{"id":3586,"date":"2023-10-12T02:01:38","date_gmt":"2023-10-11T17:01:38","guid":{"rendered":"https:\/\/m365jp.xyz\/?p=3586"},"modified":"2023-10-12T02:16:16","modified_gmt":"2023-10-11T17:16:16","slug":"mc680761-new-security-capabilities-of-event-tracing-for-windows","status":"publish","type":"post","link":"https:\/\/m365jp.net\/index.php\/2023-10-12-mc680761-new-security-capabilities-of-event-tracing-for-windows","title":{"rendered":"MC680761 | New security capabilities of Event Tracing for Windows"},"content":{"rendered":"<div class=\"postie-post\">\n<div>\n<hr>\n<table id=\"section\">\n<tbody>\n<tr>\n<th width=\"95%\">MC680761 | New security capabilities of Event Tracing for Windows<\/th>\n<\/tr>\n<\/tbody>\n<\/table>\n<hr>\n<table id=\"data\">\n<tbody>\n<tr>\n<th>Classification<\/th>\n<td>stayInformed<\/td>\n<\/tr>\n<tr>\n<th>Last Updated<\/th>\n<td>10\/11\/2023 16:58:30<\/td>\n<\/tr>\n<tr>\n<th>Start Time<\/th>\n<td>10\/11\/2023 16:58:29<\/td>\n<\/tr>\n<tr>\n<th>End Time<\/th>\n<td>10\/11\/2024 16:58:29<\/td>\n<\/tr>\n<tr>\n<th>Message Content<\/th>\n<td>\n<div>Whether you\u2019re in cybersecurity, IT, performance, or software development, improved resources can help you diagnose cybersecurity threats. While you could previously use Event Tracing for Windows for limited audit functions, nine events have recently been   improved for better insight. Specifically, several security-related events now show Process ID and Process Start Key in the event schema, allowing you to confirm the causal process of these events. We\u2019ve also increased the event version as events are updated   over time, following the application compatibility policy.&nbsp;&nbsp;<\/div>\n<div>&nbsp;<\/div>\n<div><b>When will this happen:<\/b>&nbsp;<\/div>\n<div>These improvements are already available on all Windows versions.&nbsp;<\/div>\n<div>&nbsp;<\/div>\n<div><b>How this will affect your organization:<\/b>&nbsp;<\/div>\n<div>Organizations can better leverage Windows Event Viewer for security diagnostics and auditing. Before now, Event Tracing for Windows logs listed some events and processes affecting a device with a generic message of &#8220;The system\/kernel logged this event.&#8221;   As such, some events might have appeared as if they were caused by a different action. Today, the initiating process is added to the payload part of the following events in form of Process ID and Process Start Key:&nbsp;<\/div>\n<div>&nbsp;<\/div>\n<ul>\n<li>4697: A service was installed in the system.&nbsp;<\/li>\n<li>4698: A scheduled task was created.&nbsp;<\/li>\n<li>4699: A scheduled task was deleted.&nbsp;<\/li>\n<li>4700: A scheduled task was enabled.&nbsp;<\/li>\n<li>4701: A scheduled task was disabled.&nbsp;<\/li>\n<li>4702: A scheduled task was updated.