Windows
application
Field | Data Type | Event IDs | Example |
---|---|---|---|
Application | string | 1, 2 | |
Computer | string | 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 15, 16, 17, 18, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 38, 43, 45, 47, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 256, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 637, 641, 642, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 781, 852, 854, 865, 866, 867, 868, 873, 882, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1010, 1012, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1041, 1042, 1043, 1044, 1061, 1066, 1109, 1114, 1130, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1511, 1512, 1514, 1515, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 1704, 1903, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2080, 2303, 2484, 2486, 3001, 3002, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4121, 4128, 4129, 4176, 4177, 4178, 4202, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 4879, 5000, 5001, 5008, 5602, 5604, 5605, 5606, 5611, 5612, 5615, 5617, 5631, 5973, 6000, 6003, 6253, 6527, 7000, 7002, 8192, 8193, 8194, 8195, 8196, 8198, 8199, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 8303, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | windowsvictim |
Event | string | 1, 3, 4, 5 | |
EventID | integer | 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 15, 16, 17, 18, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 38, 43, 45, 47, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 256, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 637, 641, 642, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 781, 852, 854, 865, 866, 867, 868, 873, 882, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1010, 1012, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1041, 1042, 1043, 1044, 1061, 1066, 1109, 1114, 1130, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1511, 1512, 1514, 1515, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 1704, 1903, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2080, 2303, 2484, 2486, 3001, 3002, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4121, 4128, 4129, 4176, 4177, 4178, 4202, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 4879, 5000, 5001, 5008, 5602, 5604, 5605, 5606, 5611, 5612, 5615, 5617, 5631, 5973, 6000, 6003, 6253, 6527, 7000, 7002, 8192, 8193, 8194, 8195, 8196, 8198, 8199, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 8303, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 9689 |
File | string | 1508, 1509, 1514, 10002, 10003, 10006, 10007 | C:\Users\user2\ntuser.dat |
FileName | string | 1, 10009 | |
Name | string | 0, 1, 2, 3, 4, 5, 11, 13, 15, 16, 26, 30, 32, 34, 35, 38, 45, 47, 48, 63, 64, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 637, 641, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1552, 1704, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5000, 5001, 5008, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | "edgeupdate" |
Object | string | 4, 8 | |
Path | string | 0, 5, 9 | |
Service | string | 1008, 1020, 10009 | BITS |
Source | string | 1509, 1600, 1601 | |
Target | string | 1509, 1600, 1601 | |
Task | integer | 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 9 |
Task | string | 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 15, 16, 17, 18, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 38, 43, 45, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 92, 100, 101, 102, 103, 105, 198, 200, 256, 257, 300, 301, 302, 326, 330, 335, 455, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 641, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 865, 866, 867, 868, 882, 900, 902, 903, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1010, 1012, 1013, 1020, 1022, 1025, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1041, 1042, 1043, 1044, 1066, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1512, 1514, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 1704, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2484, 2486, 3001, 3002, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4128, 4129, 4176, 4177, 4178, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 5000, 5001, 5008, 5602, 5604, 5605, 5606, 5612, 5615, 5617, 5631, 5973, 6000, 7000, 7002, 8192, 8194, 8199, 8212, 8216, 8224, 8225, 8300, 8301, 8302, 8303, 9027, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 11707, 11728, 11756, 12116, 16384, 16390, 16394, 20221, 20222, 20223, 20224, 20225, 20226 | |
Text | string | 81, 82, 83 | |
User | string | 5 | WINDEV2202EVAL\user2 |
action | string | 642, 4879 | unknown |
file | string | 3 | |
hr | string | 27, 28, 29, 31, 33, 34 | |
id | integer | 0, 1, 2, 3, 4, 5, 11, 13, 15, 16, 26, 30, 32, 34, 35, 38, 45, 47, 48, 63, 64, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 637, 641, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1552, 1704, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5000, 5001, 5008, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 9617 |
line | string | 3 | |
name | string | 637, 641, 642, 852, 4625, 4879 | User Account Changed |
status | string | 4, 7, 8, 9 | unknown |
ActivityID | string | 64, 900, 902, 903, 1003, 1004, 1008, 1013, 1020, 1033, 1034, 1040, 1066, 1531, 1532, 1552, 4097, 4109, 4111, 4625, 5611, 5615, 5617, 6000, 8224, 8300, 8301, 8302, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 16384, 16390, 16394 | "9AEFBC8D-3E49-4448-B988-5F313E7F68B0" |
AdditionalDetails | string | 1 | |
AddonName | string | 1, 2 | |
AppId | string | 3, 5, 7, 9 | |
AppName | string | 1, 2, 3, 10001, 10002 | |
AppNameCount | string | 1, 2, 3 | |
AppType | string | 10002, 10003, 10006, 10007, 10010 | |
AppVersion | string | 10002, 10003, 10006, 10007, 10010 | |
ApplicationId | string | 5, 5, 6 | |
ApplicationName | string | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11 | C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted |
ApplicationPool | string | 0, 2, 3, 3 | MSExchangeOABAppPool |
Applications | string | 0, 0, 0, 1, 5 | |
AttemptedPath | string | 50, 865, 866, 867, 868, 882 | |
AuthorId | string | 2001, 2002, 3002 | |
BackupFailureLogPath | string | 4, 5, 7 | |
BackupFile | string | 67, 68, 5602 | |
BackupRepository | string | 66, 5604 | |
BackupSourceNumUnreadableBytes | string | 2, 5, 5 | |
BackupTarget | string | 2, 3, 5 | |
BackupTargetFriendlyName | string | 522, 564, 658 | |
BackupTargetList | string | 608, 609, 611 | |
BackupTime | string | 517, 518, 519, 521, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611 | |
BackupUserName | string | 4, 5, 6 | |
BufferSize | integer | 0, 0, 1, 2 | |
CVEID | string | 1 | |
Caption | string | 81, 82, 83 | |
CatalogName | string | 1, 1, 2, 4 | SystemIndex |
CategoryString | string | 637, 641, 642 | Account Management |
Channel | string | 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 15, 16, 17, 18, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 38, 43, 45, 47, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 256, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 637, 641, 642, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 781, 852, 854, 865, 866, 867, 868, 873, 882, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1010, 1012, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1041, 1042, 1043, 1044, 1061, 1066, 1109, 1114, 1130, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1511, 1512, 1514, 1515, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 1704, 1903, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2080, 2303, 2484, 2486, 3001, 3002, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4121, 4128, 4129, 4176, 4177, 4178, 4202, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 4879, 5000, 5001, 5008, 5602, 5604, 5605, 5606, 5611, 5612, 5615, 5617, 5631, 5973, 6000, 6003, 6253, 6527, 7000, 7002, 8192, 8193, 8194, 8195, 8196, 8198, 8199, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 8303, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | Application |
Class | string | 24, 25, 58, 59, 5631 | |
Component | string | 1, 3, 4, 5 | |
ComponentName | string | 5, 5, 6 | |
ContentType | string | 1 | |
Context | string | 64, 86 | Système local |
CurDirDllPath | string | 11, 12 | |
DBType | string | 1, 2, 3 | |
Detail | string | 0, 1, 3, 5 | 1 user registry handles leaked from \Registry\User\S-1-5-21-712794737-353456615-3249761964-1001: |
DisplayName | string | 10002, 10003, 10006, 10007, 10010 | |
Error | string | 4, 10, 11, 12, 13, 22, 43, 48, 68, 502, 513, 515, 517, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1512, 1519, 1520, 1521, 1522, 1523, 1533, 1534, 1537, 1538, 1539, 1541, 1542, 3001, 5604 | The process cannot access the file because it is being used by another process. |
ErrorCode | string | 9, 86, 502, 517, 518, 519, 521, 526, 527, 528, 544, 546, 565, 707, 708, 722, 723, 738, 739, 770, 773, 774, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1010, 1012, 1041, 1042, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 5973, 8301, 8302, 8303 | Non trouvé (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND) |
ErrorDetails | string | 502, 503, 505, 506, 507, 508, 509, 511, 513, 515, 517 | |
ErrorMessage | string | 517, 518, 519, 521, 527, 528, 544, 546, 707, 708, 722, 723, 738, 739, 770, 773, 774, 1041, 1042 | |
ErrorMsg | string | 1002, 1003, 1004, 1005, 1006, 1007, 1010, 1012 | |
ErrorNumber | string | 28, 29 | |
ErrorString | string | 10, 11, 12 | |
Error_Code | integer | 0, 1, 5, 9 | 3221225539 |
Error_Code | string | 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | - |
EventCode | integer | 0, 1, 2, 3, 4, 5, 11, 13, 15, 16, 26, 30, 32, 34, 35, 38, 45, 47, 48, 63, 64, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 637, 641, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1552, 1704, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5000, 5001, 5008, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 9689 |
EventData_Xml | string | 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1530, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | mardi 16 mars 2021 08:29:24 |
EventProvider | string | 21, 22, 23, 24, 25 | |
EventRecordID | integer | 0, 1, 2, 3, 4, 5, 11, 13, 15, 16, 26, 30, 32, 34, 35, 38, 45, 47, 48, 63, 64, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 637, 641, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1552, 1704, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5000, 5001, 5008, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 9617 |
EventSourceName | string | 5, 64, 86, 781, 900, 902, 903, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1024, 1025, 1029, 1033, 1034, 1040, 1061, 1066, 2303, 3036, 3079, 4097, 4100, 4101, 4102, 4107, 4108, 4109, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5615, 5617, 6000, 6003, 8198, 8200, 8230, 10024, 12288, 12290, 16384, 16388, 16390, 16394 | "Wlclntfy" |
ExpectedInterfaceID | string | 0, 1 | |
ExtraInfo | string | 3036, 3079 | Context: Windows Application |
FailedBinary | string | 9 | |
FailedVolumeNames | string | 519, 547 | |
FailureReason | string | 0, 1 | |
FileNumber | string | 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418 | |
FilesCachedFirstPass | string | 8301, 8302, 8303 | |
FilesMissedSecondPass | string | 8301, 8302, 8303 | |
FilesResident | string | 8301, 8302, 8303 | |
FilesScoped | string | 8301, 8302, 8303 | |
FilterHostProcessID | integer | 0, 0, 1, 2, 4 | 4860 |
First | string | 16, 33, 34 | |
Flags | string | 0, 0, 1, 3 | |
Folder | string | 505, 506, 507, 508, 509, 514, 515, 516, 517, 1533, 1535, 1536, 1537, 1538, 1539, 1543 | C:\Users\TEMP |
FolderPath | string | 2, 2 | |
FolderString | string | 1, 3 | |
FoundDllPath | string | 1, 1 | |
FromFolder | string | 501, 502, 512, 513 | |
FullPath | string | 10002, 10003, 10006, 10007, 10010 | |
Guid | string | 5, 11, 64, 86, 781, 900, 902, 903, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1020, 1024, 1025, 1029, 1033, 1034, 1040, 1061, 1066, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1552, 2303, 3036, 3079, 4097, 4100, 4101, 4102, 4107, 4108, 4109, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 8198, 8200, 8230, 8300, 8301, 8302, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 10024, 12288, 12290, 16384, 16388, 16390, 16394 | "{e23b33b0-c8c9-472c-a5f9-f2bdfea0f156}" |
HandleInstallErrorCode | string | 5, 5, 7 | |
HostName | string | 4097, 4098, 4099, 4100 | |
HostProcessID | string | 1, 2, 5, 6 | |
Hresult | string | 2 | |
ImportDllName | string | 0, 1 | |
InterfaceGUID | string | 2, 3, 5, 7, 8 | |
InterfaceId | string | 1, 1 | 3F31C91E-2545-4B7B-9311-9529E8BFFEF6 |
InterferingImageName | string | 1545, 1552 | C:\Users\User\Downloads\ProfSvcLPE.exe |
InterferingPID | integer | 1, 4, 5, 5 | 4336 |
InterferingPID | string | 1545, 1552 | |
Keywords | string | 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 15, 16, 17, 18, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 38, 43, 45, 47, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 256, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 637, 641, 642, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 781, 852, 854, 865, 866, 867, 868, 873, 882, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1010, 1012, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1041, 1042, 1043, 1044, 1061, 1066, 1109, 1114, 1130, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1511, 1512, 1514, 1515, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 1704, 1903, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2080, 2303, 2484, 2486, 3001, 3002, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4121, 4128, 4129, 4176, 4177, 4178, 4202, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 4879, 5000, 5001, 5008, 5602, 5604, 5605, 5606, 5611, 5612, 5615, 5617, 5631, 5973, 6000, 6003, 6253, 6527, 7000, 7002, 8192, 8193, 8194, 8195, 8196, 8198, 8199, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 8303, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 0x8080000000000000 |
Level | integer | 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 15, 16, 17, 18, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 38, 43, 45, 47, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 256, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 637, 641, 642, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 781, 852, 854, 865, 866, 867, 868, 873, 882, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1010, 1012, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1041, 1042, 1043, 1044, 1061, 1066, 1109, 1114, 1130, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1511, 1512, 1514, 1515, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 1704, 1903, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2080, 2303, 2484, 2486, 3001, 3002, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4121, 4128, 4129, 4176, 4177, 4178, 4202, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 4879, 5000, 5001, 5008, 5602, 5604, 5605, 5606, 5611, 5612, 5615, 5617, 5631, 5973, 6000, 6003, 6253, 6527, 7000, 7002, 8192, 8193, 8194, 8195, 8196, 8198, 8199, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 8303, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 4 |
Library | string | 1008, 1020 | C:\Windows\System32\bitsperf.dll |
LineNumber | string | 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418 | |
LogicalPath | string | 5, 5, 6 | |
MOF | string | 4 | |
MachineKeys | string | 0, 1, 5, 9 | BCD00000000, COMPONENTS, |
MachineName | string | 2, 3, 5 | |
Message | string | 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 16, 17, 18, 20, 21, 22, 23, 24, 25, 27, 28, 29, 31, 33, 34, 43, 48, 50, 58, 59, 63, 66, 67, 68, 81, 82, 83, 256, 257, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 865, 866, 867, 868, 882, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1010, 1012, 1040, 1041, 1042, 1043, 1044, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1512, 1514, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2484, 2486, 3001, 3002, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4128, 4129, 4176, 4177, 4178, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 5602, 5604, 5605, 5606, 5612, 5631, 5973, 7000, 7002, 8192, 8199, 8300, 8301, 8302, 8303, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010 | |
MessageText | string | 6, 8 | GetCACaps |
Method | integer | 1, 1 | 10 |
Method | string | 11, 86 | GET(250ms) |
MethodString | string | 0, 0, 1, 3 | |
ModuleName | string | 0, 0, 1, 3 | |
NTSTATUS | integer | 1000, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 8199 | |
Namespace | string | 10, 22, 23, 24, 43, 48, 63, 5605, 5606 | |
ObjId | string | 4, 6 | |
Opcode | integer | 1, 3, 5, 11, 13, 15, 16, 86, 100, 102, 103, 105, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1024, 1025, 1026, 1029, 1033, 1034, 1038, 1040, 1042, 1061, 1066, 1109, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 2001, 2303, 3036, 3079, 3408, 4097, 4100, 4101, 4102, 4107, 4108, 4109, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8195, 8198, 8200, 8224, 8225, 8230, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 0 |
Opcode | string | 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 16, 17, 18, 20, 21, 22, 23, 24, 25, 27, 28, 29, 31, 33, 34, 43, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 256, 257, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 865, 866, 867, 868, 882, 900, 902, 903, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1010, 1012, 1013, 1020, 1033, 1034, 1040, 1041, 1042, 1043, 1044, 1066, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1512, 1514, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2484, 2486, 3001, 3002, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4128, 4129, 4176, 4177, 4178, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 5602, 5604, 5605, 5606, 5612, 5615, 5617, 5631, 5973, 6000, 7000, 7002, 8192, 8199, 8224, 8300, 8301, 8302, 8303, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 16384, 16390, 16394 | |
Operation | string | 20, 21, 23, 24 | |
OperationError | string | 20, 21, 23, 24 | |
Options | string | 501, 502, 512, 513, 514, 515, 516, 517 | |
PackageFamily | string | 20, 21, 23, 24 | |
PackageFullName | string | 9 | |
PackageString | string | 1, 3 | |
Parameter | string | 0, 1, 5 | |
Pid | string | 10002, 10003, 10006, 10007, 10010 | |
ProcessID | string | 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 15, 16, 17, 18, 20, 21, 22, 23, 24, 25, 27, 28, 29, 31, 33, 34, 43, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 86, 100, 102, 103, 105, 256, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 642, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 781, 852, 854, 865, 866, 867, 868, 873, 882, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1010, 1012, 1013, 1014, 1016, 1020, 1024, 1025, 1026, 1029, 1033, 1034, 1038, 1040, 1041, 1042, 1043, 1044, 1061, 1066, 1109, 1130, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1511, 1512, 1514, 1515, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2303, 2484, 2486, 3001, 3002, 3036, 3079, 3408, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4121, 4128, 4129, 4176, 4177, 4178, 4202, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 4879, 5602, 5604, 5605, 5606, 5611, 5612, 5615, 5617, 5631, 5973, 6000, 6003, 6253, 6527, 7000, 7002, 8192, 8193, 8195, 8198, 8199, 8200, 8224, 8225, 8230, 8300, 8301, 8302, 8303, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | "9576" |
ProcessId | integer | 1, 3, 5, 11, 13, 15, 16, 86, 100, 102, 103, 105, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1024, 1025, 1026, 1029, 1033, 1034, 1038, 1040, 1042, 1061, 1066, 1109, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 2001, 2303, 3036, 3079, 3408, 4097, 4100, 4101, 4102, 4107, 4108, 4109, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8195, 8198, 8200, 8224, 8225, 8230, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 9576 |
ProcessId | string | 2, 3, 4, 5, 6, 7, 8, 9, 10, 11 | |
ProcessImagePath | string | 10, 11, 12 | |
ProfsvcPID | integer | 1, 4, 5, 5 | 1716 |
ProfsvcPID | string | 1545, 1552 | |
Provider | string | 3, 6 | |
ProviderGUID | string | 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 16, 17, 18, 20, 21, 22, 23, 24, 25, 27, 28, 29, 31, 33, 34, 43, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 256, 257, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 865, 866, 867, 868, 882, 900, 902, 903, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1010, 1012, 1013, 1020, 1033, 1034, 1040, 1041, 1042, 1043, 1044, 1066, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1512, 1514, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2484, 2486, 3001, 3002, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4128, 4129, 4176, 4177, 4178, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 5602, 5604, 5605, 5606, 5612, 5615, 5617, 5631, 5973, 6000, 7000, 7002, 8192, 8199, 8300, 8301, 8302, 8303, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 16384, 16390, 16394 | |
ProviderIconId | string | 0, 1, 4, 4 | |
ProviderName | string | 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 16, 17, 18, 20, 21, 22, 23, 24, 25, 27, 28, 29, 31, 33, 34, 43, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 256, 257, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 865, 866, 867, 868, 882, 900, 902, 903, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1010, 1012, 1013, 1020, 1033, 1034, 1040, 1041, 1042, 1043, 1044, 1066, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1512, 1514, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2484, 2486, 3001, 3002, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4128, 4129, 4176, 4177, 4178, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 5602, 5604, 5605, 5606, 5612, 5615, 5617, 5631, 5973, 6000, 7000, 7002, 8192, 8199, 8300, 8301, 8302, 8303, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 16384, 16390, 16394 | |
ProviderNameId | string | 0, 1, 4, 4 | |
ProvidersInHost | string | 1, 2, 5, 6 | |
PsmKey | string | 2484, 2486 | |
Publisher | string | 1, 2 | |
Qualifiers | string | 0, 1, 2, 3, 4, 5, 13, 15, 16, 26, 30, 32, 34, 35, 38, 45, 47, 48, 63, 64, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 637, 641, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1704, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5000, 5001, 5008, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8216, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | "49754" |
Query | string | 10, 21, 22, 23, 24, 25 | |
QuotaName | string | 1, 2, 5, 6 | |
QuotaThreshold | string | 1, 2, 5, 6 | |
QuotaValue | string | 1, 2, 5, 6 | |
Reason | string | 1004, 1008, 7000, 7002, 10010 | Full Index Reset |
ReceivedInterfaceID | string | 0, 1 | |
RecordNumber | integer | 0, 1, 2, 3, 4, 5, 11, 13, 15, 16, 26, 30, 32, 34, 35, 38, 45, 47, 48, 63, 64, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 637, 641, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1552, 1704, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5000, 5001, 5008, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 9617 |
RelatedActivityID | string | 64, 900, 902, 903, 1003, 1004, 1013, 1020, 1033, 1034, 1040, 1066, 1531, 1532, 1552, 4097, 4109, 4111, 4625, 5615, 5617, 6000, 8224, 8300, 8301, 8302, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 16384, 16390, 16394 | |
RepairTriggerError | string | 21, 24 | |
RequiredSize | integer | 0, 0, 1, 2 | |
ResourceDll | string | 0, 1, 4, 4 | |
ResponseTime | string | 0, 0, 0, 1, 1 | |
RestoreTargetNameList | string | 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 1040, 1041, 1042, 1043 | |
RestoreTime | string | 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 769, 770, 771, 772, 773, 774, 1040, 1041, 1042, 1043 | |
Result | string | 5, 8 | |
RmSessionId | string | 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010 | |
RulePath | string | 6, 6, 8 | |
Second | string | 16, 33, 34 | |
SessionID | string | 1, 2, 3 | |
SessionId | string | 0, 1, 2, 3, 15, 16, 26, 30, 32, 34, 35, 38, 45, 63, 64, 92, 100, 101, 102, 103, 105, 198, 200, 300, 301, 302, 326, 330, 335, 455, 641, 900, 902, 903, 1000, 1003, 1004, 1013, 1020, 1022, 1025, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1042, 1066, 1531, 1532, 1552, 1704, 4097, 4098, 4109, 4111, 4625, 5000, 5001, 5008, 5615, 5617, 6000, 8194, 8212, 8216, 8224, 8225, 8300, 8301, 8302, 9027, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 11707, 11728, 11756, 12116, 16384, 16390, 16394, 20221, 20222, 20223, 20224, 20225, 20226 | |
SigmaEventCode | integer | 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 9689 |
SnapinId | string | 0, 1, 4, 4 | |
SnapshotPath | string | 8300, 8301, 8302, 8303 | |
SrpRuleGuid | string | 50, 866, 868, 882 | |
Stage | string | 6, 8 | GetCACaps |
Status | integer | 0, 1, 5, 9 | 3221225539 |
Status | string | 1509, 10002, 10003, 10006, 10007, 10010 | |
String | string | 2 | |
Summary | string | 1, 2, 3 | |
SummaryCount | string | 1, 2, 3 | |
SvcHostPid | string | 0, 0, 0, 1, 9 | |
SystemTime | string | 0, 1, 2, 3, 4, 5, 11, 13, 15, 16, 26, 30, 32, 34, 35, 38, 45, 47, 48, 63, 64, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 637, 641, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1552, 1704, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5000, 5001, 5008, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | '2022-07-26 17:31:46.583705 UTC' |
System_Props_Xml | string | 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 |
|
TSSessionId | string | 10002, 10003, 10006, 10007, 10010 | |
