Skip to content

Reference

Every setting in the kit, one row each: the events it produces, the log size the kit applies, how heavy it is, who recommends it, and whether the spydi baselines include it.

Reading the columns:

  • Key events - the main event IDs the setting produces. Audit rows come from the kit's curated ATT&CK event map; others are the IDs named in the setting's own documentation. Indicative, not exhaustive.
  • Size - default -> kit target, for event log channels.
  • Volume - how heavy the logs get: High = a high-volume generator (the HighVolume tier), Watch = normal volume with a documented pilot-week caution, Low = quiet.
  • Refs - who asks for it: A = ASD, C = Microsoft Client, S = Microsoft Server, Y = Yamato (per the shipped reference presets; kit-added extras such as the Server 2025 SMB auditing and the NTLM audit values show no reference letter and are sourced in the settings table).
  • Minimal / Heavy - membership in spydi_Server_Minimal / spydi_Server_Heavy (the superset role presets; rows marked (DC) are deselected in the Workstation variants and inert off domain controllers).
Setting Type Key events Size Volume Refs Minimal Heavy
Security Channel - 20 MB -> 1 GB Low A Y
Microsoft-Windows-PowerShell/Operational Channel 4103, 4104 15 MB -> 1 GB Low Y
Windows PowerShell Channel 400, 403, 600 15 MB -> 1 GB Low Y
PowerShellCore/Operational Channel - 15 MB -> 1 GB Low Y
System Channel 7045, 7036, 104 20 MB -> 128 MB Low A Y
Application Channel 1040, 1034 20 MB -> 128 MB Low A Y
Microsoft-Windows-Windows Defender/Operational Channel - 1 MB -> 128 MB Low Y
Microsoft-Windows-Bits-Client/Operational Channel - 1 MB -> 128 MB Low Y
Microsoft-Windows-Windows Firewall With Advanced Security/Firewall Channel - 1 MB -> 128 MB Low Y
Microsoft-Windows-NTLM/Operational Channel - 1 MB -> 128 MB Low Y
Microsoft-Windows-Security-Mitigations/KernelMode Channel - 1 MB -> 128 MB Low Y
Microsoft-Windows-Security-Mitigations/UserMode Channel - 1 MB -> 128 MB Low Y
Microsoft-Windows-PrintService/Admin Channel - 1 MB -> 128 MB Low Y
Microsoft-Windows-PrintService/Operational Channel - 1 MB -> 128 MB Low Y
Microsoft-Windows-SmbClient/Security Channel - 8 MB -> 128 MB Low Y
Microsoft-Windows-AppLocker/EXE and DLL Channel - 1 MB -> 128 MB Low Y
Microsoft-Windows-AppLocker/MSI and Script Channel - 1 MB -> 128 MB Low Y
Microsoft-Windows-AppLocker/Packaged app-Deployment Channel - 1 MB -> 128 MB Low Y
Microsoft-Windows-AppLocker/Packaged app-Execution Channel - 1 MB -> 128 MB Low Y
Microsoft-Windows-CodeIntegrity/Operational Channel - 1 MB -> 128 MB Low Y
Microsoft-Windows-Diagnosis-Scripted/Operational Channel - 1 MB -> 128 MB Low Y
Microsoft-Windows-DriverFrameworks-UserMode/Operational Channel - 1 MB -> 128 MB Low Y
Microsoft-Windows-WMI-Activity/Operational Channel - 1 MB -> 128 MB Low Y
Microsoft-Windows-TerminalServices-LocalSessionManager/Operational Channel - 1 MB -> 128 MB Low Y
Microsoft-Windows-TaskScheduler/Operational Channel - 1 MB -> 128 MB Low Y
Microsoft-Windows-SMBServer/Audit Channel 3021, 3022 8 MB -> 128 MB Low -
Microsoft-Windows-SmbClient/Audit Channel 31998, 31999 8 MB -> 128 MB Low -
Microsoft-Windows-Crypto-DPAPI/Debug Channel - 1 MB -> 128 MB Watch - - -
Credential Validation Audit subcategory 4776 - Low C S Y
Kerberos Authentication Service (DC) Audit subcategory 4768, 4771 - Low Y
Kerberos Service Ticket Operations (DC) Audit subcategory 4769, 4770 - Low Y
Computer Account Management (DC) Audit subcategory 4741-4743, 4742 - Low A C S Y
Distribution Group Management (DC) Audit subcategory - - Low Y
