List of EMET event ID/level and messages?

I didn't see this in the users guide - is there a complete listing of all the event log Event IDs and levels (Info, warning, error) and the messages that go with these?

This would greatly help analysts write rules ahead of time to detect when EMET configuration has changed or when EMET actively blocked an exploit.

Sure, I can collect all events with the source 'EMET' but knowing what the events mean will help security analysts looking at the logs (or an aggregation of logs from machines) really understand what the events are telling them.

What's left is the "figure it out as you go" method - completely experiential learning.

Thanks,

Ted

October 25th, 2012 10:57pm

I didn't see this in the users guide - is there a complete listing of all the event log Event IDs and levels (Info, warning, error) and the messages that go with these?

This would greatly help analysts write rules ahead of time to detect when EMET configuration has changed or when EMET actively blocked an exploit.

Sure, I can collect all events with the source 'EMET' but knowing what the events mean will help security analysts looking at the logs (or an aggregation of logs from machines) really understand what the events are telling them.

What's left is the "figure it out as you go" method - completely experiential learning.

Thanks,

Ted

Really? More than a year no reply to such an important question?
Free Windows Admin Tool Kit Click here and download it now
December 9th, 2013 12:00pm

Section 1.4 / page 14 (Reporting) of the EMET 4.1 User Guide.
December 10th, 2013 3:22pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics