Skip to content

Windows

application

Field Data Type Event IDs Example
Application string 1, 2
Computer string 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 15, 16, 17, 18, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 38, 43, 45, 47, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 256, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 637, 641, 642, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 781, 852, 854, 865, 866, 867, 868, 873, 882, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1010, 1012, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1041, 1042, 1043, 1044, 1061, 1066, 1109, 1114, 1130, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1511, 1512, 1514, 1515, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 1704, 1903, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2080, 2303, 2484, 2486, 3001, 3002, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4121, 4128, 4129, 4176, 4177, 4178, 4202, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 4879, 5000, 5001, 5008, 5602, 5604, 5605, 5606, 5611, 5612, 5615, 5617, 5631, 5973, 6000, 6003, 6253, 6527, 7000, 7002, 8192, 8193, 8194, 8195, 8196, 8198, 8199, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 8303, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
windowsvictim
Event string 1, 3, 4, 5
EventID integer 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 15, 16, 17, 18, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 38, 43, 45, 47, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 256, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 637, 641, 642, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 781, 852, 854, 865, 866, 867, 868, 873, 882, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1010, 1012, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1041, 1042, 1043, 1044, 1061, 1066, 1109, 1114, 1130, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1511, 1512, 1514, 1515, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 1704, 1903, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2080, 2303, 2484, 2486, 3001, 3002, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4121, 4128, 4129, 4176, 4177, 4178, 4202, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 4879, 5000, 5001, 5008, 5602, 5604, 5605, 5606, 5611, 5612, 5615, 5617, 5631, 5973, 6000, 6003, 6253, 6527, 7000, 7002, 8192, 8193, 8194, 8195, 8196, 8198, 8199, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 8303, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
9689
File string 1508, 1509, 1514, 10002, 10003, 10006, 10007
C:\Users\user2\ntuser.dat
FileName string 1, 10009
Name string 0, 1, 2, 3, 4, 5, 11, 13, 15, 16, 26, 30, 32, 34, 35, 38, 45, 47, 48, 63, 64, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 637, 641, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1552, 1704, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5000, 5001, 5008, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
"edgeupdate"
Object string 4, 8
Path string 0, 5, 9
Service string 1008, 1020, 10009
BITS
Source string 1509, 1600, 1601
Target string 1509, 1600, 1601
Task integer 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
9
Task string 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 15, 16, 17, 18, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 38, 43, 45, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 92, 100, 101, 102, 103, 105, 198, 200, 256, 257, 300, 301, 302, 326, 330, 335, 455, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 641, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 865, 866, 867, 868, 882, 900, 902, 903, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1010, 1012, 1013, 1020, 1022, 1025, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1041, 1042, 1043, 1044, 1066, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1512, 1514, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 1704, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2484, 2486, 3001, 3002, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4128, 4129, 4176, 4177, 4178, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 5000, 5001, 5008, 5602, 5604, 5605, 5606, 5612, 5615, 5617, 5631, 5973, 6000, 7000, 7002, 8192, 8194, 8199, 8212, 8216, 8224, 8225, 8300, 8301, 8302, 8303, 9027, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 11707, 11728, 11756, 12116, 16384, 16390, 16394, 20221, 20222, 20223, 20224, 20225, 20226
Text string 81, 82, 83
User string 5
WINDEV2202EVAL\user2
action string 642, 4879
unknown
file string 3
hr string 27, 28, 29, 31, 33, 34
id integer 0, 1, 2, 3, 4, 5, 11, 13, 15, 16, 26, 30, 32, 34, 35, 38, 45, 47, 48, 63, 64, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 637, 641, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1552, 1704, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5000, 5001, 5008, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
9617
line string 3
name string 637, 641, 642, 852, 4625, 4879
User Account Changed
status string 4, 7, 8, 9
unknown
ActivityID string 64, 900, 902, 903, 1003, 1004, 1008, 1013, 1020, 1033, 1034, 1040, 1066, 1531, 1532, 1552, 4097, 4109, 4111, 4625, 5611, 5615, 5617, 6000, 8224, 8300, 8301, 8302, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 16384, 16390, 16394
"9AEFBC8D-3E49-4448-B988-5F313E7F68B0"
AdditionalDetails string 1
AddonName string 1, 2
AppId string 3, 5, 7, 9
AppName string 1, 2, 3, 10001, 10002
AppNameCount string 1, 2, 3
AppType string 10002, 10003, 10006, 10007, 10010
AppVersion string 10002, 10003, 10006, 10007, 10010
ApplicationId string 5, 5, 6
ApplicationName string 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
ApplicationPool string 0, 2, 3, 3
MSExchangeOABAppPool
Applications string 0, 0, 0, 1, 5
AttemptedPath string 50, 865, 866, 867, 868, 882
AuthorId string 2001, 2002, 3002
BackupFailureLogPath string 4, 5, 7
BackupFile string 67, 68, 5602
BackupRepository string 66, 5604
BackupSourceNumUnreadableBytes string 2, 5, 5
BackupTarget string 2, 3, 5
BackupTargetFriendlyName string 522, 564, 658
BackupTargetList string 608, 609, 611
BackupTime string 517, 518, 519, 521, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611
BackupUserName string 4, 5, 6
BufferSize integer 0, 0, 1, 2
CVEID string 1
Caption string 81, 82, 83
CatalogName string 1, 1, 2, 4
SystemIndex
CategoryString string 637, 641, 642
Account Management
Channel string 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 15, 16, 17, 18, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 38, 43, 45, 47, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 256, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 637, 641, 642, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 781, 852, 854, 865, 866, 867, 868, 873, 882, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1010, 1012, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1041, 1042, 1043, 1044, 1061, 1066, 1109, 1114, 1130, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1511, 1512, 1514, 1515, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 1704, 1903, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2080, 2303, 2484, 2486, 3001, 3002, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4121, 4128, 4129, 4176, 4177, 4178, 4202, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 4879, 5000, 5001, 5008, 5602, 5604, 5605, 5606, 5611, 5612, 5615, 5617, 5631, 5973, 6000, 6003, 6253, 6527, 7000, 7002, 8192, 8193, 8194, 8195, 8196, 8198, 8199, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 8303, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
Application
Class string 24, 25, 58, 59, 5631
Component string 1, 3, 4, 5
ComponentName string 5, 5, 6
ContentType string 1
Context string 64, 86
Système local
CurDirDllPath string 11, 12
DBType string 1, 2, 3
Detail string 0, 1, 3, 5
1 user registry handles leaked from \Registry\User\S-1-5-21-712794737-353456615-3249761964-1001:
Process 576 (\Device\HarddiskVolume2\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-712794737-353456615-3249761964-1001
DisplayName string 10002, 10003, 10006, 10007, 10010
Error string 4, 10, 11, 12, 13, 22, 43, 48, 68, 502, 513, 515, 517, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1512, 1519, 1520, 1521, 1522, 1523, 1533, 1534, 1537, 1538, 1539, 1541, 1542, 3001, 5604
The process cannot access the file because it is being used by another process.
ErrorCode string 9, 86, 502, 517, 518, 519, 521, 526, 527, 528, 544, 546, 565, 707, 708, 722, 723, 738, 739, 770, 773, 774, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1010, 1012, 1041, 1042, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 5973, 8301, 8302, 8303
Non trouvé (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)
ErrorDetails string 502, 503, 505, 506, 507, 508, 509, 511, 513, 515, 517
ErrorMessage string 517, 518, 519, 521, 527, 528, 544, 546, 707, 708, 722, 723, 738, 739, 770, 773, 774, 1041, 1042
ErrorMsg string 1002, 1003, 1004, 1005, 1006, 1007, 1010, 1012
ErrorNumber string 28, 29
ErrorString string 10, 11, 12
Error_Code integer 0, 1, 5, 9
3221225539
Error_Code string 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
-
EventCode integer 0, 1, 2, 3, 4, 5, 11, 13, 15, 16, 26, 30, 32, 34, 35, 38, 45, 47, 48, 63, 64, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 637, 641, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1552, 1704, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5000, 5001, 5008, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
9689
EventData_Xml string 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1530, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
‎mardi ‎16 ‎mars ‎2021 08:29:24    
EventProvider string 21, 22, 23, 24, 25
EventRecordID integer 0, 1, 2, 3, 4, 5, 11, 13, 15, 16, 26, 30, 32, 34, 35, 38, 45, 47, 48, 63, 64, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 637, 641, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1552, 1704, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5000, 5001, 5008, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
9617
EventSourceName string 5, 64, 86, 781, 900, 902, 903, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1024, 1025, 1029, 1033, 1034, 1040, 1061, 1066, 2303, 3036, 3079, 4097, 4100, 4101, 4102, 4107, 4108, 4109, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5615, 5617, 6000, 6003, 8198, 8200, 8230, 10024, 12288, 12290, 16384, 16388, 16390, 16394
"Wlclntfy"
ExpectedInterfaceID string 0, 1
ExtraInfo string 3036, 3079
Context: Windows Application

Details:
The volume change journal is being deleted. (HRESULT : 0x8007049a) (0x8007049a)
FailedBinary string 9
FailedVolumeNames string 519, 547
FailureReason string 0, 1
FileNumber string 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418
FilesCachedFirstPass string 8301, 8302, 8303
FilesMissedSecondPass string 8301, 8302, 8303
FilesResident string 8301, 8302, 8303
FilesScoped string 8301, 8302, 8303
FilterHostProcessID integer 0, 0, 1, 2, 4
4860
First string 16, 33, 34
Flags string 0, 0, 1, 3
Folder string 505, 506, 507, 508, 509, 514, 515, 516, 517, 1533, 1535, 1536, 1537, 1538, 1539, 1543
C:\Users\TEMP
FolderPath string 2, 2
FolderString string 1, 3
FoundDllPath string 1, 1
FromFolder string 501, 502, 512, 513
FullPath string 10002, 10003, 10006, 10007, 10010
Guid string 5, 11, 64, 86, 781, 900, 902, 903, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1020, 1024, 1025, 1029, 1033, 1034, 1040, 1061, 1066, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1552, 2303, 3036, 3079, 4097, 4100, 4101, 4102, 4107, 4108, 4109, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 8198, 8200, 8230, 8300, 8301, 8302, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 10024, 12288, 12290, 16384, 16388, 16390, 16394
"{e23b33b0-c8c9-472c-a5f9-f2bdfea0f156}"
HandleInstallErrorCode string 5, 5, 7
HostName string 4097, 4098, 4099, 4100
HostProcessID string 1, 2, 5, 6
Hresult string 2
ImportDllName string 0, 1
InterfaceGUID string 2, 3, 5, 7, 8
InterfaceId string 1, 1
3F31C91E-2545-4B7B-9311-9529E8BFFEF6
InterferingImageName string 1545, 1552
C:\Users\User\Downloads\ProfSvcLPE.exe
InterferingPID integer 1, 4, 5, 5
4336
InterferingPID string 1545, 1552
Keywords string 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 15, 16, 17, 18, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 38, 43, 45, 47, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 256, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 637, 641, 642, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 781, 852, 854, 865, 866, 867, 868, 873, 882, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1010, 1012, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1041, 1042, 1043, 1044, 1061, 1066, 1109, 1114, 1130, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1511, 1512, 1514, 1515, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 1704, 1903, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2080, 2303, 2484, 2486, 3001, 3002, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4121, 4128, 4129, 4176, 4177, 4178, 4202, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 4879, 5000, 5001, 5008, 5602, 5604, 5605, 5606, 5611, 5612, 5615, 5617, 5631, 5973, 6000, 6003, 6253, 6527, 7000, 7002, 8192, 8193, 8194, 8195, 8196, 8198, 8199, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 8303, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
0x8080000000000000
Level integer 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 15, 16, 17, 18, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 38, 43, 45, 47, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 256, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 637, 641, 642, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 781, 852, 854, 865, 866, 867, 868, 873, 882, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1010, 1012, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1041, 1042, 1043, 1044, 1061, 1066, 1109, 1114, 1130, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1511, 1512, 1514, 1515, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 1704, 1903, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2080, 2303, 2484, 2486, 3001, 3002, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4121, 4128, 4129, 4176, 4177, 4178, 4202, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 4879, 5000, 5001, 5008, 5602, 5604, 5605, 5606, 5611, 5612, 5615, 5617, 5631, 5973, 6000, 6003, 6253, 6527, 7000, 7002, 8192, 8193, 8194, 8195, 8196, 8198, 8199, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 8303, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
4
Library string 1008, 1020
C:\Windows\System32\bitsperf.dll
LineNumber string 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418
LogicalPath string 5, 5, 6
MOF string 4
MachineKeys string 0, 1, 5, 9
BCD00000000, COMPONENTS,
MachineName string 2, 3, 5
Message string 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 16, 17, 18, 20, 21, 22, 23, 24, 25, 27, 28, 29, 31, 33, 34, 43, 48, 50, 58, 59, 63, 66, 67, 68, 81, 82, 83, 256, 257, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 865, 866, 867, 868, 882, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1010, 1012, 1040, 1041, 1042, 1043, 1044, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1512, 1514, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2484, 2486, 3001, 3002, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4128, 4129, 4176, 4177, 4178, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 5602, 5604, 5605, 5606, 5612, 5631, 5973, 7000, 7002, 8192, 8199, 8300, 8301, 8302, 8303, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010
MessageText string 6, 8
GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"vmw-keyid-e7286866ba6366b54d95a3bc555d89931e800152.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Tue, 01 Mar 2022 19:17:49 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 07abe409-5f87-4a2a-8370-5361e9a5bb9e
Method integer 1, 1
10
Method string 11, 86
GET(250ms)
MethodString string 0, 0, 1, 3
ModuleName string 0, 0, 1, 3
NTSTATUS integer 1000, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 8199
Namespace string 10, 22, 23, 24, 43, 48, 63, 5605, 5606
ObjId string 4, 6
Opcode integer 1, 3, 5, 11, 13, 15, 16, 86, 100, 102, 103, 105, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1024, 1025, 1026, 1029, 1033, 1034, 1038, 1040, 1042, 1061, 1066, 1109, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 2001, 2303, 3036, 3079, 3408, 4097, 4100, 4101, 4102, 4107, 4108, 4109, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8195, 8198, 8200, 8224, 8225, 8230, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
0
Opcode string 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 16, 17, 18, 20, 21, 22, 23, 24, 25, 27, 28, 29, 31, 33, 34, 43, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 256, 257, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 865, 866, 867, 868, 882, 900, 902, 903, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1010, 1012, 1013, 1020, 1033, 1034, 1040, 1041, 1042, 1043, 1044, 1066, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1512, 1514, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2484, 2486, 3001, 3002, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4128, 4129, 4176, 4177, 4178, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 5602, 5604, 5605, 5606, 5612, 5615, 5617, 5631, 5973, 6000, 7000, 7002, 8192, 8199, 8224, 8300, 8301, 8302, 8303, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 16384, 16390, 16394
Operation string 20, 21, 23, 24
OperationError string 20, 21, 23, 24
Options string 501, 502, 512, 513, 514, 515, 516, 517
PackageFamily string 20, 21, 23, 24
PackageFullName string 9
PackageString string 1, 3
Parameter string 0, 1, 5
Pid string 10002, 10003, 10006, 10007, 10010
ProcessID string 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 15, 16, 17, 18, 20, 21, 22, 23, 24, 25, 27, 28, 29, 31, 33, 34, 43, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 86, 100, 102, 103, 105, 256, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 642, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 781, 852, 854, 865, 866, 867, 868, 873, 882, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1010, 1012, 1013, 1014, 1016, 1020, 1024, 1025, 1026, 1029, 1033, 1034, 1038, 1040, 1041, 1042, 1043, 1044, 1061, 1066, 1109, 1130, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1511, 1512, 1514, 1515, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2303, 2484, 2486, 3001, 3002, 3036, 3079, 3408, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4121, 4128, 4129, 4176, 4177, 4178, 4202, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 4879, 5602, 5604, 5605, 5606, 5611, 5612, 5615, 5617, 5631, 5973, 6000, 6003, 6253, 6527, 7000, 7002, 8192, 8193, 8195, 8198, 8199, 8200, 8224, 8225, 8230, 8300, 8301, 8302, 8303, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
"9576"
ProcessId integer 1, 3, 5, 11, 13, 15, 16, 86, 100, 102, 103, 105, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1024, 1025, 1026, 1029, 1033, 1034, 1038, 1040, 1042, 1061, 1066, 1109, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 2001, 2303, 3036, 3079, 3408, 4097, 4100, 4101, 4102, 4107, 4108, 4109, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8195, 8198, 8200, 8224, 8225, 8230, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
9576
ProcessId string 2, 3, 4, 5, 6, 7, 8, 9, 10, 11
ProcessImagePath string 10, 11, 12
ProfsvcPID integer 1, 4, 5, 5
1716
ProfsvcPID string 1545, 1552
Provider string 3, 6
ProviderGUID string 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 16, 17, 18, 20, 21, 22, 23, 24, 25, 27, 28, 29, 31, 33, 34, 43, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 256, 257, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 865, 866, 867, 868, 882, 900, 902, 903, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1010, 1012, 1013, 1020, 1033, 1034, 1040, 1041, 1042, 1043, 1044, 1066, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1512, 1514, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2484, 2486, 3001, 3002, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4128, 4129, 4176, 4177, 4178, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 5602, 5604, 5605, 5606, 5612, 5615, 5617, 5631, 5973, 6000, 7000, 7002, 8192, 8199, 8300, 8301, 8302, 8303, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 16384, 16390, 16394
ProviderIconId string 0, 1, 4, 4
ProviderName string 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 16, 17, 18, 20, 21, 22, 23, 24, 25, 27, 28, 29, 31, 33, 34, 43, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 256, 257, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 865, 866, 867, 868, 882, 900, 902, 903, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1010, 1012, 1013, 1020, 1033, 1034, 1040, 1041, 1042, 1043, 1044, 1066, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1512, 1514, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2484, 2486, 3001, 3002, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4128, 4129, 4176, 4177, 4178, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 5602, 5604, 5605, 5606, 5612, 5615, 5617, 5631, 5973, 6000, 7000, 7002, 8192, 8199, 8300, 8301, 8302, 8303, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 16384, 16390, 16394
ProviderNameId string 0, 1, 4, 4
ProvidersInHost string 1, 2, 5, 6
PsmKey string 2484, 2486
Publisher string 1, 2
Qualifiers string 0, 1, 2, 3, 4, 5, 13, 15, 16, 26, 30, 32, 34, 35, 38, 45, 47, 48, 63, 64, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 637, 641, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1704, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5000, 5001, 5008, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8216, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
"49754"
Query string 10, 21, 22, 23, 24, 25
QuotaName string 1, 2, 5, 6
QuotaThreshold string 1, 2, 5, 6
QuotaValue string 1, 2, 5, 6
Reason string 1004, 1008, 7000, 7002, 10010
Full Index Reset
ReceivedInterfaceID string 0, 1
RecordNumber integer 0, 1, 2, 3, 4, 5, 11, 13, 15, 16, 26, 30, 32, 34, 35, 38, 45, 47, 48, 63, 64, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 637, 641, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1552, 1704, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5000, 5001, 5008, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
9617
RelatedActivityID string 64, 900, 902, 903, 1003, 1004, 1013, 1020, 1033, 1034, 1040, 1066, 1531, 1532, 1552, 4097, 4109, 4111, 4625, 5615, 5617, 6000, 8224, 8300, 8301, 8302, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 16384, 16390, 16394
RepairTriggerError string 21, 24
RequiredSize integer 0, 0, 1, 2
ResourceDll string 0, 1, 4, 4
ResponseTime string 0, 0, 0, 1, 1
RestoreTargetNameList string 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 1040, 1041, 1042, 1043
RestoreTime string 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 769, 770, 771, 772, 773, 774, 1040, 1041, 1042, 1043
Result string 5, 8
RmSessionId string 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010
RulePath string 6, 6, 8
Second string 16, 33, 34
SessionID string 1, 2, 3
SessionId string 0, 1, 2, 3, 15, 16, 26, 30, 32, 34, 35, 38, 45, 63, 64, 92, 100, 101, 102, 103, 105, 198, 200, 300, 301, 302, 326, 330, 335, 455, 641, 900, 902, 903, 1000, 1003, 1004, 1013, 1020, 1022, 1025, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1042, 1066, 1531, 1532, 1552, 1704, 4097, 4098, 4109, 4111, 4625, 5000, 5001, 5008, 5615, 5617, 6000, 8194, 8212, 8216, 8224, 8225, 8300, 8301, 8302, 9027, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 11707, 11728, 11756, 12116, 16384, 16390, 16394, 20221, 20222, 20223, 20224, 20225, 20226
SigmaEventCode integer 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
9689
SnapinId string 0, 1, 4, 4
SnapshotPath string 8300, 8301, 8302, 8303
SrpRuleGuid string 50, 866, 868, 882
Stage string 6, 8
GetCACaps
Status integer 0, 1, 5, 9
3221225539
Status string 1509, 10002, 10003, 10006, 10007, 10010
String string 2
Summary string 1, 2, 3
SummaryCount string 1, 2, 3
SvcHostPid string 0, 0, 0, 1, 9
SystemTime string 0, 1, 2, 3, 4, 5, 11, 13, 15, 16, 26, 30, 32, 34, 35, 38, 45, 47, 48, 63, 64, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 637, 641, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1552, 1704, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5000, 5001, 5008, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
'2022-07-26 17:31:46.583705 UTC'
System_Props_Xml string 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
        1109    0    4    0    0    0x80000000000000            3857                    Application    win10-base        
TSSessionId string 10002, 10003, 10006, 10007, 10010
ThreadID string 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 15, 16, 17, 18, 20, 21, 22, 23, 24, 25, 27, 28, 29, 31, 33, 34, 43, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 86, 100, 102, 103, 105, 256, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 642, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 781, 852, 854, 865, 866, 867, 868, 873, 882, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1010, 1012, 1013, 1014, 1016, 1020, 1024, 1025, 1026, 1029, 1033, 1034, 1038, 1040, 1041, 1042, 1043, 1044, 1061, 1066, 1109, 1130, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1511, 1512, 1514, 1515, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2303, 2484, 2486, 3001, 3002, 3036, 3079, 3408, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4121, 4128, 4129, 4176, 4177, 4178, 4202, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 4879, 5602, 5604, 5605, 5606, 5611, 5612, 5615, 5617, 5631, 5973, 6000, 6003, 6253, 6527, 7000, 7002, 8192, 8193, 8195, 8198, 8199, 8200, 8224, 8225, 8230, 8300, 8301, 8302, 8303, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
"8568"
ToFolder string 501, 502, 512, 513
TotalDirectories string 8301, 8302, 8303
TotalFiles string 8301, 8302, 8303
TypeId string 2001, 2002, 3002
URL string 3036, 4097, 4098, 4099, 4100
csc://{S-1-5-21-712794737-353456615-3249761964-1001}/
UTCStartTime string 10000, 10001
UnknownRequestCode string 5, 6, 7
Url string 6, 8
https://VMW-KeyId-e7286866ba6366b54d95a3bc555d89931e800152.microsoftaik.azure.net/templates/Aik/scep
UserData_Xml string 1000, 1001, 10000, 10001, 10002, 10006
      2      2022-03-07 15:22:24.267074 UTC    
UserID string 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 15, 16, 17, 18, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 38, 43, 45, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 86, 92, 100, 101, 102, 103, 105, 198, 200, 256, 257, 300, 301, 302, 326, 330, 335, 455, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 641, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 865, 866, 867, 868, 882, 900, 902, 903, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1010, 1012, 1013, 1020, 1022, 1025, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1041, 1042, 1043, 1044, 1066, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1511, 1512, 1514, 1515, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 1704, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2484, 2486, 3001, 3002, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4128, 4129, 4176, 4177, 4178, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 5000, 5001, 5008, 5602, 5604, 5605, 5606, 5611, 5612, 5615, 5617, 5631, 5973, 6000, 7000, 7002, 8192, 8194, 8199, 8212, 8216, 8224, 8225, 8300, 8301, 8302, 8303, 9027, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 11707, 11724, 11728, 11756, 12116, 16384, 16390, 16394, 20221, 20222, 20223, 20224, 20225, 20226
"S-1-5-21-582766833-432816504-4207985818-1009"
UserKeys string 0, 1, 5, 9
UserSid string 1, 1, 5, 7
VendorId string 2001, 2002, 3002
VendorName string 1, 2, 3
VendorNameCount string 1, 2, 3
VendorType string 2001, 2002, 3002
Version integer 1, 3, 5, 11, 13, 15, 16, 86, 100, 102, 103, 105, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1024, 1025, 1026, 1029, 1033, 1034, 1038, 1040, 1042, 1061, 1066, 1109, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 2001, 2303, 3036, 3079, 3408, 4097, 4100, 4101, 4102, 4107, 4108, 4109, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8195, 8198, 8200, 8224, 8225, 8230, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
2
Version string 1, 2, 64, 900, 902, 903, 1003, 1004, 1013, 1020, 1033, 1034, 1040, 1066, 1531, 1532, 1552, 4097, 4109, 4111, 4625, 5615, 5617, 6000, 8224, 8300, 8301, 8302, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 16384, 16390, 16394
VolumeFriendlyName string 2, 5, 5
VolumeGuid string 2, 5, 5
VolumeName string 0, 3, 7, 9
C:\
Win32Error integer 0, 0, 1, 8
1359
Wordlist string 2
WriterId string 5, 5, 6
cbSize string 0, 0, 0, 1, 8
clsid string 0
dest string 0, 1, 2, 3, 4, 5, 11, 13, 15, 16, 26, 30, 32, 34, 35, 38, 45, 47, 48, 63, 64, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 637, 641, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1552, 1704, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5000, 5001, 5008, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
windowsvictim
dvc string 0, 1, 2, 3, 4, 5, 11, 13, 15, 16, 26, 30, 32, 34, 35, 38, 45, 47, 48, 63, 64, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 637, 641, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1552, 1704, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5000, 5001, 5008, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
windowsvictim
dvc_nt_host string 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
windowsvictim_7db9e240-15f7-410a-8cd9-cc1fa9f3f50a
dwCheckPoint string 2
dwControlsAccepted string 2
dwCurrentState string 2
dwRebootReasons string 0, 0, 0, 1, 5
dwServiceSpecificExitCode string 2
dwServiceType string 2
dwWaitHint string 2
dwWin32ExitCode string 2
error string 3
event_id integer 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
9617
function string 3
hresult string 0, 1
languageTag string 0, 2
nApplications string 0, 0, 0, 1, 5
nFiles string 10002, 10003, 10006, 10007, 10009
nServices string 0, 0, 0, 1, 9
param1 integer 781, 4202, 4625, 4879
86400
param10 integer 0, 2, 2, 4
0
param11 integer 0, 2, 2, 4
0
param12 integer 0, 2, 2, 4
1
param2 integer 0, 2, 2, 4
0
param2 string 781, 4625, 4879
TEST-THKWMDWTQP
param3 integer 0, 2, 2, 4
0
param3 string 781, 4625
Software\Microsoft\EventSystem\EventLog
param4 integer 0, 2, 2, 4
0
param5 integer 0, 2, 2, 4
0
param6 integer 0, 2, 2, 4
0
param7 integer 0, 2, 2, 4
1
param8 string 0, 2, 2, 4
Mutual Authentication Required
param9 string 0, 2, 2, 4
NT AUTHORITY\NetworkService
pbBinary string 0, 0, 0, 1, 8
policyName string 0
policyValue string 0
sigma_product string 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
windows
sigma_service string 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
application
signature string 637, 641, 642, 852, 4625, 4879
User Account Changed
signature_id integer 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
9689
string string 1, 17, 18
subject string 637, 641, 642, 852, 4625, 4879
User Account Changed
timeendpos integer 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
592
timestartpos integer 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
562
user_id string 11, 86, 1000, 1001, 1008, 1022, 1025, 1029, 1033, 1035, 1038, 1040, 1042, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 5611, 5615, 5617, 10000, 10001, 10002, 10006, 11707, 11724, 11728
"S-1-5-21-582766833-432816504-4207985818-1009"
vendor_product string 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921
Microsoft Windows
wordlist string 20, 31

dns-server

Field Data Type Event IDs Example
Computer string 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
WIN-FPV0DSIC9O6.sigma.fr
EventID integer 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
7693
Name string 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
"Microsoft-Windows-DNS-Server-Service"
Task integer 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
0
id integer 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
60
name string 0, 0, 4, 5
Metabase Add Key
Channel string 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
DNS Server
EventCode integer 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
7693
EventData_Xml string 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4015, 4500, 5504, 7693
_msdcs.sigma.fr    ForestDnsZones.sigma.fr    0D000000
EventRecordID integer 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
60
Guid string 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
"71A551F5-C893-4849-886B-B5EC8502641E"
Keywords string 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
0x8000000000100000
Level integer 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
4
Opcode integer 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
0
ProcessID string 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
"6628"
ProcessId integer 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
6628
RecordNumber integer 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
60
SigmaEventCode integer 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
7693
SystemTime string 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
'2022-06-03 10:04:40.847180 UTC'
System_Props_Xml string 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
        769    0    4    0    0    0x8000000000000010            9                    DNS Server    WIN-FPV0DSIC9O6.sigma.fr        
ThreadID string 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
"6844"
UserID string 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
"S-1-5-21-2121334350-1110938707-2888912545-500"
Version integer 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
0
VirtualizationID string 6, 7, 9
.
dvc string 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
WIN-FPV0DSIC9O6.sigma.fr
dvc_nt_host string 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
Win2022-AD
event_id integer 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
60
param1 integer 3150, 7693
65433
param1 string 404, 407, 408, 769, 2631, 4007, 4500, 5504
_msdcs.sigma.fr
param2 string 769, 2631, 3150, 4007, 4500
sigma.fr
param3 string 769, 2631, 3150
sigma.fr.dns
sigma_product string 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
windows
sigma_service string 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
dns-server
signature string 0, 0, 4, 5
Metabase Add Key
signature_id integer 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
7693
subject string 0, 0, 4, 5
Metabase Add Key
timeendpos integer 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
523
timestartpos integer 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
493
user_id string 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
"S-1-5-21-2121334350-1110938707-2888912545-500"
vendor_product string 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693
Microsoft Windows

msexchange-management

Field Data Type Event IDs Example
Computer string 1
MXS01.snapattack.local
EventID integer 1
1
Name string 1
"MSExchange CmdletLogs"
Task integer 1
1
id integer 1
66
Channel string 1
MSExchange Management
EventCode integer 1
1
EventData_Xml string 1
New-MailboxExportRequest,-Mailbox "snapattack" -Name "03a5108c89f64c4993c8faf52d4322ca" -ContentFilter "Subject -eq '03a5108c89f64c4993c8faf52d4322ca'" -FilePath "\127.0.0.1\c$\inetpub\wwwroot\aspnet_client\fbxvgf.aspx",snapattack.local/Users/snapattack,S-1-5-21-2783883905-3325768869-1243185101-500,S-1-5-21-2783883905-3325768869-1243185101-500,Remote-PowerShell-Unknown,20280 w3wp#MSExchangePowerShellAppPool,,19,00:00:00.3437022,View Entire Forest: 'False', Default Scope: 'snapattack.local', Configuration Domain Controller: 'DC01.snapattack.local', Preferred Global Catalog: 'DC01.snapattack.local', Preferred Domain Controllers: '{ DC01.snapattack.local }',,,,,,,False,,0 objects execution has been proxied to remote server.,,,1,ActivityId: 72e61d11-0b45-4821-90a2-08848e150425,ServicePlan:;IsAdmin:True;,,en-US    
EventRecordID integer 1
66
Keywords string 1
0x80000000000000
Level integer 1
4
Qualifiers string 1
"16384"
RecordNumber integer 1
66
SigmaEventCode integer 1
1
SystemTime string 1
'2022-05-03 18:36:53.520477 UTC'
System_Props_Xml string 1
        1    4    1    0x80000000000000            66    MSExchange Management    MXS01.snapattack.local        
dvc string 1
MXS01.snapattack.local
dvc_nt_host string 1
MXS01_ec25d050-3a58-4db1-a8f0-0b397e2cf39a
event_id integer 1
66
sigma_product string 1
windows
sigma_service string 1
msexchange-management
signature_id integer 1
1
timeendpos integer 1
432
timestartpos integer 1
402
vendor_product string 1
Microsoft Windows

powershell

Field Data Type Event IDs Example
Computer string 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 8198, 12039, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508
training1
EventID integer 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 8198, 12039, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508
8197
FileName string 24577, 24578, 24595, 24596, 24597, 24598, 24599
Name string 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 24577, 32784, 40961, 40962, 53251, 53504
"Microsoft-Windows-PowerShell"
Path string 0, 1, 4, 4
C:\Users\bob\desktop\capattack\modules\stop.ps1
ScriptBlockText string 0, 1, 4, 4
prompt
Task integer 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504
4
Task string 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8197, 8198, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508
id integer 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 24577, 32784, 40961, 40962, 53504
68147
ActivityID string 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 24577, 32784, 40961, 40962, 53504
"F0414E1E-7305-0002-9755-41F00573D801"
Channel string 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 8198, 12039, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508
Microsoft-Windows-PowerShell/Operational
ContextInfo string 4100, 4101, 4102, 4103
Severity = Warning
Host Name = ConsoleHost
Host Version = 5.1.22000.653
Host ID = 541d5dcc-3581-44f9-be3f-c72032a1a0d0
Host Application = powershell -WindowStyle Hidden -exec bypass
Engine Version = 5.1.22000.653
Runspace ID = c93372c9-8497-4ada-b4a0-8e7f67b2d07e
Pipeline ID = 280
Command Name = Invoke-WebRequest
Command Type = Cmdlet
Script Name =
Command Path =
Sequence Number = 4995
User = WINDOWSVICTIM\User
Connected User =
Shell ID = Microsoft.PowerShell
CurrentLine string 24595, 24596, 24597, 24598, 24599
ErrorCode string 2, 3, 4, 7, 8
ErrorMessage string 2, 3, 4, 7, 8
An unknown element "" was received. This can happen if the remote process closed or ended abnormally.
EventCode integer 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 24577, 32784, 40961, 40962, 53504
8197
EventData_Xml string 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8197, 32784, 53504
Opened
EventRecordID integer 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 24577, 32784, 40961, 40962, 53504
68147
Guid string 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 24577, 32784, 40961, 40962, 53504
"A0C1853B-5C40-4B15-8766-3CF1C58F985A"
InnerException string 1, 2, 3, 5, 5
InstanceId string 1, 4, 8, 9
0aacaf17-f104-4cde-8fab-27831ef15a2e
Keywords string 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 8198, 12039, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508
0x8000000000000020
Level integer 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 8198, 12039, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508
5
MaxRunspaces string 1, 4, 8, 9
Message string 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8197, 8198, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508
MessageNumber string 0, 1, 4, 4
MessageTotal string 0, 1, 4, 4
MinRunspaces string 1, 4, 8, 9
Opcode integer 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504
20
Opcode string 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8197, 8198, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508
Payload string 4100, 4101, 4102, 4103
PackageManagement: A package is installed.
PipelineId string 2, 3, 4, 7, 8
00000000-0000-0000-0000-000000000000
ProcessID string 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 8198, 12039, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508
"9868"
ProcessId integer 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504
9868
ProviderGUID string 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8197, 8198, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508
ProviderName string 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8197, 8198, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508
Qualifiers string 0, 1, 3, 4
RecordNumber integer 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 24577, 32784, 40961, 40962, 53504
68147
RelatedActivityID string 4100, 4101, 4103, 4104, 24577, 40961, 40962, 53504
RunspaceId string 4105, 4106
1aa6385f-8a7d-4de1-ba84-96a62662dc3a
ScheduledJobDefName string 53249, 53250
ScriptBlockId string 4104, 4105, 4106
576808c7-2ec5-4ebc-8c72-0b7608c807a7
SessionId string 4100, 4101, 4103, 4104, 24577, 32784, 40961, 40962, 53504
00000000-0000-0000-0000-000000000000
SigmaEventCode integer 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504
8197
StackTrace string 32784, 53251
at System.Management.Automation.Remoting.Server.OutOfProcessMediatorBase.Start(String initialCommand, String configurationName)
StartTime string 2, 3, 4, 5, 9
State string 0, 2, 3, 5, 5
StopTime string 0, 2, 3, 5, 5
SystemTime string 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 24577, 32784, 40961, 40962, 53504
'2022-07-28 14:45:54.626336 UTC'
System_Props_Xml string 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504
        8197    1    5    1    10    0x0            68162                    Microsoft-Windows-PowerShell/Operational    EC2AMAZ-NNKUICG        
ThreadID string 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 8198, 12039, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508
"6032"
UserData string 4100, 4101, 4102, 4103
Package=AADInternals, Version=0.6.8, Provider=PowerShellGet, Source=PSGallery, Status=Installed, DestinationPath=
UserID string 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 8198, 12039, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508
"S-1-5-21-582766833-432816504-4207985818-1009"
Version integer 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 24577, 32784, 40961, 40962, 53504
1
dvc string 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 24577, 32784, 40961, 40962, 53504
training1
dvc_nt_host string 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504
training1_a6b51cc8-8b81-4d7e-a2c9-90e7ef573946
event_id integer 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504
68147
meta string 4103, 4104
param1 integer 0, 3, 4, 5, 5
9868
param1 string 8193, 8197, 8198, 32777, 53504, 53505, 53506, 53507, 53508
Opened
param2 string 8198, 32777, 53504, 53505, 53506, 53507, 53508
DefaultAppDomain
param3 string 8198, 32777, 53506, 53507, 53508
sigma_product string 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504
windows
sigma_service string 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504
powershell
signature_id integer 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504
8197
timeendpos integer 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504
516
timestartpos integer 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504
486
user_id string 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504
"S-1-5-21-582766833-432816504-4207985818-1009"
vendor_product string 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504
Microsoft Windows

powershell-classic

Field Data Type Event IDs Example
Computer string 300, 400, 403, 600, 800
windowsvictim
EventID integer 300, 400, 403, 600, 800
800
Name string 300, 400, 403, 600, 800
"PowerShell"
Task integer 300, 400, 403, 600, 800
8
id integer 300, 400, 403, 600, 800
75963
name string 0, 0, 6
A process was assigned a primary token
Channel string 300, 400, 403, 600, 800
Windows PowerShell
EventCode integer 300, 400, 403, 600, 800
800
EventData_Xml string 300, 400, 403, 600, 800
Stopped,Available,  NewEngineState=Stopped
PreviousEngineState=Available

SequenceNumber=15

HostName=ConsoleHost
HostVersion=5.1.17763.2268
HostId=0081ab7c-fe58-4e1a-863c-3cf3182de39c
HostApplication=powershell.exe
EngineVersion=5.1.17763.2268
RunspaceId=31e8c8db-2b2b-46e4-af37-46642b996c32
PipelineId=
CommandName=
CommandType=
ScriptName=
CommandPath=
CommandLine=
EventRecordID integer 300, 400, 403, 600, 800
75963
Keywords string 300, 400, 403, 600, 800
0x80000000000000
Level integer 300, 400, 403, 600, 800
4
Opcode integer 400, 403, 600, 800
0
ProcessID string 400, 403, 600, 800
"0"
ProcessId integer 400, 403, 600, 800
0
Qualifiers string 300, 400, 403, 600, 800
"0"
RecordNumber integer 300, 400, 403, 600, 800
75963
SigmaEventCode integer 400, 403, 600, 800
800
SigmaEventCode string 0, 0, 3
N/A
SystemTime string 300, 400, 403, 600, 800
'2022-07-15 12:06:22.041268 UTC'
System_Props_Xml string 300, 400, 403, 600, 800
        800    4    8    0x80000000000000            75856    Windows PowerShell    EC2AMAZ-1CL0VOR        
ThreadID string 400, 403, 600, 800
"0"
Version integer 400, 403, 600, 800
0
dvc string 300, 400, 403, 600, 800
windowsvictim
dvc_nt_host string 300, 400, 403, 600, 800
windowsvictim_32d8f699-9b6a-46e8-8381-9f403508b83f
event_id integer 300, 400, 403, 600, 800
75963
sigma_product string 300, 400, 403, 600, 800
windows
sigma_service string 300, 400, 403, 600, 800
powershell-classic
signature string 0, 0, 6
A process was assigned a primary token
signature_id integer 300, 400, 403, 600, 800
800
subject string 0, 0, 6
A process was assigned a primary token
timeendpos integer 300, 400, 403, 600, 800
465
timestartpos integer 300, 400, 403, 600, 800
435
vendor_product string 300, 400, 403, 600, 800
Microsoft Windows

printservice-admin

Field Data Type Event IDs Example
EventID integer 808, 823
823
Name string 808, 823
Microsoft-Windows-PrintService
EventCode integer 808, 823
823
Guid string 808, 823
747EF6FD-E535-4D16-B510-42C90F6873A1
ProcessID integer 808, 823
2612
ProcessId integer 808, 823
2612
SigmaEventCode integer 808, 823
823
SystemTime string 808, 823
'2022-07-20 16:47:56.388245 UTC'
ThreadID integer 808, 823
2648
UserID string 808, 823
S-1-5-21-2414553406-2212388514-3030099854-1009
sigma_product string 808, 823
windows
sigma_service string 808, 823
printservice-admin
timeendpos integer 808, 823
519
timestartpos integer 808, 823
489
xmlns string 808, 823
http://schemas.microsoft.com/win/2004/08/events/event

security

Field Data Type Event IDs Description Example
Application string 5031, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159 Full path and the name of the executable for the process.
\device\harddiskvolume4\windows\system32\svchost.exe
CommandLine string 4688
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Computer string 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4949, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5478, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424, 8222
windowsvictim
EventID integer 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222
8222
EventID string 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424
FileName string 4664, 5051 the name of a file or folder that the virtualized file name refers to.
Name string 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222
"VSSAudit"
Object string 4934, 4937
ParentProcessName string 4688
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
ProcessName string 4615, 4616, 4624, 4625, 4648, 4649, 4656, 4657, 4658, 4660, 4661, 4663, 4670, 4673, 4674, 4689, 4696, 4703, 4818, 4904, 4905, 4907, 4911, 4913, 4985, 5039, 5051, 5712, 6417, 6418 full path and the name of the executable for the process.
C:\Windows\System32\wevtutil.exe
Service string 3, 4, 6, 7
-
Task integer 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222
3
Task string 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424
Type integer 3, 5, 7, 9
0
Type string 5148, 5149, 5379
action string 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416
success
app string 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222
win:unknown
id integer 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222
843214
name string 1102, 4611, 4624, 4625, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4800, 4801, 4904, 4905, 4907, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890
Windows Firewall settings were restored to the default values
process string 4624, 4625, 4648, 4656, 4657, 4658, 4660, 4661, 4663, 4670, 4673, 4674, 4688, 4689, 4696, 4703, 4904, 4905, 4907, 4911, 4985
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
process_name string 4624, 4625, 4648, 4656, 4657, 4658, 4660, 4661, 4663, 4670, 4673, 4674, 4688, 4689, 4703, 4904, 4905, 4907, 4911, 4985
wevtutil.exe
product string 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222
Windows
service string 4673, 4697, 4768, 4769, 5478
krbtgt
status string 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416
success
user integer 4624, 4627, 4634, 4648, 4688, 4696, 4703, 4720, 4726, 4728, 4729, 4732
user string 4624, 4625, 4627, 4634, 4648, 4673, 4674, 4688, 4689, 4697, 4703, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4798, 4799, 4800, 4801
user
AccessGranted string 1, 4, 7, 7
SeServiceLogonRight
AccessList string 4656, 4659, 4661, 4662, 4663, 4691, 5140, 5145 the list of access rights which were requested by user_sid. These access rights depend on Object Type.
%%4484
AccessMask string 4656, 4659, 4661, 4662, 4663, 4674, 4691, 5140, 5145 the sum of hexadecimal values of requested access rights. See "Table 13. File access codes."
983103
AccessReason string 4656, 4661, 4818, 5145 the list of access check results.
-
AccessRemoved string 1, 4, 7, 8
SeServiceLogonRight
AccountDomain string 4778, 4779, 4825 SID of account that requested the "invoke screensaver" operation
EC2AMAZ-1CL0VOR
AccountExpires string 4720, 4738, 4741, 4742 the date when the account expires. If the value of accountExpiresattribute of computer object was changed, you will see the new value here. For computer objects, it is optional, and typically is not set. You can change this attribute by using Active Directory Users and Computers, or through a script, for example.
%%1794
AccountName string 4778, 4779, 4822, 4823, 4825 the name of the account that requested the "invoke screensaver" operation.
user
AccountSessionIdentifier string 6272, 6273, 6274, 6275, 6276, 6277, 6278
Action string 5441, 5447
%%16390
ActiveProfile string 4, 5, 6, 9
ActivityID string 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4662, 4670, 4672, 4673, 4674, 4688, 4689, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4946, 4947, 4948, 4949, 4950, 4957, 5058, 5059, 5061, 5379, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890
"DB372A64-1DDF-0000-34E1-C3F65585D801"
AddedCAPs string 1, 4, 8, 9
AdditionalInfo string 2, 4, 6, 6
Local Read (ExecQuery)
AdditionalInfo2 string 2, 4, 6, 6
root\cimv2\security\MicrosoftVolumeEncryption:__Win32Provider.Name="Win32_EncryptableVolumeProvider"
AdvancedOptions string 2, 4, 6, 8
AhAuthType string 1, 4, 5, 5
AlgorithmName string 5057, 5058, 5059, 5060, 5061 the name of cryptographic algorithm through which the key was used or accessed.
UNKNOWN
AllowedToDelegateTo string 4720, 4738, 4741, 4742 the list of SPNs to which this account can present delegated credentials. Can be changed using Active Directory Users and Computers management console in Delegation tab of computer account. If the SPNs list on Delegation tab of a computer account was changed, you will see the new SPNs list in AllowedToDelegateTo field (note that you will see the new list instead of changes) of this event.
-
AppCorrelationID string 5136, 5137, 5138, 5139, 5141, 5169, 5170 always has "-" value. Not in use.
AppInstance string 4665, 4666, 4667, 4668 (Application Information) Application Instance ID
AppName string 4665, 4666, 4667, 4668 (Application Information) Application Name
AsIsCAPs string 1, 4, 8, 9
Attribute string 3, 4, 4, 9
AttributeLDAPDisplayName string 5136, 5169, 5170 the object attribute that was modified.
AttributeSyntaxOID string 5136, 5169, 5170 The syntax for an attribute defines the storage representation, byte ordering, and matching rules for comparisons of property types.
AttributeValue string 5136, 5169, 5170 the value which was added or deleted, depending on the Operation\Type field.
Attributes string 4874, 4886, 4887, 4888, 4889
AuditFilter string 4, 5, 8, 8
AuditPolicyChanges string 4719, 4912 changes which were made for the subcategory.
%%8448, %%8450
AuditSourceName string 4904, 4905 the name of unregistered security event source. You can see all registered security event source names in this registry path: "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security".
VSSAudit
AuditStatusCode string 4935, 4936 there is no detailed information about this field in this document.
AuditsDiscarded string 1, 2, 4, 6
AuthenticationLevel string 1, 2, 5, 7
AuthenticationPackage string 4, 4, 6, 9
AuthenticationPackageName string 4610, 4624, 4625 The name of the authentication package which was used for the logon authentication process. Default packages loaded on LSA startup are located in "HKLM\SYSTEM\CurrentControlSet\Control\Lsa\OSConfig" registry key.
Negotiate
AuthenticationProvider string 6272, 6273, 6274, 6275, 6276, 6277, 6278
AuthenticationServer string 6272, 6273, 6274, 6275, 6276, 6277, 6278
AuthenticationService string 1, 2, 5, 7
AuthenticationSetId string 5040, 5041, 5042
AuthenticationSetName string 5040, 5041, 5042
AuthenticationType string 6272, 6273, 6274, 6275, 6276, 6277, 6278
BackupFileName string 5376, 5377
BackupPath string 0, 1, 1, 5
BackupType string 4, 6, 7, 8
BaseCRLHash string 1, 2, 5, 7
BaseCRLNumber string 1, 2, 5, 7
BaseCRLThisUpdate string 1, 2, 5, 7
CACertificateHash string 4880, 4881
CAConfigurationId string 5122, 5126, 5127
CAName string 1, 2, 5, 5
CAPublicKeyHash string 4880, 4881
CRLNumber string 2, 4, 7, 8
CalledStationID string 6272, 6273, 6274, 6275, 6276, 6277, 6278
CallerDomainName string 1, 4, 6, 7
CallerLogonId string 1, 4, 6, 7
CallerProcessId string 4798, 4799 hexadecimal Process ID of the process that enumerated the members of the group. Process ID (PID) is a number used by the operating system to uniquely identify an active process. You can also correlate this process ID with a process ID in other events, for example, "4688: A new process has been created" Process Information\New Process ID.
0x73c
CallerProcessName string 4798, 4799, 5050 full path and the name of the executable for the process.
C:\Windows\System32\ntdsutil.exe
CallerUserName string 1, 4, 6, 7
CallerUserSid string 1, 4, 6, 7
Caller_Domain string 4611, 4624, 4625, 4627, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4798, 4799, 4904, 4905, 4907, 4911, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5379, 5381, 6416
training1
Caller_User_Name string 1102, 4611, 4624, 4625, 4627, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4798, 4799, 4904, 4905, 4907, 4911, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5379, 5381, 5888, 5890, 6416
user
CallingStationID string 6272, 6273, 6274, 6275, 6276, 6277, 6278
CalloutId integer 4, 4, 5, 6
290
CalloutId string 5440, 5446
CalloutKey string 5440, 5441, 5446, 5447
31114833-2891-4EDD-A8EC-2FF8549AA491
CalloutName string 5440, 5441, 5446, 5447
windefend_datagram_v4
CalloutType string 5440, 5446
%%16388
Categories string 6406, 6408
CategoryId string 4719, 4912 the name of auditing category which subcategory state was changed.
%%8273
CategoryString string 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738
Account Management
CertIssuerName string 4768, 4771, 4820, 4824 the name of the Certification Authority that issued the smart card certificate. Populated in Issued by field in certificate.
CertSerialNumber string 4768, 4771, 4820, 4824 smart card certificate's serial number. Can be found in Serial number field in the certificate.
CertThumbprint string 4768, 4771, 4820, 4824 smart card certificate's thumbprint. Can be found in Thumbprint field in the certificate.
Certificate string 4, 4, 8, 8
CertificateDatabaseHash string 4880, 4881
CertificateHash string 4, 5, 8, 9
CertificateSerialNumber string 0, 4, 7, 8
ChangeType string 5446, 5447, 5448, 5449, 5450
%%16385
Channel string 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4949, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5478, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424, 8222
Security
CipherType string 1, 4, 5, 5
ClassId string 6416, 6419, 6420, 6421, 6422, 6423, 6424 "Class Guid" attribute of device.
1ED2BBF9-11F0-4084-B21F-AD83A8E6DCDC
ClassName string 6416, 6419, 6420, 6421, 6422, 6423, 6424 "Class" attribute of device.
Monitor
ClientAddress string 4778, 4779, 4825 IP address of the computer from which the session was disconnected
10.0.4.126
ClientCreationTime string 5058, 5059
2022-06-15 13:07:13.665388 UTC
ClientDomain string 4665, 4666, 4667, 4668 subject's domain or computer name.
ClientIPAddress string 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6400, 6401, 6402
ClientLogonId string 4665, 4666, 4667, 4668 (Subject) Client Context ID
ClientName string 4665, 4666, 4667, 4668, 4778, 4779, 6272, 6273, 6274, 6275, 6276, 6277, 6278 machine name from which the session was disconnected. Has "Unknown"value for console session.
Guacamole RDP
ClientProcessId integer 4697, 4698, 4699, 4700, 4701, 4702, 5058, 5059, 5379, 5381
484
ClientProcessId string 4697, 4698, 4699, 4700, 4701, 4702, 5058, 5059, 5376, 5377, 5379, 5380, 5381, 5382
ClientProcessStartKey string 4697, 4698, 4699, 4700, 4701, 4702
ClientUserName string 4774, 4775, 4777 the name of the account that had its credentials validated by the Authentication Package. Can be user name, computer account name or well-known security principal account name.
CollisionTargetName string 4, 4, 6, 8
CollisionTargetType string 4, 4, 6, 8
CompatibleIds string 6416, 6419, 6420, 6421, 6422, 6423, 6424 "Compatible Ids" attribute of device.
*PNP09FF
ComputerAccountChange string 2, 4, 4, 7
ComputerName string 1, 4, 6, 8
Conditions string 5441, 5447
Condition ID:  {d78e1e87-8644-4ea5-9437-d809ecefc971}
Match value: Equal to
Condition value:
00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 .d.e.v.i.c.e..
00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.
00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2..
00000030 70 00 72 00 6f 00 67 00-72 00 61 00 6d 00 20 00 p.r.o.g.r.a.m. .
00000040 66 00 69 00 6c 00 65 00-73 00 20 00 28 00 78 00 f.i.l.e.s. .(.x.
00000050 38 00 36 00 29 00 5c 00-6d 00 69 00 63 00 72 00 8.6.)..m.i.c.r.
00000060 6f 00 73 00 6f 00 66 00-74 00 5c 00 65 00 64 00 o.s.o.f.t..e.d.
00000070 67 00 65 00 5c 00 61 00-70 00 70 00 6c 00 69 00 g.e..a.p.p.l.i.
00000080 63 00 61 00 74 00 69 00-6f 00 6e 00 5c 00 6d 00 c.a.t.i.o.n..m.
00000090 73 00 65 00 64 00 67 00-65 00 2e 00 65 00 78 00 s.e.d.g.e...e.x.
000000a0 65 00 00 00 e...