ThreadID | string | 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 15, 16, 17, 18, 20, 21, 22, 23, 24, 25, 27, 28, 29, 31, 33, 34, 43, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 86, 100, 102, 103, 105, 256, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 642, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 781, 852, 854, 865, 866, 867, 868, 873, 882, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1010, 1012, 1013, 1014, 1016, 1020, 1024, 1025, 1026, 1029, 1033, 1034, 1038, 1040, 1041, 1042, 1043, 1044, 1061, 1066, 1109, 1130, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1511, 1512, 1514, 1515, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2303, 2484, 2486, 3001, 3002, 3036, 3079, 3408, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4121, 4128, 4129, 4176, 4177, 4178, 4202, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 4879, 5602, 5604, 5605, 5606, 5611, 5612, 5615, 5617, 5631, 5973, 6000, 6003, 6253, 6527, 7000, 7002, 8192, 8193, 8195, 8198, 8199, 8200, 8224, 8225, 8230, 8300, 8301, 8302, 8303, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | "8568" |
ToFolder | string | 501, 502, 512, 513 | |
TotalDirectories | string | 8301, 8302, 8303 | |
TotalFiles | string | 8301, 8302, 8303 | |
TypeId | string | 2001, 2002, 3002 | |
URL | string | 3036, 4097, 4098, 4099, 4100 | csc://{S-1-5-21-712794737-353456615-3249761964-1001}/ |
UTCStartTime | string | 10000, 10001 | |
UnknownRequestCode | string | 5, 6, 7 | |
Url | string | 6, 8 | https://VMW-KeyId-e7286866ba6366b54d95a3bc555d89931e800152.microsoftaik.azure.net/templates/Aik/scep |
UserData_Xml | string | 1000, 1001, 10000, 10001, 10002, 10006 |
|
UserID | string | 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 15, 16, 17, 18, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 38, 43, 45, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 86, 92, 100, 101, 102, 103, 105, 198, 200, 256, 257, 300, 301, 302, 326, 330, 335, 455, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 641, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 865, 866, 867, 868, 882, 900, 902, 903, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1010, 1012, 1013, 1020, 1022, 1025, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1041, 1042, 1043, 1044, 1066, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1511, 1512, 1514, 1515, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 1704, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2484, 2486, 3001, 3002, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4128, 4129, 4176, 4177, 4178, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 5000, 5001, 5008, 5602, 5604, 5605, 5606, 5611, 5612, 5615, 5617, 5631, 5973, 6000, 7000, 7002, 8192, 8194, 8199, 8212, 8216, 8224, 8225, 8300, 8301, 8302, 8303, 9027, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 11707, 11724, 11728, 11756, 12116, 16384, 16390, 16394, 20221, 20222, 20223, 20224, 20225, 20226 | "S-1-5-21-582766833-432816504-4207985818-1009" |
UserKeys | string | 0, 1, 5, 9 | |
UserSid | string | 1, 1, 5, 7 | |
VendorId | string | 2001, 2002, 3002 | |
VendorName | string | 1, 2, 3 | |
VendorNameCount | string | 1, 2, 3 | |
VendorType | string | 2001, 2002, 3002 | |
Version | integer | 1, 3, 5, 11, 13, 15, 16, 86, 100, 102, 103, 105, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1024, 1025, 1026, 1029, 1033, 1034, 1038, 1040, 1042, 1061, 1066, 1109, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 2001, 2303, 3036, 3079, 3408, 4097, 4100, 4101, 4102, 4107, 4108, 4109, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8195, 8198, 8200, 8224, 8225, 8230, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 2 |
Version | string | 1, 2, 64, 900, 902, 903, 1003, 1004, 1013, 1020, 1033, 1034, 1040, 1066, 1531, 1532, 1552, 4097, 4109, 4111, 4625, 5615, 5617, 6000, 8224, 8300, 8301, 8302, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 16384, 16390, 16394 | |
VolumeFriendlyName | string | 2, 5, 5 | |
VolumeGuid | string | 2, 5, 5 | |
VolumeName | string | 0, 3, 7, 9 | C:\ |
Win32Error | integer | 0, 0, 1, 8 | 1359 |
Wordlist | string | 2 | |
WriterId | string | 5, 5, 6 | |
cbSize | string | 0, 0, 0, 1, 8 | |
clsid | string | 0 | |
dest | string | 0, 1, 2, 3, 4, 5, 11, 13, 15, 16, 26, 30, 32, 34, 35, 38, 45, 47, 48, 63, 64, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 637, 641, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1552, 1704, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5000, 5001, 5008, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | windowsvictim |
dvc | string | 0, 1, 2, 3, 4, 5, 11, 13, 15, 16, 26, 30, 32, 34, 35, 38, 45, 47, 48, 63, 64, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 637, 641, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1552, 1704, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5000, 5001, 5008, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | windowsvictim |
dvc_nt_host | string | 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | windowsvictim_7db9e240-15f7-410a-8cd9-cc1fa9f3f50a |
dwCheckPoint | string | 2 | |
dwControlsAccepted | string | 2 | |
dwCurrentState | string | 2 | |
dwRebootReasons | string | 0, 0, 0, 1, 5 | |
dwServiceSpecificExitCode | string | 2 | |
dwServiceType | string | 2 | |
dwWaitHint | string | 2 | |
dwWin32ExitCode | string | 2 | |
error | string | 3 | |
event_id | integer | 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 9617 |
function | string | 3 | |
hresult | string | 0, 1 | |
languageTag | string | 0, 2 | |
nApplications | string | 0, 0, 0, 1, 5 | |
nFiles | string | 10002, 10003, 10006, 10007, 10009 | |
nServices | string | 0, 0, 0, 1, 9 | |
param1 | integer | 781, 4202, 4625, 4879 | 86400 |
param10 | integer | 0, 2, 2, 4 | 0 |
param11 | integer | 0, 2, 2, 4 | 0 |
param12 | integer | 0, 2, 2, 4 | 1 |
param2 | integer | 0, 2, 2, 4 | 0 |
param2 | string | 781, 4625, 4879 | TEST-THKWMDWTQP |
param3 | integer | 0, 2, 2, 4 | 0 |
param3 | string | 781, 4625 | Software\Microsoft\EventSystem\EventLog |
param4 | integer | 0, 2, 2, 4 | 0 |
param5 | integer | 0, 2, 2, 4 | 0 |
param6 | integer | 0, 2, 2, 4 | 0 |
param7 | integer | 0, 2, 2, 4 | 1 |
param8 | string | 0, 2, 2, 4 | Mutual Authentication Required |
param9 | string | 0, 2, 2, 4 | NT AUTHORITY\NetworkService |
pbBinary | string | 0, 0, 0, 1, 8 | |
policyName | string | 0 | |
policyValue | string | 0 | |
sigma_product | string | 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | windows |
sigma_service | string | 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | application |
signature | string | 637, 641, 642, 852, 4625, 4879 | User Account Changed |
signature_id | integer | 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 9689 |
string | string | 1, 17, 18 | |
subject | string | 637, 641, 642, 852, 4625, 4879 | User Account Changed |
timeendpos | integer | 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 592 |
timestartpos | integer | 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 562 |
user_id | string | 11, 86, 1000, 1001, 1008, 1022, 1025, 1029, 1033, 1035, 1038, 1040, 1042, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 5611, 5615, 5617, 10000, 10001, 10002, 10006, 11707, 11724, 11728 | "S-1-5-21-582766833-432816504-4207985818-1009" |
vendor_product | string | 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | Microsoft Windows |
wordlist | string | 20, 31 |
dns-server
Field | Data Type | Event IDs | Example |
---|---|---|---|
Computer | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | WIN-FPV0DSIC9O6.sigma.fr |
EventID | integer | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 7693 |
Name | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | "Microsoft-Windows-DNS-Server-Service" |
Task | integer | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 0 |
id | integer | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 60 |
name | string | 0, 0, 4, 5 | Metabase Add Key |
Channel | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | DNS Server |
EventCode | integer | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 7693 |
EventData_Xml | string | 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4015, 4500, 5504, 7693 | _msdcs.sigma.fr ForestDnsZones.sigma.fr |
EventRecordID | integer | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 60 |
Guid | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | "71A551F5-C893-4849-886B-B5EC8502641E" |
Keywords | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 0x8000000000100000 |
Level | integer | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 4 |
Opcode | integer | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 0 |
ProcessID | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | "6628" |
ProcessId | integer | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 6628 |
RecordNumber | integer | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 60 |
SigmaEventCode | integer | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 7693 |
SystemTime | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | '2022-06-03 10:04:40.847180 UTC' |
System_Props_Xml | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 |
|
ThreadID | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | "6844" |
UserID | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | "S-1-5-21-2121334350-1110938707-2888912545-500" |
Version | integer | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 0 |
VirtualizationID | string | 6, 7, 9 | . |
dvc | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | WIN-FPV0DSIC9O6.sigma.fr |
dvc_nt_host | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | Win2022-AD |
event_id | integer | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 60 |
param1 | integer | 3150, 7693 | 65433 |
param1 | string | 404, 407, 408, 769, 2631, 4007, 4500, 5504 | _msdcs.sigma.fr |
param2 | string | 769, 2631, 3150, 4007, 4500 | sigma.fr |
param3 | string | 769, 2631, 3150 | sigma.fr.dns |
sigma_product | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | windows |
sigma_service | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | dns-server |
signature | string | 0, 0, 4, 5 | Metabase Add Key |
signature_id | integer | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 7693 |
subject | string | 0, 0, 4, 5 | Metabase Add Key |
timeendpos | integer | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 523 |
timestartpos | integer | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 493 |
user_id | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | "S-1-5-21-2121334350-1110938707-2888912545-500" |
vendor_product | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | Microsoft Windows |
msexchange-management
Field | Data Type | Event IDs | Example |
---|---|---|---|
Computer | string | 1 | MXS01.snapattack.local |
EventID | integer | 1 | 1 |
Name | string | 1 | "MSExchange CmdletLogs" |
Task | integer | 1 | 1 |
id | integer | 1 | 66 |
Channel | string | 1 | MSExchange Management |
EventCode | integer | 1 | 1 |
EventData_Xml | string | 1 | New-MailboxExportRequest,-Mailbox "snapattack" -Name "03a5108c89f64c4993c8faf52d4322ca" -ContentFilter "Subject -eq '03a5108c89f64c4993c8faf52d4322ca'" -FilePath "\127.0.0.1\c$\inetpub\wwwroot\aspnet_client\fbxvgf.aspx",snapattack.local/Users/snapattack,S-1-5-21-2783883905-3325768869-1243185101-500,S-1-5-21-2783883905-3325768869-1243185101-500,Remote-PowerShell-Unknown,20280 w3wp#MSExchangePowerShellAppPool,,19,00:00:00.3437022,View Entire Forest: 'False', Default Scope: 'snapattack.local', Configuration Domain Controller: 'DC01.snapattack.local', Preferred Global Catalog: 'DC01.snapattack.local', Preferred Domain Controllers: '{ DC01.snapattack.local }',,,,,,,False,,0 objects execution has been proxied to remote server.,,,1,ActivityId: 72e61d11-0b45-4821-90a2-08848e150425,ServicePlan:;IsAdmin:True;,,en-US |
EventRecordID | integer | 1 | 66 |
Keywords | string | 1 | 0x80000000000000 |
Level | integer | 1 | 4 |
Qualifiers | string | 1 | "16384" |
RecordNumber | integer | 1 | 66 |
SigmaEventCode | integer | 1 | 1 |
SystemTime | string | 1 | '2022-05-03 18:36:53.520477 UTC' |
System_Props_Xml | string | 1 |
|
dvc | string | 1 | MXS01.snapattack.local |
dvc_nt_host | string | 1 | MXS01_ec25d050-3a58-4db1-a8f0-0b397e2cf39a |
event_id | integer | 1 | 66 |
sigma_product | string | 1 | windows |
sigma_service | string | 1 | msexchange-management |
signature_id | integer | 1 | 1 |
timeendpos | integer | 1 | 432 |
timestartpos | integer | 1 | 402 |
vendor_product | string | 1 | Microsoft Windows |
powershell
Field | Data Type | Event IDs | Example |
---|---|---|---|
Computer | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 8198, 12039, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508 | training1 |
EventID | integer | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 8198, 12039, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508 | 8197 |
FileName | string | 24577, 24578, 24595, 24596, 24597, 24598, 24599 | |
Name | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 24577, 32784, 40961, 40962, 53251, 53504 | "Microsoft-Windows-PowerShell" |
Path | string | 0, 1, 4, 4 | C:\Users\bob\desktop\capattack\modules\stop.ps1 |
ScriptBlockText | string | 0, 1, 4, 4 | prompt |
Task | integer | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504 | 4 |
Task | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8197, 8198, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508 | |
id | integer | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 24577, 32784, 40961, 40962, 53504 | 68147 |
ActivityID | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 24577, 32784, 40961, 40962, 53504 | "F0414E1E-7305-0002-9755-41F00573D801" |
Channel | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 8198, 12039, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508 | Microsoft-Windows-PowerShell/Operational |
ContextInfo | string | 4100, 4101, 4102, 4103 | Severity = Warning |
CurrentLine | string | 24595, 24596, 24597, 24598, 24599 | |
ErrorCode | string | 2, 3, 4, 7, 8 | ྠ |
ErrorMessage | string | 2, 3, 4, 7, 8 | An unknown element "" was received. This can happen if the remote process closed or ended abnormally. |
EventCode | integer | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 24577, 32784, 40961, 40962, 53504 | 8197 |
EventData_Xml | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8197, 32784, 53504 | Opened |
EventRecordID | integer | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 24577, 32784, 40961, 40962, 53504 | 68147 |
Guid | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 24577, 32784, 40961, 40962, 53504 | "A0C1853B-5C40-4B15-8766-3CF1C58F985A" |
InnerException | string | 1, 2, 3, 5, 5 | |
InstanceId | string | 1, 4, 8, 9 | 0aacaf17-f104-4cde-8fab-27831ef15a2e |
Keywords | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 8198, 12039, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508 | 0x8000000000000020 |
Level | integer | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 8198, 12039, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508 | 5 |
MaxRunspaces | string | 1, 4, 8, 9 | |
Message | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8197, 8198, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508 | |
MessageNumber | string | 0, 1, 4, 4 | |
MessageTotal | string | 0, 1, 4, 4 | |
MinRunspaces | string | 1, 4, 8, 9 | |
Opcode | integer | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504 | 20 |
Opcode | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8197, 8198, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508 | |
Payload | string | 4100, 4101, 4102, 4103 | PackageManagement: A package is installed. |
PipelineId | string | 2, 3, 4, 7, 8 | 00000000-0000-0000-0000-000000000000 |
ProcessID | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 8198, 12039, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508 | "9868" |
ProcessId | integer | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504 | 9868 |
ProviderGUID | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8197, 8198, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508 | |
ProviderName | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8197, 8198, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508 | |
Qualifiers | string | 0, 1, 3, 4 | |
RecordNumber | integer | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 24577, 32784, 40961, 40962, 53504 | 68147 |
RelatedActivityID | string | 4100, 4101, 4103, 4104, 24577, 40961, 40962, 53504 | |
RunspaceId | string | 4105, 4106 | 1aa6385f-8a7d-4de1-ba84-96a62662dc3a |
ScheduledJobDefName | string | 53249, 53250 | |
ScriptBlockId | string | 4104, 4105, 4106 | 576808c7-2ec5-4ebc-8c72-0b7608c807a7 |
SessionId | string | 4100, 4101, 4103, 4104, 24577, 32784, 40961, 40962, 53504 | 00000000-0000-0000-0000-000000000000 |
SigmaEventCode | integer | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504 | 8197 |
StackTrace | string | 32784, 53251 | at System.Management.Automation.Remoting.Server.OutOfProcessMediatorBase.Start(String initialCommand, String configurationName) |
StartTime | string | 2, 3, 4, 5, 9 | |
State | string | 0, 2, 3, 5, 5 | |
StopTime | string | 0, 2, 3, 5, 5 | |
SystemTime | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 24577, 32784, 40961, 40962, 53504 | '2022-07-28 14:45:54.626336 UTC' |
System_Props_Xml | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504 |
|
ThreadID | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 8198, 12039, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508 | "6032" |
UserData | string | 4100, 4101, 4102, 4103 | Package=AADInternals, Version=0.6.8, Provider=PowerShellGet, Source=PSGallery, Status=Installed, DestinationPath= |
UserID | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 8198, 12039, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508 | "S-1-5-21-582766833-432816504-4207985818-1009" |
Version | integer | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 24577, 32784, 40961, 40962, 53504 | 1 |
dvc | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 24577, 32784, 40961, 40962, 53504 | training1 |
dvc_nt_host | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504 | training1_a6b51cc8-8b81-4d7e-a2c9-90e7ef573946 |
event_id | integer | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504 | 68147 |
meta | string | 4103, 4104 | |
param1 | integer | 0, 3, 4, 5, 5 | 9868 |
param1 | string | 8193, 8197, 8198, 32777, 53504, 53505, 53506, 53507, 53508 | Opened |
param2 | string | 8198, 32777, 53504, 53505, 53506, 53507, 53508 | DefaultAppDomain |
param3 | string | 8198, 32777, 53506, 53507, 53508 | |
sigma_product | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504 | windows |
sigma_service | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504 | powershell |
signature_id | integer | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504 | 8197 |
timeendpos | integer | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504 | 516 |
timestartpos | integer | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504 | 486 |
user_id | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504 | "S-1-5-21-582766833-432816504-4207985818-1009" |
vendor_product | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504 | Microsoft Windows |
powershell-classic
Field | Data Type | Event IDs | Example |
---|---|---|---|
Computer | string | 300, 400, 403, 600, 800 | windowsvictim |
EventID | integer | 300, 400, 403, 600, 800 | 800 |
Name | string | 300, 400, 403, 600, 800 | "PowerShell" |
Task | integer | 300, 400, 403, 600, 800 | 8 |
id | integer | 300, 400, 403, 600, 800 | 75963 |
name | string | 0, 0, 6 | A process was assigned a primary token |
Channel | string | 300, 400, 403, 600, 800 | Windows PowerShell |
EventCode | integer | 300, 400, 403, 600, 800 | 800 |
EventData_Xml | string | 300, 400, 403, 600, 800 | Stopped,Available, NewEngineState=Stopped |
EventRecordID | integer | 300, 400, 403, 600, 800 | 75963 |
Keywords | string | 300, 400, 403, 600, 800 | 0x80000000000000 |
Level | integer | 300, 400, 403, 600, 800 | 4 |
Opcode | integer | 400, 403, 600, 800 | 0 |
ProcessID | string | 400, 403, 600, 800 | "0" |
ProcessId | integer | 400, 403, 600, 800 | 0 |
Qualifiers | string | 300, 400, 403, 600, 800 | "0" |
RecordNumber | integer | 300, 400, 403, 600, 800 | 75963 |
SigmaEventCode | integer | 400, 403, 600, 800 | 800 |
SigmaEventCode | string | 0, 0, 3 | N/A |
SystemTime | string | 300, 400, 403, 600, 800 | '2022-07-15 12:06:22.041268 UTC' |
System_Props_Xml | string | 300, 400, 403, 600, 800 |
|
ThreadID | string | 400, 403, 600, 800 | "0" |
Version | integer | 400, 403, 600, 800 | 0 |
dvc | string | 300, 400, 403, 600, 800 | windowsvictim |
dvc_nt_host | string | 300, 400, 403, 600, 800 | windowsvictim_32d8f699-9b6a-46e8-8381-9f403508b83f |
event_id | integer | 300, 400, 403, 600, 800 | 75963 |
sigma_product | string | 300, 400, 403, 600, 800 | windows |
sigma_service | string | 300, 400, 403, 600, 800 | powershell-classic |
signature | string | 0, 0, 6 | A process was assigned a primary token |
signature_id | integer | 300, 400, 403, 600, 800 | 800 |
subject | string | 0, 0, 6 | A process was assigned a primary token |
timeendpos | integer | 300, 400, 403, 600, 800 | 465 |
timestartpos | integer | 300, 400, 403, 600, 800 | 435 |
vendor_product | string | 300, 400, 403, 600, 800 | Microsoft Windows |
printservice-admin
Field | Data Type | Event IDs | Example |
---|---|---|---|
EventID | integer | 808, 823 | 823 |
Name | string | 808, 823 | Microsoft-Windows-PrintService |
EventCode | integer | 808, 823 | 823 |
Guid | string | 808, 823 | 747EF6FD-E535-4D16-B510-42C90F6873A1 |
ProcessID | integer | 808, 823 | 2612 |
ProcessId | integer | 808, 823 | 2612 |
SigmaEventCode | integer | 808, 823 | 823 |
SystemTime | string | 808, 823 | '2022-07-20 16:47:56.388245 UTC' |
ThreadID | integer | 808, 823 | 2648 |
UserID | string | 808, 823 | S-1-5-21-2414553406-2212388514-3030099854-1009 |
sigma_product | string | 808, 823 | windows |
sigma_service | string | 808, 823 | printservice-admin |
timeendpos | integer | 808, 823 | 519 |
timestartpos | integer | 808, 823 | 489 |
xmlns | string | 808, 823 | http://schemas.microsoft.com/win/2004/08/events/event |
security
Field | Data Type | Event IDs | Description | Example |
---|---|---|---|---|
Application | string | 5031, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159 | Full path and the name of the executable for the process. | \device\harddiskvolume4\windows\system32\svchost.exe |
CommandLine | string | 4688 | C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Computer | string | 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4949, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5478, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424, 8222 | windowsvictim |
|
EventID | integer | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | 8222 |
|
EventID | string | 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424 | ||
FileName | string | 4664, 5051 | the name of a file or folder that the virtualized file name refers to. | |
Name | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | "VSSAudit" |
|
Object | string | 4934, 4937 | ||
ParentProcessName | string | 4688 | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
|
ProcessName | string | 4615, 4616, 4624, 4625, 4648, 4649, 4656, 4657, 4658, 4660, 4661, 4663, 4670, 4673, 4674, 4689, 4696, 4703, 4818, 4904, 4905, 4907, 4911, 4913, 4985, 5039, 5051, 5712, 6417, 6418 | full path and the name of the executable for the process. | C:\Windows\System32\wevtutil.exe |
Service | string | 3, 4, 6, 7 | - |
|
Task | integer | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | 3 |
|
Task | string | 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424 | ||
Type | integer | 3, 5, 7, 9 | 0 |
|
Type | string | 5148, 5149, 5379 | ||
action | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416 | success |
|
app | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | win:unknown |
|
id | integer | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | 843214 |
|
name | string | 1102, 4611, 4624, 4625, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4800, 4801, 4904, 4905, 4907, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890 | Windows Firewall settings were restored to the default values |
|
process | string | 4624, 4625, 4648, 4656, 4657, 4658, 4660, 4661, 4663, 4670, 4673, 4674, 4688, 4689, 4696, 4703, 4904, 4905, 4907, 4911, 4985 | C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
process_name | string | 4624, 4625, 4648, 4656, 4657, 4658, 4660, 4661, 4663, 4670, 4673, 4674, 4688, 4689, 4703, 4904, 4905, 4907, 4911, 4985 | wevtutil.exe |
|
product | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | Windows |
|
service | string | 4673, 4697, 4768, 4769, 5478 | krbtgt |
|
status | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416 | success |
|
user | integer | 4624, 4627, 4634, 4648, 4688, 4696, 4703, 4720, 4726, 4728, 4729, 4732 | ||
user | string | 4624, 4625, 4627, 4634, 4648, 4673, 4674, 4688, 4689, 4697, 4703, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4798, 4799, 4800, 4801 | user |
|
AccessGranted | string | 1, 4, 7, 7 | SeServiceLogonRight |
|
AccessList | string | 4656, 4659, 4661, 4662, 4663, 4691, 5140, 5145 | the list of access rights which were requested by user_sid . These access rights depend on Object Type. |
%%4484 |
AccessMask | string | 4656, 4659, 4661, 4662, 4663, 4674, 4691, 5140, 5145 | the sum of hexadecimal values of requested access rights. See "Table 13. File access codes." | 983103 |
AccessReason | string | 4656, 4661, 4818, 5145 | the list of access check results. | - |
AccessRemoved | string | 1, 4, 7, 8 | SeServiceLogonRight |
|
AccountDomain | string | 4778, 4779, 4825 | SID of account that requested the "invoke screensaver" operation | EC2AMAZ-1CL0VOR |
AccountExpires | string | 4720, 4738, 4741, 4742 | the date when the account expires. If the value of accountExpiresattribute of computer object was changed, you will see the new value here. For computer objects, it is optional, and typically is not set. You can change this attribute by using Active Directory Users and Computers, or through a script, for example. | %%1794 |
AccountName | string | 4778, 4779, 4822, 4823, 4825 | the name of the account that requested the "invoke screensaver" operation. | user |
AccountSessionIdentifier | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
