Windows
application
| Field | Data Type | Event IDs | Example |
|---|---|---|---|
| Application | string | 1, 2 | |
| Computer | string | 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 15, 16, 17, 18, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 38, 43, 45, 47, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 256, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 637, 641, 642, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 781, 852, 854, 865, 866, 867, 868, 873, 882, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1010, 1012, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1041, 1042, 1043, 1044, 1061, 1066, 1109, 1114, 1130, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1511, 1512, 1514, 1515, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 1704, 1903, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2080, 2303, 2484, 2486, 3001, 3002, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4121, 4128, 4129, 4176, 4177, 4178, 4202, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 4879, 5000, 5001, 5008, 5602, 5604, 5605, 5606, 5611, 5612, 5615, 5617, 5631, 5973, 6000, 6003, 6253, 6527, 7000, 7002, 8192, 8193, 8194, 8195, 8196, 8198, 8199, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 8303, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | windowsvictim |
| Event | string | 1, 3, 4, 5 | |
| EventID | integer | 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 15, 16, 17, 18, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 38, 43, 45, 47, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 256, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 637, 641, 642, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 781, 852, 854, 865, 866, 867, 868, 873, 882, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1010, 1012, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1041, 1042, 1043, 1044, 1061, 1066, 1109, 1114, 1130, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1511, 1512, 1514, 1515, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 1704, 1903, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2080, 2303, 2484, 2486, 3001, 3002, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4121, 4128, 4129, 4176, 4177, 4178, 4202, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 4879, 5000, 5001, 5008, 5602, 5604, 5605, 5606, 5611, 5612, 5615, 5617, 5631, 5973, 6000, 6003, 6253, 6527, 7000, 7002, 8192, 8193, 8194, 8195, 8196, 8198, 8199, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 8303, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 9689 |
| File | string | 1508, 1509, 1514, 10002, 10003, 10006, 10007 | C:\Users\user2\ntuser.dat |
| FileName | string | 1, 10009 | |
| Name | string | 0, 1, 2, 3, 4, 5, 11, 13, 15, 16, 26, 30, 32, 34, 35, 38, 45, 47, 48, 63, 64, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 637, 641, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1552, 1704, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5000, 5001, 5008, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | "edgeupdate" |
| Object | string | 4, 8 | |
| Path | string | 0, 5, 9 | |
| Service | string | 1008, 1020, 10009 | BITS |
| Source | string | 1509, 1600, 1601 | |
| Target | string | 1509, 1600, 1601 | |
| Task | integer | 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 9 |
| Task | string | 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 15, 16, 17, 18, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 38, 43, 45, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 92, 100, 101, 102, 103, 105, 198, 200, 256, 257, 300, 301, 302, 326, 330, 335, 455, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 641, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 865, 866, 867, 868, 882, 900, 902, 903, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1010, 1012, 1013, 1020, 1022, 1025, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1041, 1042, 1043, 1044, 1066, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1512, 1514, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 1704, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2484, 2486, 3001, 3002, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4128, 4129, 4176, 4177, 4178, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 5000, 5001, 5008, 5602, 5604, 5605, 5606, 5612, 5615, 5617, 5631, 5973, 6000, 7000, 7002, 8192, 8194, 8199, 8212, 8216, 8224, 8225, 8300, 8301, 8302, 8303, 9027, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 11707, 11728, 11756, 12116, 16384, 16390, 16394, 20221, 20222, 20223, 20224, 20225, 20226 | |
| Text | string | 81, 82, 83 | |
| User | string | 5 | WINDEV2202EVAL\user2 |
| action | string | 642, 4879 | unknown |
| file | string | 3 | |
| hr | string | 27, 28, 29, 31, 33, 34 | |
| id | integer | 0, 1, 2, 3, 4, 5, 11, 13, 15, 16, 26, 30, 32, 34, 35, 38, 45, 47, 48, 63, 64, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 637, 641, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1552, 1704, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5000, 5001, 5008, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 9617 |
| line | string | 3 | |
| name | string | 637, 641, 642, 852, 4625, 4879 | User Account Changed |
| status | string | 4, 7, 8, 9 | unknown |
| ActivityID | string | 64, 900, 902, 903, 1003, 1004, 1008, 1013, 1020, 1033, 1034, 1040, 1066, 1531, 1532, 1552, 4097, 4109, 4111, 4625, 5611, 5615, 5617, 6000, 8224, 8300, 8301, 8302, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 16384, 16390, 16394 | "9AEFBC8D-3E49-4448-B988-5F313E7F68B0" |
| AdditionalDetails | string | 1 | |
| AddonName | string | 1, 2 | |
| AppId | string | 3, 5, 7, 9 | |
| AppName | string | 1, 2, 3, 10001, 10002 | |
| AppNameCount | string | 1, 2, 3 | |
| AppType | string | 10002, 10003, 10006, 10007, 10010 | |
| AppVersion | string | 10002, 10003, 10006, 10007, 10010 | |
| ApplicationId | string | 5, 5, 6 | |
| ApplicationName | string | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11 | C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted |
| ApplicationPool | string | 0, 2, 3, 3 | MSExchangeOABAppPool |
| Applications | string | 0, 0, 0, 1, 5 | |
| AttemptedPath | string | 50, 865, 866, 867, 868, 882 | |
| AuthorId | string | 2001, 2002, 3002 | |
| BackupFailureLogPath | string | 4, 5, 7 | |
| BackupFile | string | 67, 68, 5602 | |
| BackupRepository | string | 66, 5604 | |
| BackupSourceNumUnreadableBytes | string | 2, 5, 5 | |
| BackupTarget | string | 2, 3, 5 | |
| BackupTargetFriendlyName | string | 522, 564, 658 | |
| BackupTargetList | string | 608, 609, 611 | |
| BackupTime | string | 517, 518, 519, 521, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611 | |
| BackupUserName | string | 4, 5, 6 | |
| BufferSize | integer | 0, 0, 1, 2 | |
| CVEID | string | 1 | |
| Caption | string | 81, 82, 83 | |
| CatalogName | string | 1, 1, 2, 4 | SystemIndex |
| CategoryString | string | 637, 641, 642 | Account Management |
| Channel | string | 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 15, 16, 17, 18, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 38, 43, 45, 47, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 256, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 637, 641, 642, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 781, 852, 854, 865, 866, 867, 868, 873, 882, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1010, 1012, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1041, 1042, 1043, 1044, 1061, 1066, 1109, 1114, 1130, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1511, 1512, 1514, 1515, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 1704, 1903, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2080, 2303, 2484, 2486, 3001, 3002, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4121, 4128, 4129, 4176, 4177, 4178, 4202, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 4879, 5000, 5001, 5008, 5602, 5604, 5605, 5606, 5611, 5612, 5615, 5617, 5631, 5973, 6000, 6003, 6253, 6527, 7000, 7002, 8192, 8193, 8194, 8195, 8196, 8198, 8199, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 8303, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | Application |
| Class | string | 24, 25, 58, 59, 5631 | |
| Component | string | 1, 3, 4, 5 | |
| ComponentName | string | 5, 5, 6 | |
| ContentType | string | 1 | |
| Context | string | 64, 86 | Système local |
| CurDirDllPath | string | 11, 12 | |
| DBType | string | 1, 2, 3 | |
| Detail | string | 0, 1, 3, 5 | 1 user registry handles leaked from \Registry\User\S-1-5-21-712794737-353456615-3249761964-1001: |
| DisplayName | string | 10002, 10003, 10006, 10007, 10010 | |
| Error | string | 4, 10, 11, 12, 13, 22, 43, 48, 68, 502, 513, 515, 517, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1512, 1519, 1520, 1521, 1522, 1523, 1533, 1534, 1537, 1538, 1539, 1541, 1542, 3001, 5604 | The process cannot access the file because it is being used by another process. |
| ErrorCode | string | 9, 86, 502, 517, 518, 519, 521, 526, 527, 528, 544, 546, 565, 707, 708, 722, 723, 738, 739, 770, 773, 774, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1010, 1012, 1041, 1042, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 5973, 8301, 8302, 8303 | Non trouvé (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND) |
| ErrorDetails | string | 502, 503, 505, 506, 507, 508, 509, 511, 513, 515, 517 | |
| ErrorMessage | string | 517, 518, 519, 521, 527, 528, 544, 546, 707, 708, 722, 723, 738, 739, 770, 773, 774, 1041, 1042 | |
| ErrorMsg | string | 1002, 1003, 1004, 1005, 1006, 1007, 1010, 1012 | |
| ErrorNumber | string | 28, 29 | |
| ErrorString | string | 10, 11, 12 | |
| Error_Code | integer | 0, 1, 5, 9 | 3221225539 |
| Error_Code | string | 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | - |
| EventCode | integer | 0, 1, 2, 3, 4, 5, 11, 13, 15, 16, 26, 30, 32, 34, 35, 38, 45, 47, 48, 63, 64, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 637, 641, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1552, 1704, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5000, 5001, 5008, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 9689 |
| EventData_Xml | string | 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1530, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | mardi 16 mars 2021 08:29:24 |
| EventProvider | string | 21, 22, 23, 24, 25 | |
| EventRecordID | integer | 0, 1, 2, 3, 4, 5, 11, 13, 15, 16, 26, 30, 32, 34, 35, 38, 45, 47, 48, 63, 64, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 637, 641, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1552, 1704, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5000, 5001, 5008, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 9617 |
| EventSourceName | string | 5, 64, 86, 781, 900, 902, 903, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1024, 1025, 1029, 1033, 1034, 1040, 1061, 1066, 2303, 3036, 3079, 4097, 4100, 4101, 4102, 4107, 4108, 4109, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5615, 5617, 6000, 6003, 8198, 8200, 8230, 10024, 12288, 12290, 16384, 16388, 16390, 16394 | "Wlclntfy" |
| ExpectedInterfaceID | string | 0, 1 | |
| ExtraInfo | string | 3036, 3079 | Context: Windows Application |
| FailedBinary | string | 9 | |
| FailedVolumeNames | string | 519, 547 | |
| FailureReason | string | 0, 1 | |
| FileNumber | string | 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418 | |
| FilesCachedFirstPass | string | 8301, 8302, 8303 | |
| FilesMissedSecondPass | string | 8301, 8302, 8303 | |
| FilesResident | string | 8301, 8302, 8303 | |
| FilesScoped | string | 8301, 8302, 8303 | |
| FilterHostProcessID | integer | 0, 0, 1, 2, 4 | 4860 |
| First | string | 16, 33, 34 | |
| Flags | string | 0, 0, 1, 3 | |
| Folder | string | 505, 506, 507, 508, 509, 514, 515, 516, 517, 1533, 1535, 1536, 1537, 1538, 1539, 1543 | C:\Users\TEMP |
| FolderPath | string | 2, 2 | |
| FolderString | string | 1, 3 | |
| FoundDllPath | string | 1, 1 | |
| FromFolder | string | 501, 502, 512, 513 | |
| FullPath | string | 10002, 10003, 10006, 10007, 10010 | |
| Guid | string | 5, 11, 64, 86, 781, 900, 902, 903, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1020, 1024, 1025, 1029, 1033, 1034, 1040, 1061, 1066, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1552, 2303, 3036, 3079, 4097, 4100, 4101, 4102, 4107, 4108, 4109, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 8198, 8200, 8230, 8300, 8301, 8302, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 10024, 12288, 12290, 16384, 16388, 16390, 16394 | "{e23b33b0-c8c9-472c-a5f9-f2bdfea0f156}" |
| HandleInstallErrorCode | string | 5, 5, 7 | |
| HostName | string | 4097, 4098, 4099, 4100 | |
| HostProcessID | string | 1, 2, 5, 6 | |
| Hresult | string | 2 | |
| ImportDllName | string | 0, 1 | |
| InterfaceGUID | string | 2, 3, 5, 7, 8 | |
| InterfaceId | string | 1, 1 | 3F31C91E-2545-4B7B-9311-9529E8BFFEF6 |
| InterferingImageName | string | 1545, 1552 | C:\Users\User\Downloads\ProfSvcLPE.exe |
| InterferingPID | integer | 1, 4, 5, 5 | 4336 |
| InterferingPID | string | 1545, 1552 | |
| Keywords | string | 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 15, 16, 17, 18, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 38, 43, 45, 47, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 256, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 637, 641, 642, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 781, 852, 854, 865, 866, 867, 868, 873, 882, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1010, 1012, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1041, 1042, 1043, 1044, 1061, 1066, 1109, 1114, 1130, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1511, 1512, 1514, 1515, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 1704, 1903, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2080, 2303, 2484, 2486, 3001, 3002, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4121, 4128, 4129, 4176, 4177, 4178, 4202, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 4879, 5000, 5001, 5008, 5602, 5604, 5605, 5606, 5611, 5612, 5615, 5617, 5631, 5973, 6000, 6003, 6253, 6527, 7000, 7002, 8192, 8193, 8194, 8195, 8196, 8198, 8199, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 8303, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 0x8080000000000000 |
| Level | integer | 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 15, 16, 17, 18, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 38, 43, 45, 47, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 256, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 637, 641, 642, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 781, 852, 854, 865, 866, 867, 868, 873, 882, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1010, 1012, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1041, 1042, 1043, 1044, 1061, 1066, 1109, 1114, 1130, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1511, 1512, 1514, 1515, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 1704, 1903, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2080, 2303, 2484, 2486, 3001, 3002, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4121, 4128, 4129, 4176, 4177, 4178, 4202, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 4879, 5000, 5001, 5008, 5602, 5604, 5605, 5606, 5611, 5612, 5615, 5617, 5631, 5973, 6000, 6003, 6253, 6527, 7000, 7002, 8192, 8193, 8194, 8195, 8196, 8198, 8199, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 8303, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 4 |
| Library | string | 1008, 1020 | C:\Windows\System32\bitsperf.dll |
| LineNumber | string | 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418 | |
| LogicalPath | string | 5, 5, 6 | |
| MOF | string | 4 | |
| MachineKeys | string | 0, 1, 5, 9 | BCD00000000, COMPONENTS, |
| MachineName | string | 2, 3, 5 | |
| Message | string | 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 16, 17, 18, 20, 21, 22, 23, 24, 25, 27, 28, 29, 31, 33, 34, 43, 48, 50, 58, 59, 63, 66, 67, 68, 81, 82, 83, 256, 257, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 865, 866, 867, 868, 882, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1010, 1012, 1040, 1041, 1042, 1043, 1044, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1512, 1514, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2484, 2486, 3001, 3002, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4128, 4129, 4176, 4177, 4178, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 5602, 5604, 5605, 5606, 5612, 5631, 5973, 7000, 7002, 8192, 8199, 8300, 8301, 8302, 8303, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010 | |
| MessageText | string | 6, 8 | GetCACaps |
| Method | integer | 1, 1 | 10 |
| Method | string | 11, 86 | GET(250ms) |
| MethodString | string | 0, 0, 1, 3 | |
| ModuleName | string | 0, 0, 1, 3 | |
| NTSTATUS | integer | 1000, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 8199 | |
| Namespace | string | 10, 22, 23, 24, 43, 48, 63, 5605, 5606 | |
| ObjId | string | 4, 6 | |
| Opcode | integer | 1, 3, 5, 11, 13, 15, 16, 86, 100, 102, 103, 105, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1024, 1025, 1026, 1029, 1033, 1034, 1038, 1040, 1042, 1061, 1066, 1109, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 2001, 2303, 3036, 3079, 3408, 4097, 4100, 4101, 4102, 4107, 4108, 4109, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8195, 8198, 8200, 8224, 8225, 8230, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 0 |
| Opcode | string | 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 16, 17, 18, 20, 21, 22, 23, 24, 25, 27, 28, 29, 31, 33, 34, 43, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 256, 257, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 865, 866, 867, 868, 882, 900, 902, 903, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1010, 1012, 1013, 1020, 1033, 1034, 1040, 1041, 1042, 1043, 1044, 1066, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1512, 1514, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2484, 2486, 3001, 3002, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4128, 4129, 4176, 4177, 4178, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 5602, 5604, 5605, 5606, 5612, 5615, 5617, 5631, 5973, 6000, 7000, 7002, 8192, 8199, 8224, 8300, 8301, 8302, 8303, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 16384, 16390, 16394 | |
| Operation | string | 20, 21, 23, 24 | |
| OperationError | string | 20, 21, 23, 24 | |
| Options | string | 501, 502, 512, 513, 514, 515, 516, 517 | |
| PackageFamily | string | 20, 21, 23, 24 | |
| PackageFullName | string | 9 | |
| PackageString | string | 1, 3 | |
| Parameter | string | 0, 1, 5 | |
| Pid | string | 10002, 10003, 10006, 10007, 10010 | |
| ProcessID | string | 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 15, 16, 17, 18, 20, 21, 22, 23, 24, 25, 27, 28, 29, 31, 33, 34, 43, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 86, 100, 102, 103, 105, 256, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 642, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 781, 852, 854, 865, 866, 867, 868, 873, 882, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1010, 1012, 1013, 1014, 1016, 1020, 1024, 1025, 1026, 1029, 1033, 1034, 1038, 1040, 1041, 1042, 1043, 1044, 1061, 1066, 1109, 1130, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1511, 1512, 1514, 1515, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2303, 2484, 2486, 3001, 3002, 3036, 3079, 3408, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4121, 4128, 4129, 4176, 4177, 4178, 4202, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 4879, 5602, 5604, 5605, 5606, 5611, 5612, 5615, 5617, 5631, 5973, 6000, 6003, 6253, 6527, 7000, 7002, 8192, 8193, 8195, 8198, 8199, 8200, 8224, 8225, 8230, 8300, 8301, 8302, 8303, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | "9576" |