Condition ID: {0c1ba1af-5765-453f-af22-a8f791ac775b}
Match value: Equal to
Condition value: 0x14e9

Condition ID: {3971ef2b-623e-4f9a-8cb1-6e79b806b9a7}
Match value: Equal to
Condition value: 0x11
ConfigAccessPolicy string 2, 4, 6, 8
ConfiguredNames string 1, 5, 6, 8
ConnectionSecurityRuleId string 5043, 5044, 5045
ConnectionSecurityRuleName string 5043, 5044, 5045
ContextName string 5064, 5065, 5066, 5067, 5068, 5069, 5070
Count string 0, 4, 5, 6
CountOfCredentialsReturned integer 5379, 5381
0
CountOfCredentialsReturned string 5379, 5380, 5381
CrashOnAuditFailValue string 4621, 4906 contains new value of CrashOnAuditFail flag.
CredType string 3, 5, 7, 8
CryptoAlgorithms string 4694, 4695 Cryptographic Algorithms of the protection
AES-256 , SHA2-512
CryptographicSetId string 5046, 5047, 5048
CryptographicSetName string 5046, 5047, 5048
CurrentProfile string 1, 5, 5, 7
%%14644
DCDNSName string 4898, 4899, 4900
DHGroup string 4650, 4651, 4979, 4980, 4981, 4982
DSName string 5136, 5137, 5138, 5139, 5141, 5169, 5170 the name of an Active Directory domain, where the object was deleted.
DSType string 5136, 5137, 5138, 5139, 5141, 5169, 5170 has "Active Directory Domain Services" value for this event.
DataDescription string 4694, 4695 -
827ed4bc-54ff-4032-b410-02f985a5c118
DeletedCAPs string 1, 4, 8, 9
DeltaCRLHash string 1, 2, 5, 7
DeltaCRLIndicator string 1, 2, 5, 7
DeltaCRLNumber string 1, 2, 5, 7
DeltaCRLThisUpdate string 1, 2, 5, 7
DestAddress string 5146, 5147, 5150, 5151, 5152, 5153, 5156, 5157 IP address from which connection was received or initiated.
239.255.255.250
DestPort integer 5152, 5156, 5157 Port number which was used from remote machine to initiate connection.
5355
DestPort string 5152, 5153, 5156, 5157 Port number which was used from remote machine to initiate connection.
DestinationDRA string 4928, 4929, 4930, 4931, 4932, 4933, 4937 destination directory replication agent distinguished name.
DestinationvSwitchPort string 5146, 5147
DeviceClaims string 2, 4, 6, 6
DeviceDescription string 6416, 6419, 6420, 6421, 6422, 6423, 6424 "Device description" attribute of device.
Generic Non-PnP Monitor
DeviceId string 6416, 6419, 6420, 6421, 6422, 6423, 6424 "Device instance path" attribute of device.
DISPLAY\Default_Monitor\1&1f0c3c2f&0&UID256
DeviceName string 4820, 4821, 4822, 4823
Direction string 5146, 5147, 5150, 5151, 5152, 5153, 5156, 5157 Direction of blocked connection.
%%14593
DisableIntegrityChecks string 2, 4, 6, 8
DisabledPrivilegeList string 0, 3, 4, 7
-
DisplayName string 4720, 4738, 4741, 4742 it is a name displayed in the address book for a particular account (typically - user account). This is usually the combination of the user's first name, middle initial, and last name. For computer objects, it is optional, and typically is not set. You can change this attribute by using Active Directory Users and Computers, or through a script, for example. If the value of displayName attribute of computer object was changed, you will see the new value here.
%%1793
Disposition string 4887, 4888, 4889
DnsHostName string 4741, 4742 name of computer account as registered in DNS. If the value of dNSHostName attribute of computer object was changed, you will see the new value here.
DnsName string 4864, 4865, 4866, 4867 DNS name of the trust partner. This parameter might not be captured in the event, and in that case appears as "-".
DomainBehaviorVersion string 3, 4, 7, 9
DomainName string 4706, 4707, 4716, 4739 the name of domain for which policy changes were made.
DomainPolicyChanged string 3, 4, 7, 9
DomainSid string 4706, 4707, 4716, 4739, 4864, 4865, 4866, 4867 SID of the trust partner. This parameter might not be captured in the event, and in that case appears as "NULL SID".
Dummy string 3, 4, 7, 8
-
Duration string 1, 4, 6, 8
EAPErrorCode string 2, 3, 5, 6
EAPReasonCode string 2, 3, 5, 6
EAPType string 6272, 6273, 6274, 6275, 6276, 6277, 6278
EMAuthMethod string 4979, 4981, 4984
EMImpersonationState string 4979, 4980, 4981, 4982, 4983, 4984
EapRootCauseString string 2, 3, 5, 6
EfsPolicyChange string 1, 4, 4, 7
ElevatedToken string 2, 4, 4, 6
%%1842
EnableRestrictedPermissions string 0, 4, 8, 9
EnabledPrivilegeList string 0, 3, 4, 7
SeAssignPrimaryTokenPrivilege
SeIncreaseQuotaPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeSystemtimePrivilege
SeBackupPrivilege
SeRestorePrivilege
SeShutdownPrivilege
SeSystemEnvironmentPrivilege
SeUndockPrivilege
SeManageVolumePrivilege
EndUSN string 3, 3, 4, 9
Entry string 1, 4, 8, 9
EntryType string 4865, 4866, 4867 the type of modified entry.
Error string 4958, 5457, 5459, 5461, 5462, 5472, 5474, 5477, 5483, 5484
ErrorCode string 1107, 1108, 5027, 5028, 5029, 5030, 5032, 5035, 5037, 5168, 5632, 5633, 6144, 6145, 6404 specific error code which shows the error which happened during Group Policy processing.
Error_Code string 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222
0xc000006d
EspAuthType string 1, 4, 5, 5
EtherType string 5146, 5147, 5150, 5151
EventCode integer 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222
8222
EventCount string 1, 4, 6, 8
EventCountTotal integer 2, 4, 6, 7
1
EventCountTotal string 4626, 4627 Total number of events in the sequence.
EventData_Xml string 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5888, 5890, 6416, 8222
S-1-5-21-582766833-432816504-4207985818-1009,EC2AMAZ-NNKUICG\user,0x0000000000000274,C:\Windows\System32\vssadmin.exe,{5d0247f2-6dbc-4295-8ba8-a779b444c3f6},{bc77a77b-e166-46aa-a3a0-9a46334b947a},{b5946137-7b9f-4925-af80-51abd60b20d5},EC2AMAZ-NNKUICG,\?\Volume{e3c0cc15-0000-0000-0000-100000000000}\,\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1    
EventId string 4618, 6405
EventIdx integer 2, 4, 6, 7
1
EventIdx string 4626, 4627 If is there is not enough space in one event to put all groups, you will see "1 of N" in this field and additional events will be generated. Typically this field has "1 of 1" value.
EventRecordID integer 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222
843214
EventSourceId string 4904, 4905 the unique hexadecimal identifier of unregistered security event source.
0x10d178
ExpirationTime string 5169, 5170
ExtendedQuarantineState string 6276, 6277, 6278
ExtensionData string 3, 4, 7, 8
ExtensionDataType string 3, 4, 7, 8
ExtensionName string 3, 4, 7, 8
ExtensionPolicyFlags string 3, 4, 7, 8
FQDN string 4698, 4699, 4700, 4701, 4702
EC2AMAZ-NNKUICG
FailureCode string 4772, 4773
FailureId string 3, 4, 6, 9
FailurePoint string 4652, 4653, 4654, 4983, 4984
FailureReason string 4625, 4652, 4653, 4654, 4692, 4694, 4695, 4983, 4984 -
0x0
FatalCode string 1, 4, 6, 8
Filter string 4, 6, 8, 9
FilterId integer 4, 4, 5, 7
68102
FilterId string 5441, 5447
FilterKey string 5441, 5447
00307222-72B1-4AEF-8A7F-62AF4B4604DF
FilterName string 5441, 5447
Microsoft Edge (mDNS-In)
FilterOrigin string 5152, 5157
Query User Default
FilterRTID integer 5152, 5154, 5156, 5157, 5158 Unique filter ID which allows application to bind the port.
70338
FilterRTID string 5146, 5147, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159 Unique filter ID which blocks the application from binding to the port.
FilterType string 5441, 5447
%%16388
Flags integer 1, 3, 5, 8
512
Flags string 4864, 4865, 4866, 4867, 5381, 5382 Forest flags flags.
FlightSigning string 2, 4, 6, 8
ForceLogoff string 3, 4, 7, 9
ForestRoot string 4864, 4865, 4866, 4867 the name of the Active Directory forest for which trusted forest information entry was modified.
ForestRootSid string 4865, 4866, 4867 the SID of the Active Directory forest for which trusted forest information entry was modified. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID cannot be resolved, you will see the source data in the event.
FullyQualifiedSubjectMachineName string 6272, 6273, 6274, 6275, 6276, 6277, 6278
FullyQualifiedSubjectUserName string 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280
FunctionName string 5066, 5067, 5068, 5069, 5070
GPOList string 6144, 6145 the list of Group Policy Objects that include "Security Settings" policies, and that were applied with errors to the computer.
GUID string 0, 4, 6, 9
Group string 4, 6, 6, 6
GroupMembership string 2, 4, 6, 7
%{S-1-5-21-2414553406-2212388514-3030099854-513}
%{S-1-1-0}
%{S-1-5-114}
%{S-1-5-32-544}
%{S-1-5-32-545}
%{S-1-5-2}
%{S-1-5-11}
%{S-1-5-15}
%{S-1-5-113}
%{S-1-5-64-10}
%{S-1-16-12288}
GroupPolicyApplied string 4, 4, 4, 9
GroupTypeChange string 4, 4, 6, 7
Group_Domain string 4728, 4729, 4732, 4733, 4799
EC2AMAZ-NNKUICG
Group_Name string 4728, 4729, 4732, 4733, 4799
Users
Guid string 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416
"{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}"
HandleId string 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4670, 4674, 4818, 4907, 4911, 4913 hexadecimal value of a handle to Object Name. This field can help you correlate this event with other events that might contain the same Handle ID, for example, "4663(S): An attempt was made to access an object." This parameter might not be captured in the event, and in that case appears as "0x0".
0xd24
HardwareIds string 6419, 6420, 6421, 6422, 6423, 6424 "Hardware Ids" attribute of device.
HasRemoteDynamicKeywordAddress string 1, 5, 5, 7
%%1826
HomeDirectory string 4720, 4738, 4741, 4742 user's home directory. If homeDrive attribute is set and specifies a drive letter, homeDirectory should be a UNC path. The path must be a network UNC of the form \Server\Share\Directory. If the value of homeDirectory attribute of computer object was changed, you will see the new value here. For computer objects, it is optional, and typically is not set. You can change this attribute by using Active Directory Users and Computers, or through a script, for example.
%%1793
HomePath string 4720, 4738, 4741, 4742 specifies the drive letter to which to map the UNC path specified by homeDirectory account's attribute. The drive letter must be specified in the form "DRIVE_LETTER:". For example - "H:". If the value of homeDrive attribute of computer object was changed, you will see the new value here. For computer objects, it is optional, and typically is not set. You can change this attribute by using Active Directory Users and Computers, or through a script, for example.
%%1793
HostedCacheName string 6403, 6404
HypervisorDebug string 2, 4, 6, 8
HypervisorLaunchType string 2, 4, 6, 8
HypervisorLoadOptions string 2, 4, 6, 8
Identity string 5382, 5632, 5633 User Principal Name (UPN) of account for which 802.1x authentication request was made.
ImpersonationLevel string 2, 4, 4, 6
%%1833
InboundSpi string 1, 4, 5, 5
InitiatorCookie string 4652, 4653
InterfaceId string 5066, 5067, 5068, 5069, 5070
InterfaceIndex integer 1, 5, 5, 7
16
InterfaceName string 3, 3, 5, 6
InterfaceType string 5150, 5151
InterfaceUuid string 1, 2, 5, 7
IntfGuid string 2, 3, 5, 6
InvalidCallName string 1, 4, 5, 6
IpAddress string 4624, 4625, 4648, 4768, 4769, 4770, 4771, 4772, 4773, 4820, 4821, 4824, 5140, 5145 source IP address from which access was performed.
::1
IpAddresses string 1, 5, 6, 8
IpPort integer 4768, 4769, 5140, 5145 source TCP or UDP port which was used from remote or local machine to request the access.
49901
IpPort string 4624, 4625, 4648, 4768, 4769, 4770, 4771, 4772, 4773, 4820, 4821, 4824, 5140, 5145 source TCP or UDP port which was used from remote or local machine to request the access.
-
IpProtocol string 5451, 5452
IpSecSecurityAssociationId string 0, 4, 5, 9
IpSecSecurityAssociationName string 0, 4, 5, 9
IsBaseCRL string 2, 4, 7, 8
IsLoopback string 1, 5, 5, 7
%%1826
KRAHashes string 3, 4, 8, 9
KerberosPolicyChange string 1, 3, 4, 7
KernelDebug string 2, 4, 6, 8
KeyContainer string 2, 4, 7, 8
KeyFilePath string 0, 5, 5, 8
C:\ProgramData\Microsoft\Crypto\SystemKeys\c56b3f40b196d4f8d43940688b5b8765_4d6cbdb8-0892-45ee-9d0d-f2e8b7a5fa78
KeyLength string 4624, 4625 the length of NTLM Session Security key. Typically it has 128 bit or 56 bit length. This parameter is always 0 if "Authentication Package" = "Kerberos", because it is not applicable for Kerberos protocol. This field will also have "0" value if Kerberos was negotiated using Negotiate authentication package.
KeyModName string 4650, 4651, 4652, 4653, 4654, 4655, 4976, 4977, 4978
KeyName string 5058, 5059, 5060, 5061 the name of the key (key container) with which operation was performed.
te-8811d5ab-8de8-4b50-a578-845af8f06794
KeyType string 5058, 5059, 5060, 5061 can have one of the following values: "User key." - user's cryptographic key. "Machine key." - machine's cryptographic key.
%%2500
KeyingModuleName string 1, 4, 5, 5
Keywords string 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4949, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5478, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424, 8222
0x80a0000000000000
LayerId integer 5446, 5447
46
LayerId string 5440, 5441, 5446, 5447
LayerKey string 5440, 5441, 5446, 5447
A3B42C97-9F04-4672-B87E-CEE9C483257F
LayerName string 5146, 5147, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5440, 5441, 5446, 5447 Application Layer Enforcement layer name.
ALE Receive/Accept v6 Layer
LayerRTID integer 5152, 5154, 5156, 5157, 5158 Windows Filtering Platform layer identifier.
48
LayerRTID string 5146, 5147, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159 Windows Filtering Platform layer identifier.
Level integer 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4949, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5478, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424, 8222
4
LifetimeKilobytes string 1, 4, 5, 5
LifetimePackets string 1, 4, 5, 5
LifetimeSeconds string 1, 4, 5, 5
LinkName string 4, 4, 6, 6
LmPackageName string 4624, 4625 The name of the LAN Manager sub-package (NTLM-family protocol name) that was used during logon. Possible values are: NTLM V1, NTLM V2, LM. Only populated if Authentication Package = NTLM.
-
LoadOptions string 2, 4, 6, 8
LocalAddress string 4650, 4651, 4652, 4653, 4654, 4655, 4976, 4977, 4978, 4979, 4980, 4981, 4983, 4984, 5451, 5452
LocalAddressMask string 4654, 5451, 5452
LocalEMCertHash string 4980, 4982, 4983
LocalEMIssuingCA string 4980, 4982, 4983
LocalEMPrincipalName string 4979, 4980, 4981, 4982, 4983, 4984
LocalEMRootCA string 4980, 4982, 4983
LocalKeyModPort string 4650, 4651, 4652, 4653, 4979, 4980, 4981, 4982, 4983, 4984
LocalMMCertHash string 4651, 4652, 4981, 4982
LocalMMIssuingCA string 4651, 4652, 4981, 4982
LocalMMPrincipalName string 4650, 4651, 4652, 4653, 4979, 4980, 4981, 4982
LocalMMRootCA string 4651, 4652, 4981, 4982
LocalMac string 2, 3, 5, 6
LocalPort string 4654, 5451, 5452
LocalTunnelEndpoint string 4654, 5451, 5452
LocationInformation string 6416, 6419, 6420, 6421, 6422, 6423, 6424 "Location information" attribute of device.
-
LockoutDuration string 3, 4, 7, 9
LockoutObservationWindow string 3, 4, 7, 9
LockoutThreshold string 3, 4, 7, 9
LogDroppedPacketsEnabled string 4, 4, 4, 9
LogFileCleared_Xml string 0, 1, 1, 2
S-1-5-21-2158604247-1726342757-1935066190-500      doadmin      DOAZLAB      0xb82dc
LogSuccessfulConnectionsEnabled string 4, 4, 4, 9
LoggingResult string 6272, 6273
LogonGuid string 4624, 4648, 4769, 4821, 4964 a GUID that can help you correlate this event with another event that can contain the same Logon GUID, "4769(S, F): A Kerberos service ticket was requested event on a domain controller.
6D906345-171E-BA8F-34F0-A0F6E60FC960
LogonHours string 4720, 4738, 4741, 4742 hours that the account is allowed to logon to the domain. If the value of logonHours attribute of computer object was changed, you will see the new value here. For computer objects, it is optional, and typically is not set. You can change this attribute by using Active Directory Users and Computers, or through a script, for example.
%%1797
LogonID string 4778, 4779, 4825 hexadecimal value that can help you correlate this event with recent events that might contain the same Logon ID
0x9fb6c3
LogonProcessName string 4611, 4624, 4625, 4649 the name of the trusted logon process that was used for the logon attempt. See event "4611: A trusted logon process has been registered with the Local Security Authority" description for more information.
UserManager
LogonType integer 4624, 4625, 4627, 4634 the type of logon which was performed.
3
LogonType string 4624, 4625, 4626, 4627, 4634 the type of logon which was performed.
Logon_ID integer 5888, 5890
1207182
Logon_ID string 4611, 4624, 4625, 4627, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4798, 4799, 4904, 4905, 4907, 4911, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5379, 5381, 6416
0xcedae
Logon_Type integer 4624, 4625, 4627, 4634
3
MMAuthMethod string 4650, 4651, 4652, 4653, 4979, 4980
MMCipherAlg string 4650, 4651, 4979, 4980, 4981, 4982
MMFilterID string 4650, 4651, 4652, 4653, 4979, 4980, 4981, 4982
MMImpersonationState string 4650, 4651, 4652, 4653, 4979, 4980, 4981, 4982
MMIntegrityAlg string 4650, 4651, 4979, 4980, 4981, 4982
MMLifetime string 4650, 4651, 4979, 4980, 4981, 4982
MMSAID string 4650, 4651, 4654, 4655, 4979, 4980, 4981, 4982
MachineAccountQuota string 3, 4, 7, 9
MachineInventory string 6272, 6273, 6274, 6275, 6276, 6277, 6278
MainModeSaId string 1, 4, 5, 5
MandatoryLabel string 4688
S-1-16-12288
MappedName string 4, 4, 7, 7
MappingBy string 4774, 4775 The name of Authentication Package which was used for credential validation.
MasterKeyId string 4692, 4693, 4694, 4695 -
Edge
MaxPasswordAge string 3, 4, 7, 9
MediaType string 5150, 5151
MemberName string 4728, 4729, 4732, 4733, 4746, 4747, 4751, 4752, 4756, 4757, 4761, 4762, 4785, 4786, 4787, 4788 distinguished name of account that was removed from the group. For example: "CN=Auditor,CN=Users,DC=contoso,DC=local". For some well-known security principals, such as LOCAL SERVICE or ANONYMOUS LOGON, the value of this field is "-".
-
MemberSid string 4728, 4729, 4732, 4733, 4746, 4747, 4751, 4752, 4756, 4757, 4761, 4762, 4785, 4786, 4787, 4788 SID of account that was removed from the group. Event Viewer automatically tries to resolve SIDs and show the group name. If the SID cannot be resolved, you will see the source data in the event.
S-1-5-21-582766833-432816504-4207985818-1010
MembershipExpirationTime string 4728, 4732, 4746, 4751, 4756, 4761, 4785
Message string 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424
MessageID string 4, 4, 5, 6
MinPasswordAge string 3, 4, 7, 9
MinPasswordLength string 3, 4, 7, 9
MixedDomainMode string 3, 4, 7, 9
Mode string 4654, 5451
ModifiedCAPs string 1, 4, 8, 9
ModifiedObjectProperties string 5, 8, 8, 8
Transaction = '1' -> '0'
Synchronization = '3' -> '0'
JustInTimeActivation = '1' -> '0'
EventTrackingEnabled = '1' -> '0'
Module string 5056, 5062
ModuleName string 0, 3, 5, 6
MulticastFlowsEnabled string 4, 4, 4, 9
NASIPv4Address string 6272, 6273, 6274, 6275, 6276, 6277, 6278
NASIPv6Address string 6272, 6273, 6274, 6275, 6276, 6277, 6278
NASIdentifier string 6272, 6273, 6274, 6275, 6276, 6277, 6278
NASPort string 6272, 6273, 6274, 6275, 6276, 6277, 6278
NASPortType string 6272, 6273, 6274, 6275, 6276, 6277, 6278
NamingContext string 4928, 4929, 4930, 4931, 4932, 4933 naming context to replicate.
NetbiosName string 4864, 4865, 4866, 4867 NetBIOS name of the trust partner. This parameter might not be captured in the event, and in that case appears as "-".
NetworkPolicyName string 6272, 6273, 6274, 6275, 6276, 6277, 6278
NewBlockedOrdinals string 4909, 4910
NewDate string 1, 4, 6, 6
NewIgnoreDefaultSettings string 0, 1, 4, 9
NewIgnoreLocalSettings string 0, 1, 4, 9
NewMaxUsers string 1, 3, 4, 5
NewObjectDN string 5138, 5139 New distinguished name of moved object.
NewProcessId string 4688
0x2260
NewProcessName string 4688
C:\Windows\System32\conhost.exe
NewRemark string 1, 3, 4, 5
NewSD string 1, 3, 4, 5
NewSd string 4670, 4715, 4817, 4907, 4911, 4913 the Security Descriptor Definition Language (SDDL) value for the new Central Policy ID (for the policy that has been applied to the object).
S:ARAI(RA;;;;;WD;("IMAGELOAD",TU,0x0,1))
NewSecurityDescriptor string 0, 0, 4, 9
NewSecuritySettings string 1, 2, 4, 5
NewShareFlags string 1, 3, 4, 5
NewSigningCertificateHash string 1, 2, 5, 6
NewState string 4, 5, 8, 9
NewTargetUserName string 1, 4, 7, 8
NewTemplateContent string 4899, 4900
NewTime string 1, 4, 6, 6
NewUacValue string 4720, 4738, 4741, 4742 specifies flags that control password, lockout, disable/enable, script, and other behavior for the user or computer account. If the value of userAccountControl attribute of computer object was changed, you will see the new value here.
0x15
NewValue string 4657, 4934, 5065, 5067, 5070, 5122, 5123 new value for changed registry key value.
%%1800
NewValueType string 4, 5, 6, 7
%%1873
NextPublish string 2, 4, 7, 8
NextPublishForBaseCRL string 1, 4, 7, 8
NextPublishForDeltaCRL string 1, 4, 7, 8
NextUpdate string 1, 4, 7, 8
Node string 1, 4, 8, 9
NotificationPackageName string 1, 4, 4, 6
ObjectClass string 5136, 5137, 5138, 5139, 5141, 5169, 5170 class of the object that was deleted.
ObjectCollectionName string 5888, 5889, 5890 the name of COM+ collection to which the new object was added.
InterfacesForComponent
ObjectDN string 5136, 5137, 5141, 5169, 5170 distinguished name of the object that was deleted.
ObjectGUID string 5136, 5137, 5138, 5139, 5141, 5169, 5170 each Active Directory object has globally unique identifier (GUID), which is a 128-bit value that is unique not only in the enterprise but also across the world.
ObjectIdentifyingProperties string 5888, 5889, 5890 object-specific fields with the names and identifiers for the new object.
ID = {D155805A-726F-4163-8879-E4AAC4F058F3}
AppPartitionID = {41E90F3E-56C1-4633-81C3-6E8BAC8BDD70}
ObjectName string 4656, 4657, 4659, 4661, 4662, 4663, 4666, 4670, 4674, 4691, 4817, 4818, 4907, 4911, 4913 full path and/or name of the object on which the Central Access Policy was changed.
root\cimv2\security\MicrosoftVolumeEncryption
ObjectPath string 0, 3, 5, 9
ObjectProperties string 5889, 5890 the list of new object's (Object Name) properties.
Name = T1218.009
ApplicationProxyServerName =
ProcessType = 2
CommandLine =
ServiceName =
RunAsUserType = 1
Identity = Interactive User
Description =
IsSystem = N
Authentication = 4
ShutdownAfter = 3
RunForever = N
Password = **
Activation = Inproc
Changeable = Y
Deleteable = Y
CreatedBy =
AccessChecksLevel = 0
ApplicationAccessChecksEnabled = 1
cCOL_SecurityDescriptor =
ObjectServer string 4656, 4658, 4659, 4660, 4661, 4662, 4663, 4670, 4673, 4674, 4817, 4818, 4819, 4907, 4911, 4913 has "Security" value for this event.
WMI
ObjectType string 4656, 4659, 4661, 4662, 4663, 4670, 4674, 4691, 4817, 4818, 4819, 4907, 4911, 4913, 5140, 5143, 5145 The type of an object that was accessed during the operation. Always "File" for this event.
WMI Namespace
ObjectValueName string 4, 5, 6, 7
ConfigXML
ObjectVirtualPath string 0, 3, 5, 9
OemInformation string 3, 4, 7, 9
OldBlockedOrdinals string 4909, 4910
OldIgnoreDefaultSettings string 0, 1, 4, 9
OldIgnoreLocalSettings string 0, 1, 4, 9
OldMaxUsers string 1, 3, 4, 5
OldObjectDN string 5138, 5139 Old distinguished name of moved object.
OldRemark string 1, 3, 4, 5
OldSD string 1, 3, 4, 5
OldSd string 4670, 4715, 4817, 4907, 4911, 4913 the Security Descriptor Definition Language (SDDL) value for the old Central Policy ID (for the policy that was formerly applied to the object).
D:(A;;GA;;;BA)(A;;GA;;;SY)
OldSecurityDescriptor string 0, 0, 4, 9
OldShareFlags string 1, 3, 4, 5
OldTargetUserName string 1, 4, 7, 8
OldTemplateContent string 4899, 4900
OldUacValue string 4720, 4738, 4741, 4742 specifies flags that control password, lockout, disable/enable, script, and other behavior for the user or computer account. This parameter contains the previous value of userAccountControlattribute of computer object.
0x15
OldValue string 4657, 5065, 5067, 5070 old value for changed registry key value.
%%1800
OldValueType string 4, 5, 6, 7
%%1873
OpCorrelationID string 5136, 5137, 5138, 5139, 5141, 5169, 5170 multiple modifications are often executed as one operation via LDAP.
Opcode integer 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416
0
Opcode string 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424
Operation string 5058, 5059, 5061, 5063, 5064, 5066, 5068, 5069 performed operation.
%%2480
OperationId string 4666, 4865, 4866, 4867 unique hexadecimal identifier of the operation. You can correlate this event with other events (4865(S): A trusted forest information entry was added, 4866(S): A trusted forest information entry was removed) using this field.
OperationMode string 4, 4, 4, 9
OperationName string 4, 6, 6, 6
OperationType string 4657, 4662, 5136, 5169, 5170 type of performed operation.
Object Access
Options string 4928, 4929, 4930, 4931, 4932, 4933, 4937 decimal value of DRS Options.
Ordinal string 1, 4, 6, 7
OriginalProfile string 1, 5, 5, 7
%%14644
OutboundSpi string 1, 4, 5, 5
Package string 3, 5, 7, 8
PackageName string 4, 6, 7, 7
MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
PackageSid string 2, 3, 5, 8
PacketsDiscarded string 1, 4, 5, 9
ParentProcessId string 4697, 4698, 4699, 4700, 4701, 4702
PasswordHistoryLength string 3, 4, 7, 9
PasswordLastSet string 4720, 4738, 4741, 4742 last time the account's password was modified. If the value of pwdLastSet attribute of computer object was changed, you will see the new value here. For example: 8/12/2015 11:41:39 AM. This value will be changed, for example, after manual computer account reset action or automatically every 30 days by default for computer objects.
%%1794
PasswordProperties string 3, 4, 7, 9
PeerMac string 2, 3, 5, 6
PeerName string 1, 4, 6, 8
PeerPrivateAddress string 1, 4, 5, 5
PercentFull string 0, 1, 1, 3
Policy string 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474
PolicyName string 4820, 4821, 4823
Position string 5066, 5068
PreAuthType integer 4, 6, 7, 8
2
PreAuthType string 4768, 4771, 4820, 4824 the code of pre-Authentication type which was used in TGT request.
PreviousDate string 1, 4, 6, 6
PreviousTime string 1, 4, 6, 6
PrimaryGroupId integer 4720, 4738 Relative Identifier (RID) of user's object primary group.
513
PrimaryGroupId string 4720, 4738, 4741, 4742 Relative Identifier (RID) of computer's object primary group.
PrivateKeyUsageCount string 4880, 4881
PrivilegeList string 4656, 4659, 4661, 4672, 4673, 4674, 4704, 4705, 4720, 4723, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4780, 4781, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4830 the list of user privileges which were used during the operation, for example, SeBackupPrivilege. This parameter might not be captured in the event, and in that case appears as "-". See full list of user privileges in "Table 8. User Privileges.".
SeTakeOwnershipPrivilege
ProcessCreationTime string 5376, 5377, 5379, 5380, 5381, 5382
2022-06-28 15:09:44.051913 UTC
ProcessID string 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4949, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5478, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424 Hexadecimal Process ID of the process that attempted to create the connection.
"760"
ProcessId integer 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416 Hexadecimal Process ID of the process which was permitted to bind to the local port.
9048
ProcessId string 4615, 4616, 4624, 4625, 4648, 4649, 4656, 4657, 4658, 4659, 4660, 4661, 4663, 4670, 4673, 4674, 4688, 4689, 4690, 4691, 4696, 4703, 4818, 4904, 4905, 4907, 4911, 4913, 4985, 5039, 5050, 5051, 5152, 5153, 5154, 5155, 5158, 5159, 5446, 5447, 5448, 5449, 5450, 5712, 6417, 6418 Hexadecimal Process ID of the process which was permitted to bind to the local port.
0x8f8
Process_Command_Line string 4688
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
ProductName string 6406, 6408
Profile string 4944, 4951, 4952, 4953 the name of the profile of the ignored rule.
ProfileChanged string 4946, 4947, 4948, 4950, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049 the name of profile in which setting was changed.
Public
ProfilePath string 4720, 4738, 4741, 4742 specifies a path to the account's profile. This value can be a null string, a local absolute path, or a UNC path. If the value of profilePath attribute of computer object was changed, you will see the new value here. For computer objects, it is optional, and typically is not set. You can change this attribute by using Active Directory Users and Computers, or through a script, for example.
%%1793
ProfileUsed string 4, 4, 5, 9
Profiles string 0, 1, 3, 5
Properties string 4661, 4662 first part is the type of access that was used. Typically has the same value as Accesses field.
---
{19195a5a-6da0-11d0-afd3-00c04fd930c9}
%%1537
%%1538
%%1539
%%1540
%%5392
%%5393
%%5394
%%5395
%%5396
%%5397
%%5398
%%5399
%%5400
