API Reference
AuditSubcategory
Advanced Audit Policy subcategories. Names and descriptions mirror Windows labels/intent.
Inheritance
- Enum
- AuditSubcategory
Usage
This type appears in these public API surfaces even when no hand-authored example is attached directly to the page.
Returned or exposed by
- Field AuditSubcategory.AccountLockout
- Field AuditSubcategory.ApplicationGroupManagement
- Field AuditSubcategory.AuditPolicyChange
- Field AuditSubcategory.AuthenticationPolicyChange
- Field AuditSubcategory.AuthorizationPolicyChange
- Field AuditSubcategory.CentralPolicyStaging
- Field AuditSubcategory.CertificationServices
- Field AuditSubcategory.ComputerAccountManagement
- Field AuditSubcategory.CredentialValidation
- Field AuditSubcategory.DetailedDirectoryServiceReplication
- Field AuditSubcategory.DirectoryServiceAccess
- Field AuditSubcategory.DirectoryServiceChanges
- Field AuditSubcategory.DirectoryServiceReplication
- Field AuditSubcategory.DistributionGroupManagement
- Field AuditSubcategory.DPAPIActivity
- Field AuditSubcategory.FileSystem
- Field AuditSubcategory.FilteringPlatformConnection
- Field AuditSubcategory.FilteringPlatformPacketDrop
- Field AuditSubcategory.FilteringPlatformPolicyChange
- Field AuditSubcategory.HandleManipulation
- Field AuditSubcategory.IPsecDriver
- Field AuditSubcategory.KerberosAuthenticationService
- Field AuditSubcategory.KerberosServiceTicketOperations
- Field AuditSubcategory.KernelObject
- Field AuditSubcategory.Logoff
- Field AuditSubcategory.Logon
- Field AuditSubcategory.MPSSVCRuleLevelPolicyChange
- Field AuditSubcategory.NetworkPolicyServer
- Field AuditSubcategory.NonSensitivePrivilegeUse
- Field AuditSubcategory.OtherAccountLogonEvents
- Field AuditSubcategory.OtherAccountManagementEvents
- Field AuditSubcategory.OtherLogonLogoffEvents
- Field AuditSubcategory.OtherObjectAccessEvents
- Field AuditSubcategory.OtherPolicyChangeEvents
- Field AuditSubcategory.OtherPrivilegeUseEvents
- Field AuditSubcategory.OtherSystemEvents
- Field AuditSubcategory.PNPActivity
- Field AuditSubcategory.ProcessCreation
- Field AuditSubcategory.ProcessTermination
- Field AuditSubcategory.Registry
- Field AuditSubcategory.RemovableStorage
- Field AuditSubcategory.RPCEvents
- Field AuditSubcategory.SAM
- Field AuditSubcategory.SecurityGroupManagement
- Field AuditSubcategory.SecurityStateChange
- Field AuditSubcategory.SecuritySystemExtension
- Field AuditSubcategory.SensitivePrivilegeUse
- Field AuditSubcategory.SpecialLogon
- Field AuditSubcategory.SystemIntegrity
- Field AuditSubcategory.UserAccountManagement
- Field AuditSubcategory.UserDeviceClaims
- Field AuditSubcategory.WMI
Inherited Methods
public override sealed Int32 CompareTo(Object target) #Int32Parameters
- target Object
public override sealed String ToString(String format, IFormatProvider provider) #StringObsolete("The provider argument is not used. Use ToString(String) instead.")Parameters
- format String
Values
public const AuditSubcategory KerberosAuthenticationService #Kerberos AS requests (TGT acquisition).
0public const AuditSubcategory KerberosServiceTicketOperations #Kerberos TGS requests (service tickets).
1public const AuditSubcategory CredentialValidation #NTLM and other credential validation events.
2public const AuditSubcategory UserAccountManagement #User account lifecycle (create/modify/delete).
4public const AuditSubcategory SecurityGroupManagement #Security group changes and membership.
6public const AuditSubcategory DistributionGroupManagement #Distribution group changes and membership.
7public const AuditSubcategory OtherAccountManagementEvents #Other Account Management events.
9public const AuditSubcategory ProcessCreation #Process creation (4688). Often paired with command line logging.
10public const AuditSubcategory DirectoryServiceChanges #DS object changes (audit directory service changes).
16public const AuditSubcategory DetailedDirectoryServiceReplication #Detailed replication operations.
18public const AuditSubcategory MPSSVCRuleLevelPolicyChange #Windows Defender Firewall policy change.
41public const AuditSubcategory SensitivePrivilegeUse #Sensitive privilege use (e.g., SeDebug, SeTcb).
44public const AuditSubcategory SecurityStateChange #Security state change (startup/shutdown).
47