The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

NSACryptEvents collector

Prev Next

NSACryptEvents collector retrieves Windows events log information from Microsoft-Windows-Audit-CVE provider.

Collector output

Field

Type

Description

id

Number

The process system identifier.

process_id

Number

ID given by operating system to the process.

thread_id

Number

The thread ID spawned by the process.

time_created

Timestamp

Time when the event was created.

message

String

CVE associated with the vulnerability for which this event is created.



Example: Show hostnames that reported a CVE exploitation attempt through Microsoft-Windows-Audit-CVE.
HostInfo hostname and NSACryptEvents where NSACryptEvents id not equals ""  

Strings in conditions and filters are case insensitive: "software" and "SOFTWARE" match the same registry entries.



Example: Show hostnames that reported a CVE exploitation attempt through Microsoft-Windows-Audit-CVE.
HostInfo hostname and NSACryptEvents where NSACryptEvents id not equals ""  

Strings in conditions and filters are case insensitive: "software" and "SOFTWARE" match the same registry entries.