&nbsp;<\/li>\n<li>4719: System audit policy was changed.&nbsp;<\/li>\n<li>1102: Security audit log was cleared.\u202fDisplayed in the Security channel.&nbsp;<\/li>\n<li>104: The {channel name} log file was cleared.\u202fDisplayed in the System channel.&nbsp;<\/li>\n<\/ul>\n<div>&nbsp;<\/div>\n<div>These are considered security-related events because attack tools often clear the event log and disable auditing.&nbsp;<\/div>\n<div>&nbsp;<\/div>\n<div><b>What you need to do to prepare:<\/b>&nbsp;<\/div>\n<div>Read <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/windows-it-pro-blog\/new-security-capabilities-of-event-tracing-for-windows\/ba-p\/3949941\" rel=\"noopener noreferrer\" target=\"_blank\">  New security capabilities of Event Tracing for Windows<\/a> for step-by-step instructions, screenshots, and examples of these improvements. Review additional information for further help.&nbsp;<\/div>\n<div>  <\/div>\n<div><b>Additional information:<\/b>&nbsp;<\/div>\n<ul>\n<li><a href=\"https:\/\/techcommunity.microsoft.com\/t5\/windows-it-pro-blog\/new-security-capabilities-of-event-tracing-for-windows\/ba-p\/3949941\" rel=\"noopener noreferrer\" target=\"_blank\">New security capabilities of Event Tracing for Windows<\/a>&nbsp;<\/li>\n<li><a href=\"https:\/\/learn.microsoft.com\/windows-hardware\/test\/weg\/instrumenting-your-code-with-etw\" rel=\"noopener noreferrer\" target=\"_blank\">Instrumenting your code with ETW<\/a>&nbsp;<\/li>\n<li><a href=\"https:\/\/learn.microsoft.com\/windows\/win32\/api\/_etw\/\" rel=\"noopener noreferrer\" target=\"_blank\">Event tracing &#8211; Win32 apps<\/a>&nbsp;<\/li>\n<li><a href=\"https:\/\/learn.microsoft.com\/windows\/win32\/api\/evntrace\/ns-evntrace-enable_trace_parameters\" rel=\"noopener noreferrer\" target=\"_blank\">ENABLE_TRACE_PARAMETERS (evntrace.h)<\/a>&nbsp;<\/li>\n<li><a href=\"https:\/\/learn.microsoft.com\/training\/modules\/manage-monitor-event-logs\/2-describe-windows-server-event-logs\" rel=\"noopener noreferrer\" target=\"_blank\">Describe Windows Server event logs<\/a>&nbsp;<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<th>Machine Translation<\/th>\n<td>\n<div>\u30b5\u30a4\u30d0\u30fc\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u3001IT\u3001\u30d1\u30d5\u30a9\u30fc\u30de\u30f3\u30b9\u3001\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u958b\u767a\u306e\u3044\u305a\u308c\u3067\u3042\u3063\u3066\u3082\u3001\u30ea\u30bd\u30fc\u30b9\u306e\u6539\u5584\u306f\u30b5\u30a4\u30d0\u30fc\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u306e\u8105\u5a01\u306e\u8a3a\u65ad\u306b\u5f79\u7acb\u3061\u307e\u3059\u3002\u4ee5\u524d\u306f\u3001Windows \u30a4\u30d9\u30f3\u30c8 \u30c8\u30ec\u30fc\u30b7\u30f3\u30b0\u3092\u4f7f\u7528\u3057\u3066\u76e3\u67fb\u6a5f\u80fd\u3092\u5236\u9650\u3067\u304d\u307e\u3057\u305f\u304c\u3001\u6700\u8fd1\u30019 \u3064\u306e\u30a4\u30d9\u30f3\u30c8\u304c\u6539\u5584\u3055\u308c\u3001\u5206\u6790\u60c5\u5831\u304c\u5411\u4e0a\u3057\u307e\u3057\u305f\u3002\u5177\u4f53\u7684\u306b\u306f\u3001\u3044\u304f\u3064\u304b\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u95a2\u9023\u30a4\u30d9\u30f3\u30c8\u3067\u3001\u30a4\u30d9\u30f3\u30c8 \u30b9\u30ad\u30fc\u30de\u306b\u30d7\u30ed\u30bb\u30b9 ID \u3068\u30d7\u30ed\u30bb\u30b9\u958b\u59cb\u30ad\u30fc\u304c\u8868\u793a\u3055\u308c\u308b\u3088\u3046\u306b\u306a\u308a\u3001\u3053\u308c\u3089\u306e\u30a4\u30d9\u30f3\u30c8\u306e\u539f\u56e0\u30d7\u30ed\u30bb\u30b9\u3092\u78ba\u8a8d\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3057\u305f\u3002\u307e\u305f\u3001\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306e\u4e92\u63db\u6027\u30dd\u30ea\u30b7\u30fc\u306b\u5f93\u3063\u3066\u3001\u30a4\u30d9\u30f3\u30c8\u304c\u6642\u9593\u306e\u7d4c\u904e\u3068\u5171\u306b\u66f4\u65b0\u3055\u308c\u308b\u305f\u3081\u3001\u30a4\u30d9\u30f3\u30c8   \u30d0\u30fc\u30b8\u30e7\u30f3\u3082\u5897\u52a0\u3057\u307e\u3057\u305f\u3002&nbsp;&nbsp;<\/div>\n<div>&nbsp;<\/div>\n<div><b>\u3053\u308c\u306f\u3044\u3064\u8d77\u3053\u308a\u307e\u3059\u304b:<\/b>&nbsp;<\/div>\n<div>\u3053\u308c\u3089\u306e\u6a5f\u80fd\u5f37\u5316\u306f\u3001\u3059\u3079\u3066\u306e Windows \u30d0\u30fc\u30b8\u30e7\u30f3\u3067\u65e2\u306b\u5229\u7528\u53ef\u80fd\u3067\u3059\u3002&nbsp;<\/div>\n<div>&nbsp;<\/div>\n<div><b>\u3053\u308c\u304c\u7d44\u7e54\u306b\u4e0e\u3048\u308b\u5f71\u97ff:<\/b>&nbsp;<\/div>\n<div>\u7d44\u7e54\u306f\u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u8a3a\u65ad\u3068\u76e3\u67fb\u306e\u305f\u3081\u306b Windows \u30a4\u30d9\u30f3\u30c8 \u30d3\u30e5\u30fc\u30a2\u30fc\u3092\u3088\u308a\u6709\u52b9\u306b\u6d3b\u7528\u3067\u304d\u307e\u3059\u3002\u3053\u308c\u307e\u3067\u3001Windows \u30a4\u30d9\u30f3\u30c8 \u30c8\u30ec\u30fc\u30b7\u30f3\u30b0\u306e\u30ed\u30b0\u306b\u306f\u3001\u30c7\u30d0\u30a4\u30b9\u306b\u5f71\u97ff\u3092\u4e0e\u3048\u308b\u3044\u304f\u3064\u304b\u306e\u30a4\u30d9\u30f3\u30c8\u3068\u30d7\u30ed\u30bb\u30b9\u304c\u3001&#8221;\u30b7\u30b9\u30c6\u30e0\/\u30ab\u30fc\u30cd\u30eb\u304c\u3053\u306e\u30a4\u30d9\u30f3\u30c8\u3092\u30ed\u30b0\u306b\u8a18\u9332\u3057\u307e\u3057\u305f&#8221; \u3068\u3044\u3046\u4e00\u822c\u7684\u306a\u30e1\u30c3\u30bb\u30fc\u30b8\u3068\u5171\u306b\u4e00\u89a7\u8868\u793a\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u3002\u305d\u306e\u305f\u3081\u3001\u4e00\u90e8\u306e\u30a4\u30d9\u30f3\u30c8\u306f\u3001\u5225\u306e\u30a2\u30af\u30b7\u30e7\u30f3\u306b\u3088\u3063\u3066\u5f15\u304d\u8d77\u3053\u3055\u308c\u305f\u304b\u306e\u3088\u3046\u306b\u8868\u793a\u3055\u308c\u308b\u5834\u5408\u304c\u3042\u308a\u307e\u3059\u3002\u73fe\u5728\u3001\u958b\u59cb\u30d7\u30ed\u30bb\u30b9\u306f\u3001\u30d7\u30ed\u30bb\u30b9 