Windows Software And Service Installation

As part of normal network operations, new software and services will be installed, and there is value in monitoring this activity. Administrators can review these logs for newly installed software or system services and verify that they do not pose a risk to the network. It should be noted that an additional Program Inventory event ID 800 is generated daily on Windows 7 at 12:30 AM to provide a summary of application activities (e.g., number of new application installations). Event ID 800 is generated on Windows 8 as well under different circumstances. This event is beneficial to administrators seeking to identify the number of applications that were installed or removed on a machine.
AIS Managed SIEM

SIEM Events

New Windows Service
Service Start Failure
New MSI File Installed
New Application Installation
Updated Application
Removed Application
Windows Update Installed

Last modified September 14, 2021