| | | | |
|
| | CPUID Properties:
|
| | | CPUID Manufacturer | GenuineIntel
|
| | | CPUID CPU Name | Intel(R) Core(TM) Ultra 5 225T
|
| | | CPUID Revision | 000C0662h
|
| | | IA Brand ID | 00h (Unknown)
|
| | | Platform ID | 0061h / MC 02h (LGA1851)
|
| | | Microcode Update Revision | 121h
|
| | | SMT / CMP Units | 0 / 10
|
| | | Tjmax Temperature | 105 °C (221 °F)
|
| | | CPU Thermal Design Power (TDP) | 35 W
|
| | | CPU Thermal Design Current (TDC) | 79 A
|
| | | CPU Max Power Limit | Unlimited Power / 256.00 sec
|
| | | CPU Power Limit 1 (Long Duration) | 35 W / 28.00 sec (Unlocked)
|
| | | CPU Power Limit 2 (Short Duration) | 74 W / 2.44 ms (Unlocked)
|
| | | Max Turbo Boost Multipliers (P-cores) | 1C: 49x, 2C: 49x, 3C: 47x, 4C: 47x, 5C: 47x, 6C: 47x, 7C: 47x, 8C: 47x
|
| | | Max Turbo Boost Multipliers (E-cores) | 1c: 44x, 2c: 44x, 3c: 44x, 4c: 44x, 5c: 44x, 6c: 44x, 7c: 44x, 8c: 44x
|
|
|
| | Instruction Set:
|
| | | 64-bit x86 Extension (x86-64) (AMD64, Intel64) | Supported
|
| | | AES Extensions | Supported
|
| | | AMD 3DNow! | Not Supported
|
| | | AMD 3DNow! Professional | Not Supported
|
| | | AMD 3DNowPrefetch | Supported
|
| | | AMD Enhanced 3DNow! | Not Supported
|
| | | AMD Extended MMX | Not Supported
|
| | | AMD FMA4 | Not Supported
|
| | | AMD MisAligned SSE | Not Supported
|
| | | AMD SSE4A | Not Supported
|
| | | AMD XOP | Not Supported
|
| | | AMX-BF16 | Not Supported
|
| | | AMX-COMPLEX | Not Supported
|
| | | AMX-FP16 | Not Supported
|
| | | AMX-INT8 | Not Supported
|
| | | AMX Tile Architecture (AMX-TILE) | Not Supported
|
| | | APX (APX_F) | Not Supported
|
| | | APX Flags Supression (NF) | Not Supported
|
| | | APX New Conditional Instructions (NCI) | Not Supported
|
| | | APX New Data Destination (NDD) | Not Supported
|
| | | AVX | Supported, Enabled
|
| | | AVX2 | Supported, Enabled
|
| | | AVX10.1 | Not Supported
|
| | | AVX10.2 | Not Supported
|
| | | AVX10-VNNI-INT | Not Supported
|
| | | AVX-512 (AVX512F) | Not Supported
|
| | | AVX-512 4x Fused Multiply-Add Single Precision (AVX512_4FMAPS) | Not Supported
|
| | | AVX-512 4x Neural Network Instructions (AVX512_4VNNIW) | Not Supported
|
| | | AVX-512 52-bit Integer Multiply-Add Instructions (AVX512_IFMA) | Not Supported
|
| | | AVX-512 BF16 (AVX512_BF16) | Not Supported
|
| | | AVX-512 Bit Algorithm (AVX512_BITALG) | Not Supported
|
| | | AVX-512 Bit Matrix Multiply Instructions (AVX512_BMM) | Not Supported
|
| | | AVX-512 Byte and Word Instructions (AVX512BW) | Not Supported
|
| | | AVX-512 Conflict Detection Instructions (AVX512CD) | Not Supported
|
| | | AVX-512 Doubleword and Quadword Instructions (AVX512DQ) | Not Supported
|
| | | AVX-512 Exponential and Reciprocal Instructions (AVX512ER) | Not Supported
|
| | | AVX-512 FP16 (AVX512_FP16) | Not Supported
|
| | | AVX-512 Intersection (AVX512_VP2INTERSECT) | Not Supported
|
| | | AVX-512 Neural Network Instructions (AVX512_VNNI) | Not Supported
|
| | | AVX-512 Prefetch Instructions (AVX512PF) | Not Supported
|
| | | AVX-512 Vector Bit Manipulation Instructions (AVX512_VBMI) | Not Supported
|
| | | AVX-512 Vector Bit Manipulation Instructions 2 (AVX512_VBMI2) | Not Supported
|
| | | AVX-512 Vector Length Extensions (AVX512VL) | Not Supported
|
| | | AVX-512 VPOPCNTDQ | Not Supported
|
| | | AVX Vector Neural Network Instructions (AVX-VNNI) | Supported, Enabled
|
| | | AVX-IFMA | Supported, Enabled
|
| | | AVX-NE-CONVERT | Supported, Enabled
|
| | | AVX-VNNI-INT8 | Supported, Enabled
|
| | | BMI1 | Supported
|
| | | BMI2 | Supported
|
| | | Cyrix Extended MMX | Not Supported
|
| | | Enhanced REP MOVSB/STOSB | Supported
|
| | | Enqueue Stores | Not Supported
|
| | | Float-16 Conversion Instructions | Supported, Enabled
|
| | | FMA | Supported, Enabled
|
| | | Galois Field New Instructions (GFNI) | Supported
|
| | | IA-64 | Not Supported
|
| | | MMX | Supported
|
| | | SHA Extensions | Supported
|
| | | SHA512 | Supported
|
| | | SM2 | Not Supported
|
| | | SSE | Supported
|
| | | SSE2 | Supported
|
| | | SSE3 | Supported
|
| | | Supplemental SSE3 | Supported
|
| | | SSE4.1 | Supported
|
| | | SSE4.2 | Supported
|
| | | SM3 | Supported
|
| | | SM4 | Supported
|
| | | Vector AES (VAES) | Supported, Enabled
|
| | | Vector-Extension Packed Matrix Multiplication (VPMM) | Not Supported
|
| | | VIA Alternate Instruction Set | Not Supported
|
| | | ADCX / ADOX Instruction | Supported
|
| | | CLDEMOTE Instruction | Not Supported
|
| | | CLFLUSH Instruction | Supported
|
| | | CLFLUSHOPT Instruction | Supported
|
| | | CLWB Instruction | Supported
|
| | | CLZERO Instruction | Not Supported
|
| | | CMPccXADD Instruction | Supported
|
| | | CMPXCHG8B Instruction | Supported
|
| | | CMPXCHG16B Instruction | Supported
|
| | | Conditional Move Instruction | Supported
|
| | | Fast Short CMPSB & SCASB Instruction | Not Supported
|
| | | Fast Short REP MOV Instruction | Supported
|
| | | Fast Short REP STOSB (FSRS) Instruction | Not Supported
|
| | | Fast Short REPE CMPSB (FSRC) Instruction | Not Supported
|
| | | Fast Short STOSB Instruction | Supported
|
| | | Fast Zero-Length MOVSB Instruction | Not Supported
|
| | | HRESET Instruction | Supported
|
| | | INVLPGB Instruction | Not Supported
|
| | | INVPCID Instruction | Supported
|
| | | LAHF / SAHF Instruction | Supported
|
| | | LZCNT Instruction | Supported
|
| | | MCOMMIT Instruction | Not Supported
|
| | | MONITOR / MWAIT Instruction | Supported
|
| | | MONITORX / MWAITX Instruction | Not Supported
|
| | | MOVBE Instruction | Supported
|
| | | MOVDIR64B Instruction | Supported
|
| | | MOVDIRI Instruction | Supported
|
| | | PCLMULQDQ Instruction | Supported
|
| | | PCOMMIT Instruction | Not Supported
|
| | | PCONFIG Instruction | Not Supported
|
| | | POPCNT Instruction | Supported
|
| | | PREFETCHIT0 / PREFETCHIT1 Instruction | Not Supported
|
| | | PREFETCHWT1 Instruction | Not Supported
|
| | | PTWRITE Instruction | Not Supported
|
| | | RAO-INT Instruction | Not Supported
|
| | | RDFSBASE / RDGSBASE / WRFSBASE / WRGSBASE Instruction | Supported
|
| | | RDMSRLIST / WRMSRLIST Instruction | Not Supported
|
| | | RDPRU Instruction | Not Supported
|
| | | RDRAND Instruction | Supported
|
| | | RDSEED Instruction | Supported
|
| | | RDTSCP Instruction | Supported
|
| | | SKINIT / STGI Instruction | Not Supported
|
| | | SYSCALL / SYSRET Instruction | Supported
|
| | | SYSENTER / SYSEXIT Instruction | Supported
|
| | | Trailing Bit Manipulation Instructions | Not Supported
|
| | | VIA FEMMS Instruction | Not Supported
|
| | | VPCLMULQDQ Instruction | Supported
|
| | | WBNOINVD Instruction | Supported
|
| | | WRMSRNS Instruction | Not Supported
|
|
|
| | Security Features:
|
| | | Advanced Cryptography Engine (ACE) | Not Supported
|
| | | Advanced Cryptography Engine 2 (ACE2) | Not Supported
|
| | | Control-flow Enforcement Technology - Indirect Branch Tracking (CET_IBT) | Supported
|
| | | Control-flow Enforcement Technology - Shadow Stack (CET_SS) | Supported
|
| | | Control-flow Enforcement Technology - Supervisor Shadow Stack (CET_SSS) | Supported
|
| | | Data Execution Prevention (DEP, NX, EDB) | Supported
|
| | | Enhanced Indirect Branch Restricted Speculation | Supported
|
| | | Enhanced Predictive Store Forwarding (EPSF) | Not Supported
|
| | | FRED Transitions | Not Supported
|
| | | Hardware Random Number Generator (RNG) | Not Supported
|
| | | Hardware Random Number Generator 2 (RNG2) | Not Supported
|
| | | Indirect Branch Predictor Barrier (IBPB) | Supported
|
| | | Indirect Branch Restricted Speculation (IBRS) | Supported
|
| | | Key Locker | Not Supported
|
| | | L1D Flush | Supported
|
| | | Linear Address Masking (LAM) | Supported
|
| | | Linear Address Space Separation (LASS) | Supported
|
| | | LKGS | Not Supported
|
| | | MD_CLEAR | Supported
|
| | | Memory Protection Extensions (MPX) | Not Supported
|
| | | PadLock Hash Engine (PHE) | Not Supported
|
| | | PadLock Hash Engine 2 (PHE2) | Not Supported
|
| | | PadLock Montgomery Multiplier (PMM) | Not Supported
|
| | | PadLock Montgomery Multiplier 2 (PMM2) | Not Supported
|
| | | Processor Serial Number (PSN) | Not Supported
|
| | | Protection Keys for Supervisor-Mode Pages (PKS) | Supported, Disabled
|
| | | Protection Keys for User-Mode Pages (PKU) | Supported, Disabled
|
| | | Read Processor ID (RDPID) | Supported
|
| | | Rogue Data Cache Load (RDCL) | Not Susceptible
|
| | | Safer Mode Extensions (SMX) | Supported
|
| | | Secure Memory Encryption (SME) | Not Supported
|
| | | SGX Attestation Services (SGX-KEYS) | Not Supported
|
| | | SGX Launch Configuration (SGX_LC) | Not Supported
|
| | | Software Guard Extensions (SGX) | Not Supported
|
| | | Single Thread Indirect Branch Predictors (STIBP) | Supported
|
| | | Speculative Store Bypass Disable (SSBD) | Supported
|
| | | SRBDS_CTRL | Not Supported
|
| | | Static Lockstep Mode (SLSM) | Not Supported
|
| | | Supervisor Mode Access Prevention (SMAP) | Supported
|
| | | Supervisor Mode Execution Protection (SMEP) | Supported
|
| | | Total Memory Encryption (TME) | Not Supported
|
| | | Total Storage Encryption (TSE) | Not Supported
|
| | | User-Mode Instruction Prevention (UMIP) | Supported
|
|
|
| | Power Management Features:
|
| | | APM Power Reporting | Not Supported
|
| | | Application Power Management (APM) | Not Supported
|
| | | Automatic Clock Control | Supported
|
| | | Configurable TDP (cTDP) | Not Supported
|
| | | Connected Standby | Not Supported
|
| | | Core C6 State (CC6) | Not Supported
|
| | | Digital Thermometer | Supported
|
| | | Dynamic FSB Frequency Switching | Not Supported
|
| | | Enhanced Halt State (C1E) | Supported, Enabled
|
| | | Enhanced SpeedStep Technology (EIST, ESS) | Supported, Enabled
|
| | | Frequency ID Control | Not Supported
|
| | | Hardware P-State Control | Not Supported
|
| | | Hardware Thermal Control (HTC) | Not Supported
|
| | | LongRun | Not Supported
|
| | | LongRun Table Interface | Not Supported
|
| | | Overstress | Not Supported
|
| | | Package C6 State (PC6) | Not Supported
|
| | | Parallax | Not Supported
|
| | | PowerSaver 1.0 | Not Supported
|
| | | PowerSaver 2.0 | Not Supported
|
| | | PowerSaver 3.0 | Not Supported
|
| | | Processor Duty Cycle Control | Supported
|
| | | Running Average Power Limit (RAPL) | Not Supported
|
| | | Software Thermal Control | Not Supported
|
| | | SpeedShift (SST, HWP) | Supported, Enabled (Autonomous Mode)
|
| | | Temperature Sensing Diode | Not Supported
|
| | | Thermal Monitor 1 | Supported
|
| | | Thermal Monitor 2 | Supported
|
| | | Thermal Monitor 3 | Not Supported
|
| | | Thermal Monitoring | Not Supported
|
| | | Thermal Trip | Not Supported
|
| | | Voltage ID Control | Not Supported
|
|
|
| | Virtualization Features:
|
| | | AMD Virtual Interrupt Controller (AVIC) | Not Supported
|
| | | Decode Assists | Not Supported
|
| | | Encrypted Microcode Patch | Not Supported
|
| | | Encrypted State (SEV-ES) | Not Supported
|
| | | Extended Page Table (EPT) | Supported
|
| | | Flush by ASID | Not Supported
|
| | | Guest Mode Execute Trap Extension (GMET) | Not Supported
|
| | | Hypervisor | Not Present
|
| | | INVEPT Instruction | Supported
|
| | | INVVPID Instruction | Supported
|
| | | LBR Virtualization | Not Supported
|
| | | Memory Bandwidth Enforcement (MBE) | Not Supported
|
| | | Nested Paging (NPT, RVI) | Not Supported
|
| | | NRIP Save (NRIPS) | Not Supported
|
| | | PAUSE Filter Threshold | Not Supported
|
| | | PAUSE Intercept Filter | Not Supported
|
| | | Secure AVIC | Not Supported
|
| | | Secure Encrypted Virtualization (SEV) | Not Supported
|
| | | Secure Virtual Machine (SVM, Pacifica) | Not Supported
|
| | | SVM Lock (SVML) | Not Supported
|
| | | Virtual Transparent Encryption (VTE) | Not Supported
|
| | | Virtualized GIF (vGIF) | Not Supported
|
| | | Virtualized VMLOAD and VMSAVE | Not Supported
|
| | | Virtualized X2APIC (X2AVIC) | Not Supported
|
| | | Virtual Machine Extensions (VMX, Vanderpool) | Supported
|
| | | Virtual Processor ID (VPID) | Supported
|
| | | VMCB Clean Bits | Not Supported
|
|
|
| | CPUID Features:
|
| | | 1 GB Page Size | Supported
|
| | | 36-bit Page Size Extension | Supported
|
| | | 5-Level Paging | Not Supported
|
| | | 64-bit DS Area | Supported
|
| | | 64-bit SIPI | Not Supported
|
| | | Adaptive Overclocking | Not Supported
|
| | | Address Region Registers (ARR) | Not Supported
|
| | | Asymmetrical RDT Allocation | Not Supported
|
| | | Asymmetrical RDT Monitoring | Not Supported
|
| | | Resource Director Technology Monitoring (RDT-M) | Not Supported
|
| | | Code and Data Prioritization Technology (CDP) | Not Supported
|
| | | Core Performance Boost (CPB) | Not Supported
|
| | | Core Performance Counters | Not Supported
|
| | | CPL Qualified Debug Store | Supported
|
| | | Data Breakpoint Extension | Not Supported
|
| | | Debug Trace Store | Supported
|
| | | Debugging Extension | Supported
|
| | | Deprecated FPU CS and FPU DS | Supported
|
| | | Direct Cache Access | Not Supported
|
| | | Dynamic Acceleration Technology (IDA) | Not Supported
|
| | | Dynamic Configurable TDP (DcTDP) | Not Supported
|
| | | Enhanced Hardware Feedback Interface (EHFI) | Supported
|
| | | Extended APIC Register Space | Not Supported
|
| | | Fast Save & Restore | Supported
|
| | | FP512 Downgrade | Not Supported
|
| | | Hardware Feedback Interface (HFI) | Supported
|
| | | Hardware Lock Elision (HLE) | Not Supported
|
| | | Hybrid Boost | Not Supported
|
| | | Hybrid CPU | Supported
|
| | | Hyper-Threading Technology (HTT) | Not Supported
|
| | | Instruction Based Sampling | Not Supported
|
| | | Invariant Time Stamp Counter | Supported
|
| | | L1 Context ID | Not Supported
|
| | | L2I Performance Counters | Not Supported
|
| | | Lightweight Profiling | Not Supported
|
| | | Local APIC On Chip | Supported
|
| | | Machine Check Architecture (MCA) | Supported
|
| | | Machine Check Exception (MCE) | Supported
|
| | | Memory Configuration Registers (MCR) | Not Supported
|
| | | Memory Protection Range Registers (MPRR) | Not Supported
|
| | | Memory Type Range Registers (MTRR) | Supported
|
| | | Model Specific Registers (MSR) | Supported
|
| | | NB Performance Counters | Not Supported
|
| | | Page Attribute Table (PAT) | Supported
|
| | | Page Global Extension | Supported
|
| | | Page Size Extension (PSE) | Supported
|
| | | Pending Break Event (PBE) | Supported
|
| | | Performance Time Stamp Counter (PTSC) | Not Supported
|
| | | Physical Address Extension (PAE) | Supported
|
| | | Process Context Identifiers (PCID) | Supported
|
| | | Processor Feedback Interface | Not Supported
|
| | | Processor Trace (PT) | Supported
|
| | | Processor Trace Trigger Tracing (PTTT) | Not Supported
|
| | | Resource Director Technology Allocation (RDT-A) | Supported
|
| | | Resource Director Technology Monitoring (RDT-M) | Not Supported
|
| | | Restricted Transactional Memory (RTM) | Not Supported
|
| | | Self-Snoop | Supported
|
| | | Time Stamp Counter (TSC) | Supported
|
| | | Time Stamp Counter Adjust | Supported
|
| | | TSX Suspend Load Address Tracking | Not Supported
|
| | | Turbo Boost | Supported, Enabled
|
| | | Turbo Boost Max 3.0 | Not Supported
|
| | | Upper Address Ignore (UAI) | Not Supported
|
| | | Upper Address Ignore (UAI) V2 | Not Supported
|
| | | User Interrupts (UINTR) | Supported
|
| | | Virtual Mode Extension | Supported
|
| | | Watchdog Timer | Not Supported
|
| | | x2APIC | Supported, Enabled
|
| | | X86S | Not Supported
|
| | | XGETBV / XSETBV OS Enabled | Supported
|
| | | XSAVE / XRSTOR / XSETBV / XGETBV Extended States | Supported
|
| | | XSAVEOPT | Supported
|
|
|
| | CPUID Registers (CPU #0):
|
| | | CPUID 00000000 | 00000023-756E6547-6C65746E-49656E69 [GenuineIntel]
|
| | | CPUID 00000001 | 000C0662-00800800-7FFAFBFF-BFEBFBFF
|
| | | CPUID 00000002 | 00FEFF01-000000F0-00000000-00000000
|
| | | CPUID 00000003 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000004 | FC004121-02C0003F-0000003F-00000000 [SL 00]
|
| | | CPUID 00000004 | FC004122-03C0003F-0000003F-00000000 [SL 01]
|
| | | CPUID 00000004 | FC01C143-02C0003F-00000FFF-00000000 [SL 02]
|
| | | CPUID 00000004 | FC1FC163-0240003F-00007FFF-00000004 [SL 03]
|
| | | CPUID 00000005 | 00000040-00000040-00000003-10102020
|
| | | CPUID 00000006 | 00DF8FF7-00000002-00000409-00000003
|
| | | CPUID 00000007 | 00000002-239CA7EB-994007AC-FC18C430 [SL 00]
|
| | | CPUID 00000007 | 44C009D7-00000001-00000000-00040430 [SL 01]
|
| | | CPUID 00000007 | 00000000-00000000-00000000-000000BF [SL 02]
|
| | | CPUID 00000008 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000009 | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000000A | 0D300806-00000280-00000007-00008603
|
| | | CPUID 0000000B | 00000001-00000001-00000100-00000000 [SL 00]
|
| | | CPUID 0000000B | 00000007-0000000A-00000201-00000000 [SL 01]
|
| | | CPUID 0000000C | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000000D | 00000207-00000340-00000A88-00000000 [SL 00]
|
| | | CPUID 0000000D | 0000000F-000003D0-0001D900-00000000 [SL 01]
|
| | | CPUID 0000000D | 00000100-00000240-00000000-00000000 [SL 02]
|
| | | CPUID 0000000D | 00000080-00000000-00000001-00000000 [SL 08]
|
| | | CPUID 0000000D | 00000008-00000A80-00000000-00000000 [SL 09]
|
| | | CPUID 0000000D | 00000010-00000000-00000001-00000000 [SL 0B]
|
| | | CPUID 0000000D | 00000018-00000000-00000001-00000000 [SL 0C]
|
| | | CPUID 0000000D | 00000030-00000000-00000001-00000000 [SL 0E]
|
| | | CPUID 0000000D | 00000328-00000000-00000001-00000000 [SL 0F]
|
| | | CPUID 0000000D | 00000008-00000000-00000001-00000000 [SL 10]
|
| | | CPUID 0000000E | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000000F | 00000000-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 0000000F | 00000000-00000000-00000000-00000000 [SL 01]
|
| | | CPUID 00000010 | 00000000-00000040-00000000-00000000 [SL 00]
|
| | | CPUID 00000010 | 00000000-00000000-00000000-00000000 [SL 01]
|
| | | CPUID 00000011 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000012 | 00000000-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 00000012 | 00000000-00000000-00000000-00000000 [SL 01]
|
| | | CPUID 00000013 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000014 | 00000001-0000015F-00000007-00000000 [SL 00]
|
| | | CPUID 00000014 | 02490002-003F003F-00000000-00000000 [SL 01]
|
| | | CPUID 00000015 | 00000002-00000082-0249F000-00000000 [65.00x / 38400000 / 2496.00]
|
| | | CPUID 00000016 | 000009C4-00001324-00000064-00000000 [2500 / 4900 / 100]
|
| | | CPUID 00000017 | 00000000-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 00000018 | 00000008-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 00000018 | 00000000-00080001-00000020-00004022 [SL 01]
|
| | | CPUID 00000018 | 00000000-00080006-00000004-00004022 [SL 02]
|
| | | CPUID 00000018 | 00000000-0010000F-00000001-00004125 [SL 03]
|
| | | CPUID 00000018 | 00000000-00080001-00000010-00004024 [SL 04]
|
| | | CPUID 00000018 | 00000000-00040006-00000008-00004024 [SL 05]
|
| | | CPUID 00000018 | 00000000-00080008-00000001-00004124 [SL 06]
|
| | | CPUID 00000018 | 00000000-00080007-00000080-00004043 [SL 07]
|
| | | CPUID 00000018 | 00000000-00080009-00000080-00004043 [SL 08]
|
| | | CPUID 00000019 | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001A | 40000003-00000000-00000000-00000000 [Core: Lion Cove]
|
| | | CPUID 0000001B | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001C | 4000000B-00000007-000F0007-00000000
|
| | | CPUID 0000001D | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001E | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001F | 00000001-00000001-00000100-00000000 [SL 00]
|
| | | CPUID 0000001F | 00000003-00000001-00000201-00000000 [SL 01]
|
| | | CPUID 0000001F | 00000007-0000000A-00000302-00000000 [SL 02]
|
| | | CPUID 00000020 | 00000000-00000001-00000000-00000000
|
| | | CPUID 00000021 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000022 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000023 | 0000000B-00000003-00000000-00000000
|
| | | CPUID 80000000 | 80000008-00000000-00000000-00000000
|
| | | CPUID 80000001 | 00000000-00000000-00000121-2C100800
|
| | | CPUID 80000002 | 65746E49-2952286C-726F4320-4D542865 [Intel(R) Core(TM]
|
| | | CPUID 80000003 | 6C552029-20617274-32322035-00005435 [) Ultra 5 225T]
|
| | | CPUID 80000004 | 00000000-00000000-00000000-00000000 []
|
| | | CPUID 80000005 | 00000000-00000000-00000000-00000000
|
| | | CPUID 80000006 | 00000000-00000000-0C007040-00000000
|
| | | CPUID 80000007 | 00000000-00000000-00000000-00000100
|
| | | CPUID 80000008 | 0000302A-00000200-00000000-00000000
|
|
|
| | CPUID Registers (CPU #1):
|
| | | CPUID 00000000 | 00000023-756E6547-6C65746E-49656E69 [GenuineIntel]
|
| | | CPUID 00000001 | 000C0662-08800800-7FFAFBFF-BFEBFBFF
|
| | | CPUID 00000002 | 00FEFF01-000000F0-00000000-00000000
|
| | | CPUID 00000003 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000004 | FC004121-02C0003F-0000003F-00000000 [SL 00]
|
| | | CPUID 00000004 | FC004122-03C0003F-0000003F-00000000 [SL 01]
|
| | | CPUID 00000004 | FC01C143-02C0003F-00000FFF-00000000 [SL 02]
|
| | | CPUID 00000004 | FC1FC163-0240003F-00007FFF-00000004 [SL 03]
|
| | | CPUID 00000005 | 00000040-00000040-00000003-10102020
|
| | | CPUID 00000006 | 00DF8FF7-00000002-00000409-00010003
|
| | | CPUID 00000007 | 00000002-239CA7EB-994007AC-FC18C430 [SL 00]
|
| | | CPUID 00000007 | 44C009D7-00000001-00000000-00040430 [SL 01]
|
| | | CPUID 00000007 | 00000000-00000000-00000000-000000BF [SL 02]
|
| | | CPUID 00000008 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000009 | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000000A | 0D300806-00000280-00000007-00008603
|
| | | CPUID 0000000B | 00000001-00000001-00000100-00000008 [SL 00]
|
| | | CPUID 0000000B | 00000007-0000000A-00000201-00000008 [SL 01]
|
| | | CPUID 0000000C | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000000D | 00000207-00000340-00000A88-00000000 [SL 00]
|
| | | CPUID 0000000D | 0000000F-000003D0-0001D900-00000000 [SL 01]
|
| | | CPUID 0000000D | 00000100-00000240-00000000-00000000 [SL 02]
|
| | | CPUID 0000000D | 00000080-00000000-00000001-00000000 [SL 08]
|
| | | CPUID 0000000D | 00000008-00000A80-00000000-00000000 [SL 09]
|
| | | CPUID 0000000D | 00000010-00000000-00000001-00000000 [SL 0B]
|
| | | CPUID 0000000D | 00000018-00000000-00000001-00000000 [SL 0C]
|
| | | CPUID 0000000D | 00000030-00000000-00000001-00000000 [SL 0E]
|
| | | CPUID 0000000D | 00000328-00000000-00000001-00000000 [SL 0F]
|
| | | CPUID 0000000D | 00000008-00000000-00000001-00000000 [SL 10]
|
| | | CPUID 0000000E | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000000F | 00000000-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 0000000F | 00000000-00000000-00000000-00000000 [SL 01]
|
| | | CPUID 00000010 | 00000000-00000040-00000000-00000000 [SL 00]
|
| | | CPUID 00000010 | 00000000-00000000-00000000-00000000 [SL 01]
|
| | | CPUID 00000011 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000012 | 00000000-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 00000012 | 00000000-00000000-00000000-00000000 [SL 01]
|
| | | CPUID 00000013 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000014 | 00000001-0000015F-00000007-00000000 [SL 00]
|
| | | CPUID 00000014 | 02490002-003F003F-00000000-00000000 [SL 01]
|
| | | CPUID 00000015 | 00000002-00000082-0249F000-00000000 [65.00x / 38400000 / 2496.00]
|
| | | CPUID 00000016 | 000009C4-00001324-00000064-00000000 [2500 / 4900 / 100]
|
| | | CPUID 00000017 | 00000000-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 00000018 | 00000008-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 00000018 | 00000000-00080001-00000020-00004022 [SL 01]
|
| | | CPUID 00000018 | 00000000-00080006-00000004-00004022 [SL 02]
|
| | | CPUID 00000018 | 00000000-0010000F-00000001-00004125 [SL 03]
|
| | | CPUID 00000018 | 00000000-00080001-00000010-00004024 [SL 04]
|
| | | CPUID 00000018 | 00000000-00040006-00000008-00004024 [SL 05]
|
| | | CPUID 00000018 | 00000000-00080008-00000001-00004124 [SL 06]
|
| | | CPUID 00000018 | 00000000-00080007-00000080-00004043 [SL 07]
|
| | | CPUID 00000018 | 00000000-00080009-00000080-00004043 [SL 08]
|
| | | CPUID 00000019 | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001A | 40000003-00000000-00000000-00000000 [Core: Lion Cove]
|
| | | CPUID 0000001B | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001C | 4000000B-00000007-000F0007-00000000
|
| | | CPUID 0000001D | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001E | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001F | 00000001-00000001-00000100-00000008 [SL 00]
|
| | | CPUID 0000001F | 00000003-00000001-00000201-00000008 [SL 01]
|
| | | CPUID 0000001F | 00000007-0000000A-00000302-00000008 [SL 02]
|
| | | CPUID 00000020 | 00000000-00000001-00000000-00000000
|
| | | CPUID 00000021 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000022 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000023 | 0000000B-00000003-00000000-00000000
|
| | | CPUID 80000000 | 80000008-00000000-00000000-00000000
|
| | | CPUID 80000001 | 00000000-00000000-00000121-2C100800
|
| | | CPUID 80000002 | 65746E49-2952286C-726F4320-4D542865 [Intel(R) Core(TM]
|
| | | CPUID 80000003 | 6C552029-20617274-32322035-00005435 [) Ultra 5 225T]
|
| | | CPUID 80000004 | 00000000-00000000-00000000-00000000 []
|
| | | CPUID 80000005 | 00000000-00000000-00000000-00000000
|
| | | CPUID 80000006 | 00000000-00000000-0C007040-00000000
|
| | | CPUID 80000007 | 00000000-00000000-00000000-00000100
|
| | | CPUID 80000008 | 0000302A-00000200-00000000-00000000
|
|
|
| | CPUID Registers (CPU #2):
|
| | | CPUID 00000000 | 00000023-756E6547-6C65746E-49656E69 [GenuineIntel]
|
| | | CPUID 00000001 | 000C0662-10800800-7FFAFBFF-BFEBFBFF
|
| | | CPUID 00000002 | 00FEFF01-000000F0-00000000-00000000
|
| | | CPUID 00000003 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000004 | FC000121-01C0003F-0000003F-00000000 [SL 00]
|
| | | CPUID 00000004 | FC000122-01C0003F-0000007F-00000000 [SL 01]
|
| | | CPUID 00000004 | FC01C143-03C0003F-00000FFF-00000000 [SL 02]
|
| | | CPUID 00000004 | FC1FC163-0240003F-00007FFF-00000004 [SL 03]
|
| | | CPUID 00000005 | 00000040-00000040-00000003-10102020
|
| | | CPUID 00000006 | 00DF8FF7-00000002-00000409-00060003
|
| | | CPUID 00000007 | 00000002-239CA7EB-994007AC-FC18C430 [SL 00]
|
| | | CPUID 00000007 | 44C009D7-00000001-00000000-00040430 [SL 01]
|
| | | CPUID 00000007 | 00000000-00000000-00000000-000000BF [SL 02]
|
| | | CPUID 00000008 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000009 | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000000A | 0D300806-00000280-00000007-00008603
|
| | | CPUID 0000000B | 00000001-00000001-00000100-00000010 [SL 00]
|
| | | CPUID 0000000B | 00000007-0000000A-00000201-00000010 [SL 01]
|
| | | CPUID 0000000C | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000000D | 00000207-00000340-00000A88-00000000 [SL 00]
|
| | | CPUID 0000000D | 0000000F-000003D0-0001D900-00000000 [SL 01]
|
| | | CPUID 0000000D | 00000100-00000240-00000000-00000000 [SL 02]
|
| | | CPUID 0000000D | 00000080-00000000-00000001-00000000 [SL 08]
|
| | | CPUID 0000000D | 00000008-00000A80-00000000-00000000 [SL 09]
|
| | | CPUID 0000000D | 00000010-00000000-00000001-00000000 [SL 0B]
|
| | | CPUID 0000000D | 00000018-00000000-00000001-00000000 [SL 0C]
|
| | | CPUID 0000000D | 00000030-00000000-00000001-00000000 [SL 0E]
|
| | | CPUID 0000000D | 00000328-00000000-00000001-00000000 [SL 0F]
|
| | | CPUID 0000000D | 00000008-00000000-00000001-00000000 [SL 10]
|
| | | CPUID 0000000E | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000000F | 00000000-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 0000000F | 00000000-00000000-00000000-00000000 [SL 01]
|
| | | CPUID 00000010 | 00000000-00000040-00000000-00000000 [SL 00]
|
| | | CPUID 00000010 | 00000000-00000000-00000000-00000000 [SL 01]
|
| | | CPUID 00000011 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000012 | 00000000-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 00000012 | 00000000-00000000-00000000-00000000 [SL 01]
|
| | | CPUID 00000013 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000014 | 00000001-0000015F-80000007-00000000 [SL 00]
|
| | | CPUID 00000014 | 02490002-003F003F-00000000-00000000 [SL 01]
|
| | | CPUID 00000015 | 00000002-00000082-0249F000-00000000 [65.00x / 38400000 / 2496.00]
|
| | | CPUID 00000016 | 000009C4-00001130-00000064-00000000 [2500 / 4400 / 100]
|
| | | CPUID 00000017 | 00000000-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 00000018 | 00000004-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 00000018 | 00000000-00300003-00000001-00000121 [SL 01]
|
| | | CPUID 00000018 | 00000000-00040003-00000400-00000043 [SL 02]
|
| | | CPUID 00000018 | 00000000-00800001-00000001-00000122 [SL 03]
|
| | | CPUID 00000018 | 00000000-00080008-00000001-00000143 [SL 04]
|
| | | CPUID 00000019 | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001A | 20000003-00000000-00000000-00000000 [Atom: Skymont]
|
| | | CPUID 0000001B | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001C | C000000B-00000007-000F0007-00000000
|
| | | CPUID 0000001D | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001E | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001F | 00000001-00000001-00000100-00000010 [SL 00]
|
| | | CPUID 0000001F | 00000003-00000004-00000201-00000010 [SL 01]
|
| | | CPUID 0000001F | 00000007-0000000A-00000302-00000010 [SL 02]
|
| | | CPUID 00000020 | 00000000-00000001-00000000-00000000
|
| | | CPUID 00000021 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000022 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000023 | 0000000F-00000003-00000008-00000000
|
| | | CPUID 80000000 | 80000008-00000000-00000000-00000000
|
| | | CPUID 80000001 | 00000000-00000000-00000121-2C100800
|
| | | CPUID 80000002 | 65746E49-2952286C-726F4320-4D542865 [Intel(R) Core(TM]
|
| | | CPUID 80000003 | 6C552029-20617274-32322035-00005435 [) Ultra 5 225T]
|
| | | CPUID 80000004 | 00000000-00000000-00000000-00000000 []
|
| | | CPUID 80000005 | 00000000-00000000-00000000-00000000
|
| | | CPUID 80000006 | 00000000-00000000-10008040-00000000
|
| | | CPUID 80000007 | 00000000-00000000-00000000-00000100
|
| | | CPUID 80000008 | 0000302A-00000200-00000000-00000000
|
|
|
| | CPUID Registers (CPU #3):
|
| | | CPUID 00000000 | 00000023-756E6547-6C65746E-49656E69 [GenuineIntel]
|
| | | CPUID 00000001 | 000C0662-12800800-7FFAFBFF-BFEBFBFF
|
| | | CPUID 00000002 | 00FEFF01-000000F0-00000000-00000000
|
| | | CPUID 00000003 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000004 | FC000121-01C0003F-0000003F-00000000 [SL 00]
|
| | | CPUID 00000004 | FC000122-01C0003F-0000007F-00000000 [SL 01]
|
| | | CPUID 00000004 | FC01C143-03C0003F-00000FFF-00000000 [SL 02]
|
| | | CPUID 00000004 | FC1FC163-0240003F-00007FFF-00000004 [SL 03]
|
| | | CPUID 00000005 | 00000040-00000040-00000003-10102020
|
| | | CPUID 00000006 | 00DF8FF7-00000002-00000409-00070003
|
| | | CPUID 00000007 | 00000002-239CA7EB-994007AC-FC18C430 [SL 00]
|
| | | CPUID 00000007 | 44C009D7-00000001-00000000-00040430 [SL 01]
|
| | | CPUID 00000007 | 00000000-00000000-00000000-000000BF [SL 02]
|
| | | CPUID 00000008 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000009 | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000000A | 0D300806-00000280-00000007-00008603
|
| | | CPUID 0000000B | 00000001-00000001-00000100-00000012 [SL 00]
|
| | | CPUID 0000000B | 00000007-0000000A-00000201-00000012 [SL 01]
|
| | | CPUID 0000000C | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000000D | 00000207-00000340-00000A88-00000000 [SL 00]
|
| | | CPUID 0000000D | 0000000F-000003D0-0001D900-00000000 [SL 01]
|
| | | CPUID 0000000D | 00000100-00000240-00000000-00000000 [SL 02]
|
| | | CPUID 0000000D | 00000080-00000000-00000001-00000000 [SL 08]
|
| | | CPUID 0000000D | 00000008-00000A80-00000000-00000000 [SL 09]
|
| | | CPUID 0000000D | 00000010-00000000-00000001-00000000 [SL 0B]
|
| | | CPUID 0000000D | 00000018-00000000-00000001-00000000 [SL 0C]
|
| | | CPUID 0000000D | 00000030-00000000-00000001-00000000 [SL 0E]
|
| | | CPUID 0000000D | 00000328-00000000-00000001-00000000 [SL 0F]
|
| | | CPUID 0000000D | 00000008-00000000-00000001-00000000 [SL 10]
|
| | | CPUID 0000000E | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000000F | 00000000-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 0000000F | 00000000-00000000-00000000-00000000 [SL 01]
|
| | | CPUID 00000010 | 00000000-00000040-00000000-00000000 [SL 00]
|
| | | CPUID 00000010 | 00000000-00000000-00000000-00000000 [SL 01]
|
| | | CPUID 00000011 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000012 | 00000000-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 00000012 | 00000000-00000000-00000000-00000000 [SL 01]
|
| | | CPUID 00000013 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000014 | 00000001-0000015F-80000007-00000000 [SL 00]
|
| | | CPUID 00000014 | 02490002-003F003F-00000000-00000000 [SL 01]
|
| | | CPUID 00000015 | 00000002-00000082-0249F000-00000000 [65.00x / 38400000 / 2496.00]
|
| | | CPUID 00000016 | 000009C4-00001130-00000064-00000000 [2500 / 4400 / 100]
|
| | | CPUID 00000017 | 00000000-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 00000018 | 00000004-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 00000018 | 00000000-00300003-00000001-00000121 [SL 01]
|
| | | CPUID 00000018 | 00000000-00040003-00000400-00000043 [SL 02]
|
| | | CPUID 00000018 | 00000000-00800001-00000001-00000122 [SL 03]
|
| | | CPUID 00000018 | 00000000-00080008-00000001-00000143 [SL 04]
|
| | | CPUID 00000019 | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001A | 20000003-00000000-00000000-00000000 [Atom: Skymont]
|
| | | CPUID 0000001B | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001C | C000000B-00000007-000F0007-00000000
|
| | | CPUID 0000001D | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001E | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001F | 00000001-00000001-00000100-00000012 [SL 00]
|
| | | CPUID 0000001F | 00000003-00000004-00000201-00000012 [SL 01]
|
| | | CPUID 0000001F | 00000007-0000000A-00000302-00000012 [SL 02]
|
| | | CPUID 00000020 | 00000000-00000001-00000000-00000000
|
| | | CPUID 00000021 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000022 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000023 | 0000000F-00000003-00000008-00000000
|
| | | CPUID 80000000 | 80000008-00000000-00000000-00000000
|
| | | CPUID 80000001 | 00000000-00000000-00000121-2C100800
|
| | | CPUID 80000002 | 65746E49-2952286C-726F4320-4D542865 [Intel(R) Core(TM]
|
| | | CPUID 80000003 | 6C552029-20617274-32322035-00005435 [) Ultra 5 225T]
|
| | | CPUID 80000004 | 00000000-00000000-00000000-00000000 []
|
| | | CPUID 80000005 | 00000000-00000000-00000000-00000000
|
| | | CPUID 80000006 | 00000000-00000000-10008040-00000000
|
| | | CPUID 80000007 | 00000000-00000000-00000000-00000100
|
| | | CPUID 80000008 | 0000302A-00000200-00000000-00000000
|
|
|
| | CPUID Registers (CPU #4):
|
| | | CPUID 00000000 | 00000023-756E6547-6C65746E-49656E69 [GenuineIntel]
|
| | | CPUID 00000001 | 000C0662-14800800-7FFAFBFF-BFEBFBFF
|
| | | CPUID 00000002 | 00FEFF01-000000F0-00000000-00000000
|
| | | CPUID 00000003 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000004 | FC000121-01C0003F-0000003F-00000000 [SL 00]
|
| | | CPUID 00000004 | FC000122-01C0003F-0000007F-00000000 [SL 01]
|
| | | CPUID 00000004 | FC01C143-03C0003F-00000FFF-00000000 [SL 02]
|
| | | CPUID 00000004 | FC1FC163-0240003F-00007FFF-00000004 [SL 03]
|
| | | CPUID 00000005 | 00000040-00000040-00000003-10102020
|
| | | CPUID 00000006 | 00DF8FF7-00000002-00000409-00080003
|
| | | CPUID 00000007 | 00000002-239CA7EB-994007AC-FC18C430 [SL 00]
|
| | | CPUID 00000007 | 44C009D7-00000001-00000000-00040430 [SL 01]
|
| | | CPUID 00000007 | 00000000-00000000-00000000-000000BF [SL 02]
|
| | | CPUID 00000008 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000009 | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000000A | 0D300806-00000280-00000007-00008603
|
| | | CPUID 0000000B | 00000001-00000001-00000100-00000014 [SL 00]
|
| | | CPUID 0000000B | 00000007-0000000A-00000201-00000014 [SL 01]
|
| | | CPUID 0000000C | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000000D | 00000207-00000340-00000A88-00000000 [SL 00]
|
| | | CPUID 0000000D | 0000000F-000003D0-0001D900-00000000 [SL 01]
|
| | | CPUID 0000000D | 00000100-00000240-00000000-00000000 [SL 02]
|
| | | CPUID 0000000D | 00000080-00000000-00000001-00000000 [SL 08]
|
| | | CPUID 0000000D | 00000008-00000A80-00000000-00000000 [SL 09]
|
| | | CPUID 0000000D | 00000010-00000000-00000001-00000000 [SL 0B]
|
| | | CPUID 0000000D | 00000018-00000000-00000001-00000000 [SL 0C]
|
| | | CPUID 0000000D | 00000030-00000000-00000001-00000000 [SL 0E]
|
| | | CPUID 0000000D | 00000328-00000000-00000001-00000000 [SL 0F]
|
| | | CPUID 0000000D | 00000008-00000000-00000001-00000000 [SL 10]
|
| | | CPUID 0000000E | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000000F | 00000000-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 0000000F | 00000000-00000000-00000000-00000000 [SL 01]
|
| | | CPUID 00000010 | 00000000-00000040-00000000-00000000 [SL 00]
|
| | | CPUID 00000010 | 00000000-00000000-00000000-00000000 [SL 01]
|
| | | CPUID 00000011 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000012 | 00000000-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 00000012 | 00000000-00000000-00000000-00000000 [SL 01]
|
| | | CPUID 00000013 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000014 | 00000001-0000015F-80000007-00000000 [SL 00]
|
| | | CPUID 00000014 | 02490002-003F003F-00000000-00000000 [SL 01]
|
| | | CPUID 00000015 | 00000002-00000082-0249F000-00000000 [65.00x / 38400000 / 2496.00]
|
| | | CPUID 00000016 | 000009C4-00001130-00000064-00000000 [2500 / 4400 / 100]
|
| | | CPUID 00000017 | 00000000-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 00000018 | 00000004-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 00000018 | 00000000-00300003-00000001-00000121 [SL 01]
|
| | | CPUID 00000018 | 00000000-00040003-00000400-00000043 [SL 02]
|
| | | CPUID 00000018 | 00000000-00800001-00000001-00000122 [SL 03]
|
| | | CPUID 00000018 | 00000000-00080008-00000001-00000143 [SL 04]
|
| | | CPUID 00000019 | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001A | 20000003-00000000-00000000-00000000 [Atom: Skymont]
|
| | | CPUID 0000001B | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001C | C000000B-00000007-000F0007-00000000
|
| | | CPUID 0000001D | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001E | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001F | 00000001-00000001-00000100-00000014 [SL 00]
|
| | | CPUID 0000001F | 00000003-00000004-00000201-00000014 [SL 01]
|
| | | CPUID 0000001F | 00000007-0000000A-00000302-00000014 [SL 02]
|
| | | CPUID 00000020 | 00000000-00000001-00000000-00000000
|
| | | CPUID 00000021 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000022 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000023 | 0000000F-00000003-00000008-00000000
|
| | | CPUID 80000000 | 80000008-00000000-00000000-00000000
|
| | | CPUID 80000001 | 00000000-00000000-00000121-2C100800
|
| | | CPUID 80000002 | 65746E49-2952286C-726F4320-4D542865 [Intel(R) Core(TM]
|
| | | CPUID 80000003 | 6C552029-20617274-32322035-00005435 [) Ultra 5 225T]
|
| | | CPUID 80000004 | 00000000-00000000-00000000-00000000 []
|
| | | CPUID 80000005 | 00000000-00000000-00000000-00000000
|
| | | CPUID 80000006 | 00000000-00000000-10008040-00000000
|
| | | CPUID 80000007 | 00000000-00000000-00000000-00000100
|
| | | CPUID 80000008 | 0000302A-00000200-00000000-00000000
|
|
|
| | CPUID Registers (CPU #5):
|
| | | CPUID 00000000 | 00000023-756E6547-6C65746E-49656E69 [GenuineIntel]
|
| | | CPUID 00000001 | 000C0662-16800800-7FFAFBFF-BFEBFBFF
|
| | | CPUID 00000002 | 00FEFF01-000000F0-00000000-00000000
|
| | | CPUID 00000003 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000004 | FC000121-01C0003F-0000003F-00000000 [SL 00]
|
| | | CPUID 00000004 | FC000122-01C0003F-0000007F-00000000 [SL 01]
|
| | | CPUID 00000004 | FC01C143-03C0003F-00000FFF-00000000 [SL 02]
|
| | | CPUID 00000004 | FC1FC163-0240003F-00007FFF-00000004 [SL 03]
|
| | | CPUID 00000005 | 00000040-00000040-00000003-10102020
|
| | | CPUID 00000006 | 00DF8FF7-00000002-00000409-00090003
|
| | | CPUID 00000007 | 00000002-239CA7EB-994007AC-FC18C430 [SL 00]
|
| | | CPUID 00000007 | 44C009D7-00000001-00000000-00040430 [SL 01]
|
| | | CPUID 00000007 | 00000000-00000000-00000000-000000BF [SL 02]
|
| | | CPUID 00000008 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000009 | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000000A | 0D300806-00000280-00000007-00008603
|
| | | CPUID 0000000B | 00000001-00000001-00000100-00000016 [SL 00]
|
| | | CPUID 0000000B | 00000007-0000000A-00000201-00000016 [SL 01]
|
| | | CPUID 0000000C | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000000D | 00000207-00000340-00000A88-00000000 [SL 00]
|
| | | CPUID 0000000D | 0000000F-000003D0-0001D900-00000000 [SL 01]
|
| | | CPUID 0000000D | 00000100-00000240-00000000-00000000 [SL 02]
|
| | | CPUID 0000000D | 00000080-00000000-00000001-00000000 [SL 08]
|
| | | CPUID 0000000D | 00000008-00000A80-00000000-00000000 [SL 09]
|
| | | CPUID 0000000D | 00000010-00000000-00000001-00000000 [SL 0B]
|
| | | CPUID 0000000D | 00000018-00000000-00000001-00000000 [SL 0C]
|
| | | CPUID 0000000D | 00000030-00000000-00000001-00000000 [SL 0E]
|
| | | CPUID 0000000D | 00000328-00000000-00000001-00000000 [SL 0F]
|
| | | CPUID 0000000D | 00000008-00000000-00000001-00000000 [SL 10]
|
| | | CPUID 0000000E | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000000F | 00000000-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 0000000F | 00000000-00000000-00000000-00000000 [SL 01]
|
| | | CPUID 00000010 | 00000000-00000040-00000000-00000000 [SL 00]
|
| | | CPUID 00000010 | 00000000-00000000-00000000-00000000 [SL 01]
|
| | | CPUID 00000011 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000012 | 00000000-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 00000012 | 00000000-00000000-00000000-00000000 [SL 01]
|
| | | CPUID 00000013 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000014 | 00000001-0000015F-80000007-00000000 [SL 00]
|
| | | CPUID 00000014 | 02490002-003F003F-00000000-00000000 [SL 01]
|
| | | CPUID 00000015 | 00000002-00000082-0249F000-00000000 [65.00x / 38400000 / 2496.00]
|
| | | CPUID 00000016 | 000009C4-00001130-00000064-00000000 [2500 / 4400 / 100]
|
| | | CPUID 00000017 | 00000000-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 00000018 | 00000004-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 00000018 | 00000000-00300003-00000001-00000121 [SL 01]
|
| | | CPUID 00000018 | 00000000-00040003-00000400-00000043 [SL 02]
|
| | | CPUID 00000018 | 00000000-00800001-00000001-00000122 [SL 03]
|
| | | CPUID 00000018 | 00000000-00080008-00000001-00000143 [SL 04]
|
| | | CPUID 00000019 | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001A | 20000003-00000000-00000000-00000000 [Atom: Skymont]
|
| | | CPUID 0000001B | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001C | C000000B-00000007-000F0007-00000000
|
| | | CPUID 0000001D | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001E | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001F | 00000001-00000001-00000100-00000016 [SL 00]
|
| | | CPUID 0000001F | 00000003-00000004-00000201-00000016 [SL 01]
|
| | | CPUID 0000001F | 00000007-0000000A-00000302-00000016 [SL 02]
|
| | | CPUID 00000020 | 00000000-00000001-00000000-00000000
|
| | | CPUID 00000021 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000022 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000023 | 0000000F-00000003-00000008-00000000
|
| | | CPUID 80000000 | 80000008-00000000-00000000-00000000
|
| | | CPUID 80000001 | 00000000-00000000-00000121-2C100800
|
| | | CPUID 80000002 | 65746E49-2952286C-726F4320-4D542865 [Intel(R) Core(TM]
|
| | | CPUID 80000003 | 6C552029-20617274-32322035-00005435 [) Ultra 5 225T]
|
| | | CPUID 80000004 | 00000000-00000000-00000000-00000000 []
|
| | | CPUID 80000005 | 00000000-00000000-00000000-00000000
|
| | | CPUID 80000006 | 00000000-00000000-10008040-00000000
|
| | | CPUID 80000007 | 00000000-00000000-00000000-00000100
|
| | | CPUID 80000008 | 0000302A-00000200-00000000-00000000
|
|
|
| | CPUID Registers (CPU #6):
|
| | | CPUID 00000000 | 00000023-756E6547-6C65746E-49656E69 [GenuineIntel]
|
| | | CPUID 00000001 | 000C0662-20800800-7FFAFBFF-BFEBFBFF
|
| | | CPUID 00000002 | 00FEFF01-000000F0-00000000-00000000
|
| | | CPUID 00000003 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000004 | FC004121-02C0003F-0000003F-00000000 [SL 00]
|
| | | CPUID 00000004 | FC004122-03C0003F-0000003F-00000000 [SL 01]
|
| | | CPUID 00000004 | FC01C143-02C0003F-00000FFF-00000000 [SL 02]
|
| | | CPUID 00000004 | FC1FC163-0240003F-00007FFF-00000004 [SL 03]
|
| | | CPUID 00000005 | 00000040-00000040-00000003-10102020
|
| | | CPUID 00000006 | 00DF8FF7-00000002-00000409-00020003
|
| | | CPUID 00000007 | 00000002-239CA7EB-994007AC-FC18C430 [SL 00]
|
| | | CPUID 00000007 | 44C009D7-00000001-00000000-00040430 [SL 01]
|
| | | CPUID 00000007 | 00000000-00000000-00000000-000000BF [SL 02]
|
| | | CPUID 00000008 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000009 | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000000A | 0D300806-00000280-00000007-00008603
|
| | | CPUID 0000000B | 00000001-00000001-00000100-00000020 [SL 00]
|
| | | CPUID 0000000B | 00000007-0000000A-00000201-00000020 [SL 01]
|
| | | CPUID 0000000C | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000000D | 00000207-00000340-00000A88-00000000 [SL 00]
|
| | | CPUID 0000000D | 0000000F-000003D0-0001D900-00000000 [SL 01]
|
| | | CPUID 0000000D | 00000100-00000240-00000000-00000000 [SL 02]
|
| | | CPUID 0000000D | 00000080-00000000-00000001-00000000 [SL 08]
|
| | | CPUID 0000000D | 00000008-00000A80-00000000-00000000 [SL 09]
|
| | | CPUID 0000000D | 00000010-00000000-00000001-00000000 [SL 0B]
|
| | | CPUID 0000000D | 00000018-00000000-00000001-00000000 [SL 0C]
|
| | | CPUID 0000000D | 00000030-00000000-00000001-00000000 [SL 0E]
|
| | | CPUID 0000000D | 00000328-00000000-00000001-00000000 [SL 0F]
|
| | | CPUID 0000000D | 00000008-00000000-00000001-00000000 [SL 10]
|
| | | CPUID 0000000E | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000000F | 00000000-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 0000000F | 00000000-00000000-00000000-00000000 [SL 01]
|
| | | CPUID 00000010 | 00000000-00000040-00000000-00000000 [SL 00]
|
| | | CPUID 00000010 | 00000000-00000000-00000000-00000000 [SL 01]
|
| | | CPUID 00000011 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000012 | 00000000-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 00000012 | 00000000-00000000-00000000-00000000 [SL 01]
|
| | | CPUID 00000013 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000014 | 00000001-0000015F-00000007-00000000 [SL 00]
|
| | | CPUID 00000014 | 02490002-003F003F-00000000-00000000 [SL 01]
|
| | | CPUID 00000015 | 00000002-00000082-0249F000-00000000 [65.00x / 38400000 / 2496.00]
|
| | | CPUID 00000016 | 000009C4-00001324-00000064-00000000 [2500 / 4900 / 100]
|
| | | CPUID 00000017 | 00000000-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 00000018 | 00000008-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 00000018 | 00000000-00080001-00000020-00004022 [SL 01]
|
| | | CPUID 00000018 | 00000000-00080006-00000004-00004022 [SL 02]
|
| | | CPUID 00000018 | 00000000-0010000F-00000001-00004125 [SL 03]
|
| | | CPUID 00000018 | 00000000-00080001-00000010-00004024 [SL 04]
|
| | | CPUID 00000018 | 00000000-00040006-00000008-00004024 [SL 05]
|
| | | CPUID 00000018 | 00000000-00080008-00000001-00004124 [SL 06]
|
| | | CPUID 00000018 | 00000000-00080007-00000080-00004043 [SL 07]
|
| | | CPUID 00000018 | 00000000-00080009-00000080-00004043 [SL 08]
|
| | | CPUID 00000019 | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001A | 40000003-00000000-00000000-00000000 [Core: Lion Cove]
|
| | | CPUID 0000001B | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001C | 4000000B-00000007-000F0007-00000000
|
| | | CPUID 0000001D | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001E | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001F | 00000001-00000001-00000100-00000020 [SL 00]
|
| | | CPUID 0000001F | 00000003-00000001-00000201-00000020 [SL 01]
|
| | | CPUID 0000001F | 00000007-0000000A-00000302-00000020 [SL 02]
|
| | | CPUID 00000020 | 00000000-00000001-00000000-00000000
|
| | | CPUID 00000021 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000022 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000023 | 0000000B-00000003-00000000-00000000
|
| | | CPUID 80000000 | 80000008-00000000-00000000-00000000
|
| | | CPUID 80000001 | 00000000-00000000-00000121-2C100800
|
| | | CPUID 80000002 | 65746E49-2952286C-726F4320-4D542865 [Intel(R) Core(TM]
|
| | | CPUID 80000003 | 6C552029-20617274-32322035-00005435 [) Ultra 5 225T]
|
| | | CPUID 80000004 | 00000000-00000000-00000000-00000000 []
|
| | | CPUID 80000005 | 00000000-00000000-00000000-00000000
|
| | | CPUID 80000006 | 00000000-00000000-0C007040-00000000
|
| | | CPUID 80000007 | 00000000-00000000-00000000-00000100
|
| | | CPUID 80000008 | 0000302A-00000200-00000000-00000000
|
|
|
| | CPUID Registers (CPU #7):
|
| | | CPUID 00000000 | 00000023-756E6547-6C65746E-49656E69 [GenuineIntel]
|
| | | CPUID 00000001 | 000C0662-28800800-7FFAFBFF-BFEBFBFF
|
| | | CPUID 00000002 | 00FEFF01-000000F0-00000000-00000000
|
| | | CPUID 00000003 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000004 | FC004121-02C0003F-0000003F-00000000 [SL 00]
|
| | | CPUID 00000004 | FC004122-03C0003F-0000003F-00000000 [SL 01]
|
| | | CPUID 00000004 | FC01C143-02C0003F-00000FFF-00000000 [SL 02]
|
| | | CPUID 00000004 | FC1FC163-0240003F-00007FFF-00000004 [SL 03]
|
| | | CPUID 00000005 | 00000040-00000040-00000003-10102020
|
| | | CPUID 00000006 | 00DF8FF7-00000002-00000409-00030003
|
| | | CPUID 00000007 | 00000002-239CA7EB-994007AC-FC18C430 [SL 00]
|
| | | CPUID 00000007 | 44C009D7-00000001-00000000-00040430 [SL 01]
|
| | | CPUID 00000007 | 00000000-00000000-00000000-000000BF [SL 02]
|
| | | CPUID 00000008 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000009 | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000000A | 0D300806-00000280-00000007-00008603
|
| | | CPUID 0000000B | 00000001-00000001-00000100-00000028 [SL 00]
|
| | | CPUID 0000000B | 00000007-0000000A-00000201-00000028 [SL 01]
|
| | | CPUID 0000000C | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000000D | 00000207-00000340-00000A88-00000000 [SL 00]
|
| | | CPUID 0000000D | 0000000F-000003D0-0001D900-00000000 [SL 01]
|
| | | CPUID 0000000D | 00000100-00000240-00000000-00000000 [SL 02]
|
| | | CPUID 0000000D | 00000080-00000000-00000001-00000000 [SL 08]
|
| | | CPUID 0000000D | 00000008-00000A80-00000000-00000000 [SL 09]
|
| | | CPUID 0000000D | 00000010-00000000-00000001-00000000 [SL 0B]
|
| | | CPUID 0000000D | 00000018-00000000-00000001-00000000 [SL 0C]
|
| | | CPUID 0000000D | 00000030-00000000-00000001-00000000 [SL 0E]
|
| | | CPUID 0000000D | 00000328-00000000-00000001-00000000 [SL 0F]
|
| | | CPUID 0000000D | 00000008-00000000-00000001-00000000 [SL 10]
|
| | | CPUID 0000000E | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000000F | 00000000-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 0000000F | 00000000-00000000-00000000-00000000 [SL 01]
|
| | | CPUID 00000010 | 00000000-00000040-00000000-00000000 [SL 00]
|
| | | CPUID 00000010 | 00000000-00000000-00000000-00000000 [SL 01]
|
| | | CPUID 00000011 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000012 | 00000000-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 00000012 | 00000000-00000000-00000000-00000000 [SL 01]
|
| | | CPUID 00000013 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000014 | 00000001-0000015F-00000007-00000000 [SL 00]
|
| | | CPUID 00000014 | 02490002-003F003F-00000000-00000000 [SL 01]
|
| | | CPUID 00000015 | 00000002-00000082-0249F000-00000000 [65.00x / 38400000 / 2496.00]
|
| | | CPUID 00000016 | 000009C4-00001324-00000064-00000000 [2500 / 4900 / 100]
|
| | | CPUID 00000017 | 00000000-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 00000018 | 00000008-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 00000018 | 00000000-00080001-00000020-00004022 [SL 01]
|
| | | CPUID 00000018 | 00000000-00080006-00000004-00004022 [SL 02]
|
| | | CPUID 00000018 | 00000000-0010000F-00000001-00004125 [SL 03]
|
| | | CPUID 00000018 | 00000000-00080001-00000010-00004024 [SL 04]
|
| | | CPUID 00000018 | 00000000-00040006-00000008-00004024 [SL 05]
|
| | | CPUID 00000018 | 00000000-00080008-00000001-00004124 [SL 06]
|
| | | CPUID 00000018 | 00000000-00080007-00000080-00004043 [SL 07]
|
| | | CPUID 00000018 | 00000000-00080009-00000080-00004043 [SL 08]
|
| | | CPUID 00000019 | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001A | 40000003-00000000-00000000-00000000 [Core: Lion Cove]
|
| | | CPUID 0000001B | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001C | 4000000B-00000007-000F0007-00000000
|
| | | CPUID 0000001D | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001E | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001F | 00000001-00000001-00000100-00000028 [SL 00]
|
| | | CPUID 0000001F | 00000003-00000001-00000201-00000028 [SL 01]
|
| | | CPUID 0000001F | 00000007-0000000A-00000302-00000028 [SL 02]
|
| | | CPUID 00000020 | 00000000-00000001-00000000-00000000
|
| | | CPUID 00000021 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000022 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000023 | 0000000B-00000003-00000000-00000000
|
| | | CPUID 80000000 | 80000008-00000000-00000000-00000000
|
| | | CPUID 80000001 | 00000000-00000000-00000121-2C100800
|
| | | CPUID 80000002 | 65746E49-2952286C-726F4320-4D542865 [Intel(R) Core(TM]
|
| | | CPUID 80000003 | 6C552029-20617274-32322035-00005435 [) Ultra 5 225T]
|
| | | CPUID 80000004 | 00000000-00000000-00000000-00000000 []
|
| | | CPUID 80000005 | 00000000-00000000-00000000-00000000
|
| | | CPUID 80000006 | 00000000-00000000-0C007040-00000000
|
| | | CPUID 80000007 | 00000000-00000000-00000000-00000100
|
| | | CPUID 80000008 | 0000302A-00000200-00000000-00000000
|
|
|
| | CPUID Registers (CPU #8):
|
| | | CPUID 00000000 | 00000023-756E6547-6C65746E-49656E69 [GenuineIntel]
|
| | | CPUID 00000001 | 000C0662-30800800-7FFAFBFF-BFEBFBFF
|
| | | CPUID 00000002 | 00FEFF01-000000F0-00000000-00000000
|
| | | CPUID 00000003 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000004 | FC004121-02C0003F-0000003F-00000000 [SL 00]
|
| | | CPUID 00000004 | FC004122-03C0003F-0000003F-00000000 [SL 01]
|
| | | CPUID 00000004 | FC01C143-02C0003F-00000FFF-00000000 [SL 02]
|
| | | CPUID 00000004 | FC1FC163-0240003F-00007FFF-00000004 [SL 03]
|
| | | CPUID 00000005 | 00000040-00000040-00000003-10102020
|
| | | CPUID 00000006 | 00DF8FF7-00000002-00000409-00040003
|
| | | CPUID 00000007 | 00000002-239CA7EB-994007AC-FC18C430 [SL 00]
|
| | | CPUID 00000007 | 44C009D7-00000001-00000000-00040430 [SL 01]
|
| | | CPUID 00000007 | 00000000-00000000-00000000-000000BF [SL 02]
|
| | | CPUID 00000008 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000009 | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000000A | 0D300806-00000280-00000007-00008603
|
| | | CPUID 0000000B | 00000001-00000001-00000100-00000030 [SL 00]
|
| | | CPUID 0000000B | 00000007-0000000A-00000201-00000030 [SL 01]
|
| | | CPUID 0000000C | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000000D | 00000207-00000340-00000A88-00000000 [SL 00]
|
| | | CPUID 0000000D | 0000000F-000003D0-0001D900-00000000 [SL 01]
|
| | | CPUID 0000000D | 00000100-00000240-00000000-00000000 [SL 02]
|
| | | CPUID 0000000D | 00000080-00000000-00000001-00000000 [SL 08]
|
| | | CPUID 0000000D | 00000008-00000A80-00000000-00000000 [SL 09]
|
| | | CPUID 0000000D | 00000010-00000000-00000001-00000000 [SL 0B]
|
| | | CPUID 0000000D | 00000018-00000000-00000001-00000000 [SL 0C]
|
| | | CPUID 0000000D | 00000030-00000000-00000001-00000000 [SL 0E]
|
| | | CPUID 0000000D | 00000328-00000000-00000001-00000000 [SL 0F]
|
| | | CPUID 0000000D | 00000008-00000000-00000001-00000000 [SL 10]
|
| | | CPUID 0000000E | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000000F | 00000000-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 0000000F | 00000000-00000000-00000000-00000000 [SL 01]
|
| | | CPUID 00000010 | 00000000-00000040-00000000-00000000 [SL 00]
|
| | | CPUID 00000010 | 00000000-00000000-00000000-00000000 [SL 01]
|
| | | CPUID 00000011 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000012 | 00000000-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 00000012 | 00000000-00000000-00000000-00000000 [SL 01]
|
| | | CPUID 00000013 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000014 | 00000001-0000015F-00000007-00000000 [SL 00]
|
| | | CPUID 00000014 | 02490002-003F003F-00000000-00000000 [SL 01]
|
| | | CPUID 00000015 | 00000002-00000082-0249F000-00000000 [65.00x / 38400000 / 2496.00]
|
| | | CPUID 00000016 | 000009C4-00001324-00000064-00000000 [2500 / 4900 / 100]
|
| | | CPUID 00000017 | 00000000-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 00000018 | 00000008-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 00000018 | 00000000-00080001-00000020-00004022 [SL 01]
|