| ProcessId | integer | 1, 3, 5, 11, 13, 15, 16, 86, 100, 102, 103, 105, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1024, 1025, 1026, 1029, 1033, 1034, 1038, 1040, 1042, 1061, 1066, 1109, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 2001, 2303, 3036, 3079, 3408, 4097, 4100, 4101, 4102, 4107, 4108, 4109, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8195, 8198, 8200, 8224, 8225, 8230, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 9576 |
| ProcessId | string | 2, 3, 4, 5, 6, 7, 8, 9, 10, 11 | |
| ProcessImagePath | string | 10, 11, 12 | |
| ProfsvcPID | integer | 1, 4, 5, 5 | 1716 |
| ProfsvcPID | string | 1545, 1552 | |
| Provider | string | 3, 6 | |
| ProviderGUID | string | 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 16, 17, 18, 20, 21, 22, 23, 24, 25, 27, 28, 29, 31, 33, 34, 43, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 256, 257, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 865, 866, 867, 868, 882, 900, 902, 903, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1010, 1012, 1013, 1020, 1033, 1034, 1040, 1041, 1042, 1043, 1044, 1066, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1512, 1514, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2484, 2486, 3001, 3002, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4128, 4129, 4176, 4177, 4178, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 5602, 5604, 5605, 5606, 5612, 5615, 5617, 5631, 5973, 6000, 7000, 7002, 8192, 8199, 8300, 8301, 8302, 8303, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 16384, 16390, 16394 | |
| ProviderIconId | string | 0, 1, 4, 4 | |
| ProviderName | string | 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 16, 17, 18, 20, 21, 22, 23, 24, 25, 27, 28, 29, 31, 33, 34, 43, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 256, 257, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 865, 866, 867, 868, 882, 900, 902, 903, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1010, 1012, 1013, 1020, 1033, 1034, 1040, 1041, 1042, 1043, 1044, 1066, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1512, 1514, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2484, 2486, 3001, 3002, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4128, 4129, 4176, 4177, 4178, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 5602, 5604, 5605, 5606, 5612, 5615, 5617, 5631, 5973, 6000, 7000, 7002, 8192, 8199, 8300, 8301, 8302, 8303, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 16384, 16390, 16394 | |
| ProviderNameId | string | 0, 1, 4, 4 | |
| ProvidersInHost | string | 1, 2, 5, 6 | |
| PsmKey | string | 2484, 2486 | |
| Publisher | string | 1, 2 | |
| Qualifiers | string | 0, 1, 2, 3, 4, 5, 13, 15, 16, 26, 30, 32, 34, 35, 38, 45, 47, 48, 63, 64, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 637, 641, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1704, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5000, 5001, 5008, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8216, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | "49754" |
| Query | string | 10, 21, 22, 23, 24, 25 | |
| QuotaName | string | 1, 2, 5, 6 | |
| QuotaThreshold | string | 1, 2, 5, 6 | |
| QuotaValue | string | 1, 2, 5, 6 | |
| Reason | string | 1004, 1008, 7000, 7002, 10010 | Full Index Reset |
| ReceivedInterfaceID | string | 0, 1 | |
| RecordNumber | integer | 0, 1, 2, 3, 4, 5, 11, 13, 15, 16, 26, 30, 32, 34, 35, 38, 45, 47, 48, 63, 64, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 637, 641, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1552, 1704, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5000, 5001, 5008, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 9617 |
| RelatedActivityID | string | 64, 900, 902, 903, 1003, 1004, 1013, 1020, 1033, 1034, 1040, 1066, 1531, 1532, 1552, 4097, 4109, 4111, 4625, 5615, 5617, 6000, 8224, 8300, 8301, 8302, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 16384, 16390, 16394 | |
| RepairTriggerError | string | 21, 24 | |
| RequiredSize | integer | 0, 0, 1, 2 | |
| ResourceDll | string | 0, 1, 4, 4 | |
| ResponseTime | string | 0, 0, 0, 1, 1 | |
| RestoreTargetNameList | string | 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 1040, 1041, 1042, 1043 | |
| RestoreTime | string | 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 769, 770, 771, 772, 773, 774, 1040, 1041, 1042, 1043 | |
| Result | string | 5, 8 | |
| RmSessionId | string | 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010 | |
| RulePath | string | 6, 6, 8 | |
| Second | string | 16, 33, 34 | |
| SessionID | string | 1, 2, 3 | |
| SessionId | string | 0, 1, 2, 3, 15, 16, 26, 30, 32, 34, 35, 38, 45, 63, 64, 92, 100, 101, 102, 103, 105, 198, 200, 300, 301, 302, 326, 330, 335, 455, 641, 900, 902, 903, 1000, 1003, 1004, 1013, 1020, 1022, 1025, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1042, 1066, 1531, 1532, 1552, 1704, 4097, 4098, 4109, 4111, 4625, 5000, 5001, 5008, 5615, 5617, 6000, 8194, 8212, 8216, 8224, 8225, 8300, 8301, 8302, 9027, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 11707, 11728, 11756, 12116, 16384, 16390, 16394, 20221, 20222, 20223, 20224, 20225, 20226 | |
| SigmaEventCode | integer | 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 9689 |
| SnapinId | string | 0, 1, 4, 4 | |
| SnapshotPath | string | 8300, 8301, 8302, 8303 | |
| SrpRuleGuid | string | 50, 866, 868, 882 | |
| Stage | string | 6, 8 | GetCACaps |
| Status | integer | 0, 1, 5, 9 | 3221225539 |
| Status | string | 1509, 10002, 10003, 10006, 10007, 10010 | |
| String | string | 2 | |
| Summary | string | 1, 2, 3 | |
| SummaryCount | string | 1, 2, 3 | |
| SvcHostPid | string | 0, 0, 0, 1, 9 | |
| SystemTime | string | 0, 1, 2, 3, 4, 5, 11, 13, 15, 16, 26, 30, 32, 34, 35, 38, 45, 47, 48, 63, 64, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 637, 641, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1552, 1704, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5000, 5001, 5008, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | '2022-07-26 17:31:46.583705 UTC' |
| System_Props_Xml | string | 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 |
|
| TSSessionId | string | 10002, 10003, 10006, 10007, 10010 | |
| ThreadID | string | 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 15, 16, 17, 18, 20, 21, 22, 23, 24, 25, 27, 28, 29, 31, 33, 34, 43, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 86, 100, 102, 103, 105, 256, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 642, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 781, 852, 854, 865, 866, 867, 868, 873, 882, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1010, 1012, 1013, 1014, 1016, 1020, 1024, 1025, 1026, 1029, 1033, 1034, 1038, 1040, 1041, 1042, 1043, 1044, 1061, 1066, 1109, 1130, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1511, 1512, 1514, 1515, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2303, 2484, 2486, 3001, 3002, 3036, 3079, 3408, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4121, 4128, 4129, 4176, 4177, 4178, 4202, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 4879, 5602, 5604, 5605, 5606, 5611, 5612, 5615, 5617, 5631, 5973, 6000, 6003, 6253, 6527, 7000, 7002, 8192, 8193, 8195, 8198, 8199, 8200, 8224, 8225, 8230, 8300, 8301, 8302, 8303, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | "8568" |
| ToFolder | string | 501, 502, 512, 513 | |
| TotalDirectories | string | 8301, 8302, 8303 | |
| TotalFiles | string | 8301, 8302, 8303 | |
| TypeId | string | 2001, 2002, 3002 | |
| URL | string | 3036, 4097, 4098, 4099, 4100 | csc://{S-1-5-21-712794737-353456615-3249761964-1001}/ |
| UTCStartTime | string | 10000, 10001 | |
| UnknownRequestCode | string | 5, 6, 7 | |
| Url | string | 6, 8 | https://VMW-KeyId-e7286866ba6366b54d95a3bc555d89931e800152.microsoftaik.azure.net/templates/Aik/scep |
| UserData_Xml | string | 1000, 1001, 10000, 10001, 10002, 10006 |
|
| UserID | string | 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 15, 16, 17, 18, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 38, 43, 45, 48, 50, 58, 59, 63, 64, 66, 67, 68, 81, 82, 83, 86, 92, 100, 101, 102, 103, 105, 198, 200, 256, 257, 300, 301, 302, 326, 330, 335, 455, 501, 502, 503, 505, 506, 507, 508, 509, 511, 512, 513, 514, 515, 516, 517, 518, 519, 521, 522, 523, 525, 526, 527, 528, 544, 545, 546, 547, 561, 564, 565, 608, 609, 611, 641, 658, 704, 706, 707, 708, 709, 710, 711, 721, 722, 723, 724, 737, 738, 739, 740, 755, 756, 769, 770, 771, 772, 773, 774, 865, 866, 867, 868, 882, 900, 902, 903, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1010, 1012, 1013, 1020, 1022, 1025, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1041, 1042, 1043, 1044, 1066, 1500, 1501, 1502, 1503, 1505, 1506, 1508, 1509, 1511, 1512, 1514, 1515, 1517, 1519, 1520, 1521, 1522, 1523, 1530, 1531, 1532, 1533, 1534, 1535, 1536, 1537, 1538, 1539, 1541, 1542, 1543, 1545, 1552, 1600, 1601, 1704, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2008, 2009, 2010, 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2484, 2486, 3001, 3002, 4097, 4098, 4099, 4100, 4101, 4102, 4103, 4104, 4105, 4106, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4114, 4115, 4116, 4117, 4128, 4129, 4176, 4177, 4178, 4376, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4392, 4393, 4400, 4401, 4402, 4403, 4404, 4418, 4625, 5000, 5001, 5008, 5602, 5604, 5605, 5606, 5611, 5612, 5615, 5617, 5631, 5973, 6000, 7000, 7002, 8192, 8194, 8199, 8212, 8216, 8224, 8225, 8300, 8301, 8302, 8303, 9027, 10000, 10001, 10002, 10003, 10005, 10006, 10007, 10008, 10009, 10010, 11707, 11724, 11728, 11756, 12116, 16384, 16390, 16394, 20221, 20222, 20223, 20224, 20225, 20226 | "S-1-5-21-582766833-432816504-4207985818-1009" |
| UserKeys | string | 0, 1, 5, 9 | |
| UserSid | string | 1, 1, 5, 7 | |
| VendorId | string | 2001, 2002, 3002 | |
| VendorName | string | 1, 2, 3 | |
| VendorNameCount | string | 1, 2, 3 | |
| VendorType | string | 2001, 2002, 3002 | |
| Version | integer | 1, 3, 5, 11, 13, 15, 16, 86, 100, 102, 103, 105, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1024, 1025, 1026, 1029, 1033, 1034, 1038, 1040, 1042, 1061, 1066, 1109, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 2001, 2303, 3036, 3079, 3408, 4097, 4100, 4101, 4102, 4107, 4108, 4109, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8195, 8198, 8200, 8224, 8225, 8230, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 2 |
| Version | string | 1, 2, 64, 900, 902, 903, 1003, 1004, 1013, 1020, 1033, 1034, 1040, 1066, 1531, 1532, 1552, 4097, 4109, 4111, 4625, 5615, 5617, 6000, 8224, 8300, 8301, 8302, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 16384, 16390, 16394 | |
| VolumeFriendlyName | string | 2, 5, 5 | |
| VolumeGuid | string | 2, 5, 5 | |
| VolumeName | string | 0, 3, 7, 9 | C:\ |
| Win32Error | integer | 0, 0, 1, 8 | 1359 |
| Wordlist | string | 2 | |
| WriterId | string | 5, 5, 6 | |
| cbSize | string | 0, 0, 0, 1, 8 | |
| clsid | string | 0 | |
| dest | string | 0, 1, 2, 3, 4, 5, 11, 13, 15, 16, 26, 30, 32, 34, 35, 38, 45, 47, 48, 63, 64, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 637, 641, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1552, 1704, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5000, 5001, 5008, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | windowsvictim |
| dvc | string | 0, 1, 2, 3, 4, 5, 11, 13, 15, 16, 26, 30, 32, 34, 35, 38, 45, 47, 48, 63, 64, 86, 92, 100, 101, 102, 103, 105, 198, 200, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 330, 335, 336, 413, 439, 455, 472, 488, 490, 492, 637, 641, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1020, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1036, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1552, 1704, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5000, 5001, 5008, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8216, 8224, 8225, 8230, 8300, 8301, 8302, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10003, 10005, 10006, 10010, 10024, 11707, 11724, 11728, 11756, 12002, 12116, 12288, 12290, 15268, 16028, 16384, 16388, 16390, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 20221, 20222, 20223, 20224, 20225, 20226, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | windowsvictim |
| dvc_nt_host | string | 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | windowsvictim_7db9e240-15f7-410a-8cd9-cc1fa9f3f50a |
| dwCheckPoint | string | 2 | |
| dwControlsAccepted | string | 2 | |
| dwCurrentState | string | 2 | |
| dwRebootReasons | string | 0, 0, 0, 1, 5 | |
| dwServiceSpecificExitCode | string | 2 | |
| dwServiceType | string | 2 | |
| dwWaitHint | string | 2 | |
| dwWin32ExitCode | string | 2 | |
| error | string | 3 | |
| event_id | integer | 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 9617 |
| function | string | 3 | |
| hresult | string | 0, 1 | |
| languageTag | string | 0, 2 | |
| nApplications | string | 0, 0, 0, 1, 5 | |
| nFiles | string | 10002, 10003, 10006, 10007, 10009 | |
| nServices | string | 0, 0, 0, 1, 9 | |
| param1 | integer | 781, 4202, 4625, 4879 | 86400 |
| param10 | integer | 0, 2, 2, 4 | 0 |
| param11 | integer | 0, 2, 2, 4 | 0 |
| param12 | integer | 0, 2, 2, 4 | 1 |
| param2 | integer | 0, 2, 2, 4 | 0 |
| param2 | string | 781, 4625, 4879 | TEST-THKWMDWTQP |
| param3 | integer | 0, 2, 2, 4 | 0 |
| param3 | string | 781, 4625 | Software\Microsoft\EventSystem\EventLog |
| param4 | integer | 0, 2, 2, 4 | 0 |
| param5 | integer | 0, 2, 2, 4 | 0 |
| param6 | integer | 0, 2, 2, 4 | 0 |
| param7 | integer | 0, 2, 2, 4 | 1 |
| param8 | string | 0, 2, 2, 4 | Mutual Authentication Required |
| param9 | string | 0, 2, 2, 4 | NT AUTHORITY\NetworkService |
| pbBinary | string | 0, 0, 0, 1, 8 | |
| policyName | string | 0 | |
| policyValue | string | 0 | |
| sigma_product | string | 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | windows |
| sigma_service | string | 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | application |
| signature | string | 637, 641, 642, 852, 4625, 4879 | User Account Changed |
| signature_id | integer | 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 9689 |
| string | string | 1, 17, 18 | |
| subject | string | 637, 641, 642, 852, 4625, 4879 | User Account Changed |
| timeendpos | integer | 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 592 |
| timestartpos | integer | 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | 562 |
| user_id | string | 11, 86, 1000, 1001, 1008, 1022, 1025, 1029, 1033, 1035, 1038, 1040, 1042, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 5611, 5615, 5617, 10000, 10001, 10002, 10006, 11707, 11724, 11728 | "S-1-5-21-582766833-432816504-4207985818-1009" |
| vendor_product | string | 0, 1, 3, 4, 5, 11, 13, 15, 16, 47, 48, 86, 100, 102, 103, 105, 210, 213, 216, 220, 221, 223, 225, 257, 258, 259, 264, 270, 281, 284, 294, 300, 301, 302, 320, 325, 326, 327, 336, 413, 439, 472, 488, 490, 492, 637, 642, 781, 852, 854, 873, 894, 900, 902, 903, 958, 1000, 1001, 1002, 1003, 1004, 1005, 1008, 1010, 1013, 1014, 1016, 1022, 1024, 1025, 1026, 1029, 1033, 1034, 1035, 1038, 1040, 1042, 1061, 1066, 1109, 1114, 1130, 1502, 1508, 1509, 1511, 1515, 1530, 1531, 1532, 1533, 1545, 1903, 2001, 2003, 2005, 2006, 2080, 2303, 3007, 3036, 3079, 3408, 4005, 4007, 4008, 4017, 4036, 4097, 4098, 4100, 4101, 4102, 4107, 4108, 4109, 4110, 4111, 4112, 4113, 4121, 4202, 4625, 4879, 5611, 5615, 5617, 6000, 6003, 6253, 6527, 8193, 8194, 8195, 8196, 8198, 8200, 8212, 8224, 8225, 8230, 9000, 9003, 9007, 9009, 9027, 9048, 9666, 9688, 9689, 10000, 10001, 10002, 10006, 10024, 11707, 11724, 11728, 12002, 12288, 12290, 15268, 16028, 16384, 16388, 16394, 17069, 17101, 17103, 17104, 17110, 17111, 17115, 17118, 17125, 17126, 17136, 17137, 17148, 17152, 17162, 17164, 17176, 17199, 17663, 17811, 18496, 19030, 19032, 26018, 26048, 26067, 26076, 33217, 33218, 49903, 49904, 49910, 49916, 49917, 49921 | Microsoft Windows |
| wordlist | string | 20, 31 |
dns-server
| Field | Data Type | Event IDs | Example |
|---|---|---|---|
| Computer | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | WIN-FPV0DSIC9O6.sigma.fr |
| EventID | integer | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 7693 |
| Name | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | "Microsoft-Windows-DNS-Server-Service" |
| Task | integer | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 0 |
| id | integer | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 60 |
| name | string | 0, 0, 4, 5 | Metabase Add Key |
| Channel | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | DNS Server |
| EventCode | integer | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 7693 |
| EventData_Xml | string | 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4015, 4500, 5504, 7693 | _msdcs.sigma.fr ForestDnsZones.sigma.fr |
| EventRecordID | integer | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 60 |
| Guid | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | "71A551F5-C893-4849-886B-B5EC8502641E" |
| Keywords | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 0x8000000000100000 |
| Level | integer | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 4 |
| Opcode | integer | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 0 |
| ProcessID | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | "6628" |
| ProcessId | integer | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 6628 |
| RecordNumber | integer | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 60 |
| SigmaEventCode | integer | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 7693 |
| SystemTime | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | '2022-06-03 10:04:40.847180 UTC' |
| System_Props_Xml | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 |
|
| ThreadID | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | "6844" |
| UserID | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | "S-1-5-21-2121334350-1110938707-2888912545-500" |
| Version | integer | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 0 |
| VirtualizationID | string | 6, 7, 9 | . |
| dvc | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | WIN-FPV0DSIC9O6.sigma.fr |
| dvc_nt_host | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | Win2022-AD |
| event_id | integer | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 60 |
| param1 | integer | 3150, 7693 | 65433 |
| param1 | string | 404, 407, 408, 769, 2631, 4007, 4500, 5504 | _msdcs.sigma.fr |
| param2 | string | 769, 2631, 3150, 4007, 4500 | sigma.fr |
| param3 | string | 769, 2631, 3150 | sigma.fr.dns |
| sigma_product | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | windows |
| sigma_service | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | dns-server |
| signature | string | 0, 0, 4, 5 | Metabase Add Key |
| signature_id | integer | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 7693 |
| subject | string | 0, 0, 4, 5 | Metabase Add Key |
| timeendpos | integer | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 523 |