Action | string | 5441, 5447 | %%16390 |
|
ActiveProfile | string | 4, 5, 6, 9 | ||
ActivityID | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4662, 4670, 4672, 4673, 4674, 4688, 4689, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4946, 4947, 4948, 4949, 4950, 4957, 5058, 5059, 5061, 5379, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890 | "DB372A64-1DDF-0000-34E1-C3F65585D801" |
|
AddedCAPs | string | 1, 4, 8, 9 | ||
AdditionalInfo | string | 2, 4, 6, 6 | Local Read (ExecQuery) |
|
AdditionalInfo2 | string | 2, 4, 6, 6 | root\cimv2\security\MicrosoftVolumeEncryption:__Win32Provider.Name="Win32_EncryptableVolumeProvider" |
|
AdvancedOptions | string | 2, 4, 6, 8 | ||
AhAuthType | string | 1, 4, 5, 5 | ||
AlgorithmName | string | 5057, 5058, 5059, 5060, 5061 | the name of cryptographic algorithm through which the key was used or accessed. | UNKNOWN |
AllowedToDelegateTo | string | 4720, 4738, 4741, 4742 | the list of SPNs to which this account can present delegated credentials. Can be changed using Active Directory Users and Computers management console in Delegation tab of computer account. If the SPNs list on Delegation tab of a computer account was changed, you will see the new SPNs list in AllowedToDelegateTo field (note that you will see the new list instead of changes) of this event. | - |
AppCorrelationID | string | 5136, 5137, 5138, 5139, 5141, 5169, 5170 | always has "-" value. Not in use. | |
AppInstance | string | 4665, 4666, 4667, 4668 | (Application Information) Application Instance ID | |
AppName | string | 4665, 4666, 4667, 4668 | (Application Information) Application Name | |
AsIsCAPs | string | 1, 4, 8, 9 | ||
Attribute | string | 3, 4, 4, 9 | ||
AttributeLDAPDisplayName | string | 5136, 5169, 5170 | the object attribute that was modified. | |
AttributeSyntaxOID | string | 5136, 5169, 5170 | The syntax for an attribute defines the storage representation, byte ordering, and matching rules for comparisons of property types. | |
AttributeValue | string | 5136, 5169, 5170 | the value which was added or deleted, depending on the Operation\Type field. | |
Attributes | string | 4874, 4886, 4887, 4888, 4889 | ||
AuditFilter | string | 4, 5, 8, 8 | ||
AuditPolicyChanges | string | 4719, 4912 | changes which were made for the subcategory. | %%8448, %%8450 |
AuditSourceName | string | 4904, 4905 | the name of unregistered security event source. You can see all registered security event source names in this registry path: "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security". | VSSAudit |
AuditStatusCode | string | 4935, 4936 | there is no detailed information about this field in this document. | |
AuditsDiscarded | string | 1, 2, 4, 6 | ||
AuthenticationLevel | string | 1, 2, 5, 7 | ||
AuthenticationPackage | string | 4, 4, 6, 9 | ||
AuthenticationPackageName | string | 4610, 4624, 4625 | The name of the authentication package which was used for the logon authentication process. Default packages loaded on LSA startup are located in "HKLM\SYSTEM\CurrentControlSet\Control\Lsa\OSConfig" registry key. | Negotiate |
AuthenticationProvider | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
AuthenticationServer | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
AuthenticationService | string | 1, 2, 5, 7 | ||
AuthenticationSetId | string | 5040, 5041, 5042 | ||
AuthenticationSetName | string | 5040, 5041, 5042 | ||
AuthenticationType | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
BackupFileName | string | 5376, 5377 | ||
BackupPath | string | 0, 1, 1, 5 | ||
BackupType | string | 4, 6, 7, 8 | ||
BaseCRLHash | string | 1, 2, 5, 7 | ||
BaseCRLNumber | string | 1, 2, 5, 7 | ||
BaseCRLThisUpdate | string | 1, 2, 5, 7 | ||
CACertificateHash | string | 4880, 4881 | ||
CAConfigurationId | string | 5122, 5126, 5127 | ||
CAName | string | 1, 2, 5, 5 | ||
CAPublicKeyHash | string | 4880, 4881 | ||
CRLNumber | string | 2, 4, 7, 8 | ||
CalledStationID | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
CallerDomainName | string | 1, 4, 6, 7 | ||
CallerLogonId | string | 1, 4, 6, 7 | ||
CallerProcessId | string | 4798, 4799 | hexadecimal Process ID of the process that enumerated the members of the group. Process ID (PID) is a number used by the operating system to uniquely identify an active process. You can also correlate this process ID with a process ID in other events, for example, "4688: A new process has been created" Process Information\New Process ID. | 0x73c |
CallerProcessName | string | 4798, 4799, 5050 | full path and the name of the executable for the process. | C:\Windows\System32\ntdsutil.exe |
CallerUserName | string | 1, 4, 6, 7 | ||
CallerUserSid | string | 1, 4, 6, 7 | ||
Caller_Domain | string | 4611, 4624, 4625, 4627, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4798, 4799, 4904, 4905, 4907, 4911, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5379, 5381, 6416 | training1 |
|
Caller_User_Name | string | 1102, 4611, 4624, 4625, 4627, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4798, 4799, 4904, 4905, 4907, 4911, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5379, 5381, 5888, 5890, 6416 | user |
|
CallingStationID | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
CalloutId | integer | 4, 4, 5, 6 | 290 |
|
CalloutId | string | 5440, 5446 | ||
CalloutKey | string | 5440, 5441, 5446, 5447 | 31114833-2891-4EDD-A8EC-2FF8549AA491 |
|
CalloutName | string | 5440, 5441, 5446, 5447 | windefend_datagram_v4 |
|
CalloutType | string | 5440, 5446 | %%16388 |
|
Categories | string | 6406, 6408 | ||
CategoryId | string | 4719, 4912 | the name of auditing category which subcategory state was changed. | %%8273 |
CategoryString | string | 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738 | Account Management |
|
CertIssuerName | string | 4768, 4771, 4820, 4824 | the name of the Certification Authority that issued the smart card certificate. Populated in Issued by field in certificate. | |
CertSerialNumber | string | 4768, 4771, 4820, 4824 | smart card certificate's serial number. Can be found in Serial number field in the certificate. | |
CertThumbprint | string | 4768, 4771, 4820, 4824 | smart card certificate's thumbprint. Can be found in Thumbprint field in the certificate. | |
Certificate | string | 4, 4, 8, 8 | ||
CertificateDatabaseHash | string | 4880, 4881 | ||
CertificateHash | string | 4, 5, 8, 9 | ||
CertificateSerialNumber | string | 0, 4, 7, 8 | ||
ChangeType | string | 5446, 5447, 5448, 5449, 5450 | %%16385 |
|
Channel | string | 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4949, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5478, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424, 8222 | Security |
|
CipherType | string | 1, 4, 5, 5 | ||
ClassId | string | 6416, 6419, 6420, 6421, 6422, 6423, 6424 | "Class Guid" attribute of device. | 1ED2BBF9-11F0-4084-B21F-AD83A8E6DCDC |
ClassName | string | 6416, 6419, 6420, 6421, 6422, 6423, 6424 | "Class" attribute of device. | Monitor |
ClientAddress | string | 4778, 4779, 4825 | IP address of the computer from which the session was disconnected | 10.0.4.126 |
ClientCreationTime | string | 5058, 5059 | 2022-06-15 13:07:13.665388 UTC |
|
ClientDomain | string | 4665, 4666, 4667, 4668 | subject's domain or computer name. | |
ClientIPAddress | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6400, 6401, 6402 | ||
ClientLogonId | string | 4665, 4666, 4667, 4668 | (Subject) Client Context ID | |
ClientName | string | 4665, 4666, 4667, 4668, 4778, 4779, 6272, 6273, 6274, 6275, 6276, 6277, 6278 | machine name from which the session was disconnected. Has "Unknown"value for console session. | Guacamole RDP |
ClientProcessId | integer | 4697, 4698, 4699, 4700, 4701, 4702, 5058, 5059, 5379, 5381 | 484 |
|
ClientProcessId | string | 4697, 4698, 4699, 4700, 4701, 4702, 5058, 5059, 5376, 5377, 5379, 5380, 5381, 5382 | ||
ClientProcessStartKey | string | 4697, 4698, 4699, 4700, 4701, 4702 | ||
ClientUserName | string | 4774, 4775, 4777 | the name of the account that had its credentials validated by the Authentication Package. Can be user name, computer account name or well-known security principal account name. | |
CollisionTargetName | string | 4, 4, 6, 8 | ||
CollisionTargetType | string | 4, 4, 6, 8 | ||
CompatibleIds | string | 6416, 6419, 6420, 6421, 6422, 6423, 6424 | "Compatible Ids" attribute of device. | *PNP09FF |
ComputerAccountChange | string | 2, 4, 4, 7 | ||
ComputerName | string | 1, 4, 6, 8 | ||
Conditions | string | 5441, 5447 | Condition ID: {d78e1e87-8644-4ea5-9437-d809ecefc971} |
|
ConfigAccessPolicy | string | 2, 4, 6, 8 | ||
ConfiguredNames | string | 1, 5, 6, 8 | ||
ConnectionSecurityRuleId | string | 5043, 5044, 5045 | ||
ConnectionSecurityRuleName | string | 5043, 5044, 5045 | ||
ContextName | string | 5064, 5065, 5066, 5067, 5068, 5069, 5070 | ||
Count | string | 0, 4, 5, 6 | ||
CountOfCredentialsReturned | integer | 5379, 5381 | 0 |
|
CountOfCredentialsReturned | string | 5379, 5380, 5381 | ||
CrashOnAuditFailValue | string | 4621, 4906 | contains new value of CrashOnAuditFail flag. | |
CredType | string | 3, 5, 7, 8 | ||
CryptoAlgorithms | string | 4694, 4695 | Cryptographic Algorithms of the protection | AES-256 , SHA2-512 |
CryptographicSetId | string | 5046, 5047, 5048 | ||
CryptographicSetName | string | 5046, 5047, 5048 | ||
CurrentProfile | string | 1, 5, 5, 7 | %%14644 |
|
DCDNSName | string | 4898, 4899, 4900 | ||
DHGroup | string | 4650, 4651, 4979, 4980, 4981, 4982 | ||
DSName | string | 5136, 5137, 5138, 5139, 5141, 5169, 5170 | the name of an Active Directory domain, where the object was deleted. | |
DSType | string | 5136, 5137, 5138, 5139, 5141, 5169, 5170 | has "Active Directory Domain Services" value for this event. | |
DataDescription | string | 4694, 4695 | - | 827ed4bc-54ff-4032-b410-02f985a5c118 |
DeletedCAPs | string | 1, 4, 8, 9 | ||
DeltaCRLHash | string | 1, 2, 5, 7 | ||
DeltaCRLIndicator | string | 1, 2, 5, 7 | ||
DeltaCRLNumber | string | 1, 2, 5, 7 | ||
DeltaCRLThisUpdate | string | 1, 2, 5, 7 | ||
DestAddress | string | 5146, 5147, 5150, 5151, 5152, 5153, 5156, 5157 | IP address from which connection was received or initiated. | 239.255.255.250 |
DestPort | integer | 5152, 5156, 5157 | Port number which was used from remote machine to initiate connection. | 5355 |
DestPort | string | 5152, 5153, 5156, 5157 | Port number which was used from remote machine to initiate connection. | |
DestinationDRA | string | 4928, 4929, 4930, 4931, 4932, 4933, 4937 | destination directory replication agent distinguished name. | |
DestinationvSwitchPort | string | 5146, 5147 | ||
DeviceClaims | string | 2, 4, 6, 6 | ||
DeviceDescription | string | 6416, 6419, 6420, 6421, 6422, 6423, 6424 | "Device description" attribute of device. | Generic Non-PnP Monitor |
DeviceId | string | 6416, 6419, 6420, 6421, 6422, 6423, 6424 | "Device instance path" attribute of device. | DISPLAY\Default_Monitor\1&1f0c3c2f&0&UID256 |
DeviceName | string | 4820, 4821, 4822, 4823 | ||
Direction | string | 5146, 5147, 5150, 5151, 5152, 5153, 5156, 5157 | Direction of blocked connection. | %%14593 |
DisableIntegrityChecks | string | 2, 4, 6, 8 | ||
DisabledPrivilegeList | string | 0, 3, 4, 7 | - |
|
DisplayName | string | 4720, 4738, 4741, 4742 | it is a name displayed in the address book for a particular account (typically - user account). This is usually the combination of the user's first name, middle initial, and last name. For computer objects, it is optional, and typically is not set. You can change this attribute by using Active Directory Users and Computers, or through a script, for example. If the value of displayName attribute of computer object was changed, you will see the new value here. | %%1793 |
Disposition | string | 4887, 4888, 4889 | ||
DnsHostName | string | 4741, 4742 | name of computer account as registered in DNS. If the value of dNSHostName attribute of computer object was changed, you will see the new value here. | |
DnsName | string | 4864, 4865, 4866, 4867 | DNS name of the trust partner. This parameter might not be captured in the event, and in that case appears as "-". | |
DomainBehaviorVersion | string | 3, 4, 7, 9 | ||
DomainName | string | 4706, 4707, 4716, 4739 | the name of domain for which policy changes were made. | |
DomainPolicyChanged | string | 3, 4, 7, 9 | ||
DomainSid | string | 4706, 4707, 4716, 4739, 4864, 4865, 4866, 4867 | SID of the trust partner. This parameter might not be captured in the event, and in that case appears as "NULL SID". | |
Dummy | string | 3, 4, 7, 8 | - |
|
Duration | string | 1, 4, 6, 8 | ||
EAPErrorCode | string | 2, 3, 5, 6 | ||
EAPReasonCode | string | 2, 3, 5, 6 | ||
EAPType | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
EMAuthMethod | string | 4979, 4981, 4984 | ||
EMImpersonationState | string | 4979, 4980, 4981, 4982, 4983, 4984 | ||
EapRootCauseString | string | 2, 3, 5, 6 | ||
EfsPolicyChange | string | 1, 4, 4, 7 | ||
ElevatedToken | string | 2, 4, 4, 6 | %%1842 |
|
EnableRestrictedPermissions | string | 0, 4, 8, 9 | ||
EnabledPrivilegeList | string | 0, 3, 4, 7 | SeAssignPrimaryTokenPrivilege |
|
EndUSN | string | 3, 3, 4, 9 | ||
Entry | string | 1, 4, 8, 9 | ||
EntryType | string | 4865, 4866, 4867 | the type of modified entry. | |
Error | string | 4958, 5457, 5459, 5461, 5462, 5472, 5474, 5477, 5483, 5484 | ||
ErrorCode | string | 1107, 1108, 5027, 5028, 5029, 5030, 5032, 5035, 5037, 5168, 5632, 5633, 6144, 6145, 6404 | specific error code which shows the error which happened during Group Policy processing. | |
Error_Code | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | 0xc000006d |
|
EspAuthType | string | 1, 4, 5, 5 | ||
EtherType | string | 5146, 5147, 5150, 5151 | ||
EventCode | integer | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | 8222 |
|
EventCount | string | 1, 4, 6, 8 | ||
EventCountTotal | integer | 2, 4, 6, 7 | 1 |
|
EventCountTotal | string | 4626, 4627 | Total number of events in the sequence. | |
EventData_Xml | string | 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5888, 5890, 6416, 8222 | S-1-5-21-582766833-432816504-4207985818-1009,EC2AMAZ-NNKUICG\user,0x0000000000000274,C:\Windows\System32\vssadmin.exe,{5d0247f2-6dbc-4295-8ba8-a779b444c3f6},{bc77a77b-e166-46aa-a3a0-9a46334b947a},{b5946137-7b9f-4925-af80-51abd60b20d5},EC2AMAZ-NNKUICG,\?\Volume{e3c0cc15-0000-0000-0000-100000000000}\,\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1 |
|
EventId | string | 4618, 6405 | ||
EventIdx | integer | 2, 4, 6, 7 | 1 |
|
EventIdx | string | 4626, 4627 | If is there is not enough space in one event to put all groups, you will see "1 of N" in this field and additional events will be generated. Typically this field has "1 of 1" value. | |
EventRecordID | integer | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | 843214 |
|
EventSourceId | string | 4904, 4905 | the unique hexadecimal identifier of unregistered security event source. | 0x10d178 |
ExpirationTime | string | 5169, 5170 | ||
ExtendedQuarantineState | string | 6276, 6277, 6278 | ||
ExtensionData | string | 3, 4, 7, 8 | ||
ExtensionDataType | string | 3, 4, 7, 8 | ||
ExtensionName | string | 3, 4, 7, 8 | ||
ExtensionPolicyFlags | string | 3, 4, 7, 8 | ||
FQDN | string | 4698, 4699, 4700, 4701, 4702 | EC2AMAZ-NNKUICG |
|
FailureCode | string | 4772, 4773 | ||
FailureId | string | 3, 4, 6, 9 | ||
FailurePoint | string | 4652, 4653, 4654, 4983, 4984 | ||
FailureReason | string | 4625, 4652, 4653, 4654, 4692, 4694, 4695, 4983, 4984 | - | 0x0 |
FatalCode | string | 1, 4, 6, 8 | ||
Filter | string | 4, 6, 8, 9 | ||
FilterId | integer | 4, 4, 5, 7 | 68102 |
|
FilterId | string | 5441, 5447 | ||
FilterKey | string | 5441, 5447 | 00307222-72B1-4AEF-8A7F-62AF4B4604DF |
|
FilterName | string | 5441, 5447 | Microsoft Edge (mDNS-In) |
|
FilterOrigin | string | 5152, 5157 | Query User Default |
|
FilterRTID | integer | 5152, 5154, 5156, 5157, 5158 | Unique filter ID which allows application to bind the port. | 70338 |
FilterRTID | string | 5146, 5147, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159 | Unique filter ID which blocks the application from binding to the port. | |
FilterType | string | 5441, 5447 | %%16388 |
|
Flags | integer | 1, 3, 5, 8 | 512 |
|
Flags | string | 4864, 4865, 4866, 4867, 5381, 5382 | Forest flags flags. | |
FlightSigning | string | 2, 4, 6, 8 | ||
ForceLogoff | string | 3, 4, 7, 9 | ||
ForestRoot | string | 4864, 4865, 4866, 4867 | the name of the Active Directory forest for which trusted forest information entry was modified. | |
ForestRootSid | string | 4865, 4866, 4867 | the SID of the Active Directory forest for which trusted forest information entry was modified. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID cannot be resolved, you will see the source data in the event. | |
FullyQualifiedSubjectMachineName | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
FullyQualifiedSubjectUserName | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280 | ||
FunctionName | string | 5066, 5067, 5068, 5069, 5070 | ||
GPOList | string | 6144, 6145 | the list of Group Policy Objects that include "Security Settings" policies, and that were applied with errors to the computer. | |
GUID | string | 0, 4, 6, 9 | ||
Group | string | 4, 6, 6, 6 | ||
GroupMembership | string | 2, 4, 6, 7 | %{S-1-5-21-2414553406-2212388514-3030099854-513} |
|
GroupPolicyApplied | string | 4, 4, 4, 9 | ||
GroupTypeChange | string | 4, 4, 6, 7 | ||
Group_Domain | string | 4728, 4729, 4732, 4733, 4799 | EC2AMAZ-NNKUICG |
|
Group_Name | string | 4728, 4729, 4732, 4733, 4799 | Users |
|
Guid | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416 | "{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}" |
|
HandleId | string | 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4670, 4674, 4818, 4907, 4911, 4913 | hexadecimal value of a handle to Object Name. This field can help you correlate this event with other events that might contain the same Handle ID, for example, "4663(S): An attempt was made to access an object." This parameter might not be captured in the event, and in that case appears as "0x0". | 0xd24 |
HardwareIds | string | 6419, 6420, 6421, 6422, 6423, 6424 | "Hardware Ids" attribute of device. | |
HasRemoteDynamicKeywordAddress | string | 1, 5, 5, 7 | %%1826 |
|
HomeDirectory | string | 4720, 4738, 4741, 4742 | user's home directory. If homeDrive attribute is set and specifies a drive letter, homeDirectory should be a UNC path. The path must be a network UNC of the form \Server\Share\Directory. If the value of homeDirectory attribute of computer object was changed, you will see the new value here. For computer objects, it is optional, and typically is not set. You can change this attribute by using Active Directory Users and Computers, or through a script, for example. | %%1793 |
HomePath | string | 4720, 4738, 4741, 4742 | specifies the drive letter to which to map the UNC path specified by homeDirectory account's attribute. The drive letter must be specified in the form "DRIVE_LETTER:". For example - "H:". If the value of homeDrive attribute of computer object was changed, you will see the new value here. For computer objects, it is optional, and typically is not set. You can change this attribute by using Active Directory Users and Computers, or through a script, for example. | %%1793 |
HostedCacheName | string | 6403, 6404 | ||
HypervisorDebug | string | 2, 4, 6, 8 | ||
HypervisorLaunchType | string | 2, 4, 6, 8 | ||
HypervisorLoadOptions | string | 2, 4, 6, 8 | ||
Identity | string | 5382, 5632, 5633 | User Principal Name (UPN) of account for which 802.1x authentication request was made. | |
ImpersonationLevel | string | 2, 4, 4, 6 | %%1833 |
|
InboundSpi | string | 1, 4, 5, 5 | ||
InitiatorCookie | string | 4652, 4653 | ||
InterfaceId | string | 5066, 5067, 5068, 5069, 5070 | ||
InterfaceIndex | integer | 1, 5, 5, 7 | 16 |
|
InterfaceName | string | 3, 3, 5, 6 | ||
InterfaceType | string | 5150, 5151 | ||
InterfaceUuid | string | 1, 2, 5, 7 | ||
IntfGuid | string | 2, 3, 5, 6 | ||
InvalidCallName | string | 1, 4, 5, 6 | ||
IpAddress | string | 4624, 4625, 4648, 4768, 4769, 4770, 4771, 4772, 4773, 4820, 4821, 4824, 5140, 5145 | source IP address from which access was performed. | ::1 |
IpAddresses | string | 1, 5, 6, 8 | ||
IpPort | integer | 4768, 4769, 5140, 5145 | source TCP or UDP port which was used from remote or local machine to request the access. | 49901 |
IpPort | string | 4624, 4625, 4648, 4768, 4769, 4770, 4771, 4772, 4773, 4820, 4821, 4824, 5140, 5145 | source TCP or UDP port which was used from remote or local machine to request the access. | - |
IpProtocol | string | 5451, 5452 | ||
IpSecSecurityAssociationId | string | 0, 4, 5, 9 | ||
IpSecSecurityAssociationName | string | 0, 4, 5, 9 | ||
IsBaseCRL | string | 2, 4, 7, 8 | ||
IsLoopback | string | 1, 5, 5, 7 | %%1826 |
|
KRAHashes | string | 3, 4, 8, 9 | ||
KerberosPolicyChange | string | 1, 3, 4, 7 | ||
KernelDebug | string | 2, 4, 6, 8 | ||
KeyContainer | string | 2, 4, 7, 8 | ||
KeyFilePath | string | 0, 5, 5, 8 | C:\ProgramData\Microsoft\Crypto\SystemKeys\c56b3f40b196d4f8d43940688b5b8765_4d6cbdb8-0892-45ee-9d0d-f2e8b7a5fa78 |
|
KeyLength | string | 4624, 4625 | the length of NTLM Session Security key. Typically it has 128 bit or 56 bit length. This parameter is always 0 if "Authentication Package" = "Kerberos", because it is not applicable for Kerberos protocol. This field will also have "0" value if Kerberos was negotiated using Negotiate authentication package. | |
KeyModName | string | 4650, 4651, 4652, 4653, 4654, 4655, 4976, 4977, 4978 | ||
KeyName | string | 5058, 5059, 5060, 5061 | the name of the key (key container) with which operation was performed. | te-8811d5ab-8de8-4b50-a578-845af8f06794 |
KeyType | string | 5058, 5059, 5060, 5061 | can have one of the following values: "User key." - user's cryptographic key. "Machine key." - machine's cryptographic key. | %%2500 |
KeyingModuleName | string | 1, 4, 5, 5 | ||
Keywords | string | 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4949, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5478, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424, 8222 | 0x80a0000000000000 |
|
LayerId | integer | 5446, 5447 | 46 |
|
LayerId | string | 5440, 5441, 5446, 5447 | ||
LayerKey | string | 5440, 5441, 5446, 5447 | A3B42C97-9F04-4672-B87E-CEE9C483257F |
|
LayerName | string | 5146, 5147, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5440, 5441, 5446, 5447 | Application Layer Enforcement layer name. | ALE Receive/Accept v6 Layer |
LayerRTID | integer | 5152, 5154, 5156, 5157, 5158 | Windows Filtering Platform layer identifier. | 48 |
LayerRTID | string | 5146, 5147, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159 | Windows Filtering Platform layer identifier. | |
Level | integer | 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4949, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5478, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424, 8222 | 4 |
|
LifetimeKilobytes | string | 1, 4, 5, 5 | ||
LifetimePackets | string | 1, 4, 5, 5 | ||
LifetimeSeconds | string | 1, 4, 5, 5 | ||
LinkName | string | 4, 4, 6, 6 | ||
LmPackageName | string | 4624, 4625 | The name of the LAN Manager sub-package (NTLM-family protocol name) that was used during logon. Possible values are: NTLM V1, NTLM V2, LM. Only populated if Authentication Package = NTLM. | - |
LoadOptions | string | 2, 4, 6, 8 | ||
LocalAddress | string | 4650, 4651, 4652, 4653, 4654, 4655, 4976, 4977, 4978, 4979, 4980, 4981, 4983, 4984, 5451, 5452 | ||
LocalAddressMask | string | 4654, 5451, 5452 | ||
LocalEMCertHash | string | 4980, 4982, 4983 | ||
LocalEMIssuingCA | string | 4980, 4982, 4983 | ||
LocalEMPrincipalName | string | 4979, 4980, 4981, 4982, 4983, 4984 | ||
LocalEMRootCA | string | 4980, 4982, 4983 | ||
LocalKeyModPort | string | 4650, 4651, 4652, 4653, 4979, 4980, 4981, 4982, 4983, 4984 | ||
LocalMMCertHash | string | 4651, 4652, 4981, 4982 | ||
LocalMMIssuingCA | string | 4651, 4652, 4981, 4982 | ||
LocalMMPrincipalName | string | 4650, 4651, 4652, 4653, 4979, 4980, 4981, 4982 | ||
LocalMMRootCA | string | 4651, 4652, 4981, 4982 | ||
LocalMac | string | 2, 3, 5, 6 | ||
LocalPort | string | 4654, 5451, 5452 | ||
LocalTunnelEndpoint | string | 4654, 5451, 5452 | ||
LocationInformation | string | 6416, 6419, 6420, 6421, 6422, 6423, 6424 | "Location information" attribute of device. | - |
LockoutDuration | string | 3, 4, 7, 9 | ||
LockoutObservationWindow | string | 3, 4, 7, 9 | ||
LockoutThreshold | string | 3, 4, 7, 9 | ||
LogDroppedPacketsEnabled | string | 4, 4, 4, 9 | ||
LogFileCleared_Xml | string | 0, 1, 1, 2 |
|
|
LogSuccessfulConnectionsEnabled | string | 4, 4, 4, 9 | ||
LoggingResult | string | 6272, 6273 | ||
LogonGuid | string | 4624, 4648, 4769, 4821, 4964 | a GUID that can help you correlate this event with another event that can contain the same Logon GUID, "4769(S, F): A Kerberos service ticket was requested event on a domain controller. | 6D906345-171E-BA8F-34F0-A0F6E60FC960 |
LogonHours | string | 4720, 4738, 4741, 4742 | hours that the account is allowed to logon to the domain. If the value of logonHours attribute of computer object was changed, you will see the new value here. For computer objects, it is optional, and typically is not set. You can change this attribute by using Active Directory Users and Computers, or through a script, for example. | %%1797 |
LogonID | string | 4778, 4779, 4825 | hexadecimal value that can help you correlate this event with recent events that might contain the same Logon ID | 0x9fb6c3 |
LogonProcessName | string | 4611, 4624, 4625, 4649 | the name of the trusted logon process that was used for the logon attempt. See event "4611: A trusted logon process has been registered with the Local Security Authority" description for more information. | UserManager |
LogonType | integer | 4624, 4625, 4627, 4634 | the type of logon which was performed. | 3 |
LogonType | string | 4624, 4625, 4626, 4627, 4634 | the type of logon which was performed. | |
