Reference¶
Every setting in the kit, one row each: the events it produces, the log size the kit applies, how heavy it is, who recommends it, and whether the spydi baselines include it.
Reading the columns:
- Key events - the main event IDs the setting produces. Audit rows come from the kit's curated ATT&CK event map; others are the IDs named in the setting's own documentation. Indicative, not exhaustive.
- Size - default -> kit target, for event log channels.
- Volume - how heavy the logs get: High = a high-volume generator (the HighVolume tier), Watch = normal volume with a documented pilot-week caution, Low = quiet.
- Refs - who asks for it: A = ASD, C = Microsoft Client, S = Microsoft Server, Y = Yamato (per the shipped reference presets; kit-added extras such as the Server 2025 SMB auditing and the NTLM audit values show no reference letter and are sourced in the settings table).
- Minimal / Heavy - membership in
spydi_Server_Minimal/spydi_Server_Heavy(the superset role presets; rows marked (DC) are deselected in the Workstation variants and inert off domain controllers).
| Setting | Type | Key events | Size | Volume | Refs | Minimal | Heavy |
|---|---|---|---|---|---|---|---|
| Security | Channel | - | 20 MB -> 1 GB | Low | A Y | ||
| Microsoft-Windows-PowerShell/Operational | Channel | 4103, 4104 | 15 MB -> 1 GB | Low | Y | ||
| Windows PowerShell | Channel | 400, 403, 600 | 15 MB -> 1 GB | Low | Y | ||
| PowerShellCore/Operational | Channel | - | 15 MB -> 1 GB | Low | Y | ||
| System | Channel | 7045, 7036, 104 | 20 MB -> 128 MB | Low | A Y | ||
| Application | Channel | 1040, 1034 | 20 MB -> 128 MB | Low | A Y | ||
| Microsoft-Windows-Windows Defender/Operational | Channel | - | 1 MB -> 128 MB | Low | Y | ||
| Microsoft-Windows-Bits-Client/Operational | Channel | - | 1 MB -> 128 MB | Low | Y | ||
| Microsoft-Windows-Windows Firewall With Advanced Security/Firewall | Channel | - | 1 MB -> 128 MB | Low | Y | ||
| Microsoft-Windows-NTLM/Operational | Channel | - | 1 MB -> 128 MB | Low | Y | ||
| Microsoft-Windows-Security-Mitigations/KernelMode | Channel | - | 1 MB -> 128 MB | Low | Y | ||
| Microsoft-Windows-Security-Mitigations/UserMode | Channel | - | 1 MB -> 128 MB | Low | Y | ||
| Microsoft-Windows-PrintService/Admin | Channel | - | 1 MB -> 128 MB | Low | Y | ||
| Microsoft-Windows-PrintService/Operational | Channel | - | 1 MB -> 128 MB | Low | Y | ||
| Microsoft-Windows-SmbClient/Security | Channel | - | 8 MB -> 128 MB | Low | Y | ||
| Microsoft-Windows-AppLocker/EXE and DLL | Channel | - | 1 MB -> 128 MB | Low | Y | ||
| Microsoft-Windows-AppLocker/MSI and Script | Channel | - | 1 MB -> 128 MB | Low | Y | ||
| Microsoft-Windows-AppLocker/Packaged app-Deployment | Channel | - | 1 MB -> 128 MB | Low | Y | ||
| Microsoft-Windows-AppLocker/Packaged app-Execution | Channel | - | 1 MB -> 128 MB | Low | Y | ||
| Microsoft-Windows-CodeIntegrity/Operational | Channel | - | 1 MB -> 128 MB | Low | Y | ||
| Microsoft-Windows-Diagnosis-Scripted/Operational | Channel | - | 1 MB -> 128 MB | Low | Y | ||
| Microsoft-Windows-DriverFrameworks-UserMode/Operational | Channel | - | 1 MB -> 128 MB | Low | Y | ||
| Microsoft-Windows-WMI-Activity/Operational | Channel | - | 1 MB -> 128 MB | Low | Y | ||
| Microsoft-Windows-TerminalServices-LocalSessionManager/Operational | Channel | - | 1 MB -> 128 MB | Low | Y | ||
| Microsoft-Windows-TaskScheduler/Operational | Channel | - | 1 MB -> 128 MB | Low | Y | ||
| Microsoft-Windows-SMBServer/Audit | Channel | 3021, 3022 | 8 MB -> 128 MB | Low | - | ||
| Microsoft-Windows-SmbClient/Audit | Channel | 31998, 31999 | 8 MB -> 128 MB | Low | - | ||
| Microsoft-Windows-Crypto-DPAPI/Debug | Channel | - | 1 MB -> 128 MB | Watch | - | - | - |
| Credential Validation | Audit subcategory | 4776 | - | Low | C S Y | ||
| Kerberos Authentication Service (DC) | Audit subcategory | 4768, 4771 | - | Low | Y | ||
| Kerberos Service Ticket Operations (DC) | Audit subcategory | 4769, 4770 | - | Low | Y | ||
| Computer Account Management (DC) | Audit subcategory | 4741-4743, 4742 | - | Low | A C S Y | ||
| Distribution Group Management (DC) | Audit subcategory | - | - | Low | Y | ||
| Other Account Management Events | Audit subcategory | 4782, 4793 | - | Low | A C S Y | ||
