Event Sets for Integration Alerting
In ConnectSecure, Event Sets are the predefined events that can trigger an alert using the supported integrations. Categories organize them and can be enabled with a simple checkbox.
Event Sets are hard-coded and can not be modified or removed from the system.
Event Sets work across most of the integrations where alerting is supported.
Event Set - Table of Contents
- 1 Event Set - Details
- 2 Events by Category
- 2.1 System Changes
- 2.2 Problems
- 2.3 Solutions
- 2.4 Entra ID Audit
- 2.5 Entra ID Error
- 2.6 AD Audit
- 2.7 AD Audit Event Reference Table
- 2.8 Job Failed
- 2.9 Certificate Expires in 30 Days
- 2.10 Company Contract Expire
- 2.11 Microsoft 365 Assessment
- 2.12 Google Workspace Assessment
- 2.13 Web Application Scanning
- 2.14 Attack Surface Discovery
- 3 Event Sets Group By Options
- 4 Event Sets Filter By Options
- 5 Need Support?
Event Set - Details
You will find the Event Set options listed under the integration details.
Not all supported ones are shown, so check your specific integration for the Event Set and Integration Rules options.
You will not see the Event Set options until you have provided the credentials for the selected integration.
Events by Category
Event Set categories include:
System Changes, Problems, Solutions, Entra ID Audit, Entra ID Error, AD Audit, Job Failed, Certificate Expire in 30 Days, Microsoft 365 Assessment, Google Workspace Assessment, and Web Application Scanning.
Below is a breakdown of each category and the available 'events' you can monitor for each.
System Changes
Event | Description |
|---|---|
New Asset Added | A new asset is added to the All Asset section; this can happen when agents are installed or assets are detected by probe scanning. |
Agent has Outdated Version | The agent version for a lightweight or probe agent is behind the current version release. |
New Company Created | A new company is created in the ConnectSecure portal, using local or PSA options. |
New Open Port Discovered (Probe Scan) | A new port is discovered on an internal asset during a probe scan; port discovery and scanning are only done by a Probe agent. |
New Open Port Discovered (External Scan) | A new open port is discovered during an external scan. |
Probe Went Down | The probe agent is offline and can not be reached |
Server Agent Went Down | Any agent (probe or lightweight) that is a ‘Server’ identified by its operating system is offline and can not be reached. |
Problems
Event | Description |
|---|---|
CISA Vulnerabilities Found | Vulnerabilities found that are published by CISA |
Critical Severity Vulnerabilities Found | Vulnerabilities found with a critical severity as found in the CVSS Base Score |
High Severity Vulnerabilities Found | Vulnerabilities found with a critical severity as found in the CVSS Base Score |
Low Severity Vulnerabilities Found | Vulnerabilities found with a low severity as found in the CVSS Base Score |
Medium Severity Vulnerabilities Found | Vulnerabilities found with a critical severity as found in the CVSS Base Score |
Remote Login Vulnerabilities Found | Problems related to remote login or remote access problems; IE: RDP-NTLM |
SMB Vulnerabilities Found | Problems related to the SMB protocol; IE: SMB_Signing |
SSL/TLS Vulnerabilities Found | Problems related to SSL/TLS certificates and ciphers; IE: TLSv1.1, Sweet32, SSL_Heartbleed |
Unquoted Service Path Found | Windows-based vulnerability for improperly formatted or unquoted file paths when defining the executable path; IE: C:\Program Files\My Service\service.exe |
Vulnerabilities Found During External Scan | Vulnerabilities found during an external scan. |
Vulnerabilities Found With EPSS Score > 95 | Vulnerability is found where the EPSS score is equal to or above 95% exploitability. |
Vulnerabilities Found With EPSS Between 0.95 & 0.90 | Vulnerability is found where EPSS score is between 95% & 90% exploitability. |
Vulnerabilities Found With EPSS Between 0.90 & 0.85 | Vulnerability is found where EPSS score is between 90% & 85% exploitability |
Vulnerabilities Found With EPSS Between 0.85 & 0 | Vulnerability is found where EPSS score is between 85% & 0% exploitability |
Registry Vulnerabilities Found | Vulnerability is found in the Windows Registry |
Solutions
Event | Description |
|---|---|
Application Baseline Plans Available | Application and/or Service listed in the application baseline is found; see your Application Baseline Results for details |
Pending Remediation Found With Registry Vulnerability | Solutions found with a registry vulnerability that requires remediation |
Pending Remediation Found with Critical Severity | Solutions found with a critical severity as found in the CVSS Base Score |
Pending Remediation Found with High Severity | Solutions found with a high severity as found in the CVSS Base Score |
Pending Remediation Found with Medium Severity | Solutions found with a medium severity as found in the CVSS Base Score |
Pending Remediation Found with Low Severity | Solutions found with a low severity as found in the CVSS Base Score |
Remediation Available | Solutions found with any severity in the CVSS Base Score, or no severity/informational |