| | | CPUID 00000018 | 00000000-00080006-00000004-00004022 [SL 02]
|
| | | CPUID 00000018 | 00000000-0010000F-00000001-00004125 [SL 03]
|
| | | CPUID 00000018 | 00000000-00080001-00000010-00004024 [SL 04]
|
| | | CPUID 00000018 | 00000000-00040006-00000008-00004024 [SL 05]
|
| | | CPUID 00000018 | 00000000-00080008-00000001-00004124 [SL 06]
|
| | | CPUID 00000018 | 00000000-00080007-00000080-00004043 [SL 07]
|
| | | CPUID 00000018 | 00000000-00080009-00000080-00004043 [SL 08]
|
| | | CPUID 00000019 | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001A | 40000003-00000000-00000000-00000000 [Core: Lion Cove]
|
| | | CPUID 0000001B | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001C | 4000000B-00000007-000F0007-00000000
|
| | | CPUID 0000001D | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001E | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001F | 00000001-00000001-00000100-00000030 [SL 00]
|
| | | CPUID 0000001F | 00000003-00000001-00000201-00000030 [SL 01]
|
| | | CPUID 0000001F | 00000007-0000000A-00000302-00000030 [SL 02]
|
| | | CPUID 00000020 | 00000000-00000001-00000000-00000000
|
| | | CPUID 00000021 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000022 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000023 | 0000000B-00000003-00000000-00000000
|
| | | CPUID 80000000 | 80000008-00000000-00000000-00000000
|
| | | CPUID 80000001 | 00000000-00000000-00000121-2C100800
|
| | | CPUID 80000002 | 65746E49-2952286C-726F4320-4D542865 [Intel(R) Core(TM]
|
| | | CPUID 80000003 | 6C552029-20617274-32322035-00005435 [) Ultra 5 225T]
|
| | | CPUID 80000004 | 00000000-00000000-00000000-00000000 []
|
| | | CPUID 80000005 | 00000000-00000000-00000000-00000000
|
| | | CPUID 80000006 | 00000000-00000000-0C007040-00000000
|
| | | CPUID 80000007 | 00000000-00000000-00000000-00000100
|
| | | CPUID 80000008 | 0000302A-00000200-00000000-00000000
|
|
|
| | CPUID Registers (CPU #9):
|
| | | CPUID 00000000 | 00000023-756E6547-6C65746E-49656E69 [GenuineIntel]
|
| | | CPUID 00000001 | 000C0662-38800800-7FFAFBFF-BFEBFBFF
|
| | | CPUID 00000002 | 00FEFF01-000000F0-00000000-00000000
|
| | | CPUID 00000003 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000004 | FC004121-02C0003F-0000003F-00000000 [SL 00]
|
| | | CPUID 00000004 | FC004122-03C0003F-0000003F-00000000 [SL 01]
|
| | | CPUID 00000004 | FC01C143-02C0003F-00000FFF-00000000 [SL 02]
|
| | | CPUID 00000004 | FC1FC163-0240003F-00007FFF-00000004 [SL 03]
|
| | | CPUID 00000005 | 00000040-00000040-00000003-10102020
|
| | | CPUID 00000006 | 00DF8FF7-00000002-00000409-00050003
|
| | | CPUID 00000007 | 00000002-239CA7EB-994007AC-FC18C430 [SL 00]
|
| | | CPUID 00000007 | 44C009D7-00000001-00000000-00040430 [SL 01]
|
| | | CPUID 00000007 | 00000000-00000000-00000000-000000BF [SL 02]
|
| | | CPUID 00000008 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000009 | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000000A | 0D300806-00000280-00000007-00008603
|
| | | CPUID 0000000B | 00000001-00000001-00000100-00000038 [SL 00]
|
| | | CPUID 0000000B | 00000007-0000000A-00000201-00000038 [SL 01]
|
| | | CPUID 0000000C | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000000D | 00000207-00000340-00000A88-00000000 [SL 00]
|
| | | CPUID 0000000D | 0000000F-000003D0-0001D900-00000000 [SL 01]
|
| | | CPUID 0000000D | 00000100-00000240-00000000-00000000 [SL 02]
|
| | | CPUID 0000000D | 00000080-00000000-00000001-00000000 [SL 08]
|
| | | CPUID 0000000D | 00000008-00000A80-00000000-00000000 [SL 09]
|
| | | CPUID 0000000D | 00000010-00000000-00000001-00000000 [SL 0B]
|
| | | CPUID 0000000D | 00000018-00000000-00000001-00000000 [SL 0C]
|
| | | CPUID 0000000D | 00000030-00000000-00000001-00000000 [SL 0E]
|
| | | CPUID 0000000D | 00000328-00000000-00000001-00000000 [SL 0F]
|
| | | CPUID 0000000D | 00000008-00000000-00000001-00000000 [SL 10]
|
| | | CPUID 0000000E | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000000F | 00000000-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 0000000F | 00000000-00000000-00000000-00000000 [SL 01]
|
| | | CPUID 00000010 | 00000000-00000040-00000000-00000000 [SL 00]
|
| | | CPUID 00000010 | 00000000-00000000-00000000-00000000 [SL 01]
|
| | | CPUID 00000011 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000012 | 00000000-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 00000012 | 00000000-00000000-00000000-00000000 [SL 01]
|
| | | CPUID 00000013 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000014 | 00000001-0000015F-00000007-00000000 [SL 00]
|
| | | CPUID 00000014 | 02490002-003F003F-00000000-00000000 [SL 01]
|
| | | CPUID 00000015 | 00000002-00000082-0249F000-00000000 [65.00x / 38400000 / 2496.00]
|
| | | CPUID 00000016 | 000009C4-00001324-00000064-00000000 [2500 / 4900 / 100]
|
| | | CPUID 00000017 | 00000000-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 00000018 | 00000008-00000000-00000000-00000000 [SL 00]
|
| | | CPUID 00000018 | 00000000-00080001-00000020-00004022 [SL 01]
|
| | | CPUID 00000018 | 00000000-00080006-00000004-00004022 [SL 02]
|
| | | CPUID 00000018 | 00000000-0010000F-00000001-00004125 [SL 03]
|
| | | CPUID 00000018 | 00000000-00080001-00000010-00004024 [SL 04]
|
| | | CPUID 00000018 | 00000000-00040006-00000008-00004024 [SL 05]
|
| | | CPUID 00000018 | 00000000-00080008-00000001-00004124 [SL 06]
|
| | | CPUID 00000018 | 00000000-00080007-00000080-00004043 [SL 07]
|
| | | CPUID 00000018 | 00000000-00080009-00000080-00004043 [SL 08]
|
| | | CPUID 00000019 | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001A | 40000003-00000000-00000000-00000000 [Core: Lion Cove]
|
| | | CPUID 0000001B | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001C | 4000000B-00000007-000F0007-00000000
|
| | | CPUID 0000001D | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001E | 00000000-00000000-00000000-00000000
|
| | | CPUID 0000001F | 00000001-00000001-00000100-00000038 [SL 00]
|
| | | CPUID 0000001F | 00000003-00000001-00000201-00000038 [SL 01]
|
| | | CPUID 0000001F | 00000007-0000000A-00000302-00000038 [SL 02]
|
| | | CPUID 00000020 | 00000000-00000001-00000000-00000000
|
| | | CPUID 00000021 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000022 | 00000000-00000000-00000000-00000000
|
| | | CPUID 00000023 | 0000000B-00000003-00000000-00000000
|
| | | CPUID 80000000 | 80000008-00000000-00000000-00000000
|
| | | CPUID 80000001 | 00000000-00000000-00000121-2C100800
|
| | | CPUID 80000002 | 65746E49-2952286C-726F4320-4D542865 [Intel(R) Core(TM]
|
| | | CPUID 80000003 | 6C552029-20617274-32322035-00005435 [) Ultra 5 225T]
|
| | | CPUID 80000004 | 00000000-00000000-00000000-00000000 []
|
| | | CPUID 80000005 | 00000000-00000000-00000000-00000000
|
| | | CPUID 80000006 | 00000000-00000000-0C007040-00000000
|
| | | CPUID 80000007 | 00000000-00000000-00000000-00000100
|
| | | CPUID 80000008 | 0000302A-00000200-00000000-00000000
|
|
|
| | MSR Registers (CPU #0):
|
| | | MSR 00000017 | 0004-0000-0000-0000 [PlatID = 1]
|
| | | MSR 0000001B | 0000-0000-FEE0-0D00
|
| | | MSR 00000035 | 0000-0000-000A-000A
|
| | | MSR 00000048 | 0000-0000-0000-0001
|
| | | MSR 00000049 | < FAILED >
|
| | | MSR 0000008B | 0000-0121-0000-0000
|
| | | MSR 000000CE | 0804-0838-F081-1900 [eD = 0]
|
| | | MSR 000000E7 | 0000-000E-B100-2DFE [S200]
|
| | | MSR 000000E7 | 0000-000E-B1E8-C23A [S200]
|
| | | MSR 000000E7 | 0000-000E-B2E7-6650
|
| | | MSR 000000E8 | 0000-0015-AA6D-BADC [S200]
|
| | | MSR 000000E8 | 0000-0015-AAD7-1314 [S200]
|
| | | MSR 000000E8 | 0000-0015-AAF6-6D36
|
| | | MSR 0000010A | 0000-0000-0DF9-FD6B
|
| | | MSR 0000010B | < FAILED >
|
| | | MSR 00000194 | 0000-0000-0010-0000
|
| | | MSR 00000198 | 0000-1724-0000-1500 [S200]
|
| | | MSR 00000198 | 0000-1724-0000-1200 [S200]
|
| | | MSR 00000198 | 0000-1724-0000-1600
|
| | | MSR 00000199 | 0000-0000-0000-3100
|
| | | MSR 0000019A | 0000-0000-0000-0000
|
| | | MSR 0000019B | 0000-0000-0000-0010
|
| | | MSR 0000019C | 0000-0000-882F-2800 [S200]
|
| | | MSR 0000019C | 0000-0000-882F-2800 [S200]
|
| | | MSR 0000019C | 0000-0000-882F-2800
|
| | | MSR 0000019D | 0000-0000-0000-0000
|
| | | MSR 000001A0 | 0000-0000-0085-0089
|
| | | MSR 000001A2 | 0000-0000-8069-1600
|
| | | MSR 000001A4 | 0000-0000-0000-0000
|
| | | MSR 000001AA | 0000-0000-0000-30C2
|
| | | MSR 000001AC | < FAILED >
|
| | | MSR 000001AD | 2F2F-2F2F-2F2F-3131
|
| | | MSR 000001AE | 0807-0605-0403-0201
|
| | | MSR 000001AF | < FAILED >
|
| | | MSR 000001B0 | 0000-0000-0000-0006
|
| | | MSR 000001B1 | 0000-0000-882D-0800
|
| | | MSR 000001B2 | 0000-0000-0200-0000
|
| | | MSR 000001FC | 0000-0000-00CC-005F
|
| | | MSR 00000300 | < FAILED >
|
| | | MSR 0000030A | 0000-0000-0000-0000 [S200]
|
| | | MSR 0000030A | 0000-0000-0000-0000 [S200]
|
| | | MSR 0000030A | 0000-0000-0000-0000
|
| | | MSR 0000030B | 0000-0000-0000-0000 [S200]
|
| | | MSR 0000030B | 0000-0000-0000-0000 [S200]
|
| | | MSR 0000030B | 0000-0000-0000-0000
|
| | | MSR 00000480 | 03DA-0600-0000-0015
|
| | | MSR 00000481 | 0000-00FF-0000-0016
|
| | | MSR 00000482 | FFFB-FFFE-0401-E172
|
| | | MSR 00000483 | FF7F-FFFF-0003-6DFF
|
| | | MSR 00000484 | 007E-FFFF-0000-11FF
|
| | | MSR 00000485 | 0000-0000-7004-C1E7
|
| | | MSR 00000486 | 0000-0000-8000-0021
|
| | | MSR 00000487 | 0000-0000-FFFF-FFFF
|
| | | MSR 00000488 | 0000-0000-0000-2000
|
| | | MSR 00000489 | 0000-0000-1BF7-6FFF
|
| | | MSR 0000048A | 0000-0000-0000-002E
|
| | | MSR 0000048B | C75F-7FFF-0000-0000
|
| | | MSR 0000048C | 0000-0F01-06F3-4141
|
| | | MSR 0000048D | 0000-00FF-0000-0016
|
| | | MSR 0000048E | FFFB-FFFE-0400-6172
|
| | | MSR 0000048F | FF7F-FFFF-0003-6DFB
|
| | | MSR 00000490 | 007E-FFFF-0000-11FB
|
| | | MSR 00000601 | 0000-0000-0000-0278
|
| | | MSR 00000602 | < FAILED >
|
| | | MSR 00000603 | 0036-0000-0036-3636
|
| | | MSR 00000604 | < FAILED >
|
| | | MSR 00000606 | 0000-0000-000A-0E03
|
| | | MSR 0000060A | 0000-0000-0000-0000
|
| | | MSR 0000060B | 0000-0000-0000-0000
|
| | | MSR 0000060C | 0000-0000-0000-0000
|
| | | MSR 0000060D | 0000-0027-7E61-3843
|
| | | MSR 00000610 | 0042-8250-00DD-8118
|
| | | MSR 00000611 | 0000-0000-01CE-36B7 [S200]
|
| | | MSR 00000611 | 0000-0000-01CE-9923 [S200]
|
| | | MSR 00000611 | 0000-0000-01CE-FDC3
|
| | | MSR 00000613 | 0000-0000-0000-0055
|
| | | MSR 00000614 | 0012-0000-0000-0118
|
| | | MSR 00000618 | 0000-0000-0000-0000
|
| | | MSR 00000619 | 0000-0000-0000-0000 [S200]
|
| | | MSR 00000619 | 0000-0000-0000-0000 [S200]
|
| | | MSR 00000619 | 0000-0000-0000-0000
|
| | | MSR 0000061B | 0000-0000-0000-0000
|
| | | MSR 0000061C | < FAILED >
|
| | | MSR 0000061E | < FAILED >
|
| | | MSR 00000620 | 0000-0000-0000-0825
|
| | | MSR 00000621 | 0000-0000-1BB5-0012
|
| | | MSR 00000638 | 0000-0000-0000-0000
|
| | | MSR 00000639 | 0000-0000-00CB-4A0D [S200]
|
| | | MSR 00000639 | 0000-0000-00CB-554A [S200]
|
| | | MSR 00000639 | 0000-0000-00CB-5FD5
|
| | | MSR 0000063A | 0000-0000-0000-0000
|
| | | MSR 0000063B | < FAILED >
|
| | | MSR 00000640 | 0000-0000-0000-0000
|
| | | MSR 00000641 | 0000-0000-0000-0018 [S200]
|
| | | MSR 00000641 | 0000-0000-0000-0018 [S200]
|
| | | MSR 00000641 | 0000-0000-0000-0018
|
| | | MSR 00000642 | 0000-0000-0000-0010
|
| | | MSR 00000648 | 0000-0000-0000-0019
|
| | | MSR 00000649 | 0000-0000-0000-0000
|
| | | MSR 0000064A | 0000-0000-0000-0000
|
| | | MSR 0000064B | 0000-0000-8000-0000
|
| | | MSR 0000064C | 0000-0000-0000-0000
|
| | | MSR 00000650 | 2C2C-2C2C-2C2C-2C2C
|
| | | MSR 00000651 | 0807-0605-0403-0201
|
| | | MSR 00000690 | < FAILED >
|
| | | MSR 000006B0 | 0000-0000-0100-0000
|
| | | MSR 000006B1 | 0000-0000-0100-0000
|
| | | MSR 00000770 | 0000-0000-0000-0001
|
| | | MSR 00000771 | 0000-0000-0122-284F
|
| | | MSR 00000772 | 0000-0000-8000-FF01
|
| | | MSR 00000773 | 0000-0000-0000-0005
|
| | | MSR 00000774 | 0000-019E-3F00-4F02
|
| | | MSR 00000777 | 0000-0000-0000-0000
|
| | | MSR 00000832 | 0000-0000-0002-00D1
|
| | | MSR 00000838 | 0000-0000-0000-0209
|
| | | MSR 00000839 | 0000-0000-0000-01C7
|
| | | MSR 0000083E | 0000-0000-0000-000A
|
|
|
| | MSR Registers (CPU #1):
|
| | | MSR 00000017 | 0004-0000-0000-0000 [PlatID = 1]
|
| | | MSR 0000001B | 0000-0000-FEE0-0C00
|
| | | MSR 00000035 | 0000-0000-000A-000A
|
| | | MSR 00000048 | 0000-0000-0000-0001
|
| | | MSR 00000049 | < FAILED >
|
| | | MSR 0000008B | 0000-0121-0000-0000
|
| | | MSR 000000CE | 0804-0838-F081-1900 [eD = 0]
|
| | | MSR 000000E7 | 0000-000A-FD69-1BAF
|
| | | MSR 000000E8 | 0000-0010-F61C-D005
|
| | | MSR 0000010A | 0000-0000-0DF9-FD6B
|
| | | MSR 0000010B | < FAILED >
|
| | | MSR 00000194 | 0000-0000-0010-0000
|
| | | MSR 00000198 | 0000-1762-0000-1500
|
| | | MSR 00000199 | 0000-0000-0000-3100
|
| | | MSR 0000019A | 0000-0000-0000-0000
|
| | | MSR 0000019B | 0000-0000-0000-0010
|
| | | MSR 0000019C | 0000-0000-882F-3800
|
| | | MSR 0000019D | 0000-0000-0000-0000
|
| | | MSR 000001A0 | 0000-0000-0085-0089
|
| | | MSR 000001A2 | 0000-0000-8069-1600
|
| | | MSR 000001A4 | 0000-0000-0000-0000
|
| | | MSR 000001AA | 0000-0000-0000-30C2
|
| | | MSR 000001AC | < FAILED >
|
| | | MSR 000001AD | 2F2F-2F2F-2F2F-3131
|
| | | MSR 000001AE | 0807-0605-0403-0201
|
| | | MSR 000001AF | < FAILED >
|
| | | MSR 000001B0 | 0000-0000-0000-0006
|
| | | MSR 000001B1 | 0000-0000-882D-0800
|
| | | MSR 000001B2 | 0000-0000-0200-0000
|
| | | MSR 000001FC | 0000-0000-00CC-005F
|
| | | MSR 00000300 | < FAILED >
|
| | | MSR 0000030A | 0000-0000-0000-0000
|
| | | MSR 0000030B | 0000-0000-0000-0000
|
| | | MSR 00000480 | 03DA-0600-0000-0015
|
| | | MSR 00000481 | 0000-00FF-0000-0016
|
| | | MSR 00000482 | FFFB-FFFE-0401-E172
|
| | | MSR 00000483 | FF7F-FFFF-0003-6DFF
|
| | | MSR 00000484 | 007E-FFFF-0000-11FF
|
| | | MSR 00000485 | 0000-0000-7004-C1E7
|
| | | MSR 00000486 | 0000-0000-8000-0021
|
| | | MSR 00000487 | 0000-0000-FFFF-FFFF
|
| | | MSR 00000488 | 0000-0000-0000-2000
|
| | | MSR 00000489 | 0000-0000-1BF7-6FFF
|
| | | MSR 0000048A | 0000-0000-0000-002E
|
| | | MSR 0000048B | C75F-7FFF-0000-0000
|
| | | MSR 0000048C | 0000-0F01-06F3-4141
|
| | | MSR 0000048D | 0000-00FF-0000-0016
|
| | | MSR 0000048E | FFFB-FFFE-0400-6172
|
| | | MSR 0000048F | FF7F-FFFF-0003-6DFB
|
| | | MSR 00000490 | 007E-FFFF-0000-11FB
|
| | | MSR 00000601 | 0000-0000-0000-0278
|
| | | MSR 00000602 | < FAILED >
|
| | | MSR 00000603 | 0036-0000-0036-3636
|
| | | MSR 00000604 | < FAILED >
|
| | | MSR 00000606 | 0000-0000-000A-0E03
|
| | | MSR 0000060A | 0000-0000-0000-0000
|
| | | MSR 0000060B | 0000-0000-0000-0000
|
| | | MSR 0000060C | 0000-0000-0000-0000
|
| | | MSR 0000060D | 0000-0028-4BA1-6026
|
| | | MSR 00000610 | 0042-8250-00DD-8118
|
| | | MSR 00000611 | 0000-0000-01D1-3F5F
|
| | | MSR 00000613 | 0000-0000-0000-0055
|
| | | MSR 00000614 | 0012-0000-0000-0118
|
| | | MSR 00000618 | 0000-0000-0000-0000
|
| | | MSR 00000619 | 0000-0000-0000-0000
|
| | | MSR 0000061B | 0000-0000-0000-0000
|
| | | MSR 0000061C | < FAILED >
|
| | | MSR 0000061E | < FAILED >
|
| | | MSR 00000620 | 0000-0000-0000-0825
|
| | | MSR 00000621 | 0000-0000-1BB5-0011
|
| | | MSR 00000638 | 0000-0000-0000-0000
|
| | | MSR 00000639 | 0000-0000-00CB-73AD
|
| | | MSR 0000063A | 0000-0000-0000-0000
|
| | | MSR 0000063B | < FAILED >
|
| | | MSR 00000640 | 0000-0000-0000-0000
|
| | | MSR 00000641 | 0000-0000-0000-0018
|
| | | MSR 00000642 | 0000-0000-0000-0010
|
| | | MSR 00000648 | 0000-0000-0000-0019
|
| | | MSR 00000649 | 0000-0000-0000-0000
|
| | | MSR 0000064A | 0000-0000-0000-0000
|
| | | MSR 0000064B | 0000-0000-8000-0000
|
| | | MSR 0000064C | 0000-0000-0000-0000
|
| | | MSR 00000650 | 2C2C-2C2C-2C2C-2C2C
|
| | | MSR 00000651 | 0807-0605-0403-0201
|
| | | MSR 00000690 | < FAILED >
|
| | | MSR 000006B0 | 0000-0000-0100-0000
|
| | | MSR 000006B1 | 0000-0000-0100-0000
|
| | | MSR 00000770 | 0000-0000-0000-0001
|
| | | MSR 00000771 | 0000-0000-0122-284F
|
| | | MSR 00000772 | 0000-0000-8000-FF01
|
| | | MSR 00000773 | 0000-0000-0000-0005
|
| | | MSR 00000774 | 0000-019E-3F00-4F02
|
| | | MSR 00000777 | 0000-0000-0000-0000
|
| | | MSR 00000832 | 0000-0000-0002-00D1
|
| | | MSR 00000838 | 0000-0000-0000-0209
|
| | | MSR 00000839 | 0000-0000-0000-0157
|
| | | MSR 0000083E | 0000-0000-0000-000A
|
|
|
| | MSR Registers (CPU #2):
|
| | | MSR 00000017 | 0004-0000-0000-0000 [PlatID = 1]
|
| | | MSR 0000001B | 0000-0000-FEE0-0C00
|
| | | MSR 0000002A | 0000-0000-0000-0000
|
| | | MSR 00000035 | 0000-0000-000A-000A
|
| | | MSR 00000048 | 0000-0000-0000-0001
|
| | | MSR 00000049 | < FAILED >
|
| | | MSR 0000008B | 0000-0121-0000-0000
|
| | | MSR 000000CD | < FAILED >
|
| | | MSR 000000CE | 0804-0838-F081-1900 [eD = 0]
|
| | | MSR 000000E7 | 0000-0003-0591-2F50
|
| | | MSR 000000E8 | 0000-0003-BC39-95EA
|
| | | MSR 000000EE | < FAILED >
|
| | | MSR 0000010A | 0000-0000-0DF9-FD6B
|
| | | MSR 0000010B | < FAILED >
|
| | | MSR 0000011E | < FAILED >
|
| | | MSR 00000194 | 0000-0000-0010-0000
|
| | | MSR 00000198 | 0000-17C3-0000-1300
|
| | | MSR 00000199 | 0000-0000-0000-3100
|
| | | MSR 0000019A | 0000-0000-0000-0000
|
| | | MSR 0000019B | 0000-0000-0000-0010
|
| | | MSR 0000019C | 0000-0000-8831-2800
|
| | | MSR 0000019D | 0000-0000-0000-0000
|
| | | MSR 000001A0 | 0000-0000-0085-0089
|
| | | MSR 000001A2 | 0000-0000-8069-1600
|
| | | MSR 000001A4 | 0000-0000-0000-0084
|
| | | MSR 000001AA | 0000-0000-0000-30C2
|
| | | MSR 000001AC | < FAILED >
|
| | | MSR 000001AD | 2F2F-2F2F-2F2F-3131
|
| | | MSR 000001AE | 0807-0605-0403-0201
|
| | | MSR 000001AF | < FAILED >
|
| | | MSR 000001B0 | 0000-0000-0000-0006
|
| | | MSR 000001B1 | 0000-0000-882F-0800
|
| | | MSR 000001B2 | 0000-0000-0200-0000
|
| | | MSR 000001FC | 0000-0000-00CC-005F
|
| | | MSR 00000300 | < FAILED >
|
| | | MSR 0000030A | 0000-0000-0000-0000
|
| | | MSR 0000030B | 0000-0000-0000-0000
|
| | | MSR 00000480 | 03DA-0600-0000-0015
|
| | | MSR 00000481 | 0000-00FF-0000-0016
|
| | | MSR 00000482 | FFFB-FFFE-0401-E172
|
| | | MSR 00000483 | FF7F-FFFF-0003-6DFF
|
| | | MSR 00000484 | 007E-FFFF-0000-11FF
|
| | | MSR 00000485 | 0000-0000-7004-C1E7
|
| | | MSR 00000486 | 0000-0000-8000-0021
|
| | | MSR 00000487 | 0000-0000-FFFF-FFFF
|
| | | MSR 00000488 | 0000-0000-0000-2000
|
| | | MSR 00000489 | 0000-0000-1BF7-6FFF
|
| | | MSR 0000048A | 0000-0000-0000-002E
|
| | | MSR 0000048B | C75F-7FFF-0000-0000
|
| | | MSR 0000048C | 0000-0F01-06F3-4141
|
| | | MSR 0000048D | 0000-00FF-0000-0016
|
| | | MSR 0000048E | FFFB-FFFE-0400-6172
|
| | | MSR 0000048F | FF7F-FFFF-0003-6DFB
|
| | | MSR 00000490 | 007E-FFFF-0000-11FB
|
| | | MSR 00000601 | 0000-0000-0000-0278
|
| | | MSR 00000602 | < FAILED >
|
| | | MSR 00000603 | 0036-0000-0036-3636
|
| | | MSR 00000604 | < FAILED >
|
| | | MSR 00000606 | 0000-0000-000A-0E03
|
| | | MSR 0000060A | 0000-0000-0000-0000
|
| | | MSR 0000060B | 0000-0000-0000-0000
|
| | | MSR 0000060C | 0000-0000-0000-0000
|
| | | MSR 0000060D | 0000-0028-4BA1-6026
|
| | | MSR 00000610 | 0042-8250-00DD-8118
|
| | | MSR 00000611 | 0000-0000-01D1-401E
|
| | | MSR 00000613 | 0000-0000-0000-0055
|
| | | MSR 00000614 | 0012-0000-0000-0118
|
| | | MSR 00000618 | 0000-0000-0000-0000
|
| | | MSR 00000619 | 0000-0000-0000-0000
|
| | | MSR 0000061B | 0000-0000-0000-0000
|
| | | MSR 0000061C | < FAILED >
|
| | | MSR 0000061E | < FAILED >
|
| | | MSR 00000620 | 0000-0000-0000-0825
|
| | | MSR 00000621 | 0000-0000-1BB5-0012
|
| | | MSR 00000638 | 0000-0000-0000-0000
|
| | | MSR 00000639 | 0000-0000-00CB-73EE
|
| | | MSR 0000063A | 0000-0000-0000-0000
|
| | | MSR 0000063B | < FAILED >
|
| | | MSR 00000640 | 0000-0000-0000-0000
|
| | | MSR 00000641 | 0000-0000-0000-0018
|
| | | MSR 00000642 | 0000-0000-0000-0010
|
| | | MSR 00000648 | 0000-0000-0000-0019
|
| | | MSR 00000649 | 0000-0000-0000-0000
|
| | | MSR 0000064A | 0000-0000-0000-0000
|
| | | MSR 0000064B | 0000-0000-8000-0000
|
| | | MSR 0000064C | 0000-0000-0000-0000
|
| | | MSR 00000650 | 2C2C-2C2C-2C2C-2C2C
|
| | | MSR 00000651 | 0807-0605-0403-0201
|
| | | MSR 00000660 | 0000-000A-9E7C-EE14
|
| | | MSR 00000661 | < FAILED >
|
| | | MSR 00000662 | < FAILED >
|
| | | MSR 00000663 | < FAILED >
|
| | | MSR 00000664 | 0000-0048-1408-AF3C
|
| | | MSR 00000665 | < FAILED >
|
| | | MSR 00000666 | < FAILED >
|
| | | MSR 00000667 | < FAILED >
|
| | | MSR 00000668 | < FAILED >
|
| | | MSR 00000669 | < FAILED >
|
| | | MSR 0000066A | < FAILED >
|
| | | MSR 0000066B | < FAILED >
|
| | | MSR 0000066C | < FAILED >
|
| | | MSR 0000066D | < FAILED >
|
| | | MSR 0000066E | < FAILED >
|
| | | MSR 0000066F | < FAILED >
|
| | | MSR 00000670 | < FAILED >
|
| | | MSR 00000671 | < FAILED >
|
| | | MSR 00000672 | < FAILED >
|
| | | MSR 00000673 | < FAILED >
|
| | | MSR 00000674 | < FAILED >
|
| | | MSR 00000675 | < FAILED >
|
| | | MSR 00000676 | < FAILED >
|
| | | MSR 00000677 | < FAILED >
|
| | | MSR 00000690 | < FAILED >
|
| | | MSR 000006B0 | 0000-0000-0100-0000
|
| | | MSR 000006B1 | 0000-0000-0100-0000
|
| | | MSR 00000770 | 0000-0000-0000-0001
|
| | | MSR 00000771 | 0000-0000-0115-1B3E
|
| | | MSR 00000772 | 0000-0000-8000-FF01
|
| | | MSR 00000773 | 0000-0000-0000-0005
|
| | | MSR 00000774 | 0000-019E-3F00-3E01
|
| | | MSR 00000777 | 0000-0000-0000-0004
|
| | | MSR 00000832 | 0000-0000-0000-00D1
|
| | | MSR 00000838 | 0000-0000-0000-0258
|
| | | MSR 00000839 | 0000-0000-0000-01F7
|
| | | MSR 0000083E | 0000-0000-0000-000A
|
|
|
| | MSR Registers (CPU #3):
|
| | | MSR 00000017 | 0004-0000-0000-0000 [PlatID = 1]
|
| | | MSR 0000001B | 0000-0000-FEE0-0C00
|
| | | MSR 0000002A | 0000-0000-0000-0000
|
| | | MSR 00000035 | 0000-0000-000A-000A
|
| | | MSR 00000048 | 0000-0000-0000-0001
|
| | | MSR 00000049 | < FAILED >
|
| | | MSR 0000008B | 0000-0121-0000-0000
|
| | | MSR 000000CD | < FAILED >
|
| | | MSR 000000CE | 0804-0838-F081-1900 [eD = 0]
|
| | | MSR 000000E7 | 0000-0003-A8AC-2474
|
| | | MSR 000000E8 | 0000-0004-AAF0-D0C3
|
| | | MSR 000000EE | < FAILED >
|
| | | MSR 0000010A | 0000-0000-0DF9-FD6B
|
| | | MSR 0000010B | < FAILED >
|
| | | MSR 0000011E | < FAILED >
|
| | | MSR 00000194 | 0000-0000-0010-0000
|
| | | MSR 00000198 | 0000-17C3-0000-1300
|
| | | MSR 00000199 | 0000-0000-0000-3100
|
| | | MSR 0000019A | 0000-0000-0000-0000
|
| | | MSR 0000019B | 0000-0000-0000-0010
|
| | | MSR 0000019C | 0000-0000-8831-2800
|
| | | MSR 0000019D | 0000-0000-0000-0000
|
| | | MSR 000001A0 | 0000-0000-0085-0089
|
| | | MSR 000001A2 | 0000-0000-8069-1600
|
| | | MSR 000001A4 | 0000-0000-0000-0084
|
| | | MSR 000001AA | 0000-0000-0000-30C2
|
| | | MSR 000001AC | < FAILED >
|
| | | MSR 000001AD | 2F2F-2F2F-2F2F-3131
|
| | | MSR 000001AE | 0807-0605-0403-0201
|
| | | MSR 000001AF | < FAILED >
|
| | | MSR 000001B0 | 0000-0000-0000-0006
|
| | | MSR 000001B1 | 0000-0000-882E-0800
|
| | | MSR 000001B2 | 0000-0000-0200-0000
|
| | | MSR 000001FC | 0000-0000-00CC-005F
|
| | | MSR 00000300 | < FAILED >
|
| | | MSR 0000030A | 0000-0000-0000-0000
|
| | | MSR 0000030B | 0000-0000-0000-0000
|
| | | MSR 00000480 | 03DA-0600-0000-0015
|
| | | MSR 00000481 | 0000-00FF-0000-0016
|
| | | MSR 00000482 | FFFB-FFFE-0401-E172
|
| | | MSR 00000483 | FF7F-FFFF-0003-6DFF
|
| | | MSR 00000484 | 007E-FFFF-0000-11FF
|
| | | MSR 00000485 | 0000-0000-7004-C1E7
|
| | | MSR 00000486 | 0000-0000-8000-0021
|
| | | MSR 00000487 | 0000-0000-FFFF-FFFF
|
| | | MSR 00000488 | 0000-0000-0000-2000
|
| | | MSR 00000489 | 0000-0000-1BF7-6FFF
|
| | | MSR 0000048A | 0000-0000-0000-002E
|
| | | MSR 0000048B | C75F-7FFF-0000-0000
|
| | | MSR 0000048C | 0000-0F01-06F3-4141
|
| | | MSR 0000048D | 0000-00FF-0000-0016
|
| | | MSR 0000048E | FFFB-FFFE-0400-6172
|
| | | MSR 0000048F | FF7F-FFFF-0003-6DFB
|
| | | MSR 00000490 | 007E-FFFF-0000-11FB
|
| | | MSR 00000601 | 0000-0000-0000-0278
|
| | | MSR 00000602 | < FAILED >
|
| | | MSR 00000603 | 0036-0000-0036-3636
|
| | | MSR 00000604 | < FAILED >
|
| | | MSR 00000606 | 0000-0000-000A-0E03
|
| | | MSR 0000060A | 0000-0000-0000-0000
|
| | | MSR 0000060B | 0000-0000-0000-0000
|
| | | MSR 0000060C | 0000-0000-0000-0000
|
| | | MSR 0000060D | 0000-0028-4BA1-6026
|
| | | MSR 00000610 | 0042-8250-00DD-8118
|
| | | MSR 00000611 | 0000-0000-01D1-401E
|
| | | MSR 00000613 | 0000-0000-0000-0055
|
| | | MSR 00000614 | 0012-0000-0000-0118
|
| | | MSR 00000618 | 0000-0000-0000-0000
|
| | | MSR 00000619 | 0000-0000-0000-0000
|
| | | MSR 0000061B | 0000-0000-0000-0000
|
| | | MSR 0000061C | < FAILED >
|
| | | MSR 0000061E | < FAILED >
|
| | | MSR 00000620 | 0000-0000-0000-0825
|
| | | MSR 00000621 | 0000-0000-1BB5-0012
|
| | | MSR 00000638 | 0000-0000-0000-0000
|
| | | MSR 00000639 | 0000-0000-00CB-7428
|
| | | MSR 0000063A | 0000-0000-0000-0000
|
| | | MSR 0000063B | < FAILED >
|
| | | MSR 00000640 | 0000-0000-0000-0000
|
| | | MSR 00000641 | 0000-0000-0000-0018
|
| | | MSR 00000642 | 0000-0000-0000-0010
|
| | | MSR 00000648 | 0000-0000-0000-0019
|
| | | MSR 00000649 | 0000-0000-0000-0000
|
| | | MSR 0000064A | 0000-0000-0000-0000
|
| | | MSR 0000064B | 0000-0000-8000-0000
|
| | | MSR 0000064C | 0000-0000-0000-0000
|
| | | MSR 00000650 | 2C2C-2C2C-2C2C-2C2C
|
| | | MSR 00000651 | 0807-0605-0403-0201
|
| | | MSR 00000660 | 0000-000A-12C6-FB44
|
| | | MSR 00000661 | < FAILED >
|
| | | MSR 00000662 | < FAILED >
|
| | | MSR 00000663 | < FAILED >
|
| | | MSR 00000664 | 0000-0048-1408-AF3C
|
| | | MSR 00000665 | < FAILED >
|
| | | MSR 00000666 | < FAILED >
|
| | | MSR 00000667 | < FAILED >
|
| | | MSR 00000668 | < FAILED >
|
| | | MSR 00000669 | < FAILED >
|
| | | MSR 0000066A | < FAILED >
|
| | | MSR 0000066B | < FAILED >
|
| | | MSR 0000066C | < FAILED >
|
| | | MSR 0000066D | < FAILED >
|
| | | MSR 0000066E | < FAILED >
|
| | | MSR 0000066F | < FAILED >
|
| | | MSR 00000670 | < FAILED >
|
| | | MSR 00000671 | < FAILED >
|
| | | MSR 00000672 | < FAILED >
|
| | | MSR 00000673 | < FAILED >
|
| | | MSR 00000674 | < FAILED >
|
| | | MSR 00000675 | < FAILED >
|
| | | MSR 00000676 | < FAILED >
|
| | | MSR 00000677 | < FAILED >
|
| | | MSR 00000690 | < FAILED >
|
| | | MSR 000006B0 | 0000-0000-0100-0000
|
| | | MSR 000006B1 | 0000-0000-0100-0000
|
| | | MSR 00000770 | 0000-0000-0000-0001
|
| | | MSR 00000771 | 0000-0000-0115-1B3E
|
| | | MSR 00000772 | 0000-0000-8000-FF01
|
| | | MSR 00000773 | 0000-0000-0000-0005
|
| | | MSR 00000774 | 0000-019E-3F00-3E01
|
| | | MSR 00000777 | 0000-0000-0000-0004
|
| | | MSR 00000832 | 0000-0000-0000-00D1
|
| | | MSR 00000838 | 0000-0000-0000-0258
|
| | | MSR 00000839 | 0000-0000-0000-0203
|
| | | MSR 0000083E | 0000-0000-0000-000A
|
|
|
| | MSR Registers (CPU #4):
|
| | | MSR 00000017 | 0004-0000-0000-0000 [PlatID = 1]
|
| | | MSR 0000001B | 0000-0000-FEE0-0C00
|
| | | MSR 0000002A | 0000-0000-0000-0000
|
| | | MSR 00000035 | 0000-0000-000A-000A
|
| | | MSR 00000048 | 0000-0000-0000-0001
|
| | | MSR 00000049 | < FAILED >
|
| | | MSR 0000008B | 0000-0121-0000-0000
|
| | | MSR 000000CD | < FAILED >
|
| | | MSR 000000CE | 0804-0838-F081-1900 [eD = 0]
|
| | | MSR 000000E7 | 0000-0003-59D5-DCC8
|
| | | MSR 000000E8 | 0000-0004-5C0D-C688
|
| | | MSR 000000EE | < FAILED >
|
| | | MSR 0000010A | 0000-0000-0DF9-FD6B
|
| | | MSR 0000010B | < FAILED >
|
| | | MSR 0000011E | < FAILED >
|
| | | MSR 00000194 | 0000-0000-0010-0000
|
| | | MSR 00000198 | 0000-17C3-0000-1300
|
| | | MSR 00000199 | 0000-0000-0000-3100
|
| | | MSR 0000019A | 0000-0000-0000-0000
|
| | | MSR 0000019B | 0000-0000-0000-0010
|
| | | MSR 0000019C | 0000-0000-8831-2800
|
| | | MSR 0000019D | 0000-0000-0000-0000
|
| | | MSR 000001A0 | 0000-0000-0085-0089
|
| | | MSR 000001A2 | 0000-0000-8069-1600
|
| | | MSR 000001A4 | 0000-0000-0000-0084
|
| | | MSR 000001AA | 0000-0000-0000-30C2
|
| | | MSR 000001AC | < FAILED >
|
| | | MSR 000001AD | 2F2F-2F2F-2F2F-3131
|
| | | MSR 000001AE | 0807-0605-0403-0201
|
| | | MSR 000001AF | < FAILED >
|
| | | MSR 000001B0 | 0000-0000-0000-0006
|
| | | MSR 000001B1 | 0000-0000-882F-0800
|
| | | MSR 000001B2 | 0000-0000-0200-0000
|
| | | MSR 000001FC | 0000-0000-00CC-005F
|
| | | MSR 00000300 | < FAILED >
|
| | | MSR 0000030A | 0000-0000-0000-0000
|
| | | MSR 0000030B | 0000-0000-0000-0000
|
| | | MSR 00000480 | 03DA-0600-0000-0015
|
| | | MSR 00000481 | 0000-00FF-0000-0016
|
| | | MSR 00000482 | FFFB-FFFE-0401-E172
|
| | | MSR 00000483 | FF7F-FFFF-0003-6DFF
|
| | | MSR 00000484 | 007E-FFFF-0000-11FF
|
| | | MSR 00000485 | 0000-0000-7004-C1E7
|
| | | MSR 00000486 | 0000-0000-8000-0021
|
| | | MSR 00000487 | 0000-0000-FFFF-FFFF
|
| | | MSR 00000488 | 0000-0000-0000-2000
|
| | | MSR 00000489 | 0000-0000-1BF7-6FFF
|
| | | MSR 0000048A | 0000-0000-0000-002E
|
| | | MSR 0000048B | C75F-7FFF-0000-0000
|
| | | MSR 0000048C | 0000-0F01-06F3-4141
|
| | | MSR 0000048D | 0000-00FF-0000-0016
|
| | | MSR 0000048E | FFFB-FFFE-0400-6172
|
| | | MSR 0000048F | FF7F-FFFF-0003-6DFB
|
| | | MSR 00000490 | 007E-FFFF-0000-11FB
|
| | | MSR 00000601 | 0000-0000-0000-0278
|
| | | MSR 00000602 | < FAILED >
|
| | | MSR 00000603 | 0036-0000-0036-3636
|
| | | MSR 00000604 | < FAILED >
|
| | | MSR 00000606 | 0000-0000-000A-0E03
|
| | | MSR 0000060A | 0000-0000-0000-0000
|
| | | MSR 0000060B | 0000-0000-0000-0000
|
| | | MSR 0000060C | 0000-0000-0000-0000
|
| | | MSR 0000060D | 0000-0028-4BA1-6026
|
| | | MSR 00000610 | 0042-8250-00DD-8118
|
| | | MSR 00000611 | 0000-0000-01D1-40C9
|
| | | MSR 00000613 | 0000-0000-0000-0055
|
| | | MSR 00000614 | 0012-0000-0000-0118
|
| | | MSR 00000618 | 0000-0000-0000-0000
|
| | | MSR 00000619 | 0000-0000-0000-0000
|
| | | MSR 0000061B | 0000-0000-0000-0000
|
| | | MSR 0000061C | < FAILED >
|
| | | MSR 0000061E | < FAILED >
|
| | | MSR 00000620 | 0000-0000-0000-0825
|
| | | MSR 00000621 | 0000-0000-1BB5-0012
|
| | | MSR 00000638 | 0000-0000-0000-0000
|
| | | MSR 00000639 | 0000-0000-00CB-7428
|
| | | MSR 0000063A | 0000-0000-0000-0000
|
| | | MSR 0000063B | < FAILED >
|
| | | MSR 00000640 | 0000-0000-0000-0000
|
| | | MSR 00000641 | 0000-0000-0000-0018
|
| | | MSR 00000642 | 0000-0000-0000-0010
|
| | | MSR 00000648 | 0000-0000-0000-0019
|
| | | MSR 00000649 | 0000-0000-0000-0000
|
| | | MSR 0000064A | 0000-0000-0000-0000
|
| | | MSR 0000064B | 0000-0000-8000-0000
|
| | | MSR 0000064C | 0000-0000-0000-0000
|
| | | MSR 00000650 | 2C2C-2C2C-2C2C-2C2C
|
| | | MSR 00000651 | 0807-0605-0403-0201
|
| | | MSR 00000660 | 0000-0009-E178-7D92
|
| | | MSR 00000661 | < FAILED >
|
| | | MSR 00000662 | < FAILED >
|
| | | MSR 00000663 | < FAILED >
|
| | | MSR 00000664 | 0000-0048-1408-AF3C
|
| | | MSR 00000665 | < FAILED >
|
| | | MSR 00000666 | < FAILED >
|
| | | MSR 00000667 | < FAILED >
|
| | | MSR 00000668 | < FAILED >
|
| | | MSR 00000669 | < FAILED >
|
| | | MSR 0000066A | < FAILED >
|
| | | MSR 0000066B | < FAILED >
|
| | | MSR 0000066C | < FAILED >
|
| | | MSR 0000066D | < FAILED >
|
| | | MSR 0000066E | < FAILED >
|
| | | MSR 0000066F | < FAILED >
|
| | | MSR 00000670 | < FAILED >
|
| | | MSR 00000671 | < FAILED >
|
| | | MSR 00000672 | < FAILED >
|
| | | MSR 00000673 | < FAILED >
|
| | | MSR 00000674 | < FAILED >
|
| | | MSR 00000675 | < FAILED >
|
| | | MSR 00000676 | < FAILED >
|
| | | MSR 00000677 | < FAILED >
|
| | | MSR 00000690 | < FAILED >
|
| | | MSR 000006B0 | 0000-0000-0100-0000
|
| | | MSR 000006B1 | 0000-0000-0100-0000
|
| | | MSR 00000770 | 0000-0000-0000-0001
|
| | | MSR 00000771 | 0000-0000-0115-1B3E
|
| | | MSR 00000772 | 0000-0000-8000-FF01
|
| | | MSR 00000773 | 0000-0000-0000-0005
|
| | | MSR 00000774 | 0000-019E-3F00-3E01
|
| | | MSR 00000777 | 0000-0000-0000-0004
|
| | | MSR 00000832 | 0000-0000-0000-00D1
|
| | | MSR 00000838 | 0000-0000-0000-0258
|
| | | MSR 00000839 | 0000-0000-0000-0202
|
| | | MSR 0000083E | 0000-0000-0000-000A
|
|
|
| | MSR Registers (CPU #5):
|
| | | MSR 00000017 | 0004-0000-0000-0000 [PlatID = 1]
|
| | | MSR 0000001B | 0000-0000-FEE0-0C00
|
| | | MSR 0000002A | 0000-0000-0000-0000
|
| | | MSR 00000035 | 0000-0000-000A-000A
|
| | | MSR 00000048 | 0000-0000-0000-0001
|
| | | MSR 00000049 | < FAILED >
|
| | | MSR 0000008B | 0000-0121-0000-0000
|
| | | MSR 000000CD | < FAILED >
|
| | | MSR 000000CE | 0804-0838-F081-1900 [eD = 0]
|
| | | MSR 000000E7 | 0000-0002-7C90-54EC
|
| | | MSR 000000E8 | 0000-0003-1641-BF0B
|
| | | MSR 000000EE | < FAILED >
|
| | | MSR 0000010A | 0000-0000-0DF9-FD6B
|
| | | MSR 0000010B | < FAILED >
|
| | | MSR 0000011E | < FAILED >
|
| | | MSR 00000194 | 0000-0000-0010-0000
|
| | | MSR 00000198 | 0000-17C3-0000-1300
|
| | | MSR 00000199 | 0000-0000-0000-3100
|
| | | MSR 0000019A | 0000-0000-0000-0000
|
| | | MSR 0000019B | 0000-0000-0000-0010
|
| | | MSR 0000019C | 0000-0000-882F-2800
|
| | | MSR 0000019D | 0000-0000-0000-0000
|
| | | MSR 000001A0 | 0000-0000-0085-0089
|
| | | MSR 000001A2 | 0000-0000-8069-1600
|
| | | MSR 000001A4 | 0000-0000-0000-0084
|
| | | MSR 000001AA | 0000-0000-0000-30C2
|
| | | MSR 000001AC | < FAILED >
|
| | | MSR 000001AD | 2F2F-2F2F-2F2F-3131
|
| | | MSR 000001AE | 0807-0605-0403-0201
|
| | | MSR 000001AF | < FAILED >
|
| | | MSR 000001B0 | 0000-0000-0000-0006
|
| | | MSR 000001B1 | 0000-0000-882F-0800
|
| | | MSR 000001B2 | 0000-0000-0200-0000
|
| | | MSR 000001FC | 0000-0000-00CC-005F
|
| | | MSR 00000300 | < FAILED >
|
| | | MSR 0000030A | 0000-0000-0000-0000
|
| | | MSR 0000030B | 0000-0000-0000-0000
|
| | | MSR 00000480 | 03DA-0600-0000-0015
|
| | | MSR 00000481 | 0000-00FF-0000-0016
|
| | | MSR 00000482 | FFFB-FFFE-0401-E172
|
| | | MSR 00000483 | FF7F-FFFF-0003-6DFF
|
| | | MSR 00000484 | 007E-FFFF-0000-11FF
|
| | | MSR 00000485 | 0000-0000-7004-C1E7
|
| | | MSR 00000486 | 0000-0000-8000-0021
|
| | | MSR 00000487 | 0000-0000-FFFF-FFFF
|
| | | MSR 00000488 | 0000-0000-0000-2000
|
| | | MSR 00000489 | 0000-0000-1BF7-6FFF
|
| | | MSR 0000048A | 0000-0000-0000-002E
|
| | | MSR 0000048B | C75F-7FFF-0000-0000
|
| | | MSR 0000048C | 0000-0F01-06F3-4141
|
| | | MSR 0000048D | 0000-00FF-0000-0016
|
| | | MSR 0000048E | FFFB-FFFE-0400-6172
|
| | | MSR 0000048F | FF7F-FFFF-0003-6DFB
|
| | | MSR 00000490 | 007E-FFFF-0000-11FB
|
| | | MSR 00000601 | 0000-0000-0000-0278
|
| | | MSR 00000602 | < FAILED >
|
| | | MSR 00000603 | 0036-0000-0036-3636
|
| | | MSR 00000604 | < FAILED >
|
| | | MSR 00000606 | 0000-0000-000A-0E03
|
| | | MSR 0000060A | 0000-0000-0000-0000
|
| | | MSR 0000060B | 0000-0000-0000-0000
|
| | | MSR 0000060C | 0000-0000-0000-0000
|
| | | MSR 0000060D | 0000-0028-4BA1-6026
|
| | | MSR 00000610 | 0042-8250-00DD-8118
|
| | | MSR 00000611 | 0000-0000-01D1-4174
|
| | | MSR 00000613 | 0000-0000-0000-0055
|
| | | MSR 00000614 | 0012-0000-0000-0118
|
| | | MSR 00000618 | 0000-0000-0000-0000
|
| | | MSR 00000619 | 0000-0000-0000-0000
|
| | | MSR 0000061B | 0000-0000-0000-0000
|
| | | MSR 0000061C | < FAILED >
|
| | | MSR 0000061E | < FAILED >
|
| | | MSR 00000620 | 0000-0000-0000-0825
|
| | | MSR 00000621 | 0000-0000-1BB5-0012
|
| | | MSR 00000638 | 0000-0000-0000-0000
|
| | | MSR 00000639 | 0000-0000-00CB-7461
|
| | | MSR 0000063A | 0000-0000-0000-0000
|
| | | MSR 0000063B | < FAILED >
|
| | | MSR 00000640 | 0000-0000-0000-0000
|
| | | MSR 00000641 | 0000-0000-0000-0018
|
| | | MSR 00000642 | 0000-0000-0000-0010
|
| | | MSR 00000648 | 0000-0000-0000-0019
|
| | | MSR 00000649 | 0000-0000-0000-0000
|
| | | MSR 0000064A | 0000-0000-0000-0000
|
| | | MSR 0000064B | 0000-0000-8000-0000
|
| | | MSR 0000064C | 0000-0000-0000-0000
|
| | | MSR 00000650 | 2C2C-2C2C-2C2C-2C2C
|
| | | MSR 00000651 | 0807-0605-0403-0201
|
| | | MSR 00000660 | 0000-0009-E750-5299
|
| | | MSR 00000661 | < FAILED >
|
| | | MSR 00000662 | < FAILED >
|
| | | MSR 00000663 | < FAILED >
|
| | | MSR 00000664 | 0000-0048-1408-AF3C
|
| | | MSR 00000665 | < FAILED >
|
| | | MSR 00000666 | < FAILED >
|
| | | MSR 00000667 | < FAILED >
|
| | | MSR 00000668 | < FAILED >
|
| | | MSR 00000669 | < FAILED >
|
| | | MSR 0000066A | < FAILED >
|
| | | MSR 0000066B | < FAILED >
|
| | | MSR 0000066C | < FAILED >
|
| | | MSR 0000066D | < FAILED >
|
| | | MSR 0000066E | < FAILED >
|
| | | MSR 0000066F | < FAILED >
|
| | | MSR 00000670 | < FAILED >
|
| | | MSR 00000671 | < FAILED >
|
| | | MSR 00000672 | < FAILED >
|
| | | MSR 00000673 | < FAILED >
|
| | | MSR 00000674 | < FAILED >
|
| | | MSR 00000675 | < FAILED >
|
| | | MSR 00000676 | < FAILED >
|
| | | MSR 00000677 | < FAILED >
|
| | | MSR 00000690 | < FAILED >
|
| | | MSR 000006B0 | 0000-0000-0100-0000
|
| | | MSR 000006B1 | 0000-0000-0100-0000
|
| | | MSR 00000770 | 0000-0000-0000-0001
|
| | | MSR 00000771 | 0000-0000-0115-1B3E
|
| | | MSR 00000772 | 0000-0000-8000-FF01
|
| | | MSR 00000773 | 0000-0000-0000-0005
|
| | | MSR 00000774 | 0000-019E-3F00-3E01
|
| | | MSR 00000777 | 0000-0000-0000-0004
|
| | | MSR 00000832 | 0000-0000-0000-00D1
|
| | | MSR 00000838 | 0000-0000-0000-0258
|
| | | MSR 00000839 | 0000-0000-0000-0203
|
| | | MSR 0000083E | 0000-0000-0000-000A
|
|
|
| | MSR Registers (CPU #6):
|
| | | MSR 00000017 | 0004-0000-0000-0000 [PlatID = 1]
|
| | | MSR 0000001B | 0000-0000-FEE0-0C00
|
| | | MSR 00000035 | 0000-0000-000A-000A
|
| | | MSR 00000048 | 0000-0000-0000-0001
|
| | | MSR 00000049 | < FAILED >
|
| | | MSR 0000008B | 0000-0121-0000-0000
|
| | | MSR 000000CE | 0804-0838-F081-1900 [eD = 0]
|
| | | MSR 000000E7 | 0000-0009-4D8E-E350
|
| | | MSR 000000E8 | 0000-000E-5CE9-BF26
|
| | | MSR 0000010A | 0000-0000-0DF9-FD6B
|
| | | MSR 0000010B | < FAILED >
|
| | | MSR 00000194 | 0000-0000-0010-0000
|
| | | MSR 00000198 | 0000-1762-0000-1200
|
| | | MSR 00000199 | 0000-0000-0000-3100
|
| | | MSR 0000019A | 0000-0000-0000-0000
|
| | | MSR 0000019B | 0000-0000-0000-0010
|
| | | MSR 0000019C | 0000-0000-8831-2800
|
| | | MSR 0000019D | 0000-0000-0000-0000
|
| | | MSR 000001A0 | 0000-0000-0085-0089
|
| | | MSR 000001A2 | 0000-0000-8069-1600
|
| | | MSR 000001A4 | 0000-0000-0000-0000
|
| | | MSR 000001AA | 0000-0000-0000-30C2
|
| | | MSR 000001AC | < FAILED >
|
| | | MSR 000001AD | 2F2F-2F2F-2F2F-3131
|
| | | MSR 000001AE | 0807-0605-0403-0201
|
| | | MSR 000001AF | < FAILED >
|
| | | MSR 000001B0 | 0000-0000-0000-0006
|
| | | MSR 000001B1 | 0000-0000-882D-0800
|
| | | MSR 000001B2 | 0000-0000-0200-0000
|
| | | MSR 000001FC | 0000-0000-00CC-005F
|
| | | MSR 00000300 | < FAILED >
|
| | | MSR 0000030A | 0000-0000-0000-0000
|
| | | MSR 0000030B | 0000-0000-0000-0000
|
| | | MSR 00000480 | 03DA-0600-0000-0015
|
| | | MSR 00000481 | 0000-00FF-0000-0016
|
| | | MSR 00000482 | FFFB-FFFE-0401-E172
|
| | | MSR 00000483 | FF7F-FFFF-0003-6DFF
|
| | | MSR 00000484 | 007E-FFFF-0000-11FF
|
| | | MSR 00000485 | 0000-0000-7004-C1E7
|
| | | MSR 00000486 | 0000-0000-8000-0021
|
| | | MSR 00000487 | 0000-0000-FFFF-FFFF
|
| | | MSR 00000488 | 0000-0000-0000-2000
|
| | | MSR 00000489 | 0000-0000-1BF7-6FFF
|
| | | MSR 0000048A | 0000-0000-0000-002E
|
| | | MSR 0000048B | C75F-7FFF-0000-0000
|
| | | MSR 0000048C | 0000-0F01-06F3-4141
|
| | | MSR 0000048D | 0000-00FF-0000-0016
|
| | | MSR 0000048E | FFFB-FFFE-0400-6172
|
| | | MSR 0000048F | FF7F-FFFF-0003-6DFB
|
| | | MSR 00000490 | 007E-FFFF-0000-11FB
|
| | | MSR 00000601 | 0000-0000-0000-0278
|
| | | MSR 00000602 | < FAILED >
|
| | | MSR 00000603 | 0036-0000-0036-3636
|
| | | MSR 00000604 | < FAILED >
|
| | | MSR 00000606 | 0000-0000-000A-0E03
|
| | | MSR 0000060A | 0000-0000-0000-0000
|
| | | MSR 0000060B | 0000-0000-0000-0000
|
| | | MSR 0000060C | 0000-0000-0000-0000
|
| | | MSR 0000060D | 0000-0028-4BA1-6026
|
| | | MSR 00000610 | 0042-8250-00DD-8118
|
| | | MSR 00000611 | 0000-0000-01D1-4221
|
| | | MSR 00000613 | 0000-0000-0000-0055
|
| | | MSR 00000614 | 0012-0000-0000-0118
|
| | | MSR 00000618 | 0000-0000-0000-0000
|
| | | MSR 00000619 | 0000-0000-0000-0000
|
| | | MSR 0000061B | 0000-0000-0000-0000
|
| | | MSR 0000061C | < FAILED >
|
| | | MSR 0000061E | < FAILED >
|
| | | MSR 00000620 | 0000-0000-0000-0825
|
| | | MSR 00000621 | 0000-0000-1BB5-0012
|
| | | MSR 00000638 | 0000-0000-0000-0000
|
| | | MSR 00000639 | 0000-0000-00CB-749B
|
| | | MSR 0000063A | 0000-0000-0000-0000
|
| | | MSR 0000063B | < FAILED >
|
| | | MSR 00000640 | 0000-0000-0000-0000
|
| | | MSR 00000641 | 0000-0000-0000-0018
|
| | | MSR 00000642 | 0000-0000-0000-0010
|
| | | MSR 00000648 | 0000-0000-0000-0019
|
| | | MSR 00000649 | 0000-0000-0000-0000
|
| | | MSR 0000064A | 0000-0000-0000-0000
|
| | | MSR 0000064B | 0000-0000-8000-0000
|
| | | MSR 0000064C | 0000-0000-0000-0000
|
| | | MSR 00000650 | 2C2C-2C2C-2C2C-2C2C
|
| | | MSR 00000651 | 0807-0605-0403-0201
|
| | | MSR 00000690 | < FAILED >
|
| | | MSR 000006B0 | 0000-0000-0100-0000
|
| | | MSR 000006B1 | 0000-0000-0100-0000
|
| | | MSR 00000770 | 0000-0000-0000-0001
|
| | | MSR 00000771 | 0000-0000-0124-284F
|
| | | MSR 00000772 | 0000-0000-8000-FF01
|
| | | MSR 00000773 | 0000-0000-0000-0005
|
| | | MSR 00000774 | 0000-019E-3F00-4F02
|
| | | MSR 00000777 | 0000-0000-0000-0000
|
| | | MSR 00000832 | 0000-0000-0002-00D1
|
| | | MSR 00000838 | 0000-0000-0000-0209
|
| | | MSR 00000839 | 0000-0000-0000-0155
|
| | | MSR 0000083E | 0000-0000-0000-000A
|
|
|
| | MSR Registers (CPU #7):
|
| | | MSR 00000017 | 0004-0000-0000-0000 [PlatID = 1]
|
| | | MSR 0000001B | 0000-0000-FEE0-0C00
|
| | | MSR 00000035 | 0000-0000-000A-000A
|
| | | MSR 00000048 | 0000-0000-0000-0001
|
| | | MSR 00000049 | < FAILED >
|
| | | MSR 0000008B | 0000-0121-0000-0000
|
| | | MSR 000000CE | 0804-0838-F081-1900 [eD = 0]
|
| | | MSR 000000E7 | 0000-0008-EF99-8967
|
| | | MSR 000000E8 | 0000-000D-A1AD-6743
|
| | | MSR 0000010A | 0000-0000-0DF9-FD6B
|
| | | MSR 0000010B | < FAILED >
|
| | | MSR 00000194 | 0000-0000-0010-0000
|
| | | MSR 00000198 | 0000-1762-0000-1200
|
| | | MSR 00000199 | 0000-0000-0000-3100
|
| | | MSR 0000019A | 0000-0000-0000-0000
|
| | | MSR 0000019B | 0000-0000-0000-0010
|
| | | MSR 0000019C | 0000-0000-882F-2800
|
| | | MSR 0000019D | 0000-0000-0000-0000
|
| | | MSR 000001A0 | 0000-0000-0085-0089
|
| | | MSR 000001A2 | 0000-0000-8069-1600
|
| | | MSR 000001A4 | 0000-0000-0000-0000
|
| | | MSR 000001AA | 0000-0000-0000-30C2
|
| | | MSR 000001AC | < FAILED >
|
| | | MSR 000001AD | 2F2F-2F2F-2F2F-3131
|
| | | MSR 000001AE | 0807-0605-0403-0201
|
| | | MSR 000001AF | < FAILED >
|
| | | MSR 000001B0 | 0000-0000-0000-0006
|
| | | MSR 000001B1 | 0000-0000-882E-0800
|
| | | MSR 000001B2 | 0000-0000-0200-0000
|
| | | MSR 000001FC | 0000-0000-00CC-005F
|
| | | MSR 00000300 | < FAILED >
|
| | | MSR 0000030A | 0000-0000-0000-0000
|
| | | MSR 0000030B | 0000-0000-0000-0000
|
| | | MSR 00000480 | 03DA-0600-0000-0015
|
| | | MSR 00000481 | 0000-00FF-0000-0016
|
| | | MSR 00000482 | FFFB-FFFE-0401-E172
|
| | | MSR 00000483 | FF7F-FFFF-0003-6DFF
|
| | | MSR 00000484 | 007E-FFFF-0000-11FF
|
| | | MSR 00000485 | 0000-0000-7004-C1E7
|
| | | MSR 00000486 | 0000-0000-8000-0021
|
| | | MSR 00000487 | 0000-0000-FFFF-FFFF
|
| | | MSR 00000488 | 0000-0000-0000-2000
|
| | | MSR 00000489 | 0000-0000-1BF7-6FFF
|
| | | MSR 0000048A | 0000-0000-0000-002E
|
| | | MSR 0000048B | C75F-7FFF-0000-0000
|
| | | MSR 0000048C | 0000-0F01-06F3-4141
|
| | | MSR 0000048D | 0000-00FF-0000-0016
|
| | | MSR 0000048E | FFFB-FFFE-0400-6172
|
| | | MSR 0000048F | FF7F-FFFF-0003-6DFB
|
| | | MSR 00000490 | 007E-FFFF-0000-11FB
|
| | | MSR 00000601 | 0000-0000-0000-0278
|
| | | MSR 00000602 | < FAILED >
|
| | | MSR 00000603 | 0036-0000-0036-3636
|
| | | MSR 00000604 | < FAILED >
|
| | | MSR 00000606 | 0000-0000-000A-0E03
|
| | | MSR 0000060A | 0000-0000-0000-0000
|
| | | MSR 0000060B | 0000-0000-0000-0000
|
| | | MSR 0000060C | 0000-0000-0000-0000
|
| | | MSR 0000060D | 0000-0028-4BA1-6026
|
| | | MSR 00000610 | 0042-8250-00DD-8118
|
| | | MSR 00000611 | 0000-0000-01D1-42CD
|
| | | MSR 00000613 | 0000-0000-0000-0055
|
| | | MSR 00000614 | 0012-0000-0000-0118
|
| | | MSR 00000618 | 0000-0000-0000-0000
|
| | | MSR 00000619 | 0000-0000-0000-0000
|
| | | MSR 0000061B | 0000-0000-0000-0000
|
| | | MSR 0000061C | < FAILED >
|
| | | MSR 0000061E | < FAILED >
|
| | | MSR 00000620 | 0000-0000-0000-0825
|
| | | MSR 00000621 | 0000-0000-1BB5-0012
|
| | | MSR 00000638 | 0000-0000-0000-0000
|
| | | MSR 00000639 | 0000-0000-00CB-74DA
|
| | | MSR 0000063A | 0000-0000-0000-0000
|
| | | MSR 0000063B | < FAILED >
|
| | | MSR 00000640 | 0000-0000-0000-0000
|
| | | MSR 00000641 | 0000-0000-0000-0018
|
| | | MSR 00000642 | 0000-0000-0000-0010
|
| | | MSR 00000648 | 0000-0000-0000-0019
|
| | | MSR 00000649 | 0000-0000-0000-0000
|
| | | MSR 0000064A | 0000-0000-0000-0000
|
| | | MSR 0000064B | 0000-0000-8000-0000
|
| | | MSR 0000064C | 0000-0000-0000-0000
|
| | | MSR 00000650 | 2C2C-2C2C-2C2C-2C2C
|
| | | MSR 00000651 | 0807-0605-0403-0201
|
| | | MSR 00000690 | < FAILED >
|
| | | MSR 000006B0 | 0000-0000-0100-0000
|
| | | MSR 000006B1 | 0000-0000-0100-0000
|
| | | MSR 00000770 | 0000-0000-0000-0001
|
| | | MSR 00000771 | 0000-0000-0124-284F
|
| | | MSR 00000772 | 0000-0000-8000-FF01
|
| | | MSR 00000773 | 0000-0000-0000-0005
|
| | | MSR 00000774 | 0000-019E-3F00-4F02
|
| | | MSR 00000777 | 0000-0000-0000-0000
|
| | | MSR 00000832 | 0000-0000-0000-00D1
|
| | | MSR 00000838 | 0000-0000-0000-0258
|
| | | MSR 00000839 | 0000-0000-0000-022B
|
| | | MSR 0000083E | 0000-0000-0000-000A
|
|
|
| | MSR Registers (CPU #8):
|
| | | MSR 00000017 | 0004-0000-0000-0000 [PlatID = 1]
|
| | | MSR 0000001B | 0000-0000-FEE0-0C00
|
| | | MSR 00000035 | 0000-0000-000A-000A
|
| | | MSR 00000048 | 0000-0000-0000-0001
|
| | | MSR 00000049 | < FAILED >
|
| | | MSR 0000008B | 0000-0121-0000-0000
|
| | | MSR 000000CE | 0804-0838-F081-1900 [eD = 0]
|
| | | MSR 000000E7 | 0000-000A-6DC4-DC14
|
| | | MSR 000000E8 | 0000-000F-AC47-884B
|
| | | MSR 0000010A | 0000-0000-0DF9-FD6B
|
| | | MSR 0000010B | < FAILED >
|
| | | MSR 00000194 | 0000-0000-0010-0000
|
| | | MSR 00000198 | 0000-1724-0000-1500
|
| | | MSR 00000199 | 0000-0000-0000-3100
|
| | | MSR 0000019A | 0000-0000-0000-0000
|
| | | MSR 0000019B | 0000-0000-0000-0010
|
| | | MSR 0000019C | 0000-0000-8831-2800
|
| | | MSR 0000019D | 0000-0000-0000-0000
|
| | | MSR 000001A0 | 0000-0000-0085-0089
|
| | | MSR 000001A2 | 0000-0000-8069-1600
|
| | | MSR 000001A4 | 0000-0000-0000-0000
|
| | | MSR 000001AA | 0000-0000-0000-30C2
|
| | | MSR 000001AC | < FAILED >
|
| | | MSR 000001AD | 2F2F-2F2F-2F2F-3131
|
| | | MSR 000001AE | 0807-0605-0403-0201
|
| | | MSR 000001AF | < FAILED >
|
| | | MSR 000001B0 | 0000-0000-0000-0006
|
| | | MSR 000001B1 | 0000-0000-882E-0800
|
| | | MSR 000001B2 | 0000-0000-0200-0000
|
| | | MSR 000001FC | 0000-0000-00CC-005F
|
| | | MSR 00000300 | < FAILED >
|
| | | MSR 0000030A | 0000-0000-0000-0000
|
| | | MSR 0000030B | 0000-0000-0000-0000
|
| | | MSR 00000480 | 03DA-0600-0000-0015
|
| | | MSR 00000481 | 0000-00FF-0000-0016
|
| | | MSR 00000482 | FFFB-FFFE-0401-E172
|
| | | MSR 00000483 | FF7F-FFFF-0003-6DFF
|
| | | MSR 00000484 | 007E-FFFF-0000-11FF
|
| | | MSR 00000485 | 0000-0000-7004-C1E7
|
| | | MSR 00000486 | 0000-0000-8000-0021
|
| | | MSR 00000487 | 0000-0000-FFFF-FFFF
|
| | | MSR 00000488 | 0000-0000-0000-2000
|
| | | MSR 00000489 | 0000-0000-1BF7-6FFF
|
| | | MSR 0000048A | 0000-0000-0000-002E
|
| | | MSR 0000048B | C75F-7FFF-0000-0000
|
| | | MSR 0000048C | 0000-0F01-06F3-4141
|
| | | MSR 0000048D | 0000-00FF-0000-0016
|
| | | MSR 0000048E | FFFB-FFFE-0400-6172
|
| | | MSR 0000048F | FF7F-FFFF-0003-6DFB
|
| | | MSR 00000490 | 007E-FFFF-0000-11FB
|
| | | MSR 00000601 | 0000-0000-0000-0278
|
| | | MSR 00000602 | < FAILED >
|
| | | MSR 00000603 | 0036-0000-0036-3636
|
| | | MSR 00000604 | < FAILED >
|
| | | MSR 00000606 | 0000-0000-000A-0E03
|
| | | MSR 0000060A | 0000-0000-0000-0000
|
| | | MSR 0000060B | 0000-0000-0000-0000
|
| | | MSR 0000060C | 0000-0000-0000-0000
|
| | | MSR 0000060D | 0000-0028-4BA1-6026
|
| | | MSR 00000610 | 0042-8250-00DD-8118
|
| | | MSR 00000611 | 0000-0000-01D1-42CD
|
| | | MSR 00000613 | 0000-0000-0000-0055
|
| | | MSR 00000614 | 0012-0000-0000-0118
|
| | | MSR 00000618 | 0000-0000-0000-0000
|
| | | MSR 00000619 | 0000-0000-0000-0000
|
| | | MSR 0000061B | 0000-0000-0000-0000
|
| | | MSR 0000061C | < FAILED >
|
| | | MSR 0000061E | < FAILED >
|
| | | MSR 00000620 | 0000-0000-0000-0825
|
| | | MSR 00000621 | 0000-0000-1BB5-0012
|
| | | MSR 00000638 | 0000-0000-0000-0000
|
| | | MSR 00000639 | 0000-0000-00CB-74DA
|
| | | MSR 0000063A | 0000-0000-0000-0000
|
| | | MSR 0000063B | < FAILED >
|
| | | MSR 00000640 | 0000-0000-0000-0000
|
| | | MSR 00000641 | 0000-0000-0000-0018
|
| | | MSR 00000642 | 0000-0000-0000-0010
|
| | | MSR 00000648 | 0000-0000-0000-0019
|
| | | MSR 00000649 | 0000-0000-0000-0000
|
| | | MSR 0000064A | 0000-0000-0000-0000
|
| | | MSR 0000064B | 0000-0000-8000-0000
|
| | | MSR 0000064C | 0000-0000-0000-0000
|
| | | MSR 00000650 | 2C2C-2C2C-2C2C-2C2C
|
| | | MSR 00000651 | 0807-0605-0403-0201
|
| | | MSR 00000690 | < FAILED >
|
| | | MSR 000006B0 | 0000-0000-0100-0000
|
| | | MSR 000006B1 | 0000-0000-0100-0000
|
| | | MSR 00000770 | 0000-0000-0000-0001
|
| | | MSR 00000771 | 0000-0000-0122-284F
|
| | | MSR 00000772 | 0000-0000-8000-FF01
|
| | | MSR 00000773 | 0000-0000-0000-0005
|
| | | MSR 00000774 | 0000-019E-3F00-4F02
|
| | | MSR 00000777 | 0000-0000-0000-0000
|
| | | MSR 00000832 | 0000-0000-0002-00D1
|
| | | MSR 00000838 | 0000-0000-0000-0209
|
| | | MSR 00000839 | 0000-0000-0000-015A
|
| | | MSR 0000083E | 0000-0000-0000-000A
|
|
|
| | MSR Registers (CPU #9):
|
| | | MSR 00000017 | 0004-0000-0000-0000 [PlatID = 1]
|
| | | MSR 0000001B | 0000-0000-FEE0-0C00
|
| | | MSR 00000035 | 0000-0000-000A-000A
|
| | | MSR 00000048 | 0000-0000-0000-0001
|
| | | MSR 00000049 | < FAILED >
|
| | | MSR 0000008B | 0000-0121-0000-0000
|
| | | MSR 000000CE | 0804-0838-F081-1900 [eD = 0]
|
| | | MSR 000000E7 | 0000-0008-7D9D-1E7D
|
| | | MSR 000000E8 | 0000-000C-ABE4-1627
|
| | | MSR 0000010A | 0000-0000-0DF9-FD6B
|
| | | MSR 0000010B | < FAILED >
|
| | | MSR 00000194 | 0000-0000-0010-0000
|
| | | MSR 00000198 | 0000-1724-0000-1500
|
| | | MSR 00000199 | 0000-0000-0000-3100
|
| | | MSR 0000019A | 0000-0000-0000-0000
|
| | | MSR 0000019B | 0000-0000-0000-0010
|
| | | MSR 0000019C | 0000-0000-882F-2800
|
| | | MSR 0000019D | 0000-0000-0000-0000
|
| | | MSR 000001A0 | 0000-0000-0085-0089
|
| | | MSR 000001A2 | 0000-0000-8069-1600
|
| | | MSR 000001A4 | 0000-0000-0000-0000
|
| | | MSR 000001AA | 0000-0000-0000-30C2
|
| | | MSR 000001AC | < FAILED >
|
| | | MSR 000001AD | 2F2F-2F2F-2F2F-3131
|
| | | MSR 000001AE | 0807-0605-0403-0201
|
| | | MSR 000001AF | < FAILED >
|
| | | MSR 000001B0 | 0000-0000-0000-0006
|
| | | MSR 000001B1 | 0000-0000-882E-0800
|
| | | MSR 000001B2 | 0000-0000-0200-0000
|
| | | MSR 000001FC | 0000-0000-00CC-005F
|
| | | MSR 00000300 | < FAILED >
|
| | | MSR 0000030A | 0000-0000-0000-0000
|
| | | MSR 0000030B | 0000-0000-0000-0000
|
| | | MSR 00000480 | 03DA-0600-0000-0015
|
| | | MSR 00000481 | 0000-00FF-0000-0016
|
| | | MSR 00000482 | FFFB-FFFE-0401-E172
|
| | | MSR 00000483 | FF7F-FFFF-0003-6DFF
|
| | | MSR 00000484 | 007E-FFFF-0000-11FF
|
| | | MSR 00000485 | 0000-0000-7004-C1E7
|
| | | MSR 00000486 | 0000-0000-8000-0021
|
| | | MSR 00000487 | 0000-0000-FFFF-FFFF
|
| | | MSR 00000488 | 0000-0000-0000-2000
|
| | | MSR 00000489 | 0000-0000-1BF7-6FFF
|
| | | MSR 0000048A | 0000-0000-0000-002E
|
| | | MSR 0000048B | C75F-7FFF-0000-0000
|
| | | MSR 0000048C | 0000-0F01-06F3-4141
|
| | | MSR 0000048D | 0000-00FF-0000-0016
|
| | | MSR 0000048E | FFFB-FFFE-0400-6172
|
| | | MSR 0000048F | FF7F-FFFF-0003-6DFB
|
| | | MSR 00000490 | 007E-FFFF-0000-11FB
|
| | | MSR 00000601 | 0000-0000-0000-0278
|
| | | MSR 00000602 | < FAILED >
|
| | | MSR 00000603 | 0036-0000-0036-3636
|
| | | MSR 00000604 | < FAILED >
|
| | | MSR 00000606 | 0000-0000-000A-0E03
|
| | | MSR 0000060A | 0000-0000-0000-0000
|
| | | MSR 0000060B | 0000-0000-0000-0000
|
| | | MSR 0000060C | 0000-0000-0000-0000
|
| | | MSR 0000060D | 0000-0028-4BA1-6026
|
| | | MSR 00000610 | 0042-8250-00DD-8118
|
| | | MSR 00000611 | 0000-0000-01D1-4383
|
| | | MSR 00000613 | 0000-0000-0000-0055
|
| | | MSR 00000614 | 0012-0000-0000-0118
|
| | | MSR 00000618 | 0000-0000-0000-0000
|
| | | MSR 00000619 | 0000-0000-0000-0000
|
| | | MSR 0000061B | 0000-0000-0000-0000
|
| | | MSR 0000061C | < FAILED >
|
| | | MSR 0000061E | < FAILED >
|
| | | MSR 00000620 | 0000-0000-0000-0825
|
| | | MSR 00000621 | 0000-0000-1BB5-0011
|
| | | MSR 00000638 | 0000-0000-0000-0000
|
| | | MSR 00000639 | 0000-0000-00CB-751F
|
| | | MSR 0000063A | 0000-0000-0000-0000
|
| | | MSR 0000063B | < FAILED >
|
| | | MSR 00000640 | 0000-0000-0000-0000
|
| | | MSR 00000641 | 0000-0000-0000-0018
|
| | | MSR 00000642 | 0000-0000-0000-0010
|
| | | MSR 00000648 | 0000-0000-0000-0019
|
| | | MSR 00000649 | 0000-0000-0000-0000
|
| | | MSR 0000064A | 0000-0000-0000-0000
|
| | | MSR 0000064B | 0000-0000-8000-0000
|
| | | MSR 0000064C | 0000-0000-0000-0000
|
| | | MSR 00000650 | 2C2C-2C2C-2C2C-2C2C
|
| | | MSR 00000651 | 0807-0605-0403-0201
|
| | | MSR 00000690 | < FAILED >
|
| | | MSR 000006B0 | 0000-0000-0100-0000
|
| | | MSR 000006B1 | 0000-0000-0100-0000
|
| | | MSR 00000770 | 0000-0000-0000-0001
|
| | | MSR 00000771 | 0000-0000-0122-284F
|
| | | MSR 00000772 | 0000-0000-8000-FF01
|
| | | MSR 00000773 | 0000-0000-0000-0005
|
| | | MSR 00000774 | 0000-019E-3F00-4F02
|
| | | MSR 00000777 | 0000-0000-0000-0000
|
| | | MSR 00000832 | 0000-0000-0002-00D1
|
| | | MSR 00000838 | 0000-0000-0000-0209
|
| | | MSR 00000839 | 0000-0000-0000-014F
|
| | | MSR 0000083E | 0000-0000-0000-000A
|
| | | | |
|
| | DLL File | Version | Description
|
| | 0ae3b998-9a38-4b72-a4c4-06849441518d_servicing-stack.dll | 10.0.26100.7705 | ApiSet Schema Extension DLL
|
| | 3bc29097-7317-41d3-93b9-38a48f99d48a_mssrch.dll | 10.0.26100.7920 | ApiSet Schema Extension DLL
|
| | 4545ffe2-0dc4-4df4-9d02-299ef204635e_hvsocket.dll | 10.0.26100.7705 | ApiSet Schema Extension DLL
|
| | 69fe178f-26e7-43a9-aa7d-2b616b672dde_eventlogservice.dll | 10.0.26100.7705 | ApiSet Schema Extension DLL
|
| | 6bea57fb-8dfb-4177-9ae8-42e8b3529933_runtimedeviceinstall.dll | 10.0.26100.7920 | ApiSet Schema Extension DLL
|
| | aadauthhelper.dll | 10.0.26100.7920 | Microsoft® Microsoft Entra Auth Helper
|
| | aadcloudap.dll | 10.0.26100.8036 | Microsoft Entra Cloud AP Plugin
|
| | aadjcsp.dll | 10.0.26100.7309 | AADJCSP
|
| | aadtb.dll | 10.0.26100.7920 | Microsoft Entra WAM Helper Library
|
| | aadwamextension.dll | 10.0.26100.7920 | Microsoft Entra WAM extension DLL
|
| | aarsvc.dll | 10.0.26100.7309 | Agent Activation Runtime Service
|
| | aboutsettingshandlers.dll | 10.0.26100.7920 | System Settings About Handlers Implementation
|
| | abovelockapphost.dll | 10.0.26100.7824 | AboveLockAppHost
|
| | accessibilitycpl.dll | 10.0.26100.8036 | Ease of access control panel
|
| | accountaccessor.dll | 10.0.26100.7309 | Sync data model to access accounts
|
| | accounthealth.dll | 10.0.26100.7705 | AccountHealth
|
| | accountsrt.dll | 10.0.26100.7309 | Accounts RT utilities for mail, contacts, calendar
|
| | acgenral.dll | 10.0.26100.7920 | Windows Compatibility DLL
|
| | aclayers.dll | 10.0.26100.7705 | Windows Compatibility DLL
|
| | acledit.dll | 10.0.26100.1 | Access Control List Editor
|
| | aclui.dll | 10.0.26100.7920 | Security Descriptor Editor
|
| | acmigration.dll | 10.0.26100.7920 | Compatibility Upgrade Migration Host
|
| | acpbackgroundmanagerpolicy.dll | 10.0.26100.7705 | <d> ACP Background Manager Policy DLL
|
| | acppage.dll | 10.0.26100.7920 | Compatibility Tab Shell Extension Library
|
| | acproxy.dll | 10.0.26100.1 | Autochk Proxy DLL
|
| | acspecfc.dll | 10.0.26100.7309 | Windows Compatibility DLL
|
| | actioncenter.dll | 10.0.26100.7309 | Security and Maintenance
|
| | actioncentercpl.dll | 10.0.26100.7309 | Security and Maintenance Control Panel
|
| | actionqueue.dll | 10.0.26100.7309 | Unattend Action Queue Generator / Executor
|
| | activationclient.dll | 10.0.26100.7309 | Activation Client
|
| | activationmanager.dll | 10.0.26100.7920 | Activation Manager
|
| | activeds.dll | 10.0.26100.7019 | ADs Router Layer DLL
|
| | activesynccsp.dll | 10.0.26100.7309 | ActiveSync CSP DLL
|
| | activesyncprovider.dll | 10.0.26100.7309 | The engine that syncs ActiveSync accounts
|
| | actxprxy.dll | 10.0.26100.7705 | ActiveX Interface Marshaling Library
|
| | acwinrt.dll | 10.0.26100.1150 | Windows Compatibility DLL
|
| | acxtrnal.dll | 10.0.26100.2454 | Windows Compatibility DLL
|
| | adaptivecards.dll | 10.0.26100.7309 | Windows Adaptive Cards API Server
|
| | addressparser.dll | 10.0.26100.1882 | ADDRESSPARSER
|
| | adhapi.dll | 10.0.26100.7705 | AD harvest sites and subnets API
|
| | adhsvc.dll | 10.0.26100.5074 | AD Harvest Sites and Subnets Service
|
| | adprovider.dll | 10.0.26100.7309 | adprovider DLL
|
| | adpsvc.dll | 10.0.26100.7920 | ADPSvc
|
| | adsldp.dll | 10.0.26100.7019 | ADs LDAP Provider DLL
|
| | adsldpc.dll | 10.0.26100.1882 | ADs LDAP Provider C DLL
|
| | adsmsext.dll | 10.0.26100.1150 | ADs LDAP Provider DLL
|
| | adsnt.dll | 10.0.26100.7019 | ADs Windows NT Provider DLL
|
| | adtschema.dll | 10.0.26100.6725 | Security Audit Schema DLL
|
| | advancedemojids.dll | 10.0.26100.7309 | "AdvancedEmojiDS.DYNLINK"
|
| | advapi32.dll | 10.0.26100.7920 | Advanced Windows 32 Base API
|
| | advapi32res.dll | 10.0.26100.4202 | Advanced Windows 32 Base API
|
| | advpack.dll | 11.0.26100.7309 | ADVPACK
|
| | aeevts.dll | 10.0.26100.7920 | Application Experience Event Resources
|
| | aeinv.dll | 10.0.26100.7920 | Application Inventory Component
|
| | aemarebackup.dll | 10.0.26100.7920 | Inventory Backup
|
| | aepic.dll | 10.0.26100.7920 | Application Experience Program Cache
|
| | agentactivationruntime.dll | 10.0.26100.7309 | Agent Activation Runtime Common DLL
|
| | agentactivationruntimewindows.dll | 10.0.26100.7705 | Agent Activation Runtime Windows DLL
|
| | aidd.dll | |
|
| | amsi.dll | 10.0.26100.7309 | Anti-Malware Scan Interface
|
| | amsiproxy.dll | 10.0.26100.1 | Anti-Malware Scan Interface proxy
|
| | amstream.dll | 10.0.26100.5074 | DirectShow Runtime.
