NERC

In <NERC> there are 10 report templates.

Screenshot

 

CIP 005-6 R1.3

  • Windows : Audit Policy Changed
  • Windows : Successful Post Authentication
  • Windows : Successful Pre Authentication
  • Windows : Trusted Domain Created
  • Windows : Trusted Domain Deleted
  • Windows : Trusted Domain Modified
  • Windows : Unsuccessful Post Authentication
  • Windows : Unsuccessful Pre Authentication
  • Windows : User Right Assigned
  • Windows : User Rights Removed

CIP 007-6 R1.1

  • Windows : Windows Firewall Group Policy Changes
  • Windows : Windows Firewall Rule Added
  • Windows : Windows Firewall Rule Deleted
  • Windows : Windows Firewall Rule Modified
  • Windows : Windows Firewall Setting Changed
  • Windows : Windows Firewall Setting Restored

CIP 007-6 R3.1

  • Windows : AD Backup Error
  • Windows : Audit Logs Cleared
  • Windows : Error in EventLog Service
  • Windows : Event log automatic backup
  • Windows : Exe or DLL File Allowed to Run
  • Windows : Exe or DLL File Not Allowed to Run
  • Windows : Exe or DLL Files Not Allowed to Run due to Enforced rules
  • Windows : Falied hotpatcing
  • Windows : Failed software installations
  • Windows : Failed software installations due to privilege mismatches
  • Windows : MSI Script File Allowed to Run
  • Windows : MSI Script Files Not Allowed to Run due to Enforced rules
  • Windows : New Service Installed
  • Windows : Service Failed
  • Windows : Service Started
  • Windows : Service Stopped
  • Windows : Software Installed
  • Windows : Software Restricted to Access Program
  • Windows : Software Uninstalled
  • Windows : Software Updated
  • Windows : Threat Detections by Mcafee
  • Windows : Threats Detection by Microsoft Antimalware
  • Windows : Threats Detection by Norton AntiVirus
  • Windows : Threats Detection by Sophos Anti-Virus
  • Windows : Threats Detections by ESET Endpoint Antivirus
  • Windows : Windows Startup and Windows Shutdown

CIP 007-6 R4.1

  • Windows : Failed Network Logons
  • Windows : Failed User Logons
  • Windows : Network Logoffs
  • Windows : Network Logon
  • Windows : Successful Post Authentication
  • Windows : Successful Pre Authentication
  • Windows : Terminal Server Disconnected
  • Windows : Terminal Server Rconnected
  • Windows : Unsuccessful Post Authentication
  • Windows : Unsuccessful Pre Authentication
  • Windows : User Logoff
  • Windows : User Logon

CIP 007-6 R4.2

  • Windows : Failed Network Logons
  • Windows : Failed User Logons
  • Windows : Network Logoffs
  • Windows : Network Logon
  • Windows : Successful Post Authentication
  • Windows : Successful Pre Authentication
  • Windows : Terminal Server Disconnected
  • Windows : Terminal Server Rconnected
  • Windows : Unsuccessful Post Authentication
  • Windows : Unsuccessful Pre Authentication
  • Windows : User Logoff
  • Windows : User Logon

CIP 007-6 R5.3

  • Windows : Audit Policy Changed
  • Windows : Successful Post Authentication
  • Windows : Successful Pre Authentication
  • Windows : Trusted Domain Created
  • Windows : Trusted Domain Deleted
  • Windows : Trusted Domain Modified
  • Windows : Unsuccessful Post Authentication
  • Windows : Unsuccessful Pre Authentication
  • Windows : User Right Assigned
  • Windows : User Rights Removed
  • Windows : Windows Individual User Action

CIP 007-6 R5.7

  • Windows : Failed Network Logons
  • Windows : Failed User Logons
  • Windows : Network Logoffs
  • Windows : Network Logon
  • Windows : Successful Post Authentication
  • Windows : Successful Pre Authentication
  • Windows : Terminal Server Disconnected
  • Windows : Terminal Server Rconnected
  • Windows : Unsuccessful Post Authentication
  • Windows : Unsuccessful Pre Authentication
  • Windows : User Logoff
  • Windows : User Logon

CIP 009-6 R1.3

  • Windows : Windows Firewall Group Policy Changes
  • Windows : Windows Firewall Rule Added
  • Windows : Windows Firewall Rule Deleted
  • Windows : Windows Firewall Rule Modified
  • Windows : Windows Firewall Setting Changed
  • Windows : Windows Firewall Setting Restored
  • Windows : Windows Individual User Action

CIP 009-6 R1.4

  • Windows : AD Backup Error
  • Windows : Audit Logs Cleared
  • Windows : Error in EventLog Service
  • Windows : Event log automatic backup
  • Windows : Failed Windows backup
  • Windows : Filed Windows restores
  • Windows : Falied hotpatcing
  • Windows : Failed software installations
  • Windows : Failed software installations due to privilege mismatches
  • Windows : New Service Installed
  • Windows : Service Failed
  • Windows : Service Started
  • Windows : Service Stopped
  • Windows : Software Installed
  • Windows : Software Uninstalled
  • Windows : Software Updated
  • Windows : Successful Windows restores
  • Windows : Successful windows backup
  • Windows : Windows Startup and Windows Shutdown

CIP 010-2 R1.1

  • Windows : AD Backup Error
  • Windows : Audit Logs Cleared
  • Windows : Error in EventLog Service
  • Windows : Event log automatic backup
  • Windows : Exe or DLL File Allowed to Run
  • Windows : Exe or DLL File Not Allowed to Run
  • Windows : Exe or DLL Files Not Allowed to Run due to Enforced rules
  • Windows : Falied hotpatcing
  • Windows : Failed software installations
  • Windows : Failed software installations due to privilege mismatches
  • Windows : MSI Script File Allowed to Run
  • Windows : MSI Script Files Not Allowed to Run due to Enforced rules
  • Windows : New Service Installed
  • Windows : Service Failed
  • Windows : Service Started
  • Windows : Service Stopped
  • Windows : Software Installed
  • Windows : Software Restricted to Access Program
  • Windows : Software Uninstalled
  • Windows : Software Updated
  • Windows : Windows Startup and Windows Shutdown