Forum Discussion

Warren212's avatar
Warren212
Copper Contributor
Jun 12, 2026

Microsoft Defender for Endpoint and WDAC audit logs not include kernel audit/blocks

While testing WDAC on a fully patched Win11 pro machine - I noticed that kernel audit/block events do not get collected by MDE in the advanced hunting portal, only user mode audit/blocks are collecte...