Windows 事件檢視器中的攻擊面縮小事件

在評估攻擊面減少功能時,檢視事件檢視器中的事件非常有用。 例如,你可以啟用功能或設定的稽核模式,然後檢視如果完全啟用會發生什麼事。 你也可以看到攻擊面減少功能完全啟用時的效果。

本文說明如何利用 Windows 事件檢視器 來檢視攻擊面減少 (ASR) 能力的事件,包括:

若要檢視攻擊面縮小事件,如本文其餘部分所述,您有以下選項:

提示

你可以使用 Windows 事件轉發 來集中收集多台裝置的攻擊面減少事件。

Microsoft Defender 入口網站也提供比 Windows 事件檢視器更易使用的攻擊面減少報告功能:

在 Windows 事件檢視器中瀏覽攻擊面減少事件

所有攻擊面減少事件都位於 應用程式與服務日誌中。 要查看攻擊面縮減事件,請執行以下步驟:

  1. 選擇開始,輸入事件檢視器,然後按 Enter 鍵開啟事件檢視器。

  2. 在事件檢視器中,展開應用程式與服務日誌>Microsoft>Windows。

  3. 持續擴展 ASR 規則事件、 受控資料夾存取事件、 利用保護事件或 網路保護事件的路徑。

  4. 您可以使用 ASR 規則事件、受控資料夾存取事件、利用保護事件及網路保護事件區塊中的事件 ID 表格,或在 事件檢視器 中建立自訂檢視,來尋找並篩選你想看到的事件。

ASR 規則事件

ASR 規則事件位於 Windows Defender>操作 日誌中:

事件識別碼 描述
1121 規則在封鎖模式下觸發時的事件
1122 規則在稽核模式下觸發時會發生的事件
1129 使用者在警告模式下覆寫封鎖時會發生的事件
5007 變更設定時的事件

檢視受控資料夾存取事件

受控資料夾存取事件位於 Windows Defender>操作中。

事件識別碼 描述
5007 變更設定時的事件
1124 經審核的受控資料夾存取事件
1123 被封鎖的受控資料夾存取事件
1127 封鎖的受控資料夾存取磁區寫入封鎖事件
1128 已稽核的受控資料夾存取磁區寫入封鎖事件

查看漏洞保護事件

以下漏洞保護事件位於安全緩解>核心模式與>使用者模式日誌中:

事件識別碼 描述
1 ACG 稽核
2 ACG 強制執行
3 不允許子處理序稽核
4 不要讓子處理序造成阻塞
5 封鎖低完整性映像檔稽核
6 封鎖低完整性映像檔區塊
7 封鎖遠端映像稽核
8 封鎖遠端影像封鎖
9 停用 win32k 系統呼叫稽核
10 停用 win32k 系統呼叫封鎖
11 程式碼完整性防護稽核
12 程式碼完整性防護封鎖
13 EAF 稽核
14 EAF 強制執行
15 EAF+ 稽核
16 EAF+ 強制執行
17 IAF 稽核
18 IAF 強制執行
19 ROP StackPivot 稽核
20 ROP StackPivot 強制執行
21 ROP CallerCheck 稽核
22 ROP CallerCheck 強制執行
23 ROP SimExec 稽核
24 ROP SimExec 強制啟用

以下漏洞保護事件位於 WER 診斷>操作 日誌中:

事件識別碼 描述
5 CFG 區塊

以下漏洞利用保護事件位於 Win32k>營運 日誌中:

事件識別碼 描述
260 未受信任的字型

查看網路保護事件

網路保護事件位於 Windows Defender>Operational 中。

事件識別碼 描述
5007 變更設定時的事件
1125 網路保護在稽核模式下觸發時會發生的事件
1126 網路保護在封鎖模式下觸發時會發生的事件

在 Windows 事件檢視器中使用自訂檢視器來查看攻擊面減少事件

你可以在 Windows 事件檢視器中建立自訂視圖,只看到針對特定攻擊面減少功能的事件。 最簡單的方法是將自訂視圖匯入為 XML 檔案。 你也可以直接將 XML 複製到 事件檢視器。

如需可直接使用的 XML 範本,請參閱 適用於攻擊面縮小事件的自訂 XML 範本一節。

匯入現有的 XML 自訂視圖

要將現有的 XML 自訂檢視導入 事件檢視器,請完成以下步驟:

  1. 建立一個空的 .txt 檔案,並將你想使用的自訂視圖的 XML 複製到 .txt 檔案中。 對你想使用的每個自訂視圖都做這個步驟。 請依下列方式重新命名檔案 (確保將類型從 .txt 改為 .xml) :

    • 受控資料夾存取事件自訂檢視: cfa-events.xml
    • 攻擊防護事件自訂視圖:ep-events.xml
    • 攻擊面減少事件自訂檢視: asr-events.xml
    • 網路保護事件自訂視圖: np-events.xml
  2. 選擇開始,輸入事件檢視器,然後按 Enter 鍵開啟事件檢視器。

  3. 選擇 動作>匯入自訂檢視...

