data.win.eventdata.objectServer
Security
data.win.eventdata.privilegeList
SeTcbPrivilege
data.win.eventdata.processId
0x3df0
data.win.eventdata.processName
C:\\Windows\\System32\\svchost.exe
data.win.eventdata.subjectDomainName
LAPTOP-T061QVF1
data.win.eventdata.subjectLogonId
0x167390
data.win.eventdata.subjectUserName
abi
data.win.eventdata.subjectUserSid
value-0---------------------------------
Security
LAPT----------------------------
4673
data.win.system.eventRecordID
29320513
0x8010000000000000
0
"A privileged service was called.
Subject:
Security ID: --------------- Account Name: -------- Account Domain: --------- Logon ID: 0x167390
Service:
Server: Security
Service Name: -
Process:
Process ID: 0x3df0
Process Name: C:\Windows\System32\svchost.exe
Service Request Information:
Privileges: SeTcbPrivilege"
0
data.win.system.processID
4
data.win.system.providerGuid
------------------------------
data.win.system.providerName
Microsoft-Windows-Security-Auditing
data.win.system.severityValue
AUDIT_FAILURE
data.win.system.systemTime
2022-12-12T14:49:54.5053235Z
13056
34548
0
windows_eventchannel
1670856595.289555664
log
EventChannel
wazuh-server
Failed attempt to perform a privileged operation.
4,447
IV_32.2
windows, windows_security