|
| | apds.dll | 10.0.26100.5074 | Microsoft® Help Data Services Module
|
| | aphostclient.dll | 10.0.26100.7309 | Accounts Host Service RPC Client
|
| | aphostres.dll | 10.0.26100.1 | Accounts Host Resources
|
| | aphostservice.dll | 10.0.26100.7920 | Accounts Host Service
|
| | apisampling.dll | 10.0.26100.7920 | API Sampling
|
| | apisethost.appexecutionalias.dll | 10.0.26100.7920 | ApiSetHost.AppExecutionAlias
|
| | apisetschema.dll | 10.0.26100.7705 | ApiSet Schema DLL
|
| | apmon.dll | 10.0.26100.7920 | Adaptive Port Monitor
|
| | apmonui.dll | 10.0.26100.7309 | Adaptive Port Monitor UI
|
| | appcontracts.dll | 10.0.26100.7309 | Windows AppContracts API Server
|
| | appextension.dll | 10.0.26100.7920 | PackageExtension and AppExtension APIs
|
| | appfootprint.dll | |
|
| | apphelp.dll | 10.0.26100.7920 | Application Compatibility Client Library
|
| | apphlpdm.dll | 10.0.26100.5074 | Application Compatibility Help Module
|
| | appidapi.dll | 10.0.26100.3037 | Application Identity APIs Dll
|
| | appidsvc.dll | 10.0.26100.3037 | Application Identity Service
|
| | appinfo.dll | 10.0.26100.7920 | Application Information Service
|
| | appinfoext.dll | 10.0.26100.7309 | appinfoext
|
| | appinstallerprompt.desktop.dll | 10.0.26100.7309 | AppInstaller Prompt Desktop
|
| | applicationcontrolcsp.dll | 10.0.26100.7309 | ApplicationControl Configuration Service Provider
|
| | applicationframe.dll | 10.0.26100.7920 | Application Frame
|
| | applicationtargetedfeaturedatabase.dll | 10.0.26100.7920 | ApplicationTargetedFeatureDatabase
|
| | applistbackuplauncher.dll | 10.0.26100.7824 | AppListBackupLauncher
|
| | applockercsp.dll | 10.0.26100.7309 | AppLockerCSP
|
| | appmon.dll | 10.0.26100.7309 | App Printer
|
| | appointmentactivation.dll | 10.0.26100.7309 | DLL for AppointmentActivation
|
| | appointmentapis.dll | 10.0.26100.7309 | DLL for CalendarRT
|
| | appraiser.dll | 10.0.26100.7920 | Compatibility Appraiser
|
| | appreadiness.dll | 10.0.26100.7920 | AppReadiness
|
| | apprepapi.dll | 10.0.26100.4484 | Application Reputation APIs Dll
|
| | appresolver.dll | 10.0.26100.7920 | App Resolver
|
| | appsruprov.dll | 10.0.26100.7309 | Application System Resource Usage Monitor (SRUM) provider
|
| | appxalluserstore.dll | 10.0.26100.7920 | AppX All User Store DLL
|
| | appxapplicabilityblob.dll | 10.0.26100.7705 | Appx Applicability Blob DLL
|
| | appxapplicabilityengine.dll | 10.0.26100.7705 | AppX Applicability Engine
|
| | appxdeploymentclient.dll | 10.0.26100.7920 | AppX Deployment Client DLL
|
| | appxdeploymentextensions.desktop.dll | 10.0.26100.7920 | AppX Deployment Extensions Desktop DLL
|
| | appxdeploymentextensions.onecore.dll | 10.0.26100.7920 | AppX Deployment Extensions OneCore DLL
|
| | appxdeploymentserver.dll | 10.0.26100.8036 | AppX Deployment Server DLL
|
| | appxpackaging.dll | 10.0.26100.8036 | Native Code Appx Packaging Library
|
| | appxsip.dll | 10.0.26100.7920 | Appx Subject Interface Package
|
| | appxstreamingdatasourceps.dll | 10.0.26100.1150 | APPX Streaming Data Source COM Proxy/Stub DLL
|
| | appxsysprep.dll | 10.0.26100.7920 | AppX Sysprep Provider
|
| | apx01000.dll | 10.0.26100.7920 | Audio Proxy DLL
|
| | apxsvc.dll | 10.0.26100.7309 | Windows Virtual Audio Device Proxy Service
|
| | archiveint.dll | 3.8.4.0 | Windows-internal libarchive library
|
| | asferror.dll | 12.0.26100.1 | ASF Error Definitions
|
| | aspnet_counters.dll | 4.8.9221.0 | Microsoft ASP.NET Performance Counter Shim DLL
|
| | assignedaccessruntime.dll | 10.0.26100.7309 | AssignedAccessRuntime
|
| | asycfilt.dll | 10.0.26100.1 | ASYCFILT.DLL
|
| | atl.dll | 3.5.2284.0 | ATL Module for Windows XP (Unicode)
|
| | atlthunk.dll | 10.0.26100.1 | atlthunk.dll
|
| | atmlib.dll | 5.1.2.254 | Windows NT OpenType/Type 1 API Library.
|
| | audioendpointbuilder.dll | 10.0.26100.8036 | Windows Audio Endpoint Builder
|
| | audioeng.dll | 10.0.26100.8036 | Audio Engine
|
| | audiohandlers.dll | 10.0.26100.7920 | Audio Settings Handlers Implementation
|
| | audiokse.dll | 10.0.26100.8036 | Audio Ks Endpoint
|
| | audioresourceregistrar.dll | 10.0.26100.8036 | AudioResourceRegistrar DLL
|
| | audioses.dll | 10.0.26100.7920 | Audio Session
|
| | audiosrv.dll | 10.0.26100.8036 | Windows Audio Service
|
| | audiosrvpolicymanager.dll | 10.0.26100.7920 | Windows Audio Service Policy Manager
|
| | auditcse.dll | 10.0.26100.7019 | Windows Audit Settings CSE
|
| | auditpolcore.dll | 10.0.26100.7309 | Audit Policy Program
|
| | authbroker.dll | 10.0.26100.7309 | Web Authentication WinRT API
|
| | authbrokerui.dll | 10.0.26100.7705 | AuthBroker UI
|
| | authext.dll | 10.0.26100.7309 | Authentication Extensions
|
| | authfwcfg.dll | 10.0.26100.7019 | Windows Defender Firewall with Advanced Security Configuration Helper
|
| | authfwgp.dll | 10.0.26100.1150 | Windows Defender Firewall with Advanced Security Group Policy Editor Extension
|
| | authfwsnapin.dll | 10.0.26100.7920 | Microsoft.WindowsFirewall.SnapIn
|
| | authfwwizfwk.dll | 10.0.26100.1 | Wizard Framework
|
| | authhostproxy.dll | 10.0.26100.7019 | Web Authentication Host Proxy
|
| | authui.dll | 10.0.26100.7920 | Windows Authentication UI
|
| | authz.dll | 10.0.26100.7920 | Authorization Framework
|
| | automaticappsigninpolicy.dll | 10.0.26100.7309 | Automatic App Sign In policy
|
| | autopilot.dll | 10.0.26100.7705 | AutoPilot
|
| | autopilotdiag.dll | 10.0.26100.1150 | ETW for Autopilot Diagnostics
|
| | autoplay.dll | 10.0.26100.7920 | AutoPlay Control Panel
|
| | autotimesvc.dll | 10.0.26100.7309 | AutoTime Service
|
| | avicap32.dll | 10.0.26100.1150 | AVI Capture window class
|
| | avifil32.dll | 10.0.26100.7309 | Microsoft AVI File support library
|
| | avrt.dll | 10.0.26100.7309 | Multimedia Realtime Runtime
|
| | axinstsv.dll | 10.0.26100.7920 | ActiveX Installer Service
|
| | azroles.dll | 10.0.26100.1882 | azroles Module
|
| | azroleui.dll | 10.0.26100.1150 | Authorization Manager
|
| | azsqlext.dll | 10.0.26100.1150 | AzMan Sql Audit Extended Stored Procedures Dll
|
| | backgroundmediapolicy.dll | 10.0.26100.7309 | <d> Background Media Policy DLL
|
| | bamsettingsclient.dll | 10.0.26100.1882 | Background Activity Moderator Settings Client
|
| | barcodeprovisioningplugin.dll | 10.0.26100.7309 | Barcode Provisioning Plugin
|
| | basecsp.dll | 10.0.26100.8037 | Microsoft Base Smart Card Crypto Provider
|
| | basesrv.dll | 10.0.26100.7920 | Windows NT BASE API Server DLL
|
| | batmeter.dll | 10.0.26100.7705 | Battery Meter Helper DLL
|
| | bcastdvr.proxy.dll | 10.0.26100.1150 | Broadcast DVR Proxy
|
| | bcastdvrbroker.dll | 10.0.26100.7309 | Windows Runtime BcastDVRBroker DLL
|
| | bcastdvrclient.dll | 10.0.26100.7309 | Windows Runtime BcastDVRClient DLL
|
| | bcastdvrcommon.dll | 10.0.26100.7309 | Windows Runtime BcastDVRCommon DLL
|
| | bcastdvruserservice.dll | 10.0.26100.8036 | Broadcast DVR User Service
|
| | bcd.dll | 10.0.26100.4202 | BCD DLL
|
| | bcdprov.dll | 10.0.26100.1 | Boot Configuration Data WMI Provider
|
| | bcdsrv.dll | 10.0.26100.1 | Boot Configuration Data COM Server
|
| | bcp47langs.dll | 10.0.26100.7309 | BCP47 Language Classes
|
| | bcp47mrm.dll | 10.0.26100.7309 | BCP47 Language Classes for Resource Management
|
| | bcrypt.dll | 10.0.26100.7623 | Windows Cryptographic Primitives Library
|
| | bcryptprimitives.dll | 10.0.26100.7623 | Windows Cryptographic Primitives Library
|
| | bdehdcfglib.dll | 10.0.26100.1 | Windows BitLocker Drive Preparation Tool
|
| | bderepair.dll | 10.0.26100.4768 | BitLocker Drive Encryption: Drive Repair Tool
|
| | bdesvc.dll | 10.0.26100.7920 | BDE Service
|
| | bdeui.dll | 10.0.26100.7920 | Windows BitLocker Drive Encryption User Interface
|
| | bfe.dll | 10.0.26100.7920 | Base Filtering Engine
|
| | bi.dll | 10.0.26100.1 | Background Broker Infrastructure Client Library
|
| | bidispl.dll | 10.0.26100.7309 | Bidispl DLL
|
| | bindfltapi.dll | 10.0.26100.7309 | BindFlt user mode API
|
| | bingasds.dll | 10.0.26100.7309 | Microsoft Bing Auto Suggestion Datasource Dll
|
| | bingfilterds.dll | 10.0.26100.7309 | "BingFilterDS.DYNLINK"
|
| | bingmaps.dll | 10.0.26100.7705 | Bing Map Control
|
| | bingonlineservices.dll | 10.0.26100.7309 | Bing online services
|
| | biocredprov.dll | 10.0.26100.7920 | WinBio Credential Provider
|
| | bisrv.dll | 10.0.26100.7920 | Background Tasks Infrastructure Service
|
| | bitlockercsp.dll | 10.0.26100.7920 | BitLockerCSP
|
| | bitsigd.dll | 7.8.26100.1150 | Background Intelligent Transfer Service IGD Support
|
| | bitsperf.dll | 7.8.26100.6725 | Perfmon Counter Access
|
| | bitsproxy.dll | 7.8.26100.5074 | Background Intelligent Transfer Service Proxy
|
| | biwinrt.dll | 10.0.26100.7705 | Windows Background Broker Infrastructure
|
| | blb_ps.dll | 10.0.26100.1 | Microsoft® Block Level Backup proxy/stub
|
| | blbevents.dll | 10.0.26100.1 | Blb Publisher
|
| | blbres.dll | 10.0.26100.1 | Microsoft® Block Level Backup Engine Service Resources
|
| | bluetoothapis.dll | 10.0.26100.7920 | Bluetooth Usermode Api host
|
| | bluetoothdesktophandlers.dll | 10.0.26100.7920 | Bluetooth Desktop Handlers
|
| | bluetoothopppushclient.dll | |
|
| | bnmanager.dll | 10.0.26100.7920 | Battery Notification Manager
|
| | bootcriticalupdateplugin.dll | 1.0.0.1 | BootCriticalUpdate Plugin for WinRE boot failure scenario
|
| | bootmenuux.dll | 10.0.26100.7920 | BootMenuUX
|
| | bootstr.dll | 10.0.26100.1 | Boot String Resource Library
|
| | bootsvc.dll | 10.0.26100.7920 | BOOTSVC DLL
|
| | bootux.dll | 10.0.26100.7920 | bootux
|
| | bootvid.dll | 10.0.26100.4202 | VGA Boot Driver
|
| | bridgeres.dll | 10.0.26100.2454 | Bridge Resources
|
| | brokerfiledialog.dll | 10.0.26100.7309 | brokerfiledialog
|
| | brokerlib.dll | 10.0.26100.1150 | Broker Base Library
|
| | browcli.dll | 10.0.26100.1150 | Browser Service Client DLL
|
| | browserbroker.dll | 11.0.26100.7309 | BrowserBroker
|
| | browseui.dll | 10.0.26100.1 | Shell Browser UI Library
|
| | btagservice.dll | 10.0.26100.7920 | Bluetooth Audio Gateway Service
|
| | bthavctpsvc.dll | 10.0.26100.7920 | Bluetooth AVCTP Service DLL
|
| | bthavrcp.dll | 10.0.26100.7920 | Bluetooth AVRCP Service DLL
|
| | bthavrcpappsvc.dll | 10.0.26100.4061 | Bluetooth AVRCP Application Bridge Service DLL
|
| | bthci.dll | 10.0.26100.7309 | Bluetooth Class Installer
|
| | bthmtpcontexthandler.dll | 10.0.26100.1150 | Bluetooth MTP Context Menu Handler
|
| | bthpanapi.dll | 10.0.26100.7309 | bthpanapi
|
| | bthpancontexthandler.dll | 10.0.26100.7309 | Bluetooth PAN Context-Menu Handler
|
| | bthradiomedia.dll | 10.0.26100.7309 | Bluetooth Radio Media Provider
|
| | bthserv.dll | 10.0.26100.7920 | Bluetooth Support Service
|
| | bthtelemetry.dll | 10.0.26100.7920 | Bluetooth Telemetry Agent
|
| | btpanui.dll | 10.0.26100.1882 | Bluetooth PAN User Interface
|
| | bwcontexthandler.dll | 1.0.0.1 | ContextH Application
|
| | c_g18030.dll | 10.0.26100.7623 | GB18030 DBCS-Unicode Conversion DLL
|
| | c_gsm7.dll | 10.0.26100.7623 | GSM 7bit Code Page Translation DLL for SMS
|
| | c_is2022.dll | 10.0.26100.7623 | ISO-2022 Code Page Translation DLL
|
| | c_iscii.dll | 10.0.26100.1 | ISCII Code Page Translation DLL
|
| | cabapi.dll | 10.0.26100.7309 | Mobile Cabinet Library
|
| | cabinet.dll | 5.0.1.1 | Microsoft® Cabinet File API
|
| | cabview.dll | 10.0.26100.7309 | Cabinet File Viewer Shell Extension
|
| | callbuttons.dll | 10.0.26100.7309 | Windows Runtime CallButtonsServer DLL
|
| | callbuttons.proxystub.dll | 10.0.26100.4202 | Windows Runtime CallButtonsServer ProxyStub DLL
|
| | callhistoryclient.dll | 10.0.26100.5074 | Client DLL for accessing CallHistory information
|
| | cameracaptureui.dll | 10.0.26100.7309 | Microsoft® Windows® Operating System
|
| | camext.dll | |
|
| | capabilityaccesshandlers.dll | 10.0.26100.7920 | Capability Access Manager - Handlers' Shared DLL
|
| | capabilityaccessmanager.desktop.storage.dll | 10.0.26100.7920 | CapabilityAccessManager.Desktop.Storage
|
| | capabilityaccessmanager.dll | 10.0.26100.7920 | Capability Access Manager Service
|
| | capabilityaccessmanagerclient.dll | 10.0.26100.7920 | Capability Access Manager Client
|
| | capauthz.dll | 10.0.26100.7309 | Capability Authorization APIs
|
| | capiprovider.dll | 10.0.26100.7309 | capiprovider DLL
|
| | capisp.dll | 10.0.26100.1 | Sysprep cleanup dll for CAPI
|
| | captureservice.dll | 10.0.26100.7920 | Microsoft Windows Capture User Service
|
| | castingshellext.dll | 10.0.26100.1150 | Casting Shell Extensions
|
| | castlaunch.dll | 10.0.26100.7309 | Casting protocol app manager and launcher
|
| | catsrv.dll | 2001.12.10941.16384 | COM+ Configuration Catalog Server
|
| | catsrvps.dll | 2001.12.10941.16384 | COM+ Configuration Catalog Server Proxy/Stub
|
| | catsrvut.dll | 2001.12.10941.16384 | COM+ Configuration Catalog Server Utilities
|
| | cbdhsvc.dll | 10.0.26100.7309 | Microsoft (R) Clipboard History
|
| | cca.dll | 10.0.26100.1882 | CCA DirectShow Filter.
|
| | cdd.dll | 10.0.26100.7920 | Canonical Display Driver
|
| | cdosys.dll | 6.6.26100.5074 | Microsoft CDO for Windows Library
|
| | cdp.dll | 10.0.26100.7920 | Microsoft (R) CDP Client API
|
| | cdprt.dll | 10.0.26100.7920 | Microsoft (R) CDP Client WinRT API
|
| | cdpsvc.dll | 10.0.26100.8036 | Microsoft (R) CDP Service
|
| | cdpusersvc.dll | 10.0.26100.7920 | Microsoft (R) CDP User Components
|
| | cellulardatacapabilityhandler.dll | 10.0.26100.7309 | Windows cellularData Capability Handler
|
| | cemapi.dll | 10.0.26100.7309 | CEMAPI
|
| | certca.dll | 10.0.26100.7920 | Microsoft® Active Directory Certificate Services CA
|
| | certcli.dll | 10.0.26100.7920 | Microsoft® Active Directory Certificate Services Client
|
| | certcredprovider.dll | 10.0.26100.4484 | Cert Credential Provider
|
| | certenc.dll | 10.0.26100.7920 | Active Directory Certificate Services Encoding
|
| | certenroll.dll | 10.0.26100.7920 | Microsoft® Active Directory Certificate Services Enrollment Client
|
| | certenrollui.dll | 10.0.26100.7920 | X509 Certificate Enrollment UI
|
| | certmgr.dll | 10.0.26100.5074 | Certificates snap-in
|
| | certpkicmdlet.dll | 10.0.26100.7019 | Microsoft® PKI Client Cmdlets
|
| | certpoleng.dll | 10.0.26100.7920 | Certificate Policy Engine
|
| | certprop.dll | 10.0.26100.8037 | Microsoft Smartcard Certificate Propagation Service
|
| | cewmdm.dll | 12.0.26100.7309 | Windows CE WMDM Service Provider
|
| | cfgbkend.dll | 10.0.26100.5074 | Configuration Backend Interface
|
| | cfgmgr32.dll | 10.0.26100.7309 | Configuration Manager DLL
|
| | cfgspcellular.dll | 10.0.26100.7309 | Configuration Service Provider CMCellularEntries
|
| | cfgsppolicy.dll | 10.0.26100.7309 | Configuration Service Provider CMPolicy
|
| | cflapi.dll | 10.0.26100.7309 | CXH from LogonUI API
|
| | cfmifs.dll | 10.0.26100.5074 | FmIfs Engine
|
| | cfmifsproxy.dll | 10.0.26100.4484 | Microsoft® FmIfs Proxy Library
|
| | chakra.dll | 11.0.26100.7920 | Microsoft ® Chakra (Private)
|
| | chakradiag.dll | 11.0.26100.7920 | Microsoft ® Chakra Diagnostics (Private)
|
| | chakrathunk.dll | 10.0.26100.7920 | chakrathunk.dll
|
| | chartv.dll | 10.0.26100.1 | Chart View
|
| | chatapis.dll | 10.0.26100.7309 | DLL for ChatRT
|
| | chsstrokeds.dll | 10.0.26100.7309 | "ChsStrokeDS.DYNLINK"
|
| | chtbopomofods.dll | 10.0.26100.7309 | "ChtBopomofoDS.DYNLINK"
|
| | chtcangjieds.dll | 10.0.26100.7309 | "ChtCangjieDS.DYNLINK"
|
| | chthkstrokeds.dll | 10.0.26100.7309 | "ChtHkStrokeDS.DYNLINK"
|
| | chtquickds.dll | 10.0.26100.7309 | "ChtQuickDS.DYNLINK"
|
| | chxapds.dll | 10.0.26100.7309 | "ChxAPDS.DYNLINK"
|
| | chxdecoder.dll | 10.0.26100.7309 | "ChxDecoder.DYNLINK"
|
| | chxhapds.dll | 10.0.26100.7309 | "ChxHAPDS.DYNLINK"
|
| | chxinputrouter.dll | 10.0.26100.7309 | "ChxInputRouter.DYNLINK"
|
| | chxranker.dll | 10.0.26100.7309 | "ChxRanker.DYNLINK"
|
| | chxreadingstringime.dll | 10.0.26100.1150 | CHxReadingStringIME
|
| | ci.dll | 10.0.26100.8036 | Code Integrity Module
|
| | cic.dll | 10.0.26100.5074 | CIC - MMC controls for Taskpad
|
| | cimfs.dll | 10.0.26100.7920 | CimFS user mode API
|
| | circoinst.dll | 10.0.26100.1150 | USB Consumer IR Driver coinstaller for eHome
|
| | clbcatq.dll | 2001.12.10941.16384 | COM+ Configuration Catalog
|
| | cldapi.dll | 10.0.26100.7920 | Cloud API user mode API
|
| | cleanpccsp.dll | 10.0.26100.7309 | CleanPCCSP
|
| | clfsw32.dll | 10.0.26100.7920 | Common Log Marshalling Win32 DLL
|
| | cliconfg.dll | 10.0.26100.1150 | SQL Client Configuration Utility DLL
|
| | clipboardserver.dll | 10.0.26100.7623 | Modern Clipboard API Server
|
| | clipc.dll | 10.0.26100.1882 | Client Licensing Platform Client
|
| | clipsvc.dll | 10.0.26100.8036 | Client License Service
|
| | clipwinrt.dll | 10.0.26100.7920 | ClipWinRT
|
| | cloudap.dll | 10.0.26100.8036 | Cloud AP Security Package
|
| | clouddesktopcsp.dll | 10.0.26100.7705 | CloudDesktopCSP
|
| | clouddomainjoinaug.dll | 10.0.26100.7309 | CloudDomainJoinAuthenticUserGesture
|
| | clouddomainjoindatamodelserver.dll | 10.0.26100.7920 | CloudDomainJoinDataModelServer
|
| | cloudexperiencehost.dll | 10.0.26100.7920 | CloudExperienceHost
|
| | cloudexperiencehostbroker.dll | 10.0.26100.7920 | CloudExperienceHostBroker
|
| | cloudexperiencehostcommon.dll | 10.0.26100.7920 | CloudExperienceHostCommon
|
| | cloudexperiencehostredirection.dll | |
|
| | cloudexperiencehostuser.dll | 10.0.26100.7920 | CloudExperienceHost User Operations
|
| | cloudidwxhextension.dll | |
|
| | cloudrecoverydownloadtool.dll | 0.2.708.0 | Microsoft Cloud Recovery Download Tool
|
| | cloudrestorelauncher.dll | 10.0.26100.7920 | CloudRestoreLauncher Task
|
| | clrhost.dll | 10.0.26100.1 | In Proc server for managed servers in the Windows Runtime
|
| | clusapi.dll | 10.0.26100.7920 | Cluster API Library
|
| | cmcfg32.dll | 7.2.26100.1150 | Microsoft Connection Manager Configuration Dll
|
| | cmdext.dll | 10.0.26100.7309 | cmd.exe Extension DLL
|
| | cmdial32.dll | 7.2.26100.1 | Microsoft Connection Manager
|
| | cmgrcspps.dll | 10.0.26100.4202 | cmgrcspps
|
| | cmifw.dll | 10.0.26100.8036 | Windows Defender Firewall rule configuration plug-in
|
| | cmintegrator.dll | 10.0.26100.7920 | cmintegrator.dll
|
| | cmlua.dll | 7.2.26100.1 | Connection Manager Admin API Helper
|
| | cmpbk32.dll | 7.2.26100.1 | Microsoft Connection Manager Phonebook
|
| | cmstplua.dll | 7.2.26100.1 | Connection Manager Admin API Helper for Setup
|
| | cmutil.dll | 7.2.26100.1150 | Microsoft Connection Manager Utility Lib
|
| | cngcredui.dll | 10.0.26100.7019 | Microsoft CNG CredUI Provider
|
| | cngprovider.dll | 10.0.26100.7309 | cngprovider DLL
|
| | cnvfat.dll | 10.0.26100.7623 | FAT File System Conversion Utility DLL
|
| | codeintegrityaggregator.dll | 10.0.26100.7920 | Code Integrity Aggregator
|
| | cofiredm.dll | 10.0.26100.1882 | Corrupted File Recovery Diagnostic Module
|
| | colbact.dll | 2001.12.10941.16384 | COM+
|
| | colorcnv.dll | 10.0.26100.7309 | Windows Media Color Conversion
|
| | colorui.dll | 10.0.26100.7705 | Microsoft Color Control Panel
|
| | combase.dll | 10.0.26100.7920 | Microsoft COM for Windows
|
| | comcat.dll | 10.0.26100.1 | Microsoft Component Category Manager Library
|
| | comctl32.dll | 5.82.26100.8037 | User Experience Controls Library
|
| | comdlg32.dll | 10.0.26100.7920 | Common Dialogs DLL
|
| | coml2.dll | 10.0.26100.7705 | Microsoft COM for Windows
|
| | compataggregator.dll | |
|
| | composableshellproxystub.dll | 10.0.26100.3624 | Composable Shell Shared Proxy Stub
|
| | composerframework.dll | 10.0.26100.7309 | Composer framework for Composable Shell
|
| | comppkgsup.dll | 10.0.26100.7920 | Component Package Support DLL
|
| | compstui.dll | 10.0.26100.5074 | Common Property Sheet User Interface DLL
|
| | computecore.dll | 10.0.26100.7920 | Hyper-V Host Compute Service Core Client Library
|
| | computelibeventlog.dll | 10.0.26100.4202 | Hyper-V Host Compute Service Client Library Event Log Resource Dll
|
| | computenetwork.dll | 10.0.26100.7309 | Hyper-V Host Networking Service Client Library
|
| | computestorage.dll | 10.0.26100.7920 | Hyper-V Host Compute Service Storage Client Library
|
| | comrepl.dll | 2001.12.10941.16384 | COM+
|
| | comres.dll | 2001.12.10941.16384 | COM+ Resources
|
| | comsnap.dll | 2001.12.10941.16384 | COM+ Explorer MMC Snapin
|
| | comsvcs.dll | 2001.12.10941.16384 | COM+ Services
|
| | comuid.dll | 2001.12.10941.16384 | COM+ Explorer UI
|
| | configmanager2.dll | 10.0.26100.7920 | ConfigManager
|
| | configureexpandedstorage.dll | 10.0.26100.7309 | ConfigureExpandedStorage
|
| | connect.dll | 10.0.26100.7309 | Get Connected Wizards
|
| | connectedaccountstate.dll | 10.0.26100.7309 | ConnectedAccountState.dll
|
| | connectionattributionapi.dll | 10.0.26100.7309 | Microsoft Trust for Connected Experiences Connection Attribution API DLL
|
| | consentexperiencecommon.dll | 10.0.26100.7920 | In-Proc WinRT server for Windows.Internal.PlatformExtensions.ConsentExperienceCommon
|
| | consentux.dll | 10.0.26100.7920 | Device Broker Consent Prompt
|
| | consentuxclient.dll | 10.0.26100.7920 | Implementation of client-side Consent UX API
|
| | console.dll | 10.0.26100.7309 | Control Panel Console Applet
|
| | consolelogon.dll | 10.0.26100.7309 | Console Logon User Experience
|
| | constraintindex.search.dll | 10.0.26100.7920 | Constraint Index Search
|
| | contactactivation.dll | 10.0.26100.7309 | DLL for ContactActivation
|
| | contactapis.dll | 10.0.26100.7309 | DLL for ContactsRT
|
| | contactharvesterds.dll | 10.0.26100.7309 | Microsoft Contact Harvester Datasource Dll
|
| | container.dll | 10.0.26100.7309 | Windows Containers
|
| | containerdevicemanagement.dll | 10.0.26100.7309 | Container Device Management library
|
| | contentdeliverymanager.utilities.dll | 10.0.26100.7920 | ContentDeliveryManager.Utilities
|
| | controlcenter.dll | |
|
| | coreaudiopolicymanagerext.dll | 10.0.26100.1150 | "coreaudiopolicymanagerext.DYNLINK"
|
| | coredpus.dll | 10.0.26100.7309 | coredpus
|
| | coreglobconfig.dll | 10.0.26100.7309 | Core Globalization Configuration
|
| | coremas.dll | |
|
| | coremessaging.dll | 10.0.26100.7920 | Microsoft CoreMessaging Dll
|
| | coremmres.dll | 10.0.26100.1 | General Core Multimedia Resources
|
| | coreprivacysettingsstore.dll | 10.0.26100.7309 | CorePrivacySettingsStore
|
| | coreshell.dll | 10.0.26100.7824 | CoreShell
|
| | coreshellapi.dll | 10.0.26100.7824 | CoreShellAPI
|
| | coreshellextframework.dll | 10.0.26100.7309 | Core Shell SI Host Extension Framework for Composable Shell
|
| | coreuicomponents.dll | 10.0.26100.7627 | Microsoft Core UI Components Dll
|
| | correngine.dll | 10.0.26100.7920 | Correlation Engine
|
| | courtesyengine.dll | 10.0.26100.7309 | Microsoft Feedback Courtesy Engine DLL Server
|
| | cpfilters.dll | 10.0.26100.7920 | PTFilter & Encypter/Decrypter Tagger Filters.
|
| | creddialogbroker.dll | 10.0.26100.7920 | Credential Dialog Broker
|
| | credentialenrollmentmanagerforuser.dll | 10.0.26100.7309 | Credential Enrollment Manager ForUser API
|
| | credprov2fahelper.dll | 10.0.26100.7309 | Credential Provider 2FA Helper
|
| | credprovcommoncore.dll | 10.0.26100.7705 | Microsoft (R) Credential Provider Common Core
|
| | credprovdatamodel.dll | 10.0.26100.7920 | Cred Prov Data Model
|
| | credprovhelper.dll | 10.0.26100.7920 | Credential Provider Helper
|
| | credprovhost.dll | 10.0.26100.7920 | Credential Provider Framework Host
|
| | credprovs.dll | 10.0.26100.7920 | Credential Providers
|
| | credprovslegacy.dll | 10.0.26100.7920 | Credential Providers Legacy
|
| | credssp.dll | 10.0.26100.4652 | Credential Delegation Security Package
|
| | credui.dll | 10.0.26100.7309 | Credential Manager User Interface
|
| | crypt32.dll | 10.0.26100.7309 | Crypto API32
|
| | cryptbase.dll | 10.0.26100.7623 | Base cryptographic API DLL
|
| | cryptcatsvc.dll | 10.0.26100.7920 | Cryptographic Catalog Services
|
| | cryptdlg.dll | 10.0.26100.1882 | Microsoft Common Certificate Dialogs
|
| | cryptdll.dll | 10.0.26100.5074 | Cryptography Manager
|
| | cryptext.dll | 10.0.26100.5074 | Crypto Shell Extensions
|
| | cryptnet.dll | 10.0.26100.7309 | Crypto Network Related API
|
| | cryptngc.dll | 10.0.26100.7920 | Microsoft Passport API
|
| | cryptoss.dll | 10.0.26100.7309 | Crypto Open Source
|
| | cryptowinrt.dll | 10.0.26100.7920 | Crypto WinRT Library
|
| | cryptsp.dll | 10.0.26100.7705 | Cryptographic Service Provider API
|
| | cryptsvc.dll | 10.0.26100.7309 | Cryptographic Services
|
| | crypttpmeksvc.dll | 10.0.26100.1150 | Cryptographic TPM Endorsement Key Services
|
| | cryptui.dll | 10.0.26100.7309 | Microsoft Trust UI Provider
|
| | cryptuiwizard.dll | 10.0.26100.1150 | Microsoft Trust UI Provider
|
| | cryptxml.dll | 10.0.26100.7019 | XML DigSig API
|
| | cscapi.dll | 10.0.26100.1 | Offline Files Win32 API
|
| | cscdll.dll | 10.0.26100.1 | Offline Files Temporary Shim
|
| | cspcellularsettings.dll | 10.0.26100.7309 | Configuration Service Provider CellSettings
|
| | csplte.dll | 10.0.26100.7309 | Configuration Service Provider LTE
|
| | cspproxy.dll | 10.0.26100.5074 | CM_ProxyEntries Configuration Service Provider
|
| | csrsrv.dll | 10.0.26100.7920 | Client Server Runtime Process
|
| | csystemeventsbrokerclient.dll | 10.0.26100.1150 | Classic System Events Broker Client Library
|
| | cxcredprov.dll | 10.0.26100.7920 | Cloud Experience Credential Provider
|
| | cxhprovisioningserver.dll | 10.0.26100.7920 | CXHProvisioningServer
|
| | d2d1.dll | 10.0.26100.7920 | Microsoft D2D Library
|
| | d3d10.dll | 10.0.26100.1150 | Direct3D 10 Runtime
|
| | d3d10_1.dll | 10.0.26100.1882 | Direct3D 10.1 Runtime
|
| | d3d10_1core.dll | 10.0.26100.1882 | Direct3D 10.1 Runtime
|
| | d3d10core.dll | 10.0.26100.1882 | Direct3D 10 Runtime
|
| | d3d10level9.dll | 10.0.26100.7309 | Direct3D 10 to Direct3D9 Translation Runtime
|
| | d3d10warp.dll | 10.0.26100.7309 | Direct3D Rasterizer
|
| | d3d11.dll | 10.0.26100.7920 | Direct3D 11 Runtime
|
| | d3d11on12.dll | 10.0.26100.7920 | Direct3D 11On12 Runtime
|
| | d3d12.dll | 10.0.26100.7920 | Direct3D 12 Runtime
|
| | d3d12core.dll | 10.0.26100.7920 | Direct3D 12 Core Runtime
|
| | d3d8thk.dll | 10.0.26100.7920 | Microsoft Direct3D OS Thunk Layer
|
| | d3d9.dll | 10.0.26100.7920 | Direct3D 9 Runtime
|
| | d3d9on12.dll | 10.0.26100.7920 | Direct3D9 DDI to Direct3D12 API Mapping Layer
|
| | d3dcompiler_47.dll | 10.0.26100.8036 | Direct3D HLSL Compiler
|
| | d3dscache.dll | 10.0.26100.7309 | Microsoft (R) D3D Shader Caching Library
|
| | dab.dll | 10.0.26100.7019 | Desktop Activity Broker DLL
|
| | dabapi.dll | 10.0.26100.1 | Desktop Activity Broker API
|
| | dafaspinfraprovider.dll | 10.0.26100.7309 | Windows AspInfra DAF Plugin
|
| | dafbth.dll | 10.0.26100.7920 | Bluetooth Device Association Framework Provider
|
| | dafdnssd.dll | 10.0.26100.7920 | DAF DnsSd Provider
|
| | dafdockingprovider.dll | 10.0.26100.7309 | Windows Wireless Docking DAF Plugin
|
| | dafescl.dll | 10.0.26100.7920 | ESCL DAF Provider
|
| | dafgip.dll | 10.0.26100.7309 | DAF GIP Provider
|
| | dafipp.dll | 10.0.26100.7920 | IPP DAF Provider
|
| | dafmcp.dll | 10.0.26100.7920 | MCP DAF Provider
|
| | dafpos.dll | 10.0.26100.7309 | Point Of Service DAF Provider
|
| | dafprintprovider.dll | 10.0.26100.7309 | DAF Print Provider DLL
|
| | dafupnp.dll | 10.0.26100.7309 | DAF UPnP Provider
|
| | dafwcn.dll | 10.0.26100.7705 | Windows Connect Now DAF Plugin
|
| | dafwfdprovider.dll | 10.0.26100.7920 | Windows Wi-Fi Direct DAF Plugin
|
| | dafwiprov.dll | 10.0.26100.7309 | DAF Printer WiFi Provisioning Provider
|
| | dafwsd.dll | 10.0.26100.7309 | DAF WSD Provider
|
| | damediamanager.dll | 10.0.26100.7309 | Windows DA Media Manager DLL
|
| | daotpcredentialprovider.dll | 10.0.26100.5074 | DirectAccess One-Time Password Credential Provider
|
| | das.dll | 10.0.26100.8036 | Device Association Service
|
| | dataclen.dll | 10.0.26100.7309 | Disk Space Cleaner for Windows
|
| | dataexchange.dll | 10.0.26100.7705 | Data exchange
|
| | davclnt.dll | 10.0.26100.1 | Web DAV Client DLL
|
| | davhlpr.dll | 10.0.26100.1 | DAV Helper DLL
|
| | davsyncprovider.dll | 10.0.26100.7309 | DAV sync engine for contacts, calendar
|
| | daxexec.dll | 10.0.26100.7920 | daxexec
|
| | dbgcore.dll | 10.0.26100.7920 | Windows Core Debugging Helpers
|
| | dbgeng.dll | 10.0.26100.1 | Windows Symbolic Debugger Engine
|
| | dbghelp.dll | 10.0.26100.5074 | Windows Image Helper
|
| | dbgmodel.dll | 10.0.26100.1 | Windows Debugger Data Model
|
| | dbnetlib.dll | 10.0.26100.1150 | Winsock Oriented Net DLL for SQL Clients
|
| | dbnmpntw.dll | 10.0.26100.1 | Named Pipes Net DLL for SQL Clients
|
| | dciman32.dll | 10.0.26100.7705 | DCI Manager
|
| | dcntel.dll | 10.0.26100.7920 | dcntel
|
| | dcomp.dll | 10.0.26100.7920 | Microsoft DirectComposition Library
|
| | dcsvc.dll | 10.0.26100.7920 | dcsvc
|
| | ddaclsys.dll | 10.0.26100.1 | SysPrep module for Resetting Data Drive ACL
|
| | ddcclaimsapi.dll | 10.0.26100.1150 | DdcClaimsApi
|
| | ddccomimplementationsdesktop.dll | 10.0.26100.7309 | DdcComImplementationsDesktop
|
| | ddds.dll | 10.0.26100.7309 | Microsoft Dynamic Datasource Dll
|
| | ddisplay.dll | 10.0.26100.7920 | DirectDisplay
|
| | ddoiproxy.dll | 10.0.26100.1 | DDOI Interface Proxy
|
| | ddores.dll | 10.0.26100.1 | Device Category information and resources
|
| | ddraw.dll | 10.0.26100.7705 | Microsoft DirectDraw
|
| | ddrawex.dll | 10.0.26100.4652 | Direct Draw Ex
|
| | declaredconfiguration.dll | 10.0.26100.7309 | declaredconfiguration
|
| | defaultdevicemanager.dll | 10.0.26100.1150 | Default Device Manager
|
| | defaultprinterprovider.dll | 10.0.26100.1 | Microsoft Windows Default Printer Provider
|
| | defragproxy.dll | 10.0.26100.7705 | Microsoft® Drive Optimizer Proxy Library
|
| | defragres.dll | 10.0.26100.7705 | Microsoft\Drive Optimizer Resources
|
| | defragsvc.dll | 10.0.26100.7705 | Microsoft\Drive Optimizer
|
| | delegatorprovider.dll | 10.0.26100.7920 | WMI PassThru Provider for Storage Management
|
| | deploymentcsps.dll | 10.0.26100.5074 | Deployment CSP DLL
|
| | deskadp.dll | 10.0.26100.4484 | Advanced display adapter properties
|
| | deskmon.dll | 10.0.26100.1150 | Advanced display monitor properties
|
| | desktopshellappstatecontract.dll | 10.0.26100.7309 | Desktop Switcher Data Model
|
| | desktopshellext.dll | 10.0.26100.7920 | DesktopHost Extensions
|
| | desktopswitcherdatamodel.dll | 10.0.26100.7824 | Desktop Switcher Data Model
|
| | devdispitemprovider.dll | 10.0.26100.7920 | DeviceItem inproc devquery subsystem
|
| | developeroptionssettingshandlers.dll | 10.0.26100.7920 | DeveloperOptions Handlers Implementation
|
| | devenum.dll | 10.0.26100.7309 | Device enumeration.
|
| | deviceaccess.dll | 10.0.26100.7920 | Device Broker And Policy COM Server
|
| | deviceassociation.dll | 10.0.26100.8036 | Device Association Client DLL
|
| | devicecenter.dll | 10.0.26100.7920 | Device Center
|
| | devicecompanionappinstall.dll | 10.0.26100.5074 | Device Companion App Installation Client
|
| | devicecredential.dll | 10.0.26100.7309 | Microsoft Companion Authenticator Client
|
| | devicedirectoryclient.dll | 10.0.26100.7309 | DeviceDirectoryClient Task
|
| | devicedisplaystatusmanager.dll | 10.0.26100.1 | Device Display Status Manager
|
| | devicedriverretrievalclient.dll | 10.0.26100.7705 | Device Driver Retrieval Client
|
| | deviceelementsource.dll | 10.0.26100.7920 | DeviceElementSource
|
| | deviceflows.datamodel.dll | 10.0.26100.7920 | DeviceFlows DataModel
|
| | devicemetadataretrievalclient.dll | 10.0.26100.4202 | Windows MRC
|
| | devicengccredprov.dll | 10.0.26100.7920 | Microsoft Companion Authenticator Credential Provider
|
| | devicepairing.dll | 10.0.26100.7309 | Shell extensions for Device Pairing
|
| | devicepairingexperiencemem.dll | 10.0.26100.7309 | Device Pairing Experience contract implementation
|
| | devicepairingfolder.dll | 10.0.26100.7920 | Device Pairing Folder
|
| | devicepairingproxy.dll | 10.0.26100.3624 | Device Pairing Proxy Dll
|
| | devicereactivation.dll | 10.0.26100.7920 | DeviceReactivation
|
| | deviceregistration.dll | 10.0.26100.3323 | Device Registration DLL
|
| | devicesetupmanager.dll | 10.0.26100.7920 | Device Setup Manager
|
| | devicesetupmanagerapi.dll | 10.0.26100.7920 | Device Setup Manager Client API
|
| | devicesetupstatusprovider.dll | 10.0.26100.7920 | Device Setup Status Provider Dll
|
| | devicesflowbroker.dll | 10.0.26100.7920 | DevicesFlow Broker
|
| | devicesoftwareinstallationclient.dll | 10.0.26100.7705 | Device Software Installation Client
|
| | deviceupdateagent.dll | 10.0.26100.7309 | Device Update Agent
|
| | deviceuxres.dll | 10.0.26100.1 | Windows Device User Experience Resource File
|
| | devinv.dll | 10.0.26100.7920 | Device Inventory Library
|
| | devmgr.dll | 10.0.26100.7309 | Device Manager MMC Snapin
|
| | devobj.dll | 10.0.26100.1150 | Device Information Set DLL
|
| | devpropmgr.dll | 10.0.26100.7309 | Microsoft Windows Device Property Manager
|
| | devquerybroker.dll | 10.0.26100.7309 | DevQuery Background Discovery Broker
|
| | devrtl.dll | 10.0.26100.1882 | Device Management Run Time Library
|
| | dfdts.dll | 10.0.26100.1150 | Windows Disk Failure Diagnostic Module
|
| | dfscli.dll | 10.0.26100.1150 | Windows NT Distributed File System Client DLL
|
| | dfshim.dll | 10.0.26100.1882 | ClickOnce Application Deployment Support Library
|
| | dfsshlex.dll | 10.0.26100.1150 | Distributed File System shell extension
|
| | dhcpcmonitor.dll | 10.0.26100.7920 | DHCP Client Monitor Dll
|
| | dhcpcore.dll | 10.0.26100.7920 | DHCP Client Service
|
| | dhcpcore6.dll | 10.0.26100.7920 | DHCPv6 Client
|
| | dhcpcsvc.dll | 10.0.26100.7920 | DHCP Client Service
|
| | dhcpcsvc6.dll | 10.0.26100.7920 | DHCPv6 Client
|
| | dhcpsapi.dll | 10.0.26100.1150 | DHCP Server API Stub DLL
|
| | diagcpl.dll | 10.0.26100.7309 | Troubleshooting Control Panel
|
| | diagnosticdataquery.dll | 10.0.26100.7920 | Microsoft Windows Diagnostic data Helper API
|
| | diagnosticdatasettings.dll | 10.0.26100.7019 | Microsoft Windows Diagnostic Data Settings
|
| | diagnosticinvoker.dll | 10.0.26100.7309 | Microsoft Windows operating system.
|
| | diagnosticlogcsp.dll | 10.0.26100.7309 | DiagnosticLogCSP
|
| | diagperf.dll | 10.0.26100.7309 | Microsoft Performance Diagnostics
|
| | diagsvc.dll | 10.0.26100.7309 | Microsoft Windows operating system
|
| | diagtrack.dll | 10.0.26100.7920 | Microsoft Windows Diagnostics Tracking
|
| | dialclient.dll | 10.0.26100.7309 | DIAL DLL
|
| | dialserver.dll | 10.0.26100.7309 | DIAL Server DLL
|
| | dictationmanager.dll | 10.0.0.1 | Dictation Manager
|
| | difxapi.dll | 2.1.0.0 | Driver Install Frameworks for API library module
|
| | dimsjob.dll | 10.0.26100.7309 | DIMS Job DLL
|
| | dimsroam.dll | 10.0.26100.7309 | Key Roaming DIMS Provider DLL
|
| | dinput.dll | 10.0.26100.1591 | Microsoft DirectInput
|
| | dinput8.dll | 10.0.26100.1591 | Microsoft DirectInput
|
| | direct2ddesktop.dll | 10.0.26100.1 | Microsoft Direct2D Desktop Components
|
| | directmanipulation.dll | 10.0.26100.7920 | Microsoft Direct Manipulation Component
|
| | directml.dll | 1.15.5.0 | DirectML Library
|
| | directsr.dll | |
|
| | directxdatabasehelper.dll | 10.0.26100.7920 | DirectXDatabaseHelper
|
| | discan.dll | 10.0.26100.7309 | Data Integrity Scan Task
|
| | dismapi.dll | 10.0.26100.7920 | DISM API Framework
|
| | dispbroker.desktop.dll | 10.0.26100.7920 | Desktop Display Broker
|
| | dispbroker.dll | 10.0.26100.7705 | Display Broker API
|
| | dispex.dll | 10.0.26100.7920 | Microsoft ® DispEx
|
| | display.dll | 10.0.26100.7705 | Display Control Panel
|
| | displaymanager.dll | 10.0.26100.7309 | DisplayManager
|
| | dlnashext.dll | 10.0.26100.7309 | DLNA Namespace DLL
|
| | dmalertlistener.proxystub.dll | 10.0.26100.7705 | ProxyStub for DeviceManagment Alert
|
| | dmapisetextimpldesktop.dll | 10.0.26100.7309 | DmApiSetExtImplDesktop
|
| | dmappsres.dll | 10.0.26100.4202 | DMAppsRes
|
| | dmcfgutils.dll | 10.0.26100.7309 | dmcfgutils
|
| | dmcmnutils.dll | 10.0.26100.7920 | dmcmnutils
|
| | dmcommandlineutils.dll | 10.0.26100.1 | dmcommandlineutils
|
| | dmcsps.dll | 10.0.26100.7309 | dmcsps
|
| | dmdlgs.dll | 10.0.26100.4202 | Disk Management Snap-in Dialogs
|
| | dmdskmgr.dll | 10.0.26100.5074 | Disk Management Snap-in Support Library
|
| | dmdskres.dll | 10.0.26100.4202 | Disk Management Snap-in Resources
|
| | dmdskres2.dll | 10.0.26100.4202 | Disk Management Snap-in Resources
|
| | dmenrollengine.dll | 10.0.26100.7920 | Enroll Engine DLL
|
| | dmenterprisediagnostics.dll | 10.0.26100.7309 | ETW for MDM Enterprise Diagnostics
|
| | dmintf.dll | 10.0.26100.4202 | Disk Management DCOM Interface Stub
|
| | dmiso8601utils.dll | 10.0.26100.1 | dmiso8601utils
|
| | dmloader.dll | 10.0.26100.7309 | Microsoft DirectMusic Loader
|
| | dmocx.dll | 10.0.26100.1882 | TreeView OCX
|
| | dmoleaututils.dll | 10.0.26100.5074 | dmoleaututils
|
| | dmosconfig.dll | 10.0.26100.7920 | DmOsConfig
|
| | dmprocessxmlfiltered.dll | 10.0.26100.7309 | dmprocessxmlfiltered
|
| | dmpushproxy.dll | 10.0.26100.5074 | dmpushproxy
|
| | dmpushroutercore.dll | 10.0.26100.7309 | MDM Pushrouter
|
| | dmrcdecoder.dll | |
|
| | dmrserver.dll | 10.0.26100.7309 | Digital Media Receiver DLL
|
| | dmsynth.dll | 10.0.26100.1882 | Microsoft DirectMusic Software Synthesizer
|
| | dmusic.dll | 10.0.26100.7309 | Microsoft DirectMusic Core Services
|
| | dmutil.dll | 10.0.26100.4202 | Logical Disk Manager Utility Library
|
| | dmvdsitf.dll | 10.0.26100.1 | Disk Management Snap-in Support Library
|
| | dmwappushsvc.dll | 10.0.26100.7309 | dmwappushsvc
|
| | dmwmicsp.dll | 10.0.26100.3323 | dmwmicsp
|
| | dmxmlhelputils.dll | 10.0.26100.7309 | dmxmlhelputils
|
| | dnsapi.dll | 10.0.26100.7920 | DNS Client API DLL
|
| | dnsclientcsp.dll | |
|
| | dnscmmc.dll | 10.0.26100.8036 | DNS Client MMC Snap-in DLL
|
| | dnsext.dll | 10.0.26100.1 | DNS extension DLL
|
| | dnsrslvr.dll | 10.0.26100.7920 | DNS Caching Resolver Service
|
| | docking.virtualinput.dll | 10.0.26100.7920 | Docking.VirtualInput
|
| | dockinterface.proxystub.dll | 10.0.26100.2161 | Windows Wireless Docking DockInterface Proxy/Stub DLL
|
| | doclient.dll | 1451.2601.23012.0 | Delivery Optimization Client
|
| | docprop.dll | 10.0.26100.5074 | OLE DocFile Property Page
|
| | documentperformanceevents.dll | 10.0.26100.1 | Documents and Printing Performance Events
|
| | dolbydecmft_redirect.dll | 10.0.26100.4202 | Media Foundation Dolby Digital Atmos Decoders
|
| | domgmt.dll | 10.0.26100.7309 | Delivery Optimization Management
|
| | domiprov.dll | 1451.2510.27012.0 | Delivery Optimization MI Provider
|
| | dosettings.dll | 10.0.26100.7920 | Delivery Optimization Settings
|
| | dosvc.dll | 10.0.26100.7920 | Delivery Optimization
|
| | dot3api.dll | 10.0.26100.7309 | 802.3 Autoconfiguration API
|
| | dot3cfg.dll | 10.0.26100.7309 | 802.3 Netsh Helper
|
| | dot3gpclnt.dll | 10.0.26100.7309 | 802.3 Group Policy Client
|
| | dot3gpui.dll | 10.0.26100.7705 | 802.3 Network Policy Management Snap-in
|
| | dot3msm.dll | 10.0.26100.7309 | 802.3 Media Specific Module
|
| | dot3svc.dll | 10.0.26100.7309 | Wired AutoConfig Service
|
| | dot3ui.dll | 10.0.26100.7309 | 802.3 Advanced UI
|
| | dpapi.dll | 10.0.26100.1 | Data Protection API
|
| | dpapiprovider.dll | 10.0.26100.7309 | dpapiprovider DLL
|
| | dpapisrv.dll | 10.0.26100.7920 | DPAPI Server
|
| | dplcsp.dll | |
|
| | dpnaddr.dll | 10.0.26100.4202 | DirectPlay Stub
|
| | dpnathlp.dll | 10.0.26100.4202 | DirectPlay Stub
|
| | dpnet.dll | 10.0.26100.4202 | DirectPlay Stub
|
| | dpnhpast.dll | 10.0.26100.4202 | DirectPlay Stub
|
| | dpnhupnp.dll | 10.0.26100.4202 | DirectPlay Stub
|
| | dpnlobby.dll | 10.0.26100.4202 | DirectPlay Stub
|
| | dps.dll | 10.0.26100.7920 | WDI Diagnostic Policy Service
|
| | dpx.dll | 10.0.26100.7309 | Microsoft(R) Delta Package Expander
|
| | dragdropexperiencedataexchangedelegated.dll | 10.0.26100.7309 | In-Proc WinRT server for Windows.Internal.PlatformExtensions.DragDropExperienceDataExchangeDelegated
|
| | drprov.dll | 10.0.26100.1 | Microsoft Remote Desktop Session Host Server Network Provider
|
| | drvsetup.dll | 10.0.26100.7920 | Microsoft (R) Driver Setup
|
| | drvstore.dll | 10.0.26100.7920 | Driver Store API
|
| | dsauth.dll | 10.0.26100.2894 | DS Authorization for Services
|
| | dsccore.dll | 10.0.26100.1150 | DSC
|
| | dsccoreconfprov.dll | 6.2.9200.16384 | DSC
|
| | dsclient.dll | 10.0.26100.7920 | Data Sharing Service Client DLL
|
| | dscproxy.dll | 10.0.26100.1150 | dscproxy
|
| | dsctimer.dll | 10.0.26100.1150 | DscTimer
|
| | dsdmo.dll | 10.0.26100.5074 | DirectSound Effects
|
| | dskquota.dll | 10.0.26100.7309 | Windows Shell Disk Quota Support DLL
|
| | dskquoui.dll | 10.0.26100.7309 | Windows Shell Disk Quota UI DLL
|
| | dsound.dll | 10.0.26100.7309 | DirectSound
|
| | dsparse.dll | 10.0.26100.1 | Active Directory Domain Services API
|
| | dsprop.dll | 10.0.26100.1150 | Windows Active Directory Property Pages
|
| | dsquery.dll | 10.0.26100.7309 | Directory Service Find
|
| | dsreg.dll | 10.0.26100.7920 | Microsoft Entra User Device Registration
|
| | dsregtask.dll | 10.0.26100.7920 | DSREG task handler
|
| | dsrole.dll | 10.0.26100.1150 | DS Setup Client DLL
|
| | dssec.dll | 10.0.26100.7705 | Directory Service Security UI
|
| | dssenh.dll | 10.0.26100.5074 | Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider
|
| | dssvc.dll | 10.0.26100.7309 | Data Sharing Service NT Service DLL
|
| | dsui.dll | 10.0.26100.7309 | Device Setup UI Pages
|
| | dsuiext.dll | 10.0.26100.1150 | Directory Service Common UI
|
| | dswave.dll | 10.0.26100.7309 | Microsoft DirectMusic Wave
|
| | dtsh.dll | 10.0.26100.7309 | Detection and Sharing Status API
|
| | ducsps.dll | 10.0.26100.7309 | DuCSPs
|
| | dui70.dll | 10.0.26100.7920 | Windows DirectUI Engine
|
| | duser.dll | 10.0.26100.7920 | Windows DirectUser Engine
|
| | dusmapi.dll | 10.0.26100.7309 | Data Usage API
|
| | dusmsvc.dll | 10.0.26100.7920 | Data Usage Service
|
| | dwmapi.dll | 10.0.26100.7920 | Microsoft Desktop Window Manager API
|
| | dwmcore.dll | 10.0.26100.7920 | Microsoft DWM Core Library
|
| | dwmghost.dll | 10.0.26100.7309 | DWMGhost
|
| | dwminit.dll | 10.0.26100.7920 | DWMInit
|
| | dwmredir.dll | 10.0.26100.7920 | Microsoft Desktop Window Manager Redirection Component
|
| | dwmscene.dll | 10.0.26100.7623 | Microsoft DWM Scene Library
|
| | dwrite.dll | 10.0.26100.7824 | Microsoft DirectX Typography Services
|
| | dxcore.dll | 10.0.26100.7920 | DXCore
|
| | dxdiagn.dll | 10.0.26100.7920 | Microsoft DirectX Diagnostic Tool
|
| | dxgi.dll | 10.0.26100.7920 | DirectX Graphics Infrastructure
|
| | dxgwdi.dll | 10.0.26100.7920 | Microsoft DirectX Graphics WDI Handler
|
| | dxilconv.dll | 101.8.2502.37 | DirectX IL Converter DLL
|
| | dxmasf.dll | 12.0.26100.4202 | Microsoft Windows Media Component Removal File.
|
| | dxp.dll | 10.0.26100.7309 | Device Stage Shell Extension
|
| | dxpps.dll | 10.0.26100.1150 | Device Experience Platform Proxy\Stub DLL
|
| | dxptasksync.dll | 10.0.26100.7309 | Microsoft Windows DXP Sync.