Logon_ID | integer | 5888, 5890 | 1207182 |
|
Logon_ID | string | 4611, 4624, 4625, 4627, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4798, 4799, 4904, 4905, 4907, 4911, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5379, 5381, 6416 | 0xcedae |
|
Logon_Type | integer | 4624, 4625, 4627, 4634 | 3 |
|
MMAuthMethod | string | 4650, 4651, 4652, 4653, 4979, 4980 | ||
MMCipherAlg | string | 4650, 4651, 4979, 4980, 4981, 4982 | ||
MMFilterID | string | 4650, 4651, 4652, 4653, 4979, 4980, 4981, 4982 | ||
MMImpersonationState | string | 4650, 4651, 4652, 4653, 4979, 4980, 4981, 4982 | ||
MMIntegrityAlg | string | 4650, 4651, 4979, 4980, 4981, 4982 | ||
MMLifetime | string | 4650, 4651, 4979, 4980, 4981, 4982 | ||
MMSAID | string | 4650, 4651, 4654, 4655, 4979, 4980, 4981, 4982 | ||
MachineAccountQuota | string | 3, 4, 7, 9 | ||
MachineInventory | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
MainModeSaId | string | 1, 4, 5, 5 | ||
MandatoryLabel | string | 4688 | S-1-16-12288 |
|
MappedName | string | 4, 4, 7, 7 | ||
MappingBy | string | 4774, 4775 | The name of Authentication Package which was used for credential validation. | |
MasterKeyId | string | 4692, 4693, 4694, 4695 | - | Edge |
MaxPasswordAge | string | 3, 4, 7, 9 | ||
MediaType | string | 5150, 5151 | ||
MemberName | string | 4728, 4729, 4732, 4733, 4746, 4747, 4751, 4752, 4756, 4757, 4761, 4762, 4785, 4786, 4787, 4788 | distinguished name of account that was removed from the group. For example: "CN=Auditor,CN=Users,DC=contoso,DC=local". For some well-known security principals, such as LOCAL SERVICE or ANONYMOUS LOGON, the value of this field is "-". | - |
MemberSid | string | 4728, 4729, 4732, 4733, 4746, 4747, 4751, 4752, 4756, 4757, 4761, 4762, 4785, 4786, 4787, 4788 | SID of account that was removed from the group. Event Viewer automatically tries to resolve SIDs and show the group name. If the SID cannot be resolved, you will see the source data in the event. | S-1-5-21-582766833-432816504-4207985818-1010 |
MembershipExpirationTime | string | 4728, 4732, 4746, 4751, 4756, 4761, 4785 | ||
Message | string | 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424 | ||
MessageID | string | 4, 4, 5, 6 | ||
MinPasswordAge | string | 3, 4, 7, 9 | ||
MinPasswordLength | string | 3, 4, 7, 9 | ||
MixedDomainMode | string | 3, 4, 7, 9 | ||
Mode | string | 4654, 5451 | ||
ModifiedCAPs | string | 1, 4, 8, 9 | ||
ModifiedObjectProperties | string | 5, 8, 8, 8 | Transaction = '1' -> '0' |
|
Module | string | 5056, 5062 | ||
ModuleName | string | 0, 3, 5, 6 | ||
MulticastFlowsEnabled | string | 4, 4, 4, 9 | ||
NASIPv4Address | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
NASIPv6Address | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
NASIdentifier | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
NASPort | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
NASPortType | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
NamingContext | string | 4928, 4929, 4930, 4931, 4932, 4933 | naming context to replicate. | |
NetbiosName | string | 4864, 4865, 4866, 4867 | NetBIOS name of the trust partner. This parameter might not be captured in the event, and in that case appears as "-". | |
NetworkPolicyName | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
NewBlockedOrdinals | string | 4909, 4910 | ||
NewDate | string | 1, 4, 6, 6 | ||
NewIgnoreDefaultSettings | string | 0, 1, 4, 9 | ||
NewIgnoreLocalSettings | string | 0, 1, 4, 9 | ||
NewMaxUsers | string | 1, 3, 4, 5 | ||
NewObjectDN | string | 5138, 5139 | New distinguished name of moved object. | |
NewProcessId | string | 4688 | 0x2260 |
|
NewProcessName | string | 4688 | C:\Windows\System32\conhost.exe |
|
NewRemark | string | 1, 3, 4, 5 | ||
NewSD | string | 1, 3, 4, 5 | ||
NewSd | string | 4670, 4715, 4817, 4907, 4911, 4913 | the Security Descriptor Definition Language (SDDL) value for the new Central Policy ID (for the policy that has been applied to the object). | S:ARAI(RA;;;;;WD;("IMAGELOAD",TU,0x0,1)) |
NewSecurityDescriptor | string | 0, 0, 4, 9 | ||
NewSecuritySettings | string | 1, 2, 4, 5 | ||
NewShareFlags | string | 1, 3, 4, 5 | ||
NewSigningCertificateHash | string | 1, 2, 5, 6 | ||
NewState | string | 4, 5, 8, 9 | ||
NewTargetUserName | string | 1, 4, 7, 8 | ||
NewTemplateContent | string | 4899, 4900 | ||
NewTime | string | 1, 4, 6, 6 | ||
NewUacValue | string | 4720, 4738, 4741, 4742 | specifies flags that control password, lockout, disable/enable, script, and other behavior for the user or computer account. If the value of userAccountControl attribute of computer object was changed, you will see the new value here. | 0x15 |
NewValue | string | 4657, 4934, 5065, 5067, 5070, 5122, 5123 | new value for changed registry key value. | %%1800 |
NewValueType | string | 4, 5, 6, 7 | %%1873 |
|
NextPublish | string | 2, 4, 7, 8 | ||
NextPublishForBaseCRL | string | 1, 4, 7, 8 | ||
NextPublishForDeltaCRL | string | 1, 4, 7, 8 | ||
NextUpdate | string | 1, 4, 7, 8 | ||
Node | string | 1, 4, 8, 9 | ||
NotificationPackageName | string | 1, 4, 4, 6 | ||
ObjectClass | string | 5136, 5137, 5138, 5139, 5141, 5169, 5170 | class of the object that was deleted. | |
ObjectCollectionName | string | 5888, 5889, 5890 | the name of COM+ collection to which the new object was added. | InterfacesForComponent |
ObjectDN | string | 5136, 5137, 5141, 5169, 5170 | distinguished name of the object that was deleted. | |
ObjectGUID | string | 5136, 5137, 5138, 5139, 5141, 5169, 5170 | each Active Directory object has globally unique identifier (GUID), which is a 128-bit value that is unique not only in the enterprise but also across the world. | |
ObjectIdentifyingProperties | string | 5888, 5889, 5890 | object-specific fields with the names and identifiers for the new object. | ID = {D155805A-726F-4163-8879-E4AAC4F058F3} |
ObjectName | string | 4656, 4657, 4659, 4661, 4662, 4663, 4666, 4670, 4674, 4691, 4817, 4818, 4907, 4911, 4913 | full path and/or name of the object on which the Central Access Policy was changed. | root\cimv2\security\MicrosoftVolumeEncryption |
ObjectPath | string | 0, 3, 5, 9 | ||
ObjectProperties | string | 5889, 5890 | the list of new object's (Object Name) properties. | Name = T1218.009 |
ObjectServer | string | 4656, 4658, 4659, 4660, 4661, 4662, 4663, 4670, 4673, 4674, 4817, 4818, 4819, 4907, 4911, 4913 | has "Security" value for this event. | WMI |
ObjectType | string | 4656, 4659, 4661, 4662, 4663, 4670, 4674, 4691, 4817, 4818, 4819, 4907, 4911, 4913, 5140, 5143, 5145 | The type of an object that was accessed during the operation. Always "File" for this event. | WMI Namespace |
ObjectValueName | string | 4, 5, 6, 7 | ConfigXML |
|
ObjectVirtualPath | string | 0, 3, 5, 9 | ||
OemInformation | string | 3, 4, 7, 9 | ||
OldBlockedOrdinals | string | 4909, 4910 | ||
OldIgnoreDefaultSettings | string | 0, 1, 4, 9 | ||
OldIgnoreLocalSettings | string | 0, 1, 4, 9 | ||
OldMaxUsers | string | 1, 3, 4, 5 | ||
OldObjectDN | string | 5138, 5139 | Old distinguished name of moved object. | |
OldRemark | string | 1, 3, 4, 5 | ||
OldSD | string | 1, 3, 4, 5 | ||
OldSd | string | 4670, 4715, 4817, 4907, 4911, 4913 | the Security Descriptor Definition Language (SDDL) value for the old Central Policy ID (for the policy that was formerly applied to the object). | D:(A;;GA;;;BA)(A;;GA;;;SY) |
OldSecurityDescriptor | string | 0, 0, 4, 9 | ||
OldShareFlags | string | 1, 3, 4, 5 | ||
OldTargetUserName | string | 1, 4, 7, 8 | ||
OldTemplateContent | string | 4899, 4900 | ||
OldUacValue | string | 4720, 4738, 4741, 4742 | specifies flags that control password, lockout, disable/enable, script, and other behavior for the user or computer account. This parameter contains the previous value of userAccountControlattribute of computer object. | 0x15 |
OldValue | string | 4657, 5065, 5067, 5070 | old value for changed registry key value. | %%1800 |
OldValueType | string | 4, 5, 6, 7 | %%1873 |
|
OpCorrelationID | string | 5136, 5137, 5138, 5139, 5141, 5169, 5170 | multiple modifications are often executed as one operation via LDAP. | |
Opcode | integer | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416 | 0 |
|
Opcode | string | 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424 | ||
Operation | string | 5058, 5059, 5061, 5063, 5064, 5066, 5068, 5069 | performed operation. | %%2480 |
OperationId | string | 4666, 4865, 4866, 4867 | unique hexadecimal identifier of the operation. You can correlate this event with other events (4865(S): A trusted forest information entry was added, 4866(S): A trusted forest information entry was removed) using this field. | |
OperationMode | string | 4, 4, 4, 9 | ||
OperationName | string | 4, 6, 6, 6 | ||
OperationType | string | 4657, 4662, 5136, 5169, 5170 | type of performed operation. | Object Access |
Options | string | 4928, 4929, 4930, 4931, 4932, 4933, 4937 | decimal value of DRS Options. | |
Ordinal | string | 1, 4, 6, 7 | ||
OriginalProfile | string | 1, 5, 5, 7 | %%14644 |
|
OutboundSpi | string | 1, 4, 5, 5 | ||
Package | string | 3, 5, 7, 8 | ||
PackageName | string | 4, 6, 7, 7 | MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 |
|
PackageSid | string | 2, 3, 5, 8 | ||
PacketsDiscarded | string | 1, 4, 5, 9 | ||
ParentProcessId | string | 4697, 4698, 4699, 4700, 4701, 4702 | ||
PasswordHistoryLength | string | 3, 4, 7, 9 | ||
PasswordLastSet | string | 4720, 4738, 4741, 4742 | last time the account's password was modified. If the value of pwdLastSet attribute of computer object was changed, you will see the new value here. For example: 8/12/2015 11:41:39 AM. This value will be changed, for example, after manual computer account reset action or automatically every 30 days by default for computer objects. | %%1794 |
PasswordProperties | string | 3, 4, 7, 9 | ||
PeerMac | string | 2, 3, 5, 6 | ||
PeerName | string | 1, 4, 6, 8 | ||
PeerPrivateAddress | string | 1, 4, 5, 5 | ||
PercentFull | string | 0, 1, 1, 3 | ||
Policy | string | 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474 | ||
PolicyName | string | 4820, 4821, 4823 | ||
Position | string | 5066, 5068 | ||
PreAuthType | integer | 4, 6, 7, 8 | 2 |
|
PreAuthType | string | 4768, 4771, 4820, 4824 | the code of pre-Authentication type which was used in TGT request. | |
PreviousDate | string | 1, 4, 6, 6 | ||
PreviousTime | string | 1, 4, 6, 6 | ||
PrimaryGroupId | integer | 4720, 4738 | Relative Identifier (RID) of user's object primary group. | 513 |
PrimaryGroupId | string | 4720, 4738, 4741, 4742 | Relative Identifier (RID) of computer's object primary group. | |
PrivateKeyUsageCount | string | 4880, 4881 | ||
PrivilegeList | string | 4656, 4659, 4661, 4672, 4673, 4674, 4704, 4705, 4720, 4723, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4780, 4781, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4830 | the list of user privileges which were used during the operation, for example, SeBackupPrivilege. This parameter might not be captured in the event, and in that case appears as "-". See full list of user privileges in "Table 8. User Privileges.". | SeTakeOwnershipPrivilege |
ProcessCreationTime | string | 5376, 5377, 5379, 5380, 5381, 5382 | 2022-06-28 15:09:44.051913 UTC |
|
ProcessID | string | 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4949, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5478, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424 | Hexadecimal Process ID of the process that attempted to create the connection. | "760" |
ProcessId | integer | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416 | Hexadecimal Process ID of the process which was permitted to bind to the local port. | 9048 |
ProcessId | string | 4615, 4616, 4624, 4625, 4648, 4649, 4656, 4657, 4658, 4659, 4660, 4661, 4663, 4670, 4673, 4674, 4688, 4689, 4690, 4691, 4696, 4703, 4818, 4904, 4905, 4907, 4911, 4913, 4985, 5039, 5050, 5051, 5152, 5153, 5154, 5155, 5158, 5159, 5446, 5447, 5448, 5449, 5450, 5712, 6417, 6418 | Hexadecimal Process ID of the process which was permitted to bind to the local port. | 0x8f8 |
Process_Command_Line | string | 4688 | C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
ProductName | string | 6406, 6408 | ||
Profile | string | 4944, 4951, 4952, 4953 | the name of the profile of the ignored rule. | |
ProfileChanged | string | 4946, 4947, 4948, 4950, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049 | the name of profile in which setting was changed. | Public |
ProfilePath | string | 4720, 4738, 4741, 4742 | specifies a path to the account's profile. This value can be a null string, a local absolute path, or a UNC path. If the value of profilePath attribute of computer object was changed, you will see the new value here. For computer objects, it is optional, and typically is not set. You can change this attribute by using Active Directory Users and Computers, or through a script, for example. | %%1793 |
ProfileUsed | string | 4, 4, 5, 9 | ||
Profiles | string | 0, 1, 3, 5 | ||
Properties | string | 4661, 4662 | first part is the type of access that was used. Typically has the same value as Accesses field. | --- |
PropertyIndex | string | 2, 4, 8, 9 | ||
PropertyName | string | 4892, 5069, 5070, 5123 | ||
PropertyType | string | 2, 4, 8, 9 | ||
PropertyValue | string | 2, 4, 8, 9 | ||
ProtectedDataFlags | string | 4694, 4695 | - | 0x0 |
Protocol | integer | 5152, 5154, 5156, 5157, 5158 | Protocol number. | 6 |
Protocol | string | 4654, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159 | Protocol number. | |
ProtocolSequence | string | 4816, 5712 | ||
ProviderContextKey | string | 5443, 5449 | 382FC699-0C62-4D70-B30A-FBD3D01201AB |
|
ProviderContextName | string | 5443, 5449 | MPSSVC |
|
ProviderContextType | string | 5443, 5449 | %%16388 |
|
ProviderGUID | string | 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424 | ||
ProviderKey | string | 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450 | DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62 |
|
ProviderName | string | 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424 | the name of KSP through which the operation was performed. | Microsoft Software Key Storage Provider |
ProviderType | string | 5442, 5448 | %%16387 |
|
ProxyPolicyName | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
PuaCount | string | 0, 2, 4, 9 | ||
PuaPolicyId | string | 0, 2, 4, 9 | ||
PubID | string | 0, 1, 1, 8 | ||
PublishURLs | string | 2, 4, 7, 8 | ||
Publisher | string | 0, 0, 5, 5 | ||
PublisherGuid | string | 0, 1, 1, 7 | ||
PublisherName | string | 0, 1, 1, 7 | ||
QMFilterID | string | 4654, 4979, 4980, 4981, 4982, 4983, 4984 | ||
QMLimit | string | 4650, 4651, 4979, 4980, 4981, 4982 | ||
Qualifiers | string | 1102, 4689, 4703, 8222 | "0" |
|
QuarantineGraceTime | string | 2, 6, 7, 7 | ||
QuarantineHelpURL | string | 6276, 6277, 6278 | ||
QuarantineSessionID | string | 6276, 6277, 6278 | ||
QuarantineSessionIdentifier | string | 2, 2, 6, 7 | ||
QuarantineState | string | 6272, 6276, 6277, 6278 | ||
QuarantineSystemHealthResult | string | 6276, 6277, 6278 | ||
QuickModeFilter | string | 4, 5, 7, 7 | ||
QuickModeSaId | string | 5451, 5452 | ||
ReadOperation | string | 3, 5, 7, 9 | %%8100 |
|
Reason | string | 1101, 1106, 4958, 5057, 5060, 6273, 6274, 6275 | ||
ReasonCode | string | 5632, 5633, 6273, 6274, 6275 | hexadecimal Reason Code for wired authentication results. | |
ReasonForRejection | string | 3, 4, 5, 9 | ||
ReasonText | string | 5632, 5633 | contains Reason Text (explanation of Reason Code) and Reason Code for wired authentication results. | |
RecordNumber | integer | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | 843214 |
|
RecoveryKeyId | string | 4692, 4693 | unique identifier of a recovery key. | |
RecoveryReason | string | 3, 4, 6, 9 | ||
RecoveryServer | string | 4692, 4693 | the name (typically - DNS name) of the computer that you contacted to recover your Master Key. | |
RelatedActivityID | string | 1102, 4611, 4624, 4627, 4634, 4648, 4662, 4670, 4672, 4673, 4674, 4688, 4689, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4720, 4724, 4726, 4728, 4729, 4732 | ||
RelativeTargetName | string | 1, 4, 5, 5 | PSEXESVC.exe |
|
RemoteAddress | string | 4650, 4651, 4652, 4653, 4654, 4655, 4960, 4961, 4962, 4963, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 5451, 5452 | ||
RemoteAddressMask | string | 4654, 5451, 5452 | ||
RemoteAdminEnabled | string | 4, 4, 4, 9 | ||
RemoteEMCertHash | string | 4980, 4982, 4983 | ||
RemoteEMIssuingCA | string | 4980, 4982, 4983 | ||
RemoteEMPrincipalName | string | 4979, 4980, 4981, 4982, 4983, 4984 | ||
RemoteEMRootCA | string | 4980, 4982, 4983 | ||
RemoteEventLogging | string | 2, 4, 6, 8 | ||
RemoteIpAddress | string | 1, 2, 5, 7 | ||
RemoteKeyModPort | string | 4650, 4651, 4652, 4653, 4979, 4980, 4981, 4982, 4983, 4984 | ||
RemoteMMCertHash | string | 4651, 4652, 4981, 4982 | ||
RemoteMMIssuingCA | string | 4651, 4652, 4981, 4982 | ||
RemoteMMPrincipalName | string | 4650, 4651, 4652, 4653, 4979, 4980, 4981, 4982 | ||
RemoteMMRootCA | string | 4651, 4652, 4981, 4982 | ||
RemoteMachineID | string | 5156, 5157 | S-1-0-0 |
|
RemotePort | string | 4654, 5451, 5452, 5712 | ||
RemotePrivateAddress | string | 4, 4, 5, 6 | ||
RemoteTunnelEndpoint | string | 4654, 5451, 5452 | ||
RemoteUserID | string | 5156, 5157 | S-1-0-0 |
|
ReplicationEvent | string | 4935, 4936 | there is no detailed information about this field in this document. | |
ReplicationStatusCode | string | 3, 4, 6, 9 | ||
RequestId | string | 4868, 4869, 4873, 4874, 4883, 4884, 4886, 4887, 4888, 4889, 4893, 4894 | ||
RequestType | string | 4, 4, 6, 9 | ||
Requester | string | 4886, 4887, 4888, 4889, 4893 | ||
Resource | string | 2, 3, 5, 8 | ||
ResourceAttributes | string | 4656, 4663 | - |
|
ResourceManager | string | 4, 5, 8, 9 | 1768FEC9-9F65-11EC-B264-0EE277C94A07 |
|
ResponderCookie | string | 4652, 4653 | ||
RestrictedAdminMode | string | 2, 4, 4, 6 | - |
|
RestrictedPermissions | string | 0, 4, 8, 9 | ||
RestrictedSidCount | string | 4656, 4661 | Number of restricted SIDs in the token. Applicable to only specific Object Types. | |
ReturnCode | integer | 3, 5, 7, 9 | 3221226021 |
|
ReturnCode | string | 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5379, 5382 | has "0x0" value for Success events. | 0x0 |
RevocationReason | string | 0, 4, 7, 8 | ||
Role | string | 4650, 4651, 4652, 4653, 4654, 4666, 4979, 4980, 4981, 4982, 4983, 4984, 5451 | (Access Request Information) Role | |
RoleSeparationEnabled | string | 4, 7, 8, 9 | ||
RowsDeleted | string | 4, 6, 8, 9 | ||
RpcCallClientLocality | string | 4698, 4699, 4700, 4701, 4702 | ||
RuleAttr | string | 4, 5, 7, 9 | Local Port |
|
RuleId | string | 4945, 4946, 4947, 4948, 4951, 4952, 4953, 4957, 4958 | the unique identifier for not applied firewall rule. | {5C6A0A6C-7D33-4849-8164-F43696BFF0D9} |
RuleName | string | 4945, 4946, 4947, 4948, 4951, 4952, 4953, 4957, 4958 | the name of the rule which was not applied. | Usermode Font Driver Host |
SPI | string | 4960, 4961, 4962, 4963, 4965 | ||
SSID | string | 2, 3, 5, 6 | ||
SamAccountName | string | 4720, 4727, 4731, 4735, 4737, 4738, 4741, 4742, 4744, 4745, 4749, 4750, 4754, 4755, 4759, 4760, 4783, 4784, 4790, 4791 | This is a new name of changed group used to support clients and servers from previous versions of Windows (pre-Windows 2000 logon name). If the value of sAMAccountName attribute of group object was changed, you will see the new value here. For example: ServiceDesk. | threatactor |
Schema | string | 5380, 5382 | ||
SchemaFriendlyName | string | 5380, 5382 | ||
Scope | string | 5064, 5065, 5066, 5067, 5068, 5069, 5070 | ||
ScopeName | string | 4, 6, 6, 6 | ||
ScriptPath | string | 4720, 4738, 4741, 4742 | specifies the path of the account's logon script. If the value of scriptPathattribute of computer object was changed, you will see the new value here. For computer objects, it is optional, and typically is not set. You can change this attribute by using Active Directory Users and Computers, or through a script, for example. | %%1793 |
SearchString | string | 0, 3, 5, 8 | ||
SecurityDescriptor | string | 4898, 5071 | ||
SecurityError | string | 1, 4, 6, 8 | ||
SecurityPackageName | string | 2, 2, 4, 6 | ||
SecuritySettings | string | 2, 4, 8, 8 | ||
SerialNumber | string | 1, 2, 5, 5 | ||
ServerNames | string | 1, 5, 6, 8 | ||
ServerPortName | string | 1, 4, 5, 6 | ||
ServiceAccount | string | 4, 6, 7, 9 | LocalSystem |
|
ServiceFileName | string | 4, 6, 7, 9 | %SystemRoot%\PSEXESVC.exe |
|
ServiceName | string | 4697, 4768, 4769, 4770, 4771, 4772, 4773, 4820, 4821, 4824 | the name of the service in the Kerberos Realm to which TGT request was sent. Typically has one of the following formats: krbtgt/DOMAIN_NETBIOS_NAME. Example: krbtgt/CONTOSO, krbtgt/DOMAIN_FULL_NAME. Example: krbtgt/CONTOSO.LOCAL | krbtgt |
ServicePrincipalNames | string | 4741, 4742 | The list of SPNs, registered for computer account. If the SPN list of a computer account changed, you will see the new SPN list in Service Principal Names field (note that you will see the new list instead of changes). | |
ServiceSid | string | 4768, 4769, 4770, 4820, 4821 | SID of the account or computer object for which the TGS ticket was renewed. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID cannot be resolved, you will see the source data in the event. | S-1-5-21-989241848-306340870-1210095284-502 |
ServiceStartType | string | 4, 6, 7, 9 | ||
ServiceType | string | 4, 6, 7, 9 | 0x10 |
|
SessionID | string | 4932, 4933, 4934 | unique identifier of replication session. Using this field you can find "4932: Synchronization of a replica of an Active Directory naming context has begun." and "4933: Synchronization of a replica of an Active Directory naming context has ended." events for the same session. | |
SessionId | integer | 4800, 4801 | unique ID of unlocked session. | 2 |
SessionId | string | 1102, 4611, 4624, 4627, 4634, 4648, 4662, 4670, 4672, 4673, 4674, 4688, 4689, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4720, 4724, 4726, 4728, 4729, 4732, 4800, 4801, 4802, 4803 | unique ID of a session for which screen saver was dismissed. You can see the list of current session IDs using "query session" command in command prompt. | |
SessionName | string | 4778, 4779 | the name of disconnected session | RDP-Tcp#1 |
SettingType | string | 0, 4, 5, 9 | Enable Windows Defender Firewall |
|
SettingValue | string | 0, 4, 5, 9 | No |
|
ShareLocalPath | string | 5140, 5142, 5143, 5144, 5145 | the full system (NTFS) path for accessed share. The format is: PATH | C:\Windows |
ShareName | string | 5140, 5142, 5143, 5144, 5145 | the name of accessed network share. | \*\E$ |
SidFilteringEnabled | string | 4706, 4716 | SID Filtering state for the new trust. | |
SidHistory | string | 4720, 4727, 4731, 4735, 4737, 4738, 4741, 4742, 4744, 4745, 4749, 4750, 4754, 4755, 4759, 4760, 4783, 4784, 4790, 4791 | contains previous SIDs used for the object if the object was moved from another domain. Whenever an object is moved from one domain to another, a new SID is created and becomes the objectSID. The previous SID is added to the sIDHistory property. If the value of sIDHistory attribute of group object was changed, you will see the new value here. | - |
SidList | string | 4675, 4765, 4830, 4908, 4964 | the list of special group SIDs, which New Logon\Security ID is a member of. | |
SigmaEventCode | integer | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | 8222 |
|
SiloName | string | 4820, 4821, 4823 | ||
SourceAddr | string | 4928, 4929, 4930, 4931 | DNS record of computer to which the modification request was sent. | |
SourceAddress | string | 5146, 5147, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159 | The local IP address of the computer running the application. | :: |
SourceDRA | string | 4928, 4929, 4930, 4931, 4932, 4933, 4937 | source directory replication agent distinguished name. | |
SourceHandleId | string | 0, 4, 6, 9 | 0xb88 |
|
SourcePort | integer | 5152, 5154, 5156, 5157, 5158 | Port number which application was bind. | 5355 |
SourcePort | string | 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159 | The port number used by the application. | |
SourceProcessId | string | 0, 4, 6, 9 | 0x8f8 |
|
SourceSid | string | 4765, 4830 | ||
SourceUserName | string | 4765, 4766, 4830 | ||
Source_Port | integer | 4768, 4769, 5140, 5145 | 49901 |
|
Source_Port | string | 4624, 4625, 4648 | - |
|
Source_Workstation | string | 4624, 4625, 4648, 4768, 4769, 4776, 5140, 5145 | EC2AMAZ-NNKUICG |
|
SourcevSwitchPort | string | 5146, 5147 | ||
SpnName | string | 1, 5, 6, 8 | ||
StagingReason | string | 1, 4, 8, 8 | ||
StartUSN | string | 2, 3, 4, 9 | ||
State | string | 4652, 4653, 4654, 4983, 4984 | ||
Status | string | 4625, 4665, 4689, 4768, 4769, 4771, 4776, 4777, 4793, 4794, 4820, 4821, 4822, 4823, 4824, 5125 | for Success events it has "0x0" value. | 0xc000006d |
StatusCode | string | 4928, 4929, 4930, 4931, 4933, 4934, 4937 | if there are no issues or errors, the status code will be "0". If an error happened, you will receive Failure event and Status Code will not be equal to "0". | |
StoreUrl | string | 4, 6, 6, 8 | ||
SubLayerKey | string | 5444, 5450 | 3C1CD879-1B8C-4AB4-8F83-5ED129176EF3 |
|
SubLayerName | string | 5444, 5450 | windefend |
|
SubLayerType | string | 5444, 5450 | %%16388 |
|
SubStatus | string | 2, 4, 5, 6 | 0xc000006a |
|
Sub_Status | string | 2, 4, 5, 6 | 0xc000006a |
|
SubcategoryGuid | string | 4719, 4912 | the unique GUID of changed subcategory. | 0CCE9215-69AE-11D9-BED3-505054503030 |
SubcategoryId | string | 4719, 4912 | the name of auditing subcategory which state was changed. | %%12544 |
Subject | string | 4887, 4888, 4889 | ||
SubjectDomainName | string | 1102, 4611, 4615, 4616, 4624, 4625, 4626, 4627, 4648, 4649, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4817, 4818, 4819, 4826, 4830, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4873, 4874, 4875, 4876, 4877, 4882, 4883, 4884, 4885, 4890, 4891, 4892, 4894, 4896, 4904, 4905, 4907, 4911, 4912, 4913, 4964, 4985, 5039, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5632, 5633, 5712, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6416, 6419, 6420, 6421, 6422, 6423, 6424 | subject's domain or computer name. | training1 |