| Security Group Management | Audit subcategory | 4728, 4729, 4732, 4733, 4756, 4757, 4799, 4727-4764 | - | Low | A C S Y | ||
| User Account Management | Audit subcategory | 4720, 4723, 4724, 4726, 4738, 4740, 4798, 4720-4767 | - | Low | A C S Y | ||
| Plug and Play | Audit subcategory | 6416, 6419-6424 | - | Low | Y | ||
| Process Creation | Audit subcategory | 4688 | - | High | A C S Y | ||
| RPC Events | Audit subcategory | 5712 | - | Watch | Y | ||
| Directory Service Access (DC) | Audit subcategory | 4662, 4661 | - | Low | S Y | ||
| Directory Service Changes (DC) | Audit subcategory | 5136, 5136-5141 | - | Low | S Y | ||
| Account Lockout | Audit subcategory | 4625 | - | Low | A Y | ||
| Logoff | Audit subcategory | 4634, 4647 | - | Low | A C S Y | ||
| Logon | Audit subcategory | 4624, 4625, 4648 | - | Low | A C S Y | ||
| Other Logon/Logoff Events | Audit subcategory | 4800, 4801, 4778, 4779 | - | Low | A Y | ||
| Special Logon | Audit subcategory | 4672 | - | Low | A C S Y | ||
| Certification Services | Audit subcategory | 4898, 4899 | - | Low | Y | ||
| File Share | Audit subcategory | 5140, 5142-5144 | - | Watch | A Y | ||
| Filtering Platform Connection | Audit subcategory | 5156, 5157 | - | High | Y | - | |
| Other Object Access Events | Audit subcategory | 4698, 4702, 4698-4702 | - | Low | A Y | ||
| Removable Storage | Audit subcategory | 4663 | - | Watch | Y | ||
| SAM | Audit subcategory | 4661 | - | Watch | Y | ||
| Audit Policy Change | Audit subcategory | 4719, 4715, 4907 | - | Low | A C S Y | ||
| Authentication Policy Change | Audit subcategory | 4739, 4706, 4707, 4717 | - | Low | Y | ||
| Other Policy Change Events | Audit subcategory | 5447 | - | Low | A Y | ||
| Sensitive Privilege Use | Audit subcategory | 4673, 4674 | - | High | Y | - | |
| IPsec Driver | Audit subcategory | 4960-4963, 4965, 5478-5480, 5483-5485 | - | Low | C S | ||
| Security State Change | Audit subcategory | 4616 | - | Low | C S Y | ||
| Security System Extension | Audit subcategory | 4697, 4610, 4611, 4622 | - | Low | C S Y | ||
| System Integrity | Audit subcategory | 4612, 5038, 6281 | - | Low | A C S Y | ||
| Other System Events | Audit subcategory | - | - | Low | Y | ||
Microsoft\Windows\CurrentVersion\Policies\System\Audit\ProcessCreationIncludeCmdLine_Enabled |
Registry | 4688 | - | High | A C S Y | ||
Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging\EnableScriptBlockLogging |
Registry | 4104 | - | High | A Y | ||
Wow6432Node\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging\EnableScriptBlockLogging |
Registry | - | - | High | A Y | ||
Policies\Microsoft\Windows\PowerShell\ModuleLogging\EnableModuleLogging |
Registry | 4103 | - | High | A Y | - | |
Wow6432Node\Policies\Microsoft\Windows\PowerShell\ModuleLogging\EnableModuleLogging |
Registry | - | - | High | A Y | - | |
Policies\Microsoft\Windows\PowerShell\ModuleLogging\ModuleNames\* |
Registry | - | - | High | A Y | - | |
Wow6432Node\Policies\Microsoft\Windows\PowerShell\ModuleLogging\ModuleNames\* |
Registry | - | - | High | A Y | - | |
Policies\Microsoft\Windows\PowerShell\Transcription\EnableTranscripting |
Registry | - | - | Low | - | - | - |
Policies\Microsoft\Windows\PowerShell\Transcription\EnableInvocationHeader |
Registry | - | - | Low | - | - | - |
Wow6432Node\Policies\Microsoft\Windows\PowerShell\Transcription\EnableTranscripting |
Registry | - | - | Low | - | - | - |
Wow6432Node\Policies\Microsoft\Windows\PowerShell\Transcription\EnableInvocationHeader |
Registry | - | - | Low | - | - | - |
CurrentControlSet\Control\Lsa\MSV1_0\RestrictSendingNTLMTraffic |
Registry | - | - | Low | - | ||
CurrentControlSet\Control\Lsa\MSV1_0\AuditReceivingNTLMTraffic |
Registry | - | - | Low | - | ||
CurrentControlSet\Services\Netlogon\Parameters\AuditNTLMInDomain (DC) |
Registry | - | - | Low | - | ||
| AD CS AuditFilter (needs CertSvc restart) | Registry | 4886-4899 | - | Low | Y | ||
| Server: AuditClientDoesNotSupportEncryption | SMB audit (2025+) | 3021 | - | Low | - | ||
| Server: AuditClientDoesNotSupportSigning | SMB audit (2025+) | 3022 | - | Low | - | ||
| Client: AuditServerDoesNotSupportEncryption | SMB audit (2025+) | 31998 | - | Low | - | ||
| Client: AuditServerDoesNotSupportSigning | SMB audit (2025+) | 31999 | - | Low | - |