| timestartpos | integer | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | 493 |
| user_id | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | "S-1-5-21-2121334350-1110938707-2888912545-500" |
| vendor_product | string | 2, 3, 4, 404, 407, 408, 708, 769, 2631, 3150, 4000, 4007, 4013, 4015, 4500, 5504, 7693 | Microsoft Windows |
msexchange-management
| Field | Data Type | Event IDs | Example |
|---|---|---|---|
| Computer | string | 1 | MXS01.snapattack.local |
| EventID | integer | 1 | 1 |
| Name | string | 1 | "MSExchange CmdletLogs" |
| Task | integer | 1 | 1 |
| id | integer | 1 | 66 |
| Channel | string | 1 | MSExchange Management |
| EventCode | integer | 1 | 1 |
| EventData_Xml | string | 1 | New-MailboxExportRequest,-Mailbox "snapattack" -Name "03a5108c89f64c4993c8faf52d4322ca" -ContentFilter "Subject -eq '03a5108c89f64c4993c8faf52d4322ca'" -FilePath "\127.0.0.1\c$\inetpub\wwwroot\aspnet_client\fbxvgf.aspx",snapattack.local/Users/snapattack,S-1-5-21-2783883905-3325768869-1243185101-500,S-1-5-21-2783883905-3325768869-1243185101-500,Remote-PowerShell-Unknown,20280 w3wp#MSExchangePowerShellAppPool,,19,00:00:00.3437022,View Entire Forest: 'False', Default Scope: 'snapattack.local', Configuration Domain Controller: 'DC01.snapattack.local', Preferred Global Catalog: 'DC01.snapattack.local', Preferred Domain Controllers: '{ DC01.snapattack.local }',,,,,,,False,,0 objects execution has been proxied to remote server.,,,1,ActivityId: 72e61d11-0b45-4821-90a2-08848e150425,ServicePlan:;IsAdmin:True;,,en-US |
| EventRecordID | integer | 1 | 66 |
| Keywords | string | 1 | 0x80000000000000 |
| Level | integer | 1 | 4 |
| Qualifiers | string | 1 | "16384" |
| RecordNumber | integer | 1 | 66 |
| SigmaEventCode | integer | 1 | 1 |
| SystemTime | string | 1 | '2022-05-03 18:36:53.520477 UTC' |
| System_Props_Xml | string | 1 |
|
| dvc | string | 1 | MXS01.snapattack.local |
| dvc_nt_host | string | 1 | MXS01_ec25d050-3a58-4db1-a8f0-0b397e2cf39a |
| event_id | integer | 1 | 66 |
| sigma_product | string | 1 | windows |
| sigma_service | string | 1 | msexchange-management |
| signature_id | integer | 1 | 1 |
| timeendpos | integer | 1 | 432 |
| timestartpos | integer | 1 | 402 |
| vendor_product | string | 1 | Microsoft Windows |
powershell
| Field | Data Type | Event IDs | Example |
|---|---|---|---|
| Computer | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 8198, 12039, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508 | training1 |
| EventID | integer | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 8198, 12039, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508 | 8197 |
| FileName | string | 24577, 24578, 24595, 24596, 24597, 24598, 24599 | |
| Name | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 24577, 32784, 40961, 40962, 53251, 53504 | "Microsoft-Windows-PowerShell" |
| Path | string | 0, 1, 4, 4 | C:\Users\bob\desktop\capattack\modules\stop.ps1 |
| ScriptBlockText | string | 0, 1, 4, 4 | prompt |
| Task | integer | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504 | 4 |
| Task | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8197, 8198, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508 | |
| id | integer | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 24577, 32784, 40961, 40962, 53504 | 68147 |
| ActivityID | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 24577, 32784, 40961, 40962, 53504 | "F0414E1E-7305-0002-9755-41F00573D801" |
| Channel | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 8198, 12039, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508 | Microsoft-Windows-PowerShell/Operational |
| ContextInfo | string | 4100, 4101, 4102, 4103 | Severity = Warning |
| CurrentLine | string | 24595, 24596, 24597, 24598, 24599 | |
| ErrorCode | string | 2, 3, 4, 7, 8 | ྠ |
| ErrorMessage | string | 2, 3, 4, 7, 8 | An unknown element "" was received. This can happen if the remote process closed or ended abnormally. |
| EventCode | integer | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 24577, 32784, 40961, 40962, 53504 | 8197 |
| EventData_Xml | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8197, 32784, 53504 | Opened |
| EventRecordID | integer | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 24577, 32784, 40961, 40962, 53504 | 68147 |
| Guid | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 24577, 32784, 40961, 40962, 53504 | "A0C1853B-5C40-4B15-8766-3CF1C58F985A" |
| InnerException | string | 1, 2, 3, 5, 5 | |
| InstanceId | string | 1, 4, 8, 9 | 0aacaf17-f104-4cde-8fab-27831ef15a2e |
| Keywords | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 8198, 12039, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508 | 0x8000000000000020 |
| Level | integer | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 8198, 12039, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508 | 5 |
| MaxRunspaces | string | 1, 4, 8, 9 | |
| Message | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8197, 8198, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508 | |
| MessageNumber | string | 0, 1, 4, 4 | |
| MessageTotal | string | 0, 1, 4, 4 | |
| MinRunspaces | string | 1, 4, 8, 9 | |
| Opcode | integer | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504 | 20 |
| Opcode | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8197, 8198, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508 | |
| Payload | string | 4100, 4101, 4102, 4103 | PackageManagement: A package is installed. |
| PipelineId | string | 2, 3, 4, 7, 8 | 00000000-0000-0000-0000-000000000000 |
| ProcessID | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 8198, 12039, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508 | "9868" |
| ProcessId | integer | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504 | 9868 |
| ProviderGUID | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8197, 8198, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508 | |
| ProviderName | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8197, 8198, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508 | |
| Qualifiers | string | 0, 1, 3, 4 | |
| RecordNumber | integer | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 24577, 32784, 40961, 40962, 53504 | 68147 |
| RelatedActivityID | string | 4100, 4101, 4103, 4104, 24577, 40961, 40962, 53504 | |
| RunspaceId | string | 4105, 4106 | 1aa6385f-8a7d-4de1-ba84-96a62662dc3a |
| ScheduledJobDefName | string | 53249, 53250 | |
| ScriptBlockId | string | 4104, 4105, 4106 | 576808c7-2ec5-4ebc-8c72-0b7608c807a7 |
| SessionId | string | 4100, 4101, 4103, 4104, 24577, 32784, 40961, 40962, 53504 | 00000000-0000-0000-0000-000000000000 |
| SigmaEventCode | integer | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504 | 8197 |
| StackTrace | string | 32784, 53251 | at System.Management.Automation.Remoting.Server.OutOfProcessMediatorBase.Start(String initialCommand, String configurationName) |
| StartTime | string | 2, 3, 4, 5, 9 | |
| State | string | 0, 2, 3, 5, 5 | |
| StopTime | string | 0, 2, 3, 5, 5 | |
| SystemTime | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 24577, 32784, 40961, 40962, 53504 | '2022-07-28 14:45:54.626336 UTC' |
| System_Props_Xml | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504 |
|
| ThreadID | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 8198, 12039, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508 | "6032" |
| UserData | string | 4100, 4101, 4102, 4103 | Package=AADInternals, Version=0.6.8, Provider=PowerShellGet, Source=PSGallery, Status=Installed, DestinationPath= |
| UserID | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 8198, 12039, 24577, 24578, 24595, 24596, 24597, 24598, 24599, 32777, 32784, 40961, 40962, 53249, 53250, 53251, 53504, 53505, 53506, 53507, 53508 | "S-1-5-21-582766833-432816504-4207985818-1009" |
| Version | integer | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 24577, 32784, 40961, 40962, 53504 | 1 |
| dvc | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 24577, 32784, 40961, 40962, 53504 | training1 |
| dvc_nt_host | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504 | training1_a6b51cc8-8b81-4d7e-a2c9-90e7ef573946 |
| event_id | integer | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504 | 68147 |
| meta | string | 4103, 4104 | |
| param1 | integer | 0, 3, 4, 5, 5 | 9868 |
| param1 | string | 8193, 8197, 8198, 32777, 53504, 53505, 53506, 53507, 53508 | Opened |
| param2 | string | 8198, 32777, 53504, 53505, 53506, 53507, 53508 | DefaultAppDomain |
| param3 | string | 8198, 32777, 53506, 53507, 53508 | |
| sigma_product | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504 | windows |
| sigma_service | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504 | powershell |
| signature_id | integer | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504 | 8197 |
| timeendpos | integer | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504 | 516 |
| timestartpos | integer | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504 | 486 |
| user_id | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504 | "S-1-5-21-582766833-432816504-4207985818-1009" |
| vendor_product | string | 4100, 4101, 4102, 4103, 4104, 4105, 4106, 8193, 8194, 8195, 8196, 8197, 12039, 32784, 40961, 40962, 53504 | Microsoft Windows |
powershell-classic
| Field | Data Type | Event IDs | Example |
|---|---|---|---|
| Computer | string | 300, 400, 403, 600, 800 | windowsvictim |
| EventID | integer | 300, 400, 403, 600, 800 | 800 |
| Name | string | 300, 400, 403, 600, 800 | "PowerShell" |
| Task | integer | 300, 400, 403, 600, 800 | 8 |
| id | integer | 300, 400, 403, 600, 800 | 75963 |
| name | string | 0, 0, 6 | A process was assigned a primary token |
| Channel | string | 300, 400, 403, 600, 800 | Windows PowerShell |
| EventCode | integer | 300, 400, 403, 600, 800 | 800 |
| EventData_Xml | string | 300, 400, 403, 600, 800 | Stopped,Available, NewEngineState=Stopped |
| EventRecordID | integer | 300, 400, 403, 600, 800 | 75963 |
| Keywords | string | 300, 400, 403, 600, 800 | 0x80000000000000 |
| Level | integer | 300, 400, 403, 600, 800 | 4 |
| Opcode | integer | 400, 403, 600, 800 | 0 |
| ProcessID | string | 400, 403, 600, 800 | "0" |
| ProcessId | integer | 400, 403, 600, 800 | 0 |
| Qualifiers | string | 300, 400, 403, 600, 800 | "0" |
| RecordNumber | integer | 300, 400, 403, 600, 800 | 75963 |
| SigmaEventCode | integer | 400, 403, 600, 800 | 800 |
| SigmaEventCode | string | 0, 0, 3 | N/A |
| SystemTime | string | 300, 400, 403, 600, 800 | '2022-07-15 12:06:22.041268 UTC' |
| System_Props_Xml | string | 300, 400, 403, 600, 800 |
|
| ThreadID | string | 400, 403, 600, 800 | "0" |
| Version | integer | 400, 403, 600, 800 | 0 |
| dvc | string | 300, 400, 403, 600, 800 | windowsvictim |
| dvc_nt_host | string | 300, 400, 403, 600, 800 | windowsvictim_32d8f699-9b6a-46e8-8381-9f403508b83f |
| event_id | integer | 300, 400, 403, 600, 800 | 75963 |
| sigma_product | string | 300, 400, 403, 600, 800 | windows |
| sigma_service | string | 300, 400, 403, 600, 800 | powershell-classic |
| signature | string | 0, 0, 6 | A process was assigned a primary token |
| signature_id | integer | 300, 400, 403, 600, 800 | 800 |
| subject | string | 0, 0, 6 | A process was assigned a primary token |
| timeendpos | integer | 300, 400, 403, 600, 800 | 465 |
| timestartpos | integer | 300, 400, 403, 600, 800 | 435 |
| vendor_product | string | 300, 400, 403, 600, 800 | Microsoft Windows |
printservice-admin
| Field | Data Type | Event IDs | Example |
|---|---|---|---|
| EventID | integer | 808, 823 | 823 |
| Name | string | 808, 823 | Microsoft-Windows-PrintService |
| EventCode | integer | 808, 823 | 823 |
| Guid | string | 808, 823 | 747EF6FD-E535-4D16-B510-42C90F6873A1 |
| ProcessID | integer | 808, 823 | 2612 |
| ProcessId | integer | 808, 823 | 2612 |
| SigmaEventCode | integer | 808, 823 | 823 |
| SystemTime | string | 808, 823 | '2022-07-20 16:47:56.388245 UTC' |
| ThreadID | integer | 808, 823 | 2648 |
| UserID | string | 808, 823 | S-1-5-21-2414553406-2212388514-3030099854-1009 |
| sigma_product | string | 808, 823 | windows |
| sigma_service | string | 808, 823 | printservice-admin |
| timeendpos | integer | 808, 823 | 519 |
| timestartpos | integer | 808, 823 | 489 |
| xmlns | string | 808, 823 | http://schemas.microsoft.com/win/2004/08/events/event |
security
| Field | Data Type | Event IDs | Description | Example |
|---|---|---|---|---|
| Application | string | 5031, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159 | Full path and the name of the executable for the process. | \device\harddiskvolume4\windows\system32\svchost.exe |
| CommandLine | string | 4688 | C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
| Computer | string | 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4949, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5478, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424, 8222 | windowsvictim |
|
| EventID | integer | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | 8222 |
|
| EventID | string | 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424 | ||
| FileName | string | 4664, 5051 | the name of a file or folder that the virtualized file name refers to. | |
| Name | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | "VSSAudit" |
|
| Object | string | 4934, 4937 | ||
| ParentProcessName | string | 4688 | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
|
| ProcessName | string | 4615, 4616, 4624, 4625, 4648, 4649, 4656, 4657, 4658, 4660, 4661, 4663, 4670, 4673, 4674, 4689, 4696, 4703, 4818, 4904, 4905, 4907, 4911, 4913, 4985, 5039, 5051, 5712, 6417, 6418 | full path and the name of the executable for the process. | C:\Windows\System32\wevtutil.exe |
| Service | string | 3, 4, 6, 7 | - |
|
| Task | integer | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | 3 |
|
| Task | string | 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424 | ||
| Type | integer | 3, 5, 7, 9 | 0 |
|
| Type | string | 5148, 5149, 5379 | ||
| action | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416 | success |
|
| app | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | win:unknown |
|
| id | integer | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | 843214 |
|
| name | string | 1102, 4611, 4624, 4625, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4800, 4801, 4904, 4905, 4907, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890 | Windows Firewall settings were restored to the default values |
|
| process | string | 4624, 4625, 4648, 4656, 4657, 4658, 4660, 4661, 4663, 4670, 4673, 4674, 4688, 4689, 4696, 4703, 4904, 4905, 4907, 4911, 4985 | C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
| process_name | string | 4624, 4625, 4648, 4656, 4657, 4658, 4660, 4661, 4663, 4670, 4673, 4674, 4688, 4689, 4703, 4904, 4905, 4907, 4911, 4985 | wevtutil.exe |
|
| product | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | Windows |
|
| service | string | 4673, 4697, 4768, 4769, 5478 | krbtgt |
|
| status | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416 | success |
|
| user | integer | 4624, 4627, 4634, 4648, 4688, 4696, 4703, 4720, 4726, 4728, 4729, 4732 | ||
| user | string | 4624, 4625, 4627, 4634, 4648, 4673, 4674, 4688, 4689, 4697, 4703, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4798, 4799, 4800, 4801 | user |
|
| AccessGranted | string | 1, 4, 7, 7 | SeServiceLogonRight |
|
| AccessList | string | 4656, 4659, 4661, 4662, 4663, 4691, 5140, 5145 | the list of access rights which were requested by user_sid. These access rights depend on Object Type. |
%%4484 |
| AccessMask | string | 4656, 4659, 4661, 4662, 4663, 4674, 4691, 5140, 5145 | the sum of hexadecimal values of requested access rights. See "Table 13. File access codes." | 983103 |
| AccessReason | string | 4656, 4661, 4818, 5145 | the list of access check results. | - |
| AccessRemoved | string | 1, 4, 7, 8 | SeServiceLogonRight |
|
| AccountDomain | string | 4778, 4779, 4825 | SID of account that requested the "invoke screensaver" operation | EC2AMAZ-1CL0VOR |
| AccountExpires | string | 4720, 4738, 4741, 4742 | the date when the account expires. If the value of accountExpiresattribute of computer object was changed, you will see the new value here. For computer objects, it is optional, and typically is not set. You can change this attribute by using Active Directory Users and Computers, or through a script, for example. | %%1794 |
| AccountName | string | 4778, 4779, 4822, 4823, 4825 | the name of the account that requested the "invoke screensaver" operation. | user |
| AccountSessionIdentifier | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
| Action | string | 5441, 5447 | %%16390 |
|
| ActiveProfile | string | 4, 5, 6, 9 | ||
| ActivityID | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4662, 4670, 4672, 4673, 4674, 4688, 4689, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4946, 4947, 4948, 4949, 4950, 4957, 5058, 5059, 5061, 5379, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890 | "DB372A64-1DDF-0000-34E1-C3F65585D801" |
|
| AddedCAPs | string | 1, 4, 8, 9 | ||
| AdditionalInfo | string | 2, 4, 6, 6 | Local Read (ExecQuery) |
|
| AdditionalInfo2 | string | 2, 4, 6, 6 | root\cimv2\security\MicrosoftVolumeEncryption:__Win32Provider.Name="Win32_EncryptableVolumeProvider" |
|
| AdvancedOptions | string | 2, 4, 6, 8 | ||
| AhAuthType | string | 1, 4, 5, 5 | ||
| AlgorithmName | string | 5057, 5058, 5059, 5060, 5061 | the name of cryptographic algorithm through which the key was used or accessed. | UNKNOWN |
| AllowedToDelegateTo | string | 4720, 4738, 4741, 4742 | the list of SPNs to which this account can present delegated credentials. Can be changed using Active Directory Users and Computers management console in Delegation tab of computer account. If the SPNs list on Delegation tab of a computer account was changed, you will see the new SPNs list in AllowedToDelegateTo field (note that you will see the new list instead of changes) of this event. | - |
| AppCorrelationID | string | 5136, 5137, 5138, 5139, 5141, 5169, 5170 | always has "-" value. Not in use. | |
| AppInstance | string | 4665, 4666, 4667, 4668 | (Application Information) Application Instance ID | |
| AppName | string | 4665, 4666, 4667, 4668 | (Application Information) Application Name | |
| AsIsCAPs | string | 1, 4, 8, 9 | ||
| Attribute | string | 3, 4, 4, 9 | ||
| AttributeLDAPDisplayName | string | 5136, 5169, 5170 | the object attribute that was modified. | |
| AttributeSyntaxOID | string | 5136, 5169, 5170 | The syntax for an attribute defines the storage representation, byte ordering, and matching rules for comparisons of property types. | |
| AttributeValue | string | 5136, 5169, 5170 | the value which was added or deleted, depending on the Operation\Type field. | |
| Attributes | string | 4874, 4886, 4887, 4888, 4889 | ||
| AuditFilter | string | 4, 5, 8, 8 | ||
| AuditPolicyChanges | string | 4719, 4912 | changes which were made for the subcategory. | %%8448, %%8450 |
| AuditSourceName | string | 4904, 4905 | the name of unregistered security event source. You can see all registered security event source names in this registry path: "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security". | VSSAudit |
| AuditStatusCode | string | 4935, 4936 | there is no detailed information about this field in this document. | |
