Event Sets for Integration Alerting

Event Sets for Integration Alerting

In ConnectSecure, Event Sets are the predefined events that can trigger an alert using the supported integrations. Categories organize them and can be enabled with a simple checkbox.

Event Sets are hard-coded and can not be modified or removed from the system.

Event Sets work across most of the integrations where alerting is supported.


Event Set - Table of Contents


Event Set - Details

You will find the Event Set options listed under the integration details.

Not all supported ones are shown, so check your specific integration for the Event Set and Integration Rules options.

image-20260608-193152.png

You will not see the Event Set options until you have provided the credentials for the selected integration.

image-20250825-181630.png

 


Events by Category

Event Set categories include:

System Changes, Problems, Solutions, Entra ID Audit, Entra ID Error, AD Audit, Job Failed, Certificate Expire in 30 Days, Microsoft 365 Assessment, Google Workspace Assessment, and Web Application Scanning.

Below is a breakdown of each category and the available 'events' you can monitor for each.

System Changes

Event

Description

Event

Description

New Asset Added

A new asset is added to the All Asset section; this can happen when agents are installed or assets are detected by probe scanning.

Agent has Outdated Version

The agent version for a lightweight or probe agent is behind the current version release.

New Company Created

A new company is created in the ConnectSecure portal, using local or PSA options.

New Open Port Discovered (Probe Scan)

A new port is discovered on an internal asset during a probe scan; port discovery and scanning are only done by a Probe agent.

New Open Port Discovered (External Scan)

A new open port is discovered during an external scan.

Probe Went Down

The probe agent is offline and can not be reached

Server Agent Went Down

Any agent (probe or lightweight) that is a ‘Server’ identified by its operating system is offline and can not be reached.


Problems

Event

Description

Event

Description

CISA Vulnerabilities Found

Vulnerabilities found that are published by CISA

Known Exploited Vulnerabilities Catalog | CISA

Critical Severity Vulnerabilities Found

Vulnerabilities found with a critical severity as found in the CVSS Base Score

High Severity Vulnerabilities Found

Vulnerabilities found with a critical severity as found in the CVSS Base Score

Low Severity Vulnerabilities Found

Vulnerabilities found with a low severity as found in the CVSS Base Score

Medium Severity Vulnerabilities Found

Vulnerabilities found with a critical severity as found in the CVSS Base Score

Remote Login Vulnerabilities Found

Problems related to remote login or remote access problems; IE: RDP-NTLM

SMB Vulnerabilities Found

Problems related to the SMB protocol; IE: SMB_Signing

SSL/TLS Vulnerabilities Found

Problems related to SSL/TLS certificates and ciphers; IE: TLSv1.1, Sweet32, SSL_Heartbleed

Unquoted Service Path Found

Windows-based vulnerability for improperly formatted or unquoted file paths when defining the executable path; IE: C:\Program Files\My Service\service.exe

Vulnerabilities Found During External Scan

Vulnerabilities found during an external scan.

Vulnerabilities Found With EPSS Score > 95

Vulnerability is found where the EPSS score is equal to or above 95% exploitability.

Vulnerabilities Found With EPSS Between 0.95 & 0.90

Vulnerability is found where EPSS score is between 95% & 90% exploitability.

Vulnerabilities Found With EPSS Between 0.90 & 0.85

Vulnerability is found where EPSS score is between 90% & 85% exploitability

Vulnerabilities Found With EPSS Between 0.85 & 0

Vulnerability is found where EPSS score is between 85% & 0% exploitability

Registry Vulnerabilities Found

Vulnerability is found in the Windows Registry


Solutions

Event

Description

Event

Description

Application Baseline Plans Available

Application and/or Service listed in the application baseline is found; see your Application Baseline Results for details

Pending Remediation Found With Registry Vulnerability

Solutions found with a registry vulnerability that requires remediation

Pending Remediation Found with Critical Severity

Solutions found with a critical severity as found in the CVSS Base Score

Pending Remediation Found with High Severity

Solutions found with a high severity as found in the CVSS Base Score

Pending Remediation Found with Medium Severity

Solutions found with a medium severity as found in the CVSS Base Score

Pending Remediation Found with Low Severity

Solutions found with a low severity as found in the CVSS Base Score

Remediation Available

Solutions found with any severity in the CVSS Base Score, or no severity/informational