Other Account Management Events Audit subcategory 4782, 4793 - Low A C S Y
Security Group Management Audit subcategory 4728, 4729, 4732, 4733, 4756, 4757, 4799, 4727-4764 - Low A C S Y
User Account Management Audit subcategory 4720, 4723, 4724, 4726, 4738, 4740, 4798, 4720-4767 - Low A C S Y
Plug and Play Audit subcategory 6416, 6419-6424 - Low Y
Process Creation Audit subcategory 4688 - High A C S Y
RPC Events Audit subcategory 5712 - Watch Y
Directory Service Access (DC) Audit subcategory 4662, 4661 - Low S Y
Directory Service Changes (DC) Audit subcategory 5136, 5136-5141 - Low S Y
Account Lockout Audit subcategory 4625 - Low A Y
Logoff Audit subcategory 4634, 4647 - Low A C S Y
Logon Audit subcategory 4624, 4625, 4648 - Low A C S Y
Other Logon/Logoff Events Audit subcategory 4800, 4801, 4778, 4779 - Low A Y
Special Logon Audit subcategory 4672 - Low A C S Y
Certification Services Audit subcategory 4898, 4899 - Low Y
File Share Audit subcategory 5140, 5142-5144 - Watch A Y
Filtering Platform Connection Audit subcategory 5156, 5157 - High Y -
Other Object Access Events Audit subcategory 4698, 4702, 4698-4702 - Low A Y
Removable Storage Audit subcategory 4663 - Watch Y
SAM Audit subcategory 4661 - Watch Y
Audit Policy Change Audit subcategory 4719, 4715, 4907 - Low A C S Y
Authentication Policy Change Audit subcategory 4739, 4706, 4707, 4717 - Low Y
Other Policy Change Events Audit subcategory 5447 - Low A Y
Sensitive Privilege Use Audit subcategory 4673, 4674 - High Y -
IPsec Driver Audit subcategory 4960-4963, 4965, 5478-5480, 5483-5485 - Low C S
Security State Change Audit subcategory 4616 - Low C S Y
Security System Extension Audit subcategory 4697, 4610, 4611, 4622 - Low C S Y
System Integrity Audit subcategory 4612, 5038, 6281 - Low A C S Y
Other System Events Audit subcategory - - Low Y
Microsoft\Windows\CurrentVersion\Policies\System\Audit\ProcessCreationIncludeCmdLine_Enabled Registry 4688 - High A C S Y
Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging\EnableScriptBlockLogging Registry 4104 - High A Y
Wow6432Node\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging\EnableScriptBlockLogging Registry - - High A Y
Policies\Microsoft\Windows\PowerShell\ModuleLogging\EnableModuleLogging Registry 4103 - High A Y -
Wow6432Node\Policies\Microsoft\Windows\PowerShell\ModuleLogging\EnableModuleLogging Registry - - High A Y -
Policies\Microsoft\Windows\PowerShell\ModuleLogging\ModuleNames\* Registry - - High A Y -
Wow6432Node\Policies\Microsoft\Windows\PowerShell\ModuleLogging\ModuleNames\* Registry - - High A Y -
Policies\Microsoft\Windows\PowerShell\Transcription\EnableTranscripting Registry - - Low - - -
Policies\Microsoft\Windows\PowerShell\Transcription\EnableInvocationHeader Registry - - Low - - -
Wow6432Node\Policies\Microsoft\Windows\PowerShell\Transcription\EnableTranscripting Registry - - Low - - -
Wow6432Node\Policies\Microsoft\Windows\PowerShell\Transcription\EnableInvocationHeader Registry - - Low - - -
CurrentControlSet\Control\Lsa\MSV1_0\RestrictSendingNTLMTraffic Registry - - Low -
CurrentControlSet\Control\Lsa\MSV1_0\AuditReceivingNTLMTraffic Registry - - Low -
CurrentControlSet\Services\Netlogon\Parameters\AuditNTLMInDomain (DC) Registry - - Low -
AD CS AuditFilter (needs CertSvc restart) Registry 4886-4899 - Low Y
Server: AuditClientDoesNotSupportEncryption SMB audit (2025+) 3021 - Low -
Server: AuditClientDoesNotSupportSigning SMB audit (2025+) 3022 - Low -
Client: AuditServerDoesNotSupportEncryption SMB audit (2025+) 31998 - Low -
Client: AuditServerDoesNotSupportSigning SMB audit (2025+) 31999 - Low -