| AuditsDiscarded | string | 1, 2, 4, 6 | ||
| AuthenticationLevel | string | 1, 2, 5, 7 | ||
| AuthenticationPackage | string | 4, 4, 6, 9 | ||
| AuthenticationPackageName | string | 4610, 4624, 4625 | The name of the authentication package which was used for the logon authentication process. Default packages loaded on LSA startup are located in "HKLM\SYSTEM\CurrentControlSet\Control\Lsa\OSConfig" registry key. | Negotiate |
| AuthenticationProvider | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
| AuthenticationServer | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
| AuthenticationService | string | 1, 2, 5, 7 | ||
| AuthenticationSetId | string | 5040, 5041, 5042 | ||
| AuthenticationSetName | string | 5040, 5041, 5042 | ||
| AuthenticationType | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
| BackupFileName | string | 5376, 5377 | ||
| BackupPath | string | 0, 1, 1, 5 | ||
| BackupType | string | 4, 6, 7, 8 | ||
| BaseCRLHash | string | 1, 2, 5, 7 | ||
| BaseCRLNumber | string | 1, 2, 5, 7 | ||
| BaseCRLThisUpdate | string | 1, 2, 5, 7 | ||
| CACertificateHash | string | 4880, 4881 | ||
| CAConfigurationId | string | 5122, 5126, 5127 | ||
| CAName | string | 1, 2, 5, 5 | ||
| CAPublicKeyHash | string | 4880, 4881 | ||
| CRLNumber | string | 2, 4, 7, 8 | ||
| CalledStationID | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
| CallerDomainName | string | 1, 4, 6, 7 | ||
| CallerLogonId | string | 1, 4, 6, 7 | ||
| CallerProcessId | string | 4798, 4799 | hexadecimal Process ID of the process that enumerated the members of the group. Process ID (PID) is a number used by the operating system to uniquely identify an active process. You can also correlate this process ID with a process ID in other events, for example, "4688: A new process has been created" Process Information\New Process ID. | 0x73c |
| CallerProcessName | string | 4798, 4799, 5050 | full path and the name of the executable for the process. | C:\Windows\System32\ntdsutil.exe |
| CallerUserName | string | 1, 4, 6, 7 | ||
| CallerUserSid | string | 1, 4, 6, 7 | ||
| Caller_Domain | string | 4611, 4624, 4625, 4627, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4798, 4799, 4904, 4905, 4907, 4911, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5379, 5381, 6416 | training1 |
|
| Caller_User_Name | string | 1102, 4611, 4624, 4625, 4627, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4798, 4799, 4904, 4905, 4907, 4911, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5379, 5381, 5888, 5890, 6416 | user |
|
| CallingStationID | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
| CalloutId | integer | 4, 4, 5, 6 | 290 |
|
| CalloutId | string | 5440, 5446 | ||
| CalloutKey | string | 5440, 5441, 5446, 5447 | 31114833-2891-4EDD-A8EC-2FF8549AA491 |
|
| CalloutName | string | 5440, 5441, 5446, 5447 | windefend_datagram_v4 |
|
| CalloutType | string | 5440, 5446 | %%16388 |
|
| Categories | string | 6406, 6408 | ||
| CategoryId | string | 4719, 4912 | the name of auditing category which subcategory state was changed. | %%8273 |
| CategoryString | string | 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738 | Account Management |
|
| CertIssuerName | string | 4768, 4771, 4820, 4824 | the name of the Certification Authority that issued the smart card certificate. Populated in Issued by field in certificate. | |
| CertSerialNumber | string | 4768, 4771, 4820, 4824 | smart card certificate's serial number. Can be found in Serial number field in the certificate. | |
| CertThumbprint | string | 4768, 4771, 4820, 4824 | smart card certificate's thumbprint. Can be found in Thumbprint field in the certificate. | |
| Certificate | string | 4, 4, 8, 8 | ||
| CertificateDatabaseHash | string | 4880, 4881 | ||
| CertificateHash | string | 4, 5, 8, 9 | ||
| CertificateSerialNumber | string | 0, 4, 7, 8 | ||
| ChangeType | string | 5446, 5447, 5448, 5449, 5450 | %%16385 |
|
| Channel | string | 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4949, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5478, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424, 8222 | Security |
|
| CipherType | string | 1, 4, 5, 5 | ||
| ClassId | string | 6416, 6419, 6420, 6421, 6422, 6423, 6424 | "Class Guid" attribute of device. | 1ED2BBF9-11F0-4084-B21F-AD83A8E6DCDC |
| ClassName | string | 6416, 6419, 6420, 6421, 6422, 6423, 6424 | "Class" attribute of device. | Monitor |
| ClientAddress | string | 4778, 4779, 4825 | IP address of the computer from which the session was disconnected | 10.0.4.126 |
| ClientCreationTime | string | 5058, 5059 | 2022-06-15 13:07:13.665388 UTC |
|
| ClientDomain | string | 4665, 4666, 4667, 4668 | subject's domain or computer name. | |
| ClientIPAddress | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6400, 6401, 6402 | ||
| ClientLogonId | string | 4665, 4666, 4667, 4668 | (Subject) Client Context ID | |
| ClientName | string | 4665, 4666, 4667, 4668, 4778, 4779, 6272, 6273, 6274, 6275, 6276, 6277, 6278 | machine name from which the session was disconnected. Has "Unknown"value for console session. | Guacamole RDP |
| ClientProcessId | integer | 4697, 4698, 4699, 4700, 4701, 4702, 5058, 5059, 5379, 5381 | 484 |
|
| ClientProcessId | string | 4697, 4698, 4699, 4700, 4701, 4702, 5058, 5059, 5376, 5377, 5379, 5380, 5381, 5382 | ||
| ClientProcessStartKey | string | 4697, 4698, 4699, 4700, 4701, 4702 | ||
| ClientUserName | string | 4774, 4775, 4777 | the name of the account that had its credentials validated by the Authentication Package. Can be user name, computer account name or well-known security principal account name. | |
| CollisionTargetName | string | 4, 4, 6, 8 | ||
| CollisionTargetType | string | 4, 4, 6, 8 | ||
| CompatibleIds | string | 6416, 6419, 6420, 6421, 6422, 6423, 6424 | "Compatible Ids" attribute of device. | *PNP09FF |
| ComputerAccountChange | string | 2, 4, 4, 7 | ||
| ComputerName | string | 1, 4, 6, 8 | ||
| Conditions | string | 5441, 5447 | Condition ID: {d78e1e87-8644-4ea5-9437-d809ecefc971} |
|
| ConfigAccessPolicy | string | 2, 4, 6, 8 | ||
| ConfiguredNames | string | 1, 5, 6, 8 | ||
| ConnectionSecurityRuleId | string | 5043, 5044, 5045 | ||
| ConnectionSecurityRuleName | string | 5043, 5044, 5045 | ||
| ContextName | string | 5064, 5065, 5066, 5067, 5068, 5069, 5070 | ||
| Count | string | 0, 4, 5, 6 | ||
| CountOfCredentialsReturned | integer | 5379, 5381 | 0 |
|
| CountOfCredentialsReturned | string | 5379, 5380, 5381 | ||
| CrashOnAuditFailValue | string | 4621, 4906 | contains new value of CrashOnAuditFail flag. | |
| CredType | string | 3, 5, 7, 8 | ||
| CryptoAlgorithms | string | 4694, 4695 | Cryptographic Algorithms of the protection | AES-256 , SHA2-512 |
| CryptographicSetId | string | 5046, 5047, 5048 | ||
| CryptographicSetName | string | 5046, 5047, 5048 | ||
| CurrentProfile | string | 1, 5, 5, 7 | %%14644 |
|
| DCDNSName | string | 4898, 4899, 4900 | ||
| DHGroup | string | 4650, 4651, 4979, 4980, 4981, 4982 | ||
| DSName | string | 5136, 5137, 5138, 5139, 5141, 5169, 5170 | the name of an Active Directory domain, where the object was deleted. | |
| DSType | string | 5136, 5137, 5138, 5139, 5141, 5169, 5170 | has "Active Directory Domain Services" value for this event. | |
| DataDescription | string | 4694, 4695 | - | 827ed4bc-54ff-4032-b410-02f985a5c118 |
| DeletedCAPs | string | 1, 4, 8, 9 | ||
| DeltaCRLHash | string | 1, 2, 5, 7 | ||
| DeltaCRLIndicator | string | 1, 2, 5, 7 | ||
| DeltaCRLNumber | string | 1, 2, 5, 7 | ||
| DeltaCRLThisUpdate | string | 1, 2, 5, 7 | ||
| DestAddress | string | 5146, 5147, 5150, 5151, 5152, 5153, 5156, 5157 | IP address from which connection was received or initiated. | 239.255.255.250 |
| DestPort | integer | 5152, 5156, 5157 | Port number which was used from remote machine to initiate connection. | 5355 |
| DestPort | string | 5152, 5153, 5156, 5157 | Port number which was used from remote machine to initiate connection. | |
| DestinationDRA | string | 4928, 4929, 4930, 4931, 4932, 4933, 4937 | destination directory replication agent distinguished name. | |
| DestinationvSwitchPort | string | 5146, 5147 | ||
| DeviceClaims | string | 2, 4, 6, 6 | ||
| DeviceDescription | string | 6416, 6419, 6420, 6421, 6422, 6423, 6424 | "Device description" attribute of device. | Generic Non-PnP Monitor |
| DeviceId | string | 6416, 6419, 6420, 6421, 6422, 6423, 6424 | "Device instance path" attribute of device. | DISPLAY\Default_Monitor\1&1f0c3c2f&0&UID256 |
| DeviceName | string | 4820, 4821, 4822, 4823 | ||
| Direction | string | 5146, 5147, 5150, 5151, 5152, 5153, 5156, 5157 | Direction of blocked connection. | %%14593 |
| DisableIntegrityChecks | string | 2, 4, 6, 8 | ||
| DisabledPrivilegeList | string | 0, 3, 4, 7 | - |
|
| DisplayName | string | 4720, 4738, 4741, 4742 | it is a name displayed in the address book for a particular account (typically - user account). This is usually the combination of the user's first name, middle initial, and last name. For computer objects, it is optional, and typically is not set. You can change this attribute by using Active Directory Users and Computers, or through a script, for example. If the value of displayName attribute of computer object was changed, you will see the new value here. | %%1793 |
| Disposition | string | 4887, 4888, 4889 | ||
| DnsHostName | string | 4741, 4742 | name of computer account as registered in DNS. If the value of dNSHostName attribute of computer object was changed, you will see the new value here. | |
| DnsName | string | 4864, 4865, 4866, 4867 | DNS name of the trust partner. This parameter might not be captured in the event, and in that case appears as "-". | |
| DomainBehaviorVersion | string | 3, 4, 7, 9 | ||
| DomainName | string | 4706, 4707, 4716, 4739 | the name of domain for which policy changes were made. | |
| DomainPolicyChanged | string | 3, 4, 7, 9 | ||
| DomainSid | string | 4706, 4707, 4716, 4739, 4864, 4865, 4866, 4867 | SID of the trust partner. This parameter might not be captured in the event, and in that case appears as "NULL SID". | |
| Dummy | string | 3, 4, 7, 8 | - |
|
| Duration | string | 1, 4, 6, 8 | ||
| EAPErrorCode | string | 2, 3, 5, 6 | ||
| EAPReasonCode | string | 2, 3, 5, 6 | ||
| EAPType | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
| EMAuthMethod | string | 4979, 4981, 4984 | ||
| EMImpersonationState | string | 4979, 4980, 4981, 4982, 4983, 4984 | ||
| EapRootCauseString | string | 2, 3, 5, 6 | ||
| EfsPolicyChange | string | 1, 4, 4, 7 | ||
| ElevatedToken | string | 2, 4, 4, 6 | %%1842 |
|
| EnableRestrictedPermissions | string | 0, 4, 8, 9 | ||
| EnabledPrivilegeList | string | 0, 3, 4, 7 | SeAssignPrimaryTokenPrivilege |
|
| EndUSN | string | 3, 3, 4, 9 | ||
| Entry | string | 1, 4, 8, 9 | ||
| EntryType | string | 4865, 4866, 4867 | the type of modified entry. | |
| Error | string | 4958, 5457, 5459, 5461, 5462, 5472, 5474, 5477, 5483, 5484 | ||
| ErrorCode | string | 1107, 1108, 5027, 5028, 5029, 5030, 5032, 5035, 5037, 5168, 5632, 5633, 6144, 6145, 6404 | specific error code which shows the error which happened during Group Policy processing. | |
| Error_Code | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | 0xc000006d |
|
| EspAuthType | string | 1, 4, 5, 5 | ||
| EtherType | string | 5146, 5147, 5150, 5151 | ||
| EventCode | integer | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | 8222 |
|
| EventCount | string | 1, 4, 6, 8 | ||
| EventCountTotal | integer | 2, 4, 6, 7 | 1 |
|
| EventCountTotal | string | 4626, 4627 | Total number of events in the sequence. | |
| EventData_Xml | string | 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5888, 5890, 6416, 8222 | S-1-5-21-582766833-432816504-4207985818-1009,EC2AMAZ-NNKUICG\user,0x0000000000000274,C:\Windows\System32\vssadmin.exe,{5d0247f2-6dbc-4295-8ba8-a779b444c3f6},{bc77a77b-e166-46aa-a3a0-9a46334b947a},{b5946137-7b9f-4925-af80-51abd60b20d5},EC2AMAZ-NNKUICG,\?\Volume{e3c0cc15-0000-0000-0000-100000000000}\,\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1 |
|
| EventId | string | 4618, 6405 | ||
| EventIdx | integer | 2, 4, 6, 7 | 1 |
|
| EventIdx | string | 4626, 4627 | If is there is not enough space in one event to put all groups, you will see "1 of N" in this field and additional events will be generated. Typically this field has "1 of 1" value. | |
| EventRecordID | integer | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | 843214 |
|
| EventSourceId | string | 4904, 4905 | the unique hexadecimal identifier of unregistered security event source. | 0x10d178 |
| ExpirationTime | string | 5169, 5170 | ||
| ExtendedQuarantineState | string | 6276, 6277, 6278 | ||
| ExtensionData | string | 3, 4, 7, 8 | ||
| ExtensionDataType | string | 3, 4, 7, 8 | ||
| ExtensionName | string | 3, 4, 7, 8 | ||
| ExtensionPolicyFlags | string | 3, 4, 7, 8 | ||
| FQDN | string | 4698, 4699, 4700, 4701, 4702 | EC2AMAZ-NNKUICG |
|
| FailureCode | string | 4772, 4773 | ||
| FailureId | string | 3, 4, 6, 9 | ||
| FailurePoint | string | 4652, 4653, 4654, 4983, 4984 | ||
| FailureReason | string | 4625, 4652, 4653, 4654, 4692, 4694, 4695, 4983, 4984 | - | 0x0 |
| FatalCode | string | 1, 4, 6, 8 | ||
| Filter | string | 4, 6, 8, 9 | ||
| FilterId | integer | 4, 4, 5, 7 | 68102 |
|
| FilterId | string | 5441, 5447 | ||
| FilterKey | string | 5441, 5447 | 00307222-72B1-4AEF-8A7F-62AF4B4604DF |
|
| FilterName | string | 5441, 5447 | Microsoft Edge (mDNS-In) |
|
| FilterOrigin | string | 5152, 5157 | Query User Default |
|
| FilterRTID | integer | 5152, 5154, 5156, 5157, 5158 | Unique filter ID which allows application to bind the port. | 70338 |
| FilterRTID | string | 5146, 5147, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159 | Unique filter ID which blocks the application from binding to the port. | |
| FilterType | string | 5441, 5447 | %%16388 |
|
| Flags | integer | 1, 3, 5, 8 | 512 |
|
| Flags | string | 4864, 4865, 4866, 4867, 5381, 5382 | Forest flags flags. | |
| FlightSigning | string | 2, 4, 6, 8 | ||
| ForceLogoff | string | 3, 4, 7, 9 | ||
| ForestRoot | string | 4864, 4865, 4866, 4867 | the name of the Active Directory forest for which trusted forest information entry was modified. | |
| ForestRootSid | string | 4865, 4866, 4867 | the SID of the Active Directory forest for which trusted forest information entry was modified. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID cannot be resolved, you will see the source data in the event. | |
| FullyQualifiedSubjectMachineName | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
| FullyQualifiedSubjectUserName | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280 | ||
| FunctionName | string | 5066, 5067, 5068, 5069, 5070 | ||
| GPOList | string | 6144, 6145 | the list of Group Policy Objects that include "Security Settings" policies, and that were applied with errors to the computer. | |
| GUID | string | 0, 4, 6, 9 | ||
| Group | string | 4, 6, 6, 6 | ||
| GroupMembership | string | 2, 4, 6, 7 | %{S-1-5-21-2414553406-2212388514-3030099854-513} |
|
| GroupPolicyApplied | string | 4, 4, 4, 9 | ||
| GroupTypeChange | string | 4, 4, 6, 7 | ||
| Group_Domain | string | 4728, 4729, 4732, 4733, 4799 | EC2AMAZ-NNKUICG |
|
| Group_Name | string | 4728, 4729, 4732, 4733, 4799 | Users |
|
| Guid | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416 | "{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}" |
|
| HandleId | string | 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4670, 4674, 4818, 4907, 4911, 4913 | hexadecimal value of a handle to Object Name. This field can help you correlate this event with other events that might contain the same Handle ID, for example, "4663(S): An attempt was made to access an object." This parameter might not be captured in the event, and in that case appears as "0x0". | 0xd24 |
| HardwareIds | string | 6419, 6420, 6421, 6422, 6423, 6424 | "Hardware Ids" attribute of device. | |
| HasRemoteDynamicKeywordAddress | string | 1, 5, 5, 7 | %%1826 |
|
| HomeDirectory | string | 4720, 4738, 4741, 4742 | user's home directory. If homeDrive attribute is set and specifies a drive letter, homeDirectory should be a UNC path. The path must be a network UNC of the form \Server\Share\Directory. If the value of homeDirectory attribute of computer object was changed, you will see the new value here. For computer objects, it is optional, and typically is not set. You can change this attribute by using Active Directory Users and Computers, or through a script, for example. | %%1793 |
| HomePath | string | 4720, 4738, 4741, 4742 | specifies the drive letter to which to map the UNC path specified by homeDirectory account's attribute. The drive letter must be specified in the form "DRIVE_LETTER:". For example - "H:". If the value of homeDrive attribute of computer object was changed, you will see the new value here. For computer objects, it is optional, and typically is not set. You can change this attribute by using Active Directory Users and Computers, or through a script, for example. | %%1793 |
| HostedCacheName | string | 6403, 6404 | ||
| HypervisorDebug | string | 2, 4, 6, 8 | ||
| HypervisorLaunchType | string | 2, 4, 6, 8 | ||
| HypervisorLoadOptions | string | 2, 4, 6, 8 | ||
| Identity | string | 5382, 5632, 5633 | User Principal Name (UPN) of account for which 802.1x authentication request was made. | |
| ImpersonationLevel | string | 2, 4, 4, 6 | %%1833 |
|
| InboundSpi | string | 1, 4, 5, 5 | ||
| InitiatorCookie | string | 4652, 4653 | ||
| InterfaceId | string | 5066, 5067, 5068, 5069, 5070 | ||
| InterfaceIndex | integer | 1, 5, 5, 7 | 16 |
|
| InterfaceName | string | 3, 3, 5, 6 | ||
| InterfaceType | string | 5150, 5151 | ||
| InterfaceUuid | string | 1, 2, 5, 7 | ||
| IntfGuid | string | 2, 3, 5, 6 | ||
| InvalidCallName | string | 1, 4, 5, 6 | ||
| IpAddress | string | 4624, 4625, 4648, 4768, 4769, 4770, 4771, 4772, 4773, 4820, 4821, 4824, 5140, 5145 | source IP address from which access was performed. | ::1 |
| IpAddresses | string | 1, 5, 6, 8 | ||
| IpPort | integer | 4768, 4769, 5140, 5145 | source TCP or UDP port which was used from remote or local machine to request the access. | 49901 |
| IpPort | string | 4624, 4625, 4648, 4768, 4769, 4770, 4771, 4772, 4773, 4820, 4821, 4824, 5140, 5145 | source TCP or UDP port which was used from remote or local machine to request the access. | - |
| IpProtocol | string | 5451, 5452 | ||
| IpSecSecurityAssociationId | string | 0, 4, 5, 9 | ||
| IpSecSecurityAssociationName | string | 0, 4, 5, 9 | ||
| IsBaseCRL | string | 2, 4, 7, 8 | ||
| IsLoopback | string | 1, 5, 5, 7 | %%1826 |
|
| KRAHashes | string | 3, 4, 8, 9 | ||
| KerberosPolicyChange | string | 1, 3, 4, 7 | ||
| KernelDebug | string | 2, 4, 6, 8 | ||
| KeyContainer | string | 2, 4, 7, 8 | ||
| KeyFilePath | string | 0, 5, 5, 8 | C:\ProgramData\Microsoft\Crypto\SystemKeys\c56b3f40b196d4f8d43940688b5b8765_4d6cbdb8-0892-45ee-9d0d-f2e8b7a5fa78 |
|
| KeyLength | string | 4624, 4625 | the length of NTLM Session Security key. Typically it has 128 bit or 56 bit length. This parameter is always 0 if "Authentication Package" = "Kerberos", because it is not applicable for Kerberos protocol. This field will also have "0" value if Kerberos was negotiated using Negotiate authentication package. | |
| KeyModName | string | 4650, 4651, 4652, 4653, 4654, 4655, 4976, 4977, 4978 | ||
