API Reference
Enum
AuditSubcategory
Advanced Audit Policy subcategories. Names and descriptions mirror Windows labels/intent.
Inheritance
- Enum
- AuditSubcategory
Inherited Methods
public override sealed Int32 CompareTo(Object target) #Returns:
Int32Inherited from Enum
Parameters
- target Object
public override sealed String ToString(String format, IFormatProvider provider) #Returns:
StringInherited from Enum
Obsolete("The provider argument is not used. Use ToString(String) instead.")Parameters
- format String
Values
public const AuditSubcategory KerberosAuthenticationService #Kerberos AS requests (TGT acquisition).
Value:
0public const AuditSubcategory KerberosServiceTicketOperations #Kerberos TGS requests (service tickets).
Value:
1public const AuditSubcategory CredentialValidation #NTLM and other credential validation events.
Value:
2public const AuditSubcategory UserAccountManagement #User account lifecycle (create/modify/delete).
Value:
4public const AuditSubcategory SecurityGroupManagement #Security group changes and membership.
Value:
6public const AuditSubcategory DistributionGroupManagement #Distribution group changes and membership.
Value:
7public const AuditSubcategory OtherAccountManagementEvents #Other Account Management events.
Value:
9public const AuditSubcategory ProcessCreation #Process creation (4688). Often paired with command line logging.
Value:
10public const AuditSubcategory DirectoryServiceChanges #DS object changes (audit directory service changes).
Value:
16public const AuditSubcategory DetailedDirectoryServiceReplication #Detailed replication operations.
Value:
18public const AuditSubcategory MPSSVCRuleLevelPolicyChange #Windows Defender Firewall policy change.
Value:
41public const AuditSubcategory SensitivePrivilegeUse #Sensitive privilege use (e.g., SeDebug, SeTcb).
Value:
44public const AuditSubcategory SecurityStateChange #Security state change (startup/shutdown).
Value:
47