SubjectKeyIdentifier | string | 4887, 4888, 4889 | ||
SubjectLogonId | integer | 5888, 5890 | hexadecimal value that can help you correlate this event with recent events that might contain the same Logon ID, for example, "4624: An account was successfully logged on." | 1207182 |
SubjectLogonId | string | 1102, 4611, 4615, 4616, 4624, 4625, 4626, 4627, 4648, 4649, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4817, 4818, 4819, 4826, 4830, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4873, 4874, 4875, 4876, 4877, 4882, 4883, 4884, 4885, 4890, 4891, 4892, 4894, 4896, 4904, 4905, 4907, 4911, 4912, 4913, 4964, 4985, 5039, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5632, 5633, 5712, 5888, 5889, 5890, 6416, 6419, 6420, 6421, 6422, 6423, 6424 | hexadecimal value that can help you correlate this event with recent events that might contain the same Logon ID, for example, "4624: An account was successfully logged on." | 0xcedae |
SubjectMachineName | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
SubjectMachineSID | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
SubjectUserDomainName | string | 5888, 5889, 5890 | subject's domain or computer name. | EC2AMAZ-NNKUICG |
SubjectUserName | string | 1102, 4611, 4615, 4616, 4624, 4625, 4626, 4627, 4648, 4649, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4817, 4818, 4819, 4826, 4830, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4873, 4874, 4875, 4876, 4877, 4882, 4883, 4884, 4885, 4890, 4891, 4892, 4894, 4896, 4904, 4905, 4907, 4911, 4912, 4913, 4964, 4985, 5039, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5632, 5633, 5712, 5888, 5889, 5890, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6416, 6419, 6420, 6421, 6422, 6423, 6424 | the name of the account that forbids the device installation. | user |
SubjectUserSid | string | 1102, 4611, 4615, 4616, 4624, 4625, 4626, 4627, 4648, 4649, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4767, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4817, 4818, 4819, 4826, 4830, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4873, 4874, 4875, 4876, 4877, 4882, 4883, 4884, 4885, 4890, 4891, 4892, 4894, 4896, 4904, 4905, 4907, 4911, 4912, 4913, 4964, 4985, 5039, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5712, 5888, 5889, 5890, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6416, 6419, 6420, 6421, 6422, 6423, 6424 | SID of account that forbids the device installation. | S-1-5-21-989241848-306340870-1210095284-500 |
SystemTime | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | '2022-07-28 14:45:40.532999 UTC' |
|
System_Props_Xml | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 |
|
|
TableId | string | 4, 6, 8, 9 | ||
TargetDomainName | string | 4624, 4625, 4626, 4627, 4634, 4647, 4648, 4649, 4675, 4688, 4696, 4703, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4772, 4773, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4820, 4821, 4830, 4964 | subject's domain or computer name. | doazlab.com |
TargetHandleId | string | 0, 4, 6, 9 | 0xf80 |
|
TargetInfo | string | 4, 4, 6, 8 | localhost |
|
TargetLinkedLogonId | string | 2, 4, 4, 6 | 0x0 |
|
TargetLogonGuid | string | 4648, 4964 | a GUID that can help you correlate this event with another event that can contain the same Logon GUID, "4769(S, F): A Kerberos service ticket was requested event on a domain controller. | 00000000-0000-0000-0000-000000000000 |
TargetLogonId | string | 4618, 4624, 4626, 4627, 4634, 4647, 4688, 4696, 4703, 4800, 4801, 4802, 4803, 4964 | hexadecimal value that can help you correlate this event with recent events that might contain the same Logon ID, for example, "4624: An account was successfully logged on." | 0x9fb6c3 |
TargetName | string | 3, 5, 7, 9 | WindowsLive:target=virtualapp/didlogical |
|
TargetOutboundDomainName | string | 2, 4, 4, 6 | - |
|
TargetOutboundUserName | string | 2, 4, 4, 6 | - |
|
TargetProcessId | string | 4690, 4696 | hexadecimal Process ID of the new process with new security token. If you convert the hexadecimal value to decimal, you can compare it to the values in Task Manager. | 0x4 |
TargetProcessName | string | 4, 6, 6, 9 | ||
TargetServer | string | 3, 5, 7, 8 | ||
TargetServerName | string | 4, 4, 6, 8 | localhost |
|
TargetSid | string | 4704, 4705, 4717, 4718, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4771, 4780, 4781, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4798, 4799, 4820, 4824, 4830 | SID of the group which members were enumerated. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID cannot be resolved, you will see the source data in the event. | S-1-5-32-545 |
TargetUserDomain | string | 1, 4, 6, 8 | ||
TargetUserName | string | 4618, 4624, 4625, 4626, 4627, 4634, 4647, 4648, 4649, 4675, 4688, 4696, 4703, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4776, 4777, 4780, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4820, 4821, 4824, 4830, 4964 | the name of the account that performed the logon. | user |
TargetUserSid | string | 4618, 4624, 4625, 4626, 4627, 4634, 4647, 4675, 4688, 4696, 4703, 4800, 4801, 4802, 4803, 4912, 4964 | SID of account that performed the logon. | S-1-5-21-989241848-306340870-1210095284-500 |
Target_Domain | string | 4624, 4625, 4627, 4634, 4648, 4688, 4703, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4798, 4799, 4800, 4801 | doazlab.com |
|
Target_Server_Name | string | 4, 4, 6, 8 | localhost |
|
Target_User_Name | string | 4624, 4625, 4627, 4634, 4648, 4688, 4703, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4798, 4799, 4800, 4801 | user |
|
TaskContent | string | 4698, 4699, 4700, 4701 | the XML of the disabled task. | |
TaskContentNew | string | 0, 2, 4, 7 | ||
TaskName | string | 4698, 4699, 4700, 4701, 4702 | updated/changed scheduled task name. | \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskLogon |
TdoAttributes | string | 4675, 4706, 4716 | the decimal value of attributes for new trust. | |
TdoDirection | string | 4675, 4706, 4716 | the direction of new trust. If this attribute was not changed, then it will have "-" value or its old value. | |
TdoSid | string | 4, 5, 6, 7 | ||
TdoType | string | 4675, 4706, 4716 | the type of new trust. If this attribute was not changed, then it will have "-" value or its old value. | |
TemplateContent | string | 4, 8, 8, 9 | ||
TemplateDSObjectFQDN | string | 4898, 4899, 4900 | ||
TemplateInternalName | string | 4898, 4899, 4900 | ||
TemplateOID | string | 4898, 4899, 4900 | ||
TemplateSchemaVersion | string | 4898, 4899, 4900 | ||
TemplateVersion | string | 4898, 4899, 4900 | ||
TestSigning | string | 2, 4, 6, 8 | ||
ThreadID | string | 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4949, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5478, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424 | "9040" |
|
TicketEncryptionType | string | 4768, 4769, 4770, 4820, 4821 | the cryptographic suite that was used in renewed TGS. | 0x12 |
TicketOptions | string | 4768, 4769, 4770, 4771, 4772, 4773, 4820, 4821, 4824 | this is a set of different Ticket Flags in hexadecimal format | 0x40810010 |
TokenElevationType | string | 4688 | %%1936 |
|
Token_Elevation_Type | string | 4688 | %%1936 |
|
Token_Elevation_Type_id | integer | 4688 | 1936 |
|
TopLevelName | string | 4864, 4865, 4866, 4867 | the name of the modified trusted forest information entry. | |
TrafficSelectorId | string | 4654, 5451, 5452 | ||
TransactionId | string | 4656, 4659, 4660, 4661, 4664, 4985 | unique GUID of the transaction. This field can help you correlate this event with other events that might contain the same Transaction ID, such as "4656(S, F): A handle to an object was requested." | 870CF9EA-0BF4-11ED-80BB-42010A743766 |
TransitedServices | string | 1, 2, 4, 8 | ||
TransmittedServices | string | 4624, 4625, 4649, 4769 | this field contains list of SPNs which were requested if Kerberos delegation was used. | - |
TransportFilterId | string | 1, 4, 5, 5 | ||
TreeDelete | string | 1, 1, 4, 5 | ||
TunnelId | string | 4654, 5451, 5452 | ||
TypeOfChange | string | 3, 4, 4, 9 | ||
USN | string | 3, 4, 4, 9 | ||
UserAccountControl | string | 4720, 4738, 4741, 4742 | shows the list of changes in userAccountControl attribute. You will see a line of text for each change. See possible values in here: "Table 7. User's or Computer's account UAC flags.". In the "User Account Control field text" column, you can see text that will be displayed in the User Account Controlfield in 4742 event. | %%2080 |
UserClaims | string | 2, 4, 6, 6 | ||
UserData_Xml | string | 0, 1, 1, 2 |
|
|
UserID | string | 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424, 8222 | "S-1-5-18" |
|
UserName | string | 5446, 5447, 5448, 5449, 5450 | NT AUTHORITY\NETWORK SERVICE |
|
UserParameters | string | 4720, 4738, 4741, 4742 | if you change any setting using Active Directory Users and Computers management console in Dial-in tab of computer's account properties, then you will see \ |
- |
UserPrincipalName | string | 4720, 4738, 4741, 4742 | internet-style login name for the account, based on the Internet standard RFC 822. By convention this should map to the account's email name. If the value of userPrincipalNameattribute of computer object was changed, you will see the new value here. For computer objects, it is optional, and typically is not set. You can change this attribute by using Active Directory Users and Computers, or through a script, for example. | - |
UserSid | string | 5446, 5447, 5448, 5449, 5450 | S-1-5-20 |
|
UserUPN | string | 3, 5, 7, 8 | ||
UserWorkstations | string | 4720, 4738, 4741, 4742 | contains the list of NetBIOS or DNS names of the computers from which the user can logon. Each computer name is separated by a comma. The name of a computer is the sAMAccountName property of a computer object. If the value of userWorkstations attribute of computer object was changed, you will see the new value here. For computer objects, it is optional, and typically is not set. You can change this attribute by using Active Directory Users and Computers, or through a script, for example. | %%1793 |
ValidFrom | string | 4, 5, 8, 9 | ||
ValidTo | string | 4, 5, 8, 9 | ||
Value | string | 4891, 5069 | ||
VendorIds | string | 1, 4, 6, 6 | MONITOR\Default_Monitor |
|
Version | integer | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416 | 3 |
|
VirtualAccount | string | 2, 4, 4, 6 | %%1843 |
|
VirtualFileName | string | 0, 1, 5, 5 | ||
VlanTag | string | 5146, 5147, 5150, 5151 | ||
VsmLaunchType | string | 2, 4, 6, 8 | ||
Weight | integer | 5447, 5450 | 4096 |
|
Weight | string | 5441, 5444, 5447, 5450 | ||
Workstation | string | 4776, 4777, 4793, 4794, 4797 | the name of computer account from which the password was queried from For example "DC01". If the change request was sent locally (from the same server) this field will have the same name as the computer account | EC2AMAZ-1CL0VOR |
WorkstationName | string | 4624, 4625, 4649 | machine name from which logon attempt was performed. | EC2AMAZ-NNKUICG |
change_type | string | 1102, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738 | user |
|
dest | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | windowsvictim |
|
dest_nt_domain | string | 4624, 4625, 4627, 4634, 4648, 4688, 4703, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4798, 4799, 4800, 4801 | training1 |
|
dest_nt_host | string | 4, 4, 6, 8 | localhost |
|
dest_port | integer | 5152, 5156, 5157 | 5355 |
|
dvc | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | windowsvictim |
|
dvc_nt_host | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | windowsvictim_f57c890c-8963-4b7b-b267-755cd8191034 |
|
event_id | integer | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | 843214 |
|
file_name | string | 4656, 4663, 4907, 4911, 5058, 5140, 5142, 5145 | c56b3f40b196d4f8d43940688b5b8765_4d6cbdb8-0892-45ee-9d0d-f2e8b7a5fa78 |
|
file_path | string | 4656, 4663, 4907, 4911, 5058, 5140, 5142, 5145 | C:\Windows |
|
new_process | string | 4688 | C:\Windows\System32\conhost.exe |
|
new_process_id | string | 4688 | 0x2260 |
|
new_process_name | string | 4688 | conhost.exe |
|
notification | string | 4, 4, 6, 6 | ||
object | string | 1102, 4611, 4624, 4627, 4634, 4648, 4662, 4670, 4672, 4673, 4674, 4688, 4689, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4738 | Guest |
|
object_attrs | string | 1102, 4703, 4717, 4718, 4719, 4722, 4724, 4725, 4726, 4738, 4946, 4947, 4948, 4957 | registry |
|
object_category | string | 1102, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738 | user |
|
object_file_name | string | 4656, 4657, 4661, 4662, 4663, 4674, 4907, 4911 | lsass.exe |
|
object_file_path | string | 4656, 4657, 4661, 4662, 4663, 4674, 4907, 4911 | root\cimv2\security\MicrosoftVolumeEncryption |
|
object_id | string | 4703, 4722, 4724, 4725, 4726, 4738 | S-1-5-21-582766833-432816504-4207985818-501 |
|
param1 | string | 4709, 4710, 4711, 4712, 4816, 5038, 6281, 6410 | ||
param2 | string | 4709, 4710, 4816 | ||
param3 | string | 4709, 4816 | ||
parent_process | string | 4688 | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
|
parent_process_id | string | 4688 | 0x2024 |
|
parent_process_name | string | 4688 | powershell.exe |
|
parent_process_path | string | 4688 | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
|
process_command_line_arguments | string | 4688 | 0xffffffff -ForceV1 |
|
process_command_line_process | string | 4688 | C:\Windows\system32\conhost.exe |
|
process_exec | string | 4673, 4674, 4688, 4689 | wevtutil.exe |
|
process_id | integer | 5152, 5154, 5158, 5446, 5447, 5448, 5449, 5450 | 8456 |
|
process_id | string | 4624, 4625, 4648, 4656, 4657, 4658, 4660, 4661, 4663, 4670, 4673, 4674, 4688, 4689, 4703, 4904, 4905, 4907, 4911, 4985 | 0xeb4 |
|
process_path | string | 4624, 4625, 4648, 4656, 4657, 4658, 4660, 4661, 4663, 4670, 4673, 4674, 4688, 4689, 4703, 4904, 4905, 4907, 4911, 4985 | C:\Windows\System32\wevtutil.exe |
|
registry_path | string | 4, 5, 6, 7 | \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN |
|
registry_value_name | string | 4, 5, 6, 7 | ConfigXML |
|
registry_value_type | string | 4, 5, 6, 7 | %%1873 |
|
result | string | 4703, 4717, 4718, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738 | member was removed from a security-enabled local group |
|
service_id | string | 4768, 4769 | S-1-5-21-989241848-306340870-1210095284-502 |
|
service_name | string | 4697, 4768, 4769, 5478 | krbtgt |
|
session_id | integer | 5888, 5890 | 1207182 |
|
session_id | string | 4611, 4624, 4625, 4627, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4798, 4799, 4904, 4905, 4907, 4911, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5379, 5381, 6416 | 0xcedae |
|
sigma_product | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | windows |
|
sigma_service | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | security |
|
signature | string | 1102, 4611, 4624, 4625, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4800, 4801, 4904, 4905, 4907, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890 | Windows Firewall settings were restored to the default values |
|
signature_id | integer | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | 8222 |
|
src | string | 4624, 4625, 4648, 4768, 4769, 4776, 4778, 5140, 5145 | EC2AMAZ-NNKUICG |
|
src_ip | string | 4624, 4625, 4648, 4769, 5140 | ::ffff:10.0.1.8 |
|
src_nt_domain | string | 4611, 4624, 4625, 4627, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4798, 4799, 4904, 4905, 4907, 4911, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5379, 5381, 6416 | training1 |
|
src_nt_host | string | 4624, 4625, 4648, 4768, 4769, 4776, 5140, 5145 | EC2AMAZ-NNKUICG |
|
src_port | integer | 4768, 4769, 5140, 5145, 5156, 5158 | 5355 |
|
src_port | string | 4624, 4625, 4648 | - |
|
src_user | string | 1102, 4611, 4624, 4625, 4627, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4798, 4799, 4904, 4905, 4907, 4911, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5379, 5381, 5888, 5890, 6416 | user |
|
src_user_name | string | 4703, 4722, 4724, 4725, 4726, 4738 | user |
|
start_mode | string | 4, 6, 7, 9 | manual |
|
subject | string | 1102, 4611, 4624, 4625, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4800, 4801, 4904, 4905, 4907, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890 | Windows Firewall settings were restored to the default values |
|
ta_windows_action | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | failure |
|
ta_windows_security_CategoryString | string | 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738 | Account Management |
|
ta_windows_status | string | 4625, 4689, 4768, 4769, 4776 | 0xc000006d |
|
timeendpos | integer | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | 526 |
|
timestartpos | integer | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | 496 |
|
transport | string | 5152, 5154, 5156, 5157, 5158 | UDP |
|
user_group | string | 4624, 4625, 4627, 4634, 4648, 4688, 4703, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4798, 4799, 4800, 4801 | user |
|
user_id | string | 2, 2, 2, 8 | "S-1-5-18" |
|
user_name | string | 4703, 4722, 4724, 4725, 4726, 4738 | Guest |
|
vendor | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | Microsoft |
|
vendor_product | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | Microsoft Windows |
smbclient-security
Field | Data Type | Event IDs | Example |
---|---|---|---|
EventID | integer | 31001, 31018 | 31018 |
Name | string | 31001, 31018 | Microsoft-Windows-SMBClient |
EventCode | integer | 31001, 31018 | 31018 |
Guid | string | 31001, 31018 | 988C59C5-0A1C-45B6-A555-0C62276E327D |
ProcessID | integer | 31001, 31018 | 4 |
ProcessId | integer | 31001, 31018 | 4 |
SigmaEventCode | integer | 31001, 31018 | 31018 |
SystemTime | string | 31001, 31018 | '2022-05-23 16:00:29.832323 UTC' |
ThreadID | integer | 31001, 31018 | 340 |
UserID | string | 31001, 31018 | S-1-5-18 |
sigma_product | string | 31001, 31018 | windows |
sigma_service | string | 31001, 31018 | smbclient-security |
timeendpos | integer | 31001, 31018 | 515 |
timestartpos | integer | 31001, 31018 | 485 |
xmlns | string | 31001, 31018 | http://schemas.microsoft.com/win/2004/08/events/event |
system
Field | Data Type | Event IDs | Example |
---|---|---|---|
Application | string | 1, 5, 6, 10, 14, 15 | |
Command | string | 16, 17, 24, 25, 40, 41, 42, 43 | |
Computer | string | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 201, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 262, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 285, 286, 289, 290, 300, 301, 302, 379, 380, 381, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 566, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1025, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1056, 1058, 1060, 1061, 1065, 1068, 1074, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1281, 1282, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2001, 2003, 2004, 2005, 2042, 3261, 4000, 4001, 4002, 4003, 4004, 4005, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5202, 5203, 5211, 5300, 5774, 5781, 5782, 5805, 5823, 6000, 6005, 6006, 6009, 6011, 6013, 6027, 6033, 6035, 6036, 6037, 6038, 6040, 6041, 6100, 6145, 6146, 6148, 6400, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 9009, 10000, 10001, 10002, 10003, 10004, 10005, 10010, 10016, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10121, 10148, 10149, 10154, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14206, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 14531, 14533, 15007, 15008, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16647, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 16983, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 20010, 24576, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50036, 50037, 50038, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | win10-base |
Data | integer | 1, 8 | 0 |
Data | string | 2, 12, 14, 15, 16, 18, 20, 22, 25 | |
Event | string | 0, 0, 3, 4 | |
EventID | integer | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 201, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 262, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 285, 286, 289, 290, 300, 301, 302, 379, 380, 381, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 566, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1025, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1056, 1058, 1060, 1061, 1065, 1068, 1074, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1281, 1282, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2001, 2003, 2004, 2005, 2042, 3261, 4000, 4001, 4002, 4003, 4004, 4005, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5202, 5203, 5211, 5300, 5774, 5781, 5782, 5805, 5823, 6000, 6005, 6006, 6009, 6011, 6013, 6027, 6033, 6035, 6036, 6037, 6038, 6040, 6041, 6100, 6145, 6146, 6148, 6400, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 9009, 10000, 10001, 10002, 10003, 10004, 10005, 10010, 10016, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10121, 10148, 10149, 10154, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14206, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 14531, 14533, 15007, 15008, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16647, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 16983, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 20010, 24576, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50036, 50037, 50038, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 98 |
FileName | string | 6, 8, 10, 11, 12, 14, 150 | |
Filename | string | 0, 0, 0, 1 | |
Id | string | 16385, 16386, 16390 | 4AAC461E-F8E1-4F65-A8CA-EDB4CC03A0C3 |
Key | string | 0, 1, 4, 5, 6 | |
Line | string | 0, 0, 0, 1 | |
Name | string | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36884, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | "stornvme" |
Origin | string | 5, 5 | |
Path | string | 20, 22, 23, 9009, 36912 | C:\inetpub\history\CFGHISTORY_0000000005 |
ProcessName | string | 1, 41, 150, 225 | \Device\HarddiskVolume2\Windows\System32\svchost.exe |
Program | string | 6036, 6037 | |
Target | string | 40960, 40961, 40962, 40965 | |
Task | integer | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 8 |
Task | string | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 300, 301, 302, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1058, 1060, 1061, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2003, 2004, 2005, 2042, 4000, 4001, 4002, 4003, 4004, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5300, 6000, 6027, 6033, 6035, 6036, 6037, 6040, 6041, 6100, 6145, 6146, 6400, 7001, 7002, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 10000, 10001, 10002, 10003, 10004, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50037, 50038, 51047, 51057 | |
Type | string | 90, 36867, 36868, 36869, 36870, 36871, 36872, 36880, 36889 | |
User | string | 16950, 16951, 16952 | |
Window | string | 9 | |
enabled | string | 1, 3, 6, 6, 9 | |
hr | string | 1, 16404, 24836, 24842, 24843, 24844, 24845, 24846 | |
id | integer | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 93485 |
line | string | 0, 1, 4, 4, 6 | |
name | string | 519, 566 | Object Operation (W3 Active Directory) |
process_name | string | 1 | \Device\HarddiskVolume2\Windows\System32\svchost.exe |
product | string | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | Windows |
rule | string | 1, 3, 6, 6, 9 | |
service | integer | 7009, 10005, 10111 | 50 |
service | string | 1074, 7000, 7001, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 10010, 10016, 14204, 14205 | {4991D34B-80A1-4291-83B6-3328366B9097} |
status | string | 18, 19, 6027, 7036, 16396, 32773, 32774, 32775 | stopped |
APCpuidData | string | 7, 9 | |
AbandonedBatteryCount | string | 1, 2, 5 | |
AbortiveDisconnect | string | 6, 9 | |
AcOnline | string | 0, 1, 5 | |
AccessMode | string | 28, 29 | |
AccountDistinguishedName | string | 12293, 12303, 12304, 16391, 16392, 16393 | |
AccountName | string | 7045, 16384, 16401, 16402, 16403, 16409, 16411, 16413, 16978 | Network Service |
AccountRID | string | 1, 3, 4, 6, 9 | |
AccountSID | string | 1, 2, 3, 6, 9 | |
Action | string | 90, 130 | |
ActiveBatteryCount | string | 2, 4, 5 | |
ActiveOperation | string | 0, 0, 1, 1, 1 | |
ActiveResidencyInUs | string | 0, 5, 7 | |
ActivityID | string | 14, 19, 20, 43, 44, 1006, 1129, 1500, 1501, 1502, 1503, 2003, 2004, 7001, 7002, 7043, 10005, 10010, 10016, 16392, 16962, 16977, 16983 | "FFE311E3-7084-4A19-B935-F331C2DB7296" |
ActualFunctionTableSize | string | 6, 8 | |
ActualFuntionTableCount | string | 0, 1, 1, 1, 7 | |
ActualMaxInterval | string | 0, 1, 8 | |
ActualSize | string | 5 | |
ActualVersion | string | 6, 8 | |
AdSuffix | string | 0, 0, 1, 1 | |
AdapterName | string | 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 10317, 10400 | {87056817-E272-4172-BD6E-DB007E723246} |
AdapterSuffixName | string | 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038 | snapattack.labs |
AddServiceStatus | string | 20003, 20004 | |
AdditionalDetails | string | 2 | |
AdditionalInfo | string | 55, 129 | |
Address | string | 6, 8, 10, 12, 14, 16, 17, 1014, 4200 | 1700000000000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 |
AddressLength | string | 0, 1, 1, 4 | |
AddressSpace | string | 28, 29 | |
AffinityCount | string | 8, 9 | |
AffinityLevel | string | 28, 29 | |
AgentName | string | 15, 16 | |
AlertDesc | integer | 3, 6, 7, 8, 8 | 70 |
AlertDesc | string | 36887, 36888 | |
AllowIeeePriorityTag | string | 8, 8 | |
AllowMacSpoofing | string | 8, 8 | |
AllowTeaming | string | 8, 8 | |
AllowedOnes | string | 4, 6 | |
AllowedZeroes | string | 4, 6 | |
AoAcCompliantNic | string | 0, 5, 7 | |
ApiCallerName | string | 1, 7, 8 | |
ApiCallerNameLength | string | 1, 7, 8 | |
ApicId | string | 18, 19, 20, 21 | |