|
| | dxtmsft.dll | 11.0.26100.5074 | DirectX Media -- Image DirectX Transforms
|
| | dxtrans.dll | 11.0.26100.5074 | DirectX Media -- DirectX Transform Core
|
| | dxva2.dll | 10.0.26100.7309 | DirectX Video Acceleration 2.0 DLL
|
| | dynamoapi.dll | 10.0.26100.7309 | dynamoapi
|
| | eamprogresshandler.dll | 10.0.26100.7920 | EAMProgressHandler
|
| | eapp3hst.dll | 10.0.26100.7920 | Microsoft ThirdPartyEapDispatcher
|
| | eappcfg.dll | 10.0.26100.7920 | Eap Peer Config
|
| | eappcfgui.dll | 10.0.26100.7309 | Eap Peer Config UI
|
| | eappgnui.dll | 10.0.26100.7920 | EAP Generic UI
|
| | eapphost.dll | 10.0.26100.7920 | Microsoft EAPHost Peer service
|
| | eappprxy.dll | 10.0.26100.7920 | Microsoft EAPHost Peer Client DLL
|
| | eapprovp.dll | 10.0.26100.7920 | EAP extension DLL
|
| | eapputil.dll | 10.0.26100.7920 | EAP Private Utility DLL
|
| | eapsimextdesktop.dll | 10.0.26100.7705 | EAP SIM EXT config dll
|
| | eapsvc.dll | 10.0.26100.7705 | Microsoft EAPHost service
|
| | eapteapauth.dll | 10.0.26100.7920 | EAP Teap Runtime DLL
|
| | eapteapconfig.dll | 10.0.26100.7920 | EAP Teap Config DLL
|
| | eapteapext.dll | 10.0.26100.7309 | EAP Teap Desktop Extension DLL
|
| | easconsent.dll | 10.0.26100.1 | EASConsent
|
| | easinvoker.proxystub.dll | 10.0.26100.4484 | Exchange ActiveSync Invoker Proxy Stub
|
| | easpolicymanagerbrokerps.dll | 10.0.26100.1 | COM Proxy Dll for the Exchange Active Sync Policy Manager Broker
|
| | easwrt.dll | 10.0.26100.7920 | Exchange ActiveSync Windows Runtime DLL
|
| | ecoscoretask.dll | 10.0.26100.7309 | EcoScoreTask Task
|
| | edgeangle.dll | 11.0.26100.1882 | Microsoft Edge Angle
|
| | edgecontent.dll | 11.0.26100.7920 | Microsoft Edge Content
|
| | edgehtml.dll | 11.0.26100.7920 | Microsoft Edge Web Platform
|
| | edgeiso.dll | 11.0.26100.8036 | Isolation Library for edgehtml hosts
|
| | edgemanager.dll | 11.0.26100.7920 | Microsoft Edge Manager
|
| | edgeresetplugin.dll | 10.0.26100.1150 | Edge Reset Plugin
|
| | editbuffertesthook.dll | 10.0.26100.7309 | "EditBufferTestHook.DYNLINK"
|
| | editionupgradehelper.dll | 10.0.26100.7920 | EDITIONUPGRADEHELPER.DLL
|
| | editionupgrademanagerobj.dll | 10.0.26100.7920 | Get your Windows license
|
| | edpauditapi.dll | 10.0.26100.7309 | EDP Audit API
|
| | edpcsp.dll | 10.0.26100.7309 | EnterpriseDataProtectionCSP
|
| | edptask.dll | 10.0.26100.7920 | EdpTask Task
|
| | edputil.dll | 10.0.26100.7309 | EDP util
|
| | eeprov.dll | 10.0.26100.7920 | Energy Estimator SRUM provider
|
| | eeutil.dll | 10.0.26100.7705 | Energy Estimator Utility
|
| | efsadu.dll | 10.0.26100.7920 | File Encryption Utility
|
| | efscore.dll | 10.0.26100.7920 | EFS Core Library
|
| | efsext.dll | 10.0.26100.7309 | EFSEXT.DLL
|
| | efslsaext.dll | 10.0.26100.7309 | LSA extension for EFS
|
| | efssvc.dll | 10.0.26100.7309 | EFS Service
|
| | efsutil.dll | 10.0.26100.7309 | EFS Utility Library
|
| | efswrt.dll | 10.0.26100.7309 | Storage Protection Windows Runtime DLL
|
| | ehstorapi.dll | 10.0.26100.7920 | Windows Enhanced Storage API
|
| | ehstorpwdmgr.dll | 10.0.26100.1150 | Microsoft Enhanced Storage Password Manager
|
| | ehstorshell.dll | 10.0.26100.8036 | Windows Enhanced Storage Shell Extension DLL
|
| | els.dll | 10.0.26100.5074 | Event Viewer Snapin
|
| | elscore.dll | 10.0.26100.1882 | Els Core Platform DLL
|
| | elshyph.dll | 10.0.26100.1 | ELS Hyphenation Service
|
| | elslad.dll | 10.0.26100.3323 | ELS Language Detection
|
| | elstrans.dll | 10.0.26100.1882 | ELS Transliteration Service
|
| | emailapis.dll | 10.0.26100.7309 | DLL for EmailRT
|
| | embeddedmodesvc.dll | 10.0.26100.7309 | Debug Register Service
|
| | embeddedmodesvcapi.dll | 10.0.26100.7309 | Embedded Mode Service Client DLL
|
| | emojids.dll | 10.0.26100.7309 | "EmojiDS.DYNLINK"
|
| | encapi.dll | 10.0.26100.1150 | Encoder API
|
| | energy.dll | 10.0.26100.7920 | Power Efficiency Diagnostics
|
| | energyprov.dll | 10.0.26100.7920 | Energy System Resource Usage Monitor (SRUM) provider
|
| | energytask.dll | 10.0.26100.7019 | Power Efficiency Diagnostics Task
|
| | enrollmentapi.dll | 10.0.26100.7309 | Legacy Phone Enrollment API BackCompat Shim
|
| | enterpriseapncsp.dll | 10.0.26100.7309 | EnterpriseAPN Configuration Service Provider
|
| | enterpriseappmgmtclient.dll | 10.0.26100.5074 | EnterpriseAppMgmtClient.dll
|
| | enterpriseappmgmtsvc.dll | 10.0.26100.7920 | Enterprise server dll
|
| | enterprisecsps.dll | 10.0.26100.7920 | API for MDM Enrollment DLL
|
| | enterprisedesktopappmgmtcsp.dll | 10.0.26100.7309 | EnterpriseDesktopAppManagementCSP
|
| | enterpriseetw.dll | 10.0.26100.1 | <d> DLL
|
| | enterprisemodernappmgmtcsp.dll | 10.0.26100.7920 | EnterpriseModernAppMgmtCSP
|
| | enterpriseresourcemanager.dll | 10.0.26100.7309 | enterpriseresourcemanager DLL
|
| | eqossnap.dll | 10.0.26100.1150 | EQoS Snapin extension
|
| | errordetails.dll | 10.0.26100.7309 | Microsoft Windows operating system.
|
| | errordetailscore.dll | 10.0.26100.7309 | Microsoft Windows operating system.
|
| | es.dll | 2001.12.10941.16384 | COM+
|
| | esclprotocol.dll | 10.0.26100.7920 | EsclProtocol dll
|
| | esclscan.dll | |
|
| | esclwiadriver.dll | 10.0.26100.7920 | ESCL Scan Driver DLL
|
| | esdsip.dll | 10.0.26100.7309 | Crypto SIP provider for signing and verifying .esd Electronic Software Distribution files
|
| | esent.dll | 10.0.26100.7920 | Extensible Storage Engine for Microsoft(R) Windows(R)
|
| | esentprf.dll | 10.0.26100.1150 | Extensible Storage Engine Performance Monitoring Library for Microsoft(R) Windows(R)
|
| | esevss.dll | 10.0.26100.3624 | Microsoft(R) ESENT shadow utilities
|
| | eshims.dll | 11.0.26100.7705 | Microsoft Edge Compatibility Shims
|
| | ethernetmediamanager.dll | 10.0.26100.7920 | Windows Ethernet Media Manager DLL
|
| | etwcoreuicomponentsresources.dll | 10.0.26100.1 | Microsoft CoreComponents UI ETW manifest Dll
|
| | etweseproviderresources.dll | 10.0.26100.1 | Microsoft ESE ETW
|
| | etwrundown.dll | 10.0.26100.7019 | Etw Rundown Helper Library
|
| | euiccscsp.dll | 10.0.26100.7705 | eUICCsCSP
|
| | eventaggregation.dll | 10.0.26100.1150 | Event Aggregation User Mode Library
|
| | eventcls.dll | 10.0.26100.5074 | Microsoft® Volume Shadow Copy Service event class
|
| | evr.dll | 10.0.26100.7309 | Enhanced Video Renderer DLL
|
| | execmodelclient.dll | 10.0.26100.7309 | ExecModelClient
|
| | execmodelproxy.dll | 10.0.26100.1 | ExecModelProxy
|
| | explorerframe.dll | 10.0.26100.7920 | ExplorerFrame
|
| | exsmime.dll | 10.0.26100.5074 | LExsmime
|
| | extrasxmlparser.dll | 10.0.26100.1882 | Extras XML parser used to extract extension information from XML
|
| | f3ahvoas.dll | 10.0.26100.1 | JP Japanese Keyboard Layout for Fujitsu FMV oyayubi-shift keyboard
|
| | facecredentialprovider.dll | 10.0.26100.7920 | Face Credential Provider
|
| | facilitator.dll | 10.0.26100.7705 | Facilitator
|
| | family.authentication.dll | 10.0.26100.7309 | Family.Authentication DLL
|
| | family.cache.dll | 10.0.26100.7920 | Family.Cache DLL
|
| | family.client.dll | 10.0.26100.7309 | Family.Client DLL
|
| | family.syncengine.dll | 10.0.26100.7309 | Family.SyncEngine DLL
|
| | familysafetyext.dll | 10.0.26100.1 | FamilySafety ChildAccount Extensions
|
| | faultrep.dll | 10.0.26100.7920 | Windows User Mode Crash Reporting DLL
|
| | faxprinterinstaller.dll | 10.0.26100.7623 | Fax Printer Installer
|
| | fcon.dll | 10.0.26100.8036 | Feature Configuration
|
| | fdbth.dll | 10.0.26100.7309 | Function Discovery Bluetooth Provider Dll
|
| | fdbthproxy.dll | 10.0.26100.1 | Bluetooth Provider Proxy Dll
|
| | fddevquery.dll | 10.0.26100.1150 | Microsoft Windows Device Query Helper
|
| | fde.dll | 10.0.26100.1882 | Folder Redirection Snapin Extension
|
| | fdeploy.dll | 10.0.26100.7309 | Folder Redirection Group Policy Extension
|
| | fdphost.dll | 10.0.26100.1 | Function Discovery Provider host service
|
| | fdpnp.dll | 10.0.26100.5074 | Pnp Provider Dll
|
| | fdprint.dll | 10.0.26100.7309 | Function Discovery Print Provider Dll
|
| | fdproxy.dll | 10.0.26100.1 | Function Discovery Proxy Dll
|
| | fdrespub.dll | 10.0.26100.1 | Function Discovery Resource Publication Service
|
| | fdssdp.dll | 10.0.26100.7920 | Function Discovery SSDP Provider Dll
|
| | fdwcn.dll | 10.0.26100.7705 | Windows Connect Now - Config Function Discovery Provider DLL
|
| | fdwnet.dll | 10.0.26100.1150 | Function Discovery WNet Provider Dll
|
| | fdwsd.dll | 10.0.26100.7309 | Function Discovery WS Discovery Provider Dll
|
| | feclient.dll | 10.0.26100.7309 | Windows NT File Encryption Client Interfaces
|
| | ffbroker.dll | 10.0.26100.7019 | Force Feedback Broker And Policy COM Server
|
| | fhcat.dll | 10.0.26100.7920 | File History Catalog Library
|
| | fhcfg.dll | 10.0.26100.7920 | File History Configuration Manager
|
| | fhcleanup.dll | 10.0.26100.1882 | File History Disk Cleanup Handler
|
| | fhcpl.dll | 10.0.26100.7824 | File History Control Panel
|
| | fhengine.dll | 10.0.26100.7920 | File History Engine
|
| | fhevents.dll | 10.0.26100.1882 | File History Event Listener Library
|
| | fhsettingsprovider.dll | 10.0.26100.7309 | File History Backup & Restore Settings Provider
|
| | fhshl.dll | 10.0.26100.3323 | File History Custom Shell Library
|
| | fhsrchapi.dll | 10.0.26100.1882 | File History Search API
|
| | fhsrchph.dll | 10.0.26100.1882 | File History Search Protocol Handler
|
| | fhsvc.dll | 10.0.26100.5074 | File History Service
|
| | fhsvcctl.dll | 10.0.26100.4484 | File History Service Control Library
|
| | fhtask.dll | 10.0.26100.1882 | File History Task Handler
|
| | fhuxadapter.dll | 10.0.26100.3037 | File History Data Adapter
|
| | fhuxapi.dll | 10.0.26100.3037 | File History API
|
| | fhuxcommon.dll | 10.0.26100.3037 | File History Common Library
|
| | fhuxgraphics.dll | 10.0.26100.7920 | File History Graphics
|
| | fhuxpresentation.dll | 10.0.26100.3037 | File History Presentation
|
| | fidocredprov.dll | 10.0.26100.7920 | FIDO Credential Provider
|
| | fileappxstreamingdatasource.dll | 10.0.26100.7920 | File AppX Streaming Data Source Library
|
| | filemgmt.dll | 10.0.26100.1882 | Services and Shared Folders
|
| | filterds.dll | 10.0.26100.7309 | Microsoft Filter Data Source Datasource Dll
|
| | findnetprinters.dll | 10.0.26100.5074 | Find Network Printers COM Component
|
| | fingerprintcredential.dll | 10.0.26100.7920 | WinBio Fingerprint Credential
|
| | firewallapi.dll | 10.0.26100.7920 | Windows Defender Firewall API
|
| | firewallcontrolpanel.dll | 10.0.26100.7309 | Windows Defender Firewall Control Panel
|
| | firewallux.dll | 10.0.26100.7705 | COM server for Windows.Internal.NetworkUX.Firewall
|
| | firmwareattestationserverproxystub.dll | 10.0.26100.4202 | FirmwareAttestationServer Proxy Stub Dll
|
| | flightsettings.dll | 10.0.26100.7920 | Flight Settings
|
| | fltlib.dll | 10.0.26100.1150 | Filter Library
|
| | fltmgrres.dll | 10.0.26100.7920 | Microsoft Filesystem Filter Manager Resources
|
| | fluencyds.dll | 10.0.26100.7920 | "FluencyDS.DYNLINK"
|
| | fmapi.dll | 10.0.26100.1 | File Management API
|
| | fmifs.dll | 10.0.26100.5074 | FM IFS Utility DLL
|
| | fms.dll | 10.0.26100.7309 | Font Management Services
|
| | fntcache.dll | 10.0.26100.7309 | Windows Font Cache Service
|
| | fontext.dll | 10.0.26100.7824 | Windows Font Folder
|
| | fontglyphanimator.dll | 10.0.26100.7920 | Font Glyph Animator
|
| | fontgroupsoverride.dll | 10.0.26100.1 | fontgroupsoverride.dll
|
| | fontprovider.dll | 10.0.26100.1150 | Windows Font Provider Library
|
| | fontsub.dll | 10.0.26100.7705 | Font Subsetting DLL
|
| | fphc.dll | 10.0.26100.5074 | Filtering Platform Helper Class
|
| | framedyn.dll | 10.0.26100.7019 | WMI SDK Provider Framework
|
| | framedynos.dll | 10.0.26100.7920 | WMI SDK Provider Framework
|
| | frameserver.dll | 10.0.26100.7920 | Windows Camera Frame Server DLL
|
| | frameserverclient.dll | 10.0.26100.7920 | Frame Server Client DLL
|
| | frameservercore.dll | 10.0.26100.7920 | Windows Camera Frame Server Core DLL
|
| | frameservermonitor.dll | 10.0.26100.7920 | Windows Camera Frame Server Monitor DLL
|
| | frameservermonitorclient.dll | 10.0.26100.7920 | Frame Server Monitor Client DLL
|
| | frprov.dll | 10.0.26100.1150 | Folder Redirection WMI Provider
|
| | fsnvsdevicesource.dll | 10.0.26100.7705 | Frame Server Network Video Streaming Device Source DLL
|
| | fstx.dll | 10.0.26100.7920 | FsTx
|
| | fsutilext.dll | 10.0.26100.4768 | FS Utility Extension DLL
|
| | fthsvc.dll | 10.0.26100.1 | Microsoft Windows Fault Tolerant Heap Diagnostic Module
|
| | fundisc.dll | 10.0.26100.7920 | Function Discovery Dll
|
| | fveapi.dll | 10.0.26100.7920 | Windows BitLocker Drive Encryption API
|
| | fveapibase.dll | 10.0.26100.7920 | Windows BitLocker Drive Encryption Base API
|
| | fvecerts.dll | 10.0.26100.7705 | BitLocker Certificates Library
|
| | fvecpl.dll | 10.0.26100.7309 | BitLocker Drive Encryption control panel
|
| | fveskybackup.dll | 10.0.26100.7920 | Windows BitLocker Drive Encryption OneDrive Backup
|
| | fveui.dll | 10.0.26100.7920 | BitLocker Drive Encryption UI
|
| | fvewiz.dll | 10.0.26100.7920 | BitLocker Drive Encryption Wizard
|
| | fwbase.dll | 10.0.26100.7920 | Firewall Base DLL
|
| | fwcfg.dll | 10.0.26100.1882 | Windows Defender Firewall Configuration Helper
|
| | fwmdmcsp.dll | 10.0.26100.7920 | FWMDMCSP
|
| | fwpolicyiomgr.dll | 10.0.26100.7920 | FwPolicyIoMgr DLL
|
| | fwpuclnt.dll | 10.0.26100.7920 | FWP/IPsec User-Mode API
|
| | fwremotesvr.dll | 10.0.26100.7920 | Windows Defender Firewall Remote APIs Server
|
| | gamebarpresencewriter.proxy.dll | 10.0.26100.1882 | GameBar Presence Writer Proxy
|
| | gamechatoverlayext.dll | 10.0.26100.1150 | GameChat Overlay Extension
|
| | gamechattranscription.dll | 10.0.26100.7019 | GameChatTranscription
|
| | gameinput.dll | 0.2309.26100.7920 | GameInput API
|
| | gamemode.dll | 10.0.26100.7824 | Game Mode Client
|
| | gamepanelexternalhook.dll | 10.0.26100.1882 | GamePanelExternalHook.dll
|
| | gamestreamingext.dll | 10.0.26100.1 | Xbox Game Streaming Extension
|
| | gameux.dll | 10.0.26100.1 | Games Explorer
|
| | gamingtcui.dll | 10.0.26100.7309 | Windows Gaming Internal CallableUI dll
|
| | gcdef.dll | 10.0.26100.1591 | Game Controllers Default Sheets
|
| | gdi32.dll | 10.0.26100.8036 | GDI Client DLL
|
| | gdi32full.dll | 10.0.26100.8036 | GDI Client DLL
|
| | gdiplus.dll | 10.0.26100.8036 | Microsoft GDI+
|
| | generaltel.dll | 10.0.26100.7920 | General Telemetry
|
| | genpix.dll | |
|
| | geocommon.dll | 10.0.26100.7309 | Geocommon
|
| | geolocation.dll | 10.0.26100.7309 | Geolocation Runtime DLL
|
| | getuname.dll | 10.0.26100.1 | Unicode name Dll for UCE
|
| | glmf32.dll | 10.0.26100.1150 | OpenGL Metafiling DLL
|
| | globinputhost.dll | 10.0.26100.7920 | Windows Globalization Extension API for Input
|
| | glu32.dll | 10.0.26100.1150 | OpenGL Utility Library DLL
|
| | gmsaclient.dll | 10.0.26100.7309 | "gmsaclient.DYNLINK"
|
| | gpapi.dll | 10.0.26100.7920 | Group Policy Client API
|
| | gpcsewrappercsp.dll | 10.0.26100.7920 | GPCSEWrapperCsp
|
| | gpedit.dll | 10.0.26100.7920 | GPEdit
|
| | gpprnext.dll | 10.0.26100.5074 | Group Policy Printer Extension
|
| | gpsvc.dll | 10.0.26100.7920 | Group Policy Client
|
| | gptext.dll | 10.0.26100.1150 | GPTExt
|
| | graphicscapture.dll | 10.0.26100.7920 | Microsoft Windows Graphics Capture Api
|
| | graphicsperfsvc.dll | 10.0.26100.7920 | GraphicsPerfSvc
|
| | hal.dll | 10.0.26100.1 | Hardware Abstraction Layer DLL
|
| | halextintclpiodma.dll | 10.0.26100.4202 | HAL Extension for Intel(R) Low Power Subsystem DMA Controller
|
| | halextintcpsedma.dll | 10.0.26100.4202 | HAL Extension for Intel(R) Platform Services Engine DMA Controller
|
| | halextpl080.dll | 10.0.26100.4202 | HAL Extension for PL080 DMA Controller
|
| | hanjads.dll | 10.0.26100.7309 | "HanjaDS.DYNLINK"
|
| | hascsp.dll | 10.0.26100.7309 | HealthAttestationCSP
|
| | hashtagds.dll | 10.0.26100.7309 | HASHTAGDS.DLL
|
| | hbaapi.dll | 10.0.26100.1 | HBA API data interface dll for HBA_API_Rev_2-18_2002MAR1.doc
|
| | hcproviders.dll | 10.0.26100.7309 | Security and Maintenance Providers
|
| | hdcphandler.dll | 10.0.26100.1150 | Hdcp Handler DLL
|
| | heatcore.dll | 10.0.26100.7309 | Microsoft (R) Windows HEAT processor framework
|
| | helppaneproxy.dll | 10.0.26100.5074 | Microsoft® Help Proxy
|
| | hgcpl.dll | 10.0.26100.7309 | HomeGroup Control Panel
|
| | hhsetup.dll | 10.0.26100.7705 | Microsoft® HTML Help
|
| | hid.dll | 10.0.26100.1150 | Hid User Library
|
| | hidcfu.dll | 1.0.0.0 | hidCfu Device
|
| | hidserv.dll | 10.0.26100.4484 | Human Interface Device Service
|
| | hlink.dll | 10.0.26100.7309 | Microsoft Office 2000 component
|
| | hmkd.dll | 10.0.26100.7309 | Windows HMAC Key Derivation API
|
| | hnetcfg.dll | 10.0.26100.7309 | Home Networking Configuration Manager
|
| | hnetcfgclient.dll | 10.0.26100.7309 | Home Networking Configuration API Client
|
| | hnetmon.dll | 10.0.26100.1150 | Home Networking Monitor DLL
|
| | hotpatchutil.dll | |
|
| | hotplug.dll | 10.0.26100.1882 | Safely Remove Hardware applet
|
| | hpatchmon.dll | 10.0.26100.7920 | Hotpatch Monitoring Service
|
| | hrtfapo.dll | 10.0.26100.7309 | Spatial Audio Processing Library
|
| | hrtfdspcpu.dll | 2024.0.80.0 | Microsoft (R) Spatial Audio DSP Library
|
| | hspapi.dll | 10.0.26100.7309 | Hardware Security Platfrom API Library
|
| | httpapi.dll | 10.0.26100.7920 | HTTP Protocol Stack API
|
| | httpprxc.dll | 10.0.26100.5074 | Proxy Manager Provider RPC interface
|
| | httpprxm.dll | 10.0.26100.7019 | Proxy Manager
|
| | httpprxp.dll | 10.0.26100.1 | Proxy Manager Provider RPC interface
|
| | httpsdatasource.dll | 10.0.26100.7920 | Https Data Source Library
|
| | htui.dll | 10.0.26100.1882 | Common halftone Color Adjustment Dialogs
|
| | hvhostsvc.dll | 10.0.26100.7309 | Microsoft Hypervisor Host Service
|
| | hvloader.dll | 10.0.26100.7824 | Hv Loader Library
|
| | hvsocket.dll | 10.0.26100.7309 | HvSocket Utilities DLL
|
| | hwreqchk.dll | |
|
| | ia2comproxy.dll | 10.0.26100.1 | IAccessible2 COM Proxy Stub DLL
|
| | ias.dll | 10.0.26100.3037 | Network Policy Server
|
| | iasacct.dll | 10.0.26100.7920 | NPS Accounting Provider
|
| | iasads.dll | 10.0.26100.5074 | NPS Active Directory Data Store
|
| | iasdatastore.dll | 10.0.26100.5074 | NPS Datastore server
|
| | iashlpr.dll | 10.0.26100.1882 | NPS Surrogate Component
|
| | iasmigplugin.dll | 10.0.26100.5074 | NPS Migration DLL
|
| | iasnap.dll | 10.0.26100.3323 | NPS NAP Provider
|
| | iaspolcy.dll | 10.0.26100.3037 | NPS Pipeline
|
| | iasrad.dll | 10.0.26100.5074 | NPS RADIUS Protocol Component
|
| | iasrecst.dll | 10.0.26100.5074 | NPS XML Datastore Access
|
| | iassam.dll | 10.0.26100.1882 | NPS NT SAM Provider
|
| | iassdo.dll | 10.0.26100.5074 | NPS SDO Component
|
| | iassvcs.dll | 10.0.26100.3037 | NPS Services Component
|
| | icfupgd.dll | 10.0.26100.7920 | Windows Firewal ICF Settings Upgrade
|
| | icm32.dll | 10.0.26100.2314 | Microsoft Color Management Module (CMM)
|
| | icmp.dll | 10.0.26100.1 | ICMP DLL
|
| | icmui.dll | 10.0.26100.1591 | Microsoft Color Matching System User Interface DLL
|
| | iconcodecservice.dll | 10.0.26100.1 | Converts a PNG part of the icon to a legacy bmp icon
|
| | icsigd.dll | 10.0.26100.1882 | Internet Gateway Device properties
|
| | icsvc.dll | 10.0.26100.7705 | Virtual Machine Integration Component Service
|
| | icsvcext.dll | 10.0.26100.7309 | Virtual Machine Integration Component Service
|
| | icsvcvss.dll | 10.0.26100.7309 | Virtual Machine Integration Components Volume Snapshot Service
|
| | icu.dll | 72.1.0.4 | ICU Combined Library
|
| | icuin.dll | 72.1.0.4 | ICU I18N Forwarder DLL (deprecated)
|
| | icuuc.dll | 72.1.0.4 | ICU Common Forwarder DLL (deprecated)
|
| | idctrls.dll | 10.0.26100.7824 | Identity Controls
|
| | idstore.dll | 10.0.26100.7019 | Identity Store
|
| | ieadvpack.dll | 11.0.26100.7309 | ADVPACK
|
| | ieapfltr.dll | 11.0.26100.7920 | Microsoft SmartScreen Filter
|
| | iedkcs32.dll | 18.0.26100.7309 | IEAK branding
|
| | ieframe.dll | 11.0.26100.7920 | Internet Browser
|
| | iemigplugin.dll | 11.0.26100.7920 | IE Migration Plugin
|
| | iepeers.dll | 11.0.26100.5074 | Internet Explorer Peer Objects
|
| | ieproxy.dll | 11.0.26100.3624 | IE ActiveX Interface Marshaling Library
|
| | ieproxydesktop.dll | 11.0.26100.1 | IE Desktop ActiveX Interface Marshaling Library
|
| | iernonce.dll | 11.0.26100.7309 | Extended RunOnce processing with UI
|
| | iertutil.dll | 11.0.26100.8036 | Run time utility for Internet Explorer
|
| | iesetup.dll | 11.0.26100.7309 | IOD Version Map
|
| | iesysprep.dll | 11.0.26100.7309 | IE Sysprep Provider
|
| | ieui.dll | 11.0.26100.7920 | Internet Explorer UI Engine
|
| | ifmon.dll | 10.0.26100.1150 | IF Monitor DLL
|
| | ifsutil.dll | 10.0.26100.7019 | IFS Utility DLL
|
| | ifsutilx.dll | 10.0.26100.1 | IFS Utility Extension DLL
|
| | ihds.dll | 10.0.26100.7309 | "IHDS.DYNLINK"
|
| | ikeext.dll | 10.0.26100.7920 | IKE extension
|
| | imagehlp.dll | 10.0.26100.4202 | Windows NT Image Helper
|
| | imageres.dll | 10.0.26100.7705 | Windows Image Resource
|
| | imagesp1.dll | 10.0.26100.1 | Windows SP1 Image Resource
|
| | imapi.dll | 10.0.26100.1150 | Image Mastering API
|
| | imapi2.dll | 10.0.26100.5074 | Image Mastering API v2
|
| | imapi2fs.dll | 10.0.26100.5074 | Image Mastering File System Imaging API v2
|
| | ime_textinputhelpers.dll | 10.0.26100.7309 | "IME_TextInputHelpers.DYNLINK"
|
| | imgutil.dll | 11.0.26100.5074 | IE plugin image decoder support DLL
|
| | imm32.dll | 10.0.26100.7309 | Multi-User Windows IMM32 API Client DLL
|
| | implatsetup.dll | 10.0.26100.7309 | NdisImPlatform Network Setup Plugin
|
| | indexeddblegacy.dll | 10.0.26100.7920 | "IndexedDbLegacy.DYNLINK"
|
| | inetcomm.dll | 10.0.26100.7309 | Microsoft Internet Messaging API Resources
|
| | inetmib1.dll | 10.0.26100.1150 | Microsoft MIB-II subagent
|
| | inetpp.dll | 10.0.26100.7309 | Internet Print Provider DLL
|
| | inetppui.dll | 10.0.26100.7309 | Internet Print Client DLL
|
| | inetres.dll | 10.0.26100.6725 | Microsoft Internet Messaging API Resources
|
| | inked.dll | 10.0.26100.5074 | Microsoft Tablet PC InkEdit Control
|
| | inkobjcore.dll | 10.0.26100.5074 | Microsoft Tablet PC Ink Platform Component
|
| | inproclogger.dll | 10.0.26100.7309 | In-proc Private Event Trace Logger
|
| | input.dll | 10.0.26100.7920 | InputSetting DLL
|
| | inputcloudstore.dll | 10.0.26100.7705 | Windows Input Cloud Store Task Handlers
|
| | inputcontroller.dll | 10.0.26100.1882 | Windows Perception Simulation Input Controller
|
| | inputhost.dll | 10.0.26100.7920 | InputHost
|
| | inputinjectionbroker.dll | 10.0.26100.7309 | Broker for WinRT input injection.
|
| | inputlocalemanager.dll | 10.0.26100.7309 | "InputLocaleManager.DYNLINK"
|
| | inputservice.dll | 10.0.26100.7920 | Microsoft Text InputService Dll
|
| | inputswitch.dll | 10.0.26100.7920 | Microsoft Windows Input Switcher
|
| | inputviewexperience.dll | 10.0.26100.7309 | InputViewExperience
|
| | inseng.dll | 11.0.26100.7309 | Install engine
|
| | installmon.dll | 10.0.26100.7920 | Application Install Tracing
|
| | installservice.dll | 10.0.26100.7920 | InstallService
|
| | installservicetasks.dll | 10.0.26100.7920 | InstallService Tasks
|
| | internetmail.dll | 10.0.26100.7309 | InternetMail sync engine for contacts, calendar
|
| | internetmailcsp.dll | 10.0.26100.7309 | Internet Mail CSP DLL
|
| | invagent.dll | 10.0.26100.7920 | Inventory Agent
|
| | inventorysvc.dll | 10.0.26100.7920 | Compatibility Inventory Service
|
| | iologmsg.dll | 10.0.26100.4202 | IO Logging DLL
|
| | iphlpapi.dll | 10.0.26100.7920 | IP Helper API
|
| | iphlpsvc.dll | 10.0.26100.7920 | Service that offers IPv6 connectivity over an IPv4 network.
|
| | ipnathlp.dll | 10.0.26100.7920 | Microsoft NAT Helper Components
|
| | ipnathlpclient.dll | 10.0.26100.1 | IP NAT Helper Client
|
| | ippcommon.dll | 10.0.26100.7920 | IppCommon dll
|
| | ippcommonproxy.dll | 10.0.26100.1150 | IppCommon COM Proxy dll
|
| | iprtprio.dll | 10.0.26100.7920 | IP Routing Protocol Priority DLL
|
| | iprtrmgr.dll | 10.0.26100.7920 | IP Router Manager
|
| | ipsecsnp.dll | 10.0.26100.5074 | IP Security Policy Management Snap-in
|
| | ipsecsvc.dll | 10.0.26100.5074 | Windows IPsec SPD Server DLL
|
| | ipsmsnap.dll | 10.0.26100.7462 | IP Security Monitor Snap-in
|
| | ipxlatcfg.dll | 10.0.26100.7920 | IP Translation Configuration Service
|
| | iri.dll | 10.0.26100.1 | iri
|
| | iscsicpl.dll | 5.2.3790.1830 | iSCSI Initiator Control Panel Applet
|
| | iscsidsc.dll | 10.0.26100.3037 | iSCSI Discovery api
|
| | iscsied.dll | 10.0.26100.3037 | iSCSI Extension DLL
|
| | iscsiexe.dll | 10.0.26100.5074 | iSCSI Discovery service
|
| | iscsilog.dll | 10.0.26100.4202 | iSCSI Event Log DLL
|
| | iscsium.dll | 10.0.26100.5074 | iSCSI Discovery api
|
| | iscsiwmi.dll | 10.0.26100.3037 | MS iSCSI Initiator WMI Provider
|
| | iscsiwmiv2.dll | 10.0.26100.3037 | WMI Provider for iSCSI
|
| | ism.dll | 10.0.26100.7920 | ISM
|
| | itircl.dll | 10.0.26100.5074 | Microsoft® InfoTech IR Local DLL
|
| | itss.dll | 10.0.26100.7705 | Microsoft® InfoTech Storage System Library
|
| | iuilp.dll | 10.0.26100.7309 | iuilp
|
| | iumbase.dll | 10.0.26100.7623 | IUM Layer Secure Win32 DLL
|
| | iumcrypt.dll | 10.0.26100.7705 | IUM Crypto Support Routines
|
| | iumdll.dll | 10.0.26100.7623 | IUM Layer DLL
|
| | iumsdk.dll | 10.0.26100.7623 | IumSdk DLL
|
| | iyuv_32.dll | 10.0.26100.1150 | Intel Indeo(R) Video YUV Codec
|
| | javascriptcollectionagent.dll | 11.0.26100.1150 | JavaScript Performance Collection Agent
|
| | joinproviderol.dll | 10.0.26100.7019 | Online Join Provider DLL
|
| | joinutil.dll | 10.0.26100.3775 | Join Utility DLL
|
| | jpmapcontrol.dll | 10.0.26100.7309 | Jupiter Map Control
|
| | jpndecoder.dll | 10.0.26100.7309 | "JpnDecoder.DYNLINK"
|
| | jpninputrouter.dll | 10.0.26100.7309 | "JpnInputRouter.DYNLINK"
|
| | jpnranker.dll | 10.0.26100.7309 | "JpnRanker.DYNLINK"
|
| | jpnserviceds.dll | 10.0.26100.7309 | "JpnServiceDS.DYNLINK"
|
| | jscript.dll | 10.0.26100.7920 | Microsoft ® JScript
|
| | jscript9.dll | 11.0.26100.7920 | Microsoft ® JScript
|
| | jscript9diag.dll | 11.0.26100.7920 | Microsoft ® JScript Diagnostics
|
| | jscript9legacy.dll | 11.0.26100.7920 | Microsoft ® JScript
|
| | jsproxy.dll | 11.0.26100.7920 | JScript Proxy Auto-Configuration
|
| | kbd101.dll | 10.0.26100.2454 | JP Japanese Keyboard Layout for 101
|
| | kbd101a.dll | 10.0.26100.2454 | KO Hangeul Keyboard Layout for 101 (Type A)
|
| | kbd101b.dll | 10.0.26100.2454 | KO Hangeul Keyboard Layout for 101(Type B)
|
| | kbd101c.dll | 10.0.26100.2454 | KO Hangeul Keyboard Layout for 101(Type C)
|
| | kbd103.dll | 10.0.26100.2454 | KO Hangeul Keyboard Layout for 103
|
| | kbd106.dll | 10.0.26100.2454 | JP Japanese Keyboard Layout for 106
|
| | kbd106n.dll | 10.0.26100.2454 | JP Japanese Keyboard Layout for 106
|
| | kbda1.dll | 10.0.26100.7309 | Arabic_English_101 Keyboard Layout
|
| | kbda2.dll | 10.0.26100.7309 | Arabic_2 Keyboard Layout
|
| | kbda3.dll | 10.0.26100.7309 | Arabic_French_102 Keyboard Layout
|
| | kbdadlm.dll | 10.0.26100.2454 | Adlam Keyboard Layout
|
| | kbdal.dll | 10.0.26100.2454 | Albania Keyboard Layout
|
| | kbdarme.dll | 10.0.26100.2454 | Eastern Armenian Keyboard Layout
|
| | kbdarmph.dll | 10.0.26100.2454 | Armenian Phonetic Keyboard Layout
|
| | kbdarmty.dll | 10.0.26100.2454 | Armenian Typewriter Keyboard Layout
|
| | kbdarmw.dll | 10.0.26100.2454 | Western Armenian Keyboard Layout
|
| | kbdax2.dll | 10.0.26100.2454 | JP Japanese Keyboard Layout for AX2
|
| | kbdaze.dll | 10.0.26100.2454 | Azerbaijan_Cyrillic Keyboard Layout
|
| | kbdazel.dll | 10.0.26100.2454 | Azeri-Latin Keyboard Layout
|
| | kbdazst.dll | 10.0.26100.2454 | Azerbaijani (Standard) Keyboard Layout
|
| | kbdbash.dll | 10.0.26100.2454 | Bashkir Keyboard Layout
|
| | kbdbe.dll | 10.0.26100.2454 | Belgian Keyboard Layout
|
| | kbdbene.dll | 10.0.26100.2454 | Belgian Dutch Keyboard Layout
|
| | kbdbgph.dll | 10.0.26100.2454 | Bulgarian Phonetic Keyboard Layout
|
| | kbdbgph1.dll | 10.0.26100.2454 | Bulgarian (Phonetic Traditional) Keyboard Layout
|
| | kbdbhc.dll | 10.0.26100.2454 | Bosnian (Cyrillic) Keyboard Layout
|
| | kbdblr.dll | 10.0.26100.2454 | Belarusian Keyboard Layout
|
| | kbdbr.dll | 10.0.26100.2454 | Brazilian Keyboard Layout
|
| | kbdbu.dll | 10.0.26100.2454 | Bulgarian (Typewriter) Keyboard Layout
|
| | kbdbug.dll | 10.0.26100.2454 | Buginese Keyboard Layout
|
| | kbdbulg.dll | 10.0.26100.2454 | Bulgarian Keyboard Layout
|
| | kbdca.dll | 10.0.26100.2454 | Canadian Multilingual Keyboard Layout
|
| | kbdcan.dll | 10.0.26100.2454 | Canadian Multilingual Standard Keyboard Layout
|
| | kbdcher.dll | 10.0.26100.2454 | Cherokee Nation Keyboard Layout
|
| | kbdcherp.dll | 10.0.26100.2454 | Cherokee Phonetic Keyboard Layout
|
| | kbdcmk.dll | 10.0.26100.2454 | Colemak Keyboard Layout
|
| | kbdcr.dll | 10.0.26100.2454 | Croatian/Slovenian Keyboard Layout
|
| | kbdcz.dll | 10.0.26100.2454 | Czech Keyboard Layout
|
| | kbdcz1.dll | 10.0.26100.2454 | Czech_101 Keyboard Layout
|
| | kbdcz2.dll | 10.0.26100.2454 | Czech_Programmer's Keyboard Layout
|
| | kbdda.dll | 10.0.26100.2454 | Danish Keyboard Layout
|
| | kbddiv1.dll | 10.0.26100.2454 | Divehi Phonetic Keyboard Layout
|
| | kbddiv2.dll | 10.0.26100.2454 | Divehi Typewriter Keyboard Layout
|
| | kbddv.dll | 10.0.26100.2454 | Dvorak US English Keyboard Layout
|
| | kbddzo.dll | 10.0.26100.2454 | Dzongkha Keyboard Layout
|
| | kbdes.dll | 10.0.26100.2454 | Spanish Alernate Keyboard Layout
|
| | kbdest.dll | 10.0.26100.2454 | Estonia Keyboard Layout
|
| | kbdfa.dll | 10.0.26100.2454 | Persian Keyboard Layout
|
| | kbdfar.dll | 10.0.26100.2454 | Persian Standard Keyboard Layout
|
| | kbdfc.dll | 10.0.26100.2454 | Canadian French Keyboard Layout
|
| | kbdfi.dll | 10.0.26100.2454 | Finnish Keyboard Layout
|
| | kbdfi1.dll | 10.0.26100.2454 | Finnish-Swedish with Sami Keyboard Layout
|
| | kbdfo.dll | 10.0.26100.2454 | Færoese Keyboard Layout
|
| | kbdfr.dll | 10.0.26100.2454 | French Keyboard Layout
|
| | kbdfrna.dll | 10.0.26100.2454 | French (Standard, AZERTY) Keyboard Layout
|
| | kbdfrnb.dll | 10.0.26100.2454 | French (Standard, BÉPO) Keyboard Layout
|
| | kbdfthrk.dll | 10.0.26100.2454 | Futhark Keyboard Layout
|
| | kbdgae.dll | 10.0.26100.2454 | Scottish Gaelic (United Kingdom) Keyboard Layout
|
| | kbdgeo.dll | 10.0.26100.2454 | Georgian Keyboard Layout
|
| | kbdgeoer.dll | 10.0.26100.2454 | Georgian (Ergonomic) Keyboard Layout
|
| | kbdgeome.dll | 10.0.26100.2454 | Georgian (MES) Keyboard Layout
|
| | kbdgeooa.dll | 10.0.26100.2454 | Georgian (Old Alphabets) Keyboard Layout
|
| | kbdgeoqw.dll | 10.0.26100.2454 | Georgian (QWERTY) Keyboard Layout
|
| | kbdgkl.dll | 10.0.26100.2454 | Greek_Latin Keyboard Layout
|
| | kbdgn.dll | 10.0.26100.2454 | Guarani Keyboard Layout
|
| | kbdgr.dll | 10.0.26100.2454 | German Keyboard Layout
|
| | kbdgr1.dll | 10.0.26100.2454 | German_IBM Keyboard Layout
|
| | kbdgre1.dll | 10.0.26100.2454 | German Extended (E1) Keyboard Layout
|
| | kbdgre2.dll | 10.0.26100.2454 | German Extended (E2) Keyboard Layout
|
| | kbdgrlnd.dll | 10.0.26100.2454 | Greenlandic Keyboard Layout
|
| | kbdgthc.dll | 10.0.26100.2454 | Gothic Keyboard Layout
|
| | kbdhau.dll | 10.0.26100.2454 | Hausa Keyboard Layout
|
| | kbdhaw.dll | 10.0.26100.2454 | Hawaiian Keyboard Layout
|
| | kbdhe.dll | 10.0.26100.2454 | Greek Keyboard Layout
|
| | kbdhe220.dll | 10.0.26100.2454 | Greek IBM 220 Keyboard Layout
|
| | kbdhe319.dll | 10.0.26100.2454 | Greek IBM 319 Keyboard Layout
|
| | kbdheb.dll | 10.0.26100.2454 | KBDHEB Keyboard Layout
|
| | kbdhebl3.dll | 10.0.26100.2454 | Hebrew Standard Keyboard Layout
|
| | kbdhebsi.dll | 10.0.26100.2454 | Hebrew (Standard, 2018) Keyboard Layout
|
| | kbdhela2.dll | 10.0.26100.2454 | Greek IBM 220 Latin Keyboard Layout
|
| | kbdhela3.dll | 10.0.26100.2454 | Greek IBM 319 Latin Keyboard Layout
|
| | kbdhept.dll | 10.0.26100.2454 | Greek_Polytonic Keyboard Layout
|
| | kbdhu.dll | 10.0.26100.2454 | Hungarian Keyboard Layout
|
| | kbdhu1.dll | 10.0.26100.2454 | Hungarian 101-key Keyboard Layout
|
| | kbdibm02.dll | 10.0.26100.2454 | JP Japanese Keyboard Layout for IBM 5576-002/003
|
| | kbdibo.dll | 10.0.26100.2454 | Igbo Keyboard Layout
|
| | kbdic.dll | 10.0.26100.2454 | Icelandic Keyboard Layout
|
| | kbdinasa.dll | 10.0.26100.2454 | Assamese (Inscript) Keyboard Layout
|
| | kbdinbe1.dll | 10.0.26100.2454 | Bengali - Inscript (Legacy) Keyboard Layout
|
| | kbdinbe2.dll | 10.0.26100.2454 | Bengali (Inscript) Keyboard Layout
|
| | kbdinben.dll | 10.0.26100.2454 | Bengali Keyboard Layout
|
| | kbdindev.dll | 10.0.26100.2454 | Devanagari Keyboard Layout
|
| | kbdinen.dll | 10.0.26100.2454 | English (India) Keyboard Layout
|
| | kbdinguj.dll | 10.0.26100.2454 | Gujarati Keyboard Layout
|
| | kbdinhin.dll | 10.0.26100.2454 | Hindi Keyboard Layout
|
| | kbdinkan.dll | 10.0.26100.2454 | Kannada Keyboard Layout
|
| | kbdinmal.dll | 10.0.26100.2454 | Malayalam Keyboard Layout Keyboard Layout
|
| | kbdinmar.dll | 10.0.26100.2454 | Marathi Keyboard Layout
|
| | kbdinori.dll | 10.0.26100.2454 | Odia Keyboard Layout
|
| | kbdinpun.dll | 10.0.26100.2454 | Punjabi/Gurmukhi Keyboard Layout
|
| | kbdintam.dll | 10.0.26100.2454 | Tamil Keyboard Layout
|
| | kbdintel.dll | 10.0.26100.2454 | Telugu Keyboard Layout
|
| | kbdinuk2.dll | 10.0.26100.2454 | Inuktitut Naqittaut Keyboard Layout
|
| | kbdinuk3.dll | 10.0.26100.3624 | Inuktitut - Nattilik Keyboard Layout
|
| | kbdir.dll | 10.0.26100.2454 | Irish Keyboard Layout
|
| | kbdit.dll | 10.0.26100.2454 | Italian Keyboard Layout
|
| | kbdit142.dll | 10.0.26100.2454 | Italian 142 Keyboard Layout
|
| | kbdiulat.dll | 10.0.26100.2454 | Inuktitut Latin Keyboard Layout
|
| | kbdjav.dll | 10.0.26100.2454 | Javanese Keyboard Layout
|
| | kbdjpn.dll | 10.0.26100.2454 | JP Japanese Keyboard Layout Stub driver
|
| | kbdkaz.dll | 10.0.26100.2454 | Kazak_Cyrillic Keyboard Layout
|
| | kbdkhmr.dll | 10.0.26100.2454 | Cambodian Standard Keyboard Layout
|
| | kbdkni.dll | 10.0.26100.2454 | Khmer (NIDA) Keyboard Layout
|
| | kbdkor.dll | 10.0.26100.2454 | KO Hangeul Keyboard Layout Stub driver
|
| | kbdkurd.dll | 10.0.26100.2454 | Central Kurdish Keyboard Layout
|
| | kbdkyr.dll | 10.0.26100.2454 | Kyrgyz Keyboard Layout
|
| | kbdla.dll | 10.0.26100.2454 | Latin-American Spanish Keyboard Layout
|
| | kbdlao.dll | 10.0.26100.2454 | Lao Standard Keyboard Layout
|
| | kbdlisub.dll | 10.0.26100.2454 | Lisu Basic Keyboard Layout
|
| | kbdlisus.dll | 10.0.26100.2454 | Lisu Standard Keyboard Layout
|
| | kbdlk41a.dll | 10.0.26100.2454 | DEC LK411-AJ Keyboard Layout
|
| | kbdlt.dll | 10.0.26100.2454 | Lithuania Keyboard Layout
|
| | kbdlt1.dll | 10.0.26100.2454 | Lithuanian Keyboard Layout
|
| | kbdlt2.dll | 10.0.26100.2454 | Lithuanian Standard Keyboard Layout
|
| | kbdlv.dll | 10.0.26100.2454 | Latvia Keyboard Layout
|
| | kbdlv1.dll | 10.0.26100.2454 | Latvia-QWERTY Keyboard Layout
|
| | kbdlvst.dll | 10.0.26100.2454 | Latvian (Standard) Keyboard Layout
|
| | kbdmac.dll | 10.0.26100.2454 | Macedonian (North Macedonia) Keyboard Layout
|
| | kbdmacst.dll | 10.0.26100.2454 | Macedonian (North Macedonia) - Standard Keyboard Layout
|
| | kbdmaori.dll | 10.0.26100.2454 | Maori Keyboard Layout
|
| | kbdmlt47.dll | 10.0.26100.2454 | Maltese 47-key Keyboard Layout
|
| | kbdmlt48.dll | 10.0.26100.2454 | Maltese 48-key Keyboard Layout
|
| | kbdmon.dll | 10.0.26100.2454 | Mongolian Keyboard Layout
|
| | kbdmonmo.dll | 10.0.26100.2454 | Mongolian (Mongolian Script) Keyboard Layout
|
| | kbdmons2.dll | 10.0.26100.3624 | Traditional Mongolian (MNS) Keyboard Layout
|
| | kbdmonst.dll | 10.0.26100.2454 | Traditional Mongolian (Standard) Keyboard Layout
|
| | kbdmyan.dll | 10.0.26100.2454 | Myanmar Keyboard Layout
|
| | kbdne.dll | 10.0.26100.2454 | Dutch Keyboard Layout
|
| | kbdnec.dll | 10.0.26100.2454 | JP Japanese Keyboard Layout for (NEC PC-9800)
|
| | kbdnec95.dll | 10.0.26100.2454 | JP Japanese Keyboard Layout for (NEC PC-9800 Windows 95)
|
| | kbdnecat.dll | 10.0.26100.2454 | JP Japanese Keyboard Layout for (NEC PC-9800 on PC98-NX)
|
| | kbdnecnt.dll | 10.0.26100.2454 | JP Japanese NEC PC-9800 Keyboard Layout
|
| | kbdnepr.dll | 10.0.26100.2454 | Nepali Keyboard Layout
|
| | kbdnko.dll | 10.0.26100.2454 | N'Ko Keyboard Layout
|
| | kbdno.dll | 10.0.26100.2454 | Norwegian Keyboard Layout
|
| | kbdno1.dll | 10.0.26100.2454 | Norwegian with Sami Keyboard Layout
|
| | kbdnso.dll | 10.0.26100.2454 | Sesotho sa Leboa Keyboard Layout
|
| | kbdntl.dll | 10.0.26100.2454 | New Tai Leu Keyboard Layout
|
| | kbdogham.dll | 10.0.26100.2454 | Ogham Keyboard Layout
|
| | kbdolch.dll | 10.0.26100.2454 | Ol Chiki Keyboard Layout
|
| | kbdoldit.dll | 10.0.26100.2454 | Old Italic Keyboard Layout
|
| | kbdosa.dll | 10.0.26100.2454 | Osage Keyboard Layout
|
| | kbdosm.dll | 10.0.26100.2454 | Osmanya Keyboard Layout
|
| | kbdpash.dll | 10.0.26100.2454 | Pashto (Afghanistan) Keyboard Layout
|
| | kbdphags.dll | 10.0.26100.2454 | Phags-pa Keyboard Layout
|
| | kbdpl.dll | 10.0.26100.2454 | Polish Keyboard Layout
|
| | kbdpl1.dll | 10.0.26100.2454 | Polish Programmer's Keyboard Layout
|
| | kbdpo.dll | 10.0.26100.2454 | Portuguese Keyboard Layout
|
| | kbdro.dll | 10.0.26100.2454 | Romanian (Legacy) Keyboard Layout
|
| | kbdropr.dll | 10.0.26100.2454 | Romanian (Programmers) Keyboard Layout
|
| | kbdrost.dll | 10.0.26100.2454 | Romanian (Standard) Keyboard Layout
|
| | kbdru.dll | 10.0.26100.2454 | Russian Keyboard Layout
|
| | kbdru1.dll | 10.0.26100.2454 | Russia(Typewriter) Keyboard Layout
|
| | kbdrum.dll | 10.0.26100.2454 | Russian - Mnemonic Keyboard Layout
|
| | kbdsf.dll | 10.0.26100.2454 | Swiss French Keyboard Layout
|
| | kbdsg.dll | 10.0.26100.2454 | Swiss German Keyboard Layout
|
| | kbdsl.dll | 10.0.26100.2454 | Slovak Keyboard Layout
|
| | kbdsl1.dll | 10.0.26100.2454 | Slovak(QWERTY) Keyboard Layout
|
| | kbdsmsfi.dll | 10.0.26100.2454 | Sami Extended Finland-Sweden Keyboard Layout
|
| | kbdsmsno.dll | 10.0.26100.2454 | Sami Extended Norway Keyboard Layout
|
| | kbdsn1.dll | 10.0.26100.2454 | Sinhala Keyboard Layout
|
| | kbdsora.dll | 10.0.26100.2454 | Sora Keyboard Layout
|
| | kbdsorex.dll | 10.0.26100.2454 | Sorbian Extended Keyboard Layout
|
| | kbdsors1.dll | 10.0.26100.2454 | Sorbian Standard Keyboard Layout
|
| | kbdsorst.dll | 10.0.26100.2454 | Sorbian Standard (Legacy) Keyboard Layout
|
| | kbdsp.dll | 10.0.26100.2454 | Spanish Keyboard Layout
|
| | kbdsw.dll | 10.0.26100.2454 | Swedish Keyboard Layout
|
| | kbdsw09.dll | 10.0.26100.2454 | Sinhala - Wij 9 Keyboard Layout
|
| | kbdsyr1.dll | 10.0.26100.2454 | Syriac Standard Keyboard Layout
|
| | kbdsyr2.dll | 10.0.26100.2454 | Syriac Phoenetic Keyboard Layout
|
| | kbdtaile.dll | 10.0.26100.2454 | Tai Le Keyboard Layout
|
| | kbdtajik.dll | 10.0.26100.2454 | Tajik Keyboard Layout
|
| | kbdtam99.dll | 10.0.26100.2454 | Tamil99Keyboard Keyboard Layout
|
| | kbdtat.dll | 10.0.26100.2454 | Tatar (Legacy) Keyboard Layout
|
| | kbdth0.dll | 10.0.26100.2454 | Thai Kedmanee Keyboard Layout
|
| | kbdth1.dll | 10.0.26100.2454 | Thai Pattachote Keyboard Layout
|
| | kbdth2.dll | 10.0.26100.2454 | Thai Kedmanee (non-ShiftLock) Keyboard Layout
|
| | kbdth3.dll | 10.0.26100.2454 | Thai Pattachote (non-ShiftLock) Keyboard Layout
|
| | kbdtifi.dll | 10.0.26100.2454 | Tifinagh (Basic) Keyboard Layout
|
| | kbdtifi2.dll | 10.0.26100.2454 | Tifinagh (Extended) Keyboard Layout
|
| | kbdtiprc.dll | 10.0.26100.2454 | Tibetan (PRC) Keyboard Layout
|
| | kbdtiprd.dll | 10.0.26100.2454 | Tibetan (PRC) - Updated Keyboard Layout
|
| | kbdtt102.dll | 10.0.26100.2454 | Tatar Keyboard Layout
|
| | kbdtuf.dll | 10.0.26100.2454 | Turkish F Keyboard Layout
|
| | kbdtuq.dll | 10.0.26100.2454 | Turkish Q Keyboard Layout
|
| | kbdturme.dll | 10.0.26100.2454 | Turkmen Keyboard Layout
|
| | kbdtzm.dll | 10.0.26100.2454 | Central Atlas Tamazight Keyboard Layout
|
| | kbdughr.dll | 10.0.26100.2454 | Uyghur (Legacy) Keyboard Layout
|
| | kbdughr1.dll | 10.0.26100.2454 | Uyghur Keyboard Layout
|
| | kbduk.dll | 10.0.26100.2454 | United Kingdom Keyboard Layout
|
| | kbdukx.dll | 10.0.26100.2454 | United Kingdom Extended Keyboard Layout
|
| | kbdur.dll | 10.0.26100.2454 | Ukrainian Keyboard Layout
|
| | kbdur1.dll | 10.0.26100.2454 | Ukrainian (Enhanced) Keyboard Layout
|
| | kbdurdu.dll | 10.0.26100.2454 | Urdu Keyboard Layout
|
| | kbdus.dll | 10.0.26100.4202 | United States Keyboard Layout
|
| | kbdusa.dll | 10.0.26100.2454 | US IBM Arabic 238_L Keyboard Layout
|
| | kbdusl.dll | 10.0.26100.2454 | Dvorak Left-Hand US English Keyboard Layout
|
| | kbdusr.dll | 10.0.26100.2454 | Dvorak Right-Hand US English Keyboard Layout
|
| | kbdusx.dll | 10.0.26100.2454 | US Multinational Keyboard Layout
|
| | kbduzb.dll | 10.0.26100.2454 | Uzbek_Cyrillic Keyboard Layout
|
| | kbdvntc.dll | 10.0.26100.2454 | Vietnamese Keyboard Layout
|
| | kbdwol.dll | 10.0.26100.2454 | Wolof Keyboard Layout
|
| | kbdyak.dll | 10.0.26100.2454 | Sakha - Russia Keyboard Layout
|
| | kbdyba.dll | 10.0.26100.2454 | Yoruba Keyboard Layout
|
| | kbdycc.dll | 10.0.26100.2454 | Serbian (Cyrillic) Keyboard Layout
|
| | kbdycl.dll | 10.0.26100.2454 | Serbian (Latin) Keyboard Layout
|
| | kd.dll | 10.0.26100.1 | Local Kernel Debugger
|
| | kd_02_10df.dll | 10.0.26100.7309 | Emulex Network Kernel Debug Extensibility Module
|
| | kd_02_10ec.dll | 10.0.26100.7309 | Realtek Network Kernel Debug Extensibility Module
|
| | kd_02_1137.dll | 10.0.26100.7309 | Cisco Vic Network Kernel Debug Extensibility Module
|
| | kd_02_1414.dll | 10.0.26100.7309 | Mana Network Kernel Debug Extensibility Module
|
| | kd_02_14e4.dll | 10.0.26100.7309 | Broadcom Network Kernel Debug Extensibility Module
|
| | kd_02_15ad.dll | |
|
| | kd_02_15b3.dll | 10.0.26100.7309 | Mellanox ConnectX Network Kernel Debug Extensibility Module
|
| | kd_02_1969.dll | 10.0.26100.7309 | Qualcomm Atheros Network Kernel Debug Extensibility Module
|
| | kd_02_19a2.dll | 10.0.26100.7309 | Emulex Network Kernel Debug Extensibility Module
|
| | kd_02_1af4.dll | 10.0.26100.7309 | VirtIO Network Kernel Debug Extensibility Module
|
| | kd_02_1d0f.dll | 10.0.26100.7309 | Ena Network Kernel Debug Extensibility Module
|
| | kd_02_8086.dll | 10.0.26100.7309 | Intel Network Kernel Debug Extensibility Module
|
| | kd_07_1415.dll | 10.0.26100.7309 | Network Kernel Debug Serial Extensibility Module
|
| | kd_0c_8086.dll | 10.0.26100.7309 | Intel USB Network Kernel Debug Extensibility Module
|
| | kdcom.dll | 10.0.26100.1882 | Serial Kernel Debugger
|
| | kdcpw.dll | 10.0.26100.7623 | KDCPW
|
| | kdhvcom.dll | 10.0.26100.1150 | Enlightened Kernel Serial Debugger Extension DLL
|
| | kdnet.dll | 10.0.26100.7705 | Network Kernel Debugger
|
| | kdnet_uart16550.dll | 10.0.26100.7309 | Network Kernel Debug Serial Extensibility Module
|
| | kdscli.dll | 10.0.26100.7623 | Microsoft Key Distribution Service Provider
|
| | kdstub.dll | 10.0.26100.7705 | Network Kernel Debug Extensibility Stubs
|
| | kdusb.dll | 10.0.26100.1882 | USB 2.0 Kernel Debugger
|
| | keepaliveprovider.dll | 10.0.26100.3037 | Keep alive provider API
|
| | kerb3961.dll | 10.0.26100.7920 | Kerberos cipher suites (RFC 3961)
|
| | kerbclientshared.dll | 10.0.26100.7824 | Kerberos Client Shared Functionality
|
| | kerberos.dll | 10.0.26100.7920 | Kerberos Security Package
|
| | kernel.appcore.dll | 10.0.26100.7920 | AppModel API Host
|
| | kernel32.dll | 10.0.26100.7920 | Windows NT BASE API Client DLL
|
| | kernelbase.dll | 10.0.26100.7920 | Windows NT BASE API Client DLL
|
| | keycredmgr.dll | 10.0.26100.7309 | Microsoft Key Credential Manager
|
| | keyiso.dll | 10.0.26100.7019 | CNG Key Isolation Service
|
| | keymgr.dll | 10.0.26100.1150 | Stored User Names and Passwords
|
| | keyworddetectormsftsidadapter.dll | 10.0.26100.7309 | Microsoft keyword detector adapter for speaker id
|
| | knobscore.dll | 10.0.26100.7309 | Knobs Core Library
|
| | knobscsp.dll | 10.0.26100.7309 | Knobs CSP
|
| | ksuser.dll | 10.0.26100.1150 | User CSA Library
|
| | ktmw32.dll | 10.0.26100.1 | Windows KTM Win32 Client DLL
|
| | l2gpstore.dll | 10.0.26100.1150 | Policy Storage dll
|
| | l2nacp.dll | 10.0.26100.1150 | Windows Onex Credential Provider
|
| | lamparray.dll | 10.0.26100.7920 | LampArray DLL for Dynamic Lighting
|
| | langcleanupsysprepaction.dll | 10.0.26100.4484 | Language cleanup Sysprep action
|
| | languagecomponentsinstaller.dll | 10.0.26100.7920 | LanguageComponentsInstaller Task
|
| | languageoverlayserver.dll | 10.0.26100.7705 | Provides infrastructure support for deploying and configuring localized Windows resources.
|
| | languageoverlayutil.dll | 10.0.26100.7309 | Provides helper APIs for managing overlaid localized Windows resources.
