Covers the five core Windows event log sources: Security (incl. domain controller events), Application, System, Sysmon, and PowerShell. Every event row cites the specific sources behind its recommendation — click a row to expand and view direct links. Filtering guidance (⚠) is provided for high-volume events where full ingestion isn't cost-effective, with the specific scope or exclusion that preserves detection value. Recommendations are cross-checked against joint guidance from NSA, CISA, ASD, and international partners — not just vendor documentation. This same catalog also maps to
NIST 800-53,
MITRE ATT&CK,
MITRE ATLAS, and
CIS Critical Security Controls.