Remediation Found With EPSS between 0 and 0.85 | Solution is found where the EPSS score is between 0 and 0.85 |
Remediation Found With EPSS between 0.85 and 0.9 | Solution is found where the EPSS score is between 0.85 and 0.9 |
Remediation Found With EPSS between 0.9 and 0.95 | Solution is found where the EPSS score is between 0.9 and 0.95 |
Remediation Found With EPSS >== 0.95 | Solution is found where the EPSS score is equal to or above 0.95 |
Entra ID Audit
Event Description | Event ID (Source) | Audit Subcategory |
|---|---|---|
A member was added to a security-disabled universal group (AzureAD) | Distribution Group Management | |
A member was added to a security-enabled universal group (AzureAD) | Security Group Management | |
A member was removed from a security-disabled universal group (AzureAD) | Distribution Group Management | |
A member was removed from a security-enabled universal group (AzureAD) | Security Group Management |
Entra ID Error
Event Description | Event Source / Link | Audit Subcategory |
|---|---|---|
Entra ID Sync Failure | Directory Synchronization | |
Azure Token Expired Error | Authentication / Token Management |
AD Audit
NOTE: These events set require the ‘Active AD Audit’ which is only supported from an agent installed on the domain controller. AD Audit will scan active directory every 15 minutes.
AD Audit Event Reference Table
Event Description | Event ID (Source) | Audit Subcategory |
|---|---|---|
A directory service object was created (Success) | Directory Service Changes | |
A directory service object was deleted (Success) | Directory Service Changes | |
A directory service object was moved (Success) | Directory Service Changes | |
A group service object was modified (Success) | Directory Service Changes | |
A logon was attempted using explicit credentials (Success) | Logon/Logoff | |
A member was added to a security disabled global group | Security Group Management | |
A member was added to a security disabled local group | Security Group Management | |
A member was added to a security disabled universal group | Security Group Management | |
A member was added to a security enabled global group | Security Group Management | |
A member was added to a security enabled local group | Security Group Management | |
A member was added to a security enabled universal group | Security Group Management | |
A member was removed from a security disabled global group | Security Group Management | |
A member was removed from a security disabled local group | Security Group Management | |
A member was removed from a security disabled universal group | Security Group Management | |
A member was removed from a security enabled global group | Security Group Management | |
A member was removed from a security enabled local group | Security Group Management | |
A member was removed from a security enabled universal group | Security Group Management | |
A network share object was accessed | Object Access | |
A request was made to authenticate to a wired network (Success/Failure) | Logon/Logoff | |
A request was made to authenticate to a wireless network (Success/Failure) | Logon/Logoff | |
A risky sign-in attempt made (Success) | Identity Protection | |
A security disabled global group was created | Security Group Management | |
A security disabled global group was deleted | Security Group Management | |
A security disabled local group was created | Security Group Management | |
A security disabled local group was deleted | Security Group Management | |
A security disabled universal group was created | Security Group Management | |
A security disabled universal group was deleted | Security Group Management | |
A security enabled global group was created | Security Group Management | |
A security enabled global group was deleted | Security Group Management | |
A security enabled local group was created | Security Group Management | |
A security enabled local group was deleted | Security Group Management | |
A security enabled universal group was changed | Security Group Management | |
A security enabled universal group was created | Security Group Management | |
A security enabled universal group was deleted | Security Group Management | |
A session was disconnected from a Windows Station (Success) | Logon/Logoff | |
A session was reconnected to a Windows Station (Success) | Logon/Logoff | |
A user Account was created | Account Management | |
A user Account was deleted | Account Management | |
A user Account was enabled | Account Management | |
A user Account was disabled | Account Management | |
A user Account was locked out | Account Management | |
A user Account was unlocked | Account Management | |
A user initiated logoff (Success) | Logon/Logoff | |
An attempt was made to change an Account's password | Account Management | |
An attempt was made to reset an Account's password | Account Management | |
An attempt was made to create a hard link | Object Access | |
Computer Account was created | Account Management | |
Computer Account was deleted | Account Management | |
Login Failure | Logon/Logoff | |
Login Success | Logon/Logoff | |
System security access was granted to an Account (Success) | Privilege Use | |
The domain controller failed to validate the credentials for an Account |