|
| | languagepackdiskcleanup.dll | 10.0.26100.7920 | Language Pack Disk Cleanup
|
| | languagepackmanagementcsp.dll | 10.0.26100.7309 | LanguagePackManagementCSP
|
| | laprxy.dll | 12.0.26100.1 | Windows Media Logagent Proxy
|
| | laps.dll | 10.0.26100.7920 | LAPS Server DLL
|
| | lapscsp.dll | 10.0.26100.7309 | LAPS CSP DLL
|
| | legacynetux.dll | 10.0.26100.1882 | Legacy Net UX DLL
|
| | legacysystemsettings.dll | 10.0.26100.7309 | Legacy System Settings Extension Point
|
| | lfsvc.dll | 10.0.26100.7309 | Geolocation Service
|
| | libcrypto.dll | 3.8.2.0 | LibreSSL
|
| | liblouis.dll | |
|
| | libsmartscreenn.dll | |
|
| | licensemanager.dll | 10.0.26100.7920 | LicenseManager
|
| | licensemanagerapi.dll | 10.0.26100.7309 | "LicenseManagerApi.DYNLINK"
|
| | licensemanagersvc.dll | 10.0.26100.7920 | LicenseManagerSvc
|
| | licenseprotection.dll | 10.0.26100.7309 | LicenseProtection
|
| | licensingcsp.dll | 10.0.26100.7309 | LicensingCSP
|
| | licensingdiagspp.dll | 10.0.26100.7309 | Licensing Diagnostics SPP Plugin
|
| | licensingwinrt.dll | 10.0.26100.7920 | LicensingWinRuntime
|
| | licmgr10.dll | 11.0.26100.1150 | Microsoft® License Manager DLL
|
| | linkinfo.dll | 10.0.26100.1 | Windows Volume Tracking
|
| | lltdapi.dll | 10.0.26100.7920 | Link-Layer Topology Mapper API
|
| | lltdres.dll | 10.0.26100.1 | Link-Layer Topology Discovery Resources
|
| | lltdsvc.dll | 10.0.26100.7920 | Link-Layer Topology Mapper Service
|
| | lmhsvc.dll | 10.0.26100.1882 | TCPIP NetBios Transport Services DLL
|
| | loadperf.dll | 10.0.26100.7705 | Load & Unload Performance Counters
|
| | localkdcsvc.dll | 10.0.26100.7920 | Local KDC Service
|
| | localsec.dll | 10.0.26100.7309 | Local Users and Groups MMC Snapin
|
| | localspl.dll | 10.0.26100.7920 | Local Spooler DLL
|
| | localui.dll | 10.0.26100.6899 | Local Monitor UI DLL
|
| | locationapi.dll | 10.0.26100.7309 | Microsoft Windows Location API
|
| | locationframework.dll | 10.0.26100.7920 | Windows Geolocation Framework
|
| | locationframeworkinternalps.dll | 10.0.26100.7019 | Windows Geolocation Framework Internal PS
|
| | locationframeworkps.dll | 10.0.26100.7019 | Windows Geolocation Framework PS
|
| | locationwinpalmisc.dll | 10.0.26100.7920 | Windows Location Platform Abstraction Layer
|
| | lockappbroker.dll | 10.0.26100.7824 | Windows Lock App Broker DLL
|
| | lockcontroller.dll | 10.0.26100.7920 | LockController
|
| | lockhostingframework.dll | 10.0.26100.7824 | LockHostingFramework
|
| | lockscreencontent.dll | 10.0.26100.7920 | Windows Lock Screen Content
|
| | lockscreencontenthost.dll | 10.0.26100.7309 | LockScreenContent Host
|
| | lockscreendata.dll | 10.0.26100.7824 | Windows Lock Screen Data DLL
|
| | loghours.dll | 10.0.26100.1882 | Schedule Dialog
|
| | logoncli.dll | 10.0.26100.7705 | Net Logon Client DLL
|
| | logoncontroller.dll | 10.0.26100.7920 | Logon UX Controller
|
| | lpasvc.dll | 10.0.26100.7920 | Local Profile Assistant Service
|
| | lpk.dll | 10.0.26100.7705 | Language Pack
|
| | lpksetupproxyserv.dll | 10.0.26100.4484 | COM proxy server for lpksetup.exe
|
| | lsaadt.dll | 10.0.26100.8036 | Local Security Authority Auditing
|
| | lsasrv.dll | 10.0.26100.8036 | LSA Server DLL
|
| | lsm.dll | 10.0.26100.8036 | Local Session Manager Service
|
| | lsmproxy.dll | 10.0.26100.7705 | LSM interfaces proxy Dll
|
| | luiapi.dll | 10.0.26100.7920 | LUI API
|
| | lxutil.dll | 10.0.26100.1150 | lxutil
|
| | lz32.dll | 5.0.1.1 | LZ Expand/Compress API DLL
|
| | magnification.dll | 10.0.26100.1150 | Microsoft Magnification API
|
| | maintenanceui.dll | 10.0.26100.7309 | Maintenance Settings Control Panel
|
| | manageci.dll | 10.0.26100.7705 | Code Integrity Management Interface
|
| | mapconfiguration.dll | 10.0.26100.7309 | MapConfiguration
|
| | mapcontrolcore.dll | 10.0.26100.7309 | Map Control Core
|
| | mapcontrolstringsres.dll | 10.0.26100.1882 | Map control resource strings
|
| | mapgeocoder.dll | 10.0.26100.7309 | Maps Geocoder
|
| | mapi32.dll | 1.0.2536.0 | Extended MAPI 1.0 for Windows NT
|
| | mapistub.dll | 1.0.2536.0 | Extended MAPI 1.0 for Windows NT
|
| | maprouter.dll | 10.0.26100.7705 | Maps Router
|
| | mapsbtsvc.dll | 10.0.26100.7309 | Maps Background Transfer Service
|
| | mapsbtsvcproxy.dll | 10.0.26100.1882 | Maps Background Transfer Service proxy
|
| | mapscsp.dll | 10.0.26100.7309 | MapsCSP
|
| | mapsstore.dll | 10.0.26100.7309 | Maps Store Dll
|
| | mapstoasttask.dll | 10.0.26100.7309 | MapsToastTask Task
|
| | mapsupdatetask.dll | 10.0.26100.7309 | MapsUpdateTask Task
|
| | mbaeapi.dll | 10.0.26100.7920 | Mobile Broadband Account Experience API
|
| | mbaeapipublic.dll | 10.0.26100.7920 | Mobile Broadband Account API
|
| | mbmediamanager.dll | 10.0.26100.7920 | Windows MB Media Manager DLL
|
| | mbsmsapi.dll | 10.0.26100.7920 | Microsoft Windows Mobile Broadband SMS API
|
| | mbussdapi.dll | 10.0.26100.7705 | Microsoft Windows Mobile Broadband USSD API
|
| | mccsengineshared.dll | 10.0.26100.7309 | Utilies shared among OneSync engines
|
| | mccspal.dll | 10.0.26100.1882 | Platform abstraction layer dll for MCCS
|
| | mciavi32.dll | 10.0.26100.1882 | Video For Windows MCI driver
|
| | mcicda.dll | 10.0.26100.1150 | MCI driver for cdaudio devices
|
| | mciqtz32.dll | 10.0.26100.1150 | DirectShow MCI Driver
|
| | mciseq.dll | 10.0.26100.1 | MCI driver for MIDI sequencer
|
| | mciwave.dll | 10.0.26100.5074 | MCI driver for waveform audio
|
| | mcmsvc.dll | 10.0.26100.7920 | Mobile Connectivity Management Service
|
| | mcpmanagementproxy.dll | 10.0.26100.7705 | Universal Print Management COM Proxy dll
|
| | mcpmanagementservice.dll | 10.0.26100.7920 | Universal Print Management Service
|
| | mcrecvsrc.dll | 10.0.26100.7920 | Miracast Media Foundation Source DLL
|
| | mcupdate_authenticamd.dll | |
|
| | mcupdate_genuineintel.dll | |
|
| | mdmcommon.dll | 10.0.26100.7309 | MdmCommon
|
| | mdmdiagnostics.dll | 10.0.26100.7920 | MdmDiagnostics
|
| | mdminst.dll | 10.0.26100.1150 | Modem Class Installer
|
| | mdmlocalmanagement.dll | 10.0.26100.7309 | MDM Local Management DLL
|
| | mdmmigrator.dll | 10.0.26100.7309 | Device Management Update Migrator DLL
|
| | mdmpostprocessevaluator.dll | 10.0.26100.7309 | MDM PostProcessing Configuration Dependency Evaluator
|
| | mdmregistration.dll | 10.0.26100.7920 | MDM Registration DLL
|
| | mediafoundation.defaultperceptionprovider.dll | 10.0.26100.7309 | MediaFoundation Default Perception Provider
|
| | mediafoundationaggregator.dll | |
|
| | memorydiagnostic.dll | 10.0.26100.7920 | Microsoft Windows Memory Diagnostic Task Handler
|
| | messagingdatamodel2.dll | 10.0.26100.7309 | MessagingDataModel2
|
| | messagingservice.dll | 10.0.26100.7705 | Messaging Service
|
| | mf.dll | 10.0.26100.8036 | Media Foundation DLL
|
| | mf3216.dll | 10.0.26100.8036 | 32-bit to 16-bit Metafile Conversion DLL
|
| | mfaacenc.dll | 10.0.26100.7309 | Media Foundation AAC Encoder
|
| | mfasfsrcsnk.dll | 10.0.26100.7920 | Media Foundation ASF Source and Sink DLL
|
| | mfaudiocnv.dll | 10.0.26100.7309 | Media Foundation Audio Converter DLL
|
| | mfc42.dll | 6.6.8063.0 | MFCDLL Shared Library - Retail Version
|
| | mfc42u.dll | 6.6.8063.0 | MFCDLL Shared Library - Retail Version
|
| | mfcaptureengine.dll | 10.0.26100.7920 | Media Foundation CaptureEngine DLL
|
| | mfcore.dll | 10.0.26100.8036 | Media Foundation Core DLL
|
| | mfcsubs.dll | 2001.12.10941.16384 | COM+
|
| | mfds.dll | 10.0.26100.7309 | Media Foundation Direct Show wrapper DLL
|
| | mfdshowreversebridge.dll | 10.0.26100.7920 | Media Foundation Reverse Dshow Bridge Source DLL
|
| | mfdvdec.dll | 10.0.26100.5074 | Media Foundation DV Decoder
|
| | mferror.dll | 10.0.26100.3912 | Media Foundation Error DLL
|
| | mfh263enc.dll | 10.0.26100.3912 | Media Foundation h263 Encoder
|
| | mfh264enc.dll | 10.0.26100.7920 | Media Foundation H264 Encoder
|
| | mfksproxy.dll | 10.0.26100.7920 | Dshow MF Bridge DLL DLL
|
| | mfmediaengine.dll | 10.0.26100.7920 | Media Foundation Media Engine DLL
|
| | mfmjpegdec.dll | 10.0.26100.7920 | Media Foundation MJPEG Decoder
|
| | mfmkvsrcsnk.dll | 10.0.26100.7920 | Media Foundation MKV Media Source and Sink DLL
|
| | mfmp4srcsnk.dll | 10.0.26100.8036 | Media Foundation MPEG4 Source and Sink DLL
|
| | mfmpeg2srcsnk.dll | 10.0.26100.7920 | Media Foundation MPEG2 Source and Sink DLL
|
| | mfnetcore.dll | 10.0.26100.7309 | Media Foundation Net Core DLL
|
| | mfnetsrc.dll | 10.0.26100.7309 | Media Foundation Net Source DLL
|
| | mfperfhelper.dll | 10.0.26100.1150 | MFPerf DLL
|
| | mfplat.dll | 10.0.26100.7920 | Media Foundation Platform DLL
|
| | mfplay.dll | 10.0.26100.7920 | Media Foundation Playback API DLL
|
| | mfps.dll | 10.0.26100.1882 | Media Foundation Proxy DLL
|
| | mfreadwrite.dll | 10.0.26100.7920 | Media Foundation ReadWrite DLL
|
| | mfsensorgroup.dll | 10.0.26100.7920 | Media Foundation Sensor Group DLL
|
| | mfsrcsnk.dll | 10.0.26100.7920 | Media Foundation Source and Sink DLL
|
| | mfsvr.dll | 10.0.26100.7920 | Media Foundation Simple Video Renderer DLL
|
| | mftranscode.dll | 10.0.26100.7920 | Media Foundation Transcode DLL
|
| | mfvdsp.dll | 10.0.26100.5074 | Windows Media Foundation Video DSP Components
|
| | mfvfw.dll | 10.0.26100.1150 | MF VFW MFT
|
| | mfwmaaec.dll | 10.0.26100.1882 | Windows Media Audio AEC for Media Foundation
|
| | mgmtapi.dll | 10.0.26100.1150 | Microsoft SNMP Manager API (uses WinSNMP)
|
| | mgmtrefreshcredprov.dll | 10.0.26100.7309 | Autopilot Reset Credential Provider
|
| | mi.dll | 10.0.26100.1 | Management Infrastructure
|
| | mibincodec.dll | 10.0.26100.1 | Management Infrastructure binary codec component
|
| | microsoft.bluetooth.audio.dll | 10.0.26100.7920 | Microsoft.Bluetooth.Audio DLL
|
| | microsoft.bluetooth.proxy.dll | 10.0.26100.7309 | Microsoft Bluetooth COM Proxy DLL
|
| | microsoft.bluetooth.service.dll | 10.0.26100.7920 | Microsoft.Bluetooth.Service DLL
|
| | microsoft.bluetooth.userservice.dll | 10.0.26100.7920 | Bluetooth User Support Service
|
| | microsoft.data.usageandqualityinsights.dll | 10.0.26100.7920 | Microsoft.Data.UsageAndQualityInsights
|
| | microsoft.graphics.display.displayenhancementservice.dll | 10.0.26100.7920 | Microsoft.Graphics.Display.DisplayEnhancementService DLL
|
| | microsoft.internal.frameworkudk.system.dll | 10.0.26100.7309 | Microsoft Framework UDK System DLL
|
| | microsoft.internal.warppal.dll | |
|
| | microsoft.localuserimageprovider.dll | 10.0.26100.7309 | Local User Image Provider
|
| | microsoft.management.infrastructure.native.unmanaged.dll | 10.0.26100.1 | Microsoft.Management.Infrastructure.Native.Unmanaged.dll
|
| | microsoft.media.playready.appraiser.dll | 10.0.10011.16384 | Microsoft Media PlayReady Appraiser Dll
|
| | microsoft.windows.storage.core.dll | 10.0.26100.1 |
|
| | microsoft.windows.storage.storagebuscache.dll | 10.0.26100.1 |
|
| | microsoftaccount.tokenprovider.core.dll | 10.0.26100.7920 | Microsoft Account Token Provider Core
|
| | microsoftaccountcloudap.dll | 10.0.26100.7309 | MicrosoftAccount Cloud AP Plugin
|
| | microsoftaccountextension.dll | 10.0.26100.7920 | Microsoft Account Extension DLL
|
| | microsoftaccounttokenprovider.dll | 10.0.26100.7920 | Microsoft® Account Token Provider
|
| | microsoftaccountwamextension.dll | 10.0.26100.7920 | Microsoft Account WAM Extension DLL
|
| | microsoft-windows-appmodelexecevents.dll | 10.0.26100.1 | AppModel Execution Provider
|
| | microsoft-windows-battery-events.dll | 10.0.26100.3624 | Microsoft-Windows-Battery-Events Resources
|
| | microsoft-windows-hal-events.dll | 10.0.26100.1 | Microsoft-Windows-HAL-Events Resources
|
| | microsoft-windows-internal-shell-nearshareexperience.dll | 10.0.26100.7824 | NearByShareExperience
|
| | microsoft-windows-kernel-cc-events.dll | 10.0.26100.1 | Microsoft-Windows-Kernel-Cache-Events Resources
|
| | microsoft-windows-kernel-pnp-events.dll | 10.0.26100.1591 | Microsoft-Windows-Kernel-Pnp-Events Resources
|
| | microsoft-windows-kernel-power-events.dll | 10.0.26100.7171 | Microsoft-Windows-Kernel-Power-Events Resources
|
| | microsoft-windows-kernel-processor-power-events.dll | 10.0.26100.7705 | Microsoft-Windows-Kernel-Processor-Power-Events Resources
|
| | microsoft-windows-mapcontrols.dll | 10.0.26100.1882 | Map Event Resources
|
| | microsoft-windows-moshost.dll | 10.0.26100.1882 | MosHost Event Resources
|
| | microsoft-windows-mptf-events.dll | 10.0.26100.7309 | Microsoft-Windows-MPTF-Events Resources
|
| | microsoft-windows-pdc.dll | 10.0.26100.1 | Microsoft-Windows-Pdc Resources
|
| | microsoft-windowsphone-semanagementprovider.dll | 10.0.26100.3323 | Microsoft-WindowsPhone-SEManagementProvider
|
| | microsoft-windows-power-cad-events.dll | 10.0.26100.1 | Microsoft-Windows-Power-CAD-Events Resources
|
| | microsoft-windows-processor-aggregator-events.dll | 10.0.26100.1 | Microsoft-Windows-Processor-Aggregator-Events Resources
|
| | microsoft-windows-sleepstudy-events.dll | 10.0.26100.4202 | Microsoft-Windows-SleepStudy-Events Resources
|
| | microsoft-windows-storage-tiering-events.dll | 10.0.26100.1 | Microsoft-Windows-Storage-Tiering-Events Resources
|
| | microsoft-windows-system-events.dll | 10.0.26100.7920 | Microsoft-Windows-System-Events Resources
|
| | midi2.bs2umptransform.dll | 1.0.15.0 | MIDI 2.0 translation service plugin
|
| | midi2.diagnosticstransport.dll | 1.0.15.0 | Windows MIDI Services Service Test Transport Plugin
|
| | midi2.ksaggregatetransport.dll | 1.0.15.0 | Windows MIDI Services KSA Transport Plugin
|
| | midi2.kstransport.dll | 1.0.15.0 | Windows MIDI Services KS Transport Plugin
|
| | midi2.loopbackmiditransport.dll | 1.0.15.0 | Windows MIDI Services Loopback Transport Plugin
|
| | midi2.midisrvtransport.dll | 1.0.15.0 | Windows MIDI Services app API service interface
|
| | midi2.schedulertransform.dll | 1.0.15.0 | Windows MIDI Services Message Scheduler Service Plugin
|
| | midi2.ump2bstransform.dll | 1.0.15.0 | MIDI 2.0 translation service plugin
|
| | midi2.umpprotocoldownscalertransform.dll | 1.0.15.0 | MIDI 2.0 to MIDI 1.0 downscaler service plugin
|
| | midi2.virtualmiditransport.dll | 1.0.15.0 | Windows MIDI Services Virtual Device MIDI Transport Plugin
|
| | midimap.dll | 10.0.26100.1882 | Microsoft MIDI Mapper
|
| | migisol.dll | 10.0.26100.1 | Migration System Isolation Layer
|
| | miguiresource.dll | 10.0.26100.7019 | MIG wini32 resources
|
| | mimefilt.dll | 2008.0.26100.7309 | MIME Filter
|
| | mimofcodec.dll | 10.0.26100.1150 | Management Infrastructure mof codec component
|
| | minstoreevents.dll | 10.0.26100.1 | Minstore Event Resource
|
| | miracastinputmgr.dll | 10.0.26100.1150 | Miracast Input Manager DLL
|
| | miracastreceiver.dll | 10.0.26100.7705 | Miracast Receiver API
|
| | miracastreceiverext.dll | 10.0.26100.7309 | Miracast Receiver Extensions
|
| | mirrordrvcompat.dll | 10.0.26100.1150 | Mirror Driver Compatibility Helper
|
| | mispace.dll | 10.0.26100.7920 | Storage Management Provider for Spaces
|
| | missioncontrolaggregator.dll | 10.0.26100.7309 | Microsoft (R) Sample Aggregator Native Aggregation Plugin
|
| | mitigationclient.dll | 10.0.26100.7920 | MitigationClient
|
| | mitigationconfiguration.dll | 10.0.26100.7309 | Exploit Guard Configuration Helper
|
| | miutils.dll | 10.0.26100.3323 | Management Infrastructure
|
| | mlang.dll | 10.0.26100.7019 | Multi Language Support DLL
|
| | mmcbase.dll | 10.0.26100.5074 | MMC Base DLL
|
| | mmcndmgr.dll | 10.0.26100.7920 | MMC Node Manager DLL
|
| | mmcshext.dll | 10.0.26100.5074 | MMC Shell Extension DLL
|
| | mmdevapi.dll | 10.0.26100.7920 | MMDevice API
|
| | mmgaclient.dll | 10.0.26100.7309 | MMGA
|
| | mmgaproxystub.dll | 10.0.26100.1150 | MMGA
|
| | mmres.dll | 10.0.26100.1 | General Audio Resources
|
| | mobilenetworking.dll | 10.0.26100.7705 | "MobileNetworking.DYNLINK"
|
| | modemui.dll | 10.0.26100.1882 | Windows Modem Properties
|
| | modernexecserver.dll | 10.0.26100.7309 | Modern Execution Server
|
| | modernprintconfighelper.dll | 10.0.26100.7920 | Microsoft Modern Print Config Helper
|
| | moricons.dll | 10.0.26100.1 | Windows NT Setup Icon Resources Library
|
| | moshost.dll | 10.0.26100.7309 | Downloaded Maps Manager
|
| | moshostclient.dll | 10.0.26100.7309 | MosHostClient
|
| | moshostcore.dll | 10.0.26100.7309 | Downloaded Maps Manager Core
|
| | mosstorage.dll | 10.0.26100.7309 | MosStorage
|
| | mp3dmod.dll | 10.0.26100.4202 | Microsoft MP3 Decoder DMO
|
| | mp43decd.dll | 10.0.26100.1150 | Windows Media MPEG-4 Video Decoder
|
| | mp4sdecd.dll | 10.0.26100.7019 | Windows Media MPEG-4 S Video Decoder
|
| | mpecm.dll | 10.0.26100.7309 | Microsoft Privacy Engine Connection Monitor Native Aggregation Plugin
|
| | mpehttpext.dll | 10.0.26100.7309 | Microsoft Privacy Engine HTTP Extension DLL
|
| | mpeval.dll | 10.0.26100.1882 | Monitoring Platform Evaluator
|
| | mpg4decd.dll | 10.0.26100.2894 | Windows Media MPEG-4 Video Decoder
|
| | mpr.dll | 10.0.26100.7019 | Multiple Provider Router DLL
|
| | mprapi.dll | 10.0.26100.7920 | Windows NT MP Router Administration DLL
|
| | mprddm.dll | 10.0.26100.7920 | Demand Dial Manager Supervisor
|
| | mprdim.dll | 10.0.26100.7920 | Dynamic Interface Manager
|
| | mprext.dll | 10.0.26100.1 | Multiple Provider Router Extension DLL
|
| | mprmsg.dll | 10.0.26100.3037 | Multi-Protocol Router Service Messages DLL
|
| | mpssvc.dll | 10.0.26100.7920 | Microsoft Protection Service
|
| | mpunits.dll | 10.0.26100.1882 | Monitoring Platform Built-In Composable Units
|
| | mrmcorer.dll | 10.0.26100.7920 | Microsoft Windows MRM
|
| | mrmdeploy.dll | 10.0.26100.7920 | Microsoft Windows MRM Deployment
|
| | mrmindexer.dll | 10.0.26100.7920 | Microsoft Windows MRM
|
| | mrt_map.dll | 2.2.29722.0 | Microsoft .NET Native Error Reporting Helper
|
| | mrt100.dll | 2.2.29722.0 | Microsoft .NET Native Runtime
|
| | ms3dthumbnailprovider.dll | 10.0.26100.7309 | 3D Builder
|
| | msaatext.dll | 2.0.10413.0 | Active Accessibility text support
|
| | msacm32.dll | 10.0.26100.7019 | Microsoft ACM Audio Filter
|
| | msadce.dll | 10.0.26100.5074 | OLE DB Cursor Engine
|
| | msadce.dll | 10.0.26100.5074 | OLE DB Cursor Engine
|
| | msadcer.dll | 10.0.26100.1 | OLE DB Cursor Engine Resources
|
| | msadcer.dll | 10.0.26100.1 | OLE DB Cursor Engine Resources
|
| | msadco.dll | 10.0.26100.5074 | Remote Data Services Data Control
|
| | msadco.dll | 10.0.26100.5074 | Remote Data Services Data Control
|
| | msadcor.dll | 10.0.26100.1 | Remote Data Services Data Control Resources
|
| | msadcor.dll | 10.0.26100.1 | Remote Data Services Data Control Resources
|
| | msadds.dll | 10.0.26100.5074 | OLE DB Data Shape Provider
|
| | msadds.dll | 10.0.26100.5074 | OLE DB Data Shape Provider
|
| | msaddsr.dll | 10.0.26100.1 | OLE DB Data Shape Provider Resources
|
| | msaddsr.dll | 10.0.26100.1 | OLE DB Data Shape Provider Resources
|
| | msader15.dll | 10.0.26100.1 | ActiveX Data Objects Resources
|
| | msader15.dll | 10.0.26100.1 | ActiveX Data Objects Resources
|
| | msado15.dll | 10.0.26100.5074 | ActiveX Data Objects
|
| | msado15.dll | 10.0.26100.5074 | ActiveX Data Objects
|
| | msadomd.dll | 10.0.26100.3912 | ActiveX Data Objects (Multi-Dimensional)
|
| | msadomd.dll | 10.0.26100.3912 | ActiveX Data Objects (Multi-Dimensional)
|
| | msador15.dll | 10.0.26100.1 | Microsoft ActiveX Data Objects Recordset
|
| | msador15.dll | 10.0.26100.1 | Microsoft ActiveX Data Objects Recordset
|
| | msadox.dll | 10.0.26100.3037 | ActiveX Data Objects Extensions
|
| | msadox.dll | 10.0.26100.5074 | ActiveX Data Objects Extensions
|
| | msadrh15.dll | 10.0.26100.3037 | ActiveX Data Objects Rowset Helper
|
| | msadrh15.dll | 10.0.26100.3037 | ActiveX Data Objects Rowset Helper
|
| | msafd.dll | 10.0.26100.1 | Microsoft Windows Sockets 2.0 Service Provider
|
| | msalacdecoder.dll | 10.0.26100.1150 | Media Foundation ALAC Decoder
|
| | msalacencoder.dll | 10.0.26100.1150 | Media Foundation ALAC Encoder
|
| | msamrnbdecoder.dll | 10.0.26100.1150 | AMR Narrowband Decoder DLL
|
| | msamrnbencoder.dll | 10.0.26100.1150 | AMR Narrowband Encoder DLL
|
| | msamrnbsink.dll | 10.0.26100.1150 | AMR Narrowband Sink DLL
|
| | msamrnbsource.dll | 10.0.26100.7309 | AMR Narrowband Source DLL
|
| | msaprofilenotificationhandler.dll | 10.0.26100.7309 | MSA Profile Notification Handler
|
| | msasn1.dll | 10.0.26100.7623 | ASN.1 Runtime APIs
|
| | msauddecmft.dll | 10.0.26100.7920 | Media Foundation Audio Decoders
|
| | msaudite.dll | 10.0.26100.6725 | Security Audit Events DLL
|
| | msauserext.dll | 10.0.26100.7309 | MSA USER Extension DLL
|
| | mscandui.dll | 10.0.26100.7309 | MSCANDUI Server DLL
|
| | mscat32.dll | 10.0.26100.1 | MSCAT32 Forwarder DLL
|
| | msclmd.dll | 10.0.26100.8037 | Microsoft Class Mini-driver
|
| | mscms.dll | 10.0.26100.7920 | Microsoft Color Matching System DLL
|
| | mscoree.dll | 10.0.26100.3624 | Microsoft .NET Runtime Execution Engine
|
| | mscorier.dll | 10.0.26100.1 | Microsoft .NET Runtime IE resources
|
| | mscories.dll | 2.0.50727.9157 | Microsoft .NET IE SECURITY REGISTRATION
|
| | msctf.dll | 10.0.26100.7920 | MSCTF Server DLL
|
| | msctfmonitor.dll | 10.0.26100.7309 | MsCtfMonitor DLL
|
| | msctfp.dll | 10.0.26100.3624 | MSCTFP Server DLL
|
| | msctfui.dll | 10.0.26100.7309 | MSCTFUI Server DLL
|
| | msctfuimanager.dll | 10.0.26100.7920 | Microsoft UIManager DLL
|
| | msdadc.dll | 10.0.26100.1 | OLE DB Data Conversion Stub
|
| | msdadiag.dll | 10.0.26100.1 | Built-In Diagnostics
|
| | msdaenum.dll | 10.0.26100.1 | OLE DB Root Enumerator Stub
|
| | msdaer.dll | 10.0.26100.1 | OLE DB Error Collection Stub
|
| | msdaora.dll | 10.0.26100.3912 | OLE DB Provider for Oracle
|
| | msdaorar.dll | 10.0.26100.1 | OLE DB Provider for Oracle Resources
|
| | msdaosp.dll | 10.0.26100.1 | OLE DB Simple Provider
|
| | msdaosp.dll | 10.0.26100.1150 | OLE DB Simple Provider
|
| | msdaprsr.dll | 10.0.26100.1 | OLE DB Persistence Services Resources
|
| | msdaprsr.dll | 10.0.26100.1 | OLE DB Persistence Services Resources
|
| | msdaprst.dll | 10.0.26100.1 | OLE DB Persistence Services
|
| | msdaprst.dll | 10.0.26100.1150 | OLE DB Persistence Services
|
| | msdaps.dll | 10.0.26100.1 | OLE DB Interface Proxies/Stubs
|
| | msdaps.dll | 10.0.26100.1150 | OLE DB Interface Proxies/Stubs
|
| | msdarem.dll | 10.0.26100.3037 | OLE DB Remote Provider
|
| | msdarem.dll | 10.0.26100.5074 | OLE DB Remote Provider
|
| | msdaremr.dll | 10.0.26100.1 | OLE DB Remote Provider Resources
|
| | msdaremr.dll | 10.0.26100.1 | OLE DB Remote Provider Resources
|
| | msdart.dll | 10.0.26100.3037 | OLE DB Runtime Routines
|
| | msdasc.dll | 10.0.26100.1 | OLE DB Service Components Stub
|
| | msdasql.dll | 10.0.26100.2894 | OLE DB Provider for ODBC Drivers
|
| | msdasql.dll | 10.0.26100.2894 | OLE DB Provider for ODBC Drivers
|
| | msdasqlr.dll | 10.0.26100.1 | OLE DB Provider for ODBC Drivers Resources
|
| | msdasqlr.dll | 10.0.26100.1 | OLE DB Provider for ODBC Drivers Resources
|
| | msdatl3.dll | 10.0.26100.1882 | OLE DB Implementation Support Routines
|
| | msdatl3.dll | 10.0.26100.1882 | OLE DB Implementation Support Routines
|
| | msdatt.dll | 10.0.26100.1 | OLE DB Temporary Table Services
|
| | msdaurl.dll | 10.0.26100.1 | OLE DB RootBinder Stub
|
| | msdelta.dll | 5.0.1.1 | Microsoft Patch Engine
|
| | msdfmap.dll | 10.0.26100.1 | Data Factory Handler
|
| | msdfmap.dll | 10.0.26100.1150 | Data Factory Handler
|
| | msdmo.dll | 10.0.26100.1150 | DMO Runtime
|
| | msdrm.dll | 10.0.26100.1150 | Windows Rights Management client
|
| | msdtckrm.dll | 2001.12.10941.16384 | Microsoft Distributed Transaction Coordinator OLE Transactions KTM Resource Manager DLL
|
| | msdtclog.dll | 2001.12.10941.16384 | Microsoft Distributed Transaction Coordinator Log Manager DLL
|
| | msdtcprx.dll | 2001.12.10941.16384 | Microsoft Distributed Transaction Coordinator OLE Transactions Interface Proxy DLL
|
| | msdtcspoffln.dll | 2001.12.10941.16384 | Microsoft Distributed Transaction Coordinator SysPrep Specialize Offline DLL
|
| | msdtctm.dll | 2001.12.10941.16384 | Microsoft Distributed Transaction Coordinator Transaction Manager DLL
|
| | msdtcuiu.dll | 2001.12.10941.16384 | Microsoft Distributed Transaction Coordinator Administrative DLL
|
| | msdtcvsp1res.dll | 2001.12.10941.16384 | Microsoft Distributed Transaction Coordinator Resources for Vista SP1
|
| | msfeeds.dll | 11.0.26100.7309 | Microsoft Feeds Manager
|
| | msfeedsbs.dll | 11.0.26100.7309 | Microsoft Feeds Background Sync
|
| | msflacdecoder.dll | 10.0.26100.7920 | Media Foundation FLAC Decoder
|
| | msflacencoder.dll | 10.0.26100.7309 | Media Foundation FLAC Encoder
|
| | msftedit.dll | 10.0.26100.7705 | Rich Text Edit Control, v8.5
|
| | msftoemdlligneous.dll | 10.0.26100.7309 | Microsoft OEM DLL for Igneous
|
| | mshtml.dll | 11.0.26100.7920 | Microsoft (R) HTML Viewer
|
| | mshtmldac.dll | 11.0.26100.1150 | DAC for Trident DOM
|
| | mshtmled.dll | 11.0.26100.2454 | Microsoft® HTML Editing Component
|
| | mshtmler.dll | 11.0.26100.4202 | Microsoft® HTML Editing Component's Resource DLL
|
| | msi.dll | 5.0.26100.7920 | Windows Installer
|
| | msicofire.dll | 10.0.26100.1150 | Corrupted MSI File Recovery Diagnostic Module
|
| | msidcrl40.dll | 10.0.26100.1150 | Microsoft® Account Dynamic Link Library
|
| | msident.dll | 10.0.26100.1882 | Microsoft Identity Manager
|
| | msidle.dll | 10.0.26100.1 | User Idle Monitor
|
| | msidntld.dll | 10.0.26100.1 | Microsoft Identity Manager
|
| | msieftp.dll | 10.0.26100.7309 | Microsoft Internet Explorer FTP Folder Shell Extension
|
| | msihnd.dll | 5.0.26100.7920 | Windows® installer
|
| | msiltcfg.dll | 5.0.26100.3624 | Windows Installer Configuration API Stub
|
| | msimg32.dll | 10.0.26100.8036 | GDIEXT Client DLL
|
| | msimsg.dll | 5.0.26100.7920 | Windows® Installer International Messages
|
| | msimtf.dll | 10.0.26100.1150 | Active IMM Server DLL
|
| | msisip.dll | 5.0.26100.7309 | MSI Signature SIP Provider
|
| | msiso.dll | 11.0.26100.8036 | Isolation Library for Internet Explorer
|
| | msiwer.dll | 5.0.26100.1 | MSI Windows Error Reporting
|
| | msixdatasourceextensionps.dll | 10.0.26100.1150 | APPX Random Access Stream Provider COM Proxy/Stub DLL
|
| | msjro.dll | 10.0.26100.3912 | Jet and Replication Objects
|
| | mskeyprotcli.dll | 10.0.26100.7309 | Windows Client Key Protection Provider
|
| | mskeyprotect.dll | 10.0.26100.7623 | Microsoft Key Protection Provider
|
| | msls31.dll | 3.10.349.0 | Microsoft Line Services library file
|
| | msmpeg2adec.dll | 10.0.26100.7705 | Microsoft DTV-DVD Audio Decoder
|
| | msmpeg2enc.dll | 10.0.26100.7705 | Microsoft MPEG-2 Encoder
|
| | msmpeg2vdec.dll | 10.0.26100.8036 | Microsoft DTV-DVD Video Decoder
|
| | msobjs.dll | 10.0.26100.6725 | System object audit names
|
| | msoert2.dll | 10.0.26100.6725 | Microsoft Windows Mail RT Lib
|
| | msopusdecoder.dll | 10.0.26100.1150 | Media Foundation Opus Decoder
|
| | mspatcha.dll | 5.0.1.1 | Microsoft File Patch Application API
|
| | mspatchc.dll | 5.0.1.1 | Microsoft Patch Creation Engine
|
| | msphotography.dll | 10.0.26100.7920 | MS Photography DLL
|
| | msports.dll | 10.0.26100.7309 | Ports Class Installer
|
| | msprivs.dll | 10.0.26100.1 | Microsoft Privilege Translations
|
| | msrahc.dll | 10.0.26100.7623 | Remote Assistance Diagnostics Provider
|
| | msrating.dll | 10.0.26100.2454 | "msrating.DYNLINK"
|
| | msrdc.dll | 10.0.26100.5074 | Remote Differential Compression COM server
|
| | msrdpwebaccess.dll | 10.0.26100.1150 | Microsoft Remote Desktop Services Web Access Control
|
| | msrle32.dll | 10.0.26100.1882 | Microsoft RLE Compressor
|
| | msscntrs.dll | 7.0.26100.7920 | PKM Perfmon Counter DLL
|
| | mssign32.dll | 10.0.26100.7309 | Microsoft Trust Signing APIs
|
| | mssip32.dll | 10.0.26100.1 | MSSIP32 Forwarder DLL
|
| | mssitlb.dll | 7.0.26100.7920 | mssitlb
|
| | msspellcheckingfacility.dll | 10.0.26100.7920 | Microsoft Spell Checking Facility
|
| | mssph.dll | 7.0.26100.7920 | Microsoft Search Protocol Handler
|
| | mssprxy.dll | 7.0.26100.7920 | Microsoft Search Proxy
|
| | mssrch.dll | 7.0.26100.7920 | Microsoft Embedded Search
|
| | mssvp.dll | 7.0.26100.7920 | MSSearch Vista Platform
|
| | mstask.dll | 10.0.26100.1150 | Task Scheduler interface DLL
|
| | mstextprediction.dll | 10.0.26100.5074 | Microsoft TextPrediction DLL
|
| | mstscax.dll | 10.0.26100.7920 | Remote Desktop Services ActiveX Client
|
| | msutb.dll | 10.0.26100.7920 | MSUTB Server DLL
|
| | msv1_0.dll | 10.0.26100.7920 | Microsoft Authentication Package v1.0
|
| | msvcirt.dll | 7.0.26100.3323 | Windows NT IOStreams DLL
|
| | msvcp_win.dll | 10.0.26100.7623 | Microsoft® C Runtime Library
|
| | msvcp110_win.dll | 10.0.26100.7019 | Microsoft® STL110 C++ Runtime Library
|
| | msvcp120_clr0400.dll | 12.0.52519.0 | Microsoft® C Runtime Library
|
| | msvcp140_clr0400.dll | 14.29.30154.0 | Microsoft® C Runtime Library
|
| | msvcp60.dll | 7.0.26100.1 | Windows NT C++ Runtime Library DLL
|
| | msvcr100_clr0400.dll | 14.8.9221.0 | Microsoft® .NET Framework
|
| | msvcr120_clr0400.dll | 12.0.52519.0 | Microsoft® C Runtime Library
|
| | msvcrt.dll | 7.0.26100.7623 | Windows NT CRT DLL
|
| | msvfw32.dll | 10.0.26100.1150 | Microsoft Video for Windows DLL
|
| | msvidc32.dll | 10.0.26100.1882 | Microsoft Video 1 Compressor
|
| | msvidctl.dll | 6.5.26100.5074 | ActiveX control for streaming video
|
| | msvideodsp.dll | 10.0.26100.5074 | Video Stabilization MFT
|
| | msvp9dec.dll | 10.0.26100.4202 | Windows VP9 Video Decoder
|
| | msvproc.dll | 10.0.26100.7920 | Media Foundation Video Processor
|
| | msvpxenc.dll | 10.0.26100.4202 | Windows VPX Video Encoder
|
| | mswb7.dll | 10.0.26100.7309 | MSWB7 DLL
|
| | mswmdm.dll | 12.0.26100.5074 | Windows Media Device Manager Core
|
| | mswsock.dll | 10.0.26100.7920 | Microsoft Windows Sockets 2.0 Service Provider
|
| | msxactps.dll | 10.0.26100.1 | OLE DB Transaction Proxies/Stubs
|
| | msxactps.dll | 10.0.26100.1 | OLE DB Transaction Proxies/Stubs
|
| | msxml3.dll | 8.110.26100.7309 | MSXML 3.0
|
| | msxml3r.dll | 8.110.26100.1882 | XML Resources
|
| | msxml6.dll | 6.30.26100.7309 | MSXML 6.0
|
| | msxml6r.dll | 6.30.26100.1882 | XML Resources
|
| | msyuv.dll | 10.0.26100.1150 | Microsoft UYVY Video Decompressor
|
| | mtcmodel.dll | 10.0.26100.7309 | MtcModel
|
| | mtf.dll | 10.0.26100.7309 | "MTF.DYNLINK"
|
| | mtfappserviceds.dll | 10.0.26100.7309 | Microsoft AppService Datasource Dll
|
| | mtfdecoder.dll | 10.0.26100.7309 | "MtfDecoder.DYNLINK"
|
| | mtffuzzyds.dll | 10.0.26100.7309 | Microsoft Fuzzy Datasource Dll
|
| | mtfserver.dll | 10.0.26100.7309 | "MTFServer.DYNLINK"
|
| | mtfspellcheckds.dll | 10.0.26100.7309 | "MTFSpellcheckDS.DYNLINK"
|
| | mtxclu.dll | 2001.12.10941.16384 | Microsoft Distributed Transaction Coordinator Failover Clustering Support DLL
|
| | mtxdm.dll | 2001.12.10941.16384 | COM+
|
| | mtxex.dll | 2001.12.10941.16384 | COM+
|
| | mtxoci.dll | 2001.12.10941.16384 | Microsoft Distributed Transaction Coordinator Database Support DLL for Oracle
|
| | muifontsetup.dll | 10.0.26100.2161 | MUI Callback for font registry settings
|
| | muilanguagecleanup.dll | 10.0.26100.4484 | MUI Callback for Language pack cleanup
|
| | musappupdatehandlers.dll | 10.0.26100.7920 | Modern App Update Settings Handler Implementation
|
| | museuxdocked.dll | 10.0.26100.7920 | Muse Ux Docked DLL
|
| | musupdatehandlers.dll | |
|
| | musupdatehandlers1.dll | 10.0.26100.7920 | Modern Update Settings Handler Implementation
|
| | mycomput.dll | 10.0.26100.7019 | Computer Management
|
| | mydocs.dll | 10.0.26100.7309 | My Documents Folder UI
|
| | napcrypt.dll | 10.0.26100.8036 | NAP Cryptographic API helper
|
| | napinsp.dll | 10.0.26100.1150 | E-mail Naming Shim Provider
|
| | naturalauth.dll | 10.0.26100.7309 | Natural Authentication Service
|
| | naturalauthclient.dll | 10.0.26100.1882 | Natural Authentication Client Library
|
| | naturallanguage6.dll | 10.0.26100.7309 | Natural Language Development Platform 6
|
| | navshutdown.dll | 10.0.26100.7309 | NAVShutdown
|
| | ncaapi.dll | 10.0.26100.1 | Microsoft Network Connectivity Assistant API
|
| | ncasvc.dll | 10.0.26100.5074 | Microsoft Network Connectivity Assistant Service
|
| | ncbservice.dll | 10.0.26100.7309 | Network Connection Broker
|
| | ncdautosetup.dll | 10.0.26100.7309 | Network Connected Devices Auto-Setup service DLL
|
| | ncdprop.dll | 10.0.26100.1150 | Advanced network device properties
|
| | nci.dll | 10.0.26100.7309 | CoInstaller: NET
|
| | ncobjapi.dll | 10.0.26100.7920 | Microsoft® Windows® Operating System
|
| | ncrypt.dll | 10.0.26100.7705 | Windows NCrypt Router
|
| | ncryptprov.dll | 10.0.26100.7920 | Microsoft KSP
|
| | ncryptsslp.dll | 10.0.26100.5074 | Microsoft SChannel Provider
|
| | ncsi.dll | 10.0.26100.7920 | Network Connectivity Status Indicator
|
| | ncuprov.dll | 10.0.26100.7920 | Network Connectivity Statistics Provider for System Resource Usage Monitor Service
|
| | nddeapi.dll | 10.0.26100.1 | Network DDE Share Management APIs
|
| | ndfapi.dll | 10.0.26100.7920 | Network Diagnostic Framework Client API
|
| | ndfetw.dll | 10.0.26100.5074 | Network Diagnostic Engine Event Interface
|
| | ndfhcdiscovery.dll | 10.0.26100.5074 | Network Diagnostic Framework HC Discovery API
|
| | ndproxystub.dll | 10.0.26100.1150 | Network Diagnostic Engine Proxy/Stub
|
| | nduprov.dll | 10.0.26100.7920 | Network Statistics Provider for System Resource Usage Monitor Service
|
| | negoexts.dll | 10.0.26100.7309 | NegoExtender Security Package
|
| | netapi32.dll | 10.0.26100.7019 | Net Win32 API DLL
|
| | netbios.dll | 10.0.26100.1 | NetBIOS Interface Library
|
| | netcenter.dll | 10.0.26100.7309 | Network Center control panel
|
| | netcfgx.dll | 10.0.26100.7309 | Network Configuration Objects
|
| | netdiagfx.dll | 10.0.26100.7309 | Network Diagnostic Framework
|
| | netdriverinstall.dll | 10.0.26100.7920 | Network Driver Installation
|
| | netevent.dll | 10.0.26100.4202 | Net Event Handler
|
| | netfxperf.dll | 10.0.26100.3624 | Extensible Performance Counter Shim
|
| | neth.dll | 10.0.26100.4202 | Net Help Messages DLL
|
| | netid.dll | 10.0.26100.7309 | System Control Panel Applet; Network ID Page
|
| | netiohlp.dll | 10.0.26100.7920 | Netio Helper DLL
|
| | netjoin.dll | 10.0.26100.3037 | Domain Join DLL
|
| | netlogon.dll | 10.0.26100.7920 | Net Logon Services DLL
|
| | netman.dll | 10.0.26100.7920 | Network Connections Manager
|
| | netmsg.dll | 10.0.26100.4202 | Net Messages DLL
|
| | netplwiz.dll | 10.0.26100.7824 | Map Network Drives/Network Places Wizard
|
| | netprofm.dll | 10.0.26100.7920 | Network List Manager
|
| | netprofmsvc.dll | 10.0.26100.7920 | Network Profile Service DLL
|
| | netprovfw.dll | 10.0.26100.1150 | Provisioning Service Framework DLL
|
| | netprovisionsp.dll | 10.0.26100.1 | Provisioning Service Provider DLL
|
| | netsetupapi.dll | 10.0.26100.7920 | Network Configuration API
|
| | netsetupengine.dll | 10.0.26100.7920 | Network Configuration Engine
|
| | netsetupshim.dll | 10.0.26100.7705 | Network Configuration API
|
| | netsetupsvc.dll | 10.0.26100.7705 | Network Setup Service
|
| | netshell.dll | 10.0.26100.7920 | Network Connections Shell
|
| | nettrace.dll | 10.0.26100.7920 | Network Trace Helper
|
| | nettracehelper.dll | 10.0.26100.7920 | Network Trace Helper
|
| | netutils.dll | 10.0.26100.1882 | Net Win32 API Helpers DLL
|
| | networkbindingenginemigplugin.dll | 10.0.26100.7824 | Network Binding Engine Migration Plugin
|
| | networkcollectionagent.dll | 11.0.26100.3624 | Network Collection Agent
|
| | networkdesktopsettings.dll | 10.0.26100.7920 | System settings network desktop handlers group
|
| | networkexplorer.dll | 10.0.26100.7309 | Network Explorer
|
| | networkhelper.dll | 10.0.26100.7309 | Network utilities for mail, contacts, calendar
|
| | networkicon.dll | 10.0.26100.7920 | In-Proc WinRT server for Windows.Internal.UX.NetworkUX.NetworkIcon
|
| | networkitemfactory.dll | 10.0.26100.1 | NetworkItem Factory
|
| | networkmobilesettings.dll | 10.0.26100.7920 | System settings network mobile handlers group
|
| | networkproxycsp.dll | 10.0.26100.1150 | NetworkProxyCSP
|
| | networkqospolicycsp.dll | 10.0.26100.7309 | NetworkQoSPolicyCSP
|
| | networkuxbroker.dll | 10.0.26100.7920 | NetworkUXBroker DLL
|
| | newdev.dll | 6.0.5054.0 | Add Hardware Device Library
|
| | nfcprovisioningplugin.dll | 10.0.26100.7309 | NFC Provisioning Plugin
|
| | nfcradiomedia.dll | 10.0.26100.3323 | NFC Radio Media Provider
|
| | ngccredprov.dll | 10.0.26100.7920 | Microsoft Passport Credential Provider
|
| | ngcctnr.dll | 10.0.26100.7920 | Microsoft Passport Container
|
| | ngcctnrgidshandler.dll | 10.0.26100.7309 | Microsoft Passport Container GIDS Handler
|
| | ngcctnrsvc.dll | 10.0.26100.7920 | Microsoft Passport Container Service
|
| | ngcisoctnr.dll | 10.0.26100.7920 | Windows Hello Secure Container
|
| | ngckeyenum.dll | 10.0.26100.7920 | Microsoft Passport Key Enumeration Manager
|
| | ngcksp.dll | 10.0.26100.7920 | Microsoft Passport Key Storage Provider
|
| | ngclocal.dll | 10.0.26100.7920 | NGC Local Account APIs
|
| | ngcpopkeysrv.dll | 10.0.26100.7920 | Microsoft Passport Proof-of-possession Key Service
|
| | ngcprocsp.dll | 10.0.26100.7920 | Microsoft Passport CSP
|
| | ngcrecovery.dll | 10.0.26100.7920 | Windows Hello Recovery Helper
|
| | ngcsvc.dll | 10.0.26100.7920 | Microsoft Passport Service
|
| | ngctasks.dll | 10.0.26100.7920 | Microsoft Passport Tasks
|
| | ngcutils.dll | 10.0.26100.7920 | Microsoft Passport Utils Outside OneCore
|
| | ninput.dll | 10.0.26100.7920 | Microsoft Pen and Touch Input Component
|
| | nlaapi.dll | 10.0.26100.7920 | Network Location Awareness 2
|
| | nlansp_c.dll | 10.0.26100.7309 | NLA Namespace Service Provider DLL
|
| | nlhtml.dll | 2008.0.26100.7309 | HTML filter
|
| | nlmgp.dll | 10.0.26100.7920 | Network List Manager Snapin
|
| | nlmproxy.dll | 10.0.26100.7920 | Network List Manager Public Proxy
|
| | nlmsprep.dll | 10.0.26100.7920 | Network List Manager Sysprep Module
|
| | nlsbres.dll | 10.0.26100.4484 | NLSBuild resource DLL
|
| | nlsdata0000.dll | 10.0.26100.1150 | Microsoft Neutral Natural Language Server Data and Code
|
| | nlsdata0009.dll | 10.0.26100.3912 | Microsoft English Natural Language Server Data and Code
|
| | nlsdl.dll | 10.0.26100.1882 | Deprecated Nls Downlevel DLL
|
| | nlslexicons0009.dll | 10.0.26100.1 | Microsoft English Natural Language Server Data and Code
|
| | nmadirect.dll | 10.0.26100.7309 | Nma Direct
|
| | noise.dll | 10.0.26100.7309 | Windows Noise Protocol Implementation
|
| | normaliz.dll | 10.0.26100.1 | Unicode Normalization DLL
|
| | notificationcontroller.dll | 10.0.26100.7920 | NotificationController
|
| | notificationcontrollerps.dll | 10.0.26100.7920 | NotificationController Proxy Stub
|
| | notificationintelligenceplatform.dll | 10.0.26100.7309 | NotificationIntelligencePlatform
|
| | notificationplatformcomponent.dll | 10.0.26100.7309 | NotificationPlatformComponent
|
| | npmproxy.dll | 10.0.26100.7309 | Network List Manager Proxy
|
| | npsm.dll | 10.0.26100.7309 | NPSM
|
| | npsmdesktopprovider.dll | 10.0.26100.7309 | <d> NPSM Desktop Local Provider DLL
|
| | nrpsrv.dll | 10.0.26100.1 | Name Resolution Proxy (NRP) RPC interface
|
| | nrtapi.dll | 10.0.26100.7920 | Name Resolution Tracker API
|
| | nshdnsclient.dll | 10.0.26100.7920 | DNS client netsh DLL
|
| | nshhttp.dll | 10.0.26100.7920 | HTTP netsh DLL
|
| | nshipsec.dll | 10.0.26100.1150 | Net Shell IP Security helper DLL
|
| | nshwfp.dll | 10.0.26100.7920 | Windows Filtering Platform Netsh Helper
|
| | nsi.dll | 10.0.26100.7920 | NSI User-mode interface DLL
|
| | nsisvc.dll | 10.0.26100.7920 | Network Store Interface RPC server
|
| | ntasn1.dll | 10.0.26100.1882 | Microsoft ASN.1 API
|
| | ntdll.dll | 10.0.26100.7920 | NT Layer DLL
|
| | ntdsapi.dll | 10.0.26100.1 | Active Directory Domain Services API
|
| | ntfsres.dll | 10.0.26100.7920 | NT File System Driver Resources
|
| | ntlanman.dll | 10.0.26100.7920 | Microsoft® Lan Manager
|
| | ntlanui2.dll | 10.0.26100.1 | Network object shell UI
|
| | ntlmshared.dll | 10.0.26100.7705 | NTLM Shared Functionality
|
| | ntmarta.dll | 10.0.26100.7019 | Windows NT MARTA provider
|
| | ntprint.dll | 10.0.26100.7705 | Spooler Setup DLL
|
| | ntshrui.dll | 10.0.26100.7920 | Shell extensions for sharing
|
| | ntvdm64.dll | 10.0.26100.4202 | 16-bit Emulation on NT64
|
| | objsel.dll | 10.0.26100.7705 | Object Picker Dialog
|
| | occache.dll | 11.0.26100.5074 | Object Control Viewer
|
| | ocsetapi.dll | 10.0.26100.7920 | Windows Optional Component Setup API
|
| | odbc32.dll | 10.0.26100.7309 | ODBC Driver Manager
|
| | odbcbcp.dll | 10.0.26100.1150 | BCP for ODBC
|
| | odbcconf.dll | 10.0.26100.7824 | ODBC Driver Configuration Program
|
| | odbccp32.dll | 10.0.26100.5074 | ODBC Installer
|
| | odbccr32.dll | 10.0.26100.1 | ODBC Cursor Library
|
| | odbccu32.dll | 10.0.26100.1 | ODBC Cursor Library
|
| | odbcint.dll | 10.0.26100.3037 | ODBC Resources
|
| | odbctrac.dll | 10.0.26100.1 | ODBC Driver Manager Trace
|
| | oemdefaultassociations.dll | 10.0.26100.1301 | OEMDefaultAssociations
|
| | oemlicense.dll | 10.0.26100.4202 | Client Licensing Platform Client Provisioning
|
| | offfilt.dll | 2008.0.26100.7309 | OFFICE Filter
|
| | officecsp.dll | 10.0.26100.5074 | Office CSP
|
| | offlinelsa.dll | 10.0.26100.8036 | Windows
|
| | offlinesam.dll | 10.0.26100.7920 | Windows
|
| | offreg.dll | 10.0.26100.7623 | Offline registry DLL
|
| | ole32.dll | 10.0.26100.7920 | Microsoft OLE for Windows
|
| | oleacc.dll | 7.2.26100.7920 | Active Accessibility Core Component
|
| | oleacchooks.dll | 7.2.26100.7920 | Active Accessibility Event Hooks Library
|
| | oleaccrc.dll | 7.2.26100.4202 | Active Accessibility Resource DLL
|
| | oleaut32.dll | 10.0.26100.7920 | OLEAUT32.DLL
|
| | oledb32.dll | 10.0.26100.5074 | OLE DB Core Services
|
| | oledb32.dll | 10.0.26100.5074 | OLE DB Core Services
|
| | oledb32r.dll | 10.0.26100.1 | OLE DB Core Services Resources
|
| | oledb32r.dll | 10.0.26100.1 | OLE DB Core Services Resources
|
| | oledlg.dll | 10.0.26100.7309 | OLE User Interface Support
|
| | oleprn.dll | 10.0.26100.7309 | Oleprn DLL
|
| | omadmagent.dll | 10.0.26100.7309 | omadmagent
|
| | omadmapi.dll | 10.0.26100.7920 | omadmapi
|
| | ondemandbrokerclient.dll | 10.0.26100.5074 | OnDemandBrokerClient
|
| | ondemandconnroutehelper.dll | 10.0.26100.7920 | On Demand Connctiond Route Helper
|
| | onebackuphandler.dll | 10.0.26100.7920 | Backup & Restore Handlers Implementation
|
| | onecorecommonproxystub.dll | 10.0.26100.7920 | OneCore Common Proxy Stub
|
| | onecoreuapcommonproxystub.dll | 10.0.26100.7920 | OneCoreUAP Common Proxy Stub
|
| | onesettingsclient.dll | 10.0.26100.7309 | Microsoft OneSettings Client
|
| | onex.dll | 10.0.26100.7920 | IEEE 802.1X supplicant library
|
| | onexui.dll | 10.0.26100.7309 | IEEE 802.1X supplicant UI library
|
| | onnxruntime.dll | 1.17.2504.1701 | ONNX Runtime
|
| | oobewv2host.dll | 10.0.26100.7920 | OOBE WebView2 Host
|
| | opcservices.dll | 10.0.26100.7309 | Native Code OPC Services Library
|
| | opencl.dll | 3.0.6.0 | OpenCL Client DLL
|
| | opengl32.dll | 10.0.26100.7920 | OpenGL Client DLL
|
| | osbaseln.dll | 10.0.26100.1 | Service Reporting API
|
| | osksupport.dll | 10.0.26100.1 | Microsoft On-Screen Keyboard Support Utilities
|
| | osuninst.dll | 10.0.26100.1 | Uninstall Interface
|
| | p9np.dll | 10.0.26100.7309 | Plan 9 Network Provider
|
| | p9rdrservice.dll | 10.0.26100.7824 | Plan9 Redirector Service DLL
|
| | packager.dll | 10.0.26100.7309 | Object Packager2
|
| | packagestatechangehandler.dll | 10.0.26100.7920 | Package State Change Handler
|
| | panmap.dll | 10.0.26100.1150 | PANOSE(tm) Font Mapper
|
| | passwordenrollmentmanager.dll | 10.0.26100.7824 | In-Proc WinRT server for PasswordEnrollmentManager
|
| | pautoenr.dll | 10.0.26100.1150 | Auto Enrollment DLL
|
| | payloadrestrictions.dll | 10.0.26100.1150 | Payload Restrictions Mitigation Provider
|
| | paymentmediatorserviceproxy.dll | 10.0.26100.1150 | Payment Mediator Service Proxy
|
| | pcacli.dll | 10.0.26100.7920 | Program Compatibility Assistant Client Module
|
| | pcadm.dll | 10.0.26100.7920 | Program Compatibility Assistant Diagnostic Module
|
| | pcaevts.dll | 10.0.26100.7920 | Program Compatibility Assistant Event Resources
|
| | pcasvc.dll | 10.0.26100.7920 | Program Compatibility Assistant Service
|
| | pcaui.dll | 10.0.26100.7920 | Program Compatibility Assistant User Interface Module
|
| | pcpksp.dll | 10.0.26100.7920 | Microsoft Platform Key Storage Provider for Platform Crypto Provider
|
| | pcrpf.dll | 10.0.26100.7920 | PCRPF
|
| | pcshellcommonproxystub.dll | 10.0.26100.5074 | PCShell Common Proxy Stub
|
| | pcsvdevice.dll | 10.0.26100.1882 | PCSV Proxy Provider for devices
|
| | pcwum.dll | 10.0.26100.1 | Performance Counters for Windows Native DLL
|
| | pcwutl.dll | 10.0.26100.7920 | Program Compatibility Troubleshooter Helper
|
| | pdh.dll | 10.0.26100.7309 | Windows Performance Data Helper DLL
|
| | pdhui.dll | 10.0.26100.7309 | PDH UI
|
| | penservice.dll | 10.0.26100.7920 | Pen Service
|
| | peopleapis.dll | 10.0.26100.7019 | DLL for PeopleRT
|
| | peopleband.dll | 10.0.26100.7824 | People Desktop Band
|
| | perceptionsimulation.proxystubs.dll | 10.0.26100.1 | Windows Perception Simulation Proxy Stubs
|
| | perceptionsimulationmanager.dll | 10.0.26100.7309 | Windows Perception Simulation Manager
|
| | perfdisk.dll | 10.0.26100.7705 | Windows Disk Performance Objects DLL
|
| | perfnet.dll | 10.0.26100.7705 | Windows Network Service Performance Objects DLL
|
| | performancetracehandler.dll | 10.0.26100.7920 | PerformanceTraceHandler task
|
| | perfos.dll | 10.0.26100.7705 | Windows System Performance Objects DLL
|
| | perfproc.dll | 10.0.26100.7705 | Windows System Process Performance Objects DLL
|
| | perfts.dll | 10.0.26100.1882 | Windows Remote Desktop Services Performance Objects
|
| | personalizationcsp.dll | 10.0.26100.7309 | PersonalizationCSP
|
| | pfclient.dll | 10.0.26100.4202 | SysMain Client
|
| | phonecallhistoryapis.dll | 10.0.26100.7309 | DLL for PhoneCallHistoryRT
|
| | phoneom.dll | 10.0.26100.7920 | Phone Object Model
|
| | phoneplatformabstraction.dll | 10.0.26100.7309 | Phone Platform Abstraction
|
| | phoneproviders.dll | 10.0.26100.7920 | Phone-specific Component Provider for Windows Telephony Stack.
|
| | phoneservice.dll | 10.0.26100.7920 | The service used to manage phone calls and other telephony related functionality
|
| | phoneserviceres.dll | 10.0.26100.1 | Resource DLL for the Phone Service
|
| | phoneutil.dll | 10.0.26100.7309 | Phone utilities
|
| | phoneutilres.dll | 10.0.26100.1 | Resource DLL for Phone utilities
|
| | photometadatahandler.dll | 10.0.26100.7309 | Photo Metadata Handler
|
| | photowiz.dll | 10.0.26100.5074 | Photo Printing Wizard
|
| | pickerplatform.dll | 10.0.26100.7309 | PickerPlatform
|
| | pid.dll | 10.0.26100.1591 | Microsoft PID
|
| | pidgenx.dll | 10.0.26100.7309 | Pid Generation
|
| | pifmgr.dll | 10.0.26100.1 | Windows NT PIF Manager Icon Resources Library
|
| | pimindexmaintenance.dll | 10.0.26100.7920 | Service responsible for contacts indexing and other user data related tasks
|
| | pimindexmaintenanceclient.dll | 10.0.26100.7920 | Client dll for Pim Index Maintenance
|
| | pimstore.dll | 10.0.26100.7309 | POOM
|
| | pinenrollmenthelper.dll | 10.0.26100.7920 | PinEnrollmentHelper
|
| | pkeyhelper.dll | 10.0.26100.7920 | Product Key Helper
|
| | pktmonapi.dll | 10.0.26100.7309 | Pktmon API library
|
| | pku2u.dll | 10.0.26100.7309 | Pku2u Security Package
|
| | pla.dll | 10.0.26100.7309 | Performance Logs & Alerts
|
| | playlistfolder.dll | 10.0.26100.7920 | Playlist Folder
|
| | playsndsrv.dll | 10.0.26100.7309 | PlaySound Service
|
| | playtodevice.dll | 10.0.26100.7705 | PLAYTODEVICE DLL
|
| | playtomanager.dll | 10.0.26100.7309 | Microsoft Windows PlayTo Manager
|
| | playtomenu.dll | 12.0.26100.7309 | Cast to Device Menu DLL
|
| | playtoreceiver.dll | 10.0.26100.7309 | DLNA DMR DLL
|
| | playtostatusprovider.dll | 10.0.26100.5074 | PlayTo Status Provider Dll
|
| | ploptin.dll | 10.0.26100.5074 | Prelaunch OptIn
|
| | plutonapi.dll | |
|
| | plutonfw_authenticamd.dll | |
|
| | plutonfw_genuineintel.dll | |
|
| | plutonfw_hspv2_authenticamd.dll | |
|
| | plutontasks.dll | 10.0.26100.7705 | Pluton Tasks
|
| | pngfilt.dll | 11.0.26100.5074 | IE PNG plugin image decoder
|
| | pnpclean.dll | 10.0.26100.1150 | Plug and Play Maintenance Task Library
|
| | pnpdiag.dll | 10.0.26100.7920 | PnP Diagnostic API
|
| | pnppolicy.dll | 10.0.26100.7920 | pnppolicy Task
|
| | pnpts.dll | 10.0.26100.1 | PlugPlay Troubleshooter
|
| | pnpui.dll | 5.2.3668.0 | Plug and Play User Interface DLL
|
| | pnpxassoc.dll | 10.0.26100.7309 | PNPX Association Dll
|
| | pnpxassocprx.dll | 10.0.26100.1 | PNPX Association Dll
|
| | policymanager.dll | 10.0.26100.7920 | Policy Manager DLL
|
| | policymanagerprecheck.dll | 10.0.26100.7920 | policymanagerprecheck
|
| | polstore.dll | 10.0.26100.1 | Policy Storage dll
|
| | popkeycli.dll | 10.0.26100.7309 | Pop Key Client DLL
|
| | portabledeviceapi.dll | 10.0.26100.7920 | Windows Portable Device API Components
|
| | portabledeviceclassextension.dll | 10.0.26100.5074 | Windows Portable Device Class Extension Component
|
| | portabledeviceconnectapi.dll | 10.0.26100.5074 | Portable Device Connection API Components
|
| | portabledevicestatus.dll | 10.0.26100.5074 | Microsoft Windows Portable Device Status Provider
|
| | portabledevicesyncprovider.dll | 10.0.26100.7705 | Microsoft Windows Portable Device Provider.
|
| | portabledevicetypes.dll | 10.0.26100.5074 | Windows Portable Device (Parameter) Types Component
|
| | portabledevicewiacompat.dll | 10.0.26100.7705 | PortableDevice WIA Compatibility Driver
|
| | posetup.dll | 10.0.26100.1150 | Power Setup
|
| | posyncservices.dll | 10.0.26100.1882 | Change Tracking
|
| | pots.dll | 10.0.26100.1 | Power Troubleshooter
|
| | powercpl.dll | 10.0.26100.7309 | Power Options Control Panel
|
| | powergridforecasttask.dll | 10.0.26100.7309 | PowerGridForecastTask Task
|
| | powrprof.dll | 10.0.26100.3912 | Power Profile Helper DLL
|
| | prauthproviders.dll | 10.0.26100.7309 | prauthproviders
|
| | presentationhostproxy.dll | 10.0.26100.5074 | Windows Presentation Foundation Host Proxy
|
| | prflbmsg.dll | 10.0.26100.4202 | Perflib Event Messages
|
| | print.printsupport.source.dll | 10.0.26100.7920 | Microsoft Windows Print Support
|
| | print.workflow.source.dll | 10.0.26100.7309 | Microsoft Windows Print Workflow Source App Library
|
| | printdeviceconfigurationservice.dll | 10.0.26100.7920 | PrintDeviceConfigurationService dll
|
| | printerassociationcommon.dll | 10.0.26100.7920 | PrinterAssociationCommon dll
|
| | printerassociationcommonproxy.dll | 10.0.26100.7920 | PrinterAssociationCommon COM Proxy dll
|
| | printercleanuptask.dll | 10.0.26100.7623 | Windows Printer Cleanup Task
|
| | printerservicesadapter.dll | |
|
| | printfilterpipelineprxy.dll | 10.0.26100.7920 | Print Filter Pipeline Proxy
|
| | printisolationproxy.dll | 10.0.26100.7920 | Print Sandbox COM Proxy Stub
|
| | printnotification.dll | |
|
| | printplatformconfig.dll | 10.0.26100.7309 | Legacy Print Platform Adapter
|
| | printrenderapihost.dll | 10.0.26100.7920 | PDF Writer
|
| | printscanbrokerservice.dll | 10.0.26100.7920 | Microsoft Windows PrintScan Broker Service Internal
|
| | printticketvalidation.dll | 10.0.26100.7309 | PrintTicketValidation dll
|
| | printui.dll | 10.0.26100.7920 | Printer Settings User Interface
|
| | printworkflowservice.dll | 10.0.26100.7920 | Microsoft Windows Print Workflow Service Internal
|
| | printwsdahost.dll | 10.0.26100.7309 | PrintWSDAHost
|
| | prm0009.dll | 10.0.26100.1 | Microsoft English Natural Language Data and Code
|
| | prncache.dll | 10.0.26100.5074 | Print UI Cache
|
| | prnfldr.dll | 10.0.26100.7019 | prnfldr dll
|
| | prnntfy.dll | 10.0.26100.7920 | prnntfy DLL
|
| | prntvpt.dll | 10.0.26100.7920 | Print Ticket Services Module
|
| | productenumerator.dll | 10.0.26100.7019 | Product Enumerator
|
| | profapi.dll | 10.0.26100.7309 | User Profile Basic API
|
| | profext.dll | 10.0.26100.7920 | profext
|
| | profprov.dll | 10.0.26100.7309 | User Profile WMI Provider
|
| | profsvc.dll | 10.0.26100.7920 | ProfSvc
|
| | profsvcext.dll | 10.0.26100.7920 | ProfSvcExt
|
| | propsys.dll | 7.0.26100.7920 | Microsoft Property System
|
| | provcore.dll | 10.0.26100.7920 | Microsoft Wireless Provisioning Core
|
| | provdatastore.dll | 10.0.26100.7309 | Provisioning Engine Datastore Library
|
| | provdiagnostics.dll | 10.0.26100.4202 | ETW for Provisioning Diagnostics
|
| | provengine.dll | 10.0.26100.7309 | Provisioning Engine Library
|
| | provhandlers.dll | 10.0.26100.7309 | Provisioning Engine Handlers Library
|
| | provisioningcommandscsp.dll | 10.0.26100.7309 | Provisioning package command configuration service provider
|
| | provisioningcsp.dll | 10.0.26100.7309 | Provisioning package configuration service provider
|
| | provisioninghandlers.dll | 10.0.26100.7920 | Provisioning Handlers Implementation
|
| | provmigrate.dll | 10.0.26100.7309 | Provisioning Migration Handler
|
| | provops.dll | 10.0.26100.7920 | Provision Operations Library
|
| | provpackageapidll.dll | 10.0.26100.7309 | Provisioning package API DLL for STL encapsulation
|
| | provplatformdesktop.dll | 10.0.26100.7920 | Provisioning platform for desktop editions
|
| | provplugineng.dll | 10.0.26100.7309 | Provisioning plugin engine dll
|
| | provsysprep.dll | 10.0.26100.7309 | Sysprep provider for Provisioning
|
| | provthrd.dll | 10.0.26100.1882 | WMI Provider Thread & Log Library
|
| | proximitycommon.dll | 10.0.26100.1150 | Proximity Common Implementation
|
| | proximitycommonpal.dll | 10.0.26100.1150 | Proximity Common PAL
|
| | proximityrtapipal.dll | 10.0.26100.7309 | Proximity WinRT API PAL
|
| | proximityservice.dll | 10.0.26100.7920 | Proximity Service Implementation
|
| | proximityservicepal.dll | 10.0.26100.7920 | Proximity Service PAL
|
| | prvdmofcomp.dll | 10.0.26100.3323 | WMI
|
| | prxyqry.dll | 10.0.26100.7920 | ProxyQuery
|
| | psapi.dll | 10.0.26100.1 | Process Status Helper
|
| | pshed.dll | 10.0.26100.1150 | Platform Specific Hardware Error Driver
|
| | psisdecd.dll | 10.0.26100.3912 | Microsoft SI/PSI parser for MPEG2 based networks.
|
| | psmodulediscoveryprovider.dll | 10.0.26100.1150 | WMI
|
| | psmserviceexthost.dll | 10.0.26100.7920 | Resource Manager PSM Service Extension
|
| | psmsrv.dll | 10.0.26100.7920 | Process State Manager (PSM) Service
|
| | pstask.dll | 10.0.26100.1 | pstask Task
|
| | pstorec.dll | 10.0.26100.1 | Deprecated Protected Storage COM interfaces
|
| | ptpprov.dll | 10.0.26100.7309 | PTP Time Provider
|
| | puiapi.dll | 10.0.26100.7309 | puiapi DLL
|
| | puiobj.dll | 10.0.26100.5074 | PrintUI Objects DLL
|
| | pushtoinstall.dll | 10.0.26100.7920 | PushToInstall
|
| | pwlauncher.dll | 10.0.26100.5074 | Windows To Go Launcher
|
| | pwrshplugin.dll | 10.0.26100.1591 | pwrshplugin.dll
|
| | pwrshsip.dll | 10.0.26100.1 | Crypto SIP provider for signing and verifying PowerShell script files (.ps1/.ps1xml)
|
| | pwsso.dll | 10.0.26100.1882 | Windows To Go Shell Service Object
|
| | qasf.dll | 12.0.26100.1 | DirectShow ASF Support
|
| | qcap.dll | 10.0.26100.5074 | DirectShow Runtime.
|
| | qdv.dll | 10.0.26100.5074 | DirectShow Runtime.
|
| | qdvd.dll | 10.0.26100.7309 | DirectShow DVD PlayBack Runtime.
|
| | qedit.dll | 10.0.26100.7309 | DirectShow Editing.
|
| | qedwipes.dll | 10.0.26100.1 | DirectShow Editing SMPTE Wipes
|
| | qmgr.dll | 7.8.26100.7309 | Background Intelligent Transfer Service
|
| | quartz.dll | 10.0.26100.7309 | DirectShow Runtime.
|
| | query.dll | 10.0.26100.7920 | Content Index Utility DLL
|
| | quickactionsdatamodel.dll | 10.0.26100.7824 | QuickActionsDataModel
|
| | quiethours.dll | 10.0.26100.7920 | QuietHours
|
| | qwave.dll | 10.0.26100.7920 | Windows NT
|
| | racengn.dll | 10.0.26100.1150 | Reliability analysis metrics calculation engine
|
| | racpldlg.dll | 10.0.26100.7623 | Remote Assistance Contact List
|
| | radardt.dll | 10.0.26100.1150 | Microsoft Windows Resource Exhaustion Detector
|
| | radarrs.dll | 10.0.26100.1882 | Microsoft Windows Resource Exhaustion Resolver
|
| | radcui.dll | 10.0.26100.7309 | RemoteApp and Desktop Connection UI Component
|
| | randomaccessstreamdatasource.dll | 10.0.26100.7920 | RandomAccessStream Data Source Library
|
| | rasadhlp.dll | 10.0.26100.7920 | Remote Access AutoDial Helper
|
| | rasapi32.dll | 10.0.26100.7920 | Remote Access API
|
| | rasauto.dll | 10.0.26100.7920 | Remote Access AutoDial Manager
|
| | raschap.dll | 10.0.26100.7920 | Remote Access PPP CHAP
|
| | raschapext.dll | 10.0.26100.7920 | Windows Extension library for raschap
|
| | rasctrs.dll | 10.0.26100.8036 | Windows NT Remote Access Perfmon Counter dll
|
| | rascustom.dll | 10.0.26100.7920 | Custom Protocol Engine
|
| | rasdiag.dll | 10.0.26100.8036 | RAS Diagnostics Helper Classes
|
| | rasdlg.dll | 10.0.26100.7920 | Remote Access Common Dialog API
|
| | rasgcw.dll | 10.0.26100.7920 | RAS Wizard Pages
|
| | rasman.dll | 10.0.26100.7920 | Remote Access Connection Manager
|
| | rasmans.dll | 10.0.26100.7920 | Remote Access Connection Manager
|
| | rasmbmgr.dll | 10.0.26100.1 | Provides support for the switching of mobility enabled VPN connections if their underlying interface goes down.
|
| | rasmediamanager.dll | 10.0.26100.7920 | Windows Ras Media Manager DLL
|
| | rasmontr.dll | 10.0.26100.7705 | RAS Monitor DLL
|
| | rasplap.dll | 10.0.26100.7920 | RAS PLAP Credential Provider
|
| | rasppp.dll | 10.0.26100.7920 | Remote Access PPP
|
| | rastapi.dll | 10.0.26100.7920 | Remote Access TAPI Compliance Layer
|
| | rastls.dll | 10.0.26100.7920 | Remote Access PPP EAP-TLS
|
| | rastlsext.dll | 10.0.26100.7920 | Windows Extension library for rastls
|
| | rdbui.dll | 10.0.26100.7309 | ReadyBoost UI
|
| | rdpavenc.dll | 10.0.26100.7920 | Rdp Advanced Video Encoders
|
| | rdpbase.dll | 10.0.26100.7920 | Rdp OneCore Base Services
|
| | rdpcfgex.dll | 10.0.26100.1 | Remote Desktop Session Host Server Connection Configuration Extension for the RDP protocol
|
| | rdpcorets.dll | 10.0.26100.7920 | TS RDPCore DLL
|
| | rdpcredentialprovider.dll | 10.0.26100.7309 | "RdpCredentialProvider.DYNLINK"
|
| | rdpendp.dll | 10.0.26100.7309 | RDP Audio Endpoint
|
| | rdplite.dll | 10.0.26100.7920 | Rdp Light Stack
|
| | rdpnanotransport.dll | 3.2503.11002.0 |
|
| | rdprelaytransport.dll | 10.0.26100.1150 | RdpRelayTransport DLL
|
| | rdpsaps.dll | 10.0.26100.7705 | RDP Session Agent Proxy Stub
|
| | rdpserverbase.dll | 10.0.26100.7920 | Rdp Server OneCore Base Services
|
| | rdpsharercom.dll | 10.0.26100.7920 | RDPSRAPI Sharer COM Objects
|
| | rdpviewerax.dll | 10.0.26100.7019 | RDPSRAPI Viewer COM Objects and ActiveX
|
| | rdsappxhelper.dll | 10.0.26100.7309 | Remote Desktop AppX Scheduler Helper DLL
|
| | rdsdwmdr.dll | 10.0.26100.7920 | Microsoft Remote Desktop Services Desktop Composition Component
|
| | rdvvmtransport.dll | 10.0.26100.7920 | RdvVmTransport EndPoints
|
| | rdxservice.dll | 10.0.26100.8036 | RDXService
|
| | rdxtaskfactory.dll | 10.0.26100.8036 | RDXTaskFactory
|
| | reagent.dll | 10.0.26100.7920 | Microsoft Windows Recovery Agent DLL
|
| | reagenttask.dll | 10.0.26100.3037 | Microsoft Windows Recovery Agent Task Handler
|
| | recovery.dll | 10.0.26100.7309 | Recovery Control Panel
|
| | refsdedupsvc.proxy.dll | 10.0.26100.2605 | "RefsDedupSvc.Proxy.dll"
|
| | regapi.dll | 10.0.26100.1150 | Registry Configuration APIs
|
| | regctrl.dll | 10.0.26100.5074 | RegCtrl
|
| | regidle.dll | 10.0.26100.4202 | RegIdle Backup Task
|
| | regsvc.dll | 10.0.26100.7019 | Remote Registry Service
|
| | reguwpapi.dll | 10.0.26100.4484 | UWP Registry API
|
| | reinfo.dll | 10.0.26100.7920 | Microsoft Windows Recovery Info DLL
|
| | remoteaudioendpoint.dll | 10.0.26100.8036 | Remote Audio Endpoint
|
| | remotepg.dll | 10.0.26100.1882 | Remote Sessions CPL Extension
|
| | remoteremediationcsp.dll | 10.0.26100.7309 | RemoteRemediationCSP
|
| | remotewipecsp.dll | 10.0.26100.7309 | RemoteWipeCSP
|
| | removablemediaprovisioningplugin.dll | 10.0.26100.7309 | Removable Media Provisioning Plugin
|
| | removedevicecontexthandler.dll | 10.0.26100.7309 | Devices & Printers Remove Device Context Menu Handler
|
| | removedeviceelevated.dll | 10.0.26100.1 | RemoveDeviceElevated Proxy Dll
|
| | reportingcsp.dll | 10.0.26100.7309 | ReportingCSP
|
| | resampledmo.dll | 10.0.26100.7019 | Windows Media Resampler
|
| | resbparser.dll | 10.0.26100.3037 | Provide information to identify string resources
|
| | resetengine.dll | 10.0.26100.7920 | Push-Button Reset Engine
|
| | resetengonline.dll | 10.0.26100.7920 | Reset Engine Online
|
| | resourcemapper.dll | 10.0.26100.7309 | Provide information to identify string resources
|
| | resourcepolicyclient.dll | 10.0.26100.7309 | Resource Policy Client
|
| | resourcepolicyserver.dll | 10.0.26100.7920 | Resource Policy RM Service Extension
|
| | resutils.dll | 10.0.26100.7920 | Microsoft Cluster Resource Utility DLL
|
| | rgb9rast.dll | 10.0.26100.1882 | Microsoft® Windows® Operating System
|
| | riched20.dll | 5.31.23.1231 | Rich Text Edit Control, v3.1
|
| | riched32.dll | 10.0.26100.1 | Wrapper Dll for Richedit 1.0
|
| | rjvmdmconfig.dll | 10.0.26100.7920 | Windows System Reset Platform Plugin for MDM Agent
|
| | rmapi.dll | 10.0.26100.7920 | Radio Manager API
|
| | rmclient.dll | 10.0.26100.7309 | Resource Manager Client
|
| | rmsroamingsecurity.dll | 10.0.26100.7309 | Roaming Security RMS implementation
|
| | rnr20.dll | 10.0.26100.1 | Windows Socket2 NameSpace DLL
|
| | roamingsecurity.dll | 10.0.26100.5074 | Roaming Security implementation
|
| | rometadata.dll | 4.8.9221.0 | Microsoft MetaData Library
|
| | rotmgr.dll | 10.0.26100.5074 | Auto-Rotation Manager
|
| | rpcepmap.dll | 10.0.26100.7019 | RPC Endpoint Mapper
|
| | rpchttp.dll | 10.0.26100.1 | RPC HTTP DLL
|
| | rpcns4.dll | 10.0.26100.1 | Remote Procedure Call Name Service Client
|
| | rpcnsh.dll | 10.0.26100.7705 | RPC Netshell Helper
|
| | rpcrt4.dll | 10.0.26100.8036 | Remote Procedure Call Runtime
|
| | rpcrtremote.dll | 10.0.26100.7705 | Remote RPC Extension
|
| | rpcss.dll | 10.0.26100.7920 | Distributed COM Services
|
| | rsaenh.dll | 10.0.26100.7705 | Microsoft Enhanced Cryptographic Provider
|
| | rshx32.dll | 10.0.26100.7705 | Security Shell Extension
|
| | rstrtmgr.dll | 10.0.26100.7309 | Restart Manager
|
| | rtffilt.dll | 2008.0.26100.7309 | RTF Filter
|
| | rtm.dll | 10.0.26100.7920 | Routing Table Manager
|
| | rtmediaframe.dll | 10.0.26100.7920 | Windows Runtime MediaFrame DLL
|
| | rtutils.dll | 10.0.26100.3037 | Routing Utilities
|
| | rtworkq.dll | 10.0.26100.7309 | Realtime WorkQueue DLL
|
| | rulebasedds.dll | 10.0.26100.7309 | "RuleBasedDS.DYNLINK"
|
| | samcli.dll | 10.0.26100.7920 | Security Accounts Manager Client DLL
|
| | samlib.dll | 10.0.26100.7920 | SAM Library DLL
|
| | samsrv.dll | 10.0.26100.7920 | SAM Server DLL
|
| | sas.dll | 10.0.26100.3323 | WinLogon Software SAS Library
|
| | sbe.dll | 10.0.26100.5074 | DirectShow Stream Buffer Filter.