| KeyName | string | 5058, 5059, 5060, 5061 | the name of the key (key container) with which operation was performed. | te-8811d5ab-8de8-4b50-a578-845af8f06794 |
| KeyType | string | 5058, 5059, 5060, 5061 | can have one of the following values: "User key." - user's cryptographic key. "Machine key." - machine's cryptographic key. | %%2500 |
| KeyingModuleName | string | 1, 4, 5, 5 | ||
| Keywords | string | 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4949, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5478, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424, 8222 | 0x80a0000000000000 |
|
| LayerId | integer | 5446, 5447 | 46 |
|
| LayerId | string | 5440, 5441, 5446, 5447 | ||
| LayerKey | string | 5440, 5441, 5446, 5447 | A3B42C97-9F04-4672-B87E-CEE9C483257F |
|
| LayerName | string | 5146, 5147, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5440, 5441, 5446, 5447 | Application Layer Enforcement layer name. | ALE Receive/Accept v6 Layer |
| LayerRTID | integer | 5152, 5154, 5156, 5157, 5158 | Windows Filtering Platform layer identifier. | 48 |
| LayerRTID | string | 5146, 5147, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159 | Windows Filtering Platform layer identifier. | |
| Level | integer | 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4949, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5478, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424, 8222 | 4 |
|
| LifetimeKilobytes | string | 1, 4, 5, 5 | ||
| LifetimePackets | string | 1, 4, 5, 5 | ||
| LifetimeSeconds | string | 1, 4, 5, 5 | ||
| LinkName | string | 4, 4, 6, 6 | ||
| LmPackageName | string | 4624, 4625 | The name of the LAN Manager sub-package (NTLM-family protocol name) that was used during logon. Possible values are: NTLM V1, NTLM V2, LM. Only populated if Authentication Package = NTLM. | - |
| LoadOptions | string | 2, 4, 6, 8 | ||
| LocalAddress | string | 4650, 4651, 4652, 4653, 4654, 4655, 4976, 4977, 4978, 4979, 4980, 4981, 4983, 4984, 5451, 5452 | ||
| LocalAddressMask | string | 4654, 5451, 5452 | ||
| LocalEMCertHash | string | 4980, 4982, 4983 | ||
| LocalEMIssuingCA | string | 4980, 4982, 4983 | ||
| LocalEMPrincipalName | string | 4979, 4980, 4981, 4982, 4983, 4984 | ||
| LocalEMRootCA | string | 4980, 4982, 4983 | ||
| LocalKeyModPort | string | 4650, 4651, 4652, 4653, 4979, 4980, 4981, 4982, 4983, 4984 | ||
| LocalMMCertHash | string | 4651, 4652, 4981, 4982 | ||
| LocalMMIssuingCA | string | 4651, 4652, 4981, 4982 | ||
| LocalMMPrincipalName | string | 4650, 4651, 4652, 4653, 4979, 4980, 4981, 4982 | ||
| LocalMMRootCA | string | 4651, 4652, 4981, 4982 | ||
| LocalMac | string | 2, 3, 5, 6 | ||
| LocalPort | string | 4654, 5451, 5452 | ||
| LocalTunnelEndpoint | string | 4654, 5451, 5452 | ||
| LocationInformation | string | 6416, 6419, 6420, 6421, 6422, 6423, 6424 | "Location information" attribute of device. | - |
| LockoutDuration | string | 3, 4, 7, 9 | ||
| LockoutObservationWindow | string | 3, 4, 7, 9 | ||
| LockoutThreshold | string | 3, 4, 7, 9 | ||
| LogDroppedPacketsEnabled | string | 4, 4, 4, 9 | ||
| LogFileCleared_Xml | string | 0, 1, 1, 2 |
|
|
| LogSuccessfulConnectionsEnabled | string | 4, 4, 4, 9 | ||
| LoggingResult | string | 6272, 6273 | ||
| LogonGuid | string | 4624, 4648, 4769, 4821, 4964 | a GUID that can help you correlate this event with another event that can contain the same Logon GUID, "4769(S, F): A Kerberos service ticket was requested event on a domain controller. | 6D906345-171E-BA8F-34F0-A0F6E60FC960 |
| LogonHours | string | 4720, 4738, 4741, 4742 | hours that the account is allowed to logon to the domain. If the value of logonHours attribute of computer object was changed, you will see the new value here. For computer objects, it is optional, and typically is not set. You can change this attribute by using Active Directory Users and Computers, or through a script, for example. | %%1797 |
| LogonID | string | 4778, 4779, 4825 | hexadecimal value that can help you correlate this event with recent events that might contain the same Logon ID | 0x9fb6c3 |
| LogonProcessName | string | 4611, 4624, 4625, 4649 | the name of the trusted logon process that was used for the logon attempt. See event "4611: A trusted logon process has been registered with the Local Security Authority" description for more information. | UserManager |
| LogonType | integer | 4624, 4625, 4627, 4634 | the type of logon which was performed. | 3 |
| LogonType | string | 4624, 4625, 4626, 4627, 4634 | the type of logon which was performed. | |
| Logon_ID | integer | 5888, 5890 | 1207182 |
|
| Logon_ID | string | 4611, 4624, 4625, 4627, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4798, 4799, 4904, 4905, 4907, 4911, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5379, 5381, 6416 | 0xcedae |
|
| Logon_Type | integer | 4624, 4625, 4627, 4634 | 3 |
|
| MMAuthMethod | string | 4650, 4651, 4652, 4653, 4979, 4980 | ||
| MMCipherAlg | string | 4650, 4651, 4979, 4980, 4981, 4982 | ||
| MMFilterID | string | 4650, 4651, 4652, 4653, 4979, 4980, 4981, 4982 | ||
| MMImpersonationState | string | 4650, 4651, 4652, 4653, 4979, 4980, 4981, 4982 | ||
| MMIntegrityAlg | string | 4650, 4651, 4979, 4980, 4981, 4982 | ||
| MMLifetime | string | 4650, 4651, 4979, 4980, 4981, 4982 | ||
| MMSAID | string | 4650, 4651, 4654, 4655, 4979, 4980, 4981, 4982 | ||
| MachineAccountQuota | string | 3, 4, 7, 9 | ||
| MachineInventory | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
| MainModeSaId | string | 1, 4, 5, 5 | ||
| MandatoryLabel | string | 4688 | S-1-16-12288 |
|
| MappedName | string | 4, 4, 7, 7 | ||
| MappingBy | string | 4774, 4775 | The name of Authentication Package which was used for credential validation. | |
| MasterKeyId | string | 4692, 4693, 4694, 4695 | - | Edge |
| MaxPasswordAge | string | 3, 4, 7, 9 | ||
| MediaType | string | 5150, 5151 | ||
| MemberName | string | 4728, 4729, 4732, 4733, 4746, 4747, 4751, 4752, 4756, 4757, 4761, 4762, 4785, 4786, 4787, 4788 | distinguished name of account that was removed from the group. For example: "CN=Auditor,CN=Users,DC=contoso,DC=local". For some well-known security principals, such as LOCAL SERVICE or ANONYMOUS LOGON, the value of this field is "-". | - |
| MemberSid | string | 4728, 4729, 4732, 4733, 4746, 4747, 4751, 4752, 4756, 4757, 4761, 4762, 4785, 4786, 4787, 4788 | SID of account that was removed from the group. Event Viewer automatically tries to resolve SIDs and show the group name. If the SID cannot be resolved, you will see the source data in the event. | S-1-5-21-582766833-432816504-4207985818-1010 |
| MembershipExpirationTime | string | 4728, 4732, 4746, 4751, 4756, 4761, 4785 | ||
| Message | string | 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424 | ||
| MessageID | string | 4, 4, 5, 6 | ||
| MinPasswordAge | string | 3, 4, 7, 9 | ||
| MinPasswordLength | string | 3, 4, 7, 9 | ||
| MixedDomainMode | string | 3, 4, 7, 9 | ||
| Mode | string | 4654, 5451 | ||
| ModifiedCAPs | string | 1, 4, 8, 9 | ||
| ModifiedObjectProperties | string | 5, 8, 8, 8 | Transaction = '1' -> '0' |
|
| Module | string | 5056, 5062 | ||
| ModuleName | string | 0, 3, 5, 6 | ||
| MulticastFlowsEnabled | string | 4, 4, 4, 9 | ||
| NASIPv4Address | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
| NASIPv6Address | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
| NASIdentifier | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
| NASPort | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
| NASPortType | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
| NamingContext | string | 4928, 4929, 4930, 4931, 4932, 4933 | naming context to replicate. | |
| NetbiosName | string | 4864, 4865, 4866, 4867 | NetBIOS name of the trust partner. This parameter might not be captured in the event, and in that case appears as "-". | |
| NetworkPolicyName | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
| NewBlockedOrdinals | string | 4909, 4910 | ||
| NewDate | string | 1, 4, 6, 6 | ||
| NewIgnoreDefaultSettings | string | 0, 1, 4, 9 | ||
| NewIgnoreLocalSettings | string | 0, 1, 4, 9 | ||
| NewMaxUsers | string | 1, 3, 4, 5 | ||
| NewObjectDN | string | 5138, 5139 | New distinguished name of moved object. | |
| NewProcessId | string | 4688 | 0x2260 |
|
| NewProcessName | string | 4688 | C:\Windows\System32\conhost.exe |
|
| NewRemark | string | 1, 3, 4, 5 | ||
| NewSD | string | 1, 3, 4, 5 | ||
| NewSd | string | 4670, 4715, 4817, 4907, 4911, 4913 | the Security Descriptor Definition Language (SDDL) value for the new Central Policy ID (for the policy that has been applied to the object). | S:ARAI(RA;;;;;WD;("IMAGELOAD",TU,0x0,1)) |
| NewSecurityDescriptor | string | 0, 0, 4, 9 | ||
| NewSecuritySettings | string | 1, 2, 4, 5 | ||
| NewShareFlags | string | 1, 3, 4, 5 | ||
| NewSigningCertificateHash | string | 1, 2, 5, 6 | ||
| NewState | string | 4, 5, 8, 9 | ||
| NewTargetUserName | string | 1, 4, 7, 8 | ||
| NewTemplateContent | string | 4899, 4900 | ||
| NewTime | string | 1, 4, 6, 6 | ||
| NewUacValue | string | 4720, 4738, 4741, 4742 | specifies flags that control password, lockout, disable/enable, script, and other behavior for the user or computer account. If the value of userAccountControl attribute of computer object was changed, you will see the new value here. | 0x15 |
| NewValue | string | 4657, 4934, 5065, 5067, 5070, 5122, 5123 | new value for changed registry key value. | %%1800 |
| NewValueType | string | 4, 5, 6, 7 | %%1873 |
|
| NextPublish | string | 2, 4, 7, 8 | ||
| NextPublishForBaseCRL | string | 1, 4, 7, 8 | ||
| NextPublishForDeltaCRL | string | 1, 4, 7, 8 | ||
| NextUpdate | string | 1, 4, 7, 8 | ||
| Node | string | 1, 4, 8, 9 | ||
| NotificationPackageName | string | 1, 4, 4, 6 | ||
| ObjectClass | string | 5136, 5137, 5138, 5139, 5141, 5169, 5170 | class of the object that was deleted. | |
| ObjectCollectionName | string | 5888, 5889, 5890 | the name of COM+ collection to which the new object was added. | InterfacesForComponent |
| ObjectDN | string | 5136, 5137, 5141, 5169, 5170 | distinguished name of the object that was deleted. | |
| ObjectGUID | string | 5136, 5137, 5138, 5139, 5141, 5169, 5170 | each Active Directory object has globally unique identifier (GUID), which is a 128-bit value that is unique not only in the enterprise but also across the world. | |
| ObjectIdentifyingProperties | string | 5888, 5889, 5890 | object-specific fields with the names and identifiers for the new object. | ID = {D155805A-726F-4163-8879-E4AAC4F058F3} |
| ObjectName | string | 4656, 4657, 4659, 4661, 4662, 4663, 4666, 4670, 4674, 4691, 4817, 4818, 4907, 4911, 4913 | full path and/or name of the object on which the Central Access Policy was changed. | root\cimv2\security\MicrosoftVolumeEncryption |
| ObjectPath | string | 0, 3, 5, 9 | ||
| ObjectProperties | string | 5889, 5890 | the list of new object's (Object Name) properties. | Name = T1218.009 |
| ObjectServer | string | 4656, 4658, 4659, 4660, 4661, 4662, 4663, 4670, 4673, 4674, 4817, 4818, 4819, 4907, 4911, 4913 | has "Security" value for this event. | WMI |
| ObjectType | string | 4656, 4659, 4661, 4662, 4663, 4670, 4674, 4691, 4817, 4818, 4819, 4907, 4911, 4913, 5140, 5143, 5145 | The type of an object that was accessed during the operation. Always "File" for this event. | WMI Namespace |
| ObjectValueName | string | 4, 5, 6, 7 | ConfigXML |
|
| ObjectVirtualPath | string | 0, 3, 5, 9 | ||
| OemInformation | string | 3, 4, 7, 9 | ||
| OldBlockedOrdinals | string | 4909, 4910 | ||
| OldIgnoreDefaultSettings | string | 0, 1, 4, 9 | ||
| OldIgnoreLocalSettings | string | 0, 1, 4, 9 | ||
| OldMaxUsers | string | 1, 3, 4, 5 | ||
| OldObjectDN | string | 5138, 5139 | Old distinguished name of moved object. | |
| OldRemark | string | 1, 3, 4, 5 | ||
| OldSD | string | 1, 3, 4, 5 | ||
| OldSd | string | 4670, 4715, 4817, 4907, 4911, 4913 | the Security Descriptor Definition Language (SDDL) value for the old Central Policy ID (for the policy that was formerly applied to the object). | D:(A;;GA;;;BA)(A;;GA;;;SY) |
| OldSecurityDescriptor | string | 0, 0, 4, 9 | ||
| OldShareFlags | string | 1, 3, 4, 5 | ||
| OldTargetUserName | string | 1, 4, 7, 8 | ||
| OldTemplateContent | string | 4899, 4900 | ||
| OldUacValue | string | 4720, 4738, 4741, 4742 | specifies flags that control password, lockout, disable/enable, script, and other behavior for the user or computer account. This parameter contains the previous value of userAccountControlattribute of computer object. | 0x15 |
| OldValue | string | 4657, 5065, 5067, 5070 | old value for changed registry key value. | %%1800 |
| OldValueType | string | 4, 5, 6, 7 | %%1873 |
|
| OpCorrelationID | string | 5136, 5137, 5138, 5139, 5141, 5169, 5170 | multiple modifications are often executed as one operation via LDAP. | |
| Opcode | integer | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416 | 0 |
|
| Opcode | string | 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424 | ||
| Operation | string | 5058, 5059, 5061, 5063, 5064, 5066, 5068, 5069 | performed operation. | %%2480 |
| OperationId | string | 4666, 4865, 4866, 4867 | unique hexadecimal identifier of the operation. You can correlate this event with other events (4865(S): A trusted forest information entry was added, 4866(S): A trusted forest information entry was removed) using this field. | |
| OperationMode | string | 4, 4, 4, 9 | ||
| OperationName | string | 4, 6, 6, 6 | ||
| OperationType | string | 4657, 4662, 5136, 5169, 5170 | type of performed operation. | Object Access |
| Options | string | 4928, 4929, 4930, 4931, 4932, 4933, 4937 | decimal value of DRS Options. | |
| Ordinal | string | 1, 4, 6, 7 | ||
| OriginalProfile | string | 1, 5, 5, 7 | %%14644 |
|
| OutboundSpi | string | 1, 4, 5, 5 | ||
| Package | string | 3, 5, 7, 8 | ||
| PackageName | string | 4, 6, 7, 7 | MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 |
|
| PackageSid | string | 2, 3, 5, 8 | ||
| PacketsDiscarded | string | 1, 4, 5, 9 | ||
| ParentProcessId | string | 4697, 4698, 4699, 4700, 4701, 4702 | ||
| PasswordHistoryLength | string | 3, 4, 7, 9 | ||
| PasswordLastSet | string | 4720, 4738, 4741, 4742 | last time the account's password was modified. If the value of pwdLastSet attribute of computer object was changed, you will see the new value here. For example: 8/12/2015 11:41:39 AM. This value will be changed, for example, after manual computer account reset action or automatically every 30 days by default for computer objects. | %%1794 |
| PasswordProperties | string | 3, 4, 7, 9 | ||
| PeerMac | string | 2, 3, 5, 6 | ||
| PeerName | string | 1, 4, 6, 8 | ||
| PeerPrivateAddress | string | 1, 4, 5, 5 | ||
| PercentFull | string | 0, 1, 1, 3 | ||
| Policy | string | 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474 | ||
| PolicyName | string | 4820, 4821, 4823 | ||
| Position | string | 5066, 5068 | ||
| PreAuthType | integer | 4, 6, 7, 8 | 2 |
|
| PreAuthType | string | 4768, 4771, 4820, 4824 | the code of pre-Authentication type which was used in TGT request. | |
| PreviousDate | string | 1, 4, 6, 6 | ||
| PreviousTime | string | 1, 4, 6, 6 | ||
| PrimaryGroupId | integer | 4720, 4738 | Relative Identifier (RID) of user's object primary group. | 513 |
| PrimaryGroupId | string | 4720, 4738, 4741, 4742 | Relative Identifier (RID) of computer's object primary group. | |
| PrivateKeyUsageCount | string | 4880, 4881 | ||
| PrivilegeList | string | 4656, 4659, 4661, 4672, 4673, 4674, 4704, 4705, 4720, 4723, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4780, 4781, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4830 | the list of user privileges which were used during the operation, for example, SeBackupPrivilege. This parameter might not be captured in the event, and in that case appears as "-". See full list of user privileges in "Table 8. User Privileges.". | SeTakeOwnershipPrivilege |
| ProcessCreationTime | string | 5376, 5377, 5379, 5380, 5381, 5382 | 2022-06-28 15:09:44.051913 UTC |
|
| ProcessID | string | 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4949, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5478, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424 | Hexadecimal Process ID of the process that attempted to create the connection. | "760" |
| ProcessId | integer | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416 | Hexadecimal Process ID of the process which was permitted to bind to the local port. | 9048 |
| ProcessId | string | 4615, 4616, 4624, 4625, 4648, 4649, 4656, 4657, 4658, 4659, 4660, 4661, 4663, 4670, 4673, 4674, 4688, 4689, 4690, 4691, 4696, 4703, 4818, 4904, 4905, 4907, 4911, 4913, 4985, 5039, 5050, 5051, 5152, 5153, 5154, 5155, 5158, 5159, 5446, 5447, 5448, 5449, 5450, 5712, 6417, 6418 | Hexadecimal Process ID of the process which was permitted to bind to the local port. | 0x8f8 |
| Process_Command_Line | string | 4688 | C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
| ProductName | string | 6406, 6408 | ||
| Profile | string | 4944, 4951, 4952, 4953 | the name of the profile of the ignored rule. | |
| ProfileChanged | string | 4946, 4947, 4948, 4950, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049 | the name of profile in which setting was changed. | Public |
| ProfilePath | string | 4720, 4738, 4741, 4742 | specifies a path to the account's profile. This value can be a null string, a local absolute path, or a UNC path. If the value of profilePath attribute of computer object was changed, you will see the new value here. For computer objects, it is optional, and typically is not set. You can change this attribute by using Active Directory Users and Computers, or through a script, for example. | %%1793 |
| ProfileUsed | string | 4, 4, 5, 9 | ||
| Profiles | string | 0, 1, 3, 5 | ||
| Properties | string | 4661, 4662 | first part is the type of access that was used. Typically has the same value as Accesses field. | --- |
| PropertyIndex | string | 2, 4, 8, 9 | ||
| PropertyName | string | 4892, 5069, 5070, 5123 | ||
| PropertyType | string | 2, 4, 8, 9 | ||
| PropertyValue | string | 2, 4, 8, 9 | ||
| ProtectedDataFlags | string | 4694, 4695 | - | 0x0 |
| Protocol | integer | 5152, 5154, 5156, 5157, 5158 | Protocol number. | 6 |
| Protocol | string | 4654, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159 | Protocol number. | |
| ProtocolSequence | string | 4816, 5712 | ||
| ProviderContextKey | string | 5443, 5449 | 382FC699-0C62-4D70-B30A-FBD3D01201AB |
|
| ProviderContextName | string | 5443, 5449 | MPSSVC |
|
| ProviderContextType | string | 5443, 5449 | %%16388 |
|
| ProviderGUID | string | 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424 | ||
| ProviderKey | string | 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450 | DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62 |
|
| ProviderName | string | 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424 | the name of KSP through which the operation was performed. | Microsoft Software Key Storage Provider |
| ProviderType | string | 5442, 5448 | %%16387 |
|
| ProxyPolicyName | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
| PuaCount | string | 0, 2, 4, 9 | ||
| PuaPolicyId | string | 0, 2, 4, 9 | ||
| PubID | string | 0, 1, 1, 8 | ||
| PublishURLs | string | 2, 4, 7, 8 | ||
| Publisher | string | 0, 0, 5, 5 | ||
| PublisherGuid | string | 0, 1, 1, 7 | ||
| PublisherName | string | 0, 1, 1, 7 | ||