{c7407360-20bf-11d0-a768-00aa006e0529}
{bf9679a4-0de6-11d0-a285-00aa003049e2}
{bf9679a5-0de6-11d0-a285-00aa003049e2}
{bf9679a6-0de6-11d0-a285-00aa003049e2}
{bf9679bb-0de6-11d0-a285-00aa003049e2}
{bf9679c2-0de6-11d0-a285-00aa003049e2}
{bf9679c3-0de6-11d0-a285-00aa003049e2}
{bf967a09-0de6-11d0-a285-00aa003049e2}
{bf967a0b-0de6-11d0-a285-00aa003049e2}
{b8119fd0-04f6-4762-ab7a-4986c76b3f9a}
{bf967a34-0de6-11d0-a285-00aa003049e2}
{bf967a33-0de6-11d0-a285-00aa003049e2}
{bf9679c5-0de6-11d0-a285-00aa003049e2}
{bf967a61-0de6-11d0-a285-00aa003049e2}
{bf967977-0de6-11d0-a285-00aa003049e2}
{bf96795e-0de6-11d0-a285-00aa003049e2}
{bf9679ea-0de6-11d0-a285-00aa003049e2}
{ab721a52-1e2f-11d0-9819-00aa0040529b}
PropertyIndex string 2, 4, 8, 9
PropertyName string 4892, 5069, 5070, 5123
PropertyType string 2, 4, 8, 9
PropertyValue string 2, 4, 8, 9
ProtectedDataFlags string 4694, 4695 -
0x0
Protocol integer 5152, 5154, 5156, 5157, 5158 Protocol number.
6
Protocol string 4654, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159 Protocol number.
ProtocolSequence string 4816, 5712
ProviderContextKey string 5443, 5449
382FC699-0C62-4D70-B30A-FBD3D01201AB
ProviderContextName string 5443, 5449
MPSSVC
ProviderContextType string 5443, 5449
%%16388
ProviderGUID string 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424
ProviderKey string 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450
DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62
ProviderName string 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424 the name of KSP through which the operation was performed.
Microsoft Software Key Storage Provider
ProviderType string 5442, 5448
%%16387
ProxyPolicyName string 6272, 6273, 6274, 6275, 6276, 6277, 6278
PuaCount string 0, 2, 4, 9
PuaPolicyId string 0, 2, 4, 9
PubID string 0, 1, 1, 8
PublishURLs string 2, 4, 7, 8
Publisher string 0, 0, 5, 5
PublisherGuid string 0, 1, 1, 7
PublisherName string 0, 1, 1, 7
QMFilterID string 4654, 4979, 4980, 4981, 4982, 4983, 4984
QMLimit string 4650, 4651, 4979, 4980, 4981, 4982
Qualifiers string 1102, 4689, 4703, 8222
"0"
QuarantineGraceTime string 2, 6, 7, 7
QuarantineHelpURL string 6276, 6277, 6278
QuarantineSessionID string 6276, 6277, 6278
QuarantineSessionIdentifier string 2, 2, 6, 7
QuarantineState string 6272, 6276, 6277, 6278
QuarantineSystemHealthResult string 6276, 6277, 6278
QuickModeFilter string 4, 5, 7, 7
QuickModeSaId string 5451, 5452
ReadOperation string 3, 5, 7, 9
%%8100
Reason string 1101, 1106, 4958, 5057, 5060, 6273, 6274, 6275
ReasonCode string 5632, 5633, 6273, 6274, 6275 hexadecimal Reason Code for wired authentication results.
ReasonForRejection string 3, 4, 5, 9
ReasonText string 5632, 5633 contains Reason Text (explanation of Reason Code) and Reason Code for wired authentication results.
RecordNumber integer 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222
843214
RecoveryKeyId string 4692, 4693 unique identifier of a recovery key.
RecoveryReason string 3, 4, 6, 9
RecoveryServer string 4692, 4693 the name (typically - DNS name) of the computer that you contacted to recover your Master Key.
RelatedActivityID string 1102, 4611, 4624, 4627, 4634, 4648, 4662, 4670, 4672, 4673, 4674, 4688, 4689, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4720, 4724, 4726, 4728, 4729, 4732
RelativeTargetName string 1, 4, 5, 5
PSEXESVC.exe
RemoteAddress string 4650, 4651, 4652, 4653, 4654, 4655, 4960, 4961, 4962, 4963, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 5451, 5452
RemoteAddressMask string 4654, 5451, 5452
RemoteAdminEnabled string 4, 4, 4, 9
RemoteEMCertHash string 4980, 4982, 4983
RemoteEMIssuingCA string 4980, 4982, 4983
RemoteEMPrincipalName string 4979, 4980, 4981, 4982, 4983, 4984
RemoteEMRootCA string 4980, 4982, 4983
RemoteEventLogging string 2, 4, 6, 8
RemoteIpAddress string 1, 2, 5, 7
RemoteKeyModPort string 4650, 4651, 4652, 4653, 4979, 4980, 4981, 4982, 4983, 4984
RemoteMMCertHash string 4651, 4652, 4981, 4982
RemoteMMIssuingCA string 4651, 4652, 4981, 4982
RemoteMMPrincipalName string 4650, 4651, 4652, 4653, 4979, 4980, 4981, 4982
RemoteMMRootCA string 4651, 4652, 4981, 4982
RemoteMachineID string 5156, 5157
S-1-0-0
RemotePort string 4654, 5451, 5452, 5712
RemotePrivateAddress string 4, 4, 5, 6
RemoteTunnelEndpoint string 4654, 5451, 5452
RemoteUserID string 5156, 5157
S-1-0-0
ReplicationEvent string 4935, 4936 there is no detailed information about this field in this document.
ReplicationStatusCode string 3, 4, 6, 9
RequestId string 4868, 4869, 4873, 4874, 4883, 4884, 4886, 4887, 4888, 4889, 4893, 4894
RequestType string 4, 4, 6, 9
Requester string 4886, 4887, 4888, 4889, 4893
Resource string 2, 3, 5, 8
ResourceAttributes string 4656, 4663
-
ResourceManager string 4, 5, 8, 9
1768FEC9-9F65-11EC-B264-0EE277C94A07
ResponderCookie string 4652, 4653
RestrictedAdminMode string 2, 4, 4, 6
-
RestrictedPermissions string 0, 4, 8, 9
RestrictedSidCount string 4656, 4661 Number of restricted SIDs in the token. Applicable to only specific Object Types.
ReturnCode integer 3, 5, 7, 9
3221226021
ReturnCode string 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5379, 5382 has "0x0" value for Success events.
0x0
RevocationReason string 0, 4, 7, 8
Role string 4650, 4651, 4652, 4653, 4654, 4666, 4979, 4980, 4981, 4982, 4983, 4984, 5451 (Access Request Information) Role
RoleSeparationEnabled string 4, 7, 8, 9
RowsDeleted string 4, 6, 8, 9
RpcCallClientLocality string 4698, 4699, 4700, 4701, 4702
RuleAttr string 4, 5, 7, 9
Local Port
RuleId string 4945, 4946, 4947, 4948, 4951, 4952, 4953, 4957, 4958 the unique identifier for not applied firewall rule.
{5C6A0A6C-7D33-4849-8164-F43696BFF0D9}
RuleName string 4945, 4946, 4947, 4948, 4951, 4952, 4953, 4957, 4958 the name of the rule which was not applied.
Usermode Font Driver Host
SPI string 4960, 4961, 4962, 4963, 4965
SSID string 2, 3, 5, 6
SamAccountName string 4720, 4727, 4731, 4735, 4737, 4738, 4741, 4742, 4744, 4745, 4749, 4750, 4754, 4755, 4759, 4760, 4783, 4784, 4790, 4791 This is a new name of changed group used to support clients and servers from previous versions of Windows (pre-Windows 2000 logon name). If the value of sAMAccountName attribute of group object was changed, you will see the new value here. For example: ServiceDesk.
threatactor
Schema string 5380, 5382
SchemaFriendlyName string 5380, 5382
Scope string 5064, 5065, 5066, 5067, 5068, 5069, 5070
ScopeName string 4, 6, 6, 6
ScriptPath string 4720, 4738, 4741, 4742 specifies the path of the account's logon script. If the value of scriptPathattribute of computer object was changed, you will see the new value here. For computer objects, it is optional, and typically is not set. You can change this attribute by using Active Directory Users and Computers, or through a script, for example.
%%1793
SearchString string 0, 3, 5, 8
SecurityDescriptor string 4898, 5071
SecurityError string 1, 4, 6, 8
SecurityPackageName string 2, 2, 4, 6
SecuritySettings string 2, 4, 8, 8
SerialNumber string 1, 2, 5, 5
ServerNames string 1, 5, 6, 8
ServerPortName string 1, 4, 5, 6
ServiceAccount string 4, 6, 7, 9
LocalSystem
ServiceFileName string 4, 6, 7, 9
%SystemRoot%\PSEXESVC.exe
ServiceName string 4697, 4768, 4769, 4770, 4771, 4772, 4773, 4820, 4821, 4824 the name of the service in the Kerberos Realm to which TGT request was sent. Typically has one of the following formats: krbtgt/DOMAIN_NETBIOS_NAME. Example: krbtgt/CONTOSO, krbtgt/DOMAIN_FULL_NAME. Example: krbtgt/CONTOSO.LOCAL
krbtgt
ServicePrincipalNames string 4741, 4742 The list of SPNs, registered for computer account. If the SPN list of a computer account changed, you will see the new SPN list in Service Principal Names field (note that you will see the new list instead of changes).
ServiceSid string 4768, 4769, 4770, 4820, 4821 SID of the account or computer object for which the TGS ticket was renewed. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID cannot be resolved, you will see the source data in the event.
S-1-5-21-989241848-306340870-1210095284-502
ServiceStartType string 4, 6, 7, 9
ServiceType string 4, 6, 7, 9
0x10
SessionID string 4932, 4933, 4934 unique identifier of replication session. Using this field you can find "4932: Synchronization of a replica of an Active Directory naming context has begun." and "4933: Synchronization of a replica of an Active Directory naming context has ended." events for the same session.
SessionId integer 4800, 4801 unique ID of unlocked session.
2
SessionId string 1102, 4611, 4624, 4627, 4634, 4648, 4662, 4670, 4672, 4673, 4674, 4688, 4689, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4720, 4724, 4726, 4728, 4729, 4732, 4800, 4801, 4802, 4803 unique ID of a session for which screen saver was dismissed. You can see the list of current session IDs using "query session" command in command prompt.
SessionName string 4778, 4779 the name of disconnected session
RDP-Tcp#1
SettingType string 0, 4, 5, 9
Enable Windows Defender Firewall
SettingValue string 0, 4, 5, 9
No
ShareLocalPath string 5140, 5142, 5143, 5144, 5145 the full system (NTFS) path for accessed share. The format is: PATH
C:\Windows
ShareName string 5140, 5142, 5143, 5144, 5145 the name of accessed network share.
\*\E$
SidFilteringEnabled string 4706, 4716 SID Filtering state for the new trust.
SidHistory string 4720, 4727, 4731, 4735, 4737, 4738, 4741, 4742, 4744, 4745, 4749, 4750, 4754, 4755, 4759, 4760, 4783, 4784, 4790, 4791 contains previous SIDs used for the object if the object was moved from another domain. Whenever an object is moved from one domain to another, a new SID is created and becomes the objectSID. The previous SID is added to the sIDHistory property. If the value of sIDHistory attribute of group object was changed, you will see the new value here.
-
SidList string 4675, 4765, 4830, 4908, 4964 the list of special group SIDs, which New Logon\Security ID is a member of.
SigmaEventCode integer 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222
8222
SiloName string 4820, 4821, 4823
SourceAddr string 4928, 4929, 4930, 4931 DNS record of computer to which the modification request was sent.
SourceAddress string 5146, 5147, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159 The local IP address of the computer running the application.
::
SourceDRA string 4928, 4929, 4930, 4931, 4932, 4933, 4937 source directory replication agent distinguished name.
SourceHandleId string 0, 4, 6, 9
0xb88
SourcePort integer 5152, 5154, 5156, 5157, 5158 Port number which application was bind.
5355
SourcePort string 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159 The port number used by the application.
SourceProcessId string 0, 4, 6, 9
0x8f8
SourceSid string 4765, 4830
SourceUserName string 4765, 4766, 4830
Source_Port integer 4768, 4769, 5140, 5145
49901
Source_Port string 4624, 4625, 4648
-
Source_Workstation string 4624, 4625, 4648, 4768, 4769, 4776, 5140, 5145
EC2AMAZ-NNKUICG
SourcevSwitchPort string 5146, 5147
SpnName string 1, 5, 6, 8
StagingReason string 1, 4, 8, 8
StartUSN string 2, 3, 4, 9
State string 4652, 4653, 4654, 4983, 4984
Status string 4625, 4665, 4689, 4768, 4769, 4771, 4776, 4777, 4793, 4794, 4820, 4821, 4822, 4823, 4824, 5125 for Success events it has "0x0" value.
0xc000006d
StatusCode string 4928, 4929, 4930, 4931, 4933, 4934, 4937 if there are no issues or errors, the status code will be "0". If an error happened, you will receive Failure event and Status Code will not be equal to "0".
StoreUrl string 4, 6, 6, 8
SubLayerKey string 5444, 5450
3C1CD879-1B8C-4AB4-8F83-5ED129176EF3
SubLayerName string 5444, 5450
windefend
SubLayerType string 5444, 5450
%%16388
SubStatus string 2, 4, 5, 6
0xc000006a
Sub_Status string 2, 4, 5, 6
0xc000006a
SubcategoryGuid string 4719, 4912 the unique GUID of changed subcategory.
0CCE9215-69AE-11D9-BED3-505054503030
SubcategoryId string 4719, 4912 the name of auditing subcategory which state was changed.
%%12544
Subject string 4887, 4888, 4889
SubjectDomainName string 1102, 4611, 4615, 4616, 4624, 4625, 4626, 4627, 4648, 4649, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4817, 4818, 4819, 4826, 4830, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4873, 4874, 4875, 4876, 4877, 4882, 4883, 4884, 4885, 4890, 4891, 4892, 4894, 4896, 4904, 4905, 4907, 4911, 4912, 4913, 4964, 4985, 5039, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5632, 5633, 5712, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6416, 6419, 6420, 6421, 6422, 6423, 6424 subject's domain or computer name.
training1
SubjectKeyIdentifier string 4887, 4888, 4889
SubjectLogonId integer 5888, 5890 hexadecimal value that can help you correlate this event with recent events that might contain the same Logon ID, for example, "4624: An account was successfully logged on."
1207182
SubjectLogonId string 1102, 4611, 4615, 4616, 4624, 4625, 4626, 4627, 4648, 4649, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4817, 4818, 4819, 4826, 4830, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4873, 4874, 4875, 4876, 4877, 4882, 4883, 4884, 4885, 4890, 4891, 4892, 4894, 4896, 4904, 4905, 4907, 4911, 4912, 4913, 4964, 4985, 5039, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5632, 5633, 5712, 5888, 5889, 5890, 6416, 6419, 6420, 6421, 6422, 6423, 6424 hexadecimal value that can help you correlate this event with recent events that might contain the same Logon ID, for example, "4624: An account was successfully logged on."
0xcedae
SubjectMachineName string 6272, 6273, 6274, 6275, 6276, 6277, 6278
SubjectMachineSID string 6272, 6273, 6274, 6275, 6276, 6277, 6278
SubjectUserDomainName string 5888, 5889, 5890 subject's domain or computer name.
EC2AMAZ-NNKUICG
SubjectUserName string 1102, 4611, 4615, 4616, 4624, 4625, 4626, 4627, 4648, 4649, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4817, 4818, 4819, 4826, 4830, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4873, 4874, 4875, 4876, 4877, 4882, 4883, 4884, 4885, 4890, 4891, 4892, 4894, 4896, 4904, 4905, 4907, 4911, 4912, 4913, 4964, 4985, 5039, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5632, 5633, 5712, 5888, 5889, 5890, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6416, 6419, 6420, 6421, 6422, 6423, 6424 the name of the account that forbids the device installation.
user
SubjectUserSid string 1102, 4611, 4615, 4616, 4624, 4625, 4626, 4627, 4648, 4649, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4767, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4817, 4818, 4819, 4826, 4830, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4873, 4874, 4875, 4876, 4877, 4882, 4883, 4884, 4885, 4890, 4891, 4892, 4894, 4896, 4904, 4905, 4907, 4911, 4912, 4913, 4964, 4985, 5039, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5712, 5888, 5889, 5890, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6416, 6419, 6420, 6421, 6422, 6423, 6424 SID of account that forbids the device installation.
S-1-5-21-989241848-306340870-1210095284-500
SystemTime string 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222
'2022-07-28 14:45:40.532999 UTC'
System_Props_Xml string 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222
        8222    0    3    0x80a0000000000000            108551    Security    EC2AMAZ-NNKUICG        
TableId string 4, 6, 8, 9
TargetDomainName string 4624, 4625, 4626, 4627, 4634, 4647, 4648, 4649, 4675, 4688, 4696, 4703, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4772, 4773, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4820, 4821, 4830, 4964 subject's domain or computer name.
doazlab.com
TargetHandleId string 0, 4, 6, 9
0xf80
TargetInfo string 4, 4, 6, 8
localhost
TargetLinkedLogonId string 2, 4, 4, 6
0x0
TargetLogonGuid string 4648, 4964 a GUID that can help you correlate this event with another event that can contain the same Logon GUID, "4769(S, F): A Kerberos service ticket was requested event on a domain controller.
00000000-0000-0000-0000-000000000000
TargetLogonId string 4618, 4624, 4626, 4627, 4634, 4647, 4688, 4696, 4703, 4800, 4801, 4802, 4803, 4964 hexadecimal value that can help you correlate this event with recent events that might contain the same Logon ID, for example, "4624: An account was successfully logged on."
0x9fb6c3
TargetName string 3, 5, 7, 9
WindowsLive:target=virtualapp/didlogical
TargetOutboundDomainName string 2, 4, 4, 6
-
TargetOutboundUserName string 2, 4, 4, 6
-
TargetProcessId string 4690, 4696 hexadecimal Process ID of the new process with new security token. If you convert the hexadecimal value to decimal, you can compare it to the values in Task Manager.
0x4
TargetProcessName string 4, 6, 6, 9
TargetServer string 3, 5, 7, 8
TargetServerName string 4, 4, 6, 8
localhost
TargetSid string 4704, 4705, 4717, 4718, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4771, 4780, 4781, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4798, 4799, 4820, 4824, 4830 SID of the group which members were enumerated. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID cannot be resolved, you will see the source data in the event.
S-1-5-32-545
TargetUserDomain string 1, 4, 6, 8
TargetUserName string 4618, 4624, 4625, 4626, 4627, 4634, 4647, 4648, 4649, 4675, 4688, 4696, 4703, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4776, 4777, 4780, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4820, 4821, 4824, 4830, 4964 the name of the account that performed the logon.
user
TargetUserSid string 4618, 4624, 4625, 4626, 4627, 4634, 4647, 4675, 4688, 4696, 4703, 4800, 4801, 4802, 4803, 4912, 4964 SID of account that performed the logon.
S-1-5-21-989241848-306340870-1210095284-500
Target_Domain string 4624, 4625, 4627, 4634, 4648, 4688, 4703, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4798, 4799, 4800, 4801
doazlab.com
Target_Server_Name string 4, 4, 6, 8
localhost
Target_User_Name string 4624, 4625, 4627, 4634, 4648, 4688, 4703, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4798, 4799, 4800, 4801
user
TaskContent string 4698, 4699, 4700, 4701 the XML of the disabled task.
TaskContentNew string 0, 2, 4, 7
TaskName string 4698, 4699, 4700, 4701, 4702 updated/changed scheduled task name.
\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskLogon
TdoAttributes string 4675, 4706, 4716 the decimal value of attributes for new trust.
TdoDirection string 4675, 4706, 4716 the direction of new trust. If this attribute was not changed, then it will have "-" value or its old value.
TdoSid string 4, 5, 6, 7
TdoType string 4675, 4706, 4716 the type of new trust. If this attribute was not changed, then it will have "-" value or its old value.
TemplateContent string 4, 8, 8, 9
TemplateDSObjectFQDN string 4898, 4899, 4900
TemplateInternalName string 4898, 4899, 4900
TemplateOID string 4898, 4899, 4900
TemplateSchemaVersion string 4898, 4899, 4900
TemplateVersion string 4898, 4899, 4900
TestSigning string 2, 4, 6, 8
ThreadID string 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4949, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5478, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424
"9040"
TicketEncryptionType string 4768, 4769, 4770, 4820, 4821 the cryptographic suite that was used in renewed TGS.
0x12
TicketOptions string 4768, 4769, 4770, 4771, 4772, 4773, 4820, 4821, 4824 this is a set of different Ticket Flags in hexadecimal format
0x40810010
TokenElevationType string 4688
%%1936
Token_Elevation_Type string 4688
%%1936
Token_Elevation_Type_id integer 4688
1936
TopLevelName string 4864, 4865, 4866, 4867 the name of the modified trusted forest information entry.
TrafficSelectorId string 4654, 5451, 5452
TransactionId string 4656, 4659, 4660, 4661, 4664, 4985 unique GUID of the transaction. This field can help you correlate this event with other events that might contain the same Transaction ID, such as "4656(S, F): A handle to an object was requested."
870CF9EA-0BF4-11ED-80BB-42010A743766
TransitedServices string 1, 2, 4, 8
TransmittedServices string 4624, 4625, 4649, 4769 this field contains list of SPNs which were requested if Kerberos delegation was used.
-
TransportFilterId string 1, 4, 5, 5
TreeDelete string 1, 1, 4, 5
TunnelId string 4654, 5451, 5452
TypeOfChange string 3, 4, 4, 9
USN string 3, 4, 4, 9
UserAccountControl string 4720, 4738, 4741, 4742 shows the list of changes in userAccountControl attribute. You will see a line of text for each change. See possible values in here: "Table 7. User's or Computer's account UAC flags.". In the "User Account Control field text" column, you can see text that will be displayed in the User Account Controlfield in 4742 event.
%%2080
%%2082
%%2084
UserClaims string 2, 4, 6, 6
UserData_Xml string 0, 1, 1, 2
      S-1-5-21-2158604247-1726342757-1935066190-500      doadmin      DOAZLAB      0xb82dc    
UserID string 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424, 8222
"S-1-5-18"
UserName string 5446, 5447, 5448, 5449, 5450
NT AUTHORITY\NETWORK SERVICE
UserParameters string 4720, 4738, 4741, 4742 if you change any setting using Active Directory Users and Computers management console in Dial-in tab of computer's account properties, then you will see \ in this field.
-
UserPrincipalName string 4720, 4738, 4741, 4742 internet-style login name for the account, based on the Internet standard RFC 822. By convention this should map to the account's email name. If the value of userPrincipalNameattribute of computer object was changed, you will see the new value here. For computer objects, it is optional, and typically is not set. You can change this attribute by using Active Directory Users and Computers, or through a script, for example.
-
UserSid string 5446, 5447, 5448, 5449, 5450
S-1-5-20
UserUPN string 3, 5, 7, 8
UserWorkstations string 4720, 4738, 4741, 4742 contains the list of NetBIOS or DNS names of the computers from which the user can logon. Each computer name is separated by a comma. The name of a computer is the sAMAccountName property of a computer object. If the value of userWorkstations attribute of computer object was changed, you will see the new value here. For computer objects, it is optional, and typically is not set. You can change this attribute by using Active Directory Users and Computers, or through a script, for example.
%%1793
ValidFrom string 4, 5, 8, 9
ValidTo string 4, 5, 8, 9
Value string 4891, 5069
VendorIds string 1, 4, 6, 6
MONITOR\Default_Monitor
Version integer 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416
3
VirtualAccount string 2, 4, 4, 6
%%1843
VirtualFileName string 0, 1, 5, 5
VlanTag string 5146, 5147, 5150, 5151
VsmLaunchType string 2, 4, 6, 8
Weight integer 5447, 5450
4096
Weight string 5441, 5444, 5447, 5450
Workstation string 4776, 4777, 4793, 4794, 4797 the name of computer account from which the password was queried from For example "DC01". If the change request was sent locally (from the same server) this field will have the same name as the computer account
EC2AMAZ-1CL0VOR
WorkstationName string 4624, 4625, 4649 machine name from which logon attempt was performed.
EC2AMAZ-NNKUICG
change_type string 1102, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738
user
dest string 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222
windowsvictim
dest_nt_domain string 4624, 4625, 4627, 4634, 4648, 4688, 4703, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4798, 4799, 4800, 4801
training1
dest_nt_host string 4, 4, 6, 8
localhost
dest_port integer 5152, 5156, 5157
5355
dvc string 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222
windowsvictim
dvc_nt_host string 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222
windowsvictim_f57c890c-8963-4b7b-b267-755cd8191034
event_id integer 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222
843214
file_name string 4656, 4663, 4907, 4911, 5058, 5140, 5142, 5145
c56b3f40b196d4f8d43940688b5b8765_4d6cbdb8-0892-45ee-9d0d-f2e8b7a5fa78
file_path string 4656, 4663, 4907, 4911, 5058, 5140, 5142, 5145
C:\Windows
new_process string 4688
C:\Windows\System32\conhost.exe
new_process_id string 4688
0x2260
new_process_name string 4688
conhost.exe
notification string 4, 4, 6, 6
object string 1102, 4611, 4624, 4627, 4634, 4648, 4662, 4670, 4672, 4673, 4674, 4688, 4689, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4738
Guest
object_attrs string 1102, 4703, 4717, 4718, 4719, 4722, 4724, 4725, 4726, 4738, 4946, 4947, 4948, 4957
registry
object_category string 1102, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738
user
object_file_name string 4656, 4657, 4661, 4662, 4663, 4674, 4907, 4911
lsass.exe
object_file_path string 4656, 4657, 4661, 4662, 4663, 4674, 4907, 4911
root\cimv2\security\MicrosoftVolumeEncryption
object_id string 4703, 4722, 4724, 4725, 4726, 4738
S-1-5-21-582766833-432816504-4207985818-501
param1 string 4709, 4710, 4711, 4712, 4816, 5038, 6281, 6410
param2 string 4709, 4710, 4816
param3 string 4709, 4816
parent_process string 4688
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
parent_process_id string 4688
0x2024
parent_process_name string 4688
powershell.exe
parent_process_path string 4688
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
process_command_line_arguments string 4688
0xffffffff -ForceV1
process_command_line_process string 4688
C:\Windows\system32\conhost.exe
process_exec string 4673, 4674, 4688, 4689
wevtutil.exe
process_id integer 5152, 5154, 5158, 5446, 5447, 5448, 5449, 5450
8456
process_id string 4624, 4625, 4648, 4656, 4657, 4658, 4660, 4661, 4663, 4670, 4673, 4674, 4688, 4689, 4703, 4904, 4905, 4907, 4911, 4985
0xeb4
process_path string 4624, 4625, 4648, 4656, 4657, 4658, 4660, 4661, 4663, 4670, 4673, 4674, 4688, 4689, 4703, 4904, 4905, 4907, 4911, 4985
C:\Windows\System32\wevtutil.exe
registry_path string 4, 5, 6, 7
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN
registry_value_name string 4, 5, 6, 7
ConfigXML
registry_value_type string 4, 5, 6, 7
%%1873
result string 4703, 4717, 4718, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738
member was removed from a security-enabled local group
service_id string 4768, 4769
S-1-5-21-989241848-306340870-1210095284-502
service_name string 4697, 4768, 4769, 5478
krbtgt
session_id integer 5888, 5890
1207182
session_id string 4611, 4624, 4625, 4627, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4798, 4799, 4904, 4905, 4907, 4911, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5379, 5381, 6416
0xcedae
sigma_product string 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222
windows
sigma_service string 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222
security
signature string 1102, 4611, 4624, 4625, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4800, 4801, 4904, 4905, 4907, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890
Windows Firewall settings were restored to the default values
signature_id integer 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222
8222
src string 4624, 4625, 4648, 4768, 4769, 4776, 4778, 5140, 5145
EC2AMAZ-NNKUICG
src_ip string 4624, 4625, 4648, 4769, 5140
::ffff:10.0.1.8
src_nt_domain string 4611, 4624, 4625, 4627, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4798, 4799, 4904, 4905, 4907, 4911, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5379, 5381, 6416
training1
src_nt_host string 4624, 4625, 4648, 4768, 4769, 4776, 5140, 5145
EC2AMAZ-NNKUICG
src_port integer 4768, 4769, 5140, 5145, 5156, 5158
5355
src_port string 4624, 4625, 4648
-
src_user string 1102, 4611, 4624, 4625, 4627, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4798, 4799, 4904, 4905, 4907, 4911, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5379, 5381, 5888, 5890, 6416
user
src_user_name string 4703, 4722, 4724, 4725, 4726, 4738
user
start_mode string 4, 6, 7, 9
manual
subject string 1102, 4611, 4624, 4625, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4800, 4801, 4904, 4905, 4907, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890
Windows Firewall settings were restored to the default values
ta_windows_action string 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222
failure
ta_windows_security_CategoryString string 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738
Account Management
ta_windows_status string 4625, 4689, 4768, 4769, 4776
0xc000006d
timeendpos integer 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222
526
timestartpos integer 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222
496
transport string 5152, 5154, 5156, 5157, 5158
UDP
user_group string 4624, 4625, 4627, 4634, 4648, 4688, 4703, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4798, 4799, 4800, 4801
user
user_id string 2, 2, 2, 8
"S-1-5-18"
user_name string 4703, 4722, 4724, 4725, 4726, 4738
Guest
vendor string 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222
Microsoft
vendor_product string 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222
Microsoft Windows