AppName | string | 6, 8, 9, 10, 11, 12, 14 | |
AppNameLength | string | 9 | |
Applicability | string | 0, 9 | |
Argument | string | 1000, 1001, 1002, 1004 | |
Argument1 | string | 2, 2, 2 | |
Argument2 | string | 2, 2, 2 | |
Arguments | string | 1, 5, 6, 10, 14, 15 | |
Attributes | string | 1 | |
AudioPlaybackInUs | string | 0, 5, 7 | |
AudioPlaying | string | 0, 5, 7 | |
Authorize | string | 1, 3 | |
AvailableAddressFilters | string | 243, 244 | |
AverageResume | string | 1, 1, 3 | |
BCDSetting | string | 2, 3, 5 | |
BSPCpuidData | string | 7, 9 | |
BackupPath | string | 104, 105 | |
BadFileOffset | string | 0, 1, 5 | |
BadLcn | string | 0, 1, 5 | |
BalStatus | string | 26, 38 | |
BandID | string | 1, 3 | |
BandMetadataSize | string | 1, 2 | |
Bank | string | 22, 23, 46, 47, 48, 49 | |
BatteryActionInternalFlags | string | 2, 4, 5 | |
BatteryFullChargeCapacityOnEnter | string | 0, 5, 6 | |
BatteryFullChargeCapacityOnExit | string | 0, 5, 7 | |
BatteryRemainingCapacityOnEnter | string | 0, 5, 6 | |
BatteryRemainingCapacityOnExit | string | 0, 5, 7 | |
BiasValid | string | 0, 1, 8 | |
BinaryData | string | 1, 1, 3, 4, 6 | |
BiosInitDuration | string | 1 | |
BitPosition | string | 22, 23, 46, 47 | |
BitlockerUserInputTime | string | 2, 3 | |
BlMemoryAttributes | string | 0, 1 | |
BlMemoryType | string | 0, 1 | |
BlPageCount | string | 0, 1 | |
BlStartPage | string | 0, 1 | |
BlockLength | string | 2, 3, 3, 4, 8 | |
BlockNumber | string | 2, 3, 3, 4, 8 | |
BootAppStatus | string | 1, 4 | |
BootApplication | string | 522, 523 | |
BootId | integer | 5, 6, 6 | 3 |
BootId | string | 506, 507 | |
BootMenuPolicy | string | 2, 5 | |
BootMode | string | 1, 2 | |
BootStatusPolicy | string | 0, 2 | |
BootType | string | 2, 7 | |
BridgeControl | string | 16, 17, 40, 41 | |
BridgeStatus | string | 16, 17, 40, 41 | |
BugcheckCode | string | 1, 4 | |
BugcheckInfoFromEFI | string | 1, 4 | |
BugcheckParameter | string | 1, 4 | |
BugcheckParameter1 | string | 1, 4 | 0x0 |
BugcheckParameter2 | string | 1, 4 | 0x0 |
BugcheckParameter3 | string | 1, 4 | 0x0 |
BugcheckParameter4 | string | 1, 4 | 0x0 |
BuildVersion | string | 1, 2 | |
BurstLimit | string | 2, 8 | |
BurstSize | string | 2, 8 | |
Bus | string | 16, 17, 40, 41 | |
BusAddress | string | 24, 25, 42, 43 | |
BusData | string | 24, 25, 42, 43 | |
BusNumber | string | 24, 25, 26, 27, 42, 43, 44, 45 | |
BusSegment | string | 24, 25, 42, 43 | |
CAPEDesc | string | 1, 4, 6, 6 | |
CAPEName | string | 1, 4, 6, 6 | |
CLSID | string | 10001, 10002 | |
CPU | string | 96, 97 | |
CSPName | string | 3, 6, 6, 8, 8 | |
CSPType | string | 3, 6, 6, 8, 8 | |
CVEID | string | 2 | |
CVEId | string | 0, 0, 1 | |
CacheFlushNeeded | string | 1, 5, 6 | |
CacheFlushSupported | string | 1, 5, 6 | |
CacheLevel | string | 28, 29 | |
CacheSend | string | 7, 9 | |
CallStack | string | 5, 5 | |
CallerProcessName | string | 0, 0, 4, 6 | |
CapDurationInSeconds | string | 7, 37 | |
Capabilities | string | 1, 2 | |
Caption | string | 2, 6 | Ec2Config.exe - Application Error |
Card | string | 22, 23, 46, 47 | |
CardHandle | string | 22, 23, 46, 47 | |
CeilingTriggerRid | string | 16656, 16657 | |
CertFlags | string | 2, 3, 6, 7, 8 | |
ChainLoggingRate | string | 1, 4, 6 | |
ChainingCountFailure | string | 1, 4, 6 | |
ChainingCountRequests | string | 1, 4, 6 | |
ChainingCountSuccess | string | 1, 4, 6 | |
ChangeReason | string | 0, 0, 3, 4 | |
Channel | string | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 201, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 262, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 285, 286, 289, 290, 300, 301, 302, 379, 380, 381, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 566, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1025, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1056, 1058, 1060, 1061, 1065, 1068, 1074, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1281, 1282, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2001, 2003, 2004, 2005, 2042, 3261, 4000, 4001, 4002, 4003, 4004, 4005, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5202, 5203, 5211, 5300, 5774, 5781, 5782, 5805, 5823, 6000, 6005, 6006, 6009, 6011, 6013, 6027, 6033, 6035, 6036, 6037, 6038, 6040, 6041, 6100, 6145, 6146, 6148, 6400, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 9009, 10000, 10001, 10002, 10003, 10004, 10005, 10010, 10016, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10121, 10148, 10149, 10154, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14206, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 14531, 14533, 15007, 15008, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16647, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 16983, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 20010, 24576, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50036, 50037, 50038, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | System |
ChannelPath | string | 21, 25, 26, 27, 28, 29, 30, 31, 40 | |
Checkpoint | string | 41, 218 | |
CheckpointDuration | string | 1 | |
CheckpointStatus | string | 1, 4 | |
CipherSuite | string | 0, 3, 6, 8, 8 | |
ClassCode | string | 16, 17, 26, 27, 40, 41, 44, 45 | |
ClearReason | string | 1, 5, 9 | SRK has changed or is not present. |
ClfsStatus | string | 1 | |
Client | string | 0, 3, 3, 6 | |
ClientAddress | string | 1, 5, 7 | |
ClientContext | string | 34, 35, 36 | |
ClientDisconnect | string | 6, 9 | |
ClientPID | integer | 0, 1, 1, 4 | 2352 |
ClientRID | string | 1, 5, 6 | |
ClientVersion | string | 2, 6 | |
ClientVersionLen | string | 2, 6 | |
ClustersCount | string | 0, 1, 5 | |
CmdStatus | string | 0, 1 | |
Column | string | 22, 23, 46, 47 | |
CompleterId | string | 24, 25, 42, 43 | |
CompletionType | string | 1101, 1102, 1103, 1104, 1201, 1202 | |
ComputedRIDValue | string | 1, 4, 6, 6, 6 | |
ComputerName | string | 4096, 4097, 4098, 4099, 12297, 12298, 16935, 16936, 16937 | |
Config | string | 1, 4 | |
ConfigProperty | string | 1, 2 | |
ConfigurationReader | string | 1, 1, 2, 5 | ConfigurationSystem |
ConflictingParameter | string | 0, 1, 1, 1, 3 | |
ConnectedStandbyInProgress | string | 1, 4 | |
ConnectionBufferFull | string | 8, 9 | |
ConnectivityState | string | 2, 6, 8 | |
Context | string | 1, 2, 3, 5, 100, 101, 102, 1008, 1012 | |
ContextHandle | string | 0, 3, 6, 8, 8 | |
ControlDeviceName | string | 2 | |
CorrectableErrorStatus | string | 16, 17, 18, 40, 41 | |
CorruptionActionState | string | 8, 9 | |
CorruptionState | string | 5, 5 | |
Count | string | 1, 2 | |
CountNew | string | 0, 2 | |
CountOld | string | 0, 2 | |
CreatorId | string | 1, 2 | |
CredContext | string | 36872, 36889 | |
CsEntryScenarioInstanceId | string | 1, 4 | |
CurrentBias | integer | 2, 4 | 420 |
CurrentRunLevel | string | 13, 14, 15, 16 | |
CurrentStratumNumber | string | 3, 5 | |
CurrentTime | string | 1, 8 | |
CurrentTimeZoneID | integer | 2, 4 | 2 |
DCName | string | 1002, 1006, 1007, 1030, 1058, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1104, 1109, 1112, 1126, 1127, 1500, 1501, 1502, 1503 | \WIN-FPV0DSIC9O6.sigma.fr |
DSObjectName | string | 0, 1, 1, 1 | |
Data1 | string | 1, 9 | |
Data2 | string | 1, 9 | |
DataSize | string | 2, 7 | |
DataSourceId | string | 24832, 24847, 24848 | |
DefaultQueueVmmqEnabled | string | 2, 2, 7 | |
DefaultQueueVrssEnabled | string | 2, 2, 7 | |
DefaultQueueVrssExcludePrimaryProcessor | string | 2, 2, 7 | |
DefaultQueueVrssIndependentHostSpreading | string | 2, 2, 7 | |
DefaultQueueVrssMaxQueuePairs | string | 2, 2, 7 | |
DefaultQueueVrssMinQueuePairs | string | 2, 2, 7 | |
DefaultQueueVrssQueueSchedulingMode | string | 2, 2, 7 | |
Default_SD_String_ | string | 1, 2, 6, 6, 9 | O:SYG:SYD:(A;;RC;;;BA) |
Description | string | 10, 11, 55, 125 | |
DescriptionLength | string | 1, 2, 5 | |
DetectedBy | string | 0, 0, 1, 1, 1 | |
Device | string | 1, 2, 3, 5, 6, 10, 11, 12, 14, 15, 16, 17, 22, 23, 40, 41, 46, 47 | |
DeviceDescLength | string | 1, 4 | |
DeviceDescription | string | 1, 4 | |
DeviceID | string | 16, 17, 40, 41 | |
DeviceId | string | 26, 27, 44, 45, 144, 145, 146, 148, 149, 10000, 20005, 20006, 20007, 20008 | |
DeviceInstance | string | 2, 2, 5 | |
DeviceInstanceID | string | 20001, 20002, 20003, 20004 | |
DeviceInstanceLength | string | 2, 2, 5 | |
DeviceName | string | 1, 4, 5, 6, 7, 55, 98, 140, 143, 144, 210, 211 | \Device\HarddiskVolume2 |
DeviceNameLength | integer | 1, 6 | 9 |
DeviceNameLength | string | 1, 4, 5, 6, 7, 143, 144 | |
DeviceNumber | string | 26, 27, 44, 45 | |
DeviceObject | string | 0, 0, 1, 5, 7 | \Device\Http\ReqQueue |
DeviceSerialNumber | string | 16, 17, 40, 41 | |
DeviceTime | string | 1, 4, 5, 6, 7 | 2074-11-09 08:03:12 UTC |
DeviceVersionMajor | integer | 1, 6 | 10 |
DeviceVersionMajor | string | 1, 4, 5, 6, 7 | |
DeviceVersionMinor | integer | 1, 6 | 0 |
DeviceVersionMinor | string | 1, 4, 5, 6, 7 | |
Direction | string | 90, 130 | |
DirectoryPath | string | 1, 2, 2, 6, 9 | |
DirtyPages | string | 1, 6 | |
DisabledLoadOption | string | 1, 5, 6 | |
DisconnectedStandby | string | 0, 5, 7 | |
DiskFriendlyName | string | 1 | |
DiskPmDisabledMaxInterval | string | 0, 1, 8 | |
DiskPmEnabledFlag | string | 0, 1, 8 | |
DiskPmEnabledMaxInterval | string | 0, 1, 8 | |
DiskPmPolicy | string | 0, 1, 8 | |
DnsServerList | string | 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038 | 192.168.86.45 |
DnsSuffix | string | 0, 0, 1, 1 | |
Domain | string | 18, 32773, 32774, 32775 | |
DomainName | string | 4096, 4097, 4098, 4099 | |
DomainPeer | string | 24, 25, 26, 27, 130, 131, 132, 134, 135, 138, 156 | tick.boozallencsn.com,0x9 |
DripsResidencyInUs | string | 0, 5, 7 | |
DripsTransitions | string | 0, 5, 7 | |
DriveName | string | 55, 98 | C: |
DriverDescription | string | 20001, 20002 | |
DriverFileName | string | 20003, 20004 | |
DriverInitDuration | string | 1 | |
DriverName | string | 40, 219, 10113, 20001, 20002 | |
DriverNameLength | string | 40, 219 | |
DriverObject | string | 184, 185, 186, 187, 188, 189 | |
DriverProvider | string | 20001, 20002 | |
DriverVersion | string | 20001, 20002 | |
DropLowResourcesPackets | string | 1, 2, 6 | |
DroppedClaims | string | 0, 1, 5, 6, 9 | |
DstVPortId | string | 204, 205 | |
DumpEncryptionFailureReason | string | 0, 1, 2, 7 | |
Duration | string | 4, 13 | |
DurationInUs | string | 0, 5, 7 | |
DwmSyncFlushTime | string | 0, 5, 7 | |
DwordVal | integer | 50037, 51047, 51057 | 1 |
DwordVal | string | 1004, 50037, 51047, 51057 | |
DynamicIPAddressLimit | string | 8, 8 | |
EffectiveState | string | 1, 42, 107 | |
EfiDaylightFlags | integer | 2, 3, 8 | 0 |
EfiTime | string | 2, 3, 8 | 2022-03-01 17:43:36 UTC |
EfiTimeZoneBias | integer | 2, 3, 8 | 2047 |
ElapsedTime | string | 2, 6, 7 | |
EmbeddedTeaming | string | 204, 205, 215 | |
EnableDhcpGuard | string | 8, 8 | |
EnableDisableReason | integer | 1, 3, 5 | 0 |
EnableDisableReason | string | 153, 156 | |
EnableFixSpeed10G | string | 8, 8 | |
EnableRouterGuard | string | 8, 8 | |
Enabled | string | 1, 5, 6 | |
EnabledFeatures | string | 1, 2, 9 | |
EnabledNew | string | 0, 2 | true |
EncodedCert | string | 3, 6, 6, 8, 8 | |
EndTime | string | 1001, 1002 | |
EnergyDrain | string | 0, 5, 7 | |
EntryCount | string | 1, 8 | |
Error | string | 5, 6, 14, 15, 16, 26, 140, 1000, 1001, 1003, 1008, 1010, 1018, 1043, 6146, 36865, 40960, 45057 | |
ErrorBatteryCount | string | 1, 2, 5 | |
ErrorCause | string | 7, 9 | |
ErrorCode | integer | 1006, 1129, 8018, 16392 | 9005 |
ErrorCode | string | 6, 10, 20, 21, 22, 23, 27, 28, 29, 30, 31, 40, 96, 514, 518, 519, 520, 1000, 1002, 1003, 1006, 1007, 1008, 1012, 1023, 1029, 1030, 1031, 1052, 1053, 1054, 1055, 1058, 1065, 1079, 1080, 1085, 1088, 1089, 1091, 1095, 1096, 1097, 1101, 1104, 1110, 1112, 1125, 1126, 1127, 1129, 1130, 2042, 4001, 4002, 4003, 4004, 4100, 4202, 4302, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8194, 10000, 12288, 12289, 12294, 12299, 12302, 12305, 14300, 14301, 14302, 14303, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16398, 16399, 16400, 16401, 16402, 16403, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16642, 16643, 16644, 16645, 16646, 16648, 16649, 16935, 16936, 16937, 16944, 16945, 16947, 16948, 16949, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 36870, 36872, 36876, 36877, 36878, 36879, 36889 | |
ErrorCode1 | string | 14304, 14305, 14306 | |
ErrorCode2 | string | 14304, 14305, 14306 | |
ErrorDescription | string | 401, 404, 1002, 1006, 1007, 1030, 1052, 1053, 1054, 1055, 1058, 1065, 1079, 1080, 1085, 1088, 1089, 1091, 1095, 1096, 1097, 1101, 1104, 1110, 1112, 1125, 1126, 1127, 1129, 1130 | The network is not present or not started. |
ErrorMessage | string | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 15, 16, 17, 18, 19, 20, 22, 23, 24, 25, 30, 32, 40, 43, 44, 45, 46, 47, 48, 49, 54, 129, 130, 131, 132, 133, 134, 135, 136, 159, 16401, 16402, 16403, 16651 | The specified local group does not exist. |
ErrorParam1 | string | 1, 2, 3 | |
ErrorParam2 | string | 1, 2, 3 | |
ErrorParam3 | string | 1, 2, 3 | |
ErrorParam4 | string | 1, 2, 3 | |
ErrorSource | string | 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49 | |
ErrorState | string | 36871, 36888 | |
ErrorStatus | string | 22, 23, 46, 47, 36870 | |
ErrorString | string | 1, 1, 3, 4, 6 | The system cannot find the file specified. |
ErrorType | string | 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 42, 43, 44, 45, 46, 47 | |
Error_Code | string | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 0 |
EventCode | integer | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 98 |
EventData_Xml | string | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 109, 129, 134, 137, 153, 172, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1056, 1074, 1129, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10005, 10010, 10016, 10111, 10154, 14204, 14205, 14206, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16648, 16937, 16962, 16977, 24576, 24577, 24579, 36887, 50037, 51047, 51057 | snapattack.labs. |
EventDescription | string | 0, 0, 1, 6 | |
EventGenerationTime | string | 0, 0, 2, 4 | |
EventRecordID | integer | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 93485 |
EventSourceName | string | 32, 35, 1007, 1056, 1074, 5211, 6038, 7000, 7001, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 9009, 10005, 10010, 10016, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 24576, 24577, 24579 | "WinRM" |
EventVerbosity | string | 0, 0, 1, 6 | |
Exception | string | 0, 0, 0, 5 | |
ExchangeStrength | string | 0, 3, 6, 8, 8 | |
ExitBootServicesEntry | string | 0, 3 | |
ExitBootServicesExit | string | 0, 3 | |
ExitCode | string | 0, 0, 1, 1, 1 | |
ExitLatencyInUs | string | 0, 5, 7 | |
ExitReason | integer | 2, 4 | 0 |
ExpectedFunctionTableSize | string | 6, 8 | |
ExpectedFuntionTableCount | string | 0, 1, 1, 1, 7 | |
ExpectedSize | string | 5 | |
ExpectedVersion | string | 6, 8 | |
Ext1 | string | 128, 129 | |
Ext2 | string | 128, 129 | |
Extended | string | 22, 23, 46, 47 | |
ExtendedStatus | string | 1, 2, 4 | |
ExtensibleModulePath | string | 10000, 10001, 10002, 10003, 10004 | |
ExtensionId | string | 61, 98, 1085, 1091, 1112, 1128 | |
ExtensionName | string | 61, 1085, 1091, 1112, 1128 | |
ExtensionNameLength | string | 1, 6 | |
ExternalMonitorConnectedState | string | 506, 507 | |
ExtraString | string | 2, 3, 4, 5, 6, 8, 9, 10, 11 | \SystemRoot\System32\Config\RegBack\SYSTEM |
ExtraStringLength | integer | 5 | 42 |
ExtraStringLength | string | 2, 3, 4, 5, 6, 8, 9, 10, 11 | |
FRUId | string | 16, 17, 22, 23, 24, 25, 26, 27, 40, 41, 42, 43, 44, 45, 46, 47 | |
FRUText | string | 16, 17, 22, 23, 24, 25, 26, 27, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49 | |
FailReason | string | 82, 88, 90, 94, 95, 97, 100, 113, 122, 127, 128, 129, 130, 146, 147, 149, 150, 151, 197, 216, 227, 229, 254, 256, 257, 261, 1003 | |
FailedLogFilePath | string | 2, 7 | |
FailureMode | string | 2, 5, 9 | |
FailureMsg | string | 16, 29 | |
FailureMsgId | string | 16, 29 | |
FailureName | string | 1, 2, 9 | |
FailureNameLength | string | 1, 2, 9 | |
FailureReason | integer | 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522 | |
FailureResult | string | 1, 2 | |
FailureStatus | integer | 16, 29, 150 | |
FaultCode | string | 9, 9 | |
FeatureClassId | string | 1, 6 | |
FeaturesNeeded | string | 4, 8 | |
FeaturesSupported | string | 4, 8 | |
FileList | string | 16385, 16386 | C:\Users\user\AppData\Local\Temp\BIT72FA.tmp |
FileNameBuffer | string | 24832, 24833, 24834, 24847, 24848 | |
FileNameLength | string | 12, 150, 24832, 24833, 24834, 24847, 24848 | |
FileOffset | string | 2, 3, 4, 4, 8 | |
FilePath | string | 12, 1058, 1096, 12295 | |
FilterId | string | 204, 205, 215 | |
FilterName | string | 1205, 1206 | |
FilterNameLength | string | 1205, 1206 | |
FinalStatus | string | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 10100, 10101 | 0x8000002a |
FirstDripsEntryInUs | string | 0, 5, 7 | |
FirstPage | string | 1, 2 | |
FirstRefresh | integer | 2, 4 | 0 |
Flags | string | 1, 2, 3, 9, 42, 43, 264, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24643, 24645, 24652, 24653, 24654, 24657, 24658, 24659, 24672 | |
FrameworkVersion | string | 0, 0, 0, 0, 1 | |
FreePersistentPages | string | 1, 1, 5 | |
FriendlyName | string | 1001, 10111, 10112, 10115, 10116, 14206, 14210 | EVTX-PC: evtx: |
FullChargeCapacity | string | 0, 1, 5 | |
FullChargeCapacityRatio | string | 0, 5, 7 | |
FullResume | string | 1, 1, 3 | |
Function | string | 16, 17, 40, 41, 218 | |
FunctionNumber | string | 26, 27, 44, 45 | |
FwMemoryAttributes | string | 0, 1 | |
FwMemoryType | string | 0, 1 | |
FwPageCount | string | 0, 1 | |
FwStartPage | string | 0, 1 | |
FxVersion | string | 10001, 10002 | |
GPOCNName | string | 1058, 1065, 1096, 1104 | |
GPODisplayName | string | 0, 1, 1, 3 | |
GPOFileSystemPath | string | 0, 1, 1, 3 | |
GPOScriptCommandString | string | 0, 1, 1, 3 | |
GdiOnTime | string | 0, 5, 7 | |
GetTestResult_Data | string | 2, 7 | |
Group | integer | 26, 55 | 0 |
Group | string | 26, 33, 34, 35, 36, 37, 54, 55 | |
GroupName | string | 16387, 16389, 16391, 16393, 16394, 16401, 16402, 16407, 16413 | Performance Log Users |
Guid | string | 1, 3, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 50, 52, 55, 98, 104, 109, 134, 137, 139, 143, 153, 172, 201, 206, 238, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2003, 2004, 5211, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | "{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}" |
HRESULT | string | 0, 0, 0, 1 | |
HResult | string | 517, 518, 1538 | |
HardwareEnabled | string | 1, 2, 9 | |
HardwareID | string | 1 | |
HardwareId | string | 1, 5, 6, 10, 14, 15 | |
HardwarePresent | string | 1, 2, 9 | |
HeaderFlags | string | 5, 5 | |
HeaderLog | string | 16, 17, 40, 41 | |
HeaderLog0 | string | 1, 8 | |
HeaderLog1 | string | 1, 8 | |
HeaderLog2 | string | 1, 8 | |
HeaderLog3 | string | 1, 8 | |
HelperClassName | string | 4000, 5000, 5100, 5200, 6100 | |
HiberPagesWritten | string | 1 | |
HiberReadDuration | string | 1 | |
HiberWriteDuration | string | 1 | |
HibernateTime | string | 8, 8 | |
HiveName | string | 15, 16 | \SystemRoot\System32\Config\SOFTWARE |
HiveNameLength | string | 15, 16 | |
HostName | string | 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038 | quadra |
HostOSName | string | 0, 0, 2, 3 | Windows (TM) 10 Preinstallation Environment |
HostOSbuildversion | string | 0, 0, 2, 3 | |
HostOSmajorversion | string | 0, 0, 2, 3 | |
HostOSminorversion | string | 0, 0, 2, 3 | |
HostOSservicepackName | string | 0, 0, 2, 3 | |
HostOSservicepackmajorversion | string | 0, 0, 2, 3 | |
HostOSservicepackminorversion | string | 0, 0, 2, 3 | |
HostOSwasWindowsPE | string | 0, 0, 2, 3 | true |
Host_OS_Name | string | 0, 0, 2, 3 | Windows (TM) Code Name "Longhorn" Preinstallation Environment |
Host_OS_build_version | integer | 0, 0, 2, 3 | 7600 |
Host_OS_major_version | integer | 0, 0, 2, 3 | 6 |
Host_OS_minor_version | integer | 0, 0, 2, 3 | 1 |
Host_OS_service_pack_major_version | integer | 0, 0, 2, 3 | 0 |
Host_OS_service_pack_minor_version | integer | 0, 0, 2, 3 | 0 |
Host_OS_was_Windows_PE | string | 0, 0, 2, 3 | true |
HwDripsResidencyInUs | string | 0, 5, 7 | |
HypervisorVersion | string | 0, 4 | |
IPSecOffloadLimit | string | 4, 9 | |
IdleImplementation | string | 5, 5 | |
IdleSessionTimeout | string | 0, 1, 3 | |
IdleStateCount | integer | 26, 55 | 1 |
IdleStateCount | string | 4, 26, 55 | |
IfGuid | string | 10317, 10400 | |
IfIndex | string | 41, 42, 10317, 10400 | |
IfLuid | string | 10317, 10400 | |
ImageFileName | string | 7, 9 | |
ImageName | string | 1, 34, 36, 37, 152, 153 | |
ImagePath | string | 0, 4, 5, 7 | %SystemRoot%\PSEXESVC.exe |
Index | string | 2, 4, 5 | |
Info | string | 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218 | |
InputSuppressionActionCount | string | 0, 5, 7 | |
InstallStatus | string | 20001, 20002 | |
Install_was_an_upgrade | string | 0, 0, 2, 3 | false |
Installwasanupgrade | string | 0, 0, 2, 3 | false |
InstanceId | string | 78, 80, 92, 93, 10111, 10112, 10113, 10115, 10116 | |
InstanceName | string | 0, 4 | |
InstanceNameLength | string | 0, 4 | |
Interface | string | 4002, 4200, 4201, 4202 | |
InterfaceDesc | string | 4000, 5000, 5100, 5200 | |
InterfaceGUID | string | 4000, 5000, 5100, 5200 | |
InternalCode | string | 1, 1 | |
InternalInfo | string | 1, 2, 9 | |
InterruptModeration | string | 4, 9 | |
IoApicId | string | 1, 4, 7 | |
IoctlCode | string | 2, 6, 7 | |
IovOffloadWeight | string | 4, 9 | |
IpFamily | string | 0, 0, 3, 4 | |
IpHTTPSReasonCode | string | 0, 2, 3, 4 | |
Ipaddress | string | 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038 | 192.168.86.7 |
Irql | string | 4 | |
IsAcOnline | string | 2, 4, 5 | |
IsBootVolume | string | 0, 1, 5 | |
IsCsSessionInProgressOnExit | string | 0, 5, 7 | |
IsDriverOEM | string | 20001, 20002 | |
IsPowerActionCallIgnored | string | 2, 4, 5 | |
IsPowerPolicyEnabled | string | 2, 4, 5 | |
IsTestConfig | string | 1, 4 | |
IsatapRouter | string | 0, 0, 1, 4 | |
KeyFlags | string | 3, 6, 6, 8, 8 | |
KeyName | string | 3, 6, 6, 8, 8 | |
KeyProtectionMechanism | string | 1, 2 | |
KeyType | string | 3, 6, 6, 8, 8 | |
KeysUpdated | string | 1, 6 | |
Keywords | string | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 201, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 262, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 285, 286, 289, 290, 300, 301, 302, 379, 380, 381, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 566, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1025, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1056, 1058, 1060, 1061, 1065, 1068, 1074, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1281, 1282, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2001, 2003, 2004, 2005, 2042, 3261, 4000, 4001, 4002, 4003, 4004, 4005, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5202, 5203, 5211, 5300, 5774, 5781, 5782, 5805, 5823, 6000, 6005, 6006, 6009, 6011, 6013, 6027, 6033, 6035, 6036, 6037, 6038, 6040, 6041, 6100, 6145, 6146, 6148, 6400, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 9009, 10000, 10001, 10002, 10003, 10004, 10005, 10010, 10016, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10121, 10148, 10149, 10154, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14206, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 14531, 14533, 15007, 15008, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16647, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 16983, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 20010, 24576, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50036, 50037, 50038, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 0x8080000000000000 |
Language | string | 1002, 1003, 1006, 1008, 1009, 1013, 1014, 1015, 1017, 1018, 1040, 1042, 1043 | |
Language1 | string | 1009, 1016, 1041, 1060, 1061 | |
Language2 | string | 1009, 1016, 1041, 1060, 1061 | |
LastBootGood | string | 0, 2 | true |
LastBootId | string | 0, 2 | |
LastPage | string | 1, 2 | |
LastShutdownGood | string | 0, 2 | true |
LaunchType | string | 1001, 1002, 1003, 1101, 1102, 1103, 1104 | |
Leaf | string | 4, 8 | |
LeafNumber | string | 7, 9 | |
Length | string | 1, 2, 3, 6, 8, 10, 12, 14, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 40, 41, 42, 43, 44, 45, 46, 47 | |
Level | integer | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 4 |
Level | string | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 300, 301, 302, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1058, 1060, 1061, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2003, 2004, 2005, 2042, 4000, 4001, 4002, 4003, 4004, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5300, 6000, 6027, 6033, 6035, 6036, 6037, 6040, 6041, 6100, 6145, 6146, 6400, 7001, 7002, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 10000, 10001, 10002, 10003, 10004, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50037, 50038, 51047, 51057 | |
LidOpenState | string | 506, 507 | |
LifetimeId | string | 10110, 10111, 10112, 10113, 10115, 10116 | |
LightestSystemState | string | 1, 7, 8 | |
Limit | string | 2, 8 | |
LoadBalancingAlgorithm | string | 206, 207, 208, 209, 210, 211 | |
LoadOSImageStart | string | 0, 3 | |
LoadOptions | string | 2, 7 | NOEXECUTE=OPTIN |
LocalAddr | string | 0, 9 | |
LocalAddrLen | string | 0, 9 | |
LocalAddress | string | 96, 98 | |
LocalAddressLength | string | 96, 98 | |
LocalCertSubjectName | string | 0, 3, 6, 8, 8 | |
LocalIPAddr | string | 0, 1, 3 | |
LocalIPAddrLen | string | 0, 1, 3 | |
LocalPort | string | 0, 1, 3 | |
LocalPortLen | string | 0, 1, 3 | |
LocalPrefix | string | 0, 9 | |
Location | string | 241, 1008, 1012, 10111, 10112, 10115, 10116 | |
LogFile | string | 19, 20 | |
LogStatus | string | 1, 1, 2, 2, 9 | |
MCABank | string | 18, 19, 20, 21 | |
MIDR_EL1 | string | 28, 29 | |
MPIDR_EL1 | string | 28, 29 | |
MSRIndex | string | 4, 6 | |
MacAddress | string | 25, 28, 29, 30, 31, 204 | |
MacAddressLen | string | 25, 28, 29, 30, 31 | |
MacLength | string | 0, 2, 4 | |
