// REFERENCE

4719 — System audit policy was changed

Log: Security High risk

The system audit policy was changed. Disabling audit categories to stop generating incriminating events is a quiet evasion: the attacker blinds the SIEM before acting. Alert on any reduction of auditing.

Related tools

Work with this in:

Related

Original descriptions based on Microsoft's public documentation. IDs and fields may vary with the Windows version and the active audit policy.