Audit Policy Table

๐Ÿ”’ Secure Bits ๐Ÿ’ก
๐——๐—ผ ๐˜†๐—ผ๐˜‚ ๐—ฟ๐—ฒ๐—ฎ๐—น๐—น๐˜† ๐—ธ๐—ป๐—ผ๐˜„ ๐˜„๐—ต๐—ฎ๐˜ ๐˜†๐—ผ๐˜‚๐—ฟ ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ & ๐—”๐—— ๐—ฎ๐˜‚๐—ฑ๐—ถ๐˜๐˜€?

Iโ€™ve seen so many environments where the answer is basicallyโ€ฆ โ€œ๐˜„๐—ต๐—ฎ๐˜๐—ฒ๐˜ƒ๐—ฒ๐—ฟ ๐˜๐—ต๐—ฒ ๐—ฑ๐—ฒ๐—ณ๐—ฎ๐˜‚๐—น๐˜ ๐—ถ๐˜€.โ€
Not great.

๐Ÿ‘‰ Thatโ€™s why Iโ€™ve created a simple, ๐—ฝ๐—ฟ๐—ฎ๐—ฐ๐˜๐—ถ๐—ฐ๐—ฎ๐—น ๐—˜๐˜…๐—ฐ๐—ฒ๐—น ๐—”๐˜‚๐—ฑ๐—ถ๐˜ ๐—ฃ๐—ผ๐—น๐—ถ๐—ฐ๐˜† ๐—ง๐—ฎ๐—ฏ๐—น๐—ฒ โ€” so you can:
โœ… Instantly find which audit category logs which events
โœ… Understand Success/Failure options per category
โœ… See Microsoftโ€™s configuration recommendations
โœ… Compare defaults across DCs, servers, and workstations
โœ… Avoid digging through Microsoft’s messy documentation

๐Ÿง  All audit subcategories + Event IDs + what they actually doโ€ฆ in one clean spreadsheet.

๐—ฃ๐—ฒ๐—ฟ๐—ณ๐—ฒ๐—ฐ๐˜ ๐—ถ๐—ณ ๐˜†๐—ผ๐˜‚’๐—ฟ๐—ฒ:
๐Ÿ”น Hardening your infrastructure
๐Ÿ”น Reviewing GPOs
๐Ÿ”น Building a logging baseline
๐Ÿ”น Or trying to figure out why the hell youโ€™re not seeing Event 4771

๐Ÿ’พ Itโ€™s available now in the ๐—™๐—ฟ๐—ฒ๐—ฒ ๐—ฅ๐—ฒ๐˜€๐—ผ๐˜‚๐—ฟ๐—ฐ๐—ฒ๐˜€ ๐˜€๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป ๐—ผ๐—ป ๐—บ๐˜† ๐—”๐—ฐ๐—ฎ๐—ฑ๐—ฒ๐—บ๐˜† ๐˜„๐—ฒ๐—ฏ๐˜€๐—ถ๐˜๐—ฒ.
https://academy.horizon-secured.com/p/windows-infrastructure-security-guides

One less headache next time you’re dealing with logging.