MajorVersion | integer | 1, 2 | 10 |
MajorVersion | string | 12, 29 | |
ManualPeer | string | 16, 17, 47, 48, 137 | time.windows.com,0x8 |
MaxBandCount | string | 1, 2 | |
MaxDelta | string | 1, 4, 5 | |
MaxSystemTimeChangeSeconds | string | 3, 4 | |
Maximum | string | 1, 3, 5, 6, 6 | |
MaximumPerformancePercent | string | 5, 5 | |
MciAddr | string | 18, 19, 20, 21, 48, 49 | |
MciMisc | string | 18, 19, 20, 21, 48, 49 | |
MciStat | string | 18, 19, 20, 21 | |
MciStatus | string | 48, 49 | |
MemHierarchyLvl | string | 6, 8, 10, 12, 14, 16, 17, 18, 19 | |
Member | string | 184, 185, 186, 187, 188, 189 | |
MemberAdapterFriendlyName | string | 2, 2, 9 | |
MemberAdapterFriendlyNameLen | string | 2, 2, 9 | |
MemberAdapterName | string | 2, 2, 9 | |
MemberAdapterNameLen | string | 2, 2, 9 | |
MemorIO | string | 6, 8, 10, 12, 14, 16, 17, 18, 19 | |
MemoryRequired | string | 0, 4 | |
MemorySize | string | 1101, 1102, 1103, 1104 | |
Message | string | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 300, 301, 302, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1058, 1060, 1061, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2003, 2004, 2005, 2042, 4000, 4001, 4002, 4003, 4004, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5300, 6000, 6027, 6033, 6035, 6036, 6037, 6040, 6041, 6100, 6145, 6146, 6400, 7001, 7002, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 10000, 10001, 10002, 10003, 10004, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50037, 50038, 51047, 51057 | The application was unable to start correctly (0xc0000142). Click OK to close the application. |
MinDelta | string | 1, 4, 5 | |
MinPerfPercent | string | 2, 9 | |
MinThrottlePercent | string | 2, 9 | |
MinimumPasswordLength | integer | 1, 6, 7, 7, 9 | 0 |
MinimumPasswordLength | string | 16977, 16978, 16979 | |
MinimumPasswordLengthAudit | integer | 1, 6, 7, 7, 9 | -1 |
MinimumPasswordLengthAudit | string | 16977, 16978 | |
MinimumPerformancePercent | string | 5, 5 | |
MinimumThrottle | string | 1, 2, 5 | |
MinimumThrottlePercent | string | 5, 5 | |
MiniportEventEnum | string | 0, 1, 1, 3, 7 | |
MiniportName | string | 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 37, 38, 41, 42, 43, 44, 45 | Microsoft Hyper-V Network Adapter |
MiniportNameLen | integer | 3, 10, 11 | 33 |
MiniportNameLen | string | 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 37, 38, 41, 42, 43, 44, 45 | |
MinorVersion | integer | 1, 2 | 0 |
MinorVersion | string | 12, 29 | |
MissingCAPDNs | string | 1, 4, 5, 6 | |
ModernSleepAppliedActionsBitmask | string | 0, 5, 7 | |
ModernSleepEnabledActionsBitmask | string | 0, 5, 7 | |
Module | string | 4, 22, 23, 46, 47 | |
ModuleHandle | string | 22, 23, 46, 47 | |
ModuleName | string | 3, 5, 6, 6, 8 | |
MonitorMode | string | 8, 8 | |
MonitorPowerOnTime | string | 0, 5, 7 | |
MonitorReason | integer | 5, 6, 6 | 12 |
MonitorSession | string | 8, 8 | |
NTStatus | integer | 3 | |
NdisOid | string | 2, 5, 9 | |
NdisStatus | string | 0, 2, 6 | |
NdkEnabled | string | 44, 45 | |
NetEvent | string | 38, 43, 149, 254 | |
NetStatusCode | string | 4097, 4099 | |
NewBias | string | 2, 2 | |
NewLogFilePath | string | 2, 7 | |
NewSchemeGuid | string | 12, 51 | 381B4222-F694-41F0-9685-FF5BB260DF2E |
NewSize | string | 1, 5 | |
NewTime | string | 1 | 2022-04-07 08:10:56.757996 UTC |
NewValue | string | 1, 5, 5, 6, 6 | |
NextSessionId | integer | 5, 6, 6 | 1 |
NextSessionType | integer | 5, 6, 6 | 0 |
NicFName | string | 5, 6, 7, 8, 13, 16, 17, 18, 19, 20, 21, 22, 23, 24, 29, 30, 31, 32, 33, 35, 61, 76, 77, 87, 96, 98, 99, 106, 113, 120, 122, 146, 147, 149, 150, 151, 190, 191, 192, 193, 197, 202, 203, 216, 232, 233, 236, 238, 243, 244, 254, 256, 257, 258, 259, 263, 265, 266, 269, 270, 276 | |
NicFNameLen | string | 5, 6, 7, 8, 13, 16, 17, 18, 19, 20, 21, 22, 23, 24, 29, 30, 31, 32, 33, 35, 61, 76, 77, 87, 96, 98, 99, 106, 113, 120, 122, 146, 147, 149, 150, 151, 190, 191, 192, 193, 197, 202, 203, 216, 232, 233, 236, 238, 243, 244, 254, 256, 257, 258, 259, 263, 265, 266, 269, 270, 276 | |
NicFriendlyName | string | 212, 213, 214 | |
NicFriendlyNameLen | string | 212, 213, 214 | |
NicIndex | string | 204, 205, 212, 213, 214, 215, 229 | |
NicName | string | 5, 6, 7, 8, 13, 16, 17, 18, 19, 20, 21, 22, 23, 24, 29, 30, 31, 32, 33, 35, 61, 76, 77, 87, 96, 98, 99, 106, 113, 120, 122, 146, 147, 149, 150, 151, 190, 191, 192, 193, 197, 202, 203, 212, 213, 214, 216, 232, 233, 234, 235, 236, 238, 243, 244, 254, 256, 257, 258, 259, 263, 265, 266, 269, 270, 276 | |
NicNameLen | string | 5, 6, 7, 8, 13, 16, 17, 18, 19, 20, 21, 22, 23, 24, 29, 30, 31, 32, 33, 35, 61, 76, 77, 87, 96, 98, 99, 106, 113, 120, 122, 146, 147, 149, 150, 151, 190, 191, 192, 193, 197, 202, 203, 212, 213, 214, 216, 232, 233, 234, 235, 236, 238, 243, 244, 254, 256, 257, 258, 259, 263, 265, 266, 269, 270, 276 | |
NoMultiStageResumeReason | string | 1 | |
Node | string | 22, 23, 46, 47 | |
NominalFrequency | string | 5, 5 | |
NonActivatedCpuInUs | string | 0, 5, 7 | |
NonAttributedCpuInUs | string | 0, 5, 7 | |
NonDripsTimeActivatedInUs | string | 0, 5, 7 | |
NonPagedPoolTag_1 | string | 0, 0, 2, 4 | |
NonPagedPoolTag_2 | string | 0, 0, 2, 4 | |
NonPagedPoolTag_3 | string | 0, 0, 2, 4 | |
NonPagedPoolUsage | string | 0, 0, 2, 4 | |
NonPagedPoolUsed_1 | string | 0, 0, 2, 4 | |
NonPagedPoolUsed_2 | string | 0, 0, 2, 4 | |
NonPagedPoolUsed_3 | string | 0, 0, 2, 4 | |
NonResiliencyTimeInUs | string | 0, 5, 7 | |
NormalProcessId | string | 1, 2, 4 | |
NotAffectedAtom | string | 1, 5, 6 | |
NotAffectedRdclNo | string | 1, 5, 6 | |
NotifyType | string | 1, 2 | |
NtStatus | string | 0, 8 | |
NumAttempts | string | 1001, 1002 | |
NumBadPages | string | 1101, 1102, 1103, 1104 | |
NumPagesTested | string | 1101, 1102, 1103, 1104 | |
NumPagesUnTested | string | 1101, 1102, 1103, 1104 | |
NumRootCauses | string | 1001, 1002 | |
Number | integer | 26, 55 | 0 |
Number | string | 26, 33, 34, 35, 36, 37, 54, 55 | |
NumberOfGroupPolicyObjects | string | 1502, 1503 | |
NvgreEnabled | string | 0, 2, 3 | |
OID | string | 16944, 16945, 16946, 16947 | |
OSEditionID | string | 0, 0, 2, 4 | ServerStandardEval |
OSName | string | 0, 0, 2, 4 | Windows Server 2022 Standard Evaluation |
OS_EditionID | string | 0, 0, 2, 4 | Professional |
OS_Name | string | 0, 0, 2, 4 | Windows 7 Professional |
OS_build_version | integer | 0, 0, 2, 4 | 7600 |
OS_major_version | integer | 0, 0, 2, 4 | 6 |
OS_minor_version | integer | 0, 0, 2, 4 | 1 |
OS_service_pack_major_version | integer | 0, 0, 2, 4 | 0 |
OS_service_pack_minor_version | integer | 0, 0, 2, 4 | 0 |
OSbuildversion | string | 0, 0, 2, 4 | |
OSmajorversion | string | 0, 0, 2, 4 | |
OSminorversion | string | 0, 0, 2, 4 | |
OSservicepackName | string | 0, 0, 2, 4 | |
OSservicepackmajorversion | string | 0, 0, 2, 4 | |
OSservicepackminorversion | string | 0, 0, 2, 4 | |
ObjectName | string | 4, 132, 133, 513, 514, 515, 516, 519, 520, 521, 522 | |
ObjectNameLength | string | 132, 133, 513, 514, 515, 516, 519, 520, 521, 522 | |
ObjectSize | string | 4 | |
OidFailureStatus | string | 2, 5, 9 | |
OldBias | string | 2, 2 | |
OldSchemeGuid | string | 12, 51 | 381B4222-F694-41F0-9685-FF5BB260DF2E |
OldTime | string | 1 | 2022-04-07 08:10:56.760687 UTC |
Opcode | integer | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5782, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 69 |
Opcode | string | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 300, 301, 302, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1058, 1060, 1061, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2003, 2004, 2005, 2042, 4000, 4001, 4002, 4003, 4004, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5300, 6000, 6027, 6033, 6035, 6036, 6037, 6040, 6041, 6100, 6145, 6146, 6400, 7001, 7002, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 10000, 10001, 10002, 10003, 10004, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50037, 50038, 51047, 51057 | |
Operation | string | 75, 76, 78, 80, 82, 92, 93, 100, 227, 233, 261, 16948 | |
OperationType | string | 18, 19, 28, 29 | |
OptionSelected | string | 1, 2 | |
OptionalGUID | string | 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24643, 24645, 24652, 24653, 24654, 24657, 24658, 24659, 24672 | |
OriginalSize | string | 1, 5 | |
Outcome | string | 5, 5 | |
OverThrottleThreshold | string | 1, 2, 5 | |
Owner | string | 0, 1, 3, 6, 9 | |
OwnerService | string | 9, 42, 43, 264 | |
PCIXCommand | string | 24, 25, 42, 43 | |
PID | string | 6036, 6037 | |
PSCIState | string | 28, 29 | |
Package | string | 5000, 6040, 45057 | |
PagedPoolTag_1 | string | 0, 0, 2, 4 | |
PagedPoolTag_2 | string | 0, 0, 2, 4 | |
PagedPoolTag_3 | string | 0, 0, 2, 4 | |
PagedPoolUsage | string | 0, 0, 2, 4 | |
PagedPoolUsed_1 | string | 0, 0, 2, 4 | |
PagedPoolUsed_2 | string | 0, 0, 2, 4 | |
PagedPoolUsed_3 | string | 0, 0, 2, 4 | |
Param1 | string | 10, 100, 101, 102 | |
Param2 | string | 10, 100, 101, 102 | |
Param3 | string | 10, 100, 101, 102 | |
Param4 | string | 10, 100, 101, 102 | |
Parameter | string | 414, 1004, 1005, 1007 | |
Parameter1 | string | 1, 8 | |
ParentHypervisorFlushes | string | 1, 5, 6 | |
Participation | string | 6, 8, 10, 12, 14, 16, 17, 18, 19, 28, 29 | |
PartitionId | string | 1, 2, 144, 145, 146, 148, 149 | |
PccChanges | string | 3, 7 | |
Peer | string | 22, 23, 51, 53 | |
Pending | string | 1, 3 | |
PerfStateCount | integer | 2, 6 | 0 |
PerfStateCount | string | 4, 26 | |
PerformanceImplementation | string | 5, 5 | |
Persisted | string | 1, 3 | |
PersistentMemoryDiskGuid | string | 300, 301, 302 | |
Phase | string | 63, 124 | |
PhysicalAddress | string | 22, 23, 31, 46, 47 | |
PhysicalAddressMask | string | 22, 23, 46, 47 | |
PhysicalFaultAddress | string | 28, 29 | |
PhysicalMemorySize | string | 0, 0, 2, 4 | |
PhysicalMemoryUsage | string | 0, 0, 2, 4 | |
Pid | integer | 9, 10 | |
PlatformDirected | string | 1, 3 | |
PlatformId | string | 1, 2 | |
Policy | string | 1, 2, 9 | |
Port1FName | string | 25, 28 | |
Port1FNameLen | string | 25, 28 | |
Port1Name | string | 25, 28 | |
Port1NameLen | string | 25, 28 | |
Port2FName | string | 25, 28 | |
Port2FNameLen | string | 25, 28 | |
Port2Name | string | 25, 28 | |
Port2NameLen | string | 25, 28 | |
PortFName | string | 12, 15, 17, 18, 32, 33, 34, 35, 46, 68, 70, 72, 73, 74, 75, 78, 82, 87, 88, 90, 92, 94, 95, 96, 98, 99, 119, 121, 127, 128, 129, 130, 232, 256, 257, 264 | |
PortFNameLen | string | 12, 15, 17, 18, 32, 33, 34, 35, 46, 68, 70, 72, 73, 74, 75, 78, 82, 87, 88, 90, 92, 94, 95, 96, 98, 99, 119, 121, 127, 128, 129, 130, 232, 256, 257, 264 | |
PortName | string | 12, 15, 17, 18, 32, 33, 34, 35, 46, 68, 70, 72, 73, 74, 75, 78, 82, 87, 88, 90, 92, 94, 95, 96, 98, 99, 119, 121, 127, 128, 129, 130, 232, 234, 235, 256, 257, 264 | |
PortNameLen | string | 12, 15, 17, 18, 32, 33, 34, 35, 46, 68, 70, 72, 73, 74, 75, 78, 82, 87, 88, 90, 92, 94, 95, 96, 98, 99, 119, 121, 127, 128, 129, 130, 232, 234, 235, 256, 257, 264 | |
PortType | string | 16, 17, 40, 41 | |
PowerButtonTimestamp | string | 1, 4 | |
PowerPolicyAction | string | 2, 4, 5 | |
PowerPolicyBatteryLevel | string | 2, 4, 5 | |
PowerPolicyEventCode | string | 2, 4, 5 | |
PowerPolicyMinState | string | 2, 4, 5 | |
PowerStateAc | string | 507, 566 | true |
PpcChanges | string | 7, 37 | |
PrecisePC | string | 28, 29 | |
PreviousEnergyCapacityAtEnd | integer | 5, 6, 6 | 50000 |
PreviousEnergyCapacityAtStart | integer | 5, 6, 6 | 50000 |
PreviousFullEnergyCapacityAtEnd | integer | 5, 6, 6 | 50000 |
PreviousFullEnergyCapacityAtStart | integer | 5, 6, 6 | 50000 |
PreviousSessionDurationInUs | integer | 5, 6, 6 | 1055562550 |
PreviousSessionId | integer | 5, 6, 6 | 0 |
PreviousSessionType | integer | 5, 6, 6 | 0 |
PrimaryDeviceName | string | 16, 17, 40, 41 | |
PrimaryService | string | 20003, 20004 | |
Problem | string | 0, 0, 1, 1, 1 | |
Problems | string | 1, 2, 9 | |
ProcessCommitCharge | string | 0, 0, 2, 4 | |
ProcessID | integer | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 300, 301, 302, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1058, 1060, 1061, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2003, 2004, 2005, 2042, 4000, 4001, 4002, 4003, 4004, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5300, 6000, 6027, 6033, 6035, 6036, 6037, 6040, 6041, 6100, 6145, 6146, 6400, 7001, 7002, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 10000, 10001, 10002, 10003, 10004, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50037, 50038, 51047, 51057 | |
ProcessID | string | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5782, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | "976" |
ProcessId | integer | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5782, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 976 |
ProcessId | string | 41, 97, 150, 225, 6400 | |
ProcessNameLength | string | 2, 2, 5 | |
ProcessPath | string | 12, 21, 51 | C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.20348.557_none_f1edaeb8515fa10d\TiWorker.exe |
ProcessPid | integer | 1, 2 | 1292 |
ProcessPid | string | 12, 51 | |
Process_1_CommitCharge | string | 0, 0, 2, 4 | |
Process_1_CreationTime | string | 0, 0, 2, 4 | |
Process_1_HandleCount | string | 0, 0, 2, 4 | |
Process_1_ID | string | 0, 0, 2, 4 | |
Process_1_Name | string | 0, 0, 2, 4 | |
Process_1_TypeInfo | string | 0, 0, 2, 4 | |
Process_1_Version | string | 0, 0, 2, 4 | |
Process_2_CommitCharge | string | 0, 0, 2, 4 | |
Process_2_CreationTime | string | 0, 0, 2, 4 | |
Process_2_HandleCount | string | 0, 0, 2, 4 | |
Process_2_ID | string | 0, 0, 2, 4 | |
Process_2_Name | string | 0, 0, 2, 4 | |
Process_2_TypeInfo | string | 0, 0, 2, 4 | |
Process_2_Version | string | 0, 0, 2, 4 | |
Process_3_CommitCharge | string | 0, 0, 2, 4 | |
Process_3_CreationTime | string | 0, 0, 2, 4 | |
Process_3_HandleCount | string | 0, 0, 2, 4 | |
Process_3_ID | string | 0, 0, 2, 4 | |
Process_3_Name | string | 0, 0, 2, 4 | |
Process_3_TypeInfo | string | 0, 0, 2, 4 | |
Process_3_Version | string | 0, 0, 2, 4 | |
Process_4_CommitCharge | string | 0, 0, 2, 4 | |
Process_4_CreationTime | string | 0, 0, 2, 4 | |
Process_4_HandleCount | string | 0, 0, 2, 4 | |
Process_4_ID | string | 0, 0, 2, 4 | |
Process_4_Name | string | 0, 0, 2, 4 | |
Process_4_TypeInfo | string | 0, 0, 2, 4 | |
Process_4_Version | string | 0, 0, 2, 4 | |
Process_5_CommitCharge | string | 0, 0, 2, 4 | |
Process_5_CreationTime | string | 0, 0, 2, 4 | |
Process_5_HandleCount | string | 0, 0, 2, 4 | |
Process_5_ID | string | 0, 0, 2, 4 | |
Process_5_Name | string | 0, 0, 2, 4 | |
Process_5_TypeInfo | string | 0, 0, 2, 4 | |
Process_5_Version | string | 0, 0, 2, 4 | |
Process_6_CommitCharge | string | 0, 0, 2, 4 | |
Process_6_CreationTime | string | 0, 0, 2, 4 | |
Process_6_HandleCount | string | 0, 0, 2, 4 | |
Process_6_ID | string | 0, 0, 2, 4 | |
Process_6_Name | string | 0, 0, 2, 4 | |
Process_6_TypeInfo | string | 0, 0, 2, 4 | |
Process_6_Version | string | 0, 0, 2, 4 | |
ProcessingMode | integer | 1006, 1129, 1500, 1501, 1502, 1503 | 1 |
ProcessingMode | string | 1002, 1006, 1007, 1030, 1052, 1053, 1054, 1055, 1058, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1104, 1109, 1110, 1112, 1125, 1126, 1127, 1129, 1500, 1501, 1502, 1503 | |
ProcessingTimeInMilliseconds | integer | 1006, 1129, 1500, 1501, 1502, 1503 | 94 |
ProcessingTimeInMilliseconds | string | 1002, 1006, 1007, 1030, 1052, 1053, 1054, 1055, 1058, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1104, 1109, 1110, 1112, 1125, 1126, 1127, 1129, 1500, 1501, 1502, 1503 | |
Processor | string | 1, 2, 3, 4, 7 | |
ProcessorIndex | string | 252, 253 | |
ProductName | string | 1, 2 | |
ProductVersion | string | 1, 2 | |
ProgrammedWakeTimeAc | string | 0, 1, 7 | |
ProgrammedWakeTimeDc | string | 0, 1, 7 | |
PropertyId | string | 78, 80, 92, 93 | |
ProtectorGUID | string | 513, 514, 515, 516, 517 | |
Protocol | string | 130, 36874, 36880, 40960, 40962, 40965, 40966, 40967, 40969 | |
ProtocolType | string | 4200, 4201, 4202 | |
ProviderGUID | string | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 300, 301, 302, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1058, 1060, 1061, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2003, 2004, 2005, 2042, 4000, 4001, 4002, 4003, 4004, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5300, 6000, 6027, 6033, 6035, 6036, 6037, 6040, 6041, 6100, 6145, 6146, 6400, 7001, 7002, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 10000, 10001, 10002, 10003, 10004, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50037, 50038, 51047, 51057 | |
ProviderName | string | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 300, 301, 302, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1058, 1060, 1061, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2003, 2004, 2005, 2042, 4000, 4001, 4002, 4003, 4004, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5300, 6000, 6027, 6033, 6035, 6036, 6037, 6040, 6041, 6100, 6145, 6146, 6400, 7001, 7002, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 10000, 10001, 10002, 10003, 10004, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50037, 50038, 51047, 51057 | |
PtNicFName | string | 146, 147, 150, 151, 216, 259 | |
PtNicFNameLen | string | 146, 147, 150, 151, 216, 259 | |
PtNicName | string | 146, 147, 150, 151, 216 | |
PtNicNameLen | string | 146, 147, 150, 151, 216 | |
Publisher | string | 0, 0, 4, 6 | |
PublisherGuid | string | 0, 3 | |
QfeVersion | string | 1, 2 | |
Qualifiers | string | 2, 3, 4, 13, 18, 26, 27, 28, 32, 35, 46, 48, 129, 153, 262, 285, 286, 289, 290, 379, 380, 381, 1001, 1007, 1056, 1074, 1500, 2001, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 7000, 7001, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 9009, 10005, 10010, 10016, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 24576, 24577, 24579 | "7" |
QueryName | string | 0, 1, 1, 4 | wpad |
QueueLimitMBytes | string | 252, 253 | |
QueueMode | string | 106, 122 | |
QueuePairs | string | 4, 9 | |
QueueSizeMBytes | string | 252, 253 | |
RankNumber | string | 22, 23, 46, 47 | |
RawData | string | 1, 2, 3, 6, 8, 10, 12, 14, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 40, 41, 42, 43, 44, 45, 46, 47 | |
RdmaWeight | string | 256, 257 | |
ReadSize | string | 2, 3, 4, 4, 8 | |
ReaderName | string | 1000, 1001 | |
Reason | integer | 1, 172, 566 | 6 |
Reason | string | 1, 3, 5, 12, 14, 42, 172, 237, 506, 507, 508, 1002 | |
ReasonPhrase | string | 7, 9 | |
RebootOption | string | 20001, 20002 | |
RebootTime | string | 0, 0, 0, 2, 9 | |
RecordId | string | 1, 2 | |
RecordNumber | integer | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 93485 |
Register | string | 48, 97 | |
RelaxMinimumPasswordLengthLimits | integer | 1, 6, 7, 7, 9 | 0 |
RemainingCapacity | string | 0, 1, 5 | |
RemainingPercentage | string | 2, 4, 5 | |
RemainingRids | string | 1, 5, 6, 6, 8 | |
RemoteAddr | string | 0, 9 | |
RemoteAddrLen | string | 0, 9 | |
RemoteAddress | string | 96, 98 | |
RemoteAddressLength | string | 96, 98 | |
RemoteCertSubjectName | string | 0, 3, 6, 8, 8 | |
RemoteIPAddr | string | 0, 1, 3 | |
RemoteIPAddrLen | string | 0, 1, 3 | |
RemotePort | string | 0, 1, 3 | |
RemotePortLen | string | 0, 1, 3 | |
RemotePrefix | string | 0, 9 | |
RemovedMemorySize | string | 1001, 1003 | |
RepairData | string | 130, 131 | |
RepairDataLength | string | 130, 131 | |
RepairDetail | string | 130, 131 | |
RepairGUID | string | 4000, 5000, 5100, 5200 | |
RepairOption | string | 4000, 5000, 5100, 5200 | |
RepairStatus | string | 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218 | |
RequestHandled | string | 41, 42 | |
RequestQueue | string | 7, 9 | |
RequestType | string | 6, 8, 10, 12, 14, 16, 17, 18, 19 | |
RequestedVlanIDs | string | 243, 244 | |
RequesterId | string | 22, 23, 24, 25, 42, 43, 46, 47 | |
Reservation | string | 82, 84, 100 | |
Reserved1 | string | 1, 2 | |
Reserved2 | string | 1, 2 | |
ResetCount | string | 0, 0, 0, 1, 4 | |
ResetEndStart | string | 0, 3 | |
ResetReason | string | 0, 0, 0, 1, 4 | |
ResetReasonMask | string | 1, 2, 4 | |
ResiliencyDripsTimeInUs | string | 0, 5, 7 | |
ResiliencyHwDripsTimeInUs | string | 0, 5, 7 | |
ResponderId | string | 22, 23, 46, 47 | |
RestartCount | string | 10111, 10112, 10115, 10116 | |
RestartablePC | string | 28, 29 | |
ResultCode | string | 401, 404, 405, 406, 407, 408, 409, 412, 413, 701, 702, 703, 704, 705, 716, 718 | |
ResultHR | string | 4200, 5300 | |
ResumeCount | string | 1, 1, 3 | |
RetryMinutes | integer | 1, 3, 4 | 15 |
RetryMinutes | string | 14, 17, 18, 29, 48, 129, 130, 131, 132, 133, 134, 135, 136 | |
RetryWaitTime | string | 0, 1, 3, 6, 9 | |
Revision | string | 1, 2 | |
RmDescription | string | 2 | |
RmDescriptionLength | string | 2 | |
RmId | string | 2, 11 | |
RootCause | string | 4000, 5000, 5100, 5200 | |
RootCauseGUID | string | 4000, 5000, 5100, 5200 | |
RoutingDomainGuid | string | 1, 2, 9 | |
RoutingDomainGuidLen | string | 1, 2, 9 | |
RoutingDomainName | string | 1, 2, 9 | |
RoutingDomainNameLen | string | 1, 2, 9 | |
Row | string | 22, 23, 46, 47 | |
RpcEndPointError | string | 0, 2, 8 | |
RssQueueIndex | string | 0, 2, 6 | |
RuleId | string | 4 | |
RuleName | string | 0, 1, 2, 3 | |
RunningMode | string | 1, 1, 2, 5 | Classic |
RunningState | string | 28, 29 | |
SID | string | 0, 3, 5, 6 | |
SIDTypeRequired | string | 4000, 5000, 5100, 5200 | |
SampleData | string | 5, 5 | |
SampleLength | string | 5, 5 | |
ScenarioInstanceId | string | 506, 507 | |
ScenarioInstanceIdV2 | string | 506, 507 | |
ScheduleType | string | 1001, 1002, 1003 | |
SchedulerType | string | 2 | |
ScriptType | string | 0, 1, 1, 3 | |
SecondaryBus | string | 16, 17, 40, 41 | |
SecondaryDevice | string | 16, 17, 40, 41 | |
SecondaryDeviceName | string | 16, 17, 40, 41 | |
SecondaryFunction | string | 16, 17, 40, 41 | |
SecondsRequired | string | 4000, 5000, 5100, 5200 | |
Secret | string | 0, 2, 6, 7 | |
SectionCount | string | 1, 2 | |
SecurityPackage | string | 12302, 16398 | |
Segment | string | 16, 17, 40, 41 | |
SegmentNumber | string | 26, 27, 44, 45 | |
SendStatus | string | 7, 9 | |
Sent_UpdateServer | string | 0, 1, 8, 8 | 192.168.86.45:53 |
ServerName | string | 0, 0, 3, 4 | |
ServerUrl | string | 0, 0, 3, 4 | |
ServerVersion | string | 2, 6 | |
ServerVersionLen | string | 2, 6 | |
ServiceName | integer | 7009, 10005, 10111 | 50 |
ServiceName | string | 10, 1074, 7000, 7001, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 10001, 10002, 10010, 10016, 10117, 14200, 14201, 14202, 14203, 14204, 14205, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 20003, 20004 | {4991D34B-80A1-4291-83B6-3328366B9097} |
ServiceNameLength | string | 0, 1 | |
ServiceType | string | 0, 4, 5, 7 | user mode service |
ServiceVersion | string | 1, 2 | |
SettingType | string | 0, 2, 2, 4 | |
SetupClass | string | 20001, 20002 | |
Severity | string | 1, 2, 55 | |
ShutdownActionType | string | 0, 1, 9 | |
ShutdownEventCode | string | 0, 1, 9 | |
ShutdownReason | string | 0, 1, 9 | |
ShutdownTime | string | 86, 108 | |
SigmaEventCode | integer | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 98 |
Signature | string | 1, 2, 55 | |
SiloCommand | string | 1, 1 | |
SiloStatus | string | 1, 1 | |
SiteID | integer | 0, 0, 1, 7 | 2 |
SleepDuration | string | 1 | |
SleepInProgress | string | 1, 4 | false |
SleepState | string | 1, 3, 7 | |
SleepTime | string | 1 | |
Slot | string | 16, 17, 40, 41 | |
SmtEnabled | string | 1, 5, 6 | |
SniHostname | string | 96, 98 | |
SoftRestartCount | string | 1, 8 | |
SourceFile | string | 55, 131, 134, 139, 140 | |
SourceIdBus | string | 1, 8 | |
SourceIdDev | string | 1, 8 | |
SourceIdFun | string | 1, 8 | |
SourceLine | string | 55, 131, 134, 139, 140 | |
SourceTag | string | 55, 131, 134, 139, 140 | |
SpareMemoryCount | string | 2, 2, 4 | |
SpareMemorySize | string | 2, 2, 4 | |
SparePath | string | 240, 241, 242 | |
SpareProcessorCount | string | 2, 2, 4 | |
SrcVPortId | string | 0, 2, 5 | |
StartBias | string | 0, 1, 8 | |
StartDeviceFailReason | string | 1, 4 | |
StartOSImageStart | string | 0, 3 | |
StartTime | string | 12, 1001, 1002 | 2021-11-09 21:42:16.500 UTC |
StartType | string | 0, 4, 5, 7 | demand start |
State | integer | 1, 2, 7 | 2 |
State | string | 172, 8193 | |
Stateful | string | 0, 1, 3 | |
Status | integer | 1, 2, 3, 4, 5, 6, 8, 10, 11, 12, 13, 14, 15, 16, 17, 18, 20, 32, 34, 35, 37, 38, 39, 40, 41, 42, 43, 44, 45, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 82, 84, 96, 97, 100, 113, 116, 122, 124, 132, 149, 152, 153, 156, 190, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 217, 218, 219, 227, 235, 236, 238, 239, 241, 254, 256, 257, 258, 261, 267, 269, 276, 1003, 10110, 16976, 24832, 32780 | 0 |
StatusCode | string | 97, 1004, 1018, 50038 | |
StopTime | string | 1, 3 | 2021-11-09 21:05:12.054501 UTC |
StormLimit | string | 8, 8 | |
String | string | 8, 9, 11, 1000, 19999 | |
StringCount | string | 1, 1 | |
SubKeyOrValueName | string | 0, 1, 4, 5, 6 | |
SubjectDomainName | string | 0, 1, 4 | |
SubjectUserName | string | 0, 1, 4 | |
SubkeyName | string | 5 | |
SubkeyNameLen | string | 5 | |
SupportInfo1 | integer | 1006, 1129, 1500, 1501, 1502, 1503 | 1 |
SupportInfo1 | string | 1002, 1006, 1007, 1030, 1052, 1053, 1054, 1055, 1058, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1104, 1109, 1110, 1112, 1125, 1126, 1127, 1128, 1129, 1130, 1500, 1501, 1502, 1503 | |
SupportInfo2 | integer | 1006, 1129, 1500, 1501, 1502, 1503 | 6191 |
SupportInfo2 | string | 1002, 1006, 1007, 1030, 1052, 1053, 1054, 1055, 1058, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1104, 1109, 1110, 1112, 1125, 1126, 1127, 1128, 1129, 1130, 1500, 1501, 1502, 1503 | |
SuspendEnd | string | 0, 1, 3 | |
SuspendStart | string | 0, 1, 3 | |
SwitchFName | string | 9, 10, 11, 12, 14, 15, 17, 18, 32, 33, 34, 35, 41, 42, 43, 46, 63, 65, 68, 70, 72, 73, 74, 75, 78, 80, 82, 84, 88, 90, 92, 93, 94, 95, 97, 98, 99, 100, 106, 113, 119, 120, 121, 122, 127, 128, 129, 130, 132, 227, 232, 237, 239, 243, 244, 252, 253, 259, 260, 261, 264, 265, 266, 270 | |
