windows-event-logs

Document Windows-native telemetry sources and audit policy prerequisites for detection engineering.

4|1|Updated Apr 28, 2026
One-click install
npx skills add https://github.com/OpenTideHQ/AgentTide --skill windows-event-logs
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: windows-event-logs
Source: https://github.com/OpenTideHQ/AgentTide/tree/main/skills/windows-event-logs
Command: npx skills add https://github.com/OpenTideHQ/AgentTide --skill windows-event-logs

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Windows-native event log guidance for detection engineers to translate raw telemetry into actionable detections and ensure necessary audit policies are in place.

Core Features & Use Cases

  • Event channel landscape mapping and coverage of critical Windows events
  • Sysmon, PowerShell, ETW, and Defender telemetry integration guidance
  • SIEM ingestion patterns, targeting reliable data flows and normalization
  • Use cases: align detections with audit policies and ETW tamper awareness

Quick Start

Review the Windows Event Logs skill to map common events to detection rules and verify required audit policies.

Frequently Asked Questions about windows-event-logs

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map Windows event logs for detection engineering?

Map Windows event logs for detection engineering by identifying native telemetry sources and applying them to scenarios involving Security, Sysmon, PowerShell, ETW, and Defender events. Documenting these sources translates raw telemetry into actionable detections.

What audit policy prerequisites do I need for Windows Defender and Sysmon event logging?

Audit policy prerequisites for Windows event logging specify the necessary configurations to capture critical events. Verifying these audit policies ensures reliable telemetry generation for Sysmon and Defender events before SIEM ingestion.

Can I integrate Windows ETW telemetry with SIEM ingestion patterns?

Yes, you can integrate Windows ETW telemetry with SIEM ingestion patterns. This ensures reliable data flows and normalization for enterprise Windows environments, maintaining ETW tamper awareness for detection coverage.

What is the best way to document Windows event telemetry sources for SIEM normalization?

The best way to document Windows event telemetry sources is to map the event channel landscape and specify relevant Event IDs. This aligns detections with SIEM ingestion patterns to target reliable data flows.

Does this approach cover PowerShell and ETW tamper awareness for enterprise environments?

Yes, this approach covers PowerShell and ETW tamper awareness. It provides guidance to tailor detections to enterprise Windows environments by documenting critical events and integrating with security telemetry.