Skip to content

feat(windows-eventlog): collect Defender Operational events - #593

Merged
Karib0u merged 3 commits into
mainfrom
feat/windows-defender-eventlog
Sep 24, 2026
Merged

Karib0u merged 3 commits into
mainfrom
feat/windows-defender-eventlog

Conversation

@Karib0u

@Karib0u Karib0u commented Sep 24, 2026

Copy link
Copy Markdown
Owner

Summary

  • Add a Windows Event Log subscription for the Defender Operational channel and decode the 16 requested event IDs.
  • Preserve native Defender field names and expose the aliases used by SigmaHQ rules.
  • Record availability by event ID and update the pinned SigmaHQ coverage baseline.

Validation

  • cargo test --locked passed locally.
  • Windows lab decoder, Sigma pipeline, and field availability tests passed.
  • The pinned SigmaHQ corpus test passed on the Windows lab: 17 windows/windefend rules are backed, with no parser failures.
  • Sigma field compatibility reports 7 rules with no field caveats, 10 dependent on optional event fields, and none unable to fire.
  • The Windows lab accepted the subscription query and returned a Defender 5007 event.

Event 5101 was fixture-tested. The lab's installed Defender provider does not expose a 5101 template for a live event test.

Closes #483

@Karib0u
Karib0u merged commit 208eb0f into main Sep 24, 2026
17 checks passed
@Karib0u
Karib0u deleted the feat/windows-defender-eventlog branch September 24, 2026 18:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(windows-eventlog): add a Defender Operational channel source

1 participant