SwitchFNameLen | string | 9, 10, 11, 12, 14, 15, 17, 18, 32, 33, 34, 35, 41, 42, 43, 46, 63, 65, 68, 70, 72, 73, 74, 75, 78, 80, 82, 84, 88, 90, 92, 93, 94, 95, 97, 98, 99, 100, 106, 113, 119, 120, 121, 122, 127, 128, 129, 130, 132, 227, 232, 237, 239, 243, 244, 252, 253, 259, 260, 261, 264, 265, 266, 270 | |
SwitchFriendlyName | string | 206, 207, 208, 209, 210, 211, 212, 213, 214, 229, 230 | |
SwitchFriendlyNameLen | string | 206, 207, 208, 209, 210, 211, 212, 213, 214, 229, 230 | |
SwitchName | string | 9, 10, 11, 12, 14, 15, 17, 18, 32, 33, 34, 35, 41, 42, 43, 46, 63, 65, 68, 70, 72, 73, 74, 75, 78, 80, 82, 84, 88, 90, 92, 93, 94, 95, 97, 98, 99, 100, 106, 113, 119, 120, 121, 122, 127, 128, 129, 130, 132, 206, 207, 208, 209, 210, 211, 212, 213, 214, 227, 229, 230, 232, 237, 239, 243, 244, 252, 253, 260, 261, 264, 265, 266, 270 | |
SwitchNameLen | string | 9, 10, 11, 12, 14, 15, 17, 18, 32, 33, 34, 35, 41, 42, 43, 46, 63, 65, 68, 70, 72, 73, 74, 75, 78, 80, 82, 84, 88, 90, 92, 93, 94, 95, 97, 98, 99, 100, 106, 113, 119, 120, 121, 122, 127, 128, 129, 130, 132, 206, 207, 208, 209, 210, 211, 212, 213, 214, 227, 229, 230, 232, 237, 239, 243, 244, 252, 253, 260, 261, 264, 265, 266, 270 | |
SystemAction | string | 1, 7, 8 | |
SystemAssignedAccountName | string | 0, 1, 2, 3, 4 | |
SystemCommitCharge | string | 0, 0, 2, 4 | |
SystemCommitLimit | string | 0, 0, 2, 4 | |
SystemSleepTransitionsToOn | string | 1, 4 | |
SystemTime | string | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | '2022-07-28 14:13:42.451381 UTC' |
SystemTimeChangeSeconds | integer | 3, 4 | 21 |
SystemTimeChangeSeconds | string | 33, 34 | |
System_Props_Xml | string | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 |
|
T10NumBadPages | string | 1101, 1102, 1103, 1104 | |
T11NumBadPages | string | 1101, 1102, 1103, 1104 | |
T12NumBadPages | string | 1101, 1102, 1103, 1104 | |
T13NumBadPages | string | 1101, 1102, 1103, 1104 | |
T14NumBadPages | string | 1101, 1102, 1103, 1104 | |
T15NumBadPages | string | 1101, 1102, 1103, 1104 | |
T16NumBadPages | string | 1101, 1102, 1103, 1104 | |
T1NumBadPages | string | 1101, 1102, 1103, 1104 | |
T2NumBadPages | string | 1101, 1102, 1103, 1104 | |
T3NumBadPages | string | 1101, 1102, 1103, 1104 | |
T4NumBadPages | string | 1101, 1102, 1103, 1104 | |
T5NumBadPages | string | 1101, 1102, 1103, 1104 | |
T6NumBadPages | string | 1101, 1102, 1103, 1104 | |
T7NumBadPages | string | 1101, 1102, 1103, 1104 | |
T8NumBadPages | string | 1101, 1102, 1103, 1104 | |
T9NumBadPages | string | 1101, 1102, 1103, 1104 | |
TCGInvokingID | string | 1, 1 | |
TCGMethodID | string | 1, 1 | |
TLBOperationType | string | 28, 29 | |
TPM_PT_FIRMWARE_VERSION_1 | string | 2, 7 | |
TPM_PT_FIRMWARE_VERSION_2 | string | 2, 7 | |
TPM_PT_MANUFACTURER | string | 2, 7 | |
TPM_PT_VEDNOR_STRING_2 | string | 2, 7 | |
TPM_PT_VEDNOR_STRING_3 | string | 2, 7 | |
TPM_PT_VEDNOR_STRING_4 | string | 2, 7 | |
TPM_PT_VEDNOR_TPM_TYPE | string | 2, 7 | |
TPM_PT_VENDOR_STRING_1 | string | 2, 7 | |
TSId | string | 7001, 7002 | |
TableIndex | string | 0, 1, 5 | |
TargetAffinity | string | 2, 2, 4 | |
TargetDomain | string | 32773, 32774, 32775 | |
TargetId | string | 22, 23, 24, 25, 42, 43, 46, 47 | |
TargetMemoryCount | string | 2, 2, 4 | |
TargetMemorySize | string | 2, 2, 4 | |
TargetName | string | 6037, 6040, 6041, 36880, 36888 | |
TargetPath | string | 240, 241, 242 | |
TargetProcessorCount | string | 2, 2, 4 | |
TargetRunLevel | string | 13, 14, 15, 16 | |
TargetState | string | 1, 42, 107 | |
TargetVersion | string | 0, 1, 4, 6 | |
TaskName | string | 1, 4, 4 | |
TaskProcessID | string | 2, 11 | |
TaskType | string | 1, 5, 6, 10, 14, 15 | |
TeamingMode | string | 206, 207, 208, 209, 210, 211 | |
TeredoReasonCode | string | 0, 0, 1, 4 | |
TestCount | string | 1101, 1102, 1103, 1104 | |
TestDuration | string | 1101, 1102, 1103, 1104 | |
TestType | string | 1101, 1102, 1103, 1104 | |
ThermalZoneDeviceInstance | string | 86, 88, 89, 125 | |
ThermalZoneDeviceInstanceLength | string | 86, 88, 89, 125 | |
ThreadCount | string | 7, 9 | |
ThreadID | string | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 201, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 262, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 285, 286, 289, 290, 300, 301, 302, 379, 380, 381, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 566, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1025, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1056, 1058, 1060, 1061, 1065, 1068, 1074, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1281, 1282, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2001, 2003, 2004, 2005, 2042, 3261, 4000, 4001, 4002, 4003, 4004, 4005, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5202, 5203, 5211, 5300, 5774, 5782, 5823, 6000, 6005, 6006, 6009, 6011, 6013, 6027, 6033, 6035, 6036, 6037, 6038, 6040, 6041, 6100, 6145, 6146, 6148, 6400, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 9009, 10000, 10001, 10002, 10003, 10004, 10005, 10010, 10016, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10121, 10148, 10149, 10154, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14206, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 14531, 14533, 15007, 15008, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16647, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 16983, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 20010, 24576, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50036, 50037, 50038, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | "956" |
ThreadId | integer | 7, 9 | |
ThrottleStateCount | integer | 2, 6 | 0 |
ThrottleStateCount | string | 4, 26 | |
Thumbprint | string | 96, 98, 516, 517, 518 | |
ThumbprintLength | string | 96, 98 | |
TimeDifferenceMilliseconds | string | 0, 5 | |
TimeDifferenceSeconds | string | 1, 5 | |
TimeOffsetSeconds | string | 2, 5 | |
TimeProvider | string | 1, 2, 3, 4, 5, 7, 8, 9, 10, 40, 43, 158 | |
TimeQuiesced | string | 2, 2, 4 | |
TimeRemainingToSetLocalClockFreeRunningSeconds | string | 3, 6 | |
TimeSampleSeconds | string | 0, 5 | |
TimeSource | string | 34, 35, 37, 38, 132, 135 | time.windows.com,0x8 (ntp.m |
TimeSourceRefId | string | 3, 5 | |
TimeStamp | string | 0, 4, 5, 5, 8 | |
TimeToQuiesce | string | 2, 2, 4 | |
TimeToWake | string | 2, 2, 4 | |
TimeTotal | string | 2, 2, 4 | |
TimeZoneInfoCacheUpdated | integer | 2, 4 | 0 |
Timeout | string | 18, 19, 28, 29 | |
Timestamp | string | 1, 2 | |
TimestampForced | string | 0, 1, 8 | |
Title | string | 16385, 16386, 16390 | PreSignInSettingsConfigJSON |
TmId | string | 1, 1 | |
TmIdentity | string | 3, 4 | |
TmLogFileName | string | 3, 4 | |
TmLogFileNameLength | string | 3, 4 | |
ToolsCount | string | 1, 9 | |
TotalProcesses | string | 0, 0, 2, 4 | |
TpcChanges | string | 7, 37 | |
TpmCommandOrdinal | string | 1, 7 | |
TpmResponseCode | string | 1, 7 | |
TransactionType | string | 6, 8, 10, 12, 14, 16, 17, 18, 19, 28, 29 | |
TransitionStartTime | string | 1, 8 | |
TransitionsToOn | string | 2, 4 | |
TransmissionDelayMilliseconds | string | 1, 5 | |
TriggerID | string | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15 | |
TrustletIdentity | string | 1, 2, 4 | |
TryComplete | string | 1, 2, 4 | |
Turn | string | 2, 2 | |
TxDescription | string | 1, 2, 3, 4 | |
TxDescriptionLength | string | 1, 2, 3, 4 | |
TxUow | string | 1, 2, 3, 4 | |
TxtStatus | string | 2, 2, 2 | |
URL | string | 1, 3, 3, 4, 5 | |
UncorrectableErrorStatus | string | 16, 17, 18, 40, 41 | |
Uncorrected | string | 1, 3 | |
UniqueEvent | string | 4, 6, 8, 10, 11, 12, 13, 14, 15, 16, 18, 20, 32, 34, 35, 41, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 132, 190, 235, 236, 238, 239, 258, 269, 276 | |
UniqueEventValue | string | 4, 15 | |
UnitBaseAddress | string | 1, 4, 8 | |
UnsynchronizedTimeSeconds | string | 3, 6 | |
UpdateDllName | string | 6, 8 | |
UpdateReason | string | 0, 2 | |
UpdateService | string | 20003, 20004 | |
UpdateType | string | 0, 2, 2, 4 | |
Upgrade | string | 10001, 10002 | |
UpgradeDevice | string | 20001, 20002 | |
Url | string | 97, 15007, 15008 | http://+:3387/rdp/ |
UrlPrefix | string | 0, 0, 1, 7 | http://*:80/ |
UserData_Xml | string | 104, 1001, 1121, 1206, 1208, 10000, 10001, 10100, 20001, 20003, 20010 |
|
UserID | string | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 201, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 300, 301, 302, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 566, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1025, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1058, 1060, 1061, 1065, 1068, 1074, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1281, 1282, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2003, 2004, 2005, 2042, 4000, 4001, 4002, 4003, 4004, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5300, 6000, 6027, 6033, 6035, 6036, 6037, 6040, 6041, 6100, 6145, 6146, 6148, 6400, 7001, 7002, 7040, 7042, 7045, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 10000, 10001, 10002, 10003, 10004, 10005, 10010, 10016, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16647, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 16983, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 20010, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50036, 50037, 50038, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | "S-1-5-21-582766833-432816504-4207985818-1009" |
UserName | string | 12294, 12302, 16385, 16400, 16406, 45058 | |
UserSID | string | 21, 23 | |
UserSid | string | 7001, 7002 | S-1-5-21-1103654211-1238870038-1204021333-1002 |
Username | string | 0, 4, 5, 5, 7 | |
VMId | string | 26, 61, 102 | |
VMIdLen | string | 26, 61, 102 | |
VMName | string | 26, 33, 61, 102 | |
VMNameLen | string | 26, 33, 61, 102 | |
VMQOffloadWeight | string | 4, 9 | |
ValidBatteryCount | string | 1, 2, 5 | |
ValidBits | string | 16, 17, 22, 23, 24, 25, 26, 27, 40, 41, 42, 43, 44, 45, 46, 47 | |
ValidationBits | string | 1, 2 | |
Value | string | 6, 7, 10113 | |
Vcb | string | 143, 144 | |
VendorID | string | 16, 17, 40, 41 | |
VendorId | string | 26, 27, 44, 45 | |
Verb | string | 55, 97, 99 | |
Verbosity | string | 7, 9 | |
Version | integer | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5782, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 2 |
Version | string | 1, 2, 16, 17, 40, 41, 219 | |
VersionLen | integer | 1 | 3 |
VersionLen | string | 1, 2 | |
VersionSupported | string | 0, 4 | |
VfAdapterName | string | 41, 42, 46, 47, 48 | \DEVICE{651F97F9-A838-4081-A596-E6A86FBB1145} |
VfAdapterNameLen | integer | 4, 6 | 46 |
VfAdapterNameLen | string | 41, 42, 46, 47, 48 | |
VirtualFaultAddress | string | 28, 29 | |
VirtualSubnetId | string | 88, 130 | |
VlanID | string | 1, 7, 9 | |
VlanId | string | 0, 2, 4 | |
VmqIndex | string | 0, 2, 6 | |
VmqSumOfQueues | string | 206, 207, 208, 209, 210, 211 | |
Volume | string | 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686 | |
VolumeGUID | string | 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 823, 824, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24643, 24645, 24652, 24653, 24654, 24657, 24658, 24659, 24672 | |
VolumeGuid | string | 143, 144, 150 | |
VolumeId | string | 130, 131, 134, 135, 136, 137, 138, 139, 140, 210, 211, 517, 518 | |
VolumeIdLength | string | 130, 131, 134, 135, 136, 137, 138, 139, 140, 517, 518 | |
VolumeLabel | string | 1, 3, 4 | |
VolumeLabelLength | string | 1, 3, 4 | |
VolumeName | string | 143, 144, 150, 1206 | |
VolumeNameLength | string | 143, 144, 150, 1206 | |
VolumeNames | string | 1 | |
VportsSupported | string | 204, 205, 215 | |
VsmPolicy | integer | 1, 3, 5 | 0 |
VsmPolicy | string | 153, 156 | |
VxLanEnabled | string | 0, 2, 3 | |
WDFDEVICE | string | 0, 0, 1, 3 | |
WakeDuration | string | 1 | |
WakeFromState | string | 0, 1, 7 | |
WakeRequesterTypeAc | string | 0, 1, 7 | |
WakeRequesterTypeDc | string | 0, 1, 7 | |
WakeSourceText | string | 1 | |
WakeSourceTextLength | string | 1 | |
WakeSourceType | string | 1 | |
WakeTime | string | 1 | |
WakeTimerContext | string | 1 | |
WakeTimerContextLength | string | 1 | |
WakeTimerOwner | string | 1 | |
WakeTimerOwnerLength | string | 1 | |
Weight | string | 82, 84, 100, 130 | |
Win32Err | integer | 2 | |
WinError | string | 12295, 12296 | |
WorkingSetSize | string | 7, 9 | |
WritePhase | string | 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686 | |
binaryData | string | 36867, 36869 | |
body | string | 2, 6 | The application was unable to start correctly (0xc0000142). Click OK to close the application. |
certificateContext | string | 36881, 36882, 36883, 36884 | |
currentLimit | string | 16397, 16398, 16400, 16401, 16402 | |
currentSize | string | 16397, 16398, 16400, 16401, 16402 | |
dest | string | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | win10-base |
dvc | string | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | win10-base |
dvc_nt_host | string | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | win7-x86 |
entityName | string | 16397, 16398, 16400, 16401, 16402 | |
error | integer | 0, 1, 1, 4, 5 | 1355 |
errorCode | string | 20, 24, 213 | 0x8024200b |
event_id | integer | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 93485 |
evtAdditionalInfo | string | 1 | |
evtErrorId | string | 1 | |
evtHiveName | string | 1, 2 | |
evtHiveNameLength | string | 1, 2 | |
evtStatus | string | 1, 3, 4 | |
failureReason | string | 37, 38, 39, 43 | |
fid_DripsWatchdogResult | string | 195, 196 | |
fid_UcxController | string | 1, 4 | |
fid_UsbDevice | string | 195, 196 | |
fid_bcdDevice | string | 195, 196 | |
fid_idProduct | string | 195, 196 | |
fid_idVendor | string | 195, 196 | |
filename | string | 24840, 24841 | |
function | string | 0, 1, 4, 4, 6 | |
locationCode | string | 2, 12, 14, 15, 16, 17, 18, 19, 20, 22, 25, 26, 27 | 0x140000d6 |
offset | string | 24840, 24841 | |
pCertificateContext | string | 36876, 36877, 36878, 36879 | |
param1 | integer | 7009, 10005, 10111 | 50 |
param1 | string | 1074, 7000, 7001, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 10010, 10016 | {4991D34B-80A1-4291-83B6-3328366B9097} |
param10 | string | 0, 0, 1, 1, 6 | Unavailable |
param11 | string | 0, 0, 1, 1, 6 | Unavailable |
param2 | integer | 7031, 7034, 7039 | 5748 |
param2 | string | 1074, 7000, 7001, 7009, 7023, 7024, 7036, 7038, 7040, 7042, 10005, 10016 | stopped |
param3 | integer | 7031, 7039 | 30000 |
param3 | string | 1074, 7001, 7038, 7040, 7042, 10005, 10016 | demand start |
param4 | integer | 0, 1, 3, 7 | 1 |
param4 | string | 1074, 7040, 7042, 10005, 10016 | Windows.SecurityCenter.SecurityAppBroker |
param5 | string | 1074, 7031, 7042, 10016 | restart |
param6 | string | 1074, 10016 | Reboot initiated by Ansible |
param7 | string | 1074, 10016 | SYSTEM |
param8 | string | 0, 0, 1, 1, 6 | S-1-5-18 |
param9 | string | 0, 0, 1, 1, 6 | LocalHost (Using LRPC) |
restarttime | string | 2, 2 | |
schedinstalldate | string | 1, 8 | |
schedinstalltime | string | 1, 8 | |
serverName | string | 32, 33 | |
serviceGuid | string | 19, 20, 23, 24, 212 | 9482F4B4-E343-43B6-B170-9A65BC822C77 |
service_name | integer | 7009, 10005, 10111 | 50 |
service_name | string | 1074, 7000, 7001, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 10010, 10016, 14204, 14205 | {4991D34B-80A1-4291-83B6-3328366B9097} |
sigma_product | string | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | windows |
sigma_service | string | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | system |
signature | string | 19, 20, 43, 44, 519, 566 | Security Intelligence Update for Microsoft Defender Antivirus - KB2267602 (Version 1.353.706.0) |
signature_id | integer | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 98 |
spn1 | string | 0, 1, 1, 4, 5 | WSMAN/WIN-FPV0DSIC9O6.sigma.fr |
spn2 | string | 0, 1, 1, 4, 5 | WSMAN/WIN-FPV0DSIC9O6 |
start_mode | string | 7040, 7045 | manual |
statusActive | string | 2, 4 | |
statusEnabled | string | 2, 4 | |
string | string | 19, 17005 | |
string2 | string | 0, 0, 1, 5, 7 | |
string3 | string | 0, 0, 1, 5, 7 | |
subject | string | 519, 566 | Object Operation (W3 Active Directory) |
timeendpos | integer | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 594 |
timestartpos | integer | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 564 |
updateGuid | string | 19, 20, 23, 24, 43, 44, 212, 213, 214, 215 | 6CE0FD31-E410-43E3-AACA-EDD43C217639 |
updateRevisionNumber | integer | 19, 20, 43, 44 | 200 |
updateRevisionNumber | string | 19, 20, 23, 24, 43, 44, 212, 213, 214, 215 | |
updateTitle | string | 19, 20, 23, 43, 44, 212, 214, 215 | Security Intelligence Update for Microsoft Defender Antivirus - KB2267602 (Version 1.353.706.0) |
updatelist | string | 17, 18, 21, 22, 24, 213 | |
user_id | string | 1, 3, 5, 6, 10, 11, 12, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 50, 52, 55, 98, 104, 134, 137, 139, 143, 153, 172, 201, 206, 238, 519, 521, 566, 1001, 1006, 1014, 1025, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2003, 2004, 6148, 7001, 7002, 7040, 7042, 7045, 8018, 10000, 10001, 10005, 10010, 10016, 10100, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | "S-1-5-21-582766833-432816504-4207985818-1009" |
vPortId | string | 204, 215 | |
vendor | string | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | Microsoft |
vendor_product | string | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | Microsoft Windows |
volume | string | 2, 3, 4, 5, 8 | |
wimFile | string | 24837, 24838, 24839, 24843, 24844, 24845, 24846 | |
wimHashFile | string | 24837, 24838, 24839, 24843, 24844, 24845, 24846 |
taskscheduler
Field | Data Type | Event IDs | Example |
---|---|---|---|
Account | string | 1, 1, 7 | |
Command | string | 310, 311 | |
Computer | string | 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717 | win-dc-469.attackrange.local |
EventID | integer | 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717 | 330 |
Name | string | 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 330, 332, 400, 402, 700 | 'Microsoft-Windows-TaskScheduler' |
Path | string | 1, 2, 9 | %windir%\system32\wermgr.exe |
Task | integer | 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330 | 330 |
Task | string | 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717 | |
id | integer | 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 330, 332, 400, 402, 700 | 5404 |
ActionName | string | 200, 201, 202, 203 | NGC Pregeneration Task Handler |
ActivityID | string | 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 330, 332, 400, 402, 700 | '{7AD1452B-31A1-4664-BAD4-57539A029944}' |
Channel | string | 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717 | Microsoft-Windows-TaskScheduler/Operational |
Context | string | 0, 1, 5 | |
CurrentQuota | string | 131, 132 | |
EnginePID | string | 200, 201, 202 | |
ErrorDescription | string | 104, 303, 311, 403 | |
EventCode | integer | 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 330, 332, 400, 402, 700 | 330 |
EventData_Xml | string | 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330 | \Run NotepadATTACKRANGE\Administrator{7AD1452B-31A1-4664-BAD4-57539A029944} |
EventRecordID | integer | 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 330, 332, 400, 402, 700 | 5404 |
Guid | string | 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 330, 332, 400, 402, 700 | '{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}' |
InstanceId | string | 100, 102, 103, 107, 108, 109, 110, 111, 114, 117, 118, 119, 120, 121, 122, 123, 124, 125 | {7AD1452B-31A1-4664-BAD4-57539A029944} |
Keywords | string | 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717 | 0x8000000000000001 |
Level | integer | 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717 | 4 |
LogPoint | string | 1, 1, 5 | |
Message | string | 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 403, 410, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717 | |
NewTaskInstanceId | string | 2, 3, 3 | |
Opcode | integer | 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330 | 2 |
Opcode | string | 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717 | |
Priority | string | 1, 2, 9 | |
ProcessID | string | 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717 | '1316' |
ProcessId | integer | 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330 | 1816 |
ProviderGUID | string | 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717 | |
ProviderName | string | 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717 | |
QueuedTaskInstanceId | string | 324, 325 | 5F6009CF-535A-456B-B1EB-0B7C5C30AABF |
RecordNumber | integer | 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 330, 332, 400, 402, 700 | 5404 |
RelatedActivityID | string | 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 332, 400, 402, 700 | |
ResultCode | integer | 103, 201, 202 | 2148073520 |
ResultCode | string | 101, 103, 104, 105, 113, 115, 116, 126, 130, 146, 148, 150, 151, 201, 202, 203, 204, 205, 303, 305, 306, 307, 311, 315, 316, 331, 403, 410, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717 | |
RunningTaskInstanceId | string | 2, 3, 4 | EC1D2D19-D309-4577-A40D-0FB4CE6B479C |
SecurityDescriptor | string | 0, 7, 8 | |
SessionId | string | 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 332, 400, 402, 700 | |
SigmaEventCode | integer | 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330 | 330 |
StoppedTaskInstanceId | string | 2, 3, 3 | |
SystemTime | string | 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 330, 332, 400, 402, 700 | '2022-06-28 15:11:04.524776 UTC' |
System_Props_Xml | string | 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330 |
|
TaskCount | string | 0, 3, 9 | |
TaskEngineName | string | 133, 134, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320 | |
TaskInstanceId | string | 200, 201, 202, 203, 304, 320, 322, 327, 328, 329, 330, 331 | {7AD1452B-31A1-4664-BAD4-57539A029944} |
TaskName | string | 100, 101, 102, 103, 106, 107, 108, 109, 110, 111, 112, 113, 114, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 133, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 200, 201, 202, 203, 204, 205, 304, 305, 319, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 706, 707, 708, 709, 713, 714 | \Run Notepad |
TaskPath | string | 1, 5, 5 | |
TaskStatus | string | 0, 6, 7 | |
ThreadID | string | 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717 | '5004' |
UserContext | string | 100, 101, 102, 103, 106, 110, 330 | System |
UserID | string | 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717 | 'S-1-5-18' |
UserName | string | 104, 119, 120, 121, 122, 123, 124, 125, 133, 134, 140, 141, 142, 332 | SNAPATTACK\snapattack |
Version | integer | 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 330, 332, 400, 402, 700 | 2 |
dvc | string | 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 330, 332, 400, 402, 700 | win-dc-469.attackrange.local |
dvc_nt_host | string | 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330 | win-dc-469.attackrange.local_0d8ffca2-620a-4526-a4de-aef022b9dd48 |
event_id | integer | 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330 | 5404 |
sigma_product | string | 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330 | windows |
sigma_service | string | 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330 | taskscheduler |
signature_id | integer | 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330 | 330 |
timeendpos | integer | 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330 | 521 |
timestartpos | integer | 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330 | 491 |
user_id | string | 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330 | 'S-1-5-18' |
vendor_product | string | 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330 | Microsoft Windows |
wmi
Field | Data Type | Event IDs | Example |
---|---|---|---|
EventID | integer | 5857, 5858, 5859, 5860, 5861 | 5861 |
Name | string | 5857, 5858, 5859, 5860, 5861 | Microsoft-Windows-WMI-Activity |
ProcessName | string | 5858, 5860 | 'wsmprovhost.exe' |
AND_TargetInstance_Minute | integer | 5859, 5861 | 33 |
AND_TargetInstance_Second | integer | 5859, 5861 | 0 |
ActivityID | string | 5857, 5858, 5859, 5860, 5861 | B9A944CA-4FFF-0000-E056-A9B9FF4FD801 |
Category | integer | 1, 5, 6, 8 | 0 |
CommandLineEventConsumer | string | 1, 5, 6, 8 | AtomicRedTeam-WMIPersistence-Example |
CommandLineTemplate | string | 1, 5, 6, 8 | C:\Windows\System32\notepad.exe |
CreatorSID | string | 1, 5, 6, 8 | {1, 2, 0, 0, 0, 0, 0, 5, 32, 0, 0, 0, 32, 2, 0, 0} |
EventCode | integer | 5857, 5858, 5859, 5860, 5861 | 5861 |
EventNamespace | string | 1, 5, 6, 8 | root\cimv2 |
Guid | string | 5857, 5858, 5859, 5860, 5861 | 1418EF04-B0B4-4623-BF7E-D74AB47BBDAA |
NTEventLogEventConsumer | string | 1, 5, 6, 8 | SCM Event Log Consumer |
NameOfUserSIDProperty | string | 1, 5, 6, 8 | sid |
OR_TargetInstance_DayOfWeek | integer | 5859, 5861 | 2 |
ProcessID | integer | 5857, 5858, 5859, 5860, 5861 | 4168 |
ProcessId | integer | 5857, 5858, 5859, 5860, 5861 | 4168 |
Query | string | 1, 5, 6, 8 | select * from MSFT_SCMEventLogEvent |
QueryLanguage | string | 1, 5, 6, 8 | WQL |
RunInteractively | string | 1, 5, 6, 8 | FALSE |
SigmaEventCode | integer | 5857, 5858, 5859, 5860, 5861 | 5861 |
SourceName | string | 1, 5, 6, 8 | Service Control Manager |
SystemTime | string | 5857, 5858, 5859, 5860, 5861 | '2022-07-05 18:43:00.611527 UTC' |
TargetInstance_DayOfWeek | integer | 5859, 5861 | 1 |
TargetInstance_Hour | integer | 5859, 5861 | 11 |
TargetInstance_Minute | integer | 5859, 5861 | 30 |
TargetInstance_Second | integer | 1, 5, 6, 8 | 40 |
TargetInstance_Second | string | 5, 5, 8, 9 | 40 |
ThreadID | integer | 5857, 5858, 5859, 5860, 5861 | 9020 |
UserID | string | 5857, 5858, 5859, 5860, 5861 | S-1-5-18 |
sigma_product | string | 5857, 5858, 5859, 5860, 5861 | windows |
sigma_service | string | 5857, 5858, 5859, 5860, 5861 | wmi |
timeendpos | integer | 5857, 5858, 5859, 5860, 5861 | 518 |
timestartpos | integer | 5857, 5858, 5859, 5860, 5861 | 488 |
xmlns | string | 5857, 5858, 5859, 5860, 5861 | http://schemas.microsoft.com/win/2004/08/events/event |