| QMFilterID | string | 4654, 4979, 4980, 4981, 4982, 4983, 4984 | ||
| QMLimit | string | 4650, 4651, 4979, 4980, 4981, 4982 | ||
| Qualifiers | string | 1102, 4689, 4703, 8222 | "0" |
|
| QuarantineGraceTime | string | 2, 6, 7, 7 | ||
| QuarantineHelpURL | string | 6276, 6277, 6278 | ||
| QuarantineSessionID | string | 6276, 6277, 6278 | ||
| QuarantineSessionIdentifier | string | 2, 2, 6, 7 | ||
| QuarantineState | string | 6272, 6276, 6277, 6278 | ||
| QuarantineSystemHealthResult | string | 6276, 6277, 6278 | ||
| QuickModeFilter | string | 4, 5, 7, 7 | ||
| QuickModeSaId | string | 5451, 5452 | ||
| ReadOperation | string | 3, 5, 7, 9 | %%8100 |
|
| Reason | string | 1101, 1106, 4958, 5057, 5060, 6273, 6274, 6275 | ||
| ReasonCode | string | 5632, 5633, 6273, 6274, 6275 | hexadecimal Reason Code for wired authentication results. | |
| ReasonForRejection | string | 3, 4, 5, 9 | ||
| ReasonText | string | 5632, 5633 | contains Reason Text (explanation of Reason Code) and Reason Code for wired authentication results. | |
| RecordNumber | integer | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | 843214 |
|
| RecoveryKeyId | string | 4692, 4693 | unique identifier of a recovery key. | |
| RecoveryReason | string | 3, 4, 6, 9 | ||
| RecoveryServer | string | 4692, 4693 | the name (typically - DNS name) of the computer that you contacted to recover your Master Key. | |
| RelatedActivityID | string | 1102, 4611, 4624, 4627, 4634, 4648, 4662, 4670, 4672, 4673, 4674, 4688, 4689, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4720, 4724, 4726, 4728, 4729, 4732 | ||
| RelativeTargetName | string | 1, 4, 5, 5 | PSEXESVC.exe |
|
| RemoteAddress | string | 4650, 4651, 4652, 4653, 4654, 4655, 4960, 4961, 4962, 4963, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 5451, 5452 | ||
| RemoteAddressMask | string | 4654, 5451, 5452 | ||
| RemoteAdminEnabled | string | 4, 4, 4, 9 | ||
| RemoteEMCertHash | string | 4980, 4982, 4983 | ||
| RemoteEMIssuingCA | string | 4980, 4982, 4983 | ||
| RemoteEMPrincipalName | string | 4979, 4980, 4981, 4982, 4983, 4984 | ||
| RemoteEMRootCA | string | 4980, 4982, 4983 | ||
| RemoteEventLogging | string | 2, 4, 6, 8 | ||
| RemoteIpAddress | string | 1, 2, 5, 7 | ||
| RemoteKeyModPort | string | 4650, 4651, 4652, 4653, 4979, 4980, 4981, 4982, 4983, 4984 | ||
| RemoteMMCertHash | string | 4651, 4652, 4981, 4982 | ||
| RemoteMMIssuingCA | string | 4651, 4652, 4981, 4982 | ||
| RemoteMMPrincipalName | string | 4650, 4651, 4652, 4653, 4979, 4980, 4981, 4982 | ||
| RemoteMMRootCA | string | 4651, 4652, 4981, 4982 | ||
| RemoteMachineID | string | 5156, 5157 | S-1-0-0 |
|
| RemotePort | string | 4654, 5451, 5452, 5712 | ||
| RemotePrivateAddress | string | 4, 4, 5, 6 | ||
| RemoteTunnelEndpoint | string | 4654, 5451, 5452 | ||
| RemoteUserID | string | 5156, 5157 | S-1-0-0 |
|
| ReplicationEvent | string | 4935, 4936 | there is no detailed information about this field in this document. | |
| ReplicationStatusCode | string | 3, 4, 6, 9 | ||
| RequestId | string | 4868, 4869, 4873, 4874, 4883, 4884, 4886, 4887, 4888, 4889, 4893, 4894 | ||
| RequestType | string | 4, 4, 6, 9 | ||
| Requester | string | 4886, 4887, 4888, 4889, 4893 | ||
| Resource | string | 2, 3, 5, 8 | ||
| ResourceAttributes | string | 4656, 4663 | - |
|
| ResourceManager | string | 4, 5, 8, 9 | 1768FEC9-9F65-11EC-B264-0EE277C94A07 |
|
| ResponderCookie | string | 4652, 4653 | ||
| RestrictedAdminMode | string | 2, 4, 4, 6 | - |
|
| RestrictedPermissions | string | 0, 4, 8, 9 | ||
| RestrictedSidCount | string | 4656, 4661 | Number of restricted SIDs in the token. Applicable to only specific Object Types. | |
| ReturnCode | integer | 3, 5, 7, 9 | 3221226021 |
|
| ReturnCode | string | 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5379, 5382 | has "0x0" value for Success events. | 0x0 |
| RevocationReason | string | 0, 4, 7, 8 | ||
| Role | string | 4650, 4651, 4652, 4653, 4654, 4666, 4979, 4980, 4981, 4982, 4983, 4984, 5451 | (Access Request Information) Role | |
| RoleSeparationEnabled | string | 4, 7, 8, 9 | ||
| RowsDeleted | string | 4, 6, 8, 9 | ||
| RpcCallClientLocality | string | 4698, 4699, 4700, 4701, 4702 | ||
| RuleAttr | string | 4, 5, 7, 9 | Local Port |
|
| RuleId | string | 4945, 4946, 4947, 4948, 4951, 4952, 4953, 4957, 4958 | the unique identifier for not applied firewall rule. | {5C6A0A6C-7D33-4849-8164-F43696BFF0D9} |
| RuleName | string | 4945, 4946, 4947, 4948, 4951, 4952, 4953, 4957, 4958 | the name of the rule which was not applied. | Usermode Font Driver Host |
| SPI | string | 4960, 4961, 4962, 4963, 4965 | ||
| SSID | string | 2, 3, 5, 6 | ||
| SamAccountName | string | 4720, 4727, 4731, 4735, 4737, 4738, 4741, 4742, 4744, 4745, 4749, 4750, 4754, 4755, 4759, 4760, 4783, 4784, 4790, 4791 | This is a new name of changed group used to support clients and servers from previous versions of Windows (pre-Windows 2000 logon name). If the value of sAMAccountName attribute of group object was changed, you will see the new value here. For example: ServiceDesk. | threatactor |
| Schema | string | 5380, 5382 | ||
| SchemaFriendlyName | string | 5380, 5382 | ||
| Scope | string | 5064, 5065, 5066, 5067, 5068, 5069, 5070 | ||
| ScopeName | string | 4, 6, 6, 6 | ||
| ScriptPath | string | 4720, 4738, 4741, 4742 | specifies the path of the account's logon script. If the value of scriptPathattribute of computer object was changed, you will see the new value here. For computer objects, it is optional, and typically is not set. You can change this attribute by using Active Directory Users and Computers, or through a script, for example. | %%1793 |
| SearchString | string | 0, 3, 5, 8 | ||
| SecurityDescriptor | string | 4898, 5071 | ||
| SecurityError | string | 1, 4, 6, 8 | ||
| SecurityPackageName | string | 2, 2, 4, 6 | ||
| SecuritySettings | string | 2, 4, 8, 8 | ||
| SerialNumber | string | 1, 2, 5, 5 | ||
| ServerNames | string | 1, 5, 6, 8 | ||
| ServerPortName | string | 1, 4, 5, 6 | ||
| ServiceAccount | string | 4, 6, 7, 9 | LocalSystem |
|
| ServiceFileName | string | 4, 6, 7, 9 | %SystemRoot%\PSEXESVC.exe |
|
| ServiceName | string | 4697, 4768, 4769, 4770, 4771, 4772, 4773, 4820, 4821, 4824 | the name of the service in the Kerberos Realm to which TGT request was sent. Typically has one of the following formats: krbtgt/DOMAIN_NETBIOS_NAME. Example: krbtgt/CONTOSO, krbtgt/DOMAIN_FULL_NAME. Example: krbtgt/CONTOSO.LOCAL | krbtgt |
| ServicePrincipalNames | string | 4741, 4742 | The list of SPNs, registered for computer account. If the SPN list of a computer account changed, you will see the new SPN list in Service Principal Names field (note that you will see the new list instead of changes). | |
| ServiceSid | string | 4768, 4769, 4770, 4820, 4821 | SID of the account or computer object for which the TGS ticket was renewed. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID cannot be resolved, you will see the source data in the event. | S-1-5-21-989241848-306340870-1210095284-502 |
| ServiceStartType | string | 4, 6, 7, 9 | ||
| ServiceType | string | 4, 6, 7, 9 | 0x10 |
|
| SessionID | string | 4932, 4933, 4934 | unique identifier of replication session. Using this field you can find "4932: Synchronization of a replica of an Active Directory naming context has begun." and "4933: Synchronization of a replica of an Active Directory naming context has ended." events for the same session. | |
| SessionId | integer | 4800, 4801 | unique ID of unlocked session. | 2 |
| SessionId | string | 1102, 4611, 4624, 4627, 4634, 4648, 4662, 4670, 4672, 4673, 4674, 4688, 4689, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4720, 4724, 4726, 4728, 4729, 4732, 4800, 4801, 4802, 4803 | unique ID of a session for which screen saver was dismissed. You can see the list of current session IDs using "query session" command in command prompt. | |
| SessionName | string | 4778, 4779 | the name of disconnected session | RDP-Tcp#1 |
| SettingType | string | 0, 4, 5, 9 | Enable Windows Defender Firewall |
|
| SettingValue | string | 0, 4, 5, 9 | No |
|
| ShareLocalPath | string | 5140, 5142, 5143, 5144, 5145 | the full system (NTFS) path for accessed share. The format is: PATH | C:\Windows |
| ShareName | string | 5140, 5142, 5143, 5144, 5145 | the name of accessed network share. | \*\E$ |
| SidFilteringEnabled | string | 4706, 4716 | SID Filtering state for the new trust. | |
| SidHistory | string | 4720, 4727, 4731, 4735, 4737, 4738, 4741, 4742, 4744, 4745, 4749, 4750, 4754, 4755, 4759, 4760, 4783, 4784, 4790, 4791 | contains previous SIDs used for the object if the object was moved from another domain. Whenever an object is moved from one domain to another, a new SID is created and becomes the objectSID. The previous SID is added to the sIDHistory property. If the value of sIDHistory attribute of group object was changed, you will see the new value here. | - |
| SidList | string | 4675, 4765, 4830, 4908, 4964 | the list of special group SIDs, which New Logon\Security ID is a member of. | |
| SigmaEventCode | integer | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | 8222 |
|
| SiloName | string | 4820, 4821, 4823 | ||
| SourceAddr | string | 4928, 4929, 4930, 4931 | DNS record of computer to which the modification request was sent. | |
| SourceAddress | string | 5146, 5147, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159 | The local IP address of the computer running the application. | :: |
| SourceDRA | string | 4928, 4929, 4930, 4931, 4932, 4933, 4937 | source directory replication agent distinguished name. | |
| SourceHandleId | string | 0, 4, 6, 9 | 0xb88 |
|
| SourcePort | integer | 5152, 5154, 5156, 5157, 5158 | Port number which application was bind. | 5355 |
| SourcePort | string | 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159 | The port number used by the application. | |
| SourceProcessId | string | 0, 4, 6, 9 | 0x8f8 |
|
| SourceSid | string | 4765, 4830 | ||
| SourceUserName | string | 4765, 4766, 4830 | ||
| Source_Port | integer | 4768, 4769, 5140, 5145 | 49901 |
|
| Source_Port | string | 4624, 4625, 4648 | - |
|
| Source_Workstation | string | 4624, 4625, 4648, 4768, 4769, 4776, 5140, 5145 | EC2AMAZ-NNKUICG |
|
| SourcevSwitchPort | string | 5146, 5147 | ||
| SpnName | string | 1, 5, 6, 8 | ||
| StagingReason | string | 1, 4, 8, 8 | ||
| StartUSN | string | 2, 3, 4, 9 | ||
| State | string | 4652, 4653, 4654, 4983, 4984 | ||
| Status | string | 4625, 4665, 4689, 4768, 4769, 4771, 4776, 4777, 4793, 4794, 4820, 4821, 4822, 4823, 4824, 5125 | for Success events it has "0x0" value. | 0xc000006d |
| StatusCode | string | 4928, 4929, 4930, 4931, 4933, 4934, 4937 | if there are no issues or errors, the status code will be "0". If an error happened, you will receive Failure event and Status Code will not be equal to "0". | |
| StoreUrl | string | 4, 6, 6, 8 | ||
| SubLayerKey | string | 5444, 5450 | 3C1CD879-1B8C-4AB4-8F83-5ED129176EF3 |
|
| SubLayerName | string | 5444, 5450 | windefend |
|
| SubLayerType | string | 5444, 5450 | %%16388 |
|
| SubStatus | string | 2, 4, 5, 6 | 0xc000006a |
|
| Sub_Status | string | 2, 4, 5, 6 | 0xc000006a |
|
| SubcategoryGuid | string | 4719, 4912 | the unique GUID of changed subcategory. | 0CCE9215-69AE-11D9-BED3-505054503030 |
| SubcategoryId | string | 4719, 4912 | the name of auditing subcategory which state was changed. | %%12544 |
| Subject | string | 4887, 4888, 4889 | ||
| SubjectDomainName | string | 1102, 4611, 4615, 4616, 4624, 4625, 4626, 4627, 4648, 4649, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4817, 4818, 4819, 4826, 4830, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4873, 4874, 4875, 4876, 4877, 4882, 4883, 4884, 4885, 4890, 4891, 4892, 4894, 4896, 4904, 4905, 4907, 4911, 4912, 4913, 4964, 4985, 5039, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5632, 5633, 5712, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6416, 6419, 6420, 6421, 6422, 6423, 6424 | subject's domain or computer name. | training1 |
| SubjectKeyIdentifier | string | 4887, 4888, 4889 | ||
| SubjectLogonId | integer | 5888, 5890 | hexadecimal value that can help you correlate this event with recent events that might contain the same Logon ID, for example, "4624: An account was successfully logged on." | 1207182 |
| SubjectLogonId | string | 1102, 4611, 4615, 4616, 4624, 4625, 4626, 4627, 4648, 4649, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4817, 4818, 4819, 4826, 4830, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4873, 4874, 4875, 4876, 4877, 4882, 4883, 4884, 4885, 4890, 4891, 4892, 4894, 4896, 4904, 4905, 4907, 4911, 4912, 4913, 4964, 4985, 5039, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5632, 5633, 5712, 5888, 5889, 5890, 6416, 6419, 6420, 6421, 6422, 6423, 6424 | hexadecimal value that can help you correlate this event with recent events that might contain the same Logon ID, for example, "4624: An account was successfully logged on." | 0xcedae |
| SubjectMachineName | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
| SubjectMachineSID | string | 6272, 6273, 6274, 6275, 6276, 6277, 6278 | ||
| SubjectUserDomainName | string | 5888, 5889, 5890 | subject's domain or computer name. | EC2AMAZ-NNKUICG |
| SubjectUserName | string | 1102, 4611, 4615, 4616, 4624, 4625, 4626, 4627, 4648, 4649, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4817, 4818, 4819, 4826, 4830, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4873, 4874, 4875, 4876, 4877, 4882, 4883, 4884, 4885, 4890, 4891, 4892, 4894, 4896, 4904, 4905, 4907, 4911, 4912, 4913, 4964, 4985, 5039, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5632, 5633, 5712, 5888, 5889, 5890, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6416, 6419, 6420, 6421, 6422, 6423, 6424 | the name of the account that forbids the device installation. | user |
| SubjectUserSid | string | 1102, 4611, 4615, 4616, 4624, 4625, 4626, 4627, 4648, 4649, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4767, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4817, 4818, 4819, 4826, 4830, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4873, 4874, 4875, 4876, 4877, 4882, 4883, 4884, 4885, 4890, 4891, 4892, 4894, 4896, 4904, 4905, 4907, 4911, 4912, 4913, 4964, 4985, 5039, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5712, 5888, 5889, 5890, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6416, 6419, 6420, 6421, 6422, 6423, 6424 | SID of account that forbids the device installation. | S-1-5-21-989241848-306340870-1210095284-500 |
| SystemTime | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | '2022-07-28 14:45:40.532999 UTC' |
|
| System_Props_Xml | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 |
|
|
| TableId | string | 4, 6, 8, 9 | ||
| TargetDomainName | string | 4624, 4625, 4626, 4627, 4634, 4647, 4648, 4649, 4675, 4688, 4696, 4703, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4772, 4773, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4820, 4821, 4830, 4964 | subject's domain or computer name. | doazlab.com |
| TargetHandleId | string | 0, 4, 6, 9 | 0xf80 |
|
| TargetInfo | string | 4, 4, 6, 8 | localhost |
|
| TargetLinkedLogonId | string | 2, 4, 4, 6 | 0x0 |
|
| TargetLogonGuid | string | 4648, 4964 | a GUID that can help you correlate this event with another event that can contain the same Logon GUID, "4769(S, F): A Kerberos service ticket was requested event on a domain controller. | 00000000-0000-0000-0000-000000000000 |
| TargetLogonId | string | 4618, 4624, 4626, 4627, 4634, 4647, 4688, 4696, 4703, 4800, 4801, 4802, 4803, 4964 | hexadecimal value that can help you correlate this event with recent events that might contain the same Logon ID, for example, "4624: An account was successfully logged on." | 0x9fb6c3 |
| TargetName | string | 3, 5, 7, 9 | WindowsLive:target=virtualapp/didlogical |
|
| TargetOutboundDomainName | string | 2, 4, 4, 6 | - |
|
| TargetOutboundUserName | string | 2, 4, 4, 6 | - |
|
| TargetProcessId | string | 4690, 4696 | hexadecimal Process ID of the new process with new security token. If you convert the hexadecimal value to decimal, you can compare it to the values in Task Manager. | 0x4 |
| TargetProcessName | string | 4, 6, 6, 9 | ||
| TargetServer | string | 3, 5, 7, 8 | ||
| TargetServerName | string | 4, 4, 6, 8 | localhost |
|
| TargetSid | string | 4704, 4705, 4717, 4718, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4771, 4780, 4781, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4798, 4799, 4820, 4824, 4830 | SID of the group which members were enumerated. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID cannot be resolved, you will see the source data in the event. | S-1-5-32-545 |
| TargetUserDomain | string | 1, 4, 6, 8 | ||
| TargetUserName | string | 4618, 4624, 4625, 4626, 4627, 4634, 4647, 4648, 4649, 4675, 4688, 4696, 4703, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4776, 4777, 4780, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4820, 4821, 4824, 4830, 4964 | the name of the account that performed the logon. | user |
| TargetUserSid | string | 4618, 4624, 4625, 4626, 4627, 4634, 4647, 4675, 4688, 4696, 4703, 4800, 4801, 4802, 4803, 4912, 4964 | SID of account that performed the logon. | S-1-5-21-989241848-306340870-1210095284-500 |
| Target_Domain | string | 4624, 4625, 4627, 4634, 4648, 4688, 4703, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4798, 4799, 4800, 4801 | doazlab.com |
|
| Target_Server_Name | string | 4, 4, 6, 8 | localhost |
|
| Target_User_Name | string | 4624, 4625, 4627, 4634, 4648, 4688, 4703, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4798, 4799, 4800, 4801 | user |
|
| TaskContent | string | 4698, 4699, 4700, 4701 | the XML of the disabled task. | |
| TaskContentNew | string | 0, 2, 4, 7 | ||
| TaskName | string | 4698, 4699, 4700, 4701, 4702 | updated/changed scheduled task name. | \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskLogon |
| TdoAttributes | string | 4675, 4706, 4716 | the decimal value of attributes for new trust. | |
| TdoDirection | string | 4675, 4706, 4716 | the direction of new trust. If this attribute was not changed, then it will have "-" value or its old value. | |
| TdoSid | string | 4, 5, 6, 7 | ||
| TdoType | string | 4675, 4706, 4716 | the type of new trust. If this attribute was not changed, then it will have "-" value or its old value. | |
| TemplateContent | string | 4, 8, 8, 9 | ||
| TemplateDSObjectFQDN | string | 4898, 4899, 4900 | ||
| TemplateInternalName | string | 4898, 4899, 4900 | ||
| TemplateOID | string | 4898, 4899, 4900 | ||
| TemplateSchemaVersion | string | 4898, 4899, 4900 | ||
| TemplateVersion | string | 4898, 4899, 4900 | ||
| TestSigning | string | 2, 4, 6, 8 | ||
| ThreadID | string | 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4949, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5478, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424 | "9040" |
|
| TicketEncryptionType | string | 4768, 4769, 4770, 4820, 4821 | the cryptographic suite that was used in renewed TGS. | 0x12 |
| TicketOptions | string | 4768, 4769, 4770, 4771, 4772, 4773, 4820, 4821, 4824 | this is a set of different Ticket Flags in hexadecimal format | 0x40810010 |
| TokenElevationType | string | 4688 | %%1936 |
|
| Token_Elevation_Type | string | 4688 | %%1936 |
|
| Token_Elevation_Type_id | integer | 4688 | 1936 |