|
| | sbeio.dll | 12.0.26100.7920 | Stream Buffer IO DLL
|
| | sberes.dll | 10.0.26100.1 | DirectShow Stream Buffer Filter Resouces.
|
| | sbservicetrigger.dll | 10.0.26100.3037 | Socket Broker Service Trigger
|
| | scansetting.dll | 10.0.26100.1150 | Microsoft® Windows(TM) ScanSettings Profile and Scanning implementation
|
| | scardbi.dll | 10.0.26100.7309 | SmartCard Background Infrastructure Library
|
| | scarddlg.dll | 10.0.26100.8037 | SCardDlg - Smart Card Common Dialog
|
| | scardsvr.dll | 10.0.26100.7705 | Smart Card Resource Management Server
|
| | scavengeui.dll | 10.0.26100.6725 | Update Package Cleanup
|
| | scdeviceenum.dll | 10.0.26100.8037 | Smart Card Device Enumeration Service
|
| | scecli.dll | 10.0.26100.7309 | Windows Security Configuration Editor Client Engine
|
| | scesrv.dll | 10.0.26100.7920 | Windows Security Configuration Editor Engine
|
| | schannel.dll | 10.0.26100.7920 | TLS / SSL Security Provider
|
| | schedcli.dll | 10.0.26100.1150 | Scheduler Service Client DLL
|
| | schedsvc.dll | 10.0.26100.7309 | Task Scheduler Service
|
| | scksp.dll | 10.0.26100.8037 | Microsoft Smart Card Key Storage Provider
|
| | scripto.dll | 6.6.26100.1150 | Microsoft ScriptO
|
| | scrobj.dll | 10.0.26100.7920 | Windows ® Script Component Runtime
|
| | scrrun.dll | 10.0.26100.7920 | Microsoft ® Script Runtime
|
| | sdcpl.dll | 10.0.26100.7309 | Backup and Restore (Windows 7) Control Panel
|
| | sdds.dll | 10.0.26100.7309 | "SDDS.DYNLINK"
|
| | sdengin2.dll | 10.0.26100.7309 | Microsoft® Windows Backup Engine
|
| | sdfhost.dll | 10.0.26100.7623 | SDFHOST.DLL
|
| | sdhcinst.dll | 10.0.26100.1 | Secure Digital Host Controller Class Installer
|
| | sdiageng.dll | 10.0.26100.7309 | Scripted Diagnostics Execution Engine
|
| | sdiagprv.dll | 10.0.26100.1150 | Windows Scripted Diagnostic Provider API
|
| | sdiagschd.dll | 10.0.26100.7309 | Scripted Diagnostics Scheduled Task
|
| | sdohlp.dll | 10.0.26100.5074 | NPS SDO Helper Component
|
| | sdrsvc.dll | 10.0.26100.7309 | Microsoft® Windows Backup Service
|
| | sdshext.dll | 10.0.26100.5074 | Microsoft® Windows Backup Shell Extension
|
| | search.protocolhandler.mapi2.dll | 7.0.26100.7920 | Microsoft Search Protocol Handler for MAPI2
|
| | searchfolder.dll | 10.0.26100.7920 | SearchFolder
|
| | searchindexercore.dll | 10.0.26100.7920 | Search Indexer Core
|
| | sebbackgroundmanagerpolicy.dll | 10.0.26100.7309 | <d> SEB Background Manager Policy DLL
|
| | sechost.dll | 10.0.26100.7920 | Host for SCM/SDDL/LSA Lookup APIs
|
| | seclogon.dll | 10.0.26100.7920 | Secondary Logon Service DLL
|
| | secproc.dll | 10.0.26100.5074 | Windows Rights Management Desktop Security Processor
|
| | secproc_isv.dll | 10.0.26100.5074 | Windows Rights Management Desktop Security Processor
|
| | secproc_ssp.dll | 10.0.26100.4202 | Windows Rights Management Services Server Security Processor
|
| | secproc_ssp_isv.dll | 10.0.26100.4202 | Windows Rights Management Services Server Security Processor (Pre-production)
|
| | secur32.dll | 10.0.26100.7705 | Security Support Provider Interface
|
| | securetimeaggregator.dll | 10.0.26100.7309 | Secure Time Aggregator
|
| | security.dll | 10.0.26100.1 | Security Support Provider Interface
|
| | securitycenterbroker.dll | 10.0.26100.7309 | Security Center Broker
|
| | securitycenterbrokerps.dll | 10.0.26100.2454 | SecurityCenterBrokerPS
|
| | securityhealthagent.dll | 10.0.26100.7309 | Windows Security Health Agent
|
| | securityhealthcore.dll | 10.0.26100.7824 | Windows Security Health Core
|
| | securityhealthproxystub.dll | 10.0.26100.1882 | Windows Defender Security Health Proxy Stub
|
| | securityhealthsso.dll | 10.0.26100.7309 | Security Health SSO
|
| | securityhealthssoudk.dll | 10.0.26100.7920 | Windows Security Health SSO UDK
|
| | securityhealthudk.dll | 10.0.26100.7920 | Windows Security Health UDK
|
| | semgrps.dll | 10.0.26100.3323 | SEMgrSvc Proxy
|
| | semgrsvc.dll | 10.0.26100.7920 | NFC SEManagement Service DLL
|
| | sendmail.dll | 10.0.26100.7920 | Send Mail
|
| | sens.dll | 10.0.26100.5074 | System Event Notification Service (SENS)
|
| | sensapi.dll | 10.0.26100.1 | SENS Connectivity API DLL
|
| | sensorperformanceevents.dll | 10.0.26100.1 | Sensors Performance Events
|
| | sensorsapi.dll | 10.0.26100.7920 | Sensor API
|
| | sensorsclassextension.dll | 10.0.26100.7309 | Sensor Driver Class Extension component
|
| | sensorscpl.dll | 10.0.26100.1 | Open Location and Other Sensors
|
| | sensorservice.dll | 10.0.26100.7920 | Sensor Service
|
| | sensorsnativeapi.dll | 10.0.26100.7309 | Sensors Native API
|
| | sensorsnativeapi.v2.dll | 10.0.26100.7920 | Sensors Native API (V2 stack)
|
| | sensorsutilsv2.dll | 10.0.26100.7920 | Sensors v2 Utilities DLL
|
| | sensrsvc.dll | 10.0.26100.7309 | Microsoft Windows Sensor Monitoring Service
|
| | serialui.dll | 10.0.26100.1150 | Serial Port Property Pages
|
| | servicingcommon.dll | 10.0.26100.7920 | Servicing Base DLL
|
| | servicinguapi.dll | 10.0.26100.7920 | Servicing Unified API
|
| | serwvdrv.dll | 10.0.26100.1882 | Unimodem Serial Wave driver
|
| | sessenv.dll | 10.0.26100.7920 | Remote Desktop Configuration service
|
| | setbcdlocale.dll | 10.0.26100.1 | MUI Callback for Bcd
|
| | setnetworklocation.dll | 10.0.26100.7309 | Set Network Location Utility
|
| | settingsconfigtask.dll | 10.0.26100.7920 | SettingsConfigTask Task
|
| | settingsenvironment.desktop.dll | 10.0.26100.8036 | System Settings Environment for Desktop
|
| | settingsextensibilityhandlers.dll | 10.0.26100.7920 | System Settings SettingsExtensibility Handler Implementation
|
| | settingshandlers_a9.dll | 10.0.26100.7920 | Settings Handler DLL for A9
|
| | settingshandlers_accessibility.dll | 10.0.26100.7920 | System Settings Accessibility Handlers Implementation
|
| | settingshandlers_advertisingid.dll | 10.0.26100.7920 | System Settings Advertising Id Handler
|
| | settingshandlers_appcontrol.dll | 10.0.26100.7920 | System Settings App Control Handlers Implementation
|
| | settingshandlers_appexecutionalias.dll | 10.0.26100.7920 | System Settings AppExecutionAlias Handlers Implementation
|
| | settingshandlers_authentication.dll | 10.0.26100.7920 | System Settings Authentication Handlers Implementation
|
| | settingshandlers_backgroundapps.dll | 10.0.26100.7920 | System Settings Background Apps Handlers Implementation
|
| | settingshandlers_backup.dll | 10.0.26100.7920 | Settings Handler DLL for Backup
|
| | settingshandlers_batteryusage.dll | 10.0.26100.7920 | Battery Usage Settings Handlers Implementation
|
| | settingshandlers_camera.dll | 10.0.26100.7920 | System Settings Camera Handlers Implementation
|
| | settingshandlers_capabilityaccess.dll | 10.0.26100.7920 | System Settings Capability Access Handlers Implementation
|
| | settingshandlers_clipboard.dll | 10.0.26100.7920 | Clipboard Settings Handlers
|
| | settingshandlers_closedcaptioning.dll | 10.0.26100.7920 | System Settings Closed Captioning Handlers Implementation
|
| | settingshandlers_cloudpc.dll | 10.0.26100.7920 | Settings Handler DLL for Desktop CloudPC
|
| | settingshandlers_contentdeliverymanager.dll | 10.0.26100.7920 | System Settings Handlers Implementation for Content Delivery Manager
|
| | settingshandlers_copilot.dll | 10.0.26100.7920 | System Settings Copilot Handlers Implementation
|
| | settingshandlers_cortana.dll | 10.0.26100.7920 | System Settings Search Handlers Implementation
|
| | settingshandlers_desktopdisplay.dll | 10.0.26100.7920 | Settings Handler DLL for Desktop Display
|
| | settingshandlers_desktoptaskbar.dll | 10.0.26100.7920 | Settings Handler DLL for Desktop Taskbar
|
| | settingshandlers_devices.dll | 10.0.26100.7920 | Devices settings page handler
|
| | settingshandlers_display.dll | 10.0.26100.7920 | System Settings Handlers Implementation for Display Page
|
| | settingshandlers_flights.dll | 10.0.26100.7920 | System Settings Flight Handlers Implementation
|
| | settingshandlers_fonts.dll | 10.0.26100.7920 | System Settings Fonts Handlers Implementation
|
| | settingshandlers_forcesync.dll | 10.0.26100.7920 | System Settings Sync Time Handler Implementation
|
| | settingshandlers_gaming.dll | 10.0.26100.7920 | System Settings Handlers Implementation for Desktop Gaming Page
|
| | settingshandlers_geolocation.dll | 10.0.26100.7920 | System Settings Geolocation Handlers Implementation
|
| | settingshandlers_gpu.dll | 10.0.26100.7920 | System Settings Gpu Handlers Implementation
|
| | settingshandlers_humanpresence.dll | 10.0.26100.7920 | Settings Handler DLL for Human Presence
|
| | settingshandlers_ime.dll | 10.0.26100.7920 | System Settings IME Handlers Implementation
|
| | settingshandlers_inkingtypingprivacy.dll | 10.0.26100.7920 | System Settings Inking and Typing Privacy Handlers Implementation
|
| | settingshandlers_inputpersonalization.dll | 10.0.26100.7920 | System Settings Input Personalization
|
| | settingshandlers_installedupdates.dll | 10.0.26100.7920 | System Settings Installed Updates Handlers Implementation
|
| | settingshandlers_keyboard.dll | 10.0.26100.7920 | System Settings Keyboard Handlers Implementation
|
| | settingshandlers_language.dll | 10.0.26100.7920 | System Settings Language Handlers Implementation
|
| | settingshandlers_lighting.dll | 10.0.26100.7920 | System Settings Lighting Handlers Implementation
|
| | settingshandlers_managephone.dll | 10.0.26100.7920 | Phone settings page handler
|
| | settingshandlers_maps.dll | 10.0.26100.7920 | System Settings Maps Handlers Implementation
|
| | settingshandlers_mouse.dll | 10.0.26100.7920 | System Settings Mouse Handlers Implementation
|
| | settingshandlers_notifications.dll | 10.0.26100.7920 | System Settings Notifications Handlers Implementation
|
| | settingshandlers_nt.dll | 10.0.26100.8036 | System Settings Handlers Implementation
|
| | settingshandlers_onecore_batterysaver.dll | 10.0.26100.7920 | System Settings Battery Saver One Core Handlers Implementation
|
| | settingshandlers_onecore_powerandsleep.dll | 10.0.26100.7920 | System Settings Power and Sleep One Core Handlers Implementation
|
| | settingshandlers_onedrivebackup.dll | 10.0.26100.7920 | System Settings One Drive Backup Handlers Implementation
|
| | settingshandlers_optionalfeatures.dll | 10.0.26100.7920 | System Settings Optional Features Handlers Implementation
|
| | settingshandlers_pcdisplay.dll | 10.0.26100.7920 | System Settings Handlers Implementation for Desktop Display Page
|
| | settingshandlers_pcdisplayremote.dll | 10.0.26100.7920 | System Settings Handlers Implementation for Remote Desktop Display Page
|
| | settingshandlers_pen.dll | 10.0.26100.7920 | System Settings Pen Handlers Implementation
|
| | settingshandlers_recovery.dll | 10.0.26100.7920 | System Settings Recovery Handlers Implemmentation
|
| | settingshandlers_region.dll | 10.0.26100.7920 | System Settings Region Handlers Implementation
|
| | settingshandlers_resume.dll | 10.0.26100.7920 | Settings Handler DLL for Desktop Resume
|
| | settingshandlers_sharedexperiences_rome.dll | 10.0.26100.7920 | System Settings Shared Experiences Handlers Implementation
|
| | settingshandlers_siuf.dll | 10.0.26100.7920 | System Settings System Initiated User Feedback Handlers Implementation
|
| | settingshandlers_smartactions.dll | 10.0.26100.7920 | Settings Handler DLL for SmartActions
|
| | settingshandlers_speechprivacy.dll | 10.0.26100.7920 | System Settings Speech Privacy Handlers Implementation
|
| | settingshandlers_startup.dll | 10.0.26100.7920 | System Settings Startup Handlers Implementation
|
| | settingshandlers_storage.dll | 10.0.26100.7920 | System Settings Storage Handler Implementation
|
| | settingshandlers_storagesense.dll | 10.0.26100.7920 | System Settings Storage Handler Implementation
|
| | settingshandlers_touch.dll | 10.0.26100.7920 | System Settings Touch Handlers Implementation
|
| | settingshandlers_troubleshoot.dll | 10.0.26100.7920 | Troubleshoot Handlers Implementation
|
| | settingshandlers_user.dll | 10.0.26100.7920 | System Settings Handlers Implementation for Desktop Users Page
|
| | settingshandlers_useraccount.dll | 10.0.26100.7920 | System Settings User Account Handlers Implementation
|
| | settingshandlers_userexperience.dll | 10.0.26100.7920 | System Settings UserExperience Info Handlers Implementation
|
| | settingshandlers_userintent.dll | 10.0.26100.7920 | System Settings Handlers Implementation for Desktop User Intent
|
| | settingshandlers_workaccess.dll | 10.0.26100.7920 | System Settings Work Access Handlers Implementation
|
| | settingsyncdownloadhelper.dll | 10.0.26100.7309 | SettingSyncDownloadHelper
|
| | setupapi.dll | 10.0.26100.7920 | Windows Setup API
|
| | setupcl.dll | 10.0.26100.4484 | System Clone Library
|
| | setupcln.dll | 10.0.26100.4768 | Setup Files Cleanup
|
| | setupetw.dll | 10.0.26100.4202 | Setup ETW Event Resources
|
| | sfape.dll | 10.0.26100.7623 | SFAP
|
| | sfapm.dll | 10.0.26100.7623 | SFAP
|
| | sfc.dll | 10.0.26100.1 | Windows File Protection
|
| | sfc_os.dll | 10.0.26100.1 | Windows File Protection
|
| | sfsenclave.dll | |
|
| | shacct.dll | 10.0.26100.4484 | Shell Accounts Classes
|
| | shacctprofile.dll | 10.0.26100.7309 | Shell Accounts Profile Classes
|
| | sharedpccsp.dll | 10.0.26100.7824 | SharedPCCSP
|
| | sharehost.dll | 10.0.26100.7920 | ShareHost
|
| | sharemediacpl.dll | 10.0.26100.7309 | Share Media Control Panel
|
| | sharetargets.dll | |
|
| | shcore.dll | 10.0.26100.7920 | SHCORE
|
| | shdocvw.dll | 10.0.26100.7920 | Shell Doc Object and Control Library
|
| | shell32.dll | 10.0.26100.7920 | Windows Shell Common Dll
|
| | shellcommoncommonproxystub.dll | 10.0.26100.7920 | ShellCommon Common Proxy Stub
|
| | shellconfigtask.dll | 10.0.26100.7920 | ShellConfigTask Task
|
| | shellstyle.dll | 10.0.26100.1 | Windows Shell Style Resource Dll
|
| | shfolder.dll | 10.0.26100.1 | Shell Folder Service
|
| | shgina.dll | 10.0.26100.1 | Windows Shell User Logon
|
| | shimeng.dll | 10.0.26100.5074 | Shim Engine DLL
|
| | shimgvw.dll | 10.0.26100.7309 | Photo Gallery Viewer
|
| | shlwapi.dll | 10.0.26100.7920 | Shell Light-weight Utility Library
|
| | shpafact.dll | 10.0.26100.1 | Windows Shell LUA/PA Elevation Factory Dll
|
| | shsetup.dll | 10.0.26100.7309 | Shell setup helper
|
| | shsvcs.dll | 10.0.26100.7309 | Windows Shell Services Dll
|
| | shunimpl.dll | 10.0.26100.5074 | Windows Shell Obsolete APIs
|
| | shutdownext.dll | 10.0.26100.1150 | Shutdown Graphic User Interface
|
| | shutdownux.dll | 10.0.26100.7920 | Shutdown UX
|
| | shwebsvc.dll | 10.0.26100.7309 | Windows Shell Web Services
|
| | signdrv.dll | 10.0.26100.5074 | WMI provider for Signed Drivers
|
| | simauth.dll | 10.0.26100.7920 | EAP SIM run-time dll
|
| | simcfg.dll | 10.0.26100.7705 | EAP SIM config dll
|
| | skci.dll | 10.0.26100.7705 | Secure Kernel Code Integrity Module
|
| | slc.dll | 10.0.26100.7824 | Software Licensing Client Dll
|
| | slcext.dll | 10.0.26100.4484 | Software Licensing Client Extension Dll
|
| | slwga.dll | 10.0.26100.1150 | Software Licensing WGA API
|
| | smartactionplatform.dll | 10.0.26100.7309 | SmartActionPlatform
|
| | smartcardbackgroundpolicy.dll | 10.0.26100.7309 | SmartCardBackgroundPolicy
|
| | smartcardcredentialprovider.dll | 10.0.26100.8037 | Windows Smartcard Credential Provider
|
| | smartcardsimulator.dll | 10.0.26100.7309 | Microsoft Smart Card Simulator Transport
|
| | smartscreen.dll | 1.2.2511.0 | SmartScreen Dynamic Link Library
|
| | smartscreenps.dll | 10.0.26100.7309 | SmartScreenPS
|
| | smbhelperclass.dll | 1.0.0.1 | SMB (File Sharing) Helper Class for Network Diagnostic Framework
|
| | smbwmiv2.dll | 10.0.26100.7309 | WMIv2 Provider for SMB File Server/Client
|
| | smiengine.dll | 10.0.26100.5074 | WMI Configuration Core
|
| | smphost.dll | 10.0.26100.7920 | Storage Management Provider (SMP) host service
|
| | smsroutersvc.dll | 10.0.26100.8036 | Windows SMS Router Service
|
| | sndvolsso.dll | 10.0.26100.7920 | SCA Volume
|
| | snmpapi.dll | 10.0.26100.1882 | SNMP Utility Library
|
| | socialapis.dll | 10.0.26100.7309 | DLL for SocialRT
|
| | softkbd.dll | 10.0.26100.7309 | Soft Keyboard Server and Tip
|
| | softpub.dll | 10.0.26100.1 | Softpub Forwarder DLL
|
| | sortserver2003compat.dll | 10.0.26100.1 | Sort Version Server 2003
|
| | sortwindows61.dll | 10.0.26100.1 | SortWindows61 Dll
|
| | sortwindows62.dll | 10.0.26100.1 | SortWindows62 Dll
|
| | sortwindows63.dll | 10.0.26100.1 | SortWindows63 Dll
|
| | sortwindows64.dll | 10.0.26100.1 | SortWindows64 Dll
|
| | sortwindows6compat.dll | 10.0.26100.1 | Sort Version Windows 6.0
|
| | spacecontrol.dll | 10.0.26100.7920 | Storage Spaces control panel
|
| | spbcd.dll | 10.0.26100.4202 | BCD Sysprep Plugin
|
| | spfileq.dll | 10.0.26100.1882 | Windows SPFILEQ
|
| | spinf.dll | 10.0.26100.1150 | Windows SPINF
|
| | spmpm.dll | 10.0.26100.1 | MountPointManager Sysprep Plugin
|
| | spnet.dll | 10.0.26100.1 | Net Sysprep Plugin
|
| | spoolss.dll | 10.0.26100.7920 | Spooler SubSystem DLL
|
| | spopk.dll | 10.0.26100.4484 | OPK Sysprep Plugin
|
| | spp.dll | 10.0.26100.2314 | Microsoft® Windows Shared Protection Point Library
|
| | sppc.dll | 10.0.26100.7824 | Software Licensing Client Dll
|
| | sppcext.dll | 10.0.26100.7920 | Software Protection Platform Client Extension Dll
|
| | sppcomapi.dll | 10.0.26100.7920 | Software Licensing Library
|
| | sppcommdlg.dll | 10.0.26100.1 | Software Licensing UI API
|
| | sppnp.dll | 10.0.26100.7920 | PnP module of SysPrep
|
| | sppobjs.dll | 10.0.26100.8036 | Software Protection Platform Plugins
|
| | sppwinob.dll | 10.0.26100.7920 | Software Protection Platform Windows Plugin
|
| | sppwmi.dll | 10.0.26100.7920 | Software Protection Platform WMI provider
|
| | spwinsat.dll | 10.0.26100.1 | WinSAT Sysprep Plugin
|
| | spwizeng.dll | 10.0.26100.7309 | Setup Wizard Framework
|
| | spwizimg.dll | 10.0.26100.1882 | Setup Wizard Framework Resources
|
| | spwizres.dll | 10.0.26100.1882 | Setup Wizard Framework Resources
|
| | spwmp.dll | 12.0.26100.1882 | Windows Media Player System Preparation DLL
|
| | sqloledb.dll | 10.0.26100.7309 | OLE DB Provider for SQL Server
|
| | sqloledb.dll | 10.0.26100.7309 | OLE DB Provider for SQL Server
|
| | sqlsrv32.dll | 10.0.26100.3624 | SQL Server ODBC Driver
|
| | sqlxmlx.dll | 10.0.26100.1 | XML extensions for SQL Server
|
| | sqlxmlx.dll | 10.0.26100.1150 | XML extensions for SQL Server
|
| | sqmapi.dll | 10.0.26100.7705 | SQM Client
|
| | srchadmin.dll | 7.0.26100.7920 | Indexing Options
|
| | srclient.dll | 10.0.26100.4343 | Microsoft® Windows System Restore Client Library
|
| | srcore.dll | 10.0.26100.5074 | Microsoft® Windows System Restore Core Library
|
| | srevents.dll | 10.0.26100.1 | SrEvents
|
| | srh.dll | 10.0.26100.7920 | Screen Reader Helper DLL
|
| | srhelper.dll | 10.0.26100.5074 | Microsoft® Windows driver and windows update enumeration library
|
| | srpapi.dll | 10.0.26100.7309 | SRP APIs Dll
|
| | srrstr.dll | 10.0.26100.5074 | Microsoft® Windows System Protection Configuration Library
|
| | srumapi.dll | 10.0.26100.5074 | System Resource Usage Monitor API
|
| | srumsvc.dll | 10.0.26100.7920 | System Resource Usage Monitor Service
|
| | srvcli.dll | 10.0.26100.1150 | Server Service Client DLL
|
| | srvsvc.dll | 10.0.26100.7920 | Server Service DLL
|
| | srwmi.dll | 10.0.26100.7309 | Microsoft® Windows System Restore WMI Provider
|
| | sscore.dll | 10.0.26100.7920 | Server Service Core DLL
|
| | sscoreext.dll | 10.0.26100.1 | Server Service Core DLL
|
| | ssdm.dll | 10.0.26100.7309 | Spatial Audio Shared Memory Manager
|
| | ssdpapi.dll | 10.0.26100.7920 | SSDP Client API DLL
|
| | ssdpsrv.dll | 10.0.26100.7920 | SSDP Service DLL
|
| | sspicli.dll | 10.0.26100.7920 | Security Support Provider Interface
|
| | sspisrv.dll | 10.0.26100.7920 | LSA SSPI RPC interface DLL
|
| | ssshim.dll | 10.0.26100.7920 | Windows Componentization Platform Servicing API
|
| | sstpcfg.dll | 10.0.26100.1 | SSTP config
|
| | sstpsvc.dll | 10.0.26100.8036 | Provides the facility of using Secure Socket Tunneling Protocol (SSTP) to connect to remote computers (using VPN).
|
| | starttiledata.dll | 10.0.26100.7920 | Start Tile Data InProc Server
|
| | startupscan.dll | 10.0.26100.7309 | Startup scan task DLL
|
| | staterepository.core.dll | 10.0.26100.7920 | StateRepository Core
|
| | stclient.dll | 2001.12.10941.16384 | COM+ Configuration Catalog Client
|
| | sti.dll | 10.0.26100.7309 | Still Image Devices client DLL
|
| | sti_ci.dll | 10.0.26100.7920 | Still Image Class Installer
|
| | stobject.dll | 10.0.26100.7920 | Systray shell service object
|
| | storagecontexthandler.dll | 10.0.26100.7309 | Device Center Storage Context Menu Handler
|
| | storageusage.dll | 10.0.26100.7309 | Storage Usage
|
| | storagewmi.dll | 10.0.26100.7920 | WMI Provider for Storage Management
|
| | storagewmi_passthru.dll | 10.0.26100.7920 | WMI PassThru Provider for Storage Management
|
| | storewuauth.dll | 1451.2510.27012.0 | Authentication Provider
|
| | storprop.dll | 10.0.26100.1882 | Property Pages for Storage Devices
|
| | storsvc.dll | 10.0.26100.7920 | Storage Services
|
| | streamci.dll | 10.0.26100.1 | Streaming Device Class Installer
|
| | stringfeedbackengine.dll | 10.0.26100.7309 | Component to invoke StringFeedbackEngine
|
| | structuredquery.dll | 7.0.26100.7920 | Structured Query
|
| | sud.dll | 10.0.26100.7920 | SUD Control Panel
|
| | sustainabilityservice.dll | 10.0.26100.7920 | Microsoft Windows Sustainability Service
|
| | svsvc.dll | 10.0.26100.1150 | Microsoft\Spot Verifier
|
| | switcherdatamodel.dll | 10.0.26100.7309 | Switcher Data Model
|
| | swprv.dll | 10.0.26100.5074 | Microsoft® Volume Shadow Copy Service software provider
|
| | sxproxy.dll | 10.0.26100.2314 | Microsoft® Windows System Protection Proxy Library
|
| | sxs.dll | 10.0.26100.7920 | Fusion 2.5
|
| | sxshared.dll | 10.0.26100.1882 | Microsoft® Windows SX Shared Library
|
| | sxssrv.dll | 10.0.26100.1882 | Windows SxS Server DLL
|
| | sxsstore.dll | 10.0.26100.7309 | Sxs Store DLL
|
| | symcryptk.dll | 103.9.1.0 | Microsoft® SymCrypt Kernel Module
|
| | synccenter.dll | 10.0.26100.7920 | Microsoft Sync Center
|
| | synccontroller.dll | 10.0.26100.7920 | SyncController for managing sync of mail, contacts, calendar
|
| | synchostps.dll | 10.0.26100.1150 | Proxystub for sync host
|
| | syncinfrastructure.dll | 10.0.26100.7309 | Microsoft Windows Sync Infrastructure.
|
| | syncinfrastructureps.dll | 10.0.26100.1 | Microsoft Windows sync infrastructure proxy stub.
|
| | syncproxy.dll | 10.0.26100.7309 | SyncProxy for RPC communication about sync of mail, contacts, calendar
|
| | syncreg.dll | 2007.94.26100.1150 | Microsoft Synchronization Framework Registration
|
| | syncres.dll | 10.0.26100.4202 | ActiveSync Resources
|
| | syncsettings.dll | 10.0.26100.7920 | Sync Settings
|
| | syncutil.dll | 10.0.26100.7309 | Sync utilities for mail, contacts, calendar
|
| | sysclass.dll | 10.0.26100.1 | System Class Installer Library
|
| | sysfxui.dll | 10.0.26100.7920 | Audio System FX Control Panel Extension
|
| | sysmain.dll | 10.0.26100.7309 | SysMain Service Host
|
| | sysntfy.dll | 10.0.26100.8036 | Windows Notifications Dynamic Link Library
|
| | syssetup.dll | 10.0.26100.1 | Windows NT System Setup
|
| | systemcpl.dll | 10.0.26100.7920 | My System CPL
|
| | systemeventsbrokerclient.dll | 10.0.26100.1150 | system Events Broker Client Library
|
| | systemeventsbrokerserver.dll | 10.0.26100.5074 | System Events Broker
|
| | systemsettings.datamodel.dll | 10.0.26100.7920 | SystemSettings.Datamodel private API
|
| | systemsettings.deviceencryptionhandlers.dll | 10.0.26100.7920 | Device Encryption Setting Handlers
|
| | systemsettings.handlers.dll | 10.0.26100.7920 | System settings common handler group
|
| | systemsettings.settingsextensibility.dll | 10.0.26100.7920 | System Settings Extensibility Handler Implementation
|
| | systemsettings.useraccountshandlers.dll | 10.0.26100.7920 | SystemSettings.UserAccountsHandlers DLL
|
| | systemsettingsproxyclientdvcplugin.dll | 10.0.26100.7920 | System Setting Proxy Client Plugin
|
| | systemsettingsthresholdadminflowui.dll | 10.0.26100.7920 | System Settings Admin Flow XAML UI Implementation
|
| | systemsupportinfo.dll | 10.0.26100.7309 | Microsoft Windows operating system.
|
| | t2embed.dll | 10.0.26100.7309 | Microsoft T2Embed Font Embedding
|
| | tabbtn.dll | 10.0.26100.1882 | Microsoft Tablet PC Buttons Component
|
| | tabbtnex.dll | 10.0.26100.5074 | Microsoft Tablet PC Extended Buttons Component
|
| | tabsvc.dll | 10.0.26100.7920 | Microsoft Text Input Management Service
|
| | tapi3.dll | 10.0.26100.5074 | Microsoft TAPI3
|
| | tapi32.dll | 10.0.26100.5074 | Microsoft® Windows(TM) Telephony API Client DLL
|
| | tapilua.dll | 10.0.26100.5074 | Microsoft® Windows(TM) Phone And Modem Lua Elevation Dll
|
| | tapimigplugin.dll | 10.0.26100.5074 | Microsoft® Windows(TM) TAPI Migration Plugin Dll
|
| | tapiperf.dll | 10.0.26100.5074 | Microsoft® Windows(TM) Telephony Performance Monitor
|
| | tapisrv.dll | 10.0.26100.8036 | Microsoft® Windows(TM) Telephony Server
|
| | tapisysprep.dll | 10.0.26100.5074 | Microsoft® Windows(TM) Telephony Sysprep Work
|
| | tapiui.dll | 10.0.26100.4202 | Microsoft® Windows(TM) Telephony API UI DLL
|
| | taskapis.dll | 10.0.26100.7309 | DLL for TaskRT
|
| | taskbar.dll | 10.0.26100.7920 | Taskbar Dll
|
| | taskbarcpl.dll | 10.0.26100.7309 | Taskbar Control Panel
|
| | taskcomp.dll | 10.0.26100.4202 | Task Scheduler Backward Compatibility Plug-in
|
| | taskflowdataengine.dll | 10.0.26100.7920 | Task Flow Data Engine DLL
|
| | taskmanagerdatalayer.dll | |
|
| | taskschd.dll | 10.0.26100.5074 | Task Scheduler COM API
|
| | taskschdps.dll | 10.0.26100.1 | Task Scheduler Interfaces Proxy
|
| | tbauth.dll | 10.0.26100.8036 | TBAuth protocol handler
|
| | tbs.dll | 10.0.26100.7920 | TBS
|
| | tcbloader.dll | 10.0.26100.8037 | TCB Loader Library
|
| | tcpipcfg.dll | 10.0.26100.7920 | Network Configuration Objects
|
| | tcpmib.dll | 10.0.26100.5074 | Standard TCP/IP Port Monitor Helper DLL
|
| | tcpmon.dll | 10.0.26100.7920 | Standard TCP/IP Port Monitor DLL
|
| | tcpmonui.dll | 10.0.26100.7309 | Standard TCP/IP Port Monitor UI DLL
|
| | tdh.dll | 10.0.26100.7019 | Event Trace Helper Library
|
| | tdhres.dll | 10.0.26100.8036 | Event Trace Helper Library Resources
|
| | tdlmigration.dll | 10.0.26100.7309 | TDL To TileStore Migrator
|
| | telephonyinteractiveuser.dll | 10.0.26100.7309 | A Telephony DLL that does work for the Interactive User
|
| | telephonyinteractiveuserres.dll | 10.0.26100.1882 | Resource DLL for Telephony Interactive User functions
|
| | tempsignedlicenseexchangetask.dll | 10.0.26100.1150 | TempSignedLicenseExchangeTask Task
|
| | termmgr.dll | 10.0.26100.5074 | Microsoft TAPI3 Terminal Manager
|
| | termsrv.dll | 10.0.26100.7920 | Remote Desktop Session Host Server Remote Connections Manager
|
| | tetheringclient.dll | 10.0.26100.7920 | Tethering Client
|
| | tetheringconfigsp.dll | 10.0.26100.1150 | Tethering Configuration Service Provider
|
| | tetheringieprovider.dll | 10.0.26100.1150 | Microsoft Windows Tethering IE Provider DLL
|
| | tetheringmgr.dll | 10.0.26100.7309 | Microsoft Windows Tethering Manager DLL
|
| | tetheringservice.dll | 10.0.26100.7920 | Tethering Service
|
| | tetheringstation.dll | 10.0.26100.7309 | Microsoft Windows Tethering Station DLL
|
| | textinputframework.dll | 10.0.26100.7920 | "TextInputFramework.DYNLINK"
|
| | textinputmethodformatter.dll | 10.0.26100.7920 | TextInputMethodFormatter DLL
|
| | textshaping.dll | 10.0.26100.7824 | Microsoft Text Shaping Library
|
| | themecpl.dll | 10.0.26100.7920 | Personalization CPL
|
| | themes.ssfdownload.scheduledtask.dll | 10.0.26100.7705 | ThemesSyncedImageDownload Task
|
| | themeservice.dll | 10.0.26100.7920 | Windows Shell Theme Service Dll
|
| | themeui.dll | 10.0.26100.7920 | Windows Theme API
|
| | threadpoolwinrt.dll | 10.0.26100.1 | Windows WinRT Threadpool
|
| | threatassessment.dll | 1.0.0.221 | ThreatAssessment Dynamic Link Library
|
| | threatexperiencemanager.dll | 5.0.1.1 | ThreatExperienceManager
|
| | threatintelligence.dll | 10.0.26100.7920 | Threat Intelligence Engine
|
| | threatresponseengine.dll | |
|
| | thumbcache.dll | 10.0.26100.7920 | Microsoft Thumbnail Cache
|
| | tier2punctuations.dll | 10.0.26100.7920 | Screen Reader Helper Punctuation DLL
|
| | tieringengineproxy.dll | 10.0.26100.5074 | Storage Tiers Management service proxy
|
| | tiledatarepository.dll | 10.0.26100.7920 | Tile Data Repository
|
| | timebrokerclient.dll | 10.0.26100.7920 | Time Broker Client Library
|
| | timebrokerserver.dll | 10.0.26100.7920 | Time Event Broker
|
| | timedatemuicallback.dll | 10.0.26100.1 | Time Date Control UI Language Change plugin
|
| | timesync.dll | 10.0.26100.7309 | W32Time Sync Library
|
| | timesynctask.dll | 10.0.26100.1150 | Time Synchronization Task
|
| | tlscsp.dll | 10.0.26100.4202 | Microsoft® Remote Desktop Services Cryptographic Utility
|
| | tokenbinding.dll | 10.0.26100.1150 | Token Binding Protocol
|
| | tokenbroker.dll | 10.0.26100.8036 | Token Broker
|
| | tokenbrokerui.dll | 10.0.26100.7309 | Token Broker UI
|
| | tpmcertresources.dll | 10.0.26100.7920 | TpmCertResources
|
| | tpmcompc.dll | 10.0.26100.1 | Computer Chooser Dialog
|
| | tpmcoreprovisioning.dll | 10.0.26100.7920 | TPM Core Provisioning Library
|
| | tpmtasks.dll | 10.0.26100.8036 | TPM Maintenance Tasks
|
| | tpmvsc.dll | 10.0.26100.7309 | Microsoft TPM Virtual Smart Card
|
| | tprtdll.dll | 10.0.26100.7920 | Trusted App Runtime
|
| | tquery.dll | 7.0.26100.7920 | Microsoft Tripoli Query
|
| | traffic.dll | 10.0.26100.1 | Microsoft Traffic Control 1.0 DLL
|
| | transcodewallpaper.dll | 10.0.26100.7309 | Wallpaper Image Transcoder
|
| | transfertargets.dll | |
|
| | transliterationranker.dll | 10.0.26100.7309 | "TransliterationRanker.DYNLINK"
|
| | trie.dll | 10.0.26100.7309 | Microsoft Trie Dll
|
| | trkwks.dll | 10.0.26100.4202 | Distributed Link Tracking Client
|
| | trustedsignalcredprov.dll | 10.0.26100.7309 | TrustedSignal Credential Provider
|
| | tsbyuv.dll | 10.0.26100.1150 | Toshiba Video Codec
|
| | tsf3gip.dll | 10.0.26100.7920 | "tsf3gip.DYNLINK"
|
| | tsgqec.dll | 10.0.26100.7309 | RD Gateway QEC
|
| | tsmf.dll | 10.0.26100.7019 | RDP MF Plugin
|
| | tspkg.dll | 10.0.26100.7309 | Web Service Security Package
|
| | tssessionux.dll | 10.0.26100.7309 | TS Session UX
|
| | tsusbgdcoinstaller.dll | 10.0.26100.2894 | Remote Desktop Generic USB Driver Coinstaller
|
| | tsusbredirectiongrouppolicyextension.dll | 10.0.26100.3037 | Remote Desktop USB Redirection GP Extension
|
| | tsworkspace.dll | 10.0.26100.7309 | RemoteApp and Desktop Connection Component
|
| | ttdloader.dll | 1.11.580.0 | Time Travel Debugging Runtime Loader
|
| | ttdplm.dll | 10.0.26100.3624 | Time Travel Debugger PLM APIs
|
| | ttdrecord.dll | 1.11.580.0 | Time Travel Debugging Recording Manager
|
| | ttdrecordcpu.dll | 1.11.580.0 | Time Travel Debugging CPU Recorder Runtime
|
| | ttlsauth.dll | 10.0.26100.7920 | EAP TTLS run-time dll
|
| | ttlscfg.dll | 10.0.26100.7920 | EAP TTLS configuration dll
|
| | ttlsext.dll | 10.0.26100.7705 | Windows Extension library for EAP TTLS
|
| | tvratings.dll | 10.0.26100.1882 | Module for managing TV ratings
|
| | twext.dll | 10.0.26100.7920 | Previous Versions property page
|
| | twinapi.appcore.dll | 10.0.26100.7705 | twinapi.appcore
|
| | twinapi.dll | 10.0.26100.7920 | twinapi
|
| | twinui.appcore.dll | 10.0.26100.7920 | TWINUI.APPCORE
|
| | twinui.dll | 10.0.26100.8036 | TWINUI
|
| | twinui.pcshell.dll | 10.0.26100.8036 | Twinui.PCShell
|
| | txflog.dll | 2001.12.10941.16384 | COM+
|
| | txfw32.dll | 10.0.26100.1 | TxF Win32 DLL
|
| | tzautoupdate.dll | 10.0.26100.7920 | Auto Time Zone Updater
|
| | tzres.dll | 10.0.26100.5074 | Time Zones resource DLL
|
| | tzsyncres.dll | 10.0.26100.2161 | TimeZone Sync Resources DLL
|
| | ubpm.dll | 10.0.26100.7920 | Unified Background Process Manager DLL
|
| | ucrtbase.dll | 10.0.26100.7623 | Microsoft® C Runtime Library
|
| | ucrtbase_clr0400.dll | 14.29.30154.0 | Microsoft® C Runtime Library
|
| | ucrtbase_enclave.dll | 10.0.26100.7623 | Microsoft® C Runtime Library
|
| | udhisapi.dll | 10.0.26100.5074 | UPnP Device Host ISAPI Extension
|
| | udiapiclient.dll | 0.2.708.0 | Microsoft Universal Download and Install
|
| | udwm.dll | 10.0.26100.7920 | Microsoft Desktop Window Manager
|
| | ueficsp.dll | 10.0.26100.1 | Windows UefiCsp Resources
|
| | uexfat.dll | 10.0.26100.1882 | eXfat Utility DLL
|
| | ufat.dll | 10.0.26100.1882 | FAT Utility DLL
|
| | uiamanager.dll | 10.0.26100.7309 | UiaManager
|
| | uianimation.dll | 10.0.26100.7920 | Windows Animation Manager
|
| | uiautomationcore.dll | 7.2.26100.7920 | Microsoft UI Automation Core
|
| | uicom.dll | 10.0.26100.1150 | Add/Remove Modems
|
| | uieapi.dll | 10.0.26100.7920 | UIE Api
|
| | uimanagerbrokerps.dll | 10.0.26100.4202 | Microsoft UIManager Broker Proxy Stub
|
| | uiomapapi.dll | 10.0.26100.7309 | Usermode IO Driver Library
|
| | uireng.dll | 10.0.26100.7309 | UI Recording Engine Library
|
| | uiribbon.dll | 10.0.26100.1 | Windows Ribbon Framework
|
| | uiribbonres.dll | 10.0.26100.1 | Windows Ribbon Framework Resources
|
| | ulib.dll | 10.0.26100.7019 | File Utilities Support DLL
|
| | umb.dll | 10.0.26100.5074 | User Mode Bus Driver Interface Dll
|
| | umdmxfrm.dll | 10.0.26100.1 | Unimodem Tranform Module
|
| | umpdc.dll | 10.0.26100.7019 | User Mode Power Dependency Coordinator
|
| | umpnpmgr.dll | 10.0.26100.5074 | User-mode Plug-and-Play Service
|
| | umpo.dll | 10.0.26100.7920 | User-mode Power Service
|
| | umpodev.dll | 10.0.26100.7920 | User-mode Power Device API
|
| | umpoext.dll | 10.0.26100.7920 | User-mode Power Service Extensions
|
| | umpo-overrides.dll | 10.0.26100.7309 | UMPO machine specific overrides for PC
|
| | umpowmi.dll | 10.0.26100.1150 | User-mode Power Service WMI Providers
|
| | umrdp.dll | 10.0.26100.7019 | Remote Desktop Services Device Redirector Service
|
| | unattend.dll | 10.0.26100.7309 | Unattend Library
|
| | unenrollhook.dll | 10.0.26100.7309 | unenrollhook DLL
|
| | unifiedconsent.dll | 10.0.26100.7920 | Unified Consent API implementation
|
| | unimdmat.dll | 10.0.26100.1150 | Unimodem Service Provider AT Mini Driver
|
| | unionfsapi.dll | 10.0.26100.7705 | UnionFS user mode API
|
| | uniplat.dll | 10.0.26100.1882 | Unimodem AT Mini Driver Platform Driver for Windows NT
|
| | unistore.dll | 10.0.26100.7309 | Unified Store
|
| | untfs.dll | 10.0.26100.1150 | NTFS Utility DLL
|
| | updateagent.dll | 10.0.26100.7920 | Update Agent
|
| | updatecompression.dll | 5.0.1.1 | Windows Update Compression Engine
|
| | updatecsp.dll | 10.0.26100.7309 | UpdateCsp
|
| | updatepolicy.dll | 1451.2601.23012.0 | Update Policy Reader
|
| | updatereboot.dll | 10.0.26100.7309 | Microsoft (R) Update Reboot Scenario Native Aggregation Plugin
|
| | upnp.dll | 10.0.26100.7920 | UPnP Control Point API
|
| | upnphost.dll | 10.0.26100.7920 | UPnP Device Host
|
| | upprinterinstallscsp.dll | 10.0.26100.7920 | UPPrinterInstallsCSP
|
| | upshared.dll | 10.0.26100.7309 | UNPShared
|
| | urefs.dll | 10.0.26100.7920 | UREFS Utility DLL
|
| | urefsv1.dll | 10.0.26100.5074 | NTFS Utility DLL
|
| | ureg.dll | 10.0.26100.1 | Registry Utility DLL
|
| | url.dll | 11.0.26100.1 | Internet Shortcut Shell Extension DLL
|
| | urlmon.dll | 11.0.26100.7920 | OLE32 Extensions for Win32
|
| | usbcapi.dll | 10.0.26100.1150 | USB Connector API
|
| | usbceip.dll | 10.0.26100.7019 | USBCEIP Task
|
| | usbmon.dll | 10.0.26100.7920 | Standard Dynamic Printing Port Monitor DLL
|
| | usbperf.dll | 10.0.26100.1882 | USB Performance Objects DLL
|
| | usbpmapi.dll | 10.0.26100.7920 | USB Policy Manager User-Mode Library
|
| | usbsettingshandlers.dll | 10.0.26100.7920 | USB Settings Handlers Implementation
|
| | usbtask.dll | 10.0.26100.7309 | UsbTask
|
| | usbui.dll | 10.0.26100.1150 | USB UI Dll
|
| | user32.dll | 10.0.26100.7920 | Multi-User Windows USER API Client DLL
|
| | useraccountcontrolsettings.dll | 10.0.26100.7309 | UserAccountControlSettings
|
| | useractivitybroker.dll | 10.0.26100.7309 | useractivitybroker
|
| | usercpl.dll | 10.0.26100.7920 | User control panel
|
| | userdataaccessres.dll | 10.0.26100.1882 | Resource DLL for the UserDataAccess stack
|
| | userdataaccountapis.dll | 10.0.26100.7309 | DLL for UserDataAccountsRT
|
| | userdatalanguageutil.dll | 10.0.26100.1882 | Language-related helper functions for user data
|
| | userdataplatformhelperutil.dll | 10.0.26100.7019 | Platform Utilities for data access
|
| | userdataservice.dll | 10.0.26100.7705 | The endpoint for 3rd party APIs to read/write user data
|
| | userdatatimeutil.dll | 10.0.26100.3775 | Time-related helper functions for user data
|
| | userdatatypehelperutil.dll | 10.0.26100.1882 | Type Utilities for data access
|
| | userdeviceregistration.dll | 10.0.26100.7920 | Microsoft Entra User Device Registration WinRT
|
| | userdeviceregistration.ngc.dll | 10.0.26100.7920 | Microsoft Entra User Device Registration WinRT
|
| | userenv.dll | 10.0.26100.7920 | Userenv
|
| | userinitext.dll | 10.0.26100.7309 | UserInit Utility Extension DLL
|
| | userlanguageprofilecallback.dll | 10.0.26100.7309 | MUI Callback for User Language profile changed
|
| | usermgr.dll | 10.0.26100.7920 | UserMgr
|
| | usermgrcli.dll | 10.0.26100.7920 | UserMgr API DLL
|
| | usermgrproxy.dll | 10.0.26100.7920 | UserMgrProxy
|
| | usoapi.dll | 10.0.26100.7705 | Update Session Orchestrator API
|
| | usocoreps.dll | 10.0.26100.7705 | USO Core Worker Proxy Stub
|
| | usodocked.dll | 10.0.26100.7920 | Uso Docked DLL
|
| | usosvc.dll | 10.0.26100.7920 | Update Session Orchestrator Service
|
| | usp10.dll | 10.0.26100.1 | Uniscribe Unicode script processor
|
| | ustprov.dll | 10.0.26100.1150 | User State WMI Provider
|
| | utcapi.dll | 10.0.26100.7920 | Microsoft Diagtrack RPC API surface
|
| | utcutil.dll | 10.0.26100.7920 | Microsoft Windows Telemetry Utils
|
| | utildll.dll | 10.0.26100.1 | WinStation utility support DLL
|
| | uudf.dll | 10.0.26100.1150 | UDF Utility DLL
|
| | uvcmodel.dll | 10.0.26100.7309 | UvcModel
|
| | uxframe.dll | |
|
| | uxinit.dll | 10.0.26100.7705 | Windows User Experience Session Initialization Dll
|
| | uxlib.dll | 10.0.26100.1882 | Setup Wizard Framework
|
| | uxlibres.dll | 10.0.26100.1882 | UXLib Resources
|
| | uxtheme.dll | 10.0.26100.7920 | Microsoft UxTheme Library
|
| | vault.dll | 10.0.26100.7309 | Windows vault Control Panel
|
| | vaultcds.dll | 10.0.26100.7309 | Vault CDS
|
| | vaultcli.dll | 10.0.26100.7309 | Credential Vault Client Library
|
| | vaultroaming.dll | 1.0.0.1 | Vault Roaming
|
| | vaultsvc.dll | 10.0.26100.7309 | Credential Manager Service
|
| | vbsapi.dll | 10.0.26100.7920 | Windows VBS HVCI API
|
| | vbscript.dll | 10.0.26100.7920 | Microsoft ® VBScript
|
| | vbssysprep.dll | 10.0.26100.7309 | VBS Sysprep
|
| | vcardparser.dll | 10.0.26100.5074 | Supports the parsing of VCard and ICal formatted data
|
| | vcruntime140_1_clr0400.dll | 14.29.30154.0 | Microsoft® C Runtime Library
|
| | vcruntime140_clr0400.dll | 14.29.30154.0 | Microsoft® C Runtime Library
|
| | vds_ps.dll | 10.0.26100.7920 | Microsoft® Virtual Disk Service proxy/stub
|
| | vdsbas.dll | 10.0.26100.7920 | Virtual Disk Service Basic Provider
|
| | vdsdyn.dll | 10.0.26100.5074 | VDS Dynamic Volume Provider, Version 2.1.0.1
|
| | vdsutil.dll | 10.0.26100.7920 | Virtual Disk Service Utility Library
|
| | vdsvd.dll | 10.0.26100.5074 | VDS Virtual Disk Provider, Version 1.0
|
| | veinterop.dll | 10.0.26100.7705 | VTL1 interop dll for OS components
|
| | verifier.dll | 10.0.26100.1882 | Standard application verifier provider dll
|
| | version.dll | 10.0.26100.1150 | Version Checking and File Installation Libraries
|
| | vertdll.dll | 10.0.26100.7920 | VSM enclave runtime DLL
|
| | vfuprov.dll | 10.0.26100.7309 | SRUM provider
|
| | vfwwdm32.dll | 10.0.26100.1882 | VfW MM Driver for WDM Video Capture Devices
|
| | vhfum.dll | 10.0.26100.1 | Virtual HID Framework User-Mode Library
|
| | vid.dll | 10.0.26100.5074 | Microsoft Hyper-V Virtualization Infrastructure Driver Library
|
| | videohandlers.dll | 10.0.26100.7920 | Video Settings Handlers Implementation
|
| | vidreszr.dll | 10.0.26100.7019 | Windows Media Resizer
|
| | virtdisk.dll | 10.0.26100.5074 | Virtual Disk API DLL
|
| | virtualmon.dll | 10.0.26100.7920 | Virtual Printer Monitor
|
| | virtualsurroundapo.dll | 10.0.26100.7309 | VirtualSurround APO
|
| | vmapplicationhealthmonitorproxy.dll | 10.0.26100.7309 | VM Application Health Monitor proxy dll
|
| | vmbuspipe.dll | 10.0.26100.7920 | VmBus User Mode Pipe DLL
|
| | vmdevicehost.dll | 10.0.26100.7309 | Hyper-V Device Virtualization Library
|
| | vmictimeprovider.dll | 10.0.26100.7309 | Virtual Machine Integration Component Time Sync Provider Library
|
| | vmrdvcore.dll | 10.0.26100.1150 | VmRdvCore EndPoints
|
| | vocabroaminghandler.dll | 10.0.26100.7309 | Microsoft Vocabulary Roaming Handler Dll
|
| | voiceactivationmanager.dll | 10.0.26100.7920 | Windows Voice Activation Manager
|
| | voiprt.dll | 10.0.26100.7309 | Voip Runtime
|
| | vpnike.dll | 10.0.26100.7920 | VPNIKE Protocol Engine - Test dll
|
| | vpnikeapi.dll | 10.0.26100.7462 | VPN IKE API's
|
| | vpnsohdesktop.dll | 10.0.26100.1 | VpnSohDesktop.dll
|
| | vpnv2csp.dll | 10.0.26100.7920 | VPNv2CSP
|
| | vscmgrps.dll | 10.0.26100.3624 | Microsoft Virtual Smart Card Manager Proxy/Stub
|
| | vss_ps.dll | 10.0.26100.1 | Microsoft® Volume Shadow Copy Service proxy/stub
|
| | vssapi.dll | 10.0.26100.7920 | Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL
|
| | vsstrace.dll | 10.0.26100.7920 | Microsoft® Volume Shadow Copy Service Tracing Library
|
| | vulkan-1.dll | 1.3.300.0 | Vulkan Loader
|
| | w32time.dll | 10.0.26100.7920 | Windows Time Service
|
| | w32topl.dll | 10.0.26100.1 | Windows NT Topology Maintenance Tool
|
| | waasassessment.dll | 10.0.26100.7920 | WaaS Assessment
|
| | waasmedicps.dll | 10.0.26100.7309 | WaaS Medic Proxy Stub library
|
| | waasmedicsvc.dll | 10.0.26100.7309 | Enables remediation and protection of Windows Update components.
|
| | wab32.dll | 10.0.26100.7309 | Microsoft (R) Contacts DLL
|
| | wab32.dll | 10.0.26100.7309 | Microsoft (R) Contacts DLL
|
| | wab32res.dll | 10.0.26100.1882 | Microsoft (R) Contacts DLL
|
| | wab32res.dll | 10.0.26100.1882 | Microsoft (R) Contacts DLL
|
| | wabsyncprovider.dll | 10.0.26100.1150 | Microsoft Windows Contacts Sync Provider
|
| | walletbackgroundserviceproxy.dll | 10.0.26100.7309 | Wallet Background Proxy
|
| | walletproxy.dll | 10.0.26100.1 | Wallet proxy
|
| | walletservice.dll | 10.0.26100.7920 | Wallet Service
|
| | wavemsp.dll | 10.0.26100.5074 | Microsoft Wave MSP
|
| | wbemcomn.dll | 10.0.26100.7920 | WMI
|
| | wbiosrvc.dll | 10.0.26100.7920 | Windows Biometric Service
|
| | wc_storage.dll | 10.0.26100.7623 | WC_STORAGE.DLL
|
| | wci.dll | 10.0.26100.1882 | Wci user mode API
|
| | wcimage.dll | 10.0.26100.7623 | Windows Container Base Layer Utility Library
|
| | wcmapi.dll | 10.0.26100.7920 | Windows Connection Manager Client API
|
| | wcmcsp.dll | 10.0.26100.7920 | Windows Connection Service Provider DLL
|
| | wcmsvc.dll | 10.0.26100.7920 | Windows Connection Manager Service DLL
|
| | wcnapi.dll | 10.0.26100.7920 | Windows Connect Now - API Helper DLL
|
| | wcncsvc.dll | 10.0.26100.7920 | Windows Connect Now - Config Registrar Service
|
| | wcneapauthproxy.dll | 10.0.26100.7920 | Windows Connect Now - WCN EAP Authenticator Proxy
|
| | wcneappeerproxy.dll | 10.0.26100.7920 | Windows Connect Now - WCN EAP PEER Proxy
|
| | wcnnetsh.dll | 10.0.26100.1 | WCN Netsh Helper DLL
|
| | wcnwiz.dll | 10.0.26100.7309 | Windows Connect Now Wizards
|
| | wdc.dll | 10.0.26100.7309 | Performance Monitor
|
| | wdi.dll | 10.0.26100.7705 | Windows Diagnostic Infrastructure
|
| | wdigest.dll | 10.0.26100.7705 | Microsoft Digest Access
|
| | wdscore.dll | 10.0.26100.1150 | Panther Engine Module
|
| | webauthn.dll | 10.0.26100.7920 | Web Authentication
|
| | webcamui.dll | 10.0.26100.7705 | Microsoft® Windows® Operating System
|
| | webcheck.dll | 11.0.26100.7309 | Web Site Monitor
|
| | webclnt.dll | 10.0.26100.1150 | Web DAV Service DLL
|
| | webio.dll | 10.0.26100.7920 | Web Transfer Protocols API
|
| | webplatstorageserver.dll | 10.0.26100.7920 | "webplatstorageserver.DYNLINK"
|
| | webruntimemanager.dll | 10.0.26100.7920 | Microsoft Edge Manager
|
| | webservices.dll | 10.0.26100.7920 | Windows Web Services Runtime
|
| | websocket.dll | 10.0.26100.3912 | Web Socket API
|
| | webthreatdefsvc.dll | 10.0.26100.7309 | Web Threat Defense Service
|
| | webthreatdefusersvc.dll | 10.0.26100.7309 | Web Threat Defense User Service
|
| | wecapi.dll | 10.0.26100.1 | Event Collector Configuration API
|
| | wecsvc.dll | 10.0.26100.3323 | Event Collector Service
|
| | wephostsvc.dll | 10.0.26100.1882 | WEP Host Service
|
| | wer.dll | 10.0.26100.7920 | Windows Error Reporting DLL
|
| | werconcpl.dll | 10.0.26100.7309 | PRS CPL
|
| | wercplsupport.dll | 10.0.26100.7309 | Problem Reports
|
| | werdiagcontroller.dll | 10.0.26100.7920 | WER Diagnostic Controller
|
| | werenc.dll | 10.0.26100.7920 | Windows Error Reporting Dump Encoding Library
|
| | weretw.dll | 10.0.26100.7920 | WERETW.DLL
|
| | wersvc.dll | 10.0.26100.7920 | Windows Error Reporting Service
|
| | werui.dll | 10.0.26100.7309 | Windows Error Reporting UI DLL
|
| | wevtapi.dll | 10.0.26100.7309 | Eventing Consumption and Configuration API
|
| | wevtfwd.dll | 10.0.26100.1882 | WS-Management Event Forwarding Plug-in
|
| | wevtsvc.dll | 10.0.26100.7920 | Event Logging Service
|
| | wfapigp.dll | 10.0.26100.7920 | Windows Defender Firewall GPO Helper dll
|
| | wfdprov.dll | 10.0.26100.7920 | Private WPS provisioning API DLL for Wi-Fi Direct
|
| | wfdsconmgr.dll | 10.0.26100.7705 | Wi-Fi Direct Services Connection Manager RPC client
|
| | wfdsconmgrsvc.dll | 10.0.26100.7705 | Wi-Fi Direct Services Connection Manager Service
|
| | wfhc.dll | 10.0.26100.5074 | Windows Defender Firewall Helper Class
|
| | whealogr.dll | 10.0.26100.1 | WHEA Troubleshooter
|
| | whesvc.dll | 10.0.26100.7920 | whesvc
|
| | whesvc_assets.dll | |
|
| | whhelper.dll | 10.0.26100.7705 | Net shell helper DLL for winHttp
|
| | wiaaut.dll | 10.0.26100.7309 | WIA Automation Layer
|
| | wiadefui.dll | 10.0.26100.5074 | WIA Scanner Default UI
|
| | wiadss.dll | 10.0.26100.7309 | WIA TWAIN compatibility layer
|
| | wiaextensionhost64.dll | 10.0.26100.5074 | WIA Extension Host for thunking APIs from 32-bit to 64-bit process
|
| | wiarpc.dll | 10.0.26100.7309 | Windows Image Acquisition RPC client DLL
|
| | wiascanprofiles.dll | 10.0.26100.5074 | Microsoft Windows ScanProfiles
|
| | wiaservc.dll | 10.0.26100.7920 | Still Image Devices Service
|
| | wiashext.dll | 10.0.26100.5074 | Imaging Devices Shell Folder UI
|
| | wiatrace.dll | 10.0.26100.5074 | WIA Tracing
|
| | wificloudstore.dll | 10.0.26100.7705 | Windows WiFi Sync Provider DLL
|
| | wificonfigsp.dll | 10.0.26100.7920 | Wi-Fi ConfigSP Library
|
| | wifidatacapabilityhandler.dll | 10.0.26100.7309 | Windows wifiData Capability Handler
|
| | wifidisplay.dll | 10.0.26100.7309 | Wi-Fi Display DLL
|
| | wifinetworkmanager.dll | 10.0.26100.7920 | Wireless Network Manager Library
|
| | wimgapi.dll | 10.0.26100.7920 | Windows Imaging Library
|
| | win32_deviceguard.dll | 10.0.26100.7920 | DeviceGuard WMI Provider
|
| | win32appinventorycsp.dll | 10.0.26100.7920 | Win32 Application Inventory CSP
|
| | win32compatibilityappraisercsp.dll | 10.0.26100.7920 | Win32CompatibilityAppraiserCSP
|
| | win32spl.dll | 10.0.26100.7920 | Client Side Rendering Print Provider
|
| | win32u.dll | 10.0.26100.8036 | Win32u
|
| | winbio.dll | 10.0.26100.7705 | Windows Biometrics Client API
|
| | winbiodatamodel.dll | 10.0.26100.7920 | Win Bio Enrollment Data Model
|
| | winbioext.dll | 10.0.26100.7309 | Windows Biometrics Client Extension API
|
| | winbrand.dll | 10.0.26100.7705 | Windows Branding Resources
|
| | wincorlib.dll | 10.0.26100.7920 | Microsoft Windows ® WinRT core library
|
| | wincredprovider.dll | 10.0.26100.7309 | wincredprovider DLL
|
| | wincredui.dll | 10.0.26100.7920 | Credential Manager User Internal Interface
|
| | windiag.dll | 10.0.26100.7920 | Windows Diagnostics Framework - Engine
|
| | windlp.dll | 10.0.26100.7705 | Windows Download Platform
|
| | windowmanagement.dll | 10.0.26100.7623 | Window Management
|
| | windowmanagementapi.dll | 10.0.26100.7309 | Window Management API
|
| | windows.accountscontrol.dll | 10.0.26100.7309 | Windows Accounts Control
|
| | windows.ai.machinelearning.dll | 1.17.2504.1701 | Windows Machine Learning Runtime
|
| | windows.ai.machinelearning.preview.dll | 10.0.26100.1150 | WinRT Windows Machine Learning Preview DLL
|
| | windows.applicationmodel.background.systemeventsbroker.dll | 10.0.26100.7309 | Windows Background System Events Broker API Server
|
| | windows.applicationmodel.background.timebroker.dll | 10.0.26100.1150 | Windows Background Time Broker API Server
|
| | windows.applicationmodel.conversationalagent.dll | 10.0.26100.7920 | Windows Voice Agent Services DLL
|
| | windows.applicationmodel.conversationalagent.internal.proxystub.dll | 10.0.26100.1882 | Windows Voice Agent Services Internal Proxy Stub DLL
|
| | windows.applicationmodel.conversationalagent.proxystub.dll | 10.0.26100.1882 | Windows Voice Agent Services Proxy Stub DLL
|
| | windows.applicationmodel.core.dll | 10.0.26100.7309 | Windows Application Model Core API
|
| | windows.applicationmodel.datatransfer.dll | 10.0.26100.7920 | Windows.ApplicationModel.DataTransfer
|
| | windows.applicationmodel.dll | 10.0.26100.7920 | Windows ApplicationModel API Server
|
| | windows.applicationmodel.lockscreen.dll | 10.0.26100.7920 | Windows Lock Application Framework DLL
|
| | windows.applicationmodel.store.dll | 10.0.26100.7920 | Microsoft Store Runtime DLL
|
| | windows.applicationmodel.store.preview.dosettings.dll | 10.0.26100.7309 | Delivery Optimization Settings
|
| | windows.applicationmodel.store.testingframework.dll | 10.0.26100.7705 | Microsoft Store Testing Framework Runtime DLL
|
| | windows.applicationmodel.wallet.dll | 10.0.26100.7309 | Windows ApplicationModel Wallet Runtime DLL
|
| | windows.cloudstore.dll | 10.0.26100.7920 | Cloud Data Store
|
| | windows.cloudstore.earlydownloader.dll | 10.0.26100.7920 | Early Downloader for Cloud Data Store
|
| | windows.cloudstore.schema.desktopshell.dll | 10.0.26100.7920 | Desktop Shell Schema for Cloud Data Store
|
| | windows.cloudstore.schema.shell.dll | 10.0.26100.7920 | Shell Schema for Cloud Data Store
|
| | windows.cortana.desktop.dll | 10.0.26100.7920 | Windows.Cortana.Desktop
|
| | windows.cortana.onecore.dll | 10.0.26100.7920 | Windows.Cortana.OneCore
|
| | windows.cortana.proxystub.dll | 10.0.26100.1150 | Windows.Cortana.ProxyStub
|
| | windows.data.activities.dll | 10.0.26100.7920 | Activities DataModel
|
| | windows.data.pdf.dll | 10.0.26100.7920 | PDF WinRT APIs
|
| | windows.devices.background.dll | 10.0.26100.7309 | Windows.Devices.Background
|
| | windows.devices.background.ps.dll | 10.0.26100.1882 | Windows.Devices.Background Interface Proxy
|
| | windows.devices.bluetooth.dll | 10.0.26100.7920 | Windows.Devices.Bluetooth DLL
|
| | windows.devices.custom.dll | 10.0.26100.7309 | Windows.Devices.Custom
|
| | windows.devices.custom.ps.dll | 10.0.26100.1882 | Windows.Devices.Custom Interface Proxy
|
| | windows.devices.enumeration.dll | 10.0.26100.7920 | Windows.Devices.Enumeration
|
| | windows.devices.haptics.dll | 10.0.26100.7309 | Windows Runtime Haptics DLL
|
| | windows.devices.humaninterfacedevice.dll | 10.0.26100.7705 | Windows.Devices.HumanInterfaceDevice DLL
|
| | windows.devices.lights.dll | 10.0.26100.7920 | Windows Runtime Lights DLL
|
| | windows.devices.lowlevel.dll | 10.0.26100.5074 | Windows.Devices.LowLevel DLL
|
| | windows.devices.midi.dll | 10.0.26100.7920 | Windows Runtime MIDI Device server DLL
|
| | windows.devices.perception.dll | 10.0.26100.7309 | Windows Devices Perception API
|
| | windows.devices.picker.dll | 10.0.26100.7920 | Device Picker
|
| | windows.devices.pointofservice.dll | 10.0.26100.7462 | Windows Runtime PointOfService DLL
|
| | windows.devices.portable.dll | 10.0.26100.7309 | Windows Runtime Portable Devices DLL
|
| | windows.devices.printers.dll | 10.0.26100.5074 | Windows Runtime Devices Printers DLL
|
| | windows.devices.printers.extensions.dll | 10.0.26100.5074 | Windows.Devices.Printers.Extensions
|
| | windows.devices.radios.dll | 10.0.26100.7920 | Windows.Devices.Radios DLL
|
| | windows.devices.scanners.dll | 10.0.26100.7309 | Windows Runtime Devices Scanners DLL
|
| | windows.devices.sensors.dll | 10.0.26100.7920 | Windows Runtime Sensors DLL
|
| | windows.devices.serialcommunication.dll | 10.0.26100.4202 | Windows.Devices.SerialCommunication DLL
|
| | windows.devices.smartcards.dll | 10.0.26100.8037 | Windows Runtime Smart Card API DLL
|
| | windows.devices.smartcards.phone.dll | 10.0.26100.7705 | Windows Runtime Phone Smart Card Api DLL
|
| | windows.devices.usb.dll | 10.0.26100.7309 | Windows Runtime Usb DLL
|
| | windows.devices.wifi.dll | 10.0.26100.7920 | Windows.Devices.WiFi DLL
|
| | windows.devices.wifidirect.dll | 10.0.26100.7920 | Windows.Devices.WiFiDirect DLL
|
| | windows.energy.dll | 10.0.26100.7920 | Windows Energy Runtime DLL
|
| | windows.fileexplorer.common.dll | 10.0.26100.7920 | Windows.FileExplorer.Common
|
| | windows.gaming.input.dll | 10.0.26100.7920 | Windows Gaming Input API
|
| | windows.gaming.preview.dll | 10.0.26100.7309 | Windows Gaming API Preview
|
| | windows.gaming.ui.gamebar.dll | 10.0.26100.7309 | Windows Gaming UI API GameBar
|
| | windows.gaming.xboxlive.storage.dll | 10.0.26100.4202 | Xbox Connected Storage WinRT implementation
|
| | windows.globalization.dll | 10.0.26100.7309 | Windows Globalization
|
| | windows.globalization.fontgroups.dll | 10.0.26100.1150 | Fonts Mapping API
|
| | windows.globalization.phonenumberformatting.dll | 10.0.26100.7309 | Windows Libphonenumber OSS component
|
| | windows.graphics.display.brightnessoverride.dll | 10.0.26100.7920 | Windows Runtime Brightness Override DLL
|
| | windows.graphics.display.displayenhancementoverride.dll | 10.0.26100.7920 | Windows Runtime Display Enhancement Override DLL
|
| | windows.graphics.dll | 10.0.26100.7920 | WinRT Windows Graphics DLL
|
| | windows.graphics.printing.3d.dll | 10.0.26100.7309 | Microsoft Windows Printing Support
|
| | windows.graphics.printing.dll | 10.0.26100.7920 | Microsoft Windows Printing Support
|
| | windows.graphics.printing.protectedprint.dll | 10.0.26100.7309 | Microsoft Windows Protected Print
|
| | windows.graphics.printing.workflow.dll | 10.0.26100.7920 | Microsoft Windows Print Workflow
|
| | windows.graphics.printing.workflow.native.dll | 10.0.26100.7019 | Microsoft Windows Print Workflow Native
|
| | windows.help.runtime.dll | 10.0.26100.1 |
|
| | windows.immersiveshell.serviceprovider.dll | 10.0.26100.7920 | Windows.ImmersiveShell.ServiceProvider
|
| | windows.internal.adaptivecards.xamlcardrenderer.dll | 10.0.26100.7309 | Adaptive Cards Xaml Renderer
|
| | windows.internal.capturepicker.desktop.dll | 10.0.26100.7920 | Capture Picker Desktop
|
| | windows.internal.capturepicker.dll | 10.0.26100.7309 | Capture Picker Experience
|
| | windows.internal.devices.bluetooth.dll | 10.0.26100.7920 | Windows.Internal.Devices.Bluetooth DLL
|
| | windows.internal.devices.lights.backlightserver.dll | 10.0.26100.7920 | Windows.Internal.Devices.Lights.BacklightServer DLL
|
| | windows.internal.devices.lights.configuration.dll | 10.0.26100.7920 | Windows.Internal.Devices.Lights.Configuration DLL
|
| | windows.internal.devices.sensors.dll | 10.0.26100.7920 | Windows Runtime Sensors (Internal) DLL
|
| | windows.internal.graphics.display.displaycolormanagement.dll | 10.0.26100.7705 | Windows Runtime Display Color Management DLL
|
| | windows.internal.graphics.display.displayenhancementmanagement.dll | 10.0.26100.7309 | Windows Runtime Display Enhancement Management DLL
|
| | windows.internal.hardwareconfirmator.dll | 10.0.26100.7920 | Hardware Confirmator
|
| | windows.internal.management.dll | 10.0.26100.7920 | Windows Managent Service DLL
|
| | windows.internal.openwithhost.dll | 10.0.26100.7920 | Open With
|
| | windows.internal.openwithhost_winui3.dll | 10.0.26100.7920 | Open With
|
| | windows.internal.platformextension.devicepickerexperience.dll | 10.0.26100.7309 | In-Proc WinRT server for Windows.Internal.PlatformExtension.DevicePickerExperience
|
| | windows.internal.platformextension.miracastbannerexperience.dll | 10.0.26100.7309 | In-Proc WinRT server for Windows.Internal.PlatformExtension.MiracastBannerExperience
|
| | windows.internal.predictionunit.dll | 10.0.26100.7309 | Prediction Unit
|
| | windows.internal.securitymitigationsbroker.dll | 10.0.26100.1150 | Windows Security Mitigations Broker DLL
|
| | windows.internal.shell.broker.dll | 10.0.26100.7920 | Windows Shell Broker
|
| | windows.internal.shell.clouddesktop.transitionscreen.dll | |
|
| | windows.internal.shell.xamlinputviewhost.dll | 10.0.26100.7920 | XAML Input View Host DLL
|
| | windows.internal.shellcommon.accountscontrolexperience.dll | 10.0.26100.7309 | Shell Position default shell contract handler
|
| | windows.internal.shellcommon.appresolvermodal.dll | 10.0.26100.7309 | App resolver default shell contract handler
|
| | windows.internal.shellcommon.broker.dll | 10.0.26100.7824 | Windows Shell Common Broker
|
| | windows.internal.shellcommon.dll | 10.0.26100.7920 | Windows.Internal.ShellCommon
|
| | windows.internal.shellcommon.filepickerexperiencemem.dll | 10.0.26100.7309 | File/Folder Open/Save Picker Experience contract handler
|
| | windows.internal.shellcommon.printexperience.dll | 10.0.26100.7309 | Print Experience default shell contract handler
|
| | windows.internal.shellcommon.shareexperience.dll | 10.0.26100.7920 | Share Experience
|
| | windows.internal.shellcommon.tokenbrokermodal.dll | 10.0.26100.7309 | Token broker default shell contract handler
|
| | windows.internal.signals.dll | 10.0.26100.7309 | Windows.Internal.Signals
|
| | windows.internal.system.userprofile.dll | 10.0.26100.7824 | Windows.Internal.System.UserProfile
|
| | windows.internal.taskbar.dll | 10.0.26100.7920 | TaskbarPinningWinRT PCShell
|
| | windows.internal.ui.bioenrollment.proxystub.dll | 10.0.26100.4202 | Bio Enrollment Model Proxy Stub
|
| | windows.internal.ui.dialogs.dll | 10.0.26100.7920 | Windows.Internal.UI.Dialogs.dll
|
| | windows.internal.ui.logon.proxystub.dll | 10.0.26100.4768 | Logon User Experience Proxy Stub
|
| | windows.internal.ui.shell.windowtabmanager.dll | 10.0.26100.7920 | Windows.Internal.UI.Shell.WindowTabManager
|
| | windows.internal.waasmedicdocked.dll | |
|
| | windows.management.enrollmentstatustracking.configprovider.dll | 10.0.26100.7705 | Implements settings for EnrollmentStatusPage policy tracking.