    動畫示範如何在 事件檢視器 中選擇並匯入已儲存的 XML 檔案作為自訂視圖。

  4. 導向你想要的自訂視圖的 XML 檔案並選擇它。

  5. 選取 開啟。

自訂檢視會篩選為僅顯示與所選攻擊面縮減功能相關的事件。

直接將 XML 複製到 事件檢視器 中

若要直接將 XML 貼上至自訂檢視,請完成以下步驟:

  1. 選擇開始,輸入事件檢視器,然後按 Enter 鍵開啟事件檢視器。

  2. 在 動作 面板中,選擇 建立自訂視圖...

  3. 前往 XML 標籤。請注意,如果你手動選擇 編輯查詢,之後無法透過 篩選 標籤編輯查詢。手動選擇 編輯查詢,然後選擇 「是 」以確認。

  4. 將自訂 XML 範本 中用於攻擊面減少規則、受控資料夾存取、漏洞防護或網路保護的 XML 程式碼貼上到 XML 區塊。

  5. 選取 確定。 請指定你的過濾器名稱。 自訂檢視會篩選為僅顯示與所選攻擊面縮減功能相關的事件。

用於攻擊面縮減事件的自訂 XML 範本

請使用以下 XML 範本,在 事件檢視器 中為每個攻擊面減少能力建立自訂視圖。 你可以將這些範本匯入 XML 檔案,或直接貼到 事件檢視器 中。

受攻擊面縮小規則事件的 XML

以下 XML 查詢會過濾 Windows Defender 操作日誌中的 ASR 規則事件(事件 ID 1121、1122、1129 和 5007):

<QueryList>
  <Query Id="0" Path="Microsoft-Windows-Windows Defender/Operational">
   <Select Path="Microsoft-Windows-Windows Defender/Operational">*[System[(EventID=1121 or EventID=1122 or EventID=1129 or EventID=5007)]]</Select>
   <Select Path="Microsoft-Windows-Windows Defender/WHC">*[System[(EventID=1121 or EventID=1122 or EventID=1129 or EventID=5007)]]</Select>
  </Query>
</QueryList>

用於受控資料夾存取事件的 XML

以下 XML 查詢會過濾 Windows Defender 操作日誌中的受控資料夾存取事件(事件 ID 1123、1124、1127、1128 和 5007):

<QueryList>
  <Query Id="0" Path="Microsoft-Windows-Windows Defender/Operational">
   <Select Path="Microsoft-Windows-Windows Defender/Operational">*[System[(EventID=1123 or EventID=1124 or EventID=1127 or EventID=1128 or EventID=5007)]]</Select>
   <Select Path="Microsoft-Windows-Windows Defender/WHC">*[System[(EventID=1123 or EventID=1124 or EventID=1127 or EventID=1128 or EventID=5007)]]</Select>
  </Query>
</QueryList>

用於漏洞保護事件的 XML

以下 XML 查詢會針對 Security-Mitigations、WER-Diagnostics 和 Win32k 提供者(事件 ID 1–24、5 和 260)建立攻擊防護事件的自訂檢視:

