSize)/(1024*1024*1024) by endofday(TimeGenerated), bin(endofday(TimeGenerated), 1d)",
                    "size": 0,
                    "title": "Ingestion Per Day in {Workspace:name}",
                    "timeContextFromParameter": "TimeRange",
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "crossComponentResources": [
                      "{Workspace}"
                    ],
                    "visualization": "timechart",
                    "gridSettings": {
                      "filter": true
                    }
                  },
                  "name": "query - 2 - Copy"
                }
              ]
            },
            "name": "Windows",
            "styleSettings": {
              "showBorder": true
            }
          },
          {
            "type": 12,
            "content": {
              "version": "NotebookGroup/1.0",
              "groupType": "editable",
              "title": "Syslog",
              "expandable": true,
              "items": [
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "print DCRs = dynamic({dcrlist})\r\n| evaluate bag_unpack(DCRs)\r\n| mv-expand value\r\n| evaluate bag_unpack(value)\r\n| where kind has 'linux'\r\n| project DCR = split(id, '/').[8], Facilities = properties.dataSources.syslog.[0].facilityNames, LogLevels = properties.dataSources.syslog.[0].logLevels, Workspace = tostring(split(tostring(properties.destinations.logAnalytics.[0].workspaceResourceId), '/')[8])\r\n| mv-expand test3 = split(Facilities, ',')\r\n| extend test3 = replace_string(tostring(test3), '[', '')\r\n| extend test3 = replace_string(tostring(test3), ']', '')\r\n| summarize DCRs = make_list(DCR) by tostring(Workspace), tostring(test3)",
                    "size": 2,
                    "title": "Syslog Collected by DCRs to Workspaces",
                    "timeContextFromParameter": "TimeRange",
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "crossComponentResources": [
                      "{Workspace}"
                    ],
                    "gridSettings": {
                      "formatters": [
                        {
                          "columnMatch": "Group",
                          "formatter": 1
                        }
                      ],
                      "hierarchySettings": {
                        "treeType": 1,
                        "groupBy": [
                          "Workspace"
                        ]
                      }
                    }
                  },
                  "customWidth": "70",
                  "name": "query - 0"
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "Syslog\r\n| where _IsBillable == true \r\n| summarize GBytes = sum(_BilledSize)/(1024*1024*1024) by Facility, SeverityLevel, Computer\r\n| order by GBytes desc",
                    "size": 0,
                    "title": "Ingestion per GB per Facility, Severity, and Computer in {Workspace:name}",
                    "timeContextFromParameter": "TimeRange",
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "crossComponentResources": [
                      "{Workspace}"
                    ],
                    "gridSettings": {
                      "rowLimit": 2000
                    }
                  },
                  "customWidth": "30",
                  "name": "query - 1"
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "Syslog\r\n| where _IsBillable == true \r\n| summarize GBytes = sum(_BilledSize)/(1024*1024*1024) by endofday(TimeGenerated), bin(endofday(TimeGenerated), 1d)",
                    "size": 0,
                    "title": "Ingestion per Day in {Workspace:name}",
                    "timeContextFromParameter": "TimeRange",
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "crossComponentResources": [
                      "{Workspace}"
                    ],
                    "visualization": "timechart"
                  },
                  "name": "query - 1 - Copy"
                }
              ]
            },
            "name": "Syslog",
            "styleSettings": {
              "showBorder": true
            }
          },
          {
            "type": 12,
            "content": {
              "version": "NotebookGroup/1.0",
              "groupType": "editable",
              "title": "Custom Logs",
              "expandable": true,
              "items": [
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "print DCRs = dynamic({dcrlist})\r\n| evaluate bag_unpack(DCRs)\r\n| mv-expand value\r\n| evaluate bag_unpack(value)\r\n| where isempty(kind)\r\n| project DCR = split(id, '/').[8], Streams = properties.dataFlows[0].streams, DestinationTable = properties.dataFlows[0].outputStream, Workspace = tostring(split(tostring(properties.destinations.logAnalytics.[0].workspaceResourceId), '/')[8])",
                    "size": 2,
                    "title": "Custom Logs via DCR to Workspace",
                    "timeContextFromParameter": "TimeRange",
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "crossComponentResources": [
                      "{Workspace}"
                    ],
                    "gridSettings": {
                      "formatters": [
                        {
                          "columnMatch": "Group",
                          "formatter": 1
                        }
                      ],
                      "hierarchySettings": {
                        "treeType": 1,
                        "groupBy": [
                          "Workspace"
                        ]
                      }
                    }
                  },
                  "customWidth": "70",
                  "name": "query - 0"
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "union withsource =SourceTable *_CL\r\n| where _IsBillable = true\r\n| summarize GBytes = sum(_BilledSize)/(1024*1024*1024) by SourceTable\r\n| order by GBytes desc",
                    "size": 0,
                    "title": "Ingestion per GB per Custom Table in {Workspace:name}",
                    "timeContextFromParameter": "TimeRange",
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "crossComponentResources": [
                      "{Workspace}"
                    ],
                    "gridSettings": {
                      "rowLimit": 2000,
                      "sortBy": [
                        {
                          "itemKey": "GBytes",
                          "sortOrder": 2
                        }
                      ]
                    },
                    "sortBy": [
                      {
                        "itemKey": "GBytes",
                        "sortOrder": 2
                      }
                    ]
                  },
                  "customWidth": "30",
                  "name": "query - 1"
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "union withsource =SourceTable *_CL\r\n| where _IsBillable = true\r\n| summarize GBytes = sum(_BilledSize)/(1024*1024*1024) by endofday(TimeGenerated), bin(endofday(TimeGenerated), 1d)",
                    "size": 0,
                    "title": "Ingestion per GB per Custom Table",
                    "timeContextFromParameter": "TimeRange",
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "crossComponentResources": [
                      "{Workspace}"
                    ],
                    "visualization": "timechart",
                    "gridSettings": {
                      "sortBy": [
                        {
                          "itemKey": "GBytes",
                          "sortOrder": 2
                        }
                      ]
                    },
                    "sortBy": [
                      {
                        "itemKey": "GBytes",
                        "sortOrder": 2
                      }
                    ]
                  },
                  "name": "query - 1 - Copy"
                }
              ]
            },
            "name": "Custom",
            "styleSettings": {
              "showBorder": true
            }
          }
        ]
      },
      "conditionalVisibility": {
        "parameterName": "Tab",
        "comparison": "isEqualTo",
        "value": "5"
      },
      "name": "Reporting"
    }
  ],
  "fallbackResourceIds": [
    ""
  ],
  "styleSettings": {
    "paddingStyle": "narrow",
    "spacingStyle": "narrow"
  },
  "fromTemplateId": "sentinel-DCRToolkit",
  "$schema": "https://github.com/Microsoft/Application-Insights-Workbooks/blob/master/schema/workbook.json"
}