|
| | windows.management.inprocobjects.dll | |
|
| | windows.management.moderndeployment.configproviders.dll | 10.0.26100.7920 | Holds configuration settings for access through management.
|
| | windows.management.provisioning.proxystub.dll | 10.0.26100.3470 | Windows Management Provisioning Proxy Stub
|
| | windows.management.service.dll | 10.0.26100.7705 | Windows Management Service DLL
|
| | windows.management.update.dll | 10.0.26100.7705 | Windows.Management.Update DLL
|
| | windows.management.workplace.dll | 10.0.26100.7309 | Windows Runtime MdmPolicy DLL
|
| | windows.management.workplace.workplacesettings.dll | 10.0.26100.1 | Windows Runtime WorkplaceSettings DLL
|
| | windows.media.audio.dll | 10.0.26100.7309 | Windows Runtime Window Media Audio server DLL
|
| | windows.media.backgroundmediaplayback.dll | 10.0.26100.7920 | Windows Media BackgroundMediaPlayback DLL
|
| | windows.media.devices.dll | 10.0.26100.7920 | Windows Runtime media device server DLL
|
| | windows.media.dll | 10.0.26100.7920 | Windows Media Runtime DLL
|
| | windows.media.editing.dll | 10.0.26100.7705 | Windows Media Editing DLL
|
| | windows.media.faceanalysis.dll | 10.0.26100.5074 | Microsoft (R) Face Detection DLL
|
| | windows.media.import.dll | 10.0.26100.7309 | Windows Photo Import API (WinRT/COM)
|
| | windows.media.mediacontrol.dll | 10.0.26100.7705 | Windows Runtime MediaControl server DLL
|
| | windows.media.ocr.dll | 10.0.26100.7705 | Windows OCR Runtime DLL
|
| | windows.media.playback.backgroundmediaplayer.dll | 10.0.26100.7920 | Windows Media Playback BackgroundMediaPlayer DLL
|
| | windows.media.playback.mediaplayer.dll | 10.0.26100.7920 | Windows Media Playback MediaPlayer DLL
|
| | windows.media.playback.proxystub.dll | 10.0.26100.1150 | BackgroundMediaPlayer Proxy Stub DLL
|
| | windows.media.protection.playready.dll | 10.0.26100.8036 | Microsoft PlayReady Client Framework Dll
|
| | windows.media.renewal.dll | 10.0.26100.7309 | Windows Media Renewal DLL
|
| | windows.media.speech.dll | 10.0.26100.7920 | Windows Speech Runtime DLL
|
| | windows.media.speech.uxres.dll | 10.0.26100.1882 | Windows Media Speech UX Resources DLL
|
| | windows.media.streaming.dll | 10.0.26100.7309 | DLNA DLL
|
| | windows.media.streaming.ps.dll | 10.0.26100.1 | DLNA Proxy-Stub DLL
|
| | windows.networking.backgroundtransfer.backgroundmanagerpolicy.dll | 10.0.26100.7309 | Background Transfer Background Manager Policy DLL
|
| | windows.networking.backgroundtransfer.contentprefetchtask.dll | 10.0.26100.3323 | Windows Networking Background Transfer Content Prefetch task DLL
|
| | windows.networking.backgroundtransfer.dll | 10.0.26100.7309 | Windows.Networking.BackgroundTransfer DLL
|
| | windows.networking.connectivity.dll | 10.0.26100.7920 | Windows Networking Connectivity Runtime DLL
|
| | windows.networking.dll | 10.0.26100.7920 | Windows.Networking DLL
|
| | windows.networking.hostname.dll | 10.0.26100.7920 | Windows.Networking.HostName DLL
|
| | windows.networking.networkoperators.esim.dll | 10.0.26100.7309 | ESIM API
|
| | windows.networking.networkoperators.hotspotauthentication.dll | 10.0.26100.7309 | Microsoft Windows Hotspot Authentication API
|
| | windows.networking.proximity.dll | 10.0.26100.7019 | Windows Runtime Proximity API DLL
|
| | windows.networking.servicediscovery.dnssd.dll | 10.0.26100.1 | Windows.Networking.ServiceDiscovery.Dnssd DLL
|
| | windows.networking.sockets.pushenabledapplication.dll | 10.0.26100.7309 | Windows.Networking.Sockets.PushEnabledApplication DLL
|
| | windows.networking.ux.eaprequesthandler.dll | 10.0.26100.7920 | Windows Networking UX EAP Request Handler DLL
|
| | windows.networking.vpn.dll | 10.0.26100.7920 | Windows.Networking.Vpn DLL
|
| | windows.networking.xboxlive.proxystub.dll | 10.0.26100.1 | Windows.Networking.XboxLive Proxy Stub Dll
|
| | windows.payments.dll | 10.0.26100.7705 | Payment Windows Runtime DLL
|
| | windows.perception.stub.dll | 10.0.26100.7309 | Windows Perception Api Stub
|
| | windows.security.authentication.identity.provider.dll | 10.0.26100.7309 | Secondary Factor Authentication Windows Runtime DLL
|
| | windows.security.authentication.onlineid.dll | 10.0.26100.7920 | Windows Runtime OnlineId Authentication DLL
|
| | windows.security.authentication.web.core.dll | 10.0.26100.8036 | Token Broker WinRT API
|
| | windows.security.credentials.ui.credentialpicker.dll | 10.0.26100.7309 | WinRT Credential Picker Server
|
| | windows.security.credentials.ui.userconsentverifier.dll | 10.0.26100.7309 | Windows User Consent Verifier API
|
| | windows.security.integrity.dll | 10.0.26100.7309 | Windows S-Mode and App Control API Server
|
| | windows.services.targetedcontent.dll | 10.0.26100.7920 | Windows.Services.TargetedContent
|
| | windows.sharedpc.accountmanager.dll | 10.0.26100.7920 | SharedPC.AccountManager
|
| | windows.sharedpc.credentialprovider.dll | 10.0.26100.7309 | SharedPC.CredentialProvider
|
| | windows.shell.bluelightreduction.dll | 10.0.26100.7309 | Blue Light Reduction
|
| | windows.shell.servicehostbuilder.dll | 10.0.26100.7309 | Windows.Shell.ServiceHostBuilder
|
| | windows.shell.startlayoutpopulationevents.dll | 10.0.26100.1 | StartLayoutPopulation Instrumentation Description Resources
|
| | windows.staterepository.dll | 10.0.26100.7920 | Windows StateRepository API Server
|
| | windows.staterepositorybroker.dll | 10.0.26100.7920 | Windows StateRepository API Broker
|
| | windows.staterepositoryclient.dll | 10.0.26100.7920 | Windows StateRepository Client API
|
| | windows.staterepositorycore.dll | 10.0.26100.7920 | Windows StateRepository API Core
|
| | windows.staterepositoryps.dll | 10.0.26100.7920 | Windows StateRepository Proxy/Stub Server
|
| | windows.staterepositoryupgrade.dll | 10.0.26100.7920 | Windows StateRepository Upgrade
|
| | windows.storage.applicationdata.dll | 10.0.26100.7920 | Windows Application Data API Server
|
| | windows.storage.compression.dll | 5.0.1.1 | WinRT Compression
|
| | windows.storage.dll | 10.0.26100.8036 | Microsoft WinRT Storage API
|
| | windows.storage.onecore.dll | 10.0.26100.7309 | Microsoft Windows.Storage OneCore API
|
| | windows.storage.search.dll | 10.0.26100.7920 | Windows.Storage.Search
|
| | windows.system.diagnostics.dll | 10.0.26100.7309 | Windows System Diagnostics DLL
|
| | windows.system.diagnostics.telemetry.platformtelemetryclient.dll | 10.0.26100.7309 | Platform Telemetry Client DLL
|
| | windows.system.diagnostics.tracereporting.platformdiagnosticactions.dll | 10.0.26100.7309 | Platform Diagnostic Actions DLL
|
| | windows.system.launcher.dll | 10.0.26100.7920 | Windows.System.Launcher
|
| | windows.system.power.thermal.dll | 10.0.26100.7920 | MPTF User Space Client Interface
|
| | windows.system.profile.hardwareid.dll | 10.0.26100.8036 | Windows System Profile HardwareId DLL
|
| | windows.system.profile.platformdiagnosticsandusagedatasettings.dll | 10.0.26100.7309 | Platform Diagnostics and Usage Settings DLL
|
| | windows.system.profile.retailinfo.dll | 10.0.26100.7920 | Windows.System.Profile.RetailInfo Runtime DLL
|
| | windows.system.profile.systemid.dll | 10.0.26100.7309 | Windows System Profile SystemId DLL
|
| | windows.system.profile.systemmanufacturers.dll | 10.0.26100.7309 | Windows.System.Profile.SystemManufacturers
|
| | windows.system.remotedesktop.dll | 10.0.26100.7019 | Windows System RemoteDesktop Runtime DLL
|
| | windows.system.systemmanagement.dll | 10.0.26100.7309 | Windows Runtime SystemManagement DLL
|
| | windows.system.userdeviceassociation.dll | 10.0.26100.7309 | Windows System User Device Association API
|
| | windows.system.userprofile.diagnosticssettings.dll | 10.0.26100.7309 | Diagnostics Settings DLL
|
| | windows.ui.accessibility.dll | 10.0.26100.7705 | Windows.UI.Accessibility System DLL
|
| | windows.ui.appdefaults.dll | 10.0.26100.7920 | App Defaults UX
|
| | windows.ui.biofeedback.dll | 10.0.26100.7920 | Bio Feedback User Experience
|
| | windows.ui.blockedshutdown.dll | 10.0.26100.7920 | Blocked Shutdown User Experience
|
| | windows.ui.core.textinput.dll | 10.0.26100.7920 | Windows.UI.Core.TextInput dll
|
| | windows.ui.cred.dll | 10.0.26100.7920 | Credential Prompt User Experience
|
| | windows.ui.creddialogcontroller.dll | 10.0.26100.7920 | Credential UX Dialog Controller
|
| | windows.ui.dll | 10.0.26100.7920 | Windows Runtime UI Foundation DLL
|
| | windows.ui.fileexplorer.dll | 10.0.26100.7920 | Windows.UI.FileExplorer
|
| | windows.ui.immersive.dll | 10.0.26100.7920 | WINDOWS.UI.IMMERSIVE
|
| | windows.ui.input.inking.analysis.dll | |
|
| | windows.ui.input.inking.dll | 10.0.26100.7309 | WinRT Windows Inking DLL
|
| | windows.ui.logon.dll | 10.0.26100.7920 | Logon User Experience
|
| | windows.ui.networkuxcontroller.dll | 10.0.26100.7309 | Network UX Controller
|
| | windows.ui.picturepassword.dll | 10.0.26100.7309 | Picture Password UX
|
| | windows.ui.search.dll | 10.0.26100.7920 | Windows.UI.Search
|
| | windows.ui.shell.dll | 10.0.26100.7309 | Shell UI
|
| | windows.ui.shell.internal.adaptivecards.dll | 10.0.26100.7824 | Windows Adaptive Cards Internal API Server
|
| | windows.ui.storage.dll | 10.0.26100.7920 | Windows Storage UX
|
| | windows.ui.xaml.controls.dll | 10.0.26100.7309 | Windows.UI.Xaml.Controls
|
| | windows.ui.xaml.dll | 10.0.26100.7920 | Windows.UI.Xaml dll
|
| | windows.ui.xaml.inkcontrols.dll | 10.0.26100.3323 | Windows UI XAML InkControls API
|
| | windows.ui.xaml.maps.dll | 10.0.26100.7920 | Windows UI XAML Maps API
|
| | windows.ui.xaml.phone.dll | 10.0.26100.7705 | Windows UI XAML Phone API
|
| | windows.ui.xaml.resources.19h1.dll | 10.0.26100.1301 | Windows.UI.Xaml.Resources.19H1 dll
|
| | windows.ui.xaml.resources.21h1.dll | 10.0.26100.1301 | Windows.UI.Xaml.Resources.21H1 dll
|
| | windows.ui.xaml.resources.common.dll | 10.0.26100.1882 | Windows.UI.Xaml.Resources.Common.dll
|
| | windows.ui.xaml.resources.rs1.dll | 10.0.26100.1301 | Windows.UI.Xaml.Resources.RS1 dll
|
| | windows.ui.xaml.resources.rs2.dll | 10.0.26100.1301 | Windows.UI.Xaml.Resources.RS2 dll
|
| | windows.ui.xaml.resources.rs3.dll | 10.0.26100.1301 | Windows.UI.Xaml.Resources.RS3 dll
|
| | windows.ui.xaml.resources.rs4.dll | 10.0.26100.1301 | Windows.UI.Xaml.Resources.RS4 dll
|
| | windows.ui.xaml.resources.rs5.dll | 10.0.26100.1301 | Windows.UI.Xaml.Resources.RS5 dll
|
| | windows.ui.xaml.resources.th.dll | 10.0.26100.1301 | Windows.UI.Xaml.Resources.TH dll
|
| | windows.ui.xaml.resources.win81.dll | 10.0.26100.1301 | Windows.UI.Xaml.Resources.Win81 dll
|
| | windows.ui.xaml.resources.win8rtm.dll | 10.0.26100.1301 | Windows.UI.Xaml.Resources.Win8Rtm dll
|
| | windows.ui.xamlhost.dll | 10.0.26100.7920 | XAML Host
|
| | windows.warp.jitservice.dll | 10.0.26100.7309 | D3D10Warp JIT Service
|
| | windows.web.diagnostics.dll | 10.0.26100.7309 | Windows.Web.Diagnostics
|
| | windows.web.dll | 10.0.26100.5074 | Web Client DLL
|
| | windows.web.http.dll | 10.0.26100.7309 | Windows.Web.Http DLL
|
| | windowsbackupandrestorecsp.dll | 10.0.26100.7309 | WindowsBackupAndRestoreCSP
|
| | windowscodecs.dll | 10.0.26100.7920 | Microsoft Windows Codecs Library
|
| | windowscodecsext.dll | 10.0.26100.7705 | Microsoft Windows Codecs Extended Library
|
| | windowsdefaultheatprocessor.dll | 10.0.26100.7309 | Microsoft (R) Windows default HEAT processor
|
| | windowsinternal.composableshell.display.dll | 10.0.26100.7920 | WindowsInternal.ComposableShell.Display
|
| | windowsinternal.shell.compuiactivation.dll | 10.0.26100.7309 | ComponentUiLauncher Shellcommon DLL
|
| | windowslivelogin.dll | 10.0.26100.7309 | Microsoft® Account Login Helper
|
| | windowsmanagementservicewinrt.proxystub.dll | 10.0.26100.3624 | WindowsManagementServiceWinRt Proxy Stub
|
| | windowsperformancerecordercontrol.dll | 10.0.26100.7309 | Microsoft Windows Performance Recorder Control Library
|
| | windowsprotectedprintconfiguration.dll | 10.0.26100.7309 | Windows Protected Print Configuration
|
| | windowsudk.shellcommon.dll | 10.0.26100.8037 | Windows Undocked Dev Kit Shellcommon DLL
|
| | windowsudkservices.shellcommon.dll | 10.0.26100.8037 | Windows Undocked Dev Kit Services Shellcommon DLL
|
| | winethc.dll | 10.0.26100.7309 | WinInet Helper Class
|
| | winhttp.dll | 10.0.26100.7920 | Windows HTTP Services
|
| | winhttpcom.dll | 10.0.26100.7019 | Windows COM interface for WinHttp
|
| | winhvemulation.dll | 10.0.26100.7309 | Hyper-V Instruction Emulator User-Mode API Library
|
| | winhvplatform.dll | 10.0.26100.7920 | Hyper-V Hypervisor User-Mode API Library
|
| | wini3c.dll | 10.0.26100.7920 | WinI3C Driver User-mode Library
|
| | wininet.dll | 11.0.26100.7920 | Internet Extensions for Win32
|
| | wininetlui.dll | 10.0.26100.1882 | Provides legacy UI for wininet
|
| | wininitext.dll | 10.0.26100.7705 | WinInit Utility Extension DLL
|
| | winipcfile.dll | 10.0.26100.7309 | Microsoft Active Directory Rights Management Services File API
|
| | winipcsecproc.dll | 10.0.26100.7309 | Microsoft Active Directory Rights Management Services Desktop Security Processor
|
| | winipsec.dll | 10.0.26100.1 | Windows IPsec SPD Client DLL
|
| | winlangdb.dll | 10.0.26100.7309 | Windows Bcp47 Language Database
|
| | winlogonext.dll | 10.0.26100.7920 | WinLogon Utility Extension DLL
|
| | winmde.dll | 10.0.26100.7920 | WinMDE DLL
|
| | winml.dll | 10.0.26100.1150 | Windows Machine Learning Runtime
|
| | winmm.dll | 10.0.26100.7309 | MCI API DLL
|
| | winmmbase.dll | 10.0.26100.7920 | Base Multimedia Extension API DLL
|
| | winmsipc.dll | 10.0.26100.7309 | Microsoft Active Directory Rights Management Services Client
|
| | winmsoirmprotector.dll | 10.0.26100.1150 | Windows Office file format IRM Protector
|
| | winnlsres.dll | 10.0.26100.4484 | NLSBuild resource DLL
|
| | winnsi.dll | 10.0.26100.7920 | Network Store Information RPC interface
|
| | winopcirmprotector.dll | 10.0.26100.5074 | Windows Office file format IRM Protector
|
| | winreagent.dll | 10.0.26100.7920 | Windows Recovery Environment Agent
|
| | winrnr.dll | 10.0.26100.1882 | LDAP RnR Provider DLL
|
| | winrscmd.dll | 10.0.26100.7019 | remtsvc
|
| | winrsmgr.dll | 10.0.26100.7019 | WSMan Shell API
|
| | winrssrv.dll | 10.0.26100.7019 | winrssrv
|
| | winrttracing.dll | 10.0.26100.1150 | Windows Diagnostics Tracing
|
| | winsatapi.dll | 10.0.26100.7309 | Windows System Assessment Tool API
|
| | winscard.dll | 10.0.26100.7920 | Microsoft Smart Card API
|
| | winshfhc.dll | 10.0.26100.7309 | File Risk Estimation
|
| | winsku.dll | 10.0.26100.7705 | Windows SKU Library
|
| | winsqlite3.dll | 3.51.1.0 | SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.
|
| | winsrpc.dll | 10.0.26100.1 | WINS RPC LIBRARY
|
| | winsrv.dll | 10.0.26100.7019 | Multi-User Windows Server DLL
|
| | winsrvext.dll | 10.0.26100.7920 | Multi-User Windows Server Extension DLL
|
| | winsta.dll | 10.0.26100.8036 | Winstation Library
|
| | winsync.dll | 2007.94.26100.1 | Synchronization Framework
|
| | winsyncmetastore.dll | 2007.94.26100.1 | Windows Synchronization Metadata Store
|
| | winsyncproviders.dll | 2007.94.26100.1 | Windows Synchronization Provider Framework
|
| | wintrust.dll | 10.0.26100.8036 | Microsoft Trust Verification APIs
|
| | wintypes.dll | 10.0.26100.7920 | Windows Base Types DLL
|
| | winuicohabitation.dll | |
|
| | winusb.dll | 10.0.26100.1150 | Windows USB Driver User Library
|
| | wirednetworkcsp.dll | 10.0.26100.5074 | WiredNetworkCSP
|
| | wirelessnetworkpreferencecsp.dll | 10.0.26100.7920 | WirelessNetworkPreferenceCSP
|
| | wisp.dll | 10.0.26100.7920 | Microsoft Pen and Touch Input Component
|
| | witnesswmiv2provider.dll | 10.0.26100.1150 | Witness Service WMIv2 Provider
|
| | wkscli.dll | 10.0.26100.7019 | Workstation Service Client DLL
|
| | wkspbrokerax.dll | 10.0.26100.7309 | Microsoft Workspace Broker ActiveX Control
|
| | wksprtps.dll | 10.0.26100.1 | WorkspaceRuntime ProxyStub DLL
|
| | wkssvc.dll | 10.0.26100.7920 | Workstation Service DLL
|
| | wlanapi.dll | 10.0.26100.7920 | Windows WLAN AutoConfig Client Side API DLL
|
| | wlancfg.dll | 10.0.26100.7920 | Wlan Netsh Helper DLL
|
| | wlandlg.dll | 10.0.26100.5074 | Wireless Lan Dialog Wizards
|
| | wlangpui.dll | 10.0.26100.7920 | Wireless Network Policy Management Snap-in
|
| | wlanhlp.dll | 10.0.26100.7920 | Windows Wireless LAN 802.11 Client Side Helper API
|
| | wlanmediamanager.dll | 10.0.26100.7920 | Windows WLAN Media Manager DLL
|
| | wlanmsm.dll | 10.0.26100.7920 | Windows Wireless LAN 802.11 MSM DLL
|
| | wlanpref.dll | 10.0.26100.5074 | Wireless Preferred Networks
|
| | wlanradiomanager.dll | 10.0.26100.5074 | Wlan Radio Manager
|
| | wlansec.dll | 10.0.26100.7920 | Windows Wireless LAN 802.11 MSM Security Module DLL
|
| | wlansvc.dll | 10.0.26100.7920 | Windows WLAN AutoConfig Service DLL
|
| | wlansvcpal.dll | 10.0.26100.7920 | Windows WLAN AutoConfig Service PAL DLL
|
| | wlanui.dll | 10.0.26100.7309 | Wireless Profile UI
|
| | wlanutil.dll | 10.0.26100.1 | Windows Wireless LAN 802.11 Utility DLL
|
| | wldap32.dll | 10.0.26100.7920 | Win32 LDAP API DLL
|
| | wldp.dll | 10.0.26100.7920 | Windows Lockdown Policy
|
| | wlgpclnt.dll | 10.0.26100.7309 | 802.11 Group Policy Client
|
| | wlidcli.dll | 10.0.26100.7920 | Microsoft® Account Dynamic Link Library
|
| | wlidcredprov.dll | 10.0.26100.7824 | Microsoft® Account Credential Provider
|
| | wlidfdp.dll | 10.0.26100.7309 | Microsoft® Account Function Discovery Provider
|
| | wlidnsp.dll | 10.0.26100.7309 | Microsoft® Account Namespace Provider
|
| | wlidprov.dll | 10.0.26100.7309 | Microsoft® Account Provider
|
| | wlidres.dll | 10.0.26100.1 | Microsoft® Windows Live ID Resource
|
| | wlidsvc.dll | 10.0.26100.8036 | Microsoft® Account Service
|
| | wmadmod.dll | 10.0.26100.7019 | Windows Media Audio Decoder
|
| | wmadmoe.dll | 10.0.26100.7019 | Windows Media Audio 10 Encoder/Transcoder
|
| | wmalfxgfxdsp.dll | 10.0.26100.7920 | SysFx DSP
|
| | wmasf.dll | 12.0.26100.7920 | Windows Media ASF DLL
|
| | wmcodecdspps.dll | 10.0.26100.3624 | Windows Media CodecDSP Proxy Stub Dll
|
| | wmdmlog.dll | 12.0.26100.5074 | Windows Media Device Manager Logger
|
| | wmdmps.dll | 12.0.26100.1150 | Windows Media Device Manager Proxy Stub
|
| | wmdrmsdk.dll | 10.0.26100.1 | WMDRM backwards compatibility stub
|
| | wmerror.dll | 12.0.26100.4202 | Windows Media Error Definitions (English)
|
| | wmi.dll | 10.0.26100.1 | WMI DC and DP functionality
|
| | wmiclnt.dll | 10.0.26100.1150 | WMI Client API
|
| | wmidcom.dll | 10.0.26100.1 | WMI
|
| | wmidx.dll | 12.0.26100.7920 | Windows Media Indexer DLL
|
| | wmiprop.dll | 10.0.26100.1 | WDM Provider Dynamic Property Page CoInstaller
|
| | wmitomi.dll | 10.0.26100.1150 | CIM Provider Adapter
|
| | wmnetmgr.dll | 12.0.26100.7920 | Windows Media Network Plugin Manager DLL
|
| | wmp.dll | 12.0.26100.7920 | Windows Media Player
|
| | wmpdui.dll | 12.0.26100.4202 | Windows Media Player UI Engine
|
| | wmpdxm.dll | 12.0.26100.7705 | Windows Media Player Extension
|
| | wmpeffects.dll | 12.0.26100.7705 | Windows Media Player Effects
|
| | wmphoto.dll | 10.0.26100.7019 | Windows Media Photo Codec
|
| | wmploc.dll | 12.0.26100.1882 | Windows Media Player Legacy Resources
|
| | wmpps.dll | 12.0.26100.3624 | Windows Media Player Proxy Stub Dll
|
| | wmpshell.dll | 12.0.26100.7705 | Windows Media Player Legacy Launcher
|
| | wmsgapi.dll | 10.0.26100.8036 | WinLogon IPC Client
|
| | wmspdmod.dll | 10.0.26100.7019 | Windows Media Audio Voice Decoder
|
| | wmspdmoe.dll | 10.0.26100.7019 | Windows Media Audio Voice Encoder
|
| | wmvcore.dll | 12.0.26100.7920 | Windows Media Playback/Authoring DLL
|
| | wmvdecod.dll | 10.0.26100.7920 | Windows Media Video Decoder
|
| | wmvdspa.dll | 10.0.26100.5074 | Windows Media Video DSP Components - Advanced
|
| | wmvencod.dll | 10.0.26100.7309 | Windows Media Video 9 Encoder
|
| | wmvsdecd.dll | 10.0.26100.7019 | Windows Media Screen Decoder
|
| | wmvsencd.dll | 10.0.26100.7019 | Windows Media Screen Encoder
|
| | wmvxencd.dll | 10.0.26100.7309 | Windows Media Video Encoder
|
| | woftasks.dll | 10.0.26100.4484 | WIM Boot Tasks
|
| | wofutil.dll | 10.0.26100.1 | Windows Overlay File System Filter user mode API
|
| | wordbreakers.dll | 10.0.26100.7309 | "WordBreakers.DYNLINK"
|
| | workfolderscontrol.dll | 10.0.26100.7309 | Microsoft (C) Work Folders Control Panel
|
| | workfoldersgpext.dll | 10.0.26100.5074 | Microsoft (C) Work Folders Group Policy Client Extension
|
| | workfoldersres.dll | 6.2.9200.16384 | Work Folders Resources
|
| | workfoldersshell.dll | 10.0.26100.7309 | Microsoft (C) Work Folders Shell Extension
|
| | workfolderssvc.dll | 10.0.26100.7309 | Microsoft (C) Work Folders Service
|
| | wosc.dll | 10.0.26100.8037 | Windows OneSettings Client
|
| | wow64.dll | 10.0.26100.7623 | Win32 Emulation on NT64
|
| | wow64base.dll | 10.0.26100.7623 | Win32 Emulation on NT64
|
| | wow64con.dll | 10.0.26100.7920 | Wow64 Console and Win32 API Logging
|
| | wow64cpu.dll | 10.0.26100.7922 | AMD64 Wow64 CPU
|
| | wow64win.dll | 10.0.26100.7920 | Wow64 Console and Win32 API Logging
|
| | wpc.dll | 10.0.26100.7920 | WPC Settings Library
|
| | wpcapi.dll | 10.0.26100.7920 | WpcOtsApi.dll
|
| | wpcdesktopmonsvc.dll | 10.0.26100.7920 | WpcMonSvc.dll
|
| | wpcproxystubs.dll | 10.0.26100.7309 | Windows Parental Controls Proxy Stubs
|
| | wpcrefreshtask.dll | 10.0.26100.7920 | Family Safety Refresh Task
|
| | wpcwebfilter.dll | 10.0.26100.7920 | WpcWebFilter.dll
|
| | wpd_ci.dll | 10.0.26100.7920 | Driver Setup Class Installer for Windows Portable Devices
|
| | wpdbusenum.dll | 10.0.26100.7920 | Portable Device Enumerator
|
| | wpdshext.dll | 10.0.26100.7920 | Portable Devices Shell Extension
|
| | wpdshserviceobj.dll | 10.0.26100.5074 | Windows Portable Device Shell Service Object
|
| | wpdsp.dll | 10.0.26100.7309 | WMDM Service Provider for Windows Portable Devices
|
| | wpnapps.dll | 10.0.26100.7920 | Windows Push Notification Apps
|
| | wpnclient.dll | 10.0.26100.7920 | Windows Push Notifications Client
|
| | wpncore.dll | 10.0.26100.7920 | Windows Push Notification Core
|
| | wpninprc.dll | 10.0.26100.7309 | Windows Push Notification InProc
|
| | wpnprv.dll | 10.0.26100.7920 | Windows Push Notification Platform Connection Provider
|
| | wpnservice.dll | 10.0.26100.7309 | Windows Push Notification System Service
|
| | wpnsruprov.dll | 10.0.26100.7705 | SRUM provider for WPN
|
| | wpnuserservice.dll | 10.0.26100.7309 | Windows Push Notification User Service
|
| | wpportinglibrary.dll | 10.0.26100.1 | <d> DLL
|
| | wpprecorderum.dll | 10.0.26100.7309 | "WppRecorderUM.DYNLINK"
|
| | wptaskscheduler.dll | 10.0.26100.3323 | WP Task Scheduler DLL
|
| | wpx.dll | 10.0.26100.7623 | Windows Provisioning XML
|
| | ws2_32.dll | 10.0.26100.7623 | Windows Socket 2.0 32-Bit DLL
|
| | ws2help.dll | 10.0.26100.7623 | Windows Socket 2.0 Helper for Windows NT
|
| | wsaifabrichost.dll | 10.0.26100.7920 | WSAIFabricSvc
|
| | wscapi.dll | 10.0.26100.7309 | Windows Security Center API
|
| | wscinterop.dll | 10.0.26100.3323 | Windows Health Center WSC Interop
|
| | wscisvif.dll | 10.0.26100.1882 | Windows Security Center ISV API
|
| | wsclient.dll | 10.0.26100.1 | Microsoft Store Licensing Client
|
| | wscproxystub.dll | 10.0.26100.1882 | Windows Security Center ISV Proxy Stub
|
| | wscsvc.dll | 10.0.26100.7309 | Windows Security Center Service
|
| | wsdapi.dll | 10.0.26100.7920 | Web Services for Devices API DLL
|
| | wsdchngr.dll | 10.0.26100.7705 | WSD Challenge Component
|
| | wsdprintproxy.dll | 10.0.26100.5074 | Function Discovery Printer Proxy Dll
|
| | wsdproviderutil.dll | 10.0.26100.5074 | WsdProviderUtil dll
|
| | wsdscanproxy.dll | 10.0.26100.5074 | Function Discovery WSD Scanner Proxy Dll
|
| | wsecedit.dll | 10.0.26100.7920 | Security Configuration UI Module
|
| | wsepno.dll | 7.0.26100.7309 | Profile notification support for Windows Search Service
|
| | wshbth.dll | 10.0.26100.5074 | Windows Sockets Helper DLL
|
| | wshcon.dll | 10.0.26100.7920 | Microsoft ® Windows Script Controller
|
| | wshelper.dll | 10.0.26100.4484 | Winsock Net shell helper DLL for winsock
|
| | wshext.dll | 10.0.26100.4768 | Microsoft ® Shell Extension for Windows Script Host
|
| | wshhyperv.dll | 10.0.26100.1 | Hyper-V Winsock2 Helper DLL
|
| | wship6.dll | 10.0.26100.1 | Winsock2 Helper DLL (TL/IPv6)
|
| | wshqos.dll | 10.0.26100.1150 | QoS Winsock2 Helper DLL
|
| | wshrm.dll | 10.0.26100.4202 | Windows Sockets Helper DLL for PGM
|
| | wshtcpip.dll | 10.0.26100.1 | Winsock2 Helper DLL (TL/IPv4)
|
| | wshunix.dll | 10.0.26100.1 | AF_UNIX Winsock2 Helper DLL
|
| | wslapi.dll | 10.0.26100.7309 | Windows Subsystem for Linux API
|
| | wsmagent.dll | 10.0.26100.7309 | WinRM Agent
|
| | wsmanmigrationplugin.dll | 10.0.26100.7309 | WinRM Migration Plugin
|
| | wsmauto.dll | 10.0.26100.7309 | WSMAN Automation
|
| | wsmplpxy.dll | 10.0.26100.7309 | wsmplpxy
|
| | wsmres.dll | 10.0.26100.7309 | WSMan Resource DLL
|
| | wsmsvc.dll | 10.0.26100.7920 | WSMan Service
|
| | wsmwmipl.dll | 10.0.26100.7309 | WSMAN WMI Provider
|
| | wsnmp32.dll | 10.0.26100.1150 | Microsoft WinSNMP v2.0 Manager API
|
| | wsock32.dll | 10.0.26100.1 | Windows Socket 32-Bit DLL
|
| | wsp_fs.dll | 10.0.26100.7920 | Windows Storage Provider for FileShare management
|
| | wsp_health.dll | 10.0.26100.7920 | Windows Storage Provider for Health Agent API
|
| | wsp_sr.dll | 10.0.26100.1882 | Windows Storage Provider for Storage Replication management
|
| | wsplib.dll | 10.0.26100.8036 | WSP decode library
|
| | wtdccm.dll | |
|
| | wtdhost.dll | 10.0.26100.1882 | WTD Framework Host Client
|
| | wtdsensor.dll | 10.0.26100.1150 | WTD Framework Sensor Client
|
| | wtsapi32.dll | 10.0.26100.7920 | Windows Remote Desktop Session Host Server SDK APIs
|
| | wuapi.dll | 1451.2601.23012.0 | Windows Update Client API
|
| | wuaueng.dll | 1451.2601.23012.0 | Windows Update Agent
|
| | wuceffects.dll | 10.0.26100.7920 | Microsoft Composition Effects
|
| | wudfcoinstaller.dll | 10.0.26100.7309 | Windows Driver Foundation - User-mode Platform Device Co-Installer
|
| | wudfplatform.dll | 10.0.26100.7705 | Windows Driver Foundation - User-mode Platform Library
|
| | wudfsmcclassext.dll | 10.0.26100.7019 | Smart Card Class Extension
|
| | wudfx.dll | 10.0.26100.7309 | WDF:UMDF Framework Library
|
| | wudfx02000.dll | 10.0.26100.7920 | WDF:UMDF Framework Library
|
| | wudriver.dll | 10.0.26100.7920 | Windows Update WUDriver Stub
|
| | wups.dll | 1451.2601.23012.0 | Windows Update client proxy stub
|
| | wups2.dll | 1451.2601.23012.0 | Windows Update client proxy stub 2
|
| | wusys.dll | 10.0.26100.7920 | Windows Update System Library
|
| | wvc.dll | 1.0.0.1 | Windows Visual Components
|
| | wwaapi.dll | 10.0.26100.7309 | Microsoft Web Application Host API library
|
| | wwaext.dll | 10.0.26100.7309 | Microsoft Web Application Host Extension library
|
| | wwanapi.dll | 10.0.26100.7920 | Mbnapi
|
| | wwancfg.dll | 10.0.26100.7920 | MBN Netsh Helper DLL
|
| | wwanprfl.dll | 10.0.26100.7309 | WWAN Profile Operations Binary
|
| | wwanprotdim.dll | 10.0.26100.7920 | WWAN Device Interface Module
|
| | wwanradiomanager.dll | 10.0.26100.7309 | Wwan Radio Manager
|
| | wwansvc.dll | 10.0.26100.7920 | WWAN Auto Config Service
|
| | wwapi.dll | 10.0.26100.7920 | WWAN API
|
| | xamltilerender.dll | 10.0.26100.7824 | "XamlTileRender.DYNLINK"
|
| | xaudio2_8.dll | 10.0.26100.1 | XAudio2 Game Audio API
|
| | xaudio2_9.dll | 10.0.26100.7019 | XAudio2 Game Audio API
|
| | xblauthmanager.dll | 10.0.26100.7920 | Xbox Live Auth Manager
|
| | xblauthmanagerproxy.dll | 10.0.26100.7309 | XblAuthManagerProxy
|
| | xblauthtokenbrokerext.dll | 10.0.26100.7309 | Xbox Live Token Broker Extension
|
| | xblgamesave.dll | 10.0.26100.7920 | Xbox Live Game Save Service
|
| | xblgamesaveext.dll | 10.0.26100.7309 | Microsoft XblGameSave Extension API
|
| | xblgamesaveproxy.dll | 10.0.26100.4202 | Xbox Live Game Save Service Proxies and Stubs
|
| | xboxgipradiomanager.dll | 10.0.26100.5074 | Xbox GIP Radio Manager
|
| | xboxgipsvc.dll | 10.0.26100.7309 | Xbox Gip Management Service
|
| | xboxgipsynthetic.dll | |
|
| | xboxnetapisvc.dll | 10.0.26100.5074 | Xbox Live Networking Service
|
| | xinput1_4.dll | 10.0.26100.7920 | Microsoft Common Controller API
|
| | xinput9_1_0.dll | 10.0.26100.1 | XNA Common Controller
|
| | xinputuap.dll | 10.0.26100.7309 | Microsoft Common Controller API
|
| | xmlfilter.dll | 2008.0.26100.7309 | XML Filter
|
| | xmllite.dll | 10.0.26100.7309 | Microsoft XmlLite Library
|
| | xmlprovi.dll | 10.0.26100.5074 | Network Provisioning Service Client API
|
| | xolehlp.dll | 2001.12.10941.16384 | Microsoft Distributed Transaction Coordinator Helper APIs DLL
|
| | xpsdocumenttargetprint.dll | 10.0.26100.7920 | XPS DocumentTargetPrint DLL
|
| | xpsgdiconverter.dll | 10.0.26100.7309 | XPS to GDI Converter
|
| | xpsprint.dll | 10.0.26100.7920 | XPS Printing DLL
|
| | xpspushlayer.dll | 10.0.26100.7309 | Xps Push Layer Component
|
| | xpsrasterservice.dll | 10.0.26100.7309 | XPS Rasterization Service Component
|
| | xpsservices.dll | 10.0.26100.7920 | Xps Object Model in memory creation and deserialization
|
| | xpstopclmconverter.dll | 10.0.26100.7705 | XPS to PCLm Converter
|
| | xpstopwgrconverter.dll | 10.0.26100.7309 | XPS to PWGR Converter
|
| | xpstotiffconverter.dll | 10.0.26100.7309 | XPS To TIFF Converter
|
| | xwizards.dll | 10.0.26100.5074 | Extensible Wizards Manager Module
|
| | xwreg.dll | 10.0.26100.1882 | Extensible Wizard Registration Manager Module
|
| | xwtpdui.dll | 10.0.26100.1882 | Extensible Wizard Type Plugin for DUI
|
| | xwtpw32.dll | 10.0.26100.1882 | Extensible Wizard Type Plugin for Win32
|
| | zipcontainer.dll | 10.0.26100.7019 | Zip Container DLL
|
| | zipfldr.dll | 10.0.26100.7920 | Compressed (zipped) Folders
|
| | ztrace_maps.dll | 10.0.26100.1882 | ZTrace Event Resources
|
| | | | | | | | |
|
| | Log Name | Event Type | Category | Generated On | User | Source | Description
|
| | Application | Error | None | 2026-07-13 17:13:00 | SYSTEM | CertEnroll | 86: SCEP Certificate enrollment initialization for Local system via https://IFX-KeyId-6fc8a3609be1cef8b68480e1fb2dde5e9a961d9f.microsoftaik.azure.net/templates/Aik/scep failed: GetCACaps Method: GET(47ms) Stage: GetCACaps The server name or address could not be resolved 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
|
| | Application | Error | None | 2026-07-13 17:13:01 | SYSTEM | CertEnroll | 86: SCEP Certificate enrollment initialization for \MINWINPC$ via https://IFX-KeyId-6fc8a3609be1cef8b68480e1fb2dde5e9a961d9f.microsoftaik.azure.net/templates/Aik/scep failed: GetCACaps Method: GET(407ms) Stage: GetCACaps The server name or address could not be resolved 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
|
| | Application | Warning | 1 | 2026-07-13 17:13:57 | | Windows Search Service | 1008: The Windows Search Service is starting up and attempting to remove the old search index {Reason: Full Index Reset}.
|
| | Application | Error | None | 2026-07-13 17:14:00 | SYSTEM | CertEnroll | 86: SCEP Certificate enrollment initialization for Local system via https://IFX-KeyId-6fc8a3609be1cef8b68480e1fb2dde5e9a961d9f.microsoftaik.azure.net/templates/Aik/scep failed: GetCACaps Method: GET(16ms) Stage: GetCACaps The server name or address could not be resolved 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
|
| | Application | Error | None | 2026-07-13 17:14:00 | SYSTEM | CertEnroll | 86: SCEP Certificate enrollment initialization for WORKGROUP\WIN-SLRHEC6PMT7$ via https://IFX-KeyId-6fc8a3609be1cef8b68480e1fb2dde5e9a961d9f.microsoftaik.azure.net/templates/Aik/scep failed: GetCACaps Method: GET(359ms) Stage: GetCACaps The server name or address could not be resolved 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
|
| | Application | Warning | None | 2026-07-13 17:14:08 | 1332 | Microsoft-Windows-AppModel-State | 23: Data error (cyclic redundancy check).
|
| | Application | Warning | None | 2026-07-13 17:14:08 | 1332 | Microsoft-Windows-AppModel-State | 24: The program issued a command but the command length is incorrect.
|
| | Application | Warning | None | 2026-07-13 17:14:08 | 1332 | Microsoft-Windows-AppModel-State | 23: Data error (cyclic redundancy check).
|
| | Application | Warning | None | 2026-07-13 17:14:08 | 1332 | Microsoft-Windows-AppModel-State | 23: Data error (cyclic redundancy check).
|
| | Application | Warning | None | 2026-07-13 17:14:08 | 1332 | Microsoft-Windows-AppModel-State | 24: The program issued a command but the command length is incorrect.
|
| | Application | Warning | None | 2026-07-13 17:14:08 | 1332 | Microsoft-Windows-AppModel-State | 24: The program issued a command but the command length is incorrect.
|
| | Application | Warning | None | 2026-07-13 17:14:26 | 1332 | Microsoft-Windows-AppModel-State | 23: Data error (cyclic redundancy check).
|
| | Application | Warning | None | 2026-07-13 17:14:26 | 1332 | Microsoft-Windows-AppModel-State | 24: The program issued a command but the command length is incorrect.
|
| | Application | Error | None | 2026-07-13 17:15:59 | | SecurityCenter | 16: Error while updating Windows Defender status to SECURITY_PRODUCT_STATE_ON.
|
| | Application | Warning | None | 2026-07-13 17:16:17 | Marius | Microsoft-Windows-AppModel-State | 23: Data error (cyclic redundancy check).
|
| | Application | Warning | None | 2026-07-13 17:16:17 | Marius | Microsoft-Windows-AppModel-State | 24: The program issued a command but the command length is incorrect.
|
| | Application | Warning | None | 2026-07-13 17:16:18 | Marius | Microsoft-Windows-AppModel-State | 23: Data error (cyclic redundancy check).
|
| | Application | Warning | None | 2026-07-13 17:16:18 | Marius | Microsoft-Windows-AppModel-State | 24: The program issued a command but the command length is incorrect.
|
| | Application | Warning | None | 2026-07-13 17:16:18 | Marius | Microsoft-Windows-AppModel-State | 23: Data error (cyclic redundancy check).
|
| | Application | Warning | None | 2026-07-13 17:16:18 | Marius | Microsoft-Windows-AppModel-State | 23: Data error (cyclic redundancy check).
|
| | Application | Warning | None | 2026-07-13 17:16:18 | Marius | Microsoft-Windows-AppModel-State | 24: The program issued a command but the command length is incorrect.
|
| | Application | Warning | None | 2026-07-13 17:16:18 | Marius | Microsoft-Windows-AppModel-State | 23: Data error (cyclic redundancy check).
|
| | Application | Warning | None | 2026-07-13 17:16:18 | Marius | Microsoft-Windows-AppModel-State | 24: The program issued a command but the command length is incorrect.
|
| | Application | Warning | None | 2026-07-13 17:16:18 | Marius | Microsoft-Windows-AppModel-State | 24: The program issued a command but the command length is incorrect.
|
| | Application | Error | None | 2026-07-13 17:16:23 | | Software Protection Platform Service | 8200: License acquisition failure details. hr=0x80072EE7
|
| | Application | Error | None | 2026-07-13 17:16:23 | | Software Protection Platform Service | 1014: Acquisition of End User License failed. hr=0x80072EE7 Sku Id=1d873132-f09f-4eb2-bf5a-2e4fb48935e8
|
| | Application | Error | None | 2026-07-13 17:16:23 | | Software Protection Platform Service | 8198: License Activation (slui.exe) failed with the following error code: hr=0x80072EE7 Command-line arguments: RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=1d873132-f09f-4eb2-bf5a-2e4fb48935e8;NotificationInterval=1440;Trigger=UserLogon;SessionId=2
|
| | Application | Error | None | 2026-07-13 17:29:11 | | Software Protection Platform Service | 8200: License acquisition failure details. hr=0x80072EE7
|
| | Application | Error | None | 2026-07-13 17:29:11 | | Software Protection Platform Service | 1014: Acquisition of End User License failed. hr=0x80072EE7 Sku Id=1d873132-f09f-4eb2-bf5a-2e4fb48935e8
|
| | Application | Error | None | 2026-07-13 17:29:11 | | Software Protection Platform Service | 8198: License Activation (slui.exe) failed with the following error code: hr=0x80072EE7 Command-line arguments: RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=1d873132-f09f-4eb2-bf5a-2e4fb48935e8;NotificationInterval=1440;Trigger=UserLogon;SessionId=1
|
| | Application | Error | None | 2026-07-13 17:29:19 | SYSTEM | CertEnroll | 86: SCEP Certificate enrollment initialization for Local system via https://IFX-KeyId-6fc8a3609be1cef8b68480e1fb2dde5e9a961d9f.microsoftaik.azure.net/templates/Aik/scep failed: GetCACaps Method: GET(0ms) Stage: GetCACaps The server name or address could not be resolved 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
|
| | Application | Error | None | 2026-07-13 17:29:19 | SYSTEM | CertEnroll | 86: SCEP Certificate enrollment initialization for WORKGROUP\DESKTOP-M1V6K8T$ via https://IFX-KeyId-6fc8a3609be1cef8b68480e1fb2dde5e9a961d9f.microsoftaik.azure.net/templates/Aik/scep failed: GetCACaps Method: GET(594ms) Stage: GetCACaps The server name or address could not be resolved 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
|
| | Application | Warning | None | 2026-07-13 17:29:25 | Marius | Microsoft-Windows-AppModel-State | 23: Data error (cyclic redundancy check).
|
| | Application | Warning | None | 2026-07-13 17:29:25 | Marius | Microsoft-Windows-AppModel-State | 24: The program issued a command but the command length is incorrect.
|
| | Security | Audit Success | 13312 | 2026-07-13 17:12:21 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0xc8 New Process Name: R Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x4 Creator Process Name: Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13312 | 2026-07-13 17:12:21 | | Microsoft-Windows-Security-Auditing | 4696: A primary token was assigned to process. Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Process Information: Process ID: 0x4 Process Name: Target Process: Target Process ID: 0xc8 Target Process Name: Registry New Token Information: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x3e7
|
| | Security | Audit Success | 13312 | 2026-07-13 17:12:21 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x27c New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x4 Creator Process Name: Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13312 | 2026-07-13 17:12:21 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x290 New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x27c Creator Process Name: C Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13573 | 2026-07-13 17:12:21 | | Microsoft-Windows-Security-Auditing | 4826: Boot Configuration Data loaded. Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 General Settings: Load Options: - Advanced Options: %%1843 Configuration Access Policy: %%1846 System Event Logging: %%1843 Kernel Debugging: %%1843 VSM Launch Type: %%1848 Signature Settings: Test Signing: %%1843 Flight Signing: %%1843 Disable Integrity Checks: %%1843 HyperVisor Settings: HyperVisor Load Options: - HyperVisor Launch Type: %%1848 HyperVisor Debugging: %%1843
|
| | Security | Audit Success | 13312 | 2026-07-13 17:12:22 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x30c New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x27c Creator Process Name: C Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 12288 | 2026-07-13 17:12:23 | | Microsoft-Windows-Security-Auditing | 4608: Windows is starting up. This event is logged when LSASS.EXE starts and the auditing subsystem is initialized.
|
| | Security | Audit Success | 12290 | 2026-07-13 17:12:23 | | Microsoft-Windows-Security-Auditing | 6417: The FIPS mode crypto selftests succeeded. Process ID: 0x2dc Process Name: C:\Windows\System32\lsass.exe
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:23 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Logon Information: Logon Type: 0 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: - New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x4 Process Name: Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: - Authentication Package: - Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 13312 | 2026-07-13 17:12:23 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x374 New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x324 Creator Process Name: C Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13312 | 2026-07-13 17:12:23 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x380 New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x36c Creator Process Name: C Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13312 | 2026-07-13 17:12:23 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x3d8 New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x36c Creator Process Name: C Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13312 | 2026-07-13 17:12:23 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x2d8 New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x374 Creator Process Name: C Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13312 | 2026-07-13 17:12:23 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x2dc New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x374 Creator Process Name: C Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13312 | 2026-07-13 17:12:23 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x324 New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x27c Creator Process Name: C Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13312 | 2026-07-13 17:12:23 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x32c New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x324 Creator Process Name: C Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13312 | 2026-07-13 17:12:23 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x36c New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x27c Creator Process Name: C Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4648: A logon was attempted using explicit credentials. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Account Whose Credentials Were Used: Account Name: UMFD-0 Account Domain: Font Driver Host Logon GUID: {00000000-0000-0000-0000-000000000000} Target Server: Target Server Name: localhost Additional Information: localhost Process Information: Process ID: 0x374 Process Name: C:\Windows\System32\wininit.exe Network Information: Network Address: - Port: - This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 2 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1842 Elevated Token: %%1843 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-96-0-0 Account Name: UMFD-0 Account Domain: Font Driver Host Logon ID: 0x598eb Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x374 Process Name: C:\Windows\System32\wininit.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4648: A logon was attempted using explicit credentials. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Account Whose Credentials Were Used: Account Name: UMFD-1 Account Domain: Font Driver Host Logon GUID: {00000000-0000-0000-0000-000000000000} Target Server: Target Server Name: localhost Additional Information: localhost Process Information: Process ID: 0x3d8 Process Name: C:\Windows\System32\winlogon.exe Network Information: Network Address: - Port: - This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 2 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1842 Elevated Token: %%1843 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-96-0-1 Account Name: UMFD-1 Account Domain: Font Driver Host Logon ID: 0x598e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3d8 Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-20 Account Name: NETWORK SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e4 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4648: A logon was attempted using explicit credentials. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Account Whose Credentials Were Used: Account Name: DWM-1 Account Domain: Window Manager Logon GUID: {00000000-0000-0000-0000-000000000000} Target Server: Target Server Name: localhost Additional Information: localhost Process Information: Process ID: 0x3d8 Process Name: C:\Windows\System32\winlogon.exe Network Information: Network Address: - Port: - This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 2 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1842 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-90-0-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0x62966 Linked Logon ID: 0x6298c Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3d8 Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 2 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1842 Elevated Token: %%1843 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-90-0-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0x6298c Linked Logon ID: 0x62966 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3d8 Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-20 Account Name: NETWORK SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e4 Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege SeImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege SeImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-90-0-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0x62966 Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege SeImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-90-0-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0x6298c Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 13568 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4902: The Per-user audit policy table was created. Number of Elements: 0 Policy ID: 0x5911a
|
| | Security | Audit Success | 13569 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4717: System security access was granted to an account. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Account Modified: Account Name: S-1-5-80-3169285310-278349998-1452333686-3865143136-4212226833 Access Granted: Access Right: SeServiceLogonRight
|
| | Security | Audit Success | 13824 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4720: A user account was created. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 New Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-504 Account Name: WDAGUtilityAccount Account Domain: MINWINPC Attributes: SAM Account Name: WDAGUtilityAccount Display Name: %%1793 User Principal Name: - Home Directory: %%1793 Home Drive: %%1793 Script Path: %%1793 Profile Path: %%1793 User Workstations: %%1793 Password Last Set: %%1794 Account Expires: %%1794 Primary Group ID: 513 Allowed To Delegate To: - Old UAC Value: 0x0 New UAC Value: 0x15 User Account Control: %%2080 %%2082 %%2084 User Parameters: %%1793 SID History: - Logon Hours: %%1797 Additional Information: Privileges -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4738: A user account was changed. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-504 Account Name: WDAGUtilityAccount Account Domain: MINWINPC Changed Attributes: SAM Account Name: - Display Name: - User Principal Name: - Home Directory: - Home Drive: - Script Path: - Profile Path: - User Workstations: - Password Last Set: - Account Expires: - Primary Group ID: - AllowedToDelegateTo: - Old UAC Value: 0x15 New UAC Value: 0x11 User Account Control: %%2050 User Parameters: - SID History: - Logon Hours: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4738: A user account was changed. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-504 Account Name: WDAGUtilityAccount Account Domain: MINWINPC Changed Attributes: SAM Account Name: - Display Name: - User Principal Name: - Home Directory: - Home Drive: - Script Path: - Profile Path: - User Workstations: - Password Last Set: - Account Expires: - Primary Group ID: - AllowedToDelegateTo: - Old UAC Value: - New UAC Value: - User Account Control: - User Parameters: - SID History: - Logon Hours: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4738: A user account was changed. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-504 Account Name: WDAGUtilityAccount Account Domain: MINWINPC Changed Attributes: SAM Account Name: - Display Name: - User Principal Name: - Home Directory: - Home Drive: - Script Path: - Profile Path: - User Workstations: - Password Last Set: - Account Expires: - Primary Group ID: - AllowedToDelegateTo: - Old UAC Value: - New UAC Value: - User Account Control: - User Parameters: - SID History: - Logon Hours: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4731: A security-enabled local group was created. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 New Group: Security ID: S-1-5-32-558 Group Name: Performance Monitor Users Group Domain: Builtin Attributes: SAM Account Name: Performance Monitor Users SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Group: Security ID: S-1-5-32-558 Group Name: Performance Monitor Users Group Domain: Builtin Changed Attributes: SAM Account Name: - SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4731: A security-enabled local group was created. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 New Group: Security ID: S-1-5-32-559 Group Name: Performance Log Users Group Domain: Builtin Attributes: SAM Account Name: Performance Log Users SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Group: Security ID: S-1-5-32-559 Group Name: Performance Log Users Group Domain: Builtin Changed Attributes: SAM Account Name: - SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4731: A security-enabled local group was created. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 New Group: Security ID: S-1-5-32-562 Group Name: Distributed COM Users Group Domain: Builtin Attributes: SAM Account Name: Distributed COM Users SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Group: Security ID: S-1-5-32-562 Group Name: Distributed COM Users Group Domain: Builtin Changed Attributes: SAM Account Name: - SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4731: A security-enabled local group was created. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 New Group: Security ID: S-1-5-32-568 Group Name: IIS_IUSRS Group Domain: Builtin Attributes: SAM Account Name: IIS_IUSRS SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Group: Security ID: S-1-5-32-568 Group Name: IIS_IUSRS Group Domain: Builtin Changed Attributes: SAM Account Name: - SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4732: A member was added to a security-enabled local group. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Member: Security ID: S-1-5-17 Account Name: - Group: Security ID: S-1-5-32-568 Group Name: IIS_IUSRS Group Domain: Builtin Additional Information: Privileges: - Expiration time: (null)
|
| | Security | Audit Success | 13826 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4731: A security-enabled local group was created. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 New Group: Security ID: S-1-5-32-573 Group Name: Event Log Readers Group Domain: Builtin Attributes: SAM Account Name: Event Log Readers SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Group: Security ID: S-1-5-32-573 Group Name: Event Log Readers Group Domain: Builtin Changed Attributes: SAM Account Name: - SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4731: A security-enabled local group was created. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 New Group: Security ID: S-1-5-32-580 Group Name: Remote Management Users Group Domain: Builtin Attributes: SAM Account Name: Remote Management Users SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Group: Security ID: S-1-5-32-580 Group Name: Remote Management Users Group Domain: Builtin Changed Attributes: SAM Account Name: - SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4728: A member was added to a security-enabled global group. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Member: Security ID: S-1-5-21-3469770775-847581034-1203560767-504 Account Name: - Group: Security ID: S-1-5-21-3469770775-847581034-1203560767-513 Group Name: None Group Domain: MINWINPC Additional Information: Privileges: - Expiration time: (null)
|
| | Security | Audit Success | 13826 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4731: A security-enabled local group was created. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 New Group: Security ID: S-1-5-32-585 Group Name: OpenSSH Users Group Domain: Builtin Attributes: SAM Account Name: OpenSSH Users SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Group: Security ID: S-1-5-32-585 Group Name: OpenSSH Users Group Domain: Builtin Changed Attributes: SAM Account Name: - SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4731: A security-enabled local group was created. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 New Group: Security ID: S-1-5-32-578 Group Name: Hyper-V Administrators Group Domain: Builtin Attributes: SAM Account Name: Hyper-V Administrators SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:12:24 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Group: Security ID: S-1-5-32-578 Group Name: Hyper-V Administrators Group Domain: Builtin Changed Attributes: SAM Account Name: - SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:29 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:29 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:30 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:30 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:33 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:33 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12292 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 5033: The Windows Firewall Driver started successfully.
|
| | Security | Audit Success | 12292 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 5024: The Windows Firewall service started successfully.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 13569 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4718: System security access was removed from an account. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Account Modified: Account Name: S-1-5-32-546 Access Removed: Access Right: SeInteractiveLogonRight
|
| | Security | Audit Success | 13569 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4718: System security access was removed from an account. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Account Modified: Account Name: S-1-5-32-581 Access Removed: Access Right: SeInteractiveLogonRight
|
| | Security | Audit Success | 13569 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4718: System security access was removed from an account. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Account Modified: Account Name: S-1-5-32-581 Access Removed: Access Right: SeNetworkLogonRight
|
| | Security | Audit Success | 13569 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4718: System security access was removed from an account. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Account Modified: Account Name: S-1-5-32-583 Access Removed: Access Right: SeInteractiveLogonRight
|
| | Security | Audit Success | 13569 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4718: System security access was removed from an account. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Account Modified: Account Name: S-1-5-32-583 Access Removed: Access Right: SeNetworkLogonRight
|
| | Security | Audit Success | 13569 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4718: System security access was removed from an account. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Account Modified: Account Name: S-1-5-80-3169285310-278349998-1452333686-3865143136-4212226833 Access Removed: Access Right: SeServiceLogonRight
|
| | Security | Audit Success | 13569 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4717: System security access was granted to an account. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Account Modified: Account Name: S-1-5-32-544 Access Granted: Access Right: SeRemoteInteractiveLogonRight
|
| | Security | Audit Success | 13569 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4717: System security access was granted to an account. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Account Modified: Account Name: S-1-5-32-551 Access Granted: Access Right: SeNetworkLogonRight
|
| | Security | Audit Success | 13569 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4717: System security access was granted to an account. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Account Modified: Account Name: S-1-5-32-551 Access Granted: Access Right: SeBatchLogonRight
|
| | Security | Audit Success | 13569 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4717: System security access was granted to an account. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Account Modified: Account Name: S-1-5-32-559 Access Granted: Access Right: SeBatchLogonRight
|
| | Security | Audit Success | 13569 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4718: System security access was removed from an account. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Account Modified: Account Name: S-1-1-0 Access Removed: Access Right: SeInteractiveLogonRight
|
| | Security | Audit Success | 13569 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4718: System security access was removed from an account. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Account Modified: Account Name: S-1-1-0 Access Removed: Access Right: SeRemoteInteractiveLogonRight
|
| | Security | Audit Success | 13569 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4717: System security access was granted to an account. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Account Modified: Account Name: S-1-5-21-3469770775-847581034-1203560767-501 Access Granted: Access Right: SeInteractiveLogonRight
|
| | Security | Audit Success | 13569 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4717: System security access was granted to an account. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Account Modified: Account Name: S-1-5-21-3469770775-847581034-1203560767-501 Access Granted: Access Right: SeDenyInteractiveLogonRight
|
| | Security | Audit Success | 13569 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4717: System security access was granted to an account. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Account Modified: Account Name: S-1-5-21-3469770775-847581034-1203560767-501 Access Granted: Access Right: SeDenyNetworkLogonRight
|
| | Security | Audit Success | 13569 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4718: System security access was removed from an account. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Account Modified: Account Name: S-1-5-90-0 Access Removed: Access Right: SeInteractiveLogonRight
|
| | Security | Audit Success | 13569 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4717: System security access was granted to an account. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Account Modified: Account Name: S-1-5-32-555 Access Granted: Access Right: SeRemoteInteractiveLogonRight
|
| | Security | Audit Success | 13569 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4717: System security access was granted to an account. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Account Modified: Account Name: S-1-5-80-0 Access Granted: Access Right: SeServiceLogonRight
|
| | Security | Audit Success | 13569 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4739: Domain Policy was changed. Change Type: Password Policy modified Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Domain: Domain Name: MINWINPC Domain ID: S-1-5-21-3469770775-847581034-1203560767 Changed Attributes: Min. Password Age: unavailable Max. Password Age: 42:00:00:00 Force Logoff: - Lockout Threshold: - Lockout Observation Window: - Lockout Duration: - Password Properties: 8 Min. Password Length: 0 Password History Length: 0 Machine Account Quota: - Mixed Domain Mode: - Domain Behavior Version: - OEM Information: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4725: A user account was disabled. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-500 Account Name: Administrator Account Domain: MINWINPC
|
| | Security | Audit Success | 13824 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4738: A user account was changed. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-500 Account Name: Administrator Account Domain: MINWINPC Changed Attributes: SAM Account Name: - Display Name: - User Principal Name: - Home Directory: - Home Drive: - Script Path: - Profile Path: - User Workstations: - Password Last Set: - Account Expires: - Primary Group ID: - AllowedToDelegateTo: - Old UAC Value: 0x210 New UAC Value: 0x211 User Account Control: %%2080 User Parameters: - SID History: - Logon Hours: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4725: A user account was disabled. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-501 Account Name: Guest Account Domain: MINWINPC
|
| | Security | Audit Success | 13824 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4738: A user account was changed. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-501 Account Name: Guest Account Domain: MINWINPC Changed Attributes: SAM Account Name: - Display Name: - User Principal Name: - Home Directory: - Home Drive: - Script Path: - Profile Path: - User Workstations: - Password Last Set: - Account Expires: - Primary Group ID: - AllowedToDelegateTo: - Old UAC Value: 0x214 New UAC Value: 0x215 User Account Control: %%2080 User Parameters: - SID History: - Logon Hours: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Group: Security ID: S-1-5-32-545 Group Name: Users Group Domain: Builtin Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4732: A member was added to a security-enabled local group. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Member: Security ID: S-1-5-4 Account Name: - Group: Security ID: S-1-5-32-545 Group Name: Users Group Domain: Builtin Additional Information: Privileges: - Expiration time: (null)
|
| | Security | Audit Success | 13826 | 2026-07-13 17:12:35 | | Microsoft-Windows-Security-Auditing | 4732: A member was added to a security-enabled local group. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Member: Security ID: S-1-5-11 Account Name: - Group: Security ID: S-1-5-32-545 Group Name: Users Group Domain: Builtin Additional Information: Privileges: - Expiration time: (null)
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:48 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:48 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 13826 | 2026-07-13 17:12:48 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Group: Security ID: S-1-5-32-545 Group Name: Users Group Domain: Builtin Process Information: Process ID: 0x15f0 Process Name: C:\Program Files (x86)\Microsoft\Edge\Application\145.0.3800.97\Installer\setup.exe
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:49 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:49 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:12:49 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:49 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:49 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:12:49 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:00 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:00 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:19 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:19 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:23 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:23 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:23 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:23 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:23 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:23 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:23 | | Microsoft-Windows-Security-Auditing | 4738: A user account was changed. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-500 Account Name: Administrator Account Domain: MINWINPC Changed Attributes: SAM Account Name: - Display Name: - User Principal Name: - Home Directory: - Home Drive: - Script Path: - Profile Path: - User Workstations: - Password Last Set: - Account Expires: - Primary Group ID: - AllowedToDelegateTo: - Old UAC Value: 0x211 New UAC Value: 0x211 User Account Control: - User Parameters: - SID History: - Logon Hours: - Additional Information: Privileges: -
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:24 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:24 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:24 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:24 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:24 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:24 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:24 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:24 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:25 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:25 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:25 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:25 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:25 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:25 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:25 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:25 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:25 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:25 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:26 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:26 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:27 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: MINWINPC$ Account Domain: Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2d8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:27 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 103 | 2026-07-13 17:13:30 | | Microsoft-Windows-Eventlog | 1100: The event logging service has shut down.
|
| | Security | Audit Success | 13312 | 2026-07-13 17:13:49 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0xc8 New Process Name: R Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x4 Creator Process Name: Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13312 | 2026-07-13 17:13:49 | | Microsoft-Windows-Security-Auditing | 4696: A primary token was assigned to process. Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Process Information: Process ID: 0x4 Process Name: Target Process: Target Process ID: 0xc8 Target Process Name: Registry New Token Information: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x3e7
|
| | Security | Audit Success | 13312 | 2026-07-13 17:13:49 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x27c New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x4 Creator Process Name: Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13312 | 2026-07-13 17:13:49 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x290 New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x27c Creator Process Name: C Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13312 | 2026-07-13 17:13:49 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x2f8 New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x27c Creator Process Name: C Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13573 | 2026-07-13 17:13:49 | | Microsoft-Windows-Security-Auditing | 4826: Boot Configuration Data loaded. Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 General Settings: Load Options: - Advanced Options: %%1843 Configuration Access Policy: %%1846 System Event Logging: %%1843 Kernel Debugging: %%1843 VSM Launch Type: %%1848 Signature Settings: Test Signing: %%1843 Flight Signing: %%1843 Disable Integrity Checks: %%1843 HyperVisor Settings: HyperVisor Load Options: - HyperVisor Launch Type: %%1848 HyperVisor Debugging: %%1843
|
| | Security | Audit Success | 12288 | 2026-07-13 17:13:50 | | Microsoft-Windows-Security-Auditing | 4608: Windows is starting up. This event is logged when LSASS.EXE starts and the auditing subsystem is initialized.