smbclient-security

Field Data Type Event IDs Example
EventID integer 31001, 31018
31018
Name string 31001, 31018
Microsoft-Windows-SMBClient
EventCode integer 31001, 31018
31018
Guid string 31001, 31018
988C59C5-0A1C-45B6-A555-0C62276E327D
ProcessID integer 31001, 31018
4
ProcessId integer 31001, 31018
4
SigmaEventCode integer 31001, 31018
31018
SystemTime string 31001, 31018
'2022-05-23 16:00:29.832323 UTC'
ThreadID integer 31001, 31018
340
UserID string 31001, 31018
S-1-5-18
sigma_product string 31001, 31018
windows
sigma_service string 31001, 31018
smbclient-security
timeendpos integer 31001, 31018
515
timestartpos integer 31001, 31018
485
xmlns string 31001, 31018
http://schemas.microsoft.com/win/2004/08/events/event

system

Field Data Type Event IDs Example
Application string 1, 5, 6, 10, 14, 15
Command string 16, 17, 24, 25, 40, 41, 42, 43
Computer string 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 201, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 262, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 285, 286, 289, 290, 300, 301, 302, 379, 380, 381, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 566, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1025, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1056, 1058, 1060, 1061, 1065, 1068, 1074, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1281, 1282, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2001, 2003, 2004, 2005, 2042, 3261, 4000, 4001, 4002, 4003, 4004, 4005, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5202, 5203, 5211, 5300, 5774, 5781, 5782, 5805, 5823, 6000, 6005, 6006, 6009, 6011, 6013, 6027, 6033, 6035, 6036, 6037, 6038, 6040, 6041, 6100, 6145, 6146, 6148, 6400, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 9009, 10000, 10001, 10002, 10003, 10004, 10005, 10010, 10016, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10121, 10148, 10149, 10154, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14206, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 14531, 14533, 15007, 15008, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16647, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 16983, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 20010, 24576, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50036, 50037, 50038, 50103, 50104, 50105, 50106, 51046, 51047, 51057
win10-base
Data integer 1, 8
0
Data string 2, 12, 14, 15, 16, 18, 20, 22, 25
Event string 0, 0, 3, 4
EventID integer 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 201, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 262, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 285, 286, 289, 290, 300, 301, 302, 379, 380, 381, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 566, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1025, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1056, 1058, 1060, 1061, 1065, 1068, 1074, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1281, 1282, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2001, 2003, 2004, 2005, 2042, 3261, 4000, 4001, 4002, 4003, 4004, 4005, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5202, 5203, 5211, 5300, 5774, 5781, 5782, 5805, 5823, 6000, 6005, 6006, 6009, 6011, 6013, 6027, 6033, 6035, 6036, 6037, 6038, 6040, 6041, 6100, 6145, 6146, 6148, 6400, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 9009, 10000, 10001, 10002, 10003, 10004, 10005, 10010, 10016, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10121, 10148, 10149, 10154, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14206, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 14531, 14533, 15007, 15008, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16647, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 16983, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 20010, 24576, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50036, 50037, 50038, 50103, 50104, 50105, 50106, 51046, 51047, 51057
98
FileName string 6, 8, 10, 11, 12, 14, 150
Filename string 0, 0, 0, 1
Id string 16385, 16386, 16390
4AAC461E-F8E1-4F65-A8CA-EDB4CC03A0C3
Key string 0, 1, 4, 5, 6
Line string 0, 0, 0, 1
Name string 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36884, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057
"stornvme"
Origin string 5, 5
Path string 20, 22, 23, 9009, 36912
C:\inetpub\history\CFGHISTORY_0000000005
ProcessName string 1, 41, 150, 225
\Device\HarddiskVolume2\Windows\System32\svchost.exe
Program string 6036, 6037
Target string 40960, 40961, 40962, 40965
Task integer 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057
8
Task string 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 300, 301, 302, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1058, 1060, 1061, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2003, 2004, 2005, 2042, 4000, 4001, 4002, 4003, 4004, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5300, 6000, 6027, 6033, 6035, 6036, 6037, 6040, 6041, 6100, 6145, 6146, 6400, 7001, 7002, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 10000, 10001, 10002, 10003, 10004, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50037, 50038, 51047, 51057
Type string 90, 36867, 36868, 36869, 36870, 36871, 36872, 36880, 36889
User string 16950, 16951, 16952
Window string 9
enabled string 1, 3, 6, 6, 9
hr string 1, 16404, 24836, 24842, 24843, 24844, 24845, 24846
id integer 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057
93485
line string 0, 1, 4, 4, 6
name string 519, 566
Object Operation (W3 Active Directory)
process_name string 1
\Device\HarddiskVolume2\Windows\System32\svchost.exe
product string 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057
Windows
rule string 1, 3, 6, 6, 9
service integer 7009, 10005, 10111
50
service string 1074, 7000, 7001, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 10010, 10016, 14204, 14205
{4991D34B-80A1-4291-83B6-3328366B9097}
status string 18, 19, 6027, 7036, 16396, 32773, 32774, 32775
stopped
APCpuidData string 7, 9
AbandonedBatteryCount string 1, 2, 5
AbortiveDisconnect string 6, 9
AcOnline string 0, 1, 5
AccessMode string 28, 29
AccountDistinguishedName string 12293, 12303, 12304, 16391, 16392, 16393
AccountName string 7045, 16384, 16401, 16402, 16403, 16409, 16411, 16413, 16978
Network Service
AccountRID string 1, 3, 4, 6, 9
AccountSID string 1, 2, 3, 6, 9
Action string 90, 130
ActiveBatteryCount string 2, 4, 5
ActiveOperation string 0, 0, 1, 1, 1
ActiveResidencyInUs string 0, 5, 7
ActivityID string 14, 19, 20, 43, 44, 1006, 1129, 1500, 1501, 1502, 1503, 2003, 2004, 7001, 7002, 7043, 10005, 10010, 10016, 16392, 16962, 16977, 16983
"FFE311E3-7084-4A19-B935-F331C2DB7296"
ActualFunctionTableSize string 6, 8
ActualFuntionTableCount string 0, 1, 1, 1, 7
ActualMaxInterval string 0, 1, 8
ActualSize string 5
ActualVersion string 6, 8
AdSuffix string 0, 0, 1, 1
AdapterName string 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 10317, 10400
{87056817-E272-4172-BD6E-DB007E723246}
AdapterSuffixName string 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038
snapattack.labs
AddServiceStatus string 20003, 20004
AdditionalDetails string 2
AdditionalInfo string 55, 129
Address string 6, 8, 10, 12, 14, 16, 17, 1014, 4200
1700000000000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
AddressLength string 0, 1, 1, 4
AddressSpace string 28, 29
AffinityCount string 8, 9
AffinityLevel string 28, 29
AgentName string 15, 16
AlertDesc integer 3, 6, 7, 8, 8
70
AlertDesc string 36887, 36888
AllowIeeePriorityTag string 8, 8
AllowMacSpoofing string 8, 8
AllowTeaming string 8, 8
AllowedOnes string 4, 6
AllowedZeroes string 4, 6
AoAcCompliantNic string 0, 5, 7
ApiCallerName string 1, 7, 8
ApiCallerNameLength string 1, 7, 8
ApicId string 18, 19, 20, 21
AppName string 6, 8, 9, 10, 11, 12, 14
AppNameLength string 9
Applicability string 0, 9
Argument string 1000, 1001, 1002, 1004
Argument1 string 2, 2, 2
Argument2 string 2, 2, 2
Arguments string 1, 5, 6, 10, 14, 15
Attributes string 1
AudioPlaybackInUs string 0, 5, 7
AudioPlaying string 0, 5, 7
Authorize string 1, 3
AvailableAddressFilters string 243, 244
AverageResume string 1, 1, 3
BCDSetting string 2, 3, 5
BSPCpuidData string 7, 9
BackupPath string 104, 105
BadFileOffset string 0, 1, 5
BadLcn string 0, 1, 5
BalStatus string 26, 38
BandID string 1, 3
BandMetadataSize string 1, 2
Bank string 22, 23, 46, 47, 48, 49
BatteryActionInternalFlags string 2, 4, 5
BatteryFullChargeCapacityOnEnter string 0, 5, 6
BatteryFullChargeCapacityOnExit string 0, 5, 7
BatteryRemainingCapacityOnEnter string 0, 5, 6
BatteryRemainingCapacityOnExit string 0, 5, 7
BiasValid string 0, 1, 8
BinaryData string 1, 1, 3, 4, 6
BiosInitDuration string 1
BitPosition string 22, 23, 46, 47
BitlockerUserInputTime string 2, 3
BlMemoryAttributes string 0, 1
BlMemoryType string 0, 1
BlPageCount string 0, 1
BlStartPage string 0, 1
BlockLength string 2, 3, 3, 4, 8
BlockNumber string 2, 3, 3, 4, 8
BootAppStatus string 1, 4
BootApplication string 522, 523
BootId integer 5, 6, 6
3
BootId string 506, 507
BootMenuPolicy string 2, 5
BootMode string 1, 2
BootStatusPolicy string 0, 2
BootType string 2, 7
BridgeControl string 16, 17, 40, 41
BridgeStatus string 16, 17, 40, 41
BugcheckCode string 1, 4
BugcheckInfoFromEFI string 1, 4
BugcheckParameter string 1, 4
BugcheckParameter1 string 1, 4
0x0
BugcheckParameter2 string 1, 4
0x0
BugcheckParameter3 string 1, 4
0x0
BugcheckParameter4 string 1, 4
0x0
BuildVersion string 1, 2
BurstLimit string 2, 8
BurstSize string 2, 8
Bus string 16, 17, 40, 41
BusAddress string 24, 25, 42, 43
BusData string 24, 25, 42, 43
BusNumber string 24, 25, 26, 27, 42, 43, 44, 45
BusSegment string 24, 25, 42, 43
CAPEDesc string 1, 4, 6, 6
CAPEName string 1, 4, 6, 6
CLSID string 10001, 10002
CPU string 96, 97
CSPName string 3, 6, 6, 8, 8
CSPType string 3, 6, 6, 8, 8
CVEID string 2
CVEId string 0, 0, 1
CacheFlushNeeded string 1, 5, 6
CacheFlushSupported string 1, 5, 6
CacheLevel string 28, 29
CacheSend string 7, 9
CallStack string 5, 5
CallerProcessName string 0, 0, 4, 6
CapDurationInSeconds string 7, 37
Capabilities string 1, 2
Caption string 2, 6
Ec2Config.exe - Application Error
Card string 22, 23, 46, 47
CardHandle string 22, 23, 46, 47
CeilingTriggerRid string 16656, 16657
CertFlags string 2, 3, 6, 7, 8
ChainLoggingRate string 1, 4, 6
ChainingCountFailure string 1, 4, 6
ChainingCountRequests string 1, 4, 6
ChainingCountSuccess string 1, 4, 6
ChangeReason string 0, 0, 3, 4
Channel string 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 201, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 262, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 285, 286, 289, 290, 300, 301, 302, 379, 380, 381, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 566, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1025, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1056, 1058, 1060, 1061, 1065, 1068, 1074, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1281, 1282, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2001, 2003, 2004, 2005, 2042, 3261, 4000, 4001, 4002, 4003, 4004, 4005, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5202, 5203, 5211, 5300, 5774, 5781, 5782, 5805, 5823, 6000, 6005, 6006, 6009, 6011, 6013, 6027, 6033, 6035, 6036, 6037, 6038, 6040, 6041, 6100, 6145, 6146, 6148, 6400, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 9009, 10000, 10001, 10002, 10003, 10004, 10005, 10010, 10016, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10121, 10148, 10149, 10154, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14206, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 14531, 14533, 15007, 15008, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16647, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 16983, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 20010, 24576, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50036, 50037, 50038, 50103, 50104, 50105, 50106, 51046, 51047, 51057
System
ChannelPath string 21, 25, 26, 27, 28, 29, 30, 31, 40
Checkpoint string 41, 218
CheckpointDuration string 1
CheckpointStatus string 1, 4
CipherSuite string 0, 3, 6, 8, 8
ClassCode string 16, 17, 26, 27, 40, 41, 44, 45
ClearReason string 1, 5, 9
SRK has changed or is not present.
ClfsStatus string 1
Client string 0, 3, 3, 6
ClientAddress string 1, 5, 7
ClientContext string 34, 35, 36
ClientDisconnect string 6, 9
ClientPID integer 0, 1, 1, 4
2352
ClientRID string 1, 5, 6
ClientVersion string 2, 6
ClientVersionLen string 2, 6
ClustersCount string 0, 1, 5
CmdStatus string 0, 1
Column string 22, 23, 46, 47
CompleterId string 24, 25, 42, 43
CompletionType string 1101, 1102, 1103, 1104, 1201, 1202
ComputedRIDValue string 1, 4, 6, 6, 6
ComputerName string 4096, 4097, 4098, 4099, 12297, 12298, 16935, 16936, 16937
Config string 1, 4
ConfigProperty string 1, 2
ConfigurationReader string 1, 1, 2, 5
ConfigurationSystem
ConflictingParameter string 0, 1, 1, 1, 3
ConnectedStandbyInProgress string 1, 4
ConnectionBufferFull string 8, 9
ConnectivityState string 2, 6, 8
Context string 1, 2, 3, 5, 100, 101, 102, 1008, 1012
ContextHandle string 0, 3, 6, 8, 8
ControlDeviceName string 2
CorrectableErrorStatus string 16, 17, 18, 40, 41
CorruptionActionState string 8, 9
CorruptionState string 5, 5
Count string 1, 2
CountNew string 0, 2
CountOld string 0, 2
CreatorId string 1, 2
CredContext string 36872, 36889
CsEntryScenarioInstanceId string 1, 4
CurrentBias integer 2, 4
420
CurrentRunLevel string 13, 14, 15, 16
CurrentStratumNumber string 3, 5
CurrentTime string 1, 8
CurrentTimeZoneID integer 2, 4
2
DCName string 1002, 1006, 1007, 1030, 1058, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1104, 1109, 1112, 1126, 1127, 1500, 1501, 1502, 1503
\WIN-FPV0DSIC9O6.sigma.fr
DSObjectName string 0, 1, 1, 1
Data1 string 1, 9
Data2 string 1, 9
DataSize string 2, 7
DataSourceId string 24832, 24847, 24848
DefaultQueueVmmqEnabled string 2, 2, 7
DefaultQueueVrssEnabled string 2, 2, 7
DefaultQueueVrssExcludePrimaryProcessor string 2, 2, 7
DefaultQueueVrssIndependentHostSpreading string 2, 2, 7
DefaultQueueVrssMaxQueuePairs string 2, 2, 7
DefaultQueueVrssMinQueuePairs string 2, 2, 7
DefaultQueueVrssQueueSchedulingMode string 2, 2, 7
Default_SD_String_ string 1, 2, 6, 6, 9
O:SYG:SYD:(A;;RC;;;BA)
Description string 10, 11, 55, 125
DescriptionLength string 1, 2, 5
DetectedBy string 0, 0, 1, 1, 1
Device string 1, 2, 3, 5, 6, 10, 11, 12, 14, 15, 16, 17, 22, 23, 40, 41, 46, 47
DeviceDescLength string 1, 4
DeviceDescription string 1, 4
DeviceID string 16, 17, 40, 41
DeviceId string 26, 27, 44, 45, 144, 145, 146, 148, 149, 10000, 20005, 20006, 20007, 20008
DeviceInstance string 2, 2, 5
DeviceInstanceID string 20001, 20002, 20003, 20004
DeviceInstanceLength string 2, 2, 5
DeviceName string 1, 4, 5, 6, 7, 55, 98, 140, 143, 144, 210, 211
\Device\HarddiskVolume2
DeviceNameLength integer 1, 6
9
DeviceNameLength string 1, 4, 5, 6, 7, 143, 144
DeviceNumber string 26, 27, 44, 45
DeviceObject string 0, 0, 1, 5, 7
\Device\Http\ReqQueue
DeviceSerialNumber string 16, 17, 40, 41
DeviceTime string 1, 4, 5, 6, 7
2074-11-09 08:03:12 UTC
DeviceVersionMajor integer 1, 6
10
DeviceVersionMajor string 1, 4, 5, 6, 7
DeviceVersionMinor integer 1, 6
0
DeviceVersionMinor string 1, 4, 5, 6, 7
Direction string 90, 130
DirectoryPath string 1, 2, 2, 6, 9
DirtyPages string 1, 6
DisabledLoadOption string 1, 5, 6
DisconnectedStandby string 0, 5, 7
DiskFriendlyName string 1
DiskPmDisabledMaxInterval string 0, 1, 8
DiskPmEnabledFlag string 0, 1, 8
DiskPmEnabledMaxInterval string 0, 1, 8
DiskPmPolicy string 0, 1, 8
DnsServerList string 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038
192.168.86.45
DnsSuffix string 0, 0, 1, 1
Domain string 18, 32773, 32774, 32775
DomainName string 4096, 4097, 4098, 4099
DomainPeer string 24, 25, 26, 27, 130, 131, 132, 134, 135, 138, 156
tick.boozallencsn.com,0x9
DripsResidencyInUs string 0, 5, 7
DripsTransitions string 0, 5, 7
DriveName string 55, 98
C:
DriverDescription string 20001, 20002
DriverFileName string 20003, 20004
DriverInitDuration string 1
DriverName string 40, 219, 10113, 20001, 20002
DriverNameLength string 40, 219
DriverObject string 184, 185, 186, 187, 188, 189
DriverProvider string 20001, 20002
DriverVersion string 20001, 20002
DropLowResourcesPackets string 1, 2, 6
DroppedClaims string 0, 1, 5, 6, 9
DstVPortId string 204, 205
DumpEncryptionFailureReason string 0, 1, 2, 7
Duration string 4, 13
DurationInUs string 0, 5, 7
DwmSyncFlushTime string 0, 5, 7
DwordVal integer 50037, 51047, 51057
1
DwordVal string 1004, 50037, 51047, 51057
DynamicIPAddressLimit string 8, 8
EffectiveState string 1, 42, 107
EfiDaylightFlags integer 2, 3, 8
0
EfiTime string 2, 3, 8
2022-03-01 17:43:36 UTC
EfiTimeZoneBias integer 2, 3, 8
2047
ElapsedTime string 2, 6, 7
EmbeddedTeaming string 204, 205, 215
EnableDhcpGuard string 8, 8
EnableDisableReason integer 1, 3, 5
0
EnableDisableReason string 153, 156
EnableFixSpeed10G string 8, 8
EnableRouterGuard string 8, 8
Enabled string 1, 5, 6
EnabledFeatures string 1, 2, 9
EnabledNew string 0, 2
true
EncodedCert string 3, 6, 6, 8, 8
EndTime string 1001, 1002
EnergyDrain string 0, 5, 7
EntryCount string 1, 8
Error string 5, 6, 14, 15, 16, 26, 140, 1000, 1001, 1003, 1008, 1010, 1018, 1043, 6146, 36865, 40960, 45057
ErrorBatteryCount string 1, 2, 5
ErrorCause string 7, 9
ErrorCode integer 1006, 1129, 8018, 16392
9005
ErrorCode string 6, 10, 20, 21, 22, 23, 27, 28, 29, 30, 31, 40, 96, 514, 518, 519, 520, 1000, 1002, 1003, 1006, 1007, 1008, 1012, 1023, 1029, 1030, 1031, 1052, 1053, 1054, 1055, 1058, 1065, 1079, 1080, 1085, 1088, 1089, 1091, 1095, 1096, 1097, 1101, 1104, 1110, 1112, 1125, 1126, 1127, 1129, 1130, 2042, 4001, 4002, 4003, 4004, 4100, 4202, 4302, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8194, 10000, 12288, 12289, 12294, 12299, 12302, 12305, 14300, 14301, 14302, 14303, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16398, 16399, 16400, 16401, 16402, 16403, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16642, 16643, 16644, 16645, 16646, 16648, 16649, 16935, 16936, 16937, 16944, 16945, 16947, 16948, 16949, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 36870, 36872, 36876, 36877, 36878, 36879, 36889
ErrorCode1 string 14304, 14305, 14306
ErrorCode2 string 14304, 14305, 14306
ErrorDescription string 401, 404, 1002, 1006, 1007, 1030, 1052, 1053, 1054, 1055, 1058, 1065, 1079, 1080, 1085, 1088, 1089, 1091, 1095, 1096, 1097, 1101, 1104, 1110, 1112, 1125, 1126, 1127, 1129, 1130
The network is not present or not started.
ErrorMessage string 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 15, 16, 17, 18, 19, 20, 22, 23, 24, 25, 30, 32, 40, 43, 44, 45, 46, 47, 48, 49, 54, 129, 130, 131, 132, 133, 134, 135, 136, 159, 16401, 16402, 16403, 16651
The specified local group does not exist.
ErrorParam1 string 1, 2, 3
ErrorParam2 string 1, 2, 3
ErrorParam3 string 1, 2, 3
ErrorParam4 string 1, 2, 3
ErrorSource string 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49
ErrorState string 36871, 36888
ErrorStatus string 22, 23, 46, 47, 36870
ErrorString string 1, 1, 3, 4, 6
The system cannot find the file specified.
ErrorType string 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 42, 43, 44, 45, 46, 47
Error_Code string 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057
0
EventCode integer 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057
98
EventData_Xml string 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 109, 129, 134, 137, 153, 172, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1056, 1074, 1129, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10005, 10010, 10016, 10111, 10154, 14204, 14205, 14206, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16648, 16937, 16962, 16977, 24576, 24577, 24579, 36887, 50037, 51047, 51057
snapattack.labs.    B4050000
EventDescription string 0, 0, 1, 6
EventGenerationTime string 0, 0, 2, 4
EventRecordID integer 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057
93485
EventSourceName string 32, 35, 1007, 1056, 1074, 5211, 6038, 7000, 7001, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 9009, 10005, 10010, 10016, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 24576, 24577, 24579
"WinRM"
EventVerbosity string 0, 0, 1, 6
Exception string 0, 0, 0, 5
ExchangeStrength string 0, 3, 6, 8, 8
ExitBootServicesEntry string 0, 3
ExitBootServicesExit string 0, 3
ExitCode string 0, 0, 1, 1, 1
ExitLatencyInUs string 0, 5, 7
ExitReason integer 2, 4
0
ExpectedFunctionTableSize string 6, 8
ExpectedFuntionTableCount string 0, 1, 1, 1, 7
ExpectedSize string 5
ExpectedVersion string 6, 8
Ext1 string 128, 129
Ext2 string 128, 129
Extended string 22, 23, 46, 47
ExtendedStatus string 1, 2, 4
ExtensibleModulePath string 10000, 10001, 10002, 10003, 10004
ExtensionId string 61, 98, 1085, 1091, 1112, 1128
ExtensionName string 61, 1085, 1091, 1112, 1128
ExtensionNameLength string 1, 6
ExternalMonitorConnectedState string 506, 507
ExtraString string 2, 3, 4, 5, 6, 8, 9, 10, 11
\SystemRoot\System32\Config\RegBack\SYSTEM
ExtraStringLength integer 5
42
ExtraStringLength string 2, 3, 4, 5, 6, 8, 9, 10, 11
FRUId string 16, 17, 22, 23, 24, 25, 26, 27, 40, 41, 42, 43, 44, 45, 46, 47
FRUText string 16, 17, 22, 23, 24, 25, 26, 27, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49
FailReason string 82, 88, 90, 94, 95, 97, 100, 113, 122, 127, 128, 129, 130, 146, 147, 149, 150, 151, 197, 216, 227, 229, 254, 256, 257, 261, 1003
FailedLogFilePath string 2, 7
FailureMode string 2, 5, 9
FailureMsg string 16, 29
FailureMsgId string 16, 29
FailureName string 1, 2, 9
FailureNameLength string 1, 2, 9
FailureReason integer 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522
FailureResult string 1, 2
FailureStatus integer 16, 29, 150
FaultCode string 9, 9
FeatureClassId string 1, 6
FeaturesNeeded string 4, 8
FeaturesSupported string 4, 8
FileList string 16385, 16386
C:\Users\user\AppData\Local\Temp\BIT72FA.tmp
FileNameBuffer string 24832, 24833, 24834, 24847, 24848
FileNameLength string 12, 150, 24832, 24833, 24834, 24847, 24848
FileOffset string 2, 3, 4, 4, 8
FilePath string 12, 1058, 1096, 12295
FilterId string 204, 205, 215
FilterName string 1205, 1206
FilterNameLength string 1205, 1206
FinalStatus string 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 10100, 10101
0x8000002a
FirstDripsEntryInUs string 0, 5, 7
FirstPage string 1, 2
FirstRefresh integer 2, 4
0
Flags string 1, 2, 3, 9, 42, 43, 264, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24643, 24645, 24652, 24653, 24654, 24657, 24658, 24659, 24672
FrameworkVersion string 0, 0, 0, 0, 1
FreePersistentPages string 1, 1, 5
FriendlyName string 1001, 10111, 10112, 10115, 10116, 14206, 14210
EVTX-PC: evtx:
FullChargeCapacity string 0, 1, 5
FullChargeCapacityRatio string 0, 5, 7
FullResume string 1, 1, 3
Function string 16, 17, 40, 41, 218
FunctionNumber string 26, 27, 44, 45
FwMemoryAttributes string 0, 1
