Groups
Groups
Sign in
Groups
Groups
Wazuh | Mailing List
Conversations
About
Send feedback
Help
Failed attempt to perform a privileged operation." event on daily basics,
279 views
Skip to first unread message
Chetan Hiremath
unread,
Mar 2, 2023, 6:02:27 AM
3/2/23
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Wazuh mailing list
Hello Team
I am receiving several count of "Failed attempt to perform a privileged operation." event on daily basics,
Message I am getting in the log.
A privileged service was called. Subject: Security ID: S-1-5-21-1106476451-4122483766-1007359441-1023 Account Name: SPP00018 Account Domain: SP-JUMP Logon ID: 0x2456776F Service: Server: Security Service Name: - Process: Process ID: 0x28c4 Process Name: C:\Windows\explorer.exe Service Request Information: Privileges: SeTcbPrivilege"
Kindly help me to understand why this events are getting generated ?
Eduardo Leon Aldazoro
unread,
Mar 2, 2023, 8:06:38 AM
3/2/23
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Wazuh mailing list
Hi Chetan Thanks for using Wazuh!
Can you please provide me with the following data:
-
data.win.system.severityValue
-
data.win.system.eventID
-rule.groups
-data.win.system.providerName
-
data.win.system.level
I'll be waiting for you to reply.
Thank you.
Best Regards,
Chetan Hiremath
unread,
Mar 6, 2023, 2:01:52 AM
3/6/23
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Wazuh mailing list
Hello Eduardo,
Sorry for the delay
data.win.system.severityValue - Audit-Failure.
data.win.system.eventID - 4673
rule.groups - windows, windows
security
data.win.system.providerName - Microsoft-windows-
Security-auditing
data.win.system.level - 0
Abdulaziz Aljaberi
unread,
Oct 25, 2023, 9:36:08 AM
10/25/23
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Wazuh | Mailing List
Dear
Eduardo Leon Aldazoro,
I'm facing the same issue, and below are the details requested from your side.
data.win.eventdata.privilegeList:
SeProfileSingleProcessPrivilege
data.win.eventdata.processId:
0x3988
data.win.eventdata.processName:
C:\\Users\\m.aldakheel\\AppData\\Local\\Microsoft\\Teams\\current\\Teams.exe
data.win.system.severityValue:
AUDIT_FAILURE
data.win.system.eventID:
4673
data.win.system.providerName:
Microsoft-Windows-Security-Auditing
rule.groups:
windows, windows_security
data.win.system.level:
0
can anyone please help us solve this issue?
Reply all
Reply to author
Forward
0 new messages