ID \u3068\u30d7\u30ed\u30bb\u30b9\u958b\u59cb\u30ad\u30fc\u306e\u5f62\u5f0f\u3067\u6b21\u306e\u30a4\u30d9\u30f3\u30c8\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u90e8\u5206\u306b\u8ffd\u52a0\u3055\u308c\u307e\u3059\u3002&nbsp;<\/div>\n<div>&nbsp;<\/div>\n<ul>\n<li>4697: \u30b5\u30fc\u30d3\u30b9\u304c\u30b7\u30b9\u30c6\u30e0\u306b\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u307e\u3057\u305f.&nbsp;<\/li>\n<li>4698: \u30b9\u30b1\u30b8\u30e5\u30fc\u30eb\u3055\u308c\u305f\u30bf\u30b9\u30af\u304c\u4f5c\u6210\u3055\u308c\u307e\u3057\u305f.&nbsp;<\/li>\n<li>4699: \u30b9\u30b1\u30b8\u30e5\u30fc\u30eb\u3055\u308c\u305f\u30bf\u30b9\u30af\u304c\u524a\u9664\u3055\u308c\u307e\u3057\u305f.&nbsp;<\/li>\n<li>4700: \u30b9\u30b1\u30b8\u30e5\u30fc\u30eb\u3055\u308c\u305f\u30bf\u30b9\u30af\u304c\u6709\u52b9\u306b\u306a\u308a\u307e\u3057\u305f.&nbsp;<\/li>\n<li>4701: \u30b9\u30b1\u30b8\u30e5\u30fc\u30eb\u3055\u308c\u305f\u30bf\u30b9\u30af\u304c\u7121\u52b9\u306b\u306a\u308a\u307e\u3057\u305f.&nbsp;<\/li>\n<li>4702: \u30b9\u30b1\u30b8\u30e5\u30fc\u30eb\u3055\u308c\u305f\u30bf\u30b9\u30af\u304c\u66f4\u65b0\u3055\u308c\u307e\u3057\u305f.&nbsp;<\/li>\n<li>4719: \u30b7\u30b9\u30c6\u30e0\u76e3\u67fb\u30dd\u30ea\u30b7\u30fc\u304c\u5909\u66f4\u3055\u308c\u307e\u3057\u305f.&nbsp;<\/li>\n<li>1102: \u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u76e3\u67fb\u30ed\u30b0\u304c\u30af\u30ea\u30a2\u3055\u308c\u307e\u3057\u305f\u3002[\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3] \u30c1\u30e3\u30cd\u30eb\u306b\u8868\u793a\u3055\u308c\u307e\u3059\u3002&nbsp;<\/li>\n<li>104: {\u30c1\u30e3\u30cd\u30eb\u540d} \u30ed\u30b0 \u30d5\u30a1\u30a4\u30eb\u304c\u30af\u30ea\u30a2\u3055\u308c\u307e\u3057\u305f\u3002\u30b7\u30b9\u30c6\u30e0 \u30c1\u30e3\u30cd\u30eb\u306b\u8868\u793a\u3055\u308c\u307e\u3059\u3002&nbsp;<\/li>\n<\/ul>\n<div>&nbsp;<\/div>\n<div>\u653b\u6483\u30c4\u30fc\u30eb\u306f\u30a4\u30d9\u30f3\u30c8 \u30ed\u30b0\u3092\u30af\u30ea\u30a2\u3057\u3066\u76e3\u67fb\u3092\u7121\u52b9\u306b\u3059\u308b\u3053\u3068\u304c\u591a\u3044\u305f\u3081\u3001\u3053\u308c\u3089\u306f\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u95a2\u9023\u306e\u30a4\u30d9\u30f3\u30c8\u3068\u898b\u306a\u3055\u308c\u307e\u3059\u3002&nbsp;<\/div>\n<div>&nbsp;<\/div>\n<div><b>\u6e96\u5099\u3059\u308b\u305f\u3081\u306b\u5fc5\u8981\u306a\u3053\u3068:<\/b>&nbsp;<\/div>\n<div>\u3053\u308c\u3089\u306e\u6a5f\u80fd\u5f37\u5316\u306e\u8a73\u7d30\u306a\u624b\u9806\u3001\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8\u3001\u304a\u3088\u3073\u4f8b\u306b\u3064\u3044\u3066\u306f\u3001\u300c <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/windows-it-pro-blog\/new-security-capabilities-of-event-tracing-for-windows\/ba-p\/3949941\" rel=\"noopener noreferrer\" target=\"_blank\">  Windows \u7528\u30a4\u30d9\u30f3\u30c8 \u30c8\u30ec\u30fc\u30b7\u30f3\u30b0\u306e\u65b0\u3057\u3044\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u6a5f\u80fd<\/a> \u300d\u3092\u53c2\u7167\u3057\u3066\u304f\u3060\u3055\u3044\u3002\u8a73\u7d30\u306b\u3064\u3044\u3066\u306f\u3001\u8ffd\u52a0\u60c5\u5831\u3092\u78ba\u8a8d\u3057\u3066\u304f\u3060\u3055\u3044\u3002&nbsp;<\/div>\n<div>  <\/div>\n<div><b>\u8ffd\u52a0\u60c5\u5831:<\/b>&nbsp;<\/div>\n<ul>\n<li>Windows&nbsp;<a href=\"https:\/\/techcommunity.microsoft.com\/t5\/windows-it-pro-blog\/new-security-capabilities-of-event-tracing-for-windows\/ba-p\/3949941\" rel=\"noopener noreferrer\" target=\"_blank\">\u30a4\u30d9\u30f3\u30c8 \u30c8\u30ec\u30fc\u30b7\u30f3\u30b0\u306e\u65b0\u3057\u3044\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u6a5f\u80fd<\/a><\/li>\n<li>ETW&nbsp;<a href=\"https:\/\/learn.microsoft.com\/windows-hardware\/test\/weg\/instrumenting-your-code-with-etw\" rel=\"noopener noreferrer\" target=\"_blank\">\u3092\u4f7f\u7528\u3057\u305f\u30b3\u30fc\u30c9\u306e\u30a4\u30f3\u30b9\u30c8\u30eb\u30e1\u30f3\u30c8\u5316<\/a><\/li>\n<li><a href=\"https:\/\/learn.microsoft.com\/windows\/win32\/api\/_etw\/\" rel=\"noopener noreferrer\" target=\"_blank\">\u30a4\u30d9\u30f3\u30c8 \u30c8\u30ec\u30fc\u30b9 &#8211; Win32 \u30a2\u30d7\u30ea<\/a>&nbsp;<\/li>\n<li><a href=\"https:\/\/learn.microsoft.com\/windows\/win32\/api\/evntrace\/ns-evntrace-enable_trace_parameters\" rel=\"noopener noreferrer\" target=\"_blank\">ENABLE_TRACE_PARAMETERS (evntrace.h)<\/a>&nbsp;<\/li>\n<li><a href=\"https:\/\/learn.microsoft.com\/training\/modules\/manage-monitor-event-logs\/2-describe-windows-server-event-logs\" rel=\"noopener noreferrer\" target=\"_blank\">Windows \u30b5\u30fc\u30d0\u30fc\u306e\u30a4\u30d9\u30f3\u30c8 \u30ed\u30b0<\/a>&nbsp;\u306b\u3064\u3044\u3066\u8aac\u660e\u3059\u308b<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>MC680761 | New security capabilities of Event Tracing for Windows Classification stayInformed Last Updated 10\/ [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-3586","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts\/3586","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/comments?post=3586"}],"version-history":[{"count":0,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts\/3586\/revisions"}],"wp:attachment":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/media?parent=3586"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/categories?post=3586"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/tags?post=3586"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}