FwMemoryType string 0, 1
FwPageCount string 0, 1
FwStartPage string 0, 1
FxVersion string 10001, 10002
GPOCNName string 1058, 1065, 1096, 1104
GPODisplayName string 0, 1, 1, 3
GPOFileSystemPath string 0, 1, 1, 3
GPOScriptCommandString string 0, 1, 1, 3
GdiOnTime string 0, 5, 7
GetTestResult_Data string 2, 7
Group integer 26, 55
0
Group string 26, 33, 34, 35, 36, 37, 54, 55
GroupName string 16387, 16389, 16391, 16393, 16394, 16401, 16402, 16407, 16413
Performance Log Users
Guid string 1, 3, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 50, 52, 55, 98, 104, 109, 134, 137, 139, 143, 153, 172, 201, 206, 238, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2003, 2004, 5211, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057
"{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}"
HRESULT string 0, 0, 0, 1
HResult string 517, 518, 1538
HardwareEnabled string 1, 2, 9
HardwareID string 1
HardwareId string 1, 5, 6, 10, 14, 15
HardwarePresent string 1, 2, 9
HeaderFlags string 5, 5
HeaderLog string 16, 17, 40, 41
HeaderLog0 string 1, 8
HeaderLog1 string 1, 8
HeaderLog2 string 1, 8
HeaderLog3 string 1, 8
HelperClassName string 4000, 5000, 5100, 5200, 6100
HiberPagesWritten string 1
HiberReadDuration string 1
HiberWriteDuration string 1
HibernateTime string 8, 8
HiveName string 15, 16
\SystemRoot\System32\Config\SOFTWARE
HiveNameLength string 15, 16
HostName string 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038
quadra
HostOSName string 0, 0, 2, 3
Windows (TM) 10 Preinstallation Environment
HostOSbuildversion string 0, 0, 2, 3
HostOSmajorversion string 0, 0, 2, 3
HostOSminorversion string 0, 0, 2, 3
HostOSservicepackName string 0, 0, 2, 3
HostOSservicepackmajorversion string 0, 0, 2, 3
HostOSservicepackminorversion string 0, 0, 2, 3
HostOSwasWindowsPE string 0, 0, 2, 3
true
Host_OS_Name string 0, 0, 2, 3
Windows (TM) Code Name "Longhorn" Preinstallation Environment
Host_OS_build_version integer 0, 0, 2, 3
7600
Host_OS_major_version integer 0, 0, 2, 3
6
Host_OS_minor_version integer 0, 0, 2, 3
1
Host_OS_service_pack_major_version integer 0, 0, 2, 3
0
Host_OS_service_pack_minor_version integer 0, 0, 2, 3
0
Host_OS_was_Windows_PE string 0, 0, 2, 3
true
HwDripsResidencyInUs string 0, 5, 7
HypervisorVersion string 0, 4
IPSecOffloadLimit string 4, 9
IdleImplementation string 5, 5
IdleSessionTimeout string 0, 1, 3
IdleStateCount integer 26, 55
1
IdleStateCount string 4, 26, 55
IfGuid string 10317, 10400
IfIndex string 41, 42, 10317, 10400
IfLuid string 10317, 10400
ImageFileName string 7, 9
ImageName string 1, 34, 36, 37, 152, 153
ImagePath string 0, 4, 5, 7
%SystemRoot%\PSEXESVC.exe
Index string 2, 4, 5
Info string 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218
InputSuppressionActionCount string 0, 5, 7
InstallStatus string 20001, 20002
Install_was_an_upgrade string 0, 0, 2, 3
false
Installwasanupgrade string 0, 0, 2, 3
false
InstanceId string 78, 80, 92, 93, 10111, 10112, 10113, 10115, 10116
InstanceName string 0, 4
InstanceNameLength string 0, 4
Interface string 4002, 4200, 4201, 4202
InterfaceDesc string 4000, 5000, 5100, 5200
InterfaceGUID string 4000, 5000, 5100, 5200
InternalCode string 1, 1
InternalInfo string 1, 2, 9
InterruptModeration string 4, 9
IoApicId string 1, 4, 7
IoctlCode string 2, 6, 7
IovOffloadWeight string 4, 9
IpFamily string 0, 0, 3, 4
IpHTTPSReasonCode string 0, 2, 3, 4
Ipaddress string 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038
192.168.86.7
Irql string 4
IsAcOnline string 2, 4, 5
IsBootVolume string 0, 1, 5
IsCsSessionInProgressOnExit string 0, 5, 7
IsDriverOEM string 20001, 20002
IsPowerActionCallIgnored string 2, 4, 5
IsPowerPolicyEnabled string 2, 4, 5
IsTestConfig string 1, 4
IsatapRouter string 0, 0, 1, 4
KeyFlags string 3, 6, 6, 8, 8
KeyName string 3, 6, 6, 8, 8
KeyProtectionMechanism string 1, 2
KeyType string 3, 6, 6, 8, 8
KeysUpdated string 1, 6
Keywords string 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 201, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 262, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 285, 286, 289, 290, 300, 301, 302, 379, 380, 381, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 566, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1025, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1056, 1058, 1060, 1061, 1065, 1068, 1074, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1281, 1282, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2001, 2003, 2004, 2005, 2042, 3261, 4000, 4001, 4002, 4003, 4004, 4005, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5202, 5203, 5211, 5300, 5774, 5781, 5782, 5805, 5823, 6000, 6005, 6006, 6009, 6011, 6013, 6027, 6033, 6035, 6036, 6037, 6038, 6040, 6041, 6100, 6145, 6146, 6148, 6400, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 9009, 10000, 10001, 10002, 10003, 10004, 10005, 10010, 10016, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10121, 10148, 10149, 10154, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14206, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 14531, 14533, 15007, 15008, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16647, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 16983, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 20010, 24576, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50036, 50037, 50038, 50103, 50104, 50105, 50106, 51046, 51047, 51057
0x8080000000000000
Language string 1002, 1003, 1006, 1008, 1009, 1013, 1014, 1015, 1017, 1018, 1040, 1042, 1043
Language1 string 1009, 1016, 1041, 1060, 1061
Language2 string 1009, 1016, 1041, 1060, 1061
LastBootGood string 0, 2
true
LastBootId string 0, 2
LastPage string 1, 2
LastShutdownGood string 0, 2
true
LaunchType string 1001, 1002, 1003, 1101, 1102, 1103, 1104
Leaf string 4, 8
LeafNumber string 7, 9
Length string 1, 2, 3, 6, 8, 10, 12, 14, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 40, 41, 42, 43, 44, 45, 46, 47
Level integer 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057
4
Level string 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 300, 301, 302, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1058, 1060, 1061, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2003, 2004, 2005, 2042, 4000, 4001, 4002, 4003, 4004, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5300, 6000, 6027, 6033, 6035, 6036, 6037, 6040, 6041, 6100, 6145, 6146, 6400, 7001, 7002, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 10000, 10001, 10002, 10003, 10004, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50037, 50038, 51047, 51057
LidOpenState string 506, 507
LifetimeId string 10110, 10111, 10112, 10113, 10115, 10116
LightestSystemState string 1, 7, 8
Limit string 2, 8
LoadBalancingAlgorithm string 206, 207, 208, 209, 210, 211
LoadOSImageStart string 0, 3
LoadOptions string 2, 7
NOEXECUTE=OPTIN
LocalAddr string 0, 9
LocalAddrLen string 0, 9
LocalAddress string 96, 98
LocalAddressLength string 96, 98
LocalCertSubjectName string 0, 3, 6, 8, 8
LocalIPAddr string 0, 1, 3
LocalIPAddrLen string 0, 1, 3
LocalPort string 0, 1, 3
LocalPortLen string 0, 1, 3
LocalPrefix string 0, 9
Location string 241, 1008, 1012, 10111, 10112, 10115, 10116
LogFile string 19, 20
LogStatus string 1, 1, 2, 2, 9
MCABank string 18, 19, 20, 21
MIDR_EL1 string 28, 29
MPIDR_EL1 string 28, 29
MSRIndex string 4, 6
MacAddress string 25, 28, 29, 30, 31, 204
MacAddressLen string 25, 28, 29, 30, 31
MacLength string 0, 2, 4
MajorVersion integer 1, 2
10
MajorVersion string 12, 29
ManualPeer string 16, 17, 47, 48, 137
time.windows.com,0x8
MaxBandCount string 1, 2
MaxDelta string 1, 4, 5
MaxSystemTimeChangeSeconds string 3, 4
Maximum string 1, 3, 5, 6, 6
MaximumPerformancePercent string 5, 5
MciAddr string 18, 19, 20, 21, 48, 49
MciMisc string 18, 19, 20, 21, 48, 49
MciStat string 18, 19, 20, 21
MciStatus string 48, 49
MemHierarchyLvl string 6, 8, 10, 12, 14, 16, 17, 18, 19
Member string 184, 185, 186, 187, 188, 189
MemberAdapterFriendlyName string 2, 2, 9
MemberAdapterFriendlyNameLen string 2, 2, 9
MemberAdapterName string 2, 2, 9
MemberAdapterNameLen string 2, 2, 9
MemorIO string 6, 8, 10, 12, 14, 16, 17, 18, 19
MemoryRequired string 0, 4
MemorySize string 1101, 1102, 1103, 1104
Message string 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 300, 301, 302, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1058, 1060, 1061, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2003, 2004, 2005, 2042, 4000, 4001, 4002, 4003, 4004, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5300, 6000, 6027, 6033, 6035, 6036, 6037, 6040, 6041, 6100, 6145, 6146, 6400, 7001, 7002, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 10000, 10001, 10002, 10003, 10004, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50037, 50038, 51047, 51057
The application was unable to start correctly (0xc0000142). Click OK to close the application.
MinDelta string 1, 4, 5
MinPerfPercent string 2, 9
MinThrottlePercent string 2, 9
MinimumPasswordLength integer 1, 6, 7, 7, 9
0
MinimumPasswordLength string 16977, 16978, 16979
MinimumPasswordLengthAudit integer 1, 6, 7, 7, 9
-1
MinimumPasswordLengthAudit string 16977, 16978
MinimumPerformancePercent string 5, 5
MinimumThrottle string 1, 2, 5
MinimumThrottlePercent string 5, 5
MiniportEventEnum string 0, 1, 1, 3, 7
MiniportName string 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 37, 38, 41, 42, 43, 44, 45
Microsoft Hyper-V Network Adapter
MiniportNameLen integer 3, 10, 11
33
MiniportNameLen string 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 37, 38, 41, 42, 43, 44, 45
MinorVersion integer 1, 2
0
MinorVersion string 12, 29
MissingCAPDNs string 1, 4, 5, 6
ModernSleepAppliedActionsBitmask string 0, 5, 7
ModernSleepEnabledActionsBitmask string 0, 5, 7
Module string 4, 22, 23, 46, 47
ModuleHandle string 22, 23, 46, 47
ModuleName string 3, 5, 6, 6, 8
MonitorMode string 8, 8
MonitorPowerOnTime string 0, 5, 7
MonitorReason integer 5, 6, 6
12
MonitorSession string 8, 8
NTStatus integer 3
NdisOid string 2, 5, 9
NdisStatus string 0, 2, 6
NdkEnabled string 44, 45
NetEvent string 38, 43, 149, 254
NetStatusCode string 4097, 4099
NewBias string 2, 2
NewLogFilePath string 2, 7
NewSchemeGuid string 12, 51
381B4222-F694-41F0-9685-FF5BB260DF2E
NewSize string 1, 5
NewTime string 1
2022-04-07 08:10:56.757996 UTC
NewValue string 1, 5, 5, 6, 6
NextSessionId integer 5, 6, 6
1
NextSessionType integer 5, 6, 6
0
NicFName string 5, 6, 7, 8, 13, 16, 17, 18, 19, 20, 21, 22, 23, 24, 29, 30, 31, 32, 33, 35, 61, 76, 77, 87, 96, 98, 99, 106, 113, 120, 122, 146, 147, 149, 150, 151, 190, 191, 192, 193, 197, 202, 203, 216, 232, 233, 236, 238, 243, 244, 254, 256, 257, 258, 259, 263, 265, 266, 269, 270, 276
NicFNameLen string 5, 6, 7, 8, 13, 16, 17, 18, 19, 20, 21, 22, 23, 24, 29, 30, 31, 32, 33, 35, 61, 76, 77, 87, 96, 98, 99, 106, 113, 120, 122, 146, 147, 149, 150, 151, 190, 191, 192, 193, 197, 202, 203, 216, 232, 233, 236, 238, 243, 244, 254, 256, 257, 258, 259, 263, 265, 266, 269, 270, 276
NicFriendlyName string 212, 213, 214
NicFriendlyNameLen string 212, 213, 214
NicIndex string 204, 205, 212, 213, 214, 215, 229
NicName string 5, 6, 7, 8, 13, 16, 17, 18, 19, 20, 21, 22, 23, 24, 29, 30, 31, 32, 33, 35, 61, 76, 77, 87, 96, 98, 99, 106, 113, 120, 122, 146, 147, 149, 150, 151, 190, 191, 192, 193, 197, 202, 203, 212, 213, 214, 216, 232, 233, 234, 235, 236, 238, 243, 244, 254, 256, 257, 258, 259, 263, 265, 266, 269, 270, 276
NicNameLen string 5, 6, 7, 8, 13, 16, 17, 18, 19, 20, 21, 22, 23, 24, 29, 30, 31, 32, 33, 35, 61, 76, 77, 87, 96, 98, 99, 106, 113, 120, 122, 146, 147, 149, 150, 151, 190, 191, 192, 193, 197, 202, 203, 212, 213, 214, 216, 232, 233, 234, 235, 236, 238, 243, 244, 254, 256, 257, 258, 259, 263, 265, 266, 269, 270, 276
NoMultiStageResumeReason string 1
Node string 22, 23, 46, 47
NominalFrequency string 5, 5
NonActivatedCpuInUs string 0, 5, 7
NonAttributedCpuInUs string 0, 5, 7
NonDripsTimeActivatedInUs string 0, 5, 7
NonPagedPoolTag_1 string 0, 0, 2, 4
NonPagedPoolTag_2 string 0, 0, 2, 4
NonPagedPoolTag_3 string 0, 0, 2, 4
NonPagedPoolUsage string 0, 0, 2, 4
NonPagedPoolUsed_1 string 0, 0, 2, 4
NonPagedPoolUsed_2 string 0, 0, 2, 4
NonPagedPoolUsed_3 string 0, 0, 2, 4
NonResiliencyTimeInUs string 0, 5, 7
NormalProcessId string 1, 2, 4
NotAffectedAtom string 1, 5, 6
NotAffectedRdclNo string 1, 5, 6
NotifyType string 1, 2
NtStatus string 0, 8
NumAttempts string 1001, 1002
NumBadPages string 1101, 1102, 1103, 1104
NumPagesTested string 1101, 1102, 1103, 1104
NumPagesUnTested string 1101, 1102, 1103, 1104
NumRootCauses string 1001, 1002
Number integer 26, 55
0
Number string 26, 33, 34, 35, 36, 37, 54, 55
NumberOfGroupPolicyObjects string 1502, 1503
NvgreEnabled string 0, 2, 3
OID string 16944, 16945, 16946, 16947
OSEditionID string 0, 0, 2, 4
ServerStandardEval
OSName string 0, 0, 2, 4
Windows Server 2022 Standard Evaluation
OS_EditionID string 0, 0, 2, 4
Professional
OS_Name string 0, 0, 2, 4
Windows 7 Professional
OS_build_version integer 0, 0, 2, 4
7600
OS_major_version integer 0, 0, 2, 4
6
OS_minor_version integer 0, 0, 2, 4
1
OS_service_pack_major_version integer 0, 0, 2, 4
0
OS_service_pack_minor_version integer 0, 0, 2, 4
0
OSbuildversion string 0, 0, 2, 4
OSmajorversion string 0, 0, 2, 4
OSminorversion string 0, 0, 2, 4
OSservicepackName string 0, 0, 2, 4
OSservicepackmajorversion string 0, 0, 2, 4
OSservicepackminorversion string 0, 0, 2, 4
ObjectName string 4, 132, 133, 513, 514, 515, 516, 519, 520, 521, 522
ObjectNameLength string 132, 133, 513, 514, 515, 516, 519, 520, 521, 522
ObjectSize string 4
OidFailureStatus string 2, 5, 9
OldBias string 2, 2
OldSchemeGuid string 12, 51
381B4222-F694-41F0-9685-FF5BB260DF2E
OldTime string 1
2022-04-07 08:10:56.760687 UTC
Opcode integer 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5782, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057
69
Opcode string 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 300, 301, 302, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1058, 1060, 1061, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2003, 2004, 2005, 2042, 4000, 4001, 4002, 4003, 4004, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5300, 6000, 6027, 6033, 6035, 6036, 6037, 6040, 6041, 6100, 6145, 6146, 6400, 7001, 7002, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 10000, 10001, 10002, 10003, 10004, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50037, 50038, 51047, 51057
Operation string 75, 76, 78, 80, 82, 92, 93, 100, 227, 233, 261, 16948
OperationType string 18, 19, 28, 29
OptionSelected string 1, 2
OptionalGUID string 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24643, 24645, 24652, 24653, 24654, 24657, 24658, 24659, 24672
OriginalSize string 1, 5
Outcome string 5, 5
OverThrottleThreshold string 1, 2, 5
Owner string 0, 1, 3, 6, 9
OwnerService string 9, 42, 43, 264
PCIXCommand string 24, 25, 42, 43
PID string 6036, 6037
PSCIState string 28, 29
Package string 5000, 6040, 45057
PagedPoolTag_1 string 0, 0, 2, 4
PagedPoolTag_2 string 0, 0, 2, 4
PagedPoolTag_3 string 0, 0, 2, 4
PagedPoolUsage string 0, 0, 2, 4
PagedPoolUsed_1 string 0, 0, 2, 4
PagedPoolUsed_2 string 0, 0, 2, 4
PagedPoolUsed_3 string 0, 0, 2, 4
Param1 string 10, 100, 101, 102
Param2 string 10, 100, 101, 102
Param3 string 10, 100, 101, 102
Param4 string 10, 100, 101, 102
Parameter string 414, 1004, 1005, 1007
Parameter1 string 1, 8
ParentHypervisorFlushes string 1, 5, 6
Participation string 6, 8, 10, 12, 14, 16, 17, 18, 19, 28, 29
PartitionId string 1, 2, 144, 145, 146, 148, 149
PccChanges string 3, 7
Peer string 22, 23, 51, 53
Pending string 1, 3
PerfStateCount integer 2, 6
0
PerfStateCount string 4, 26
PerformanceImplementation string 5, 5
Persisted string 1, 3
PersistentMemoryDiskGuid string 300, 301, 302
Phase string 63, 124
PhysicalAddress string 22, 23, 31, 46, 47
PhysicalAddressMask string 22, 23, 46, 47
PhysicalFaultAddress string 28, 29
PhysicalMemorySize string 0, 0, 2, 4
PhysicalMemoryUsage string 0, 0, 2, 4
Pid integer 9, 10
PlatformDirected string 1, 3
PlatformId string 1, 2
Policy string 1, 2, 9
Port1FName string 25, 28
Port1FNameLen string 25, 28
Port1Name string 25, 28
Port1NameLen string 25, 28
Port2FName string 25, 28
Port2FNameLen string 25, 28
Port2Name string 25, 28
Port2NameLen string 25, 28
PortFName string 12, 15, 17, 18, 32, 33, 34, 35, 46, 68, 70, 72, 73, 74, 75, 78, 82, 87, 88, 90, 92, 94, 95, 96, 98, 99, 119, 121, 127, 128, 129, 130, 232, 256, 257, 264
PortFNameLen string 12, 15, 17, 18, 32, 33, 34, 35, 46, 68, 70, 72, 73, 74, 75, 78, 82, 87, 88, 90, 92, 94, 95, 96, 98, 99, 119, 121, 127, 128, 129, 130, 232, 256, 257, 264
PortName string 12, 15, 17, 18, 32, 33, 34, 35, 46, 68, 70, 72, 73, 74, 75, 78, 82, 87, 88, 90, 92, 94, 95, 96, 98, 99, 119, 121, 127, 128, 129, 130, 232, 234, 235, 256, 257, 264
PortNameLen string 12, 15, 17, 18, 32, 33, 34, 35, 46, 68, 70, 72, 73, 74, 75, 78, 82, 87, 88, 90, 92, 94, 95, 96, 98, 99, 119, 121, 127, 128, 129, 130, 232, 234, 235, 256, 257, 264
PortType string 16, 17, 40, 41
PowerButtonTimestamp string 1, 4
PowerPolicyAction string 2, 4, 5
PowerPolicyBatteryLevel string 2, 4, 5
PowerPolicyEventCode string 2, 4, 5
PowerPolicyMinState string 2, 4, 5
PowerStateAc string 507, 566
true
PpcChanges string 7, 37
PrecisePC string 28, 29
PreviousEnergyCapacityAtEnd integer 5, 6, 6
50000
PreviousEnergyCapacityAtStart integer 5, 6, 6
50000
PreviousFullEnergyCapacityAtEnd integer 5, 6, 6
50000
PreviousFullEnergyCapacityAtStart integer 5, 6, 6
50000
PreviousSessionDurationInUs integer 5, 6, 6
1055562550
PreviousSessionId integer 5, 6, 6
0
PreviousSessionType integer 5, 6, 6
0
PrimaryDeviceName string 16, 17, 40, 41
PrimaryService string 20003, 20004
Problem string 0, 0, 1, 1, 1
Problems string 1, 2, 9
ProcessCommitCharge string 0, 0, 2, 4
ProcessID integer 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 300, 301, 302, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1058, 1060, 1061, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2003, 2004, 2005, 2042, 4000, 4001, 4002, 4003, 4004, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5300, 6000, 6027, 6033, 6035, 6036, 6037, 6040, 6041, 6100, 6145, 6146, 6400, 7001, 7002, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 10000, 10001, 10002, 10003, 10004, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50037, 50038, 51047, 51057
ProcessID string 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5782, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057
"976"
ProcessId integer 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5782, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057
976
ProcessId string 41, 97, 150, 225, 6400
ProcessNameLength string 2, 2, 5
ProcessPath string 12, 21, 51
C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.20348.557_none_f1edaeb8515fa10d\TiWorker.exe
ProcessPid integer 1, 2
1292
ProcessPid string 12, 51
Process_1_CommitCharge string 0, 0, 2, 4
Process_1_CreationTime string 0, 0, 2, 4
Process_1_HandleCount string 0, 0, 2, 4
Process_1_ID string 0, 0, 2, 4
Process_1_Name string 0, 0, 2, 4
Process_1_TypeInfo string 0, 0, 2, 4
Process_1_Version string 0, 0, 2, 4
Process_2_CommitCharge string 0, 0, 2, 4
Process_2_CreationTime string 0, 0, 2, 4
Process_2_HandleCount string 0, 0, 2, 4
Process_2_ID string 0, 0, 2, 4
Process_2_Name string 0, 0, 2, 4
Process_2_TypeInfo string 0, 0, 2, 4
Process_2_Version string 0, 0, 2, 4
Process_3_CommitCharge string 0, 0, 2, 4
Process_3_CreationTime string 0, 0, 2, 4
Process_3_HandleCount string 0, 0, 2, 4
Process_3_ID string 0, 0, 2, 4
Process_3_Name string 0, 0, 2, 4
Process_3_TypeInfo string 0, 0, 2, 4
Process_3_Version string 0, 0, 2, 4
Process_4_CommitCharge string 0, 0, 2, 4
Process_4_CreationTime string 0, 0, 2, 4
Process_4_HandleCount string 0, 0, 2, 4
Process_4_ID string 0, 0, 2, 4
Process_4_Name string 0, 0, 2, 4
Process_4_TypeInfo string 0, 0, 2, 4
Process_4_Version string 0, 0, 2, 4
Process_5_CommitCharge string 0, 0, 2, 4
Process_5_CreationTime string 0, 0, 2, 4
Process_5_HandleCount string 0, 0, 2, 4
Process_5_ID string 0, 0, 2, 4
Process_5_Name string 0, 0, 2, 4
Process_5_TypeInfo string 0, 0, 2, 4
Process_5_Version string 0, 0, 2, 4
Process_6_CommitCharge string 0, 0, 2, 4
Process_6_CreationTime string 0, 0, 2, 4
Process_6_HandleCount string 0, 0, 2, 4
Process_6_ID string 0, 0, 2, 4
Process_6_Name string 0, 0, 2, 4
Process_6_TypeInfo string 0, 0, 2, 4
Process_6_Version string 0, 0, 2, 4
ProcessingMode integer 1006, 1129, 1500, 1501, 1502, 1503
1
ProcessingMode string 1002, 1006, 1007, 1030, 1052, 1053, 1054, 1055, 1058, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1104, 1109, 1110, 1112, 1125, 1126, 1127, 1129, 1500, 1501, 1502, 1503
ProcessingTimeInMilliseconds integer 1006, 1129, 1500, 1501, 1502, 1503
94
ProcessingTimeInMilliseconds string 1002, 1006, 1007, 1030, 1052, 1053, 1054, 1055, 1058, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1104, 1109, 1110, 1112, 1125, 1126, 1127, 1129, 1500, 1501, 1502, 1503
Processor string 1, 2, 3, 4, 7
ProcessorIndex string 252, 253
ProductName string 1, 2
ProductVersion string 1, 2
ProgrammedWakeTimeAc string 0, 1, 7
ProgrammedWakeTimeDc string 0, 1, 7
PropertyId string 78, 80, 92, 93
ProtectorGUID string 513, 514, 515, 516, 517
Protocol string 130, 36874, 36880, 40960, 40962, 40965, 40966, 40967, 40969
ProtocolType string 4200, 4201, 4202
ProviderGUID string 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 300, 301, 302, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1058, 1060, 1061, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2003, 2004, 2005, 2042, 4000, 4001, 4002, 4003, 4004, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5300, 6000, 6027, 6033, 6035, 6036, 6037, 6040, 6041, 6100, 6145, 6146, 6400, 7001, 7002, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 10000, 10001, 10002, 10003, 10004, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50037, 50038, 51047, 51057
ProviderName string 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 300, 301, 302, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1058, 1060, 1061, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2003, 2004, 2005, 2042, 4000, 4001, 4002, 4003, 4004, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5300, 6000, 6027, 6033, 6035, 6036, 6037, 6040, 6041, 6100, 6145, 6146, 6400, 7001, 7002, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 10000, 10001, 10002, 10003, 10004, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50037, 50038, 51047, 51057
PtNicFName string 146, 147, 150, 151, 216, 259
PtNicFNameLen string 146, 147, 150, 151, 216, 259
PtNicName string 146, 147, 150, 151, 216
PtNicNameLen string 146, 147, 150, 151, 216
Publisher string 0, 0, 4, 6
PublisherGuid string 0, 3
QfeVersion string 1, 2
