— Security State Change Security System Extension System Integrity Logon Group Membership Logoff IPsec Main Mode Other Logon/Logoff Events IPsec Quick Mode Handle Manipulation Registry SAM Directory Service Access File System Application Generated Subcategory (special) Other Object Access Events Sensitive Privilege Use / Non Sensitive Privilege Use Process Creation Process Termination DPAPI Activity Authorization Policy Change Filtering Platform Policy Change Authentication Policy Change Audit Policy Change User Account Management Security Group Management Computer Account Management Distribution Group Management Kerberos Authentication Service Kerberos Service Ticket Operations Credential Validation Other Account Management Events Application Group Management Central Access Policy Staging Other Policy Change Events Certification Services Detailed Directory Service Replication Directory Service Replication MPSSVC Rule-Level Policy Change IPsec Driver Special Logon IPsec Extended Mode Other System Events Filtering Platform Connection Directory Service Changes File Share Detailed File Share Filtering Platform Packet Drop RPC Events Network Policy Server Plug and Play Events
— System Logon/Logoff Object Access DS Access Policy Change Privilege Use Detailed Tracking Account Management Account Logon
— Low Medium High