Wazuh Log Viewer

Windows Security Events

10 alerts
Timestamp
Agent
User
Process
Parent ProcessEvent IDRule ID
Severity
1/15/2024, 2:40:55 PM
WIN-WORKSTATION-05
192.168.1.105
user01C:\Users\user01\AppData\Local\Temp\malicious.exeC:\Windows\System32\wscript.exe468818161High (9)
1/15/2024, 2:38:09 PM
WIN-SERVER-03
192.168.1.52
administratorC:\Windows\System32\mstsc.exeC:\Windows\explorer.exe468818158Medium (4)
1/15/2024, 2:35:22 PM
WIN-WORKSTATION-07
192.168.1.107
bob.johnsonC:\Program Files\Google\Chrome\Application\chrome.exeC:\Windows\explorer.exe468818156Low (3)
1/15/2024, 2:32:47 PM
WIN-SERVER-01
192.168.1.50
guestC:\Windows\System32\runas.exeC:\Windows\System32\cmd.exe468818160High (8)
1/15/2024, 2:30:15 PM
WIN-WORKSTATION-03
192.168.1.103
jane.smithC:\Windows\System32\net.exeC:\Windows\System32\cmd.exe468818159Medium (5)
1/15/2024, 2:27:33 PM
WIN-SERVER-02
192.168.1.51
service_accountC:\Program Files\Application\app.exeC:\Windows\System32\services.exe468818156Low (2)
1/15/2024, 2:25:12 PM
WIN-WORKSTATION-05
192.168.1.105
adminC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\cmd.exe468818157High (7)
1/15/2024, 2:24:35 PM
WIN-WORKSTATION-02
192.168.1.102
1192110High (7)
1/15/2024, 2:24:30 PM
WIN-WORKSTATION-02
192.168.1.102
192100Medium (6)
1/15/2024, 2:23:45 PM
WIN-SERVER-01
192.168.1.50
john.doeC:\Windows\System32\cmd.exeC:\Windows\explorer.exe468818156Low (3)
Showing 1-10 of 10 alerts
Page 1 of 1
Built with v0