System32
Sysmon
Events
Compliance
Validator
TLS/SSL
GeoIP
Tools
Security Technical Implementation Guides (STIGs)
Product
Microsoft Windows 11
(2)
Microsoft Windows Server 2022
(2)
Microsoft Windows Server 2025
(2)
macOS 26 - Tahoe
(2)
Microsoft Windows 10
(1)
Microsoft Windows Server 2016
(1)
Microsoft Windows Server 2019
(1)
Severity
Medium
(11)
SRG
SRG-OS-000021-GPOS-00005
(11)
CCIs
CCI-000044
(11)
STIG IDs
APPL-26-000022
(1)
APPL-26-000060
(1)
WN10-AC-000010
(1)
WN11-AC-000010
(1)
WN11-AC-000015
(1)
WN16-AC-000020
(1)
WN19-AC-000020
(1)
WN22-AC-000020
(1)
WN22-AC-000030
(1)
WN25-AC-000020
(1)
WN25-AC-000030
(1)
Rule IDs
SV-205629r958388_rule
(1)
SV-220740r958388_rule
(1)
SV-253298r958388_rule
(1)
SV-253299r958388_rule
(1)
SV-254286r958388_rule
(1)
SV-254287r958388_rule
(1)
SV-277036r1149407_rule
(1)
SV-277048r1149408_rule
(1)
SV-278034r1180808_rule
(1)
SV-278035r1180811_rule
(1)
Tags
AppLocker
All AppLocker events
EventSentry
All EventSentry events
Security
All Windows Security events
stig
All stig events
Vulnerability ID
Severity
Description
V-254287
Medium
Windows Server 2022 must have the period of time before the bad logon counter is reset configured...
V-253299
Medium
The period of time before the bad logon counter is reset must be configured to 15 minutes
V-254286
Medium
Windows Server 2022 must have the number of allowed bad logon attempts configured to three or less
V-205629
Medium
Windows Server 2019 must have the number of allowed bad logon attempts configured to three or less
V-253298
Medium
The number of allowed bad logon attempts must be configured to three or less
V-220740
Medium
The number of allowed bad logon attempts must be configured to 3 or less
V-224867
Medium
Windows Server 2016 must have the number of allowed bad logon attempts configured to three or less
V-278034
Medium
Windows Server 2025 must have the number of allowed bad logon attempts configured to three or less
V-278035
Medium
Windows Server 2025 must have the period of time before the bad logon counter is reset configured...
V-277036
Medium
The macOS system must limit consecutive failed login attempts to three
V-277048
Medium
The macOS system must set account lockout time to 15 minutes