Remediation Found With EPSS between 0 and 0.85

Solution is found where the EPSS score is between 0 and 0.85

Remediation Found With EPSS between 0.85 and 0.9

Solution is found where the EPSS score is between 0.85 and 0.9

Remediation Found With EPSS between 0.9 and 0.95

Solution is found where the EPSS score is between 0.9 and 0.95

Remediation Found With EPSS >== 0.95

Solution is found where the EPSS score is equal to or above 0.95


Entra ID Audit

Event Description

Event ID (Source)

Audit Subcategory

Event Description

Event ID (Source)

Audit Subcategory

A member was added to a security-disabled universal group (AzureAD)

4761

Distribution Group Management

A member was added to a security-enabled universal group (AzureAD)

4756

Security Group Management

A member was removed from a security-disabled universal group (AzureAD)

4762

Distribution Group Management

A member was removed from a security-enabled universal group (AzureAD)

4757

Security Group Management


Entra ID Error

Event Description

Event Source / Link

Audit Subcategory

Event Description

Event Source / Link

Audit Subcategory

Entra ID Sync Failure

Troubleshoot Azure AD Connect sync errors

Directory Synchronization

Azure Token Expired Error

Microsoft identity platform access tokens

Authentication / Token Management


AD Audit

NOTE: These events set require the ‘Active AD Audit’ which is only supported from an agent installed on the domain controller. AD Audit will scan active directory every 15 minutes.

AD Audit Event Reference Table

Event Description

Event ID (Source)

Audit Subcategory

Event Description

Event ID (Source)

Audit Subcategory

A directory service object was created (Success)

5137

Directory Service Changes

A directory service object was deleted (Success)

5141

Directory Service Changes

A directory service object was moved (Success)

5139

Directory Service Changes

A group service object was modified (Success)

5136

Directory Service Changes

A logon was attempted using explicit credentials (Success)

4648

Logon/Logoff

A member was added to a security disabled global group

4754

Security Group Management

A member was added to a security disabled local group

4759

Security Group Management

A member was added to a security disabled universal group

4761

Security Group Management

A member was added to a security enabled global group

4728

Security Group Management

A member was added to a security enabled local group

4732

Security Group Management

A member was added to a security enabled universal group

4756

Security Group Management

A member was removed from a security disabled global group

4755

Security Group Management

A member was removed from a security disabled local group

4760

Security Group Management

A member was removed from a security disabled universal group

4762

Security Group Management

A member was removed from a security enabled global group

4729

Security Group Management

A member was removed from a security enabled local group

4733

Security Group Management

A member was removed from a security enabled universal group

4757

Security Group Management

A network share object was accessed

5140

Object Access

A request was made to authenticate to a wired network (Success/Failure)

4776

Logon/Logoff

A request was made to authenticate to a wireless network (Success/Failure)

4776

Logon/Logoff

A risky sign-in attempt made (Success)

Identity Protection Events

Identity Protection

A security disabled global group was created

4759

Security Group Management

A security disabled global group was deleted

4755

Security Group Management

A security disabled local group was created

4764

Security Group Management

A security disabled local group was deleted

4760

Security Group Management

A security disabled universal group was created

4763

Security Group Management

A security disabled universal group was deleted

4762

Security Group Management

A security enabled global group was created

4727

Security Group Management

A security enabled global group was deleted

4729

Security Group Management

A security enabled local group was created

4731

Security Group Management

A security enabled local group was deleted

4733

Security Group Management

A security enabled universal group was changed

4755

Security Group Management

A security enabled universal group was created

4756

Security Group Management

A security enabled universal group was deleted

4757

Security Group Management

A session was disconnected from a Windows Station (Success)

4779

Logon/Logoff

A session was reconnected to a Windows Station (Success)

4778

Logon/Logoff

A user Account was created

4720

Account Management

A user Account was deleted

4726

Account Management

A user Account was enabled

4722

Account Management

A user Account was disabled

4725

Account Management

A user Account was locked out

4740

Account Management

A user Account was unlocked

4767

Account Management

A user initiated logoff (Success)

4647

Logon/Logoff

An attempt was made to change an Account's password

4723

Account Management

An attempt was made to reset an Account's password

4724

Account Management

An attempt was made to create a hard link

4656

Object Access

Computer Account was created

4741

Account Management

Computer Account was deleted

4743

Account Management

Login Failure

4625

Logon/Logoff

Login Success

4624

Logon/Logoff

System security access was granted to an Account (Success)

4672

Privilege Use

The domain controller failed to validate the credentials for an Account

4776