Qualifiers string 2, 3, 4, 13, 18, 26, 27, 28, 32, 35, 46, 48, 129, 153, 262, 285, 286, 289, 290, 379, 380, 381, 1001, 1007, 1056, 1074, 1500, 2001, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 7000, 7001, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 9009, 10005, 10010, 10016, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 24576, 24577, 24579
"7"
QueryName string 0, 1, 1, 4
wpad
QueueLimitMBytes string 252, 253
QueueMode string 106, 122
QueuePairs string 4, 9
QueueSizeMBytes string 252, 253
RankNumber string 22, 23, 46, 47
RawData string 1, 2, 3, 6, 8, 10, 12, 14, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 40, 41, 42, 43, 44, 45, 46, 47
RdmaWeight string 256, 257
ReadSize string 2, 3, 4, 4, 8
ReaderName string 1000, 1001
Reason integer 1, 172, 566
6
Reason string 1, 3, 5, 12, 14, 42, 172, 237, 506, 507, 508, 1002
ReasonPhrase string 7, 9
RebootOption string 20001, 20002
RebootTime string 0, 0, 0, 2, 9
RecordId string 1, 2
RecordNumber integer 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057
93485
Register string 48, 97
RelaxMinimumPasswordLengthLimits integer 1, 6, 7, 7, 9
0
RemainingCapacity string 0, 1, 5
RemainingPercentage string 2, 4, 5
RemainingRids string 1, 5, 6, 6, 8
RemoteAddr string 0, 9
RemoteAddrLen string 0, 9
RemoteAddress string 96, 98
RemoteAddressLength string 96, 98
RemoteCertSubjectName string 0, 3, 6, 8, 8
RemoteIPAddr string 0, 1, 3
RemoteIPAddrLen string 0, 1, 3
RemotePort string 0, 1, 3
RemotePortLen string 0, 1, 3
RemotePrefix string 0, 9
RemovedMemorySize string 1001, 1003
RepairData string 130, 131
RepairDataLength string 130, 131
RepairDetail string 130, 131
RepairGUID string 4000, 5000, 5100, 5200
RepairOption string 4000, 5000, 5100, 5200
RepairStatus string 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218
RequestHandled string 41, 42
RequestQueue string 7, 9
RequestType string 6, 8, 10, 12, 14, 16, 17, 18, 19
RequestedVlanIDs string 243, 244
RequesterId string 22, 23, 24, 25, 42, 43, 46, 47
Reservation string 82, 84, 100
Reserved1 string 1, 2
Reserved2 string 1, 2
ResetCount string 0, 0, 0, 1, 4
ResetEndStart string 0, 3
ResetReason string 0, 0, 0, 1, 4
ResetReasonMask string 1, 2, 4
ResiliencyDripsTimeInUs string 0, 5, 7
ResiliencyHwDripsTimeInUs string 0, 5, 7
ResponderId string 22, 23, 46, 47
RestartCount string 10111, 10112, 10115, 10116
RestartablePC string 28, 29
ResultCode string 401, 404, 405, 406, 407, 408, 409, 412, 413, 701, 702, 703, 704, 705, 716, 718
ResultHR string 4200, 5300
ResumeCount string 1, 1, 3
RetryMinutes integer 1, 3, 4
15
RetryMinutes string 14, 17, 18, 29, 48, 129, 130, 131, 132, 133, 134, 135, 136
RetryWaitTime string 0, 1, 3, 6, 9
Revision string 1, 2
RmDescription string 2
RmDescriptionLength string 2
RmId string 2, 11
RootCause string 4000, 5000, 5100, 5200
RootCauseGUID string 4000, 5000, 5100, 5200
RoutingDomainGuid string 1, 2, 9
RoutingDomainGuidLen string 1, 2, 9
RoutingDomainName string 1, 2, 9
RoutingDomainNameLen string 1, 2, 9
Row string 22, 23, 46, 47
RpcEndPointError string 0, 2, 8
RssQueueIndex string 0, 2, 6
RuleId string 4
RuleName string 0, 1, 2, 3
RunningMode string 1, 1, 2, 5
Classic
RunningState string 28, 29
SID string 0, 3, 5, 6
SIDTypeRequired string 4000, 5000, 5100, 5200
SampleData string 5, 5
SampleLength string 5, 5
ScenarioInstanceId string 506, 507
ScenarioInstanceIdV2 string 506, 507
ScheduleType string 1001, 1002, 1003
SchedulerType string 2
ScriptType string 0, 1, 1, 3
SecondaryBus string 16, 17, 40, 41
SecondaryDevice string 16, 17, 40, 41
SecondaryDeviceName string 16, 17, 40, 41
SecondaryFunction string 16, 17, 40, 41
SecondsRequired string 4000, 5000, 5100, 5200
Secret string 0, 2, 6, 7
SectionCount string 1, 2
SecurityPackage string 12302, 16398
Segment string 16, 17, 40, 41
SegmentNumber string 26, 27, 44, 45
SendStatus string 7, 9
Sent_UpdateServer string 0, 1, 8, 8
192.168.86.45:53
ServerName string 0, 0, 3, 4
ServerUrl string 0, 0, 3, 4
ServerVersion string 2, 6
ServerVersionLen string 2, 6
ServiceName integer 7009, 10005, 10111
50
ServiceName string 10, 1074, 7000, 7001, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 10001, 10002, 10010, 10016, 10117, 14200, 14201, 14202, 14203, 14204, 14205, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 20003, 20004
{4991D34B-80A1-4291-83B6-3328366B9097}
ServiceNameLength string 0, 1
ServiceType string 0, 4, 5, 7
user mode service
ServiceVersion string 1, 2
SettingType string 0, 2, 2, 4
SetupClass string 20001, 20002
Severity string 1, 2, 55
ShutdownActionType string 0, 1, 9
ShutdownEventCode string 0, 1, 9
ShutdownReason string 0, 1, 9
ShutdownTime string 86, 108
SigmaEventCode integer 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057
98
Signature string 1, 2, 55
SiloCommand string 1, 1
SiloStatus string 1, 1
SiteID integer 0, 0, 1, 7
2
SleepDuration string 1
SleepInProgress string 1, 4
false
SleepState string 1, 3, 7
SleepTime string 1
Slot string 16, 17, 40, 41
SmtEnabled string 1, 5, 6
SniHostname string 96, 98
SoftRestartCount string 1, 8
SourceFile string 55, 131, 134, 139, 140
SourceIdBus string 1, 8
SourceIdDev string 1, 8
SourceIdFun string 1, 8
SourceLine string 55, 131, 134, 139, 140
SourceTag string 55, 131, 134, 139, 140
SpareMemoryCount string 2, 2, 4
SpareMemorySize string 2, 2, 4
SparePath string 240, 241, 242
SpareProcessorCount string 2, 2, 4
SrcVPortId string 0, 2, 5
StartBias string 0, 1, 8
StartDeviceFailReason string 1, 4
StartOSImageStart string 0, 3
StartTime string 12, 1001, 1002
2021-11-09 21:42:16.500 UTC
StartType string 0, 4, 5, 7
demand start
State integer 1, 2, 7
2
State string 172, 8193
Stateful string 0, 1, 3
Status integer 1, 2, 3, 4, 5, 6, 8, 10, 11, 12, 13, 14, 15, 16, 17, 18, 20, 32, 34, 35, 37, 38, 39, 40, 41, 42, 43, 44, 45, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 82, 84, 96, 97, 100, 113, 116, 122, 124, 132, 149, 152, 153, 156, 190, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 217, 218, 219, 227, 235, 236, 238, 239, 241, 254, 256, 257, 258, 261, 267, 269, 276, 1003, 10110, 16976, 24832, 32780
0
StatusCode string 97, 1004, 1018, 50038
StopTime string 1, 3
2021-11-09 21:05:12.054501 UTC
StormLimit string 8, 8
String string 8, 9, 11, 1000, 19999
StringCount string 1, 1
SubKeyOrValueName string 0, 1, 4, 5, 6
SubjectDomainName string 0, 1, 4
SubjectUserName string 0, 1, 4
SubkeyName string 5
SubkeyNameLen string 5
SupportInfo1 integer 1006, 1129, 1500, 1501, 1502, 1503
1
SupportInfo1 string 1002, 1006, 1007, 1030, 1052, 1053, 1054, 1055, 1058, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1104, 1109, 1110, 1112, 1125, 1126, 1127, 1128, 1129, 1130, 1500, 1501, 1502, 1503
SupportInfo2 integer 1006, 1129, 1500, 1501, 1502, 1503
6191
SupportInfo2 string 1002, 1006, 1007, 1030, 1052, 1053, 1054, 1055, 1058, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1104, 1109, 1110, 1112, 1125, 1126, 1127, 1128, 1129, 1130, 1500, 1501, 1502, 1503
SuspendEnd string 0, 1, 3
SuspendStart string 0, 1, 3
SwitchFName string 9, 10, 11, 12, 14, 15, 17, 18, 32, 33, 34, 35, 41, 42, 43, 46, 63, 65, 68, 70, 72, 73, 74, 75, 78, 80, 82, 84, 88, 90, 92, 93, 94, 95, 97, 98, 99, 100, 106, 113, 119, 120, 121, 122, 127, 128, 129, 130, 132, 227, 232, 237, 239, 243, 244, 252, 253, 259, 260, 261, 264, 265, 266, 270
SwitchFNameLen string 9, 10, 11, 12, 14, 15, 17, 18, 32, 33, 34, 35, 41, 42, 43, 46, 63, 65, 68, 70, 72, 73, 74, 75, 78, 80, 82, 84, 88, 90, 92, 93, 94, 95, 97, 98, 99, 100, 106, 113, 119, 120, 121, 122, 127, 128, 129, 130, 132, 227, 232, 237, 239, 243, 244, 252, 253, 259, 260, 261, 264, 265, 266, 270
SwitchFriendlyName string 206, 207, 208, 209, 210, 211, 212, 213, 214, 229, 230
SwitchFriendlyNameLen string 206, 207, 208, 209, 210, 211, 212, 213, 214, 229, 230
SwitchName string 9, 10, 11, 12, 14, 15, 17, 18, 32, 33, 34, 35, 41, 42, 43, 46, 63, 65, 68, 70, 72, 73, 74, 75, 78, 80, 82, 84, 88, 90, 92, 93, 94, 95, 97, 98, 99, 100, 106, 113, 119, 120, 121, 122, 127, 128, 129, 130, 132, 206, 207, 208, 209, 210, 211, 212, 213, 214, 227, 229, 230, 232, 237, 239, 243, 244, 252, 253, 260, 261, 264, 265, 266, 270
SwitchNameLen string 9, 10, 11, 12, 14, 15, 17, 18, 32, 33, 34, 35, 41, 42, 43, 46, 63, 65, 68, 70, 72, 73, 74, 75, 78, 80, 82, 84, 88, 90, 92, 93, 94, 95, 97, 98, 99, 100, 106, 113, 119, 120, 121, 122, 127, 128, 129, 130, 132, 206, 207, 208, 209, 210, 211, 212, 213, 214, 227, 229, 230, 232, 237, 239, 243, 244, 252, 253, 260, 261, 264, 265, 266, 270
SystemAction string 1, 7, 8
SystemAssignedAccountName string 0, 1, 2, 3, 4
SystemCommitCharge string 0, 0, 2, 4
SystemCommitLimit string 0, 0, 2, 4
SystemSleepTransitionsToOn string 1, 4
SystemTime string 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057
'2022-07-28 14:13:42.451381 UTC'
SystemTimeChangeSeconds integer 3, 4
21
SystemTimeChangeSeconds string 33, 34
System_Props_Xml string 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057
        129    0    3    0    0    0x80000000000000            340                    System    DESKTOP-6D0DBMB        
T10NumBadPages string 1101, 1102, 1103, 1104
T11NumBadPages string 1101, 1102, 1103, 1104
T12NumBadPages string 1101, 1102, 1103, 1104
T13NumBadPages string 1101, 1102, 1103, 1104
T14NumBadPages string 1101, 1102, 1103, 1104
T15NumBadPages string 1101, 1102, 1103, 1104
T16NumBadPages string 1101, 1102, 1103, 1104
T1NumBadPages string 1101, 1102, 1103, 1104
T2NumBadPages string 1101, 1102, 1103, 1104
T3NumBadPages string 1101, 1102, 1103, 1104
T4NumBadPages string 1101, 1102, 1103, 1104
T5NumBadPages string 1101, 1102, 1103, 1104
T6NumBadPages string 1101, 1102, 1103, 1104
T7NumBadPages string 1101, 1102, 1103, 1104
T8NumBadPages string 1101, 1102, 1103, 1104
T9NumBadPages string 1101, 1102, 1103, 1104
TCGInvokingID string 1, 1
TCGMethodID string 1, 1
TLBOperationType string 28, 29
TPM_PT_FIRMWARE_VERSION_1 string 2, 7
TPM_PT_FIRMWARE_VERSION_2 string 2, 7
TPM_PT_MANUFACTURER string 2, 7
TPM_PT_VEDNOR_STRING_2 string 2, 7
TPM_PT_VEDNOR_STRING_3 string 2, 7
TPM_PT_VEDNOR_STRING_4 string 2, 7
TPM_PT_VEDNOR_TPM_TYPE string 2, 7
TPM_PT_VENDOR_STRING_1 string 2, 7
TSId string 7001, 7002
TableIndex string 0, 1, 5
TargetAffinity string 2, 2, 4
TargetDomain string 32773, 32774, 32775
TargetId string 22, 23, 24, 25, 42, 43, 46, 47
TargetMemoryCount string 2, 2, 4
TargetMemorySize string 2, 2, 4
TargetName string 6037, 6040, 6041, 36880, 36888
TargetPath string 240, 241, 242
TargetProcessorCount string 2, 2, 4
TargetRunLevel string 13, 14, 15, 16
TargetState string 1, 42, 107
TargetVersion string 0, 1, 4, 6
TaskName string 1, 4, 4
TaskProcessID string 2, 11
TaskType string 1, 5, 6, 10, 14, 15
TeamingMode string 206, 207, 208, 209, 210, 211
TeredoReasonCode string 0, 0, 1, 4
TestCount string 1101, 1102, 1103, 1104
TestDuration string 1101, 1102, 1103, 1104
TestType string 1101, 1102, 1103, 1104
ThermalZoneDeviceInstance string 86, 88, 89, 125
ThermalZoneDeviceInstanceLength string 86, 88, 89, 125
ThreadCount string 7, 9
ThreadID string 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 201, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 262, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 285, 286, 289, 290, 300, 301, 302, 379, 380, 381, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 566, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1025, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1056, 1058, 1060, 1061, 1065, 1068, 1074, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1281, 1282, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2001, 2003, 2004, 2005, 2042, 3261, 4000, 4001, 4002, 4003, 4004, 4005, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5202, 5203, 5211, 5300, 5774, 5782, 5823, 6000, 6005, 6006, 6009, 6011, 6013, 6027, 6033, 6035, 6036, 6037, 6038, 6040, 6041, 6100, 6145, 6146, 6148, 6400, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 9009, 10000, 10001, 10002, 10003, 10004, 10005, 10010, 10016, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10121, 10148, 10149, 10154, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14206, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 14531, 14533, 15007, 15008, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16647, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 16983, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 20010, 24576, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50036, 50037, 50038, 50103, 50104, 50105, 50106, 51046, 51047, 51057
"956"
ThreadId integer 7, 9
ThrottleStateCount integer 2, 6
0
ThrottleStateCount string 4, 26
Thumbprint string 96, 98, 516, 517, 518
ThumbprintLength string 96, 98
TimeDifferenceMilliseconds string 0, 5
TimeDifferenceSeconds string 1, 5
TimeOffsetSeconds string 2, 5
TimeProvider string 1, 2, 3, 4, 5, 7, 8, 9, 10, 40, 43, 158
TimeQuiesced string 2, 2, 4
TimeRemainingToSetLocalClockFreeRunningSeconds string 3, 6
TimeSampleSeconds string 0, 5
TimeSource string 34, 35, 37, 38, 132, 135
time.windows.com,0x8 (ntp.m
TimeSourceRefId string 3, 5
TimeStamp string 0, 4, 5, 5, 8
TimeToQuiesce string 2, 2, 4
TimeToWake string 2, 2, 4
TimeTotal string 2, 2, 4
TimeZoneInfoCacheUpdated integer 2, 4
0
Timeout string 18, 19, 28, 29
Timestamp string 1, 2
TimestampForced string 0, 1, 8
Title string 16385, 16386, 16390
PreSignInSettingsConfigJSON
TmId string 1, 1
TmIdentity string 3, 4
TmLogFileName string 3, 4
TmLogFileNameLength string 3, 4
ToolsCount string 1, 9
TotalProcesses string 0, 0, 2, 4
TpcChanges string 7, 37
TpmCommandOrdinal string 1, 7
TpmResponseCode string 1, 7
TransactionType string 6, 8, 10, 12, 14, 16, 17, 18, 19, 28, 29
TransitionStartTime string 1, 8
TransitionsToOn string 2, 4
TransmissionDelayMilliseconds string 1, 5
TriggerID string 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15
TrustletIdentity string 1, 2, 4
TryComplete string 1, 2, 4
Turn string 2, 2
TxDescription string 1, 2, 3, 4
TxDescriptionLength string 1, 2, 3, 4
TxUow string 1, 2, 3, 4
TxtStatus string 2, 2, 2
URL string 1, 3, 3, 4, 5
UncorrectableErrorStatus string 16, 17, 18, 40, 41
Uncorrected string 1, 3
UniqueEvent string 4, 6, 8, 10, 11, 12, 13, 14, 15, 16, 18, 20, 32, 34, 35, 41, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 132, 190, 235, 236, 238, 239, 258, 269, 276
UniqueEventValue string 4, 15
UnitBaseAddress string 1, 4, 8
UnsynchronizedTimeSeconds string 3, 6
UpdateDllName string 6, 8
UpdateReason string 0, 2
UpdateService string 20003, 20004
UpdateType string 0, 2, 2, 4
Upgrade string 10001, 10002
UpgradeDevice string 20001, 20002
Url string 97, 15007, 15008
http://+:3387/rdp/
UrlPrefix string 0, 0, 1, 7
http://*:80/
UserData_Xml string 104, 1001, 1121, 1206, 1208, 10000, 10001, 10100, 20001, 20003, 20010
      WpdFs      112DE495-AC4C-46F8-B663-6A4266C53313      2.33.0      false    
UserID string 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 201, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 300, 301, 302, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 566, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1025, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1058, 1060, 1061, 1065, 1068, 1074, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1281, 1282, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2003, 2004, 2005, 2042, 4000, 4001, 4002, 4003, 4004, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5300, 6000, 6027, 6033, 6035, 6036, 6037, 6040, 6041, 6100, 6145, 6146, 6148, 6400, 7001, 7002, 7040, 7042, 7045, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 10000, 10001, 10002, 10003, 10004, 10005, 10010, 10016, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16647, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 16983, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 20010, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50036, 50037, 50038, 50103, 50104, 50105, 50106, 51046, 51047, 51057
"S-1-5-21-582766833-432816504-4207985818-1009"
UserName string 12294, 12302, 16385, 16400, 16406, 45058
UserSID string 21, 23
UserSid string 7001, 7002
S-1-5-21-1103654211-1238870038-1204021333-1002
Username string 0, 4, 5, 5, 7
VMId string 26, 61, 102
VMIdLen string 26, 61, 102
VMName string 26, 33, 61, 102
VMNameLen string 26, 33, 61, 102
VMQOffloadWeight string 4, 9
ValidBatteryCount string 1, 2, 5
ValidBits string 16, 17, 22, 23, 24, 25, 26, 27, 40, 41, 42, 43, 44, 45, 46, 47
ValidationBits string 1, 2
Value string 6, 7, 10113
Vcb string 143, 144
VendorID string 16, 17, 40, 41
VendorId string 26, 27, 44, 45
Verb string 55, 97, 99
Verbosity string 7, 9
Version integer 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5782, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057
2
Version string 1, 2, 16, 17, 40, 41, 219
VersionLen integer 1
3
VersionLen string 1, 2
VersionSupported string 0, 4
VfAdapterName string 41, 42, 46, 47, 48
\DEVICE{651F97F9-A838-4081-A596-E6A86FBB1145}
VfAdapterNameLen integer 4, 6
46
VfAdapterNameLen string 41, 42, 46, 47, 48
VirtualFaultAddress string 28, 29
VirtualSubnetId string 88, 130
VlanID string 1, 7, 9
VlanId string 0, 2, 4
VmqIndex string 0, 2, 6
VmqSumOfQueues string 206, 207, 208, 209, 210, 211
Volume string 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686
VolumeGUID string 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 823, 824, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24643, 24645, 24652, 24653, 24654, 24657, 24658, 24659, 24672
VolumeGuid string 143, 144, 150
VolumeId string 130, 131, 134, 135, 136, 137, 138, 139, 140, 210, 211, 517, 518
VolumeIdLength string 130, 131, 134, 135, 136, 137, 138, 139, 140, 517, 518
VolumeLabel string 1, 3, 4
VolumeLabelLength string 1, 3, 4
VolumeName string 143, 144, 150, 1206
VolumeNameLength string 143, 144, 150, 1206
VolumeNames string 1
VportsSupported string 204, 205, 215
VsmPolicy integer 1, 3, 5
0
VsmPolicy string 153, 156
VxLanEnabled string 0, 2, 3
WDFDEVICE string 0, 0, 1, 3
WakeDuration string 1
WakeFromState string 0, 1, 7
WakeRequesterTypeAc string 0, 1, 7
WakeRequesterTypeDc string 0, 1, 7
WakeSourceText string 1
WakeSourceTextLength string 1
WakeSourceType string 1
WakeTime string 1
WakeTimerContext string 1
WakeTimerContextLength string 1
WakeTimerOwner string 1
WakeTimerOwnerLength string 1
Weight string 82, 84, 100, 130
Win32Err integer 2
WinError string 12295, 12296
WorkingSetSize string 7, 9
WritePhase string 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686
binaryData string 36867, 36869
body string 2, 6
The application was unable to start correctly (0xc0000142). Click OK to close the application.
certificateContext string 36881, 36882, 36883, 36884
currentLimit string 16397, 16398, 16400, 16401, 16402
currentSize string 16397, 16398, 16400, 16401, 16402
dest string 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057
win10-base
dvc string 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057
win10-base
dvc_nt_host string 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057
win7-x86
entityName string 16397, 16398, 16400, 16401, 16402
error integer 0, 1, 1, 4, 5
1355
errorCode string 20, 24, 213
0x8024200b
event_id integer 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057
93485
evtAdditionalInfo string 1
evtErrorId string 1
evtHiveName string 1, 2
evtHiveNameLength string 1, 2
evtStatus string 1, 3, 4
failureReason string 37, 38, 39, 43
fid_DripsWatchdogResult string 195, 196
fid_UcxController string 1, 4
fid_UsbDevice string 195, 196
fid_bcdDevice string 195, 196
fid_idProduct string 195, 196
fid_idVendor string 195, 196
filename string 24840, 24841
function string 0, 1, 4, 4, 6
locationCode string 2, 12, 14, 15, 16, 17, 18, 19, 20, 22, 25, 26, 27
0x140000d6
offset string 24840, 24841
pCertificateContext string 36876, 36877, 36878, 36879
param1 integer 7009, 10005, 10111
50
param1 string 1074, 7000, 7001, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 10010, 10016
{4991D34B-80A1-4291-83B6-3328366B9097}
param10 string 0, 0, 1, 1, 6
Unavailable
param11 string 0, 0, 1, 1, 6
Unavailable
param2 integer 7031, 7034, 7039
5748
param2 string 1074, 7000, 7001, 7009, 7023, 7024, 7036, 7038, 7040, 7042, 10005, 10016
stopped
param3 integer 7031, 7039
30000
param3 string 1074, 7001, 7038, 7040, 7042, 10005, 10016
demand start
param4 integer 0, 1, 3, 7
1
param4 string 1074, 7040, 7042, 10005, 10016
Windows.SecurityCenter.SecurityAppBroker
param5 string 1074, 7031, 7042, 10016
restart
param6 string 1074, 10016
Reboot initiated by Ansible
param7 string 1074, 10016
SYSTEM
param8 string 0, 0, 1, 1, 6
S-1-5-18
param9 string 0, 0, 1, 1, 6
LocalHost (Using LRPC)
restarttime string 2, 2
schedinstalldate string 1, 8
schedinstalltime string 1, 8
serverName string 32, 33
serviceGuid string 19, 20, 23, 24, 212
9482F4B4-E343-43B6-B170-9A65BC822C77
service_name integer 7009, 10005, 10111
50
service_name string 1074, 7000, 7001, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 10010, 10016, 14204, 14205
{4991D34B-80A1-4291-83B6-3328366B9097}
sigma_product string 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057
windows
sigma_service string 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057
system
signature string 19, 20, 43, 44, 519, 566
Security Intelligence Update for Microsoft Defender Antivirus - KB2267602 (Version 1.353.706.0)
signature_id integer 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057
98
spn1 string 0, 1, 1, 4, 5
WSMAN/WIN-FPV0DSIC9O6.sigma.fr
spn2 string 0, 1, 1, 4, 5
WSMAN/WIN-FPV0DSIC9O6
start_mode string 7040, 7045
manual
statusActive string 2, 4
statusEnabled string 2, 4
string string 19, 17005
string2 string 0, 0, 1, 5, 7
string3 string 0, 0, 1, 5, 7
subject string 519, 566
Object Operation (W3 Active Directory)
timeendpos integer 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057
594
timestartpos integer 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057
564
updateGuid string 19, 20, 23, 24, 43, 44, 212, 213, 214, 215
6CE0FD31-E410-43E3-AACA-EDD43C217639
updateRevisionNumber integer 19, 20, 43, 44
200
updateRevisionNumber string 19, 20, 23, 24, 43, 44, 212, 213, 214, 215
updateTitle string 19, 20, 23, 43, 44, 212, 214, 215
Security Intelligence Update for Microsoft Defender Antivirus - KB2267602 (Version 1.353.706.0)
updatelist string 17, 18, 21, 22, 24, 213
user_id string 1, 3, 5, 6, 10, 11, 12, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 50, 52, 55, 98, 104, 134, 137, 139, 143, 153, 172, 201, 206, 238, 519, 521, 566, 1001, 1006, 1014, 1025, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2003, 2004, 6148, 7001, 7002, 7040, 7042, 7045, 8018, 10000, 10001, 10005, 10010, 10016, 10100, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057
"S-1-5-21-582766833-432816504-4207985818-1009"
vPortId string 204, 215
vendor string 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057
Microsoft
vendor_product string 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057
Microsoft Windows
volume string 2, 3, 4, 5, 8
wimFile string 24837, 24838, 24839, 24843, 24844, 24845, 24846
wimHashFile string 24837, 24838, 24839, 24843, 24844, 24845, 24846

