System32
Sysmon
Events
Compliance
Validator
TLS/SSL
GeoIP
Tools
EventSentry Events
Source
EventSentry
(6)
Category
Software Monitoring
(6)
Tags
AppLocker
All AppLocker events
EventSentry
All EventSentry events
Security
All Windows Security events
Sysmon
All Sysmon events
ID
Event Message
12000
Application %1 (%2) was installed. Additional Information: Publisher: %3 Installation Directory: %4 Version: %5 Platform: %7 User: %8 Currently logged on user(s): %6
12001
Application %1 (%2) was uninstalled. Additional Information: Publisher: %3 Installation Directory: %4 Version: %5 Platform: %7 User: %8 Currently logged on user(s): %6
12002
Application %1 registered itself in the registry key HKLM\%2 and will be automatically run when a user logs into the system. Currently logged on user(s): %3
12020
The %1 browser extension "%2" was added to user %4: Web Browser: %1 Name: %2 Version: %3 User: %4 Enabled: %5
12021
The %1 browser extension "%2" was modified for user %4: Web Browser: %1 Name: %2 Version: %3 User: %4 Enabled: %5 Field Changed: %6 ("%7" -> "%8")
12022
The %1 browser extension "%2" was removed from user %4: Web Browser: %1 Name: %2 Version: %3 User: %4 Enabled: %5