<QueryList>
  <Query Id="0" Path="Microsoft-Windows-Security-Mitigations/KernelMode">
   <Select Path="Microsoft-Windows-Security-Mitigations/KernelMode">*[System[Provider[@Name='Microsoft-Windows-Security-Mitigations' or @Name='Microsoft-Windows-WER-Diag' or @Name='Microsoft-Windows-Win32k' or @Name='Win32k'] and ( (EventID &gt;= 1 and EventID &lt;= 24)  or EventID=5 or EventID=260)]]</Select>
   <Select Path="Microsoft-Windows-Win32k/Concurrency">*[System[Provider[@Name='Microsoft-Windows-Security-Mitigations' or @Name='Microsoft-Windows-WER-Diag' or @Name='Microsoft-Windows-Win32k' or @Name='Win32k'] and ( (EventID &gt;= 1 and EventID &lt;= 24)  or EventID=5 or EventID=260)]]</Select>
   <Select Path="Microsoft-Windows-Win32k/Contention">*[System[Provider[@Name='Microsoft-Windows-Security-Mitigations' or @Name='Microsoft-Windows-WER-Diag' or @Name='Microsoft-Windows-Win32k' or @Name='Win32k'] and ( (EventID &gt;= 1 and EventID &lt;= 24)  or EventID=5 or EventID=260)]]</Select>
   <Select Path="Microsoft-Windows-Win32k/Messages">*[System[Provider[@Name='Microsoft-Windows-Security-Mitigations' or @Name='Microsoft-Windows-WER-Diag' or @Name='Microsoft-Windows-Win32k' or @Name='Win32k'] and ( (EventID &gt;= 1 and EventID &lt;= 24)  or EventID=5 or EventID=260)]]</Select>
   <Select Path="Microsoft-Windows-Win32k/Operational">*[System[Provider[@Name='Microsoft-Windows-Security-Mitigations' or @Name='Microsoft-Windows-WER-Diag' or @Name='Microsoft-Windows-Win32k' or @Name='Win32k'] and ( (EventID &gt;= 1 and EventID &lt;= 24)  or EventID=5 or EventID=260)]]</Select>
   <Select Path="Microsoft-Windows-Win32k/Power">*[System[Provider[@Name='Microsoft-Windows-Security-Mitigations' or @Name='Microsoft-Windows-WER-Diag' or @Name='Microsoft-Windows-Win32k' or @Name='Win32k'] and ( (EventID &gt;= 1 and EventID &lt;= 24)  or EventID=5 or EventID=260)]]</Select>
   <Select Path="Microsoft-Windows-Win32k/Render">*[System[Provider[@Name='Microsoft-Windows-Security-Mitigations' or @Name='Microsoft-Windows-WER-Diag' or @Name='Microsoft-Windows-Win32k' or @Name='Win32k'] and ( (EventID &gt;= 1 and EventID &lt;= 24)  or EventID=5 or EventID=260)]]</Select>
   <Select Path="Microsoft-Windows-Win32k/Tracing">*[System[Provider[@Name='Microsoft-Windows-Security-Mitigations' or @Name='Microsoft-Windows-WER-Diag' or @Name='Microsoft-Windows-Win32k' or @Name='Win32k'] and ( (EventID &gt;= 1 and EventID &lt;= 24)  or EventID=5 or EventID=260)]]</Select>
   <Select Path="Microsoft-Windows-Win32k/UIPI">*[System[Provider[@Name='Microsoft-Windows-Security-Mitigations' or @Name='Microsoft-Windows-WER-Diag' or @Name='Microsoft-Windows-Win32k' or @Name='Win32k'] and ( (EventID &gt;= 1 and EventID &lt;= 24)  or EventID=5 or EventID=260)]]</Select>
   <Select Path="System">*[System[Provider[@Name='Microsoft-Windows-Security-Mitigations' or @Name='Microsoft-Windows-WER-Diag' or @Name='Microsoft-Windows-Win32k' or @Name='Win32k'] and ( (EventID &gt;= 1 and EventID &lt;= 24)  or EventID=5 or EventID=260)]]</Select>
   <Select Path="Microsoft-Windows-Security-Mitigations/UserMode">*[System[Provider[@Name='Microsoft-Windows-Security-Mitigations' or @Name='Microsoft-Windows-WER-Diag' or @Name='Microsoft-Windows-Win32k' or @Name='Win32k'] and ( (EventID &gt;= 1 and EventID &lt;= 24)  or EventID=5 or EventID=260)]]</Select>
  </Query>
</QueryList>

網路保護事件的 XML

以下 XML 查詢會過濾 Windows Defender 營運日誌中的網路保護事件(事件 ID 1125、1126 及 5007):

<QueryList>
 <Query Id="0" Path="Microsoft-Windows-Windows Defender/Operational">
  <Select Path="Microsoft-Windows-Windows Defender/Operational">*[System[(EventID=1125 or EventID=1126 or EventID=5007)]]</Select>
  <Select Path="Microsoft-Windows-Windows Defender/WHC">*[System[(EventID=1125 or EventID=1126 or EventID=5007)]]</Select>
 </Query>
</QueryList>