|
| TopLevelName | string | 4864, 4865, 4866, 4867 | the name of the modified trusted forest information entry. | |
| TrafficSelectorId | string | 4654, 5451, 5452 | ||
| TransactionId | string | 4656, 4659, 4660, 4661, 4664, 4985 | unique GUID of the transaction. This field can help you correlate this event with other events that might contain the same Transaction ID, such as "4656(S, F): A handle to an object was requested." | 870CF9EA-0BF4-11ED-80BB-42010A743766 |
| TransitedServices | string | 1, 2, 4, 8 | ||
| TransmittedServices | string | 4624, 4625, 4649, 4769 | this field contains list of SPNs which were requested if Kerberos delegation was used. | - |
| TransportFilterId | string | 1, 4, 5, 5 | ||
| TreeDelete | string | 1, 1, 4, 5 | ||
| TunnelId | string | 4654, 5451, 5452 | ||
| TypeOfChange | string | 3, 4, 4, 9 | ||
| USN | string | 3, 4, 4, 9 | ||
| UserAccountControl | string | 4720, 4738, 4741, 4742 | shows the list of changes in userAccountControl attribute. You will see a line of text for each change. See possible values in here: "Table 7. User's or Computer's account UAC flags.". In the "User Account Control field text" column, you can see text that will be displayed in the User Account Controlfield in 4742 event. | %%2080 |
| UserClaims | string | 2, 4, 6, 6 | ||
| UserData_Xml | string | 0, 1, 1, 2 |
|
|
| UserID | string | 1101, 1102, 1103, 1105, 1106, 1107, 1108, 4610, 4611, 4612, 4614, 4615, 4616, 4618, 4621, 4622, 4624, 4625, 4626, 4627, 4634, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654, 4655, 4656, 4657, 4658, 4659, 4660, 4661, 4662, 4663, 4664, 4665, 4666, 4667, 4668, 4670, 4671, 4672, 4673, 4674, 4675, 4688, 4689, 4690, 4691, 4692, 4693, 4694, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4706, 4707, 4709, 4710, 4711, 4712, 4713, 4714, 4715, 4716, 4717, 4718, 4719, 4720, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 4779, 4780, 4781, 4782, 4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790, 4791, 4792, 4793, 4794, 4797, 4798, 4799, 4800, 4801, 4802, 4803, 4816, 4817, 4818, 4819, 4820, 4821, 4822, 4823, 4824, 4825, 4826, 4830, 4864, 4865, 4866, 4867, 4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4880, 4881, 4882, 4883, 4884, 4885, 4886, 4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898, 4899, 4900, 4902, 4904, 4905, 4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4928, 4929, 4930, 4931, 4932, 4933, 4934, 4935, 4936, 4937, 4944, 4945, 4946, 4947, 4948, 4950, 4951, 4952, 4953, 4956, 4957, 4958, 4960, 4961, 4962, 4963, 4964, 4965, 4976, 4977, 4978, 4979, 4980, 4981, 4982, 4983, 4984, 4985, 5027, 5028, 5029, 5030, 5031, 5032, 5035, 5037, 5038, 5039, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5049, 5050, 5051, 5056, 5057, 5058, 5059, 5060, 5061, 5062, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5071, 5122, 5123, 5124, 5125, 5126, 5127, 5136, 5137, 5138, 5139, 5140, 5141, 5142, 5143, 5144, 5145, 5146, 5147, 5148, 5149, 5150, 5151, 5152, 5153, 5154, 5155, 5156, 5157, 5158, 5159, 5168, 5169, 5170, 5376, 5377, 5378, 5379, 5380, 5381, 5382, 5440, 5441, 5442, 5443, 5444, 5446, 5447, 5448, 5449, 5450, 5451, 5452, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5471, 5472, 5473, 5474, 5477, 5483, 5484, 5632, 5633, 5712, 5888, 5889, 5890, 6144, 6145, 6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280, 6281, 6400, 6401, 6402, 6403, 6404, 6405, 6406, 6407, 6408, 6409, 6410, 6416, 6417, 6418, 6419, 6420, 6421, 6422, 6423, 6424, 8222 | "S-1-5-18" |
|
| UserName | string | 5446, 5447, 5448, 5449, 5450 | NT AUTHORITY\NETWORK SERVICE |
|
| UserParameters | string | 4720, 4738, 4741, 4742 | if you change any setting using Active Directory Users and Computers management console in Dial-in tab of computer's account properties, then you will see \ |
- |
| UserPrincipalName | string | 4720, 4738, 4741, 4742 | internet-style login name for the account, based on the Internet standard RFC 822. By convention this should map to the account's email name. If the value of userPrincipalNameattribute of computer object was changed, you will see the new value here. For computer objects, it is optional, and typically is not set. You can change this attribute by using Active Directory Users and Computers, or through a script, for example. | - |
| UserSid | string | 5446, 5447, 5448, 5449, 5450 | S-1-5-20 |
|
| UserUPN | string | 3, 5, 7, 8 | ||
| UserWorkstations | string | 4720, 4738, 4741, 4742 | contains the list of NetBIOS or DNS names of the computers from which the user can logon. Each computer name is separated by a comma. The name of a computer is the sAMAccountName property of a computer object. If the value of userWorkstations attribute of computer object was changed, you will see the new value here. For computer objects, it is optional, and typically is not set. You can change this attribute by using Active Directory Users and Computers, or through a script, for example. | %%1793 |
| ValidFrom | string | 4, 5, 8, 9 | ||
| ValidTo | string | 4, 5, 8, 9 | ||
| Value | string | 4891, 5069 | ||
| VendorIds | string | 1, 4, 6, 6 | MONITOR\Default_Monitor |
|
| Version | integer | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416 | 3 |
|
| VirtualAccount | string | 2, 4, 4, 6 | %%1843 |
|
| VirtualFileName | string | 0, 1, 5, 5 | ||
| VlanTag | string | 5146, 5147, 5150, 5151 | ||
| VsmLaunchType | string | 2, 4, 6, 8 | ||
| Weight | integer | 5447, 5450 | 4096 |
|
| Weight | string | 5441, 5444, 5447, 5450 | ||
| Workstation | string | 4776, 4777, 4793, 4794, 4797 | the name of computer account from which the password was queried from For example "DC01". If the change request was sent locally (from the same server) this field will have the same name as the computer account | EC2AMAZ-1CL0VOR |
| WorkstationName | string | 4624, 4625, 4649 | machine name from which logon attempt was performed. | EC2AMAZ-NNKUICG |
| change_type | string | 1102, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738 | user |
|
| dest | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | windowsvictim |
|
| dest_nt_domain | string | 4624, 4625, 4627, 4634, 4648, 4688, 4703, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4798, 4799, 4800, 4801 | training1 |
|
| dest_nt_host | string | 4, 4, 6, 8 | localhost |
|
| dest_port | integer | 5152, 5156, 5157 | 5355 |
|
| dvc | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | windowsvictim |
|
| dvc_nt_host | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | windowsvictim_f57c890c-8963-4b7b-b267-755cd8191034 |
|
| event_id | integer | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | 843214 |
|
| file_name | string | 4656, 4663, 4907, 4911, 5058, 5140, 5142, 5145 | c56b3f40b196d4f8d43940688b5b8765_4d6cbdb8-0892-45ee-9d0d-f2e8b7a5fa78 |
|
| file_path | string | 4656, 4663, 4907, 4911, 5058, 5140, 5142, 5145 | C:\Windows |
|
| new_process | string | 4688 | C:\Windows\System32\conhost.exe |
|
| new_process_id | string | 4688 | 0x2260 |
|
| new_process_name | string | 4688 | conhost.exe |
|
| notification | string | 4, 4, 6, 6 | ||
| object | string | 1102, 4611, 4624, 4627, 4634, 4648, 4662, 4670, 4672, 4673, 4674, 4688, 4689, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4738 | Guest |
|
| object_attrs | string | 1102, 4703, 4717, 4718, 4719, 4722, 4724, 4725, 4726, 4738, 4946, 4947, 4948, 4957 | registry |
|
| object_category | string | 1102, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738 | user |
|
| object_file_name | string | 4656, 4657, 4661, 4662, 4663, 4674, 4907, 4911 | lsass.exe |
|
| object_file_path | string | 4656, 4657, 4661, 4662, 4663, 4674, 4907, 4911 | root\cimv2\security\MicrosoftVolumeEncryption |
|
| object_id | string | 4703, 4722, 4724, 4725, 4726, 4738 | S-1-5-21-582766833-432816504-4207985818-501 |
|
| param1 | string | 4709, 4710, 4711, 4712, 4816, 5038, 6281, 6410 | ||
| param2 | string | 4709, 4710, 4816 | ||
| param3 | string | 4709, 4816 | ||
| parent_process | string | 4688 | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
|
| parent_process_id | string | 4688 | 0x2024 |
|
| parent_process_name | string | 4688 | powershell.exe |
|
| parent_process_path | string | 4688 | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
|
| process_command_line_arguments | string | 4688 | 0xffffffff -ForceV1 |
|
| process_command_line_process | string | 4688 | C:\Windows\system32\conhost.exe |
|
| process_exec | string | 4673, 4674, 4688, 4689 | wevtutil.exe |
|
| process_id | integer | 5152, 5154, 5158, 5446, 5447, 5448, 5449, 5450 | 8456 |
|
| process_id | string | 4624, 4625, 4648, 4656, 4657, 4658, 4660, 4661, 4663, 4670, 4673, 4674, 4688, 4689, 4703, 4904, 4905, 4907, 4911, 4985 | 0xeb4 |
|
| process_path | string | 4624, 4625, 4648, 4656, 4657, 4658, 4660, 4661, 4663, 4670, 4673, 4674, 4688, 4689, 4703, 4904, 4905, 4907, 4911, 4985 | C:\Windows\System32\wevtutil.exe |
|
| registry_path | string | 4, 5, 6, 7 | \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN |
|
| registry_value_name | string | 4, 5, 6, 7 | ConfigXML |
|
| registry_value_type | string | 4, 5, 6, 7 | %%1873 |
|
| result | string | 4703, 4717, 4718, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738 | member was removed from a security-enabled local group |
|
| service_id | string | 4768, 4769 | S-1-5-21-989241848-306340870-1210095284-502 |
|
| service_name | string | 4697, 4768, 4769, 5478 | krbtgt |
|
| session_id | integer | 5888, 5890 | 1207182 |
|
| session_id | string | 4611, 4624, 4625, 4627, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4798, 4799, 4904, 4905, 4907, 4911, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5379, 5381, 6416 | 0xcedae |
|
| sigma_product | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | windows |
|
| sigma_service | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | security |
|
| signature | string | 1102, 4611, 4624, 4625, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4800, 4801, 4904, 4905, 4907, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890 | Windows Firewall settings were restored to the default values |
|
| signature_id | integer | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | 8222 |
|
| src | string | 4624, 4625, 4648, 4768, 4769, 4776, 4778, 5140, 5145 | EC2AMAZ-NNKUICG |
|
| src_ip | string | 4624, 4625, 4648, 4769, 5140 | ::ffff:10.0.1.8 |
|
| src_nt_domain | string | 4611, 4624, 4625, 4627, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4798, 4799, 4904, 4905, 4907, 4911, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5379, 5381, 6416 | training1 |
|
| src_nt_host | string | 4624, 4625, 4648, 4768, 4769, 4776, 5140, 5145 | EC2AMAZ-NNKUICG |
|
| src_port | integer | 4768, 4769, 5140, 5145, 5156, 5158 | 5355 |
|
| src_port | string | 4624, 4625, 4648 | - |
|
| src_user | string | 1102, 4611, 4624, 4625, 4627, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4798, 4799, 4904, 4905, 4907, 4911, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5379, 5381, 5888, 5890, 6416 | user |
|
| src_user_name | string | 4703, 4722, 4724, 4725, 4726, 4738 | user |
|
| start_mode | string | 4, 6, 7, 9 | manual |
|
| subject | string | 1102, 4611, 4624, 4625, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4800, 4801, 4904, 4905, 4907, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890 | Windows Firewall settings were restored to the default values |
|
| ta_windows_action | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | failure |
|
| ta_windows_security_CategoryString | string | 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738 | Account Management |
|
| ta_windows_status | string | 4625, 4689, 4768, 4769, 4776 | 0xc000006d |
|
| timeendpos | integer | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | 526 |
|
| timestartpos | integer | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | 496 |
|
| transport | string | 5152, 5154, 5156, 5157, 5158 | UDP |
|
| user_group | string | 4624, 4625, 4627, 4634, 4648, 4688, 4703, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4798, 4799, 4800, 4801 | user |
|
| user_id | string | 2, 2, 2, 8 | "S-1-5-18" |
|
| user_name | string | 4703, 4722, 4724, 4725, 4726, 4738 | Guest |
|
| vendor | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4696, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4704, 4705, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | Microsoft |
|
| vendor_product | string | 1102, 4611, 4624, 4625, 4627, 4634, 4648, 4656, 4657, 4658, 4660, 4661, 4662, 4663, 4670, 4672, 4673, 4674, 4688, 4689, 4690, 4695, 4697, 4698, 4699, 4700, 4701, 4702, 4703, 4717, 4718, 4719, 4720, 4722, 4724, 4725, 4726, 4728, 4729, 4732, 4733, 4738, 4768, 4769, 4776, 4778, 4779, 4798, 4799, 4800, 4801, 4904, 4905, 4907, 4911, 4946, 4947, 4948, 4949, 4950, 4957, 4985, 5058, 5059, 5061, 5140, 5142, 5145, 5152, 5154, 5156, 5157, 5158, 5379, 5381, 5446, 5447, 5448, 5449, 5450, 5478, 5888, 5890, 6416, 8222 | Microsoft Windows |
smbclient-security
| Field | Data Type | Event IDs | Example |
|---|---|---|---|
| EventID | integer | 31001, 31018 | 31018 |
| Name | string | 31001, 31018 | Microsoft-Windows-SMBClient |
| EventCode | integer | 31001, 31018 | 31018 |
| Guid | string | 31001, 31018 | 988C59C5-0A1C-45B6-A555-0C62276E327D |
| ProcessID | integer | 31001, 31018 | 4 |
| ProcessId | integer | 31001, 31018 | 4 |
| SigmaEventCode | integer | 31001, 31018 | 31018 |
| SystemTime | string | 31001, 31018 | '2022-05-23 16:00:29.832323 UTC' |
| ThreadID | integer | 31001, 31018 | 340 |
| UserID | string | 31001, 31018 | S-1-5-18 |
| sigma_product | string | 31001, 31018 | windows |
| sigma_service | string | 31001, 31018 | smbclient-security |
| timeendpos | integer | 31001, 31018 | 515 |
| timestartpos | integer | 31001, 31018 | 485 |
| xmlns | string | 31001, 31018 | http://schemas.microsoft.com/win/2004/08/events/event |
system
| Field | Data Type | Event IDs | Example |
|---|---|---|---|
| Application | string | 1, 5, 6, 10, 14, 15 | |
| Command | string | 16, 17, 24, 25, 40, 41, 42, 43 | |
| Computer | string | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 201, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 262, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 285, 286, 289, 290, 300, 301, 302, 379, 380, 381, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 566, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1025, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1056, 1058, 1060, 1061, 1065, 1068, 1074, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1281, 1282, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2001, 2003, 2004, 2005, 2042, 3261, 4000, 4001, 4002, 4003, 4004, 4005, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5202, 5203, 5211, 5300, 5774, 5781, 5782, 5805, 5823, 6000, 6005, 6006, 6009, 6011, 6013, 6027, 6033, 6035, 6036, 6037, 6038, 6040, 6041, 6100, 6145, 6146, 6148, 6400, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 9009, 10000, 10001, 10002, 10003, 10004, 10005, 10010, 10016, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10121, 10148, 10149, 10154, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14206, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 14531, 14533, 15007, 15008, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16647, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 16983, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 20010, 24576, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50036, 50037, 50038, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | win10-base |
| Data | integer | 1, 8 | 0 |
| Data | string | 2, 12, 14, 15, 16, 18, 20, 22, 25 | |
| Event | string | 0, 0, 3, 4 | |
| EventID | integer | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 201, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 262, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 285, 286, 289, 290, 300, 301, 302, 379, 380, 381, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 566, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1025, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1056, 1058, 1060, 1061, 1065, 1068, 1074, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1281, 1282, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2001, 2003, 2004, 2005, 2042, 3261, 4000, 4001, 4002, 4003, 4004, 4005, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5202, 5203, 5211, 5300, 5774, 5781, 5782, 5805, 5823, 6000, 6005, 6006, 6009, 6011, 6013, 6027, 6033, 6035, 6036, 6037, 6038, 6040, 6041, 6100, 6145, 6146, 6148, 6400, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 9009, 10000, 10001, 10002, 10003, 10004, 10005, 10010, 10016, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10121, 10148, 10149, 10154, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14206, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 14531, 14533, 15007, 15008, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16647, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 16983, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 20010, 24576, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50036, 50037, 50038, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 98 |
| FileName | string | 6, 8, 10, 11, 12, 14, 150 | |
| Filename | string | 0, 0, 0, 1 | |
| Id | string | 16385, 16386, 16390 | 4AAC461E-F8E1-4F65-A8CA-EDB4CC03A0C3 |
| Key | string | 0, 1, 4, 5, 6 | |
| Line | string | 0, 0, 0, 1 | |
| Name | string | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36884, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | "stornvme" |
| Origin | string | 5, 5 | |
| Path | string | 20, 22, 23, 9009, 36912 | C:\inetpub\history\CFGHISTORY_0000000005 |
| ProcessName | string | 1, 41, 150, 225 | \Device\HarddiskVolume2\Windows\System32\svchost.exe |
| Program | string | 6036, 6037 | |
| Target | string | 40960, 40961, 40962, 40965 | |
| Task | integer | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 8 |
| Task | string | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 300, 301, 302, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1058, 1060, 1061, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2003, 2004, 2005, 2042, 4000, 4001, 4002, 4003, 4004, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5300, 6000, 6027, 6033, 6035, 6036, 6037, 6040, 6041, 6100, 6145, 6146, 6400, 7001, 7002, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 10000, 10001, 10002, 10003, 10004, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50037, 50038, 51047, 51057 | |
| Type | string | 90, 36867, 36868, 36869, 36870, 36871, 36872, 36880, 36889 | |
| User | string | 16950, 16951, 16952 | |
| Window | string | 9 | |
| enabled | string | 1, 3, 6, 6, 9 | |
| hr | string | 1, 16404, 24836, 24842, 24843, 24844, 24845, 24846 | |
| id | integer | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 93485 |
| line | string | 0, 1, 4, 4, 6 | |
| name | string | 519, 566 | Object Operation (W3 Active Directory) |
| process_name | string | 1 | \Device\HarddiskVolume2\Windows\System32\svchost.exe |
| product | string | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | Windows |
| rule | string | 1, 3, 6, 6, 9 | |
| service | integer | 7009, 10005, 10111 | 50 |
| service | string | 1074, 7000, 7001, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 10010, 10016, 14204, 14205 | {4991D34B-80A1-4291-83B6-3328366B9097} |
| status | string | 18, 19, 6027, 7036, 16396, 32773, 32774, 32775 | stopped |
