What auditing messages can I expect on a client (target) machine from an MBSA scan?
In addition to the current audit message written to the event log, additional events may be written based on the new remote installer used by MBSA to configure the target computer to use Windows Update Agent or Microsoft Update for scanning. An example of an event: Event Type:Information Event Source:MBSA Event Category:None Event ID:1 Date:3/12/2005 Time:1:33:44 PM User:domain\username Computer:computer Description: Security analysis complete. Scanned from nnn.nnn.n.n. Microsoft Baseline Security Analyzer version 2.1.nnnn.0. For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.