taskscheduler

Field Data Type Event IDs Example
Account string 1, 1, 7
Command string 310, 311
Computer string 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717
win-dc-469.attackrange.local
EventID integer 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717
330
Name string 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 330, 332, 400, 402, 700
'Microsoft-Windows-TaskScheduler'
Path string 1, 2, 9
%windir%\system32\wermgr.exe
Task integer 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330
330
Task string 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717
id integer 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 330, 332, 400, 402, 700
5404
ActionName string 200, 201, 202, 203
NGC Pregeneration Task Handler
ActivityID string 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 330, 332, 400, 402, 700
'{7AD1452B-31A1-4664-BAD4-57539A029944}'
Channel string 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717
Microsoft-Windows-TaskScheduler/Operational
Context string 0, 1, 5
CurrentQuota string 131, 132
EnginePID string 200, 201, 202
ErrorDescription string 104, 303, 311, 403
EventCode integer 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 330, 332, 400, 402, 700
330
EventData_Xml string 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330
\Run NotepadATTACKRANGE\Administrator{7AD1452B-31A1-4664-BAD4-57539A029944}
EventRecordID integer 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 330, 332, 400, 402, 700
5404
Guid string 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 330, 332, 400, 402, 700
'{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}'
InstanceId string 100, 102, 103, 107, 108, 109, 110, 111, 114, 117, 118, 119, 120, 121, 122, 123, 124, 125
{7AD1452B-31A1-4664-BAD4-57539A029944}
Keywords string 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717
0x8000000000000001
Level integer 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717
4
LogPoint string 1, 1, 5
Message string 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 403, 410, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717
NewTaskInstanceId string 2, 3, 3
Opcode integer 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330
2
Opcode string 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717
Priority string 1, 2, 9
ProcessID string 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717
'1316'
ProcessId integer 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330
1816
ProviderGUID string 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717
ProviderName string 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717
QueuedTaskInstanceId string 324, 325
5F6009CF-535A-456B-B1EB-0B7C5C30AABF
RecordNumber integer 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 330, 332, 400, 402, 700
5404
RelatedActivityID string 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 332, 400, 402, 700
ResultCode integer 103, 201, 202
2148073520
ResultCode string 101, 103, 104, 105, 113, 115, 116, 126, 130, 146, 148, 150, 151, 201, 202, 203, 204, 205, 303, 305, 306, 307, 311, 315, 316, 331, 403, 410, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717
RunningTaskInstanceId string 2, 3, 4
EC1D2D19-D309-4577-A40D-0FB4CE6B479C
SecurityDescriptor string 0, 7, 8
SessionId string 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 332, 400, 402, 700
SigmaEventCode integer 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330
330
StoppedTaskInstanceId string 2, 3, 3
SystemTime string 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 330, 332, 400, 402, 700
'2022-06-28 15:11:04.524776 UTC'
System_Props_Xml string 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330
2001420010x800000000000000013961Microsoft-Windows-TaskScheduler/Operationalwin-dc-469.attackrange.local
TaskCount string 0, 3, 9
TaskEngineName string 133, 134, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320
TaskInstanceId string 200, 201, 202, 203, 304, 320, 322, 327, 328, 329, 330, 331
{7AD1452B-31A1-4664-BAD4-57539A029944}
TaskName string 100, 101, 102, 103, 106, 107, 108, 109, 110, 111, 112, 113, 114, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 133, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 200, 201, 202, 203, 204, 205, 304, 305, 319, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 706, 707, 708, 709, 713, 714
\Run Notepad
TaskPath string 1, 5, 5
TaskStatus string 0, 6, 7
ThreadID string 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717
'5004'
UserContext string 100, 101, 102, 103, 106, 110, 330
System
UserID string 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717
'S-1-5-18'
UserName string 104, 119, 120, 121, 122, 123, 124, 125, 133, 134, 140, 141, 142, 332
SNAPATTACK\snapattack
Version integer 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 330, 332, 400, 402, 700
2
dvc string 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 330, 332, 400, 402, 700
win-dc-469.attackrange.local
dvc_nt_host string 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330
win-dc-469.attackrange.local_0d8ffca2-620a-4526-a4de-aef022b9dd48
event_id integer 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330
5404
sigma_product string 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330
windows
sigma_service string 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330
taskscheduler
signature_id integer 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330
330
timeendpos integer 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330
521
timestartpos integer 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330
491
user_id string 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330
'S-1-5-18'
vendor_product string 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330
Microsoft Windows

wmi

Field Data Type Event IDs Example
EventID integer 5857, 5858, 5859, 5860, 5861
5861
Name string 5857, 5858, 5859, 5860, 5861
Microsoft-Windows-WMI-Activity
ProcessName string 5858, 5860
'wsmprovhost.exe'
AND_TargetInstance_Minute integer 5859, 5861
33
AND_TargetInstance_Second integer 5859, 5861
0
ActivityID string 5857, 5858, 5859, 5860, 5861
B9A944CA-4FFF-0000-E056-A9B9FF4FD801
Category integer 1, 5, 6, 8
0
CommandLineEventConsumer string 1, 5, 6, 8
AtomicRedTeam-WMIPersistence-Example
CommandLineTemplate string 1, 5, 6, 8
C:\Windows\System32\notepad.exe
CreatorSID string 1, 5, 6, 8
{1, 2, 0, 0, 0, 0, 0, 5, 32, 0, 0, 0, 32, 2, 0, 0}
EventCode integer 5857, 5858, 5859, 5860, 5861
5861
EventNamespace string 1, 5, 6, 8
root\cimv2
Guid string 5857, 5858, 5859, 5860, 5861
1418EF04-B0B4-4623-BF7E-D74AB47BBDAA
NTEventLogEventConsumer string 1, 5, 6, 8
SCM Event Log Consumer
NameOfUserSIDProperty string 1, 5, 6, 8
sid
OR_TargetInstance_DayOfWeek integer 5859, 5861
2
ProcessID integer 5857, 5858, 5859, 5860, 5861
4168
ProcessId integer 5857, 5858, 5859, 5860, 5861
4168
Query string 1, 5, 6, 8
select * from MSFT_SCMEventLogEvent
QueryLanguage string 1, 5, 6, 8
WQL
RunInteractively string 1, 5, 6, 8
FALSE
SigmaEventCode integer 5857, 5858, 5859, 5860, 5861
5861
SourceName string 1, 5, 6, 8
Service Control Manager
SystemTime string 5857, 5858, 5859, 5860, 5861
'2022-07-05 18:43:00.611527 UTC'
TargetInstance_DayOfWeek integer 5859, 5861
1
TargetInstance_Hour integer 5859, 5861
11
TargetInstance_Minute integer 5859, 5861
30
TargetInstance_Second integer 1, 5, 6, 8
40
TargetInstance_Second string 5, 5, 8, 9
40
ThreadID integer 5857, 5858, 5859, 5860, 5861
9020
UserID string 5857, 5858, 5859, 5860, 5861
S-1-5-18
sigma_product string 5857, 5858, 5859, 5860, 5861
windows
sigma_service string 5857, 5858, 5859, 5860, 5861
wmi
timeendpos integer 5857, 5858, 5859, 5860, 5861
518
timestartpos integer 5857, 5858, 5859, 5860, 5861
488
xmlns string 5857, 5858, 5859, 5860, 5861
http://schemas.microsoft.com/win/2004/08/events/event