|
| | Security | Audit Success | 12290 | 2026-07-13 17:13:50 | | Microsoft-Windows-Security-Auditing | 6417: The FIPS mode crypto selftests succeeded. Process ID: 0x270 Process Name: C:\Windows\System32\lsass.exe
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:50 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Logon Information: Logon Type: 0 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: - New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x4 Process Name: Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: - Authentication Package: - Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:50 | | Microsoft-Windows-Security-Auditing | 4648: A logon was attempted using explicit credentials. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Account Whose Credentials Were Used: Account Name: UMFD-0 Account Domain: Font Driver Host Logon GUID: {00000000-0000-0000-0000-000000000000} Target Server: Target Server Name: localhost Additional Information: localhost Process Information: Process ID: 0x380 Process Name: C:\Windows\System32\wininit.exe Network Information: Network Address: - Port: - This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:50 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:50 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 2 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1842 Elevated Token: %%1843 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-96-0-0 Account Name: UMFD-0 Account Domain: Font Driver Host Logon ID: 0x9d66 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x380 Process Name: C:\Windows\System32\wininit.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:50 | | Microsoft-Windows-Security-Auditing | 4648: A logon was attempted using explicit credentials. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Account Whose Credentials Were Used: Account Name: UMFD-1 Account Domain: Font Driver Host Logon GUID: {00000000-0000-0000-0000-000000000000} Target Server: Target Server Name: localhost Additional Information: localhost Process Information: Process ID: 0x3c8 Process Name: C:\Windows\System32\winlogon.exe Network Information: Network Address: - Port: - This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:50 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 2 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1842 Elevated Token: %%1843 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-96-0-1 Account Name: UMFD-1 Account Domain: Font Driver Host Logon ID: 0x9d67 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3c8 Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:50 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-20 Account Name: NETWORK SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e4 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:50 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:50 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:50 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-20 Account Name: NETWORK SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e4 Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege SeImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:50 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 13312 | 2026-07-13 17:13:50 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x324 New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x2f8 Creator Process Name: C Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13312 | 2026-07-13 17:13:50 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x378 New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x27c Creator Process Name: C Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13312 | 2026-07-13 17:13:50 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x380 New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x2f8 Creator Process Name: C Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13312 | 2026-07-13 17:13:50 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x388 New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x378 Creator Process Name: C Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13312 | 2026-07-13 17:13:50 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x3c8 New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x378 Creator Process Name: C Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13312 | 2026-07-13 17:13:50 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x29c New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x380 Creator Process Name: C Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13312 | 2026-07-13 17:13:50 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x270 New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x380 Creator Process Name: C Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13568 | 2026-07-13 17:13:50 | | Microsoft-Windows-Security-Auditing | 4902: The Per-user audit policy table was created. Number of Elements: 0 Policy ID: 0x99a3
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:51 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:51 | | Microsoft-Windows-Security-Auditing | 4648: A logon was attempted using explicit credentials. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Account Whose Credentials Were Used: Account Name: DWM-1 Account Domain: Window Manager Logon GUID: {00000000-0000-0000-0000-000000000000} Target Server: Target Server Name: localhost Additional Information: localhost Process Information: Process ID: 0x3c8 Process Name: C:\Windows\System32\winlogon.exe Network Information: Network Address: - Port: - This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:51 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 2 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1842 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-90-0-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0xf83d Linked Logon ID: 0xf871 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3c8 Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:51 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 2 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1842 Elevated Token: %%1843 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-90-0-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0xf871 Linked Logon ID: 0xf83d Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3c8 Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:51 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:51 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:51 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:51 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:51 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:51 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-90-0-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0xf83d Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege SeImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:51 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-90-0-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0xf871 Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:51 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:51 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege SeImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:51 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:51 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:55 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:55 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:55 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:55 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:55 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:55 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12292 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 5033: The Windows Firewall Driver started successfully.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4648: A logon was attempted using explicit credentials. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Account Whose Credentials Were Used: Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Logon GUID: {00000000-0000-0000-0000-000000000000} Target Server: Target Server Name: localhost Additional Information: localhost Process Information: Process ID: 0x754 Process Name: C:\Windows\System32\oobe\msoobe.exe Network Information: Network Address: - Port: - This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 2 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1fbd5 Linked Logon ID: 0x1fd79 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x754 Process Name: C:\Windows\System32\oobe\msoobe.exe Network Information: Workstation Name: WIN-SLRHEC6PMT7 Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 2 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1843 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1fd79 Linked Logon ID: 0x1fbd5 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x754 Process Name: C:\Windows\System32\oobe\msoobe.exe Network Information: Workstation Name: WIN-SLRHEC6PMT7 Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12545 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4634: An account was logged off. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1fd79 Logon Type: 2 This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
|
| | Security | Audit Success | 12545 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4634: An account was logged off. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1fbd5 Logon Type: 2 This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1fbd5 Privileges: SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4781: The name of an account was changed: Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-32-544 Account Domain: Builtin Old Account Name: Administrators New Account Name: Administrators Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4781: The name of an account was changed: Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-32-545 Account Domain: Builtin Old Account Name: Users New Account Name: Users Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4781: The name of an account was changed: Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-32-546 Account Domain: Builtin Old Account Name: Guests New Account Name: Guests Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4781: The name of an account was changed: Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-32-558 Account Domain: Builtin Old Account Name: Performance Monitor Users New Account Name: Performance Monitor Users Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4781: The name of an account was changed: Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-32-559 Account Domain: Builtin Old Account Name: Performance Log Users New Account Name: Performance Log Users Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4781: The name of an account was changed: Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-32-562 Account Domain: Builtin Old Account Name: Distributed COM Users New Account Name: Distributed COM Users Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4781: The name of an account was changed: Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-32-568 Account Domain: Builtin Old Account Name: IIS_IUSRS New Account Name: IIS_IUSRS Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4781: The name of an account was changed: Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-32-573 Account Domain: Builtin Old Account Name: Event Log Readers New Account Name: Event Log Readers Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4781: The name of an account was changed: Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-32-580 Account Domain: Builtin Old Account Name: Remote Management Users New Account Name: Remote Management Users Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4781: The name of an account was changed: Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-32-581 Account Domain: Builtin Old Account Name: System Managed Accounts Group New Account Name: System Managed Accounts Group Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4781: The name of an account was changed: Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-32-583 Account Domain: Builtin Old Account Name: Device Owners New Account Name: Device Owners Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4781: The name of an account was changed: Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-32-584 Account Domain: Builtin Old Account Name: User Mode Hardware Operators New Account Name: User Mode Hardware Operators Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4781: The name of an account was changed: Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-32-585 Account Domain: Builtin Old Account Name: OpenSSH Users New Account Name: OpenSSH Users Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4738: A user account was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-500 Account Name: Administrator Account Domain: DESKTOP-M1V6K8T Changed Attributes: SAM Account Name: Administrator Display Name: %%1793 User Principal Name: - Home Directory: %%1793 Home Drive: %%1793 Script Path: %%1793 Profile Path: %%1793 User Workstations: %%1793 Password Last Set: %%1794 Account Expires: %%1794 Primary Group ID: 513 AllowedToDelegateTo: - Old UAC Value: 0x211 New UAC Value: 0x211 User Account Control: - User Parameters: %%1793 SID History: - Logon Hours: %%1797 Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4738: A user account was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-500 Account Name: Administrator Account Domain: DESKTOP-M1V6K8T Changed Attributes: SAM Account Name: Administrator Display Name: %%1793 User Principal Name: - Home Directory: %%1793 Home Drive: %%1793 Script Path: %%1793 Profile Path: %%1793 User Workstations: %%1793 Password Last Set: %%1794 Account Expires: %%1794 Primary Group ID: 513 AllowedToDelegateTo: - Old UAC Value: 0x211 New UAC Value: 0x211 User Account Control: - User Parameters: %%1793 SID History: - Logon Hours: %%1797 Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4738: A user account was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-501 Account Name: Guest Account Domain: DESKTOP-M1V6K8T Changed Attributes: SAM Account Name: Guest Display Name: %%1793 User Principal Name: - Home Directory: %%1793 Home Drive: %%1793 Script Path: %%1793 Profile Path: %%1793 User Workstations: %%1793 Password Last Set: %%1794 Account Expires: %%1794 Primary Group ID: 513 AllowedToDelegateTo: - Old UAC Value: 0x215 New UAC Value: 0x215 User Account Control: - User Parameters: %%1793 SID History: - Logon Hours: %%1797 Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4738: A user account was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-501 Account Name: Guest Account Domain: DESKTOP-M1V6K8T Changed Attributes: SAM Account Name: Guest Display Name: %%1793 User Principal Name: - Home Directory: %%1793 Home Drive: %%1793 Script Path: %%1793 Profile Path: %%1793 User Workstations: %%1793 Password Last Set: %%1794 Account Expires: %%1794 Primary Group ID: 513 AllowedToDelegateTo: - Old UAC Value: 0x215 New UAC Value: 0x215 User Account Control: - User Parameters: %%1793 SID History: - Logon Hours: %%1797 Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4738: A user account was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-503 Account Name: DefaultAccount Account Domain: DESKTOP-M1V6K8T Changed Attributes: SAM Account Name: DefaultAccount Display Name: %%1793 User Principal Name: - Home Directory: %%1793 Home Drive: %%1793 Script Path: %%1793 Profile Path: %%1793 User Workstations: %%1793 Password Last Set: %%1794 Account Expires: %%1794 Primary Group ID: 513 AllowedToDelegateTo: - Old UAC Value: 0x215 New UAC Value: 0x215 User Account Control: - User Parameters: %%1793 SID History: - Logon Hours: %%1797 Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4738: A user account was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-503 Account Name: DefaultAccount Account Domain: DESKTOP-M1V6K8T Changed Attributes: SAM Account Name: DefaultAccount Display Name: %%1793 User Principal Name: - Home Directory: %%1793 Home Drive: %%1793 Script Path: %%1793 Profile Path: %%1793 User Workstations: %%1793 Password Last Set: %%1794 Account Expires: %%1794 Primary Group ID: 513 AllowedToDelegateTo: - Old UAC Value: 0x215 New UAC Value: 0x215 User Account Control: - User Parameters: %%1793 SID History: - Logon Hours: %%1797 Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4738: A user account was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-504 Account Name: WDAGUtilityAccount Account Domain: DESKTOP-M1V6K8T Changed Attributes: SAM Account Name: WDAGUtilityAccount Display Name: %%1793 User Principal Name: - Home Directory: %%1793 Home Drive: %%1793 Script Path: %%1793 Profile Path: %%1793 User Workstations: %%1793 Password Last Set: 7/13/2026 5:12:24 PM Account Expires: %%1794 Primary Group ID: 513 AllowedToDelegateTo: - Old UAC Value: 0x11 New UAC Value: 0x11 User Account Control: - User Parameters: %%1793 SID History: - Logon Hours: %%1797 Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4738: A user account was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-504 Account Name: WDAGUtilityAccount Account Domain: DESKTOP-M1V6K8T Changed Attributes: SAM Account Name: WDAGUtilityAccount Display Name: %%1793 User Principal Name: - Home Directory: %%1793 Home Drive: %%1793 Script Path: %%1793 Profile Path: %%1793 User Workstations: %%1793 Password Last Set: 7/13/2026 5:12:24 PM Account Expires: %%1794 Primary Group ID: 513 AllowedToDelegateTo: - Old UAC Value: 0x11 New UAC Value: 0x11 User Account Control: - User Parameters: %%1793 SID History: - Logon Hours: %%1797 Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4781: The name of an account was changed: Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-513 Account Domain: DESKTOP-M1V6K8T Old Account Name: None New Account Name: None Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4720: A user account was created. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 New Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Attributes: SAM Account Name: defaultuser0 Display Name: %%1793 User Principal Name: - Home Directory: %%1793 Home Drive: %%1793 Script Path: %%1793 Profile Path: %%1793 User Workstations: %%1793 Password Last Set: %%1794 Account Expires: %%1794 Primary Group ID: 513 Allowed To Delegate To: - Old UAC Value: 0x0 New UAC Value: 0x15 User Account Control: %%2080 %%2082 %%2084 User Parameters: %%1793 SID History: - Logon Hours: %%1797 Additional Information: Privileges -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4722: A user account was enabled. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4738: A user account was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Changed Attributes: SAM Account Name: defaultuser0 Display Name: %%1793 User Principal Name: - Home Directory: %%1793 Home Drive: %%1793 Script Path: %%1793 Profile Path: %%1793 User Workstations: %%1793 Password Last Set: %%1794 Account Expires: %%1794 Primary Group ID: 513 AllowedToDelegateTo: - Old UAC Value: 0x15 New UAC Value: 0x14 User Account Control: %%2048 User Parameters: %%1793 SID History: - Logon Hours: %%1797 Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4738: A user account was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Changed Attributes: SAM Account Name: defaultuser0 Display Name: %%1793 User Principal Name: - Home Directory: %%1793 Home Drive: %%1793 Script Path: %%1793 Profile Path: %%1793 User Workstations: %%1793 Password Last Set: 7/13/2026 5:13:56 PM Account Expires: %%1794 Primary Group ID: 513 AllowedToDelegateTo: - Old UAC Value: 0x14 New UAC Value: 0x14 User Account Control: - User Parameters: - SID History: - Logon Hours: %%1797 Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4724: An attempt was made to reset an account's password. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4738: A user account was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Changed Attributes: SAM Account Name: defaultuser0 Display Name: %%1793 User Principal Name: - Home Directory: %%1793 Home Drive: %%1793 Script Path: %%1793 Profile Path: %%1793 User Workstations: %%1793 Password Last Set: 7/13/2026 5:13:56 PM Account Expires: %%1794 Primary Group ID: 513 AllowedToDelegateTo: - Old UAC Value: 0x14 New UAC Value: 0x214 User Account Control: %%2089 User Parameters: - SID History: - Logon Hours: %%1797 Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4724: An attempt was made to reset an account's password. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x270 Process Name: C:\Windows\System32\lsass.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Changed Attributes: SAM Account Name: - SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Changed Attributes: SAM Account Name: Administrators SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-545 Group Name: Users Group Domain: Builtin Changed Attributes: SAM Account Name: - SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-545 Group Name: Users Group Domain: Builtin Changed Attributes: SAM Account Name: Users SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-546 Group Name: Guests Group Domain: Builtin Changed Attributes: SAM Account Name: - SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-546 Group Name: Guests Group Domain: Builtin Changed Attributes: SAM Account Name: Guests SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-558 Group Name: Performance Monitor Users Group Domain: Builtin Changed Attributes: SAM Account Name: - SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-558 Group Name: Performance Monitor Users Group Domain: Builtin Changed Attributes: SAM Account Name: Performance Monitor Users SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-559 Group Name: Performance Log Users Group Domain: Builtin Changed Attributes: SAM Account Name: - SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-559 Group Name: Performance Log Users Group Domain: Builtin Changed Attributes: SAM Account Name: Performance Log Users SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-562 Group Name: Distributed COM Users Group Domain: Builtin Changed Attributes: SAM Account Name: - SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-562 Group Name: Distributed COM Users Group Domain: Builtin Changed Attributes: SAM Account Name: Distributed COM Users SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-568 Group Name: IIS_IUSRS Group Domain: Builtin Changed Attributes: SAM Account Name: - SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-568 Group Name: IIS_IUSRS Group Domain: Builtin Changed Attributes: SAM Account Name: IIS_IUSRS SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-573 Group Name: Event Log Readers Group Domain: Builtin Changed Attributes: SAM Account Name: - SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-573 Group Name: Event Log Readers Group Domain: Builtin Changed Attributes: SAM Account Name: Event Log Readers SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-580 Group Name: Remote Management Users Group Domain: Builtin Changed Attributes: SAM Account Name: - SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-580 Group Name: Remote Management Users Group Domain: Builtin Changed Attributes: SAM Account Name: Remote Management Users SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-581 Group Name: System Managed Accounts Group Group Domain: Builtin Changed Attributes: SAM Account Name: - SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-581 Group Name: System Managed Accounts Group Group Domain: Builtin Changed Attributes: SAM Account Name: System Managed Accounts Group SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-583 Group Name: Device Owners Group Domain: Builtin Changed Attributes: SAM Account Name: - SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-583 Group Name: Device Owners Group Domain: Builtin Changed Attributes: SAM Account Name: Device Owners SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-584 Group Name: User Mode Hardware Operators Group Domain: Builtin Changed Attributes: SAM Account Name: - SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-584 Group Name: User Mode Hardware Operators Group Domain: Builtin Changed Attributes: SAM Account Name: User Mode Hardware Operators SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-585 Group Name: OpenSSH Users Group Domain: Builtin Changed Attributes: SAM Account Name: - SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4735: A security-enabled local group was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-585 Group Name: OpenSSH Users Group Domain: Builtin Changed Attributes: SAM Account Name: OpenSSH Users SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4737: A security-enabled global group was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-21-3469770775-847581034-1203560767-513 Group Name: None Group Domain: DESKTOP-M1V6K8T Changed Attributes: SAM Account Name: - SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4737: A security-enabled global group was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-21-3469770775-847581034-1203560767-513 Group Name: None Group Domain: DESKTOP-M1V6K8T Changed Attributes: SAM Account Name: None SID History: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4728: A member was added to a security-enabled global group. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Member: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: - Group: Security ID: S-1-5-21-3469770775-847581034-1203560767-513 Group Name: None Group Domain: DESKTOP-M1V6K8T Additional Information: Privileges: - Expiration time: (null)
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4732: A member was added to a security-enabled local group. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Member: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: - Group: Security ID: S-1-5-32-545 Group Name: Users Group Domain: Builtin Additional Information: Privileges: - Expiration time: (null)
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0x754 Process Name: C:\Windows\System32\oobe\msoobe.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0x754 Process Name: C:\Windows\System32\oobe\msoobe.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4732: A member was added to a security-enabled local group. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Member: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: - Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Additional Information: Privileges: - Expiration time: (null)
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0x754 Process Name: C:\Windows\System32\oobe\msoobe.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0x754 Process Name: C:\Windows\System32\oobe\msoobe.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:56 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0x60c Process Name: C:\Windows\System32\svchost.exe
|
| | Security | Audit Success | 12292 | 2026-07-13 17:13:57 | | Microsoft-Windows-Security-Auditing | 5024: The Windows Firewall service started successfully.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:57 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:57 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:57 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:57 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:57 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:57 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:57 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:57 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 13568 | 2026-07-13 17:13:57 | | Microsoft-Windows-Security-Auditing | 4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Temp\winre\ExtractedFromWim Handle ID: 0x8b0 Process Information: Process ID: 0x754 Process Name: C:\Windows\System32\oobe\msoobe.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:57 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-20 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e4 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0x8fc Process Name: C:\Windows\System32\svchost.exe
|
| | Security | Audit Success | 12544 | 2026-07-13 17:13:58 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:13:58 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:58 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0x139c Process Name: C:\Windows\System32\SearchIndexer.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:13:59 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0xf88 Process Name: C:\Windows\System32\svchost.exe
|
| | Security | Audit Success | 12544 | 2026-07-13 17:14:00 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:14:00 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12544 | 2026-07-13 17:14:06 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:14:06 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:14:06 | | Microsoft-Windows-Security-Auditing | 4648: A logon was attempted using explicit credentials. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Account Whose Credentials Were Used: Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Logon GUID: {00000000-0000-0000-0000-000000000000} Target Server: Target Server Name: localhost Additional Information: localhost Process Information: Process ID: 0x664 Process Name: C:\Windows\System32\svchost.exe Network Information: Network Address: 127.0.0.1 Port: 0 This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:14:06 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 2 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Logon ID: 0x54648 Linked Logon ID: 0x54683 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x664 Process Name: C:\Windows\System32\svchost.exe Network Information: Workstation Name: WIN-SLRHEC6PMT7 Source Network Address: 127.0.0.1 Source Port: 0 Detailed Authentication Information: Logon Process: User32 Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:14:06 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 2 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1843 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Logon ID: 0x54683 Linked Logon ID: 0x54648 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x664 Process Name: C:\Windows\System32\svchost.exe Network Information: Workstation Name: WIN-SLRHEC6PMT7 Source Network Address: 127.0.0.1 Source Port: 0 Detailed Authentication Information: Logon Process: User32 Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:14:06 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:14:06 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:14:06 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Logon ID: 0x54648 Privileges: SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 13824 | 2026-07-13 17:14:06 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x270 Process Name: C:\Windows\System32\lsass.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:14:06 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0x60c Process Name: C:\Windows\System32\svchost.exe
|
| | Security | Audit Failure | 12290 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 5061: Cryptographic operation. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Logon ID: 0x54683 Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: UNKNOWN Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Cryptographic Operation: Operation: %%2480 Return Code: 0x80090016
|
| | Security | Audit Failure | 12290 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 5061: Cryptographic operation. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Logon ID: 0x54683 Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: UNKNOWN Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Cryptographic Operation: Operation: %%2480 Return Code: 0x80090016
|
| | Security | Audit Failure | 12290 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 5061: Cryptographic operation. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Logon ID: 0x54683 Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: UNKNOWN Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Cryptographic Operation: Operation: %%2480 Return Code: 0x80090016
|
| | Security | Audit Failure | 12290 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 5061: Cryptographic operation. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: UNKNOWN Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Cryptographic Operation: Operation: %%2480 Return Code: 0x80090016
|
| | Security | Audit Failure | 12290 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 5061: Cryptographic operation. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: UNKNOWN Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Cryptographic Operation: Operation: %%2480 Return Code: 0x80090016
|
| | Security | Audit Failure | 12290 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 5061: Cryptographic operation. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: UNKNOWN Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Cryptographic Operation: Operation: %%2480 Return Code: 0x80090016
|
| | Security | Audit Success | 12290 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 5061: Cryptographic operation. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Logon ID: 0x54683 Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: ECDSA_P256 Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Cryptographic Operation: Operation: %%2481 Return Code: 0x0
|
| | Security | Audit Success | 12290 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 5061: Cryptographic operation. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Logon ID: 0x54683 Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: ECDSA_P256 Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Cryptographic Operation: Operation: %%2480 Return Code: 0x0
|
| | Security | Audit Success | 12290 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 5061: Cryptographic operation. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: ECDSA_P256 Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Cryptographic Operation: Operation: %%2481 Return Code: 0x0
|
| | Security | Audit Success | 12290 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 5061: Cryptographic operation. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: ECDSA_P256 Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Cryptographic Operation: Operation: %%2480 Return Code: 0x0
|
| | Security | Audit Success | 12292 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 5058: Key file operation. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Logon ID: 0x54683 Process Information: Process ID: 6000 Process Creation Time: 2026-07-14T00:14:07.3298228Z Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: ECDSA_P256 Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Key File Operation Information: File Path: C:\Users\defaultuser0\AppData\Roaming\Microsoft\Crypto\Keys\de7cf8a7901d2ad13e5c67c29e5d1662_e35a81ea-e9f3-46c8-8766-e45e5ee1ea58 Operation: %%2459 Return Code: 0x0
|
| | Security | Audit Success | 12292 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 5058: Key file operation. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Logon ID: 0x54683 Process Information: Process ID: 6000 Process Creation Time: 2026-07-14T00:14:07.3298228Z Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: UNKNOWN Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Key File Operation Information: File Path: C:\Users\defaultuser0\AppData\Roaming\Microsoft\Crypto\Keys\de7cf8a7901d2ad13e5c67c29e5d1662_e35a81ea-e9f3-46c8-8766-e45e5ee1ea58 Operation: %%2458 Return Code: 0x0
|
| | Security | Audit Success | 12292 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 5059: Key migration operation. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Logon ID: 0x54683 Process Information: Process ID: 6000 Process Creation Time: 2026-07-14T00:14:07.3298228Z Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: ECDSA_P256 Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Additional Information: Operation: %%2464 Return Code: 0x0
|
| | Security | Audit Success | 12292 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 5059: Key migration operation. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Logon ID: 0x54683 Process Information: Process ID: 6000 Process Creation Time: 2026-07-14T00:14:07.3298228Z Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: ECDSA_P256 Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Additional Information: Operation: %%2464 Return Code: 0x0
|
| | Security | Audit Success | 12292 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 5059: Key migration operation. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Logon ID: 0x54683 Process Information: Process ID: 6000 Process Creation Time: 2026-07-14T00:14:07.3298228Z Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: ECDSA_P256 Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Additional Information: Operation: %%2464 Return Code: 0x0
|
| | Security | Audit Success | 12292 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 5058: Key file operation. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Process Information: Process ID: 4912 Process Creation Time: 2026-07-14T00:14:07.4319306Z Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: ECDSA_P256 Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Key File Operation Information: File Path: C:\WINDOWS\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Crypto\Keys\de7cf8a7901d2ad13e5c67c29e5d1662_e35a81ea-e9f3-46c8-8766-e45e5ee1ea58 Operation: %%2459 Return Code: 0x0
|
| | Security | Audit Success | 12292 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 5058: Key file operation. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Process Information: Process ID: 4912 Process Creation Time: 2026-07-14T00:14:07.4319306Z Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: UNKNOWN Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Key File Operation Information: File Path: C:\WINDOWS\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Crypto\Keys\de7cf8a7901d2ad13e5c67c29e5d1662_e35a81ea-e9f3-46c8-8766-e45e5ee1ea58 Operation: %%2458 Return Code: 0x0
|
| | Security | Audit Success | 12292 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 5059: Key migration operation. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Process Information: Process ID: 4912 Process Creation Time: 2026-07-14T00:14:07.4319306Z Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: ECDSA_P256 Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Additional Information: Operation: %%2464 Return Code: 0x0
|
| | Security | Audit Success | 12292 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 5059: Key migration operation. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Process Information: Process ID: 4912 Process Creation Time: 2026-07-14T00:14:07.4319306Z Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: ECDSA_P256 Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Additional Information: Operation: %%2464 Return Code: 0x0
|
| | Security | Audit Success | 12292 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 5059: Key migration operation. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Process Information: Process ID: 4912 Process Creation Time: 2026-07-14T00:14:07.4319306Z Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: ECDSA_P256 Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Additional Information: Operation: %%2464 Return Code: 0x0
|
| | Security | Audit Success | 12544 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 13824 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x157c Process Name: C:\Windows\System32\DeviceCensus.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Logon ID: 0x54683 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Logon ID: 0x54683 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Logon ID: 0x54683 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Logon ID: 0x54683 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Logon ID: 0x54683 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:14:07 | | Microsoft-Windows-Security-Auditing | 5382: Vault credentials were read. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 This event occurs when a user reads a stored vault credential.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:14:08 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:14:08 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12544 | 2026-07-13 17:14:09 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:14:09 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12544 | 2026-07-13 17:14:10 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:14:10 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:14:10 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:14:10 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12544 | 2026-07-13 17:14:11 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:14:11 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12544 | 2026-07-13 17:14:12 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:14:12 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12544 | 2026-07-13 17:14:27 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:14:27 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12544 | 2026-07-13 17:15:48 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:15:48 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 13826 | 2026-07-13 17:15:52 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0x2394 Process Name: C:\Windows\System32\svchost.exe
|
| | Security | Audit Success | 12544 | 2026-07-13 17:15:56 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:15:56 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12544 | 2026-07-13 17:15:57 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:15:57 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:15:57 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:15:57 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:15:57 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:15:57 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 13824 | 2026-07-13 17:16:13 | | Microsoft-Windows-Security-Auditing | 4720: A user account was created. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 New Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Attributes: SAM Account Name: Marius Display Name: %%1793 User Principal Name: - Home Directory: %%1793 Home Drive: %%1793 Script Path: %%1793 Profile Path: %%1793 User Workstations: %%1793 Password Last Set: %%1794 Account Expires: %%1794 Primary Group ID: 513 Allowed To Delegate To: - Old UAC Value: 0x0 New UAC Value: 0x15 User Account Control: %%2080 %%2082 %%2084 User Parameters: %%1793 SID History: - Logon Hours: %%1797 Additional Information: Privileges -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:16:13 | | Microsoft-Windows-Security-Auditing | 4722: A user account was enabled. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T
|
| | Security | Audit Success | 13824 | 2026-07-13 17:16:13 | | Microsoft-Windows-Security-Auditing | 4738: A user account was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Changed Attributes: SAM Account Name: Marius Display Name: %%1793 User Principal Name: - Home Directory: %%1793 Home Drive: %%1793 Script Path: %%1793 Profile Path: %%1793 User Workstations: %%1793 Password Last Set: %%1794 Account Expires: %%1794 Primary Group ID: 513 AllowedToDelegateTo: - Old UAC Value: 0x15 New UAC Value: 0x14 User Account Control: %%2048 User Parameters: %%1793 SID History: - Logon Hours: %%1797 Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:16:13 | | Microsoft-Windows-Security-Auditing | 4738: A user account was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Changed Attributes: SAM Account Name: Marius Display Name: %%1793 User Principal Name: - Home Directory: %%1793 Home Drive: %%1793 Script Path: %%1793 Profile Path: %%1793 User Workstations: %%1793 Password Last Set: 7/13/2026 5:16:13 PM Account Expires: %%1794 Primary Group ID: 513 AllowedToDelegateTo: - Old UAC Value: 0x14 New UAC Value: 0x14 User Account Control: - User Parameters: - SID History: - Logon Hours: %%1797 Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:16:13 | | Microsoft-Windows-Security-Auditing | 4724: An attempt was made to reset an account's password. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T
|
| | Security | Audit Success | 13824 | 2026-07-13 17:16:13 | | Microsoft-Windows-Security-Auditing | 4738: A user account was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Changed Attributes: SAM Account Name: Marius Display Name: %%1793 User Principal Name: - Home Directory: %%1793 Home Drive: %%1793 Script Path: %%1793 Profile Path: %%1793 User Workstations: %%1793 Password Last Set: 7/13/2026 5:16:13 PM Account Expires: %%1794 Primary Group ID: 513 AllowedToDelegateTo: - Old UAC Value: 0x14 New UAC Value: 0x214 User Account Control: %%2089 User Parameters: - SID History: - Logon Hours: %%1797 Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:16:13 | | Microsoft-Windows-Security-Auditing | 4724: An attempt was made to reset an account's password. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T
|
| | Security | Audit Success | 13824 | 2026-07-13 17:16:13 | | Microsoft-Windows-Security-Auditing | 4738: A user account was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Changed Attributes: SAM Account Name: - Display Name: - User Principal Name: - Home Directory: - Home Drive: - Script Path: - Profile Path: - User Workstations: - Password Last Set: - Account Expires: - Primary Group ID: - AllowedToDelegateTo: - Old UAC Value: - New UAC Value: - User Account Control: - User Parameters: - SID History: - Logon Hours: - Additional Information: Privileges: -
|
| | Security | Audit Success | 13824 | 2026-07-13 17:16:13 | | Microsoft-Windows-Security-Auditing | 4725: A user account was disabled. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T
|
| | Security | Audit Success | 13824 | 2026-07-13 17:16:13 | | Microsoft-Windows-Security-Auditing | 4738: A user account was changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Changed Attributes: SAM Account Name: defaultuser0 Display Name: %%1793 User Principal Name: - Home Directory: %%1793 Home Drive: %%1793 Script Path: %%1793 Profile Path: %%1793 User Workstations: %%1793 Password Last Set: 7/13/2026 5:13:56 PM Account Expires: %%1794 Primary Group ID: 513 AllowedToDelegateTo: - Old UAC Value: 0x214 New UAC Value: 0x211 User Account Control: %%2080 %%2050 User Parameters: %%1793 SID History: - Logon Hours: %%1797 Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:16:13 | | Microsoft-Windows-Security-Auditing | 4728: A member was added to a security-enabled global group. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Member: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: - Group: Security ID: S-1-5-21-3469770775-847581034-1203560767-513 Group Name: None Group Domain: DESKTOP-M1V6K8T Additional Information: Privileges: - Expiration time: (null)
|
| | Security | Audit Success | 13826 | 2026-07-13 17:16:13 | | Microsoft-Windows-Security-Auditing | 4732: A member was added to a security-enabled local group. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Member: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: - Group: Security ID: S-1-5-32-545 Group Name: Users Group Domain: Builtin Additional Information: Privileges: - Expiration time: (null)
|
| | Security | Audit Success | 13826 | 2026-07-13 17:16:13 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0x1850 Process Name: C:\Windows\System32\CloudExperienceHostBroker.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:16:13 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0x1850 Process Name: C:\Windows\System32\CloudExperienceHostBroker.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:16:13 | | Microsoft-Windows-Security-Auditing | 4732: A member was added to a security-enabled local group. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Member: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: - Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Additional Information: Privileges: - Expiration time: (null)
|
| | Security | Audit Success | 13826 | 2026-07-13 17:16:13 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0x1850 Process Name: C:\Windows\System32\CloudExperienceHostBroker.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:16:13 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0x1850 Process Name: C:\Windows\System32\CloudExperienceHostBroker.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:16:13 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-545 Group Name: Users Group Domain: Builtin Process Information: Process ID: 0x1850 Process Name: C:\Windows\System32\CloudExperienceHostBroker.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:16:13 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-545 Group Name: Users Group Domain: Builtin Process Information: Process ID: 0x1850 Process Name: C:\Windows\System32\CloudExperienceHostBroker.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:16:13 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-545 Group Name: Users Group Domain: Builtin Process Information: Process ID: 0x1850 Process Name: C:\Windows\System32\CloudExperienceHostBroker.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:16:13 | | Microsoft-Windows-Security-Auditing | 4733: A member was removed from a security-enabled local group. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Member: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: - Group: Security ID: S-1-5-32-545 Group Name: Users Group Domain: Builtin Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:16:13 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-545 Group Name: Users Group Domain: Builtin Process Information: Process ID: 0x1850 Process Name: C:\Windows\System32\CloudExperienceHostBroker.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:16:13 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-545 Group Name: Users Group Domain: Builtin Process Information: Process ID: 0x1850 Process Name: C:\Windows\System32\CloudExperienceHostBroker.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:16:13 | | Microsoft-Windows-Security-Auditing | 4733: A member was removed from a security-enabled local group. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Member: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: - Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Additional Information: Privileges: -
|
| | Security | Audit Success | 12545 | 2026-07-13 17:16:14 | | Microsoft-Windows-Security-Auditing | 4647: User initiated logoff: Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Logon ID: 0x54683 This event is generated when a logoff is initiated. No further user-initiated activity can occur. This event can be interpreted as a logoff event.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:16:15 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:16:15 | | Microsoft-Windows-Security-Auditing | 4648: A logon was attempted using explicit credentials. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Account Whose Credentials Were Used: Account Name: UMFD-2 Account Domain: Font Driver Host Logon GUID: {00000000-0000-0000-0000-000000000000} Target Server: Target Server Name: localhost Additional Information: localhost Process Information: Process ID: 0x5c8 Process Name: C:\Windows\System32\winlogon.exe Network Information: Network Address: - Port: - This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:16:15 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 2 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1842 Elevated Token: %%1843 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-96-0-2 Account Name: UMFD-2 Account Domain: Font Driver Host Logon ID: 0xe5134 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x5c8 Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:16:15 | | Microsoft-Windows-Security-Auditing | 4648: A logon was attempted using explicit credentials. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Account Whose Credentials Were Used: Account Name: DWM-2 Account Domain: Window Manager Logon GUID: {00000000-0000-0000-0000-000000000000} Target Server: Target Server Name: localhost Additional Information: localhost Process Information: Process ID: 0x5c8 Process Name: C:\Windows\System32\winlogon.exe Network Information: Network Address: - Port: - This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:16:15 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 2 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1842 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-90-0-2 Account Name: DWM-2 Account Domain: Window Manager Logon ID: 0xe5629 Linked Logon ID: 0xe565a Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x5c8 Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:16:15 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 2 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1842 Elevated Token: %%1843 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-90-0-2 Account Name: DWM-2 Account Domain: Window Manager Logon ID: 0xe565a Linked Logon ID: 0xe5629 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x5c8 Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:16:15 | | Microsoft-Windows-Security-Auditing | 4648: A logon was attempted using explicit credentials. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Account Whose Credentials Were Used: Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon GUID: {00000000-0000-0000-0000-000000000000} Target Server: Target Server Name: localhost Additional Information: localhost Process Information: Process ID: 0x664 Process Name: C:\Windows\System32\svchost.exe Network Information: Network Address: 127.0.0.1 Port: 0 This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:16:15 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 2 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f41 Linked Logon ID: 0xe7f87 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x664 Process Name: C:\Windows\System32\svchost.exe Network Information: Workstation Name: WIN-SLRHEC6PMT7 Source Network Address: 127.0.0.1 Source Port: 0 Detailed Authentication Information: Logon Process: User32 Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:16:15 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 2 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1843 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Linked Logon ID: 0xe7f41 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x664 Process Name: C:\Windows\System32\svchost.exe Network Information: Workstation Name: WIN-SLRHEC6PMT7 Source Network Address: 127.0.0.1 Source Port: 0 Detailed Authentication Information: Logon Process: User32 Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12545 | 2026-07-13 17:16:15 | | Microsoft-Windows-Security-Auditing | 4634: An account was logged off. Subject: Security ID: S-1-5-96-0-1 Account Name: UMFD-1 Account Domain: Font Driver Host Logon ID: 0x9d67 Logon Type: 2 This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:16:15 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:16:15 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-90-0-2 Account Name: DWM-2 Account Domain: Window Manager Logon ID: 0xe5629 Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege SeImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:16:15 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-90-0-2 Account Name: DWM-2 Account Domain: Window Manager Logon ID: 0xe565a Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:16:15 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f41 Privileges: SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 13824 | 2026-07-13 17:16:15 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x270 Process Name: C:\Windows\System32\lsass.exe
|
| | Security | Audit Failure | 12290 | 2026-07-13 17:16:16 | | Microsoft-Windows-Security-Auditing | 5061: Cryptographic operation. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: UNKNOWN Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Cryptographic Operation: Operation: %%2480 Return Code: 0x80090016
|
| | Security | Audit Failure | 12290 | 2026-07-13 17:16:16 | | Microsoft-Windows-Security-Auditing | 5061: Cryptographic operation. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: UNKNOWN Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Cryptographic Operation: Operation: %%2480 Return Code: 0x80090016
|
| | Security | Audit Failure | 12290 | 2026-07-13 17:16:16 | | Microsoft-Windows-Security-Auditing | 5061: Cryptographic operation. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: UNKNOWN Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Cryptographic Operation: Operation: %%2480 Return Code: 0x80090016
|
| | Security | Audit Success | 12290 | 2026-07-13 17:16:16 | | Microsoft-Windows-Security-Auditing | 5061: Cryptographic operation. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: ECDSA_P256 Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Cryptographic Operation: Operation: %%2481 Return Code: 0x0
|
| | Security | Audit Success | 12290 | 2026-07-13 17:16:16 | | Microsoft-Windows-Security-Auditing | 5061: Cryptographic operation. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: ECDSA_P256 Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Cryptographic Operation: Operation: %%2480 Return Code: 0x0
|
| | Security | Audit Success | 12292 | 2026-07-13 17:16:16 | | Microsoft-Windows-Security-Auditing | 5058: Key file operation. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Process Information: Process ID: 5844 Process Creation Time: 2026-07-14T00:16:16.6092106Z Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: ECDSA_P256 Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Key File Operation Information: File Path: C:\Users\Marius\AppData\Roaming\Microsoft\Crypto\Keys\de7cf8a7901d2ad13e5c67c29e5d1662_e35a81ea-e9f3-46c8-8766-e45e5ee1ea58 Operation: %%2459 Return Code: 0x0
|
| | Security | Audit Success | 12292 | 2026-07-13 17:16:16 | | Microsoft-Windows-Security-Auditing | 5058: Key file operation. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Process Information: Process ID: 5844 Process Creation Time: 2026-07-14T00:16:16.6092106Z Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: UNKNOWN Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Key File Operation Information: File Path: C:\Users\Marius\AppData\Roaming\Microsoft\Crypto\Keys\de7cf8a7901d2ad13e5c67c29e5d1662_e35a81ea-e9f3-46c8-8766-e45e5ee1ea58 Operation: %%2458 Return Code: 0x0
|
| | Security | Audit Success | 12292 | 2026-07-13 17:16:16 | | Microsoft-Windows-Security-Auditing | 5059: Key migration operation. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Process Information: Process ID: 5844 Process Creation Time: 2026-07-14T00:16:16.6092106Z Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: ECDSA_P256 Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Additional Information: Operation: %%2464 Return Code: 0x0
|
| | Security | Audit Success | 12292 | 2026-07-13 17:16:16 | | Microsoft-Windows-Security-Auditing | 5059: Key migration operation. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Process Information: Process ID: 5844 Process Creation Time: 2026-07-14T00:16:16.6092106Z Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: ECDSA_P256 Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Additional Information: Operation: %%2464 Return Code: 0x0
|
| | Security | Audit Success | 12292 | 2026-07-13 17:16:16 | | Microsoft-Windows-Security-Auditing | 5059: Key migration operation. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Process Information: Process ID: 5844 Process Creation Time: 2026-07-14T00:16:16.6092106Z Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: ECDSA_P256 Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Additional Information: Operation: %%2464 Return Code: 0x0
|
| | Security | Audit Success | 13824 | 2026-07-13 17:16:16 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:16:16 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:16:16 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:16:16 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:16:16 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13826 | 2026-07-13 17:16:16 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0x60c Process Name: C:\Windows\System32\svchost.exe
|
| | Security | Audit Success | 12545 | 2026-07-13 17:16:17 | | Microsoft-Windows-Security-Auditing | 4634: An account was logged off. Subject: Security ID: S-1-5-90-0-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0xf871 Logon Type: 2 This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
|
| | Security | Audit Success | 12545 | 2026-07-13 17:16:17 | | Microsoft-Windows-Security-Auditing | 4634: An account was logged off. Subject: Security ID: S-1-5-90-0-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0xf83d Logon Type: 2 This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:16:18 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:16:18 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:16:18 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:16:18 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12544 | 2026-07-13 17:16:20 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:16:20 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12544 | 2026-07-13 17:16:21 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:16:21 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:16:21 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:16:21 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 13826 | 2026-07-13 17:17:51 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0x1790 Process Name: C:\Windows\System32\svchost.exe
|
| | Security | Audit Success | 12544 | 2026-07-13 17:17:52 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:17:52 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 13826 | 2026-07-13 17:17:52 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0xc9c Process Name: C:\Windows\System32\RuntimeBroker.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:17:52 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0xc9c Process Name: C:\Windows\System32\RuntimeBroker.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:17:52 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0xc9c Process Name: C:\Windows\System32\RuntimeBroker.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:17:52 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0xc9c Process Name: C:\Windows\System32\RuntimeBroker.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:17:52 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0xc9c Process Name: C:\Windows\System32\RuntimeBroker.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:17:52 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0xc9c Process Name: C:\Windows\System32\RuntimeBroker.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:17:52 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0xc9c Process Name: C:\Windows\System32\RuntimeBroker.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:17:52 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0xc9c Process Name: C:\Windows\System32\RuntimeBroker.exe
|
| | Security | Audit Success | 12544 | 2026-07-13 17:17:56 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:17:56 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 13568 | 2026-07-13 17:17:56 | | Microsoft-Windows-Security-Auditing | 4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0xe6c Process Information: Process ID: 0x2664 Process Name: C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.26100.8035_none_a54f1c79772e807e\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:(AU;SAFA;0x1f0116;;;WD)
|
| | Security | Audit Success | 13568 | 2026-07-13 17:17:56 | | Microsoft-Windows-Security-Auditing | 4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0xe6c Process Information: Process ID: 0x2664 Process Name: C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.26100.8035_none_a54f1c79772e807e\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:(AU;SAFA;0x1f0116;;;WD)
|
| | Security | Audit Success | 13568 | 2026-07-13 17:17:56 | | Microsoft-Windows-Security-Auditing | 4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_syswow64_21ffbdd2a2dd92e0.cdf-ms Handle ID: 0xe6c Process Information: Process ID: 0x2664 Process Name: C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.26100.8035_none_a54f1c79772e807e\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:(AU;SAFA;0x1f0116;;;WD)
|
| | Security | Audit Success | 13568 | 2026-07-13 17:17:56 | | Microsoft-Windows-Security-Auditing | 4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_syswow64_wbem_1bf25d11bb30b33f.cdf-ms Handle ID: 0xe6c Process Information: Process ID: 0x2664 Process Name: C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.26100.8035_none_a54f1c79772e807e\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:(AU;SAFA;0x1f0116;;;WD)
|
| | Security | Audit Success | 13568 | 2026-07-13 17:17:56 | | Microsoft-Windows-Security-Auditing | 4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_syswow64_wbem_en-us_04f9ae10d0d40b09.cdf-ms Handle ID: 0xe6c Process Information: Process ID: 0x2664 Process Name: C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.26100.8035_none_a54f1c79772e807e\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:(AU;SAFA;0x1f0116;;;WD)
|
| | Security | Audit Success | 13568 | 2026-07-13 17:17:56 | | Microsoft-Windows-Security-Auditing | 4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0xe6c Process Information: Process ID: 0x2664 Process Name: C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.26100.8035_none_a54f1c79772e807e\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:(AU;SAFA;0x1f0116;;;WD)
|
| | Security | Audit Success | 13568 | 2026-07-13 17:17:56 | | Microsoft-Windows-Security-Auditing | 4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_wbem_06656d9fdf2f8577.cdf-ms Handle ID: 0xe6c Process Information: Process ID: 0x2664 Process Name: C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.26100.8035_none_a54f1c79772e807e\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:(AU;SAFA;0x1f0116;;;WD)
|
| | Security | Audit Success | 13568 | 2026-07-13 17:17:56 | | Microsoft-Windows-Security-Auditing | 4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_wbem_en-us_4555b1beb1c13883.cdf-ms Handle ID: 0xe6c Process Information: Process ID: 0x2664 Process Name: C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.26100.8035_none_a54f1c79772e807e\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:(AU;SAFA;0x1f0116;;;WD)
|
| | Security | Audit Success | 13824 | 2026-07-13 17:18:31 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:18:31 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:18:31 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:18:31 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:18:33 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:18:43 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:19:33 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 103 | 2026-07-13 17:19:52 | | Microsoft-Windows-Eventlog | 1100: The event logging service has shut down.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:19:52 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: WIN-SLRHEC6PMT7$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x29c Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12545 | 2026-07-13 17:19:52 | | Microsoft-Windows-Security-Auditing | 4647: User initiated logoff: Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xe7f87 This event is generated when a logoff is initiated. No further user-initiated activity can occur. This event can be interpreted as a logoff event.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:19:52 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 13312 | 2026-07-13 17:29:07 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0xc8 New Process Name: R Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x4 Creator Process Name: Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13312 | 2026-07-13 17:29:07 | | Microsoft-Windows-Security-Auditing | 4696: A primary token was assigned to process. Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Process Information: Process ID: 0x4 Process Name: Target Process: Target Process ID: 0xc8 Target Process Name: Registry New Token Information: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x3e7
|
| | Security | Audit Success | 13312 | 2026-07-13 17:29:07 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x268 New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x4 Creator Process Name: Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13312 | 2026-07-13 17:29:07 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x284 New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x268 Creator Process Name: C Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13312 | 2026-07-13 17:29:07 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x2e8 New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x268 Creator Process Name: C Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13573 | 2026-07-13 17:29:07 | | Microsoft-Windows-Security-Auditing | 4826: Boot Configuration Data loaded. Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 General Settings: Load Options: - Advanced Options: %%1843 Configuration Access Policy: %%1846 System Event Logging: %%1843 Kernel Debugging: %%1843 VSM Launch Type: %%1848 Signature Settings: Test Signing: %%1843 Flight Signing: %%1843 Disable Integrity Checks: %%1843 HyperVisor Settings: HyperVisor Load Options: - HyperVisor Launch Type: %%1848 HyperVisor Debugging: %%1843
|
| | Security | Audit Success | 12288 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4608: Windows is starting up. This event is logged when LSASS.EXE starts and the auditing subsystem is initialized.
|
| | Security | Audit Success | 12290 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 6417: The FIPS mode crypto selftests succeeded. Process ID: 0x3fc Process Name: C:\Windows\System32\lsass.exe
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Logon Information: Logon Type: 0 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: - New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x4 Process Name: Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: - Authentication Package: - Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4648: A logon was attempted using explicit credentials. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Account Whose Credentials Were Used: Account Name: UMFD-0 Account Domain: Font Driver Host Logon GUID: {00000000-0000-0000-0000-000000000000} Target Server: Target Server Name: localhost Additional Information: localhost Process Information: Process ID: 0x34c Process Name: C:\Windows\System32\wininit.exe Network Information: Network Address: - Port: - This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 2 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1842 Elevated Token: %%1843 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-96-0-0 Account Name: UMFD-0 Account Domain: Font Driver Host Logon ID: 0x9b89 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x34c Process Name: C:\Windows\System32\wininit.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4648: A logon was attempted using explicit credentials. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Account Whose Credentials Were Used: Account Name: UMFD-1 Account Domain: Font Driver Host Logon GUID: {00000000-0000-0000-0000-000000000000} Target Server: Target Server Name: localhost Additional Information: localhost Process Information: Process ID: 0x39c Process Name: C:\Windows\System32\winlogon.exe Network Information: Network Address: - Port: - This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 2 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1842 Elevated Token: %%1843 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-96-0-1 Account Name: UMFD-1 Account Domain: Font Driver Host Logon ID: 0x9b6f Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x39c Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-20 Account Name: NETWORK SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e4 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4648: A logon was attempted using explicit credentials. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Account Whose Credentials Were Used: Account Name: DWM-1 Account Domain: Window Manager Logon GUID: {00000000-0000-0000-0000-000000000000} Target Server: Target Server Name: localhost Additional Information: localhost Process Information: Process ID: 0x39c Process Name: C:\Windows\System32\winlogon.exe Network Information: Network Address: - Port: - This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 2 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1842 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-90-0-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0xfe6e Linked Logon ID: 0xfec9 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x39c Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 2 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1842 Elevated Token: %%1843 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-90-0-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0xfec9 Linked Logon ID: 0xfe6e Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x39c Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-20 Account Name: NETWORK SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e4 Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege SeImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-90-0-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0xfe6e Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege SeImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-90-0-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0xfec9 Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege SeImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 13312 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x304 New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x2e8 Creator Process Name: C Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13312 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x344 New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x268 Creator Process Name: C Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13312 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x34c New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x2e8 Creator Process Name: C Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13312 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x354 New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x344 Creator Process Name: C Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13312 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x39c New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x344 Creator Process Name: C Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13312 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x3e8 New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x34c Creator Process Name: C Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13312 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4688: A new process has been created. Creator Subject: Security ID: S-1-5-18 Account Name: - Account Domain: - Logon ID: 0x3e7 Target Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Process Information: New Process ID: 0x3fc New Process Name: C Token Elevation Type: %%1936 Mandatory Label: S-1-16-16384 Creator Process ID: 0x34c Creator Process Name: C Process Command Line: Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy. Type 1 is a full token with no privileges removed or groups disabled. A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account. Type 2 is an elevated token with no privileges removed or groups disabled. An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator. An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group. Type 3 is a limited token with administrative privileges removed and administrative groups disabled. The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
|
| | Security | Audit Success | 13568 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 4902: The Per-user audit policy table was created. Number of Elements: 0 Policy ID: 0x97f6
|
| | Security | Audit Success | 13824 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:29:08 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 12290 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 5061: Cryptographic operation. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f42f Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: ECDSA_P256 Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Cryptographic Operation: Operation: %%2480 Return Code: 0x0
|
| | Security | Audit Success | 12290 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 5061: Cryptographic operation. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: ECDSA_P256 Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Cryptographic Operation: Operation: %%2480 Return Code: 0x0
|
| | Security | Audit Success | 12292 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 5033: The Windows Firewall Driver started successfully.
|
| | Security | Audit Success | 12292 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 5058: Key file operation. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f42f Process Information: Process ID: 1700 Process Creation Time: 2026-07-14T00:29:09.3717814Z Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: UNKNOWN Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Key File Operation Information: File Path: C:\Users\Marius\AppData\Roaming\Microsoft\Crypto\Keys\de7cf8a7901d2ad13e5c67c29e5d1662_e35a81ea-e9f3-46c8-8766-e45e5ee1ea58 Operation: %%2458 Return Code: 0x0
|
| | Security | Audit Success | 12292 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 5059: Key migration operation. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f42f Process Information: Process ID: 1700 Process Creation Time: 2026-07-14T00:29:09.3717814Z Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: ECDSA_P256 Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Additional Information: Operation: %%2464 Return Code: 0x0
|
| | Security | Audit Success | 12292 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 5058: Key file operation. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Process Information: Process ID: 4488 Process Creation Time: 2026-07-14T00:29:09.5148221Z Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: UNKNOWN Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Key File Operation Information: File Path: C:\WINDOWS\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Crypto\Keys\de7cf8a7901d2ad13e5c67c29e5d1662_e35a81ea-e9f3-46c8-8766-e45e5ee1ea58 Operation: %%2458 Return Code: 0x0
|
| | Security | Audit Success | 12292 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 5059: Key migration operation. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Process Information: Process ID: 4488 Process Creation Time: 2026-07-14T00:29:09.5148221Z Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name: ECDSA_P256 Key Name: Microsoft Connected Devices Platform device certificate Key Type: %%2500 Additional Information: Operation: %%2464 Return Code: 0x0
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4648: A logon was attempted using explicit credentials. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Account Whose Credentials Were Used: Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon GUID: {00000000-0000-0000-0000-000000000000} Target Server: Target Server Name: localhost Additional Information: localhost Process Information: Process ID: 0x86c Process Name: C:\Windows\System32\svchost.exe Network Information: Network Address: 127.0.0.1 Port: 0 This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 2 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 Linked Logon ID: 0x1f42f Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x86c Process Name: C:\Windows\System32\svchost.exe Network Information: Workstation Name: DESKTOP-M1V6K8T Source Network Address: 127.0.0.1 Source Port: 0 Detailed Authentication Information: Logon Process: User32 Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 2 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1843 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f42f Linked Logon ID: 0x1f2d1 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x86c Process Name: C:\Windows\System32\svchost.exe Network Information: Workstation Name: DESKTOP-M1V6K8T Source Network Address: 127.0.0.1 Source Port: 0 Detailed Authentication Information: Logon Process: User32 Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 Privileges: SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 13824 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x3fc Process Name: C:\Windows\System32\lsass.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f42f Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f42f Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f42f Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13826 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-20 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e4 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0x560 Process Name: C:\Windows\System32\svchost.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:29:09 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0x7d0 Process Name: C:\Windows\System32\svchost.exe
|
| | Security | Audit Success | 12292 | 2026-07-13 17:29:10 | | Microsoft-Windows-Security-Auditing | 5024: The Windows Firewall service started successfully.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:10 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:10 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:10 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:10 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:10 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:10 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:10 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:10 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 13824 | 2026-07-13 17:29:10 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x514 Process Name: C:\Windows\System32\LogonUI.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:29:10 | | Microsoft-Windows-Security-Auditing | 5382: Vault credentials were read. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 This event occurs when a user reads a stored vault credential.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:11 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:11 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 13824 | 2026-07-13 17:29:11 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:29:11 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:29:11 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:12 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:12 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 13824 | 2026-07-13 17:29:13 | | Microsoft-Windows-Security-Auditing | 4726: A user account was deleted. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 Target Account: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: defaultuser0 Account Domain: DESKTOP-M1V6K8T Additional Information: Privileges -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:29:13 | | Microsoft-Windows-Security-Auditing | 4733: A member was removed from a security-enabled local group. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 Member: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: - Group: Security ID: S-1-5-32-545 Group Name: Users Group Domain: Builtin Additional Information: Privileges: -
|
| | Security | Audit Success | 13826 | 2026-07-13 17:29:13 | | Microsoft-Windows-Security-Auditing | 4729: A member was removed from a security-enabled global group. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 Member: Security ID: S-1-5-21-3469770775-847581034-1203560767-1000 Account Name: - Group: Security ID: S-1-5-21-3469770775-847581034-1203560767-513 Group Name: None Group Domain: DESKTOP-M1V6K8T Additional Information: Privileges: -
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:14 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:14 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:14 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:14 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 13826 | 2026-07-13 17:29:14 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0xd80 Process Name: C:\Windows\System32\svchost.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:29:14 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0x7d0 Process Name: C:\Windows\System32\svchost.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:29:14 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0x1d30 Process Name: C:\Windows\System32\SearchIndexer.exe
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:16 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:16 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:17 | | Microsoft-Windows-Security-Auditing | 4648: A logon was attempted using explicit credentials. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Account Whose Credentials Were Used: Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon GUID: {00000000-0000-0000-0000-000000000000} Target Server: Target Server Name: localhost Additional Information: localhost Process Information: Process ID: 0x86c Process Name: C:\Windows\System32\svchost.exe Network Information: Network Address: 127.0.0.1 Port: 0 This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:17 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 2 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xba7ce Linked Logon ID: 0xba81d Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x86c Process Name: C:\Windows\System32\svchost.exe Network Information: Workstation Name: DESKTOP-M1V6K8T Source Network Address: 127.0.0.1 Source Port: 0 Detailed Authentication Information: Logon Process: User32 Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:17 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 2 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1843 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xba81d Linked Logon ID: 0xba7ce Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x86c Process Name: C:\Windows\System32\svchost.exe Network Information: Workstation Name: DESKTOP-M1V6K8T Source Network Address: 127.0.0.1 Source Port: 0 Detailed Authentication Information: Logon Process: User32 Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:17 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:17 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12545 | 2026-07-13 17:29:17 | | Microsoft-Windows-Security-Auditing | 4634: An account was logged off. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xba81d Logon Type: 2 This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
|
| | Security | Audit Success | 12545 | 2026-07-13 17:29:17 | | Microsoft-Windows-Security-Auditing | 4634: An account was logged off. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xba7ce Logon Type: 2 This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:17 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0xba7ce Privileges: SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:17 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:17 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 13824 | 2026-07-13 17:29:17 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x3fc Process Name: C:\Windows\System32\lsass.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:29:17 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f42f Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:21 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:21 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 13826 | 2026-07-13 17:29:22 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0x1f18 Process Name: C:\Windows\System32\svchost.exe
|
| | Security | Audit Success | 12544 | 2026-07-13 17:29:25 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:29:25 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12544 | 2026-07-13 17:30:06 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:30:06 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 13824 | 2026-07-13 17:30:17 | | Microsoft-Windows-Security-Auditing | 5379: Credential Manager credentials were read. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f42f Read Operation: %%8100 This event occurs when a user performs a read operation on stored credentials in Credential Manager.
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:01 | | Microsoft-Windows-Security-Auditing | 4797: An attempt was made to query the existence of a blank password for an account. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f42f Additional Information: Caller Workstation: DESKTOP-M1V6K8T Target Account Name: Administrator Target Account Domain: DESKTOP-M1V6K8T
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:01 | | Microsoft-Windows-Security-Auditing | 4797: An attempt was made to query the existence of a blank password for an account. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f42f Additional Information: Caller Workstation: DESKTOP-M1V6K8T Target Account Name: DefaultAccount Target Account Domain: DESKTOP-M1V6K8T
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:01 | | Microsoft-Windows-Security-Auditing | 4797: An attempt was made to query the existence of a blank password for an account. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f42f Additional Information: Caller Workstation: DESKTOP-M1V6K8T Target Account Name: Guest Target Account Domain: DESKTOP-M1V6K8T
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:01 | | Microsoft-Windows-Security-Auditing | 4797: An attempt was made to query the existence of a blank password for an account. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f42f Additional Information: Caller Workstation: DESKTOP-M1V6K8T Target Account Name: WDAGUtilityAccount Target Account Domain: DESKTOP-M1V6K8T
|
| | Security | Audit Success | 12544 | 2026-07-13 17:31:09 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:31:09 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12544 | 2026-07-13 17:31:10 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:31:10 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:31:10 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12544 | 2026-07-13 17:31:10 | | Microsoft-Windows-Security-Auditing | 4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: DESKTOP-M1V6K8T$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Information: Logon Type: 5 Restricted Admin Mode: - Remote Credential Guard: - Virtual Account: %%1843 Elevated Token: %%1842 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x3e8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
|
| | Security | Audit Success | 12548 | 2026-07-13 17:31:10 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:31:10 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:31:10 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 12548 | 2026-07-13 17:31:10 | | Microsoft-Windows-Security-Auditing | 4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-500 Account Name: Administrator Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-503 Account Name: DefaultAccount Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-501 Account Name: Guest Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-504 Account Name: WDAGUtilityAccount Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-500 Account Name: Administrator Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-503 Account Name: DefaultAccount Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-501 Account Name: Guest Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-504 Account Name: WDAGUtilityAccount Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-500 Account Name: Administrator Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-500 Account Name: Administrator Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-503 Account Name: DefaultAccount Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-503 Account Name: DefaultAccount Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-501 Account Name: Guest Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-501 Account Name: Guest Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-504 Account Name: WDAGUtilityAccount Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-504 Account Name: WDAGUtilityAccount Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-500 Account Name: Administrator Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-500 Account Name: Administrator Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-501 Account Name: Guest Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-501 Account Name: Guest Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-503 Account Name: DefaultAccount Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-503 Account Name: DefaultAccount Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-500 Account Name: Administrator Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-500 Account Name: Administrator Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-501 Account Name: Guest Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-501 Account Name: Guest Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-503 Account Name: DefaultAccount Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-503 Account Name: DefaultAccount Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-504 Account Name: WDAGUtilityAccount Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-504 Account Name: WDAGUtilityAccount Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13824 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4798: A user's local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 User: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 Group: Security ID: S-1-5-32-544 Group Name: Administrators Group Domain: Builtin Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 Group: Security ID: S-1-5-32-583 Group Name: Device Owners Group Domain: Builtin Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 Group: Security ID: S-1-5-32-562 Group Name: Distributed COM Users Group Domain: Builtin Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 Group: Security ID: S-1-5-32-573 Group Name: Event Log Readers Group Domain: Builtin Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 Group: Security ID: S-1-5-32-546 Group Name: Guests Group Domain: Builtin Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 Group: Security ID: S-1-5-32-578 Group Name: Hyper-V Administrators Group Domain: Builtin Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 Group: Security ID: S-1-5-32-568 Group Name: IIS_IUSRS Group Domain: Builtin Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 Group: Security ID: S-1-5-32-585 Group Name: OpenSSH Users Group Domain: Builtin Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 Group: Security ID: S-1-5-32-559 Group Name: Performance Log Users Group Domain: Builtin Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 Group: Security ID: S-1-5-32-558 Group Name: Performance Monitor Users Group Domain: Builtin Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 Group: Security ID: S-1-5-32-580 Group Name: Remote Management Users Group Domain: Builtin Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 Group: Security ID: S-1-5-32-581 Group Name: System Managed Accounts Group Group Domain: Builtin Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 Group: Security ID: S-1-5-32-584 Group Name: User Mode Hardware Operators Group Domain: Builtin Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | Security | Audit Success | 13826 | 2026-07-13 17:31:51 | | Microsoft-Windows-Security-Auditing | 4799: A security-enabled local group membership was enumerated. Subject: Security ID: S-1-5-21-3469770775-847581034-1203560767-1001 Account Name: Marius Account Domain: DESKTOP-M1V6K8T Logon ID: 0x1f2d1 Group: Security ID: S-1-5-32-545 Group Name: Users Group Domain: Builtin Process Information: Process ID: 0x14b8 Process Name: C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe
|
| | System | Error | None | 2026-07-13 17:12:35 | | Service Control Manager | 7023: The netprofm service terminated with the following error: %%21
|
| | System | Warning | None | 2026-07-13 17:12:48 | | e1i68x64 | 27: Intel(R) Ethernet Connection (19) I219-LM Network link is disconnected.
|
| | System | Error | None | 2026-07-13 17:13:35 | SYSTEM | DCOM | 10010: The server {A47979D2-C419-11D9-A5B4-001185AD2B89} did not register with DCOM within the required timeout.
|
| | System | Warning | None | 2026-07-13 17:13:50 | | e1i68x64 | 27: Intel(R) Ethernet Connection (19) I219-LM Network link is disconnected.
|
| | System | Warning | None | 2026-07-13 17:13:56 | LOCAL SERVICE | Microsoft-Windows-Time-Service | 134: NtpClient was unable to set a manual peer to use as a time source because of DNS resolution error on 'time.windows.com,0x9'. NtpClient will try again in 15 minutes and double the reattempt interval thereafter. The error was: No such host is known. (0x80072AF9)
|
| | System | Warning | None | 2026-07-13 17:13:58 | LOCAL SERVICE | Microsoft-Windows-Time-Service | 134: NtpClient was unable to set a manual peer to use as a time source because of DNS resolution error on 'time.windows.com,0x9'. NtpClient will try again in 15 minutes and double the reattempt interval thereafter. The error was: No such host is known. (0x80072AF9)
|
| | System | Error | None | 2026-07-13 17:15:57 | | Service Control Manager | 7030: The Printer Extensions and Notifications service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
|
| | System | Error | None | 2026-07-13 17:18:57 | SYSTEM | Microsoft-Windows-TPM-WMI | 1796: The Secure Boot update failed to update DBX with error -2147020471. For more information, please see https://go.microsoft.com/fwlink/?linkid=2169931
|
| | System | Error | None | 2026-07-13 17:18:57 | SYSTEM | Microsoft-Windows-TPM-WMI | 1796: The Secure Boot update failed to update SBAT with error -2147020471. For more information, please see https://go.microsoft.com/fwlink/?linkid=2169931
|
| | System | Error | None | 2026-07-13 17:19:47 | Marius | DCOM | 10010: The server {544C4C52-DE0B-4D14-9510-21745381D5CA} did not register with DCOM within the required timeout.
|
| | System | Warning | None | 2026-07-13 17:19:52 | SYSTEM | winsrvext | 100: Process C:\Users\Marius\AppData\Local\Microsoft\OneDrive\25.087.0506.0001\Microsoft.SharePoint.exe is delaying system shutdown after 5032 milliseconds.
|
| | System | Warning | None | 2026-07-13 17:19:52 | SYSTEM | winsrvext | 100: Process C:\Users\Marius\AppData\Local\Microsoft\OneDrive\OneDrive.exe is delaying system shutdown after 5032 milliseconds.
|
| | System | Warning | None | 2026-07-13 17:29:08 | | e1i68x64 | 27: Intel(R) Ethernet Connection (19) I219-LM Network link is disconnected.
|
| | System | Error | None | 2026-07-13 17:29:11 | Marius | DCOM | 10001: Unable to start a DCOM Server: {297FDBDE-595D-4083-82B1-768BEE65F6C9} as Unavailable/Unavailable. The error: "2147943631" Happened while starting this command: "C:\Program Files\WindowsApps\Microsoft.WidgetsPlatformRuntime_1.6.14.0_x64__8wekyb3d8bbwe\WidgetService\WidgetService.exe" -RegisterProcessAsComServer -Embedding
|
| | System | Error | None | 2026-07-13 17:29:11 | Marius | DCOM | 10001: Unable to start a DCOM Server: {3E11DF0F-42EB-4747-9A35-802D98B5BCF0} as Unavailable/Unavailable. The error: "2147943631" Happened while starting this command: "C:\Program Files\WindowsApps\Microsoft.WidgetsPlatformRuntime_1.6.14.0_x64__8wekyb3d8bbwe\WidgetService\WidgetService.exe" -RegisterProcessAsComServer -Embedding
|
| | System | Error | None | 2026-07-13 17:29:11 | Marius | DCOM | 10001: Unable to start a DCOM Server: {3E11DF0F-42EB-4747-9A35-802D98B5BCF0} as Unavailable/Unavailable. The error: "2147943631" Happened while starting this command: "C:\Program Files\WindowsApps\Microsoft.WidgetsPlatformRuntime_1.6.14.0_x64__8wekyb3d8bbwe\WidgetService\WidgetService.exe" -RegisterProcessAsComServer -Embedding
|
| | System | Error | None | 2026-07-13 17:29:11 | Marius | DCOM | 10001: Unable to start a DCOM Server: {3E11DF0F-42EB-4747-9A35-802D98B5BCF0} as Unavailable/Unavailable. The error: "2147943631" Happened while starting this command: "C:\Program Files\WindowsApps\Microsoft.WidgetsPlatformRuntime_1.6.14.0_x64__8wekyb3d8bbwe\WidgetService\WidgetService.exe" -RegisterProcessAsComServer -Embedding
|
| | System | Error | None | 2026-07-13 17:29:12 | Marius | DCOM | 10001: Unable to start a DCOM Server: {740FE937-01F7-4482-AA62-C83F0AD3D6D0} as Unavailable/Unavailable. The error: "2147943631" Happened while starting this command: "C:\Program Files\WindowsApps\Microsoft.WidgetsPlatformRuntime_1.6.14.0_x64__8wekyb3d8bbwe\WidgetService\WidgetService.exe" -RegisterProcessAsComServer -Embedding
|
| | System | Error | None | 2026-07-13 17:29:12 | Marius | DCOM | 10001: Unable to start a DCOM Server: {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} as Unavailable/Unavailable. The error: "2147943631" Happened while starting this command: "C:\Program Files\WindowsApps\Microsoft.WidgetsPlatformRuntime_1.6.14.0_x64__8wekyb3d8bbwe\WidgetService\WidgetService.exe" -RegisterProcessAsComServer -Embedding
|
| | System | Error | None | 2026-07-13 17:29:17 | Marius | DCOM | 10001: Unable to start a DCOM Server: {297FDBDE-595D-4083-82B1-768BEE65F6C9} as Unavailable/Unavailable. The error: "2147943631" Happened while starting this command: "C:\Program Files\WindowsApps\Microsoft.WidgetsPlatformRuntime_1.6.14.0_x64__8wekyb3d8bbwe\WidgetService\WidgetService.exe" -RegisterProcessAsComServer -Embedding
|
| | System | Error | None | 2026-07-13 17:29:17 | Marius | DCOM | 10001: Unable to start a DCOM Server: {3E11DF0F-42EB-4747-9A35-802D98B5BCF0} as Unavailable/Unavailable. The error: "2147943631" Happened while starting this command: "C:\Program Files\WindowsApps\Microsoft.WidgetsPlatformRuntime_1.6.14.0_x64__8wekyb3d8bbwe\WidgetService\WidgetService.exe" -RegisterProcessAsComServer -Embedding
|
| | System | Error | None | 2026-07-13 17:29:17 | Marius | DCOM | 10001: Unable to start a DCOM Server: {3E11DF0F-42EB-4747-9A35-802D98B5BCF0} as Unavailable/Unavailable. The error: "2147943631" Happened while starting this command: "C:\Program Files\WindowsApps\Microsoft.WidgetsPlatformRuntime_1.6.14.0_x64__8wekyb3d8bbwe\WidgetService\WidgetService.exe" -RegisterProcessAsComServer -Embedding
|
| | System | Error | None | 2026-07-13 17:29:18 | Marius | DCOM | 10001: Unable to start a DCOM Server: {3E11DF0F-42EB-4747-9A35-802D98B5BCF0} as Unavailable/Unavailable. The error: "2147943631" Happened while starting this command: "C:\Program Files\WindowsApps\Microsoft.WidgetsPlatformRuntime_1.6.14.0_x64__8wekyb3d8bbwe\WidgetService\WidgetService.exe" -RegisterProcessAsComServer -Embedding
|
| | System | Error | None | 2026-07-13 17:29:19 | Marius | DCOM | 10001: Unable to start a DCOM Server: {740FE937-01F7-4482-AA62-C83F0AD3D6D0} as Unavailable/Unavailable. The error: "2147943631" Happened while starting this command: "C:\Program Files\WindowsApps\Microsoft.WidgetsPlatformRuntime_1.6.14.0_x64__8wekyb3d8bbwe\WidgetService\WidgetService.exe" -RegisterProcessAsComServer -Embedding
|
| | System | Error | None | 2026-07-13 17:29:19 | Marius | DCOM | 10001: Unable to start a DCOM Server: {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} as Unavailable/Unavailable. The error: "2147943631" Happened while starting this command: "C:\Program Files\WindowsApps\Microsoft.WidgetsPlatformRuntime_1.6.14.0_x64__8wekyb3d8bbwe\WidgetService\WidgetService.exe" -RegisterProcessAsComServer -Embedding
|
| | System | Warning | None | 2026-07-13 17:31:10 | SYSTEM | DCOM | 10016: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID Windows.SecurityCenter.WscBrokerManager and APPID Unavailable to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
|
| | System | Warning | None | 2026-07-13 17:31:10 | SYSTEM | DCOM | 10016: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID Windows.SecurityCenter.SecurityAppBroker and APPID Unavailable to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
|
| | System | Warning | None | 2026-07-13 17:31:10 | SYSTEM | DCOM | 10016: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID Windows.SecurityCenter.WscDataProtection and APPID Unavailable to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
|