// REFERENCE
4719 — System audit policy was changed
Log: Security
High risk
The system audit policy was changed. Disabling audit categories to stop generating incriminating events is a quiet evasion: the attacker blinds the SIEM before acting. Alert on any reduction of auditing.
Related tools
Work with this in:
Related
Original descriptions based on Microsoft's public documentation. IDs and fields may vary with the Windows version and the active audit policy.