| APCpuidData | string | 7, 9 | |
| AbandonedBatteryCount | string | 1, 2, 5 | |
| AbortiveDisconnect | string | 6, 9 | |
| AcOnline | string | 0, 1, 5 | |
| AccessMode | string | 28, 29 | |
| AccountDistinguishedName | string | 12293, 12303, 12304, 16391, 16392, 16393 | |
| AccountName | string | 7045, 16384, 16401, 16402, 16403, 16409, 16411, 16413, 16978 | Network Service |
| AccountRID | string | 1, 3, 4, 6, 9 | |
| AccountSID | string | 1, 2, 3, 6, 9 | |
| Action | string | 90, 130 | |
| ActiveBatteryCount | string | 2, 4, 5 | |
| ActiveOperation | string | 0, 0, 1, 1, 1 | |
| ActiveResidencyInUs | string | 0, 5, 7 | |
| ActivityID | string | 14, 19, 20, 43, 44, 1006, 1129, 1500, 1501, 1502, 1503, 2003, 2004, 7001, 7002, 7043, 10005, 10010, 10016, 16392, 16962, 16977, 16983 | "FFE311E3-7084-4A19-B935-F331C2DB7296" |
| ActualFunctionTableSize | string | 6, 8 | |
| ActualFuntionTableCount | string | 0, 1, 1, 1, 7 | |
| ActualMaxInterval | string | 0, 1, 8 | |
| ActualSize | string | 5 | |
| ActualVersion | string | 6, 8 | |
| AdSuffix | string | 0, 0, 1, 1 | |
| AdapterName | string | 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 10317, 10400 | {87056817-E272-4172-BD6E-DB007E723246} |
| AdapterSuffixName | string | 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038 | snapattack.labs |
| AddServiceStatus | string | 20003, 20004 | |
| AdditionalDetails | string | 2 | |
| AdditionalInfo | string | 55, 129 | |
| Address | string | 6, 8, 10, 12, 14, 16, 17, 1014, 4200 | 1700000000000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 |
| AddressLength | string | 0, 1, 1, 4 | |
| AddressSpace | string | 28, 29 | |
| AffinityCount | string | 8, 9 | |
| AffinityLevel | string | 28, 29 | |
| AgentName | string | 15, 16 | |
| AlertDesc | integer | 3, 6, 7, 8, 8 | 70 |
| AlertDesc | string | 36887, 36888 | |
| AllowIeeePriorityTag | string | 8, 8 | |
| AllowMacSpoofing | string | 8, 8 | |
| AllowTeaming | string | 8, 8 | |
| AllowedOnes | string | 4, 6 | |
| AllowedZeroes | string | 4, 6 | |
| AoAcCompliantNic | string | 0, 5, 7 | |
| ApiCallerName | string | 1, 7, 8 | |
| ApiCallerNameLength | string | 1, 7, 8 | |
| ApicId | string | 18, 19, 20, 21 | |
| AppName | string | 6, 8, 9, 10, 11, 12, 14 | |
| AppNameLength | string | 9 | |
| Applicability | string | 0, 9 | |
| Argument | string | 1000, 1001, 1002, 1004 | |
| Argument1 | string | 2, 2, 2 | |
| Argument2 | string | 2, 2, 2 | |
| Arguments | string | 1, 5, 6, 10, 14, 15 | |
| Attributes | string | 1 | |
| AudioPlaybackInUs | string | 0, 5, 7 | |
| AudioPlaying | string | 0, 5, 7 | |
| Authorize | string | 1, 3 | |
| AvailableAddressFilters | string | 243, 244 | |
| AverageResume | string | 1, 1, 3 | |
| BCDSetting | string | 2, 3, 5 | |
| BSPCpuidData | string | 7, 9 | |
| BackupPath | string | 104, 105 | |
| BadFileOffset | string | 0, 1, 5 | |
| BadLcn | string | 0, 1, 5 | |
| BalStatus | string | 26, 38 | |
| BandID | string | 1, 3 | |
| BandMetadataSize | string | 1, 2 | |
| Bank | string | 22, 23, 46, 47, 48, 49 | |
| BatteryActionInternalFlags | string | 2, 4, 5 | |
| BatteryFullChargeCapacityOnEnter | string | 0, 5, 6 | |
| BatteryFullChargeCapacityOnExit | string | 0, 5, 7 | |
| BatteryRemainingCapacityOnEnter | string | 0, 5, 6 | |
| BatteryRemainingCapacityOnExit | string | 0, 5, 7 | |
| BiasValid | string | 0, 1, 8 | |
| BinaryData | string | 1, 1, 3, 4, 6 | |
| BiosInitDuration | string | 1 | |
| BitPosition | string | 22, 23, 46, 47 | |
| BitlockerUserInputTime | string | 2, 3 | |
| BlMemoryAttributes | string | 0, 1 | |
| BlMemoryType | string | 0, 1 | |
| BlPageCount | string | 0, 1 | |
| BlStartPage | string | 0, 1 | |
| BlockLength | string | 2, 3, 3, 4, 8 | |
| BlockNumber | string | 2, 3, 3, 4, 8 | |
| BootAppStatus | string | 1, 4 | |
| BootApplication | string | 522, 523 | |
| BootId | integer | 5, 6, 6 | 3 |
| BootId | string | 506, 507 | |
| BootMenuPolicy | string | 2, 5 | |
| BootMode | string | 1, 2 | |
| BootStatusPolicy | string | 0, 2 | |
| BootType | string | 2, 7 | |
| BridgeControl | string | 16, 17, 40, 41 | |
| BridgeStatus | string | 16, 17, 40, 41 | |
| BugcheckCode | string | 1, 4 | |
| BugcheckInfoFromEFI | string | 1, 4 | |
| BugcheckParameter | string | 1, 4 | |
| BugcheckParameter1 | string | 1, 4 | 0x0 |
| BugcheckParameter2 | string | 1, 4 | 0x0 |
| BugcheckParameter3 | string | 1, 4 | 0x0 |
| BugcheckParameter4 | string | 1, 4 | 0x0 |
| BuildVersion | string | 1, 2 | |
| BurstLimit | string | 2, 8 | |
| BurstSize | string | 2, 8 | |
| Bus | string | 16, 17, 40, 41 | |
| BusAddress | string | 24, 25, 42, 43 | |
| BusData | string | 24, 25, 42, 43 | |
| BusNumber | string | 24, 25, 26, 27, 42, 43, 44, 45 | |
| BusSegment | string | 24, 25, 42, 43 | |
| CAPEDesc | string | 1, 4, 6, 6 | |
| CAPEName | string | 1, 4, 6, 6 | |
| CLSID | string | 10001, 10002 | |
| CPU | string | 96, 97 | |
| CSPName | string | 3, 6, 6, 8, 8 | |
| CSPType | string | 3, 6, 6, 8, 8 | |
| CVEID | string | 2 | |
| CVEId | string | 0, 0, 1 | |
| CacheFlushNeeded | string | 1, 5, 6 | |
| CacheFlushSupported | string | 1, 5, 6 | |
| CacheLevel | string | 28, 29 | |
| CacheSend | string | 7, 9 | |
| CallStack | string | 5, 5 | |
| CallerProcessName | string | 0, 0, 4, 6 | |
| CapDurationInSeconds | string | 7, 37 | |
| Capabilities | string | 1, 2 | |
| Caption | string | 2, 6 | Ec2Config.exe - Application Error |
| Card | string | 22, 23, 46, 47 | |
| CardHandle | string | 22, 23, 46, 47 | |
| CeilingTriggerRid | string | 16656, 16657 | |
| CertFlags | string | 2, 3, 6, 7, 8 | |
| ChainLoggingRate | string | 1, 4, 6 | |
| ChainingCountFailure | string | 1, 4, 6 | |
| ChainingCountRequests | string | 1, 4, 6 | |
| ChainingCountSuccess | string | 1, 4, 6 | |
| ChangeReason | string | 0, 0, 3, 4 | |
| Channel | string | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 201, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 262, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 285, 286, 289, 290, 300, 301, 302, 379, 380, 381, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 566, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1025, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1056, 1058, 1060, 1061, 1065, 1068, 1074, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1281, 1282, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2001, 2003, 2004, 2005, 2042, 3261, 4000, 4001, 4002, 4003, 4004, 4005, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5202, 5203, 5211, 5300, 5774, 5781, 5782, 5805, 5823, 6000, 6005, 6006, 6009, 6011, 6013, 6027, 6033, 6035, 6036, 6037, 6038, 6040, 6041, 6100, 6145, 6146, 6148, 6400, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 9009, 10000, 10001, 10002, 10003, 10004, 10005, 10010, 10016, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10121, 10148, 10149, 10154, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14206, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 14531, 14533, 15007, 15008, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16647, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 16983, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 20010, 24576, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50036, 50037, 50038, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | System |
| ChannelPath | string | 21, 25, 26, 27, 28, 29, 30, 31, 40 | |
| Checkpoint | string | 41, 218 | |
| CheckpointDuration | string | 1 | |
| CheckpointStatus | string | 1, 4 | |
| CipherSuite | string | 0, 3, 6, 8, 8 | |
| ClassCode | string | 16, 17, 26, 27, 40, 41, 44, 45 | |
| ClearReason | string | 1, 5, 9 | SRK has changed or is not present. |
| ClfsStatus | string | 1 | |
| Client | string | 0, 3, 3, 6 | |
| ClientAddress | string | 1, 5, 7 | |
| ClientContext | string | 34, 35, 36 | |
| ClientDisconnect | string | 6, 9 | |
| ClientPID | integer | 0, 1, 1, 4 | 2352 |
| ClientRID | string | 1, 5, 6 | |
| ClientVersion | string | 2, 6 | |
| ClientVersionLen | string | 2, 6 | |
| ClustersCount | string | 0, 1, 5 | |
| CmdStatus | string | 0, 1 | |
| Column | string | 22, 23, 46, 47 | |
| CompleterId | string | 24, 25, 42, 43 | |
| CompletionType | string | 1101, 1102, 1103, 1104, 1201, 1202 | |
| ComputedRIDValue | string | 1, 4, 6, 6, 6 | |
| ComputerName | string | 4096, 4097, 4098, 4099, 12297, 12298, 16935, 16936, 16937 | |
| Config | string | 1, 4 | |
| ConfigProperty | string | 1, 2 | |
| ConfigurationReader | string | 1, 1, 2, 5 | ConfigurationSystem |
| ConflictingParameter | string | 0, 1, 1, 1, 3 | |
| ConnectedStandbyInProgress | string | 1, 4 | |
| ConnectionBufferFull | string | 8, 9 | |
| ConnectivityState | string | 2, 6, 8 | |
| Context | string | 1, 2, 3, 5, 100, 101, 102, 1008, 1012 | |
| ContextHandle | string | 0, 3, 6, 8, 8 | |
| ControlDeviceName | string | 2 | |
| CorrectableErrorStatus | string | 16, 17, 18, 40, 41 | |
| CorruptionActionState | string | 8, 9 | |
| CorruptionState | string | 5, 5 | |
| Count | string | 1, 2 | |
| CountNew | string | 0, 2 | |
| CountOld | string | 0, 2 | |
| CreatorId | string | 1, 2 | |
| CredContext | string | 36872, 36889 | |
| CsEntryScenarioInstanceId | string | 1, 4 | |
| CurrentBias | integer | 2, 4 | 420 |
| CurrentRunLevel | string | 13, 14, 15, 16 | |
| CurrentStratumNumber | string | 3, 5 | |
| CurrentTime | string | 1, 8 | |
| CurrentTimeZoneID | integer | 2, 4 | 2 |
| DCName | string | 1002, 1006, 1007, 1030, 1058, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1104, 1109, 1112, 1126, 1127, 1500, 1501, 1502, 1503 | \WIN-FPV0DSIC9O6.sigma.fr |
| DSObjectName | string | 0, 1, 1, 1 | |
| Data1 | string | 1, 9 | |
| Data2 | string | 1, 9 | |
| DataSize | string | 2, 7 | |
| DataSourceId | string | 24832, 24847, 24848 | |
| DefaultQueueVmmqEnabled | string | 2, 2, 7 | |
| DefaultQueueVrssEnabled | string | 2, 2, 7 | |
| DefaultQueueVrssExcludePrimaryProcessor | string | 2, 2, 7 | |
| DefaultQueueVrssIndependentHostSpreading | string | 2, 2, 7 | |
| DefaultQueueVrssMaxQueuePairs | string | 2, 2, 7 | |
| DefaultQueueVrssMinQueuePairs | string | 2, 2, 7 | |
| DefaultQueueVrssQueueSchedulingMode | string | 2, 2, 7 | |
| Default_SD_String_ | string | 1, 2, 6, 6, 9 | O:SYG:SYD:(A;;RC;;;BA) |
| Description | string | 10, 11, 55, 125 | |
| DescriptionLength | string | 1, 2, 5 | |
| DetectedBy | string | 0, 0, 1, 1, 1 | |
| Device | string | 1, 2, 3, 5, 6, 10, 11, 12, 14, 15, 16, 17, 22, 23, 40, 41, 46, 47 | |
| DeviceDescLength | string | 1, 4 | |
| DeviceDescription | string | 1, 4 | |
| DeviceID | string | 16, 17, 40, 41 | |
| DeviceId | string | 26, 27, 44, 45, 144, 145, 146, 148, 149, 10000, 20005, 20006, 20007, 20008 | |
| DeviceInstance | string | 2, 2, 5 | |
| DeviceInstanceID | string | 20001, 20002, 20003, 20004 | |
| DeviceInstanceLength | string | 2, 2, 5 | |
| DeviceName | string | 1, 4, 5, 6, 7, 55, 98, 140, 143, 144, 210, 211 | \Device\HarddiskVolume2 |
| DeviceNameLength | integer | 1, 6 | 9 |
| DeviceNameLength | string | 1, 4, 5, 6, 7, 143, 144 | |
| DeviceNumber | string | 26, 27, 44, 45 | |
| DeviceObject | string | 0, 0, 1, 5, 7 | \Device\Http\ReqQueue |
| DeviceSerialNumber | string | 16, 17, 40, 41 | |
| DeviceTime | string | 1, 4, 5, 6, 7 | 2074-11-09 08:03:12 UTC |
| DeviceVersionMajor | integer | 1, 6 | 10 |
| DeviceVersionMajor | string | 1, 4, 5, 6, 7 | |
| DeviceVersionMinor | integer | 1, 6 | 0 |
| DeviceVersionMinor | string | 1, 4, 5, 6, 7 | |
| Direction | string | 90, 130 | |
| DirectoryPath | string | 1, 2, 2, 6, 9 | |
| DirtyPages | string | 1, 6 | |
| DisabledLoadOption | string | 1, 5, 6 | |
| DisconnectedStandby | string | 0, 5, 7 | |
| DiskFriendlyName | string | 1 | |
| DiskPmDisabledMaxInterval | string | 0, 1, 8 | |
| DiskPmEnabledFlag | string | 0, 1, 8 | |
| DiskPmEnabledMaxInterval | string | 0, 1, 8 | |
| DiskPmPolicy | string | 0, 1, 8 | |
| DnsServerList | string | 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038 | 192.168.86.45 |
| DnsSuffix | string | 0, 0, 1, 1 | |
| Domain | string | 18, 32773, 32774, 32775 | |
| DomainName | string | 4096, 4097, 4098, 4099 | |
| DomainPeer | string | 24, 25, 26, 27, 130, 131, 132, 134, 135, 138, 156 | tick.boozallencsn.com,0x9 |
| DripsResidencyInUs | string | 0, 5, 7 | |
| DripsTransitions | string | 0, 5, 7 | |
| DriveName | string | 55, 98 | C: |
| DriverDescription | string | 20001, 20002 | |
| DriverFileName | string | 20003, 20004 | |
| DriverInitDuration | string | 1 | |
| DriverName | string | 40, 219, 10113, 20001, 20002 | |
| DriverNameLength | string | 40, 219 | |
| DriverObject | string | 184, 185, 186, 187, 188, 189 | |
| DriverProvider | string | 20001, 20002 | |
| DriverVersion | string | 20001, 20002 | |
| DropLowResourcesPackets | string | 1, 2, 6 | |
| DroppedClaims | string | 0, 1, 5, 6, 9 | |
| DstVPortId | string | 204, 205 | |
| DumpEncryptionFailureReason | string | 0, 1, 2, 7 | |
| Duration | string | 4, 13 | |
| DurationInUs | string | 0, 5, 7 | |
| DwmSyncFlushTime | string | 0, 5, 7 | |
| DwordVal | integer | 50037, 51047, 51057 | 1 |
| DwordVal | string | 1004, 50037, 51047, 51057 | |
| DynamicIPAddressLimit | string | 8, 8 | |
| EffectiveState | string | 1, 42, 107 | |
| EfiDaylightFlags | integer | 2, 3, 8 | 0 |
| EfiTime | string | 2, 3, 8 | 2022-03-01 17:43:36 UTC |
| EfiTimeZoneBias | integer | 2, 3, 8 | 2047 |
| ElapsedTime | string | 2, 6, 7 | |
| EmbeddedTeaming | string | 204, 205, 215 | |
| EnableDhcpGuard | string | 8, 8 | |
| EnableDisableReason | integer | 1, 3, 5 | 0 |
| EnableDisableReason | string | 153, 156 | |
| EnableFixSpeed10G | string | 8, 8 | |
| EnableRouterGuard | string | 8, 8 | |
| Enabled | string | 1, 5, 6 | |
| EnabledFeatures | string | 1, 2, 9 | |
| EnabledNew | string | 0, 2 | true |
| EncodedCert | string | 3, 6, 6, 8, 8 | |
| EndTime | string | 1001, 1002 | |
| EnergyDrain | string | 0, 5, 7 | |
| EntryCount | string | 1, 8 | |
| Error | string | 5, 6, 14, 15, 16, 26, 140, 1000, 1001, 1003, 1008, 1010, 1018, 1043, 6146, 36865, 40960, 45057 | |
| ErrorBatteryCount | string | 1, 2, 5 | |
| ErrorCause | string | 7, 9 | |
| ErrorCode | integer | 1006, 1129, 8018, 16392 | 9005 |
| ErrorCode | string | 6, 10, 20, 21, 22, 23, 27, 28, 29, 30, 31, 40, 96, 514, 518, 519, 520, 1000, 1002, 1003, 1006, 1007, 1008, 1012, 1023, 1029, 1030, 1031, 1052, 1053, 1054, 1055, 1058, 1065, 1079, 1080, 1085, 1088, 1089, 1091, 1095, 1096, 1097, 1101, 1104, 1110, 1112, 1125, 1126, 1127, 1129, 1130, 2042, 4001, 4002, 4003, 4004, 4100, 4202, 4302, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8194, 10000, 12288, 12289, 12294, 12299, 12302, 12305, 14300, 14301, 14302, 14303, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16398, 16399, 16400, 16401, 16402, 16403, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16642, 16643, 16644, 16645, 16646, 16648, 16649, 16935, 16936, 16937, 16944, 16945, 16947, 16948, 16949, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 36870, 36872, 36876, 36877, 36878, 36879, 36889 | |
| ErrorCode1 | string | 14304, 14305, 14306 | |
| ErrorCode2 | string | 14304, 14305, 14306 | |
| ErrorDescription | string | 401, 404, 1002, 1006, 1007, 1030, 1052, 1053, 1054, 1055, 1058, 1065, 1079, 1080, 1085, 1088, 1089, 1091, 1095, 1096, 1097, 1101, 1104, 1110, 1112, 1125, 1126, 1127, 1129, 1130 | The network is not present or not started. |
| ErrorMessage | string | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 15, 16, 17, 18, 19, 20, 22, 23, 24, 25, 30, 32, 40, 43, 44, 45, 46, 47, 48, 49, 54, 129, 130, 131, 132, 133, 134, 135, 136, 159, 16401, 16402, 16403, 16651 | The specified local group does not exist. |
| ErrorParam1 | string | 1, 2, 3 | |
| ErrorParam2 | string | 1, 2, 3 | |
| ErrorParam3 | string | 1, 2, 3 | |
| ErrorParam4 | string | 1, 2, 3 | |
| ErrorSource | string | 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49 | |
| ErrorState | string | 36871, 36888 | |
| ErrorStatus | string | 22, 23, 46, 47, 36870 | |
| ErrorString | string | 1, 1, 3, 4, 6 | The system cannot find the file specified. |
| ErrorType | string | 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 42, 43, 44, 45, 46, 47 | |
| Error_Code | string | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 0 |
| EventCode | integer | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 98 |
| EventData_Xml | string | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 109, 129, 134, 137, 153, 172, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1056, 1074, 1129, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10005, 10010, 10016, 10111, 10154, 14204, 14205, 14206, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16648, 16937, 16962, 16977, 24576, 24577, 24579, 36887, 50037, 51047, 51057 | snapattack.labs. |
| EventDescription | string | 0, 0, 1, 6 | |
| EventGenerationTime | string | 0, 0, 2, 4 | |
| EventRecordID | integer | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 93485 |
| EventSourceName | string | 32, 35, 1007, 1056, 1074, 5211, 6038, 7000, 7001, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 9009, 10005, 10010, 10016, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 24576, 24577, 24579 | "WinRM" |
| EventVerbosity | string | 0, 0, 1, 6 | |
| Exception | string | 0, 0, 0, 5 | |
| ExchangeStrength | string | 0, 3, 6, 8, 8 | |
| ExitBootServicesEntry | string | 0, 3 | |
| ExitBootServicesExit | string | 0, 3 | |
| ExitCode | string | 0, 0, 1, 1, 1 | |
| ExitLatencyInUs | string | 0, 5, 7 | |
| ExitReason | integer | 2, 4 | 0 |
| ExpectedFunctionTableSize | string | 6, 8 | |
| ExpectedFuntionTableCount | string | 0, 1, 1, 1, 7 | |
| ExpectedSize | string | 5 | |
| ExpectedVersion | string | 6, 8 | |
| Ext1 | string | 128, 129 | |
| Ext2 | string | 128, 129 | |
| Extended | string | 22, 23, 46, 47 | |
| ExtendedStatus | string | 1, 2, 4 | |
| ExtensibleModulePath | string | 10000, 10001, 10002, 10003, 10004 | |
| ExtensionId | string | 61, 98, 1085, 1091, 1112, 1128 | |
| ExtensionName | string | 61, 1085, 1091, 1112, 1128 | |
| ExtensionNameLength | string | 1, 6 | |
| ExternalMonitorConnectedState | string | 506, 507 | |
| ExtraString | string | 2, 3, 4, 5, 6, 8, 9, 10, 11 | \SystemRoot\System32\Config\RegBack\SYSTEM |
| ExtraStringLength | integer | 5 | 42 |
| ExtraStringLength | string | 2, 3, 4, 5, 6, 8, 9, 10, 11 | |
| FRUId | string | 16, 17, 22, 23, 24, 25, 26, 27, 40, 41, 42, 43, 44, 45, 46, 47 | |
| FRUText | string | 16, 17, 22, 23, 24, 25, 26, 27, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49 | |
| FailReason | string | 82, 88, 90, 94, 95, 97, 100, 113, 122, 127, 128, 129, 130, 146, 147, 149, 150, 151, 197, 216, 227, 229, 254, 256, 257, 261, 1003 | |
| FailedLogFilePath | string | 2, 7 | |
| FailureMode | string | 2, 5, 9 | |
| FailureMsg | string | 16, 29 | |
| FailureMsgId | string | 16, 29 | |
| FailureName | string | 1, 2, 9 | |
| FailureNameLength | string | 1, 2, 9 | |
| FailureReason | integer | 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522 | |
| FailureResult | string | 1, 2 | |
| FailureStatus | integer | 16, 29, 150 | |
| FaultCode | string | 9, 9 | |
| FeatureClassId | string | 1, 6 | |
| FeaturesNeeded | string | 4, 8 | |
| FeaturesSupported | string | 4, 8 | |
| FileList | string | 16385, 16386 | C:\Users\user\AppData\Local\Temp\BIT72FA.tmp |
| FileNameBuffer | string | 24832, 24833, 24834, 24847, 24848 | |
| FileNameLength | string | 12, 150, 24832, 24833, 24834, 24847, 24848 | |
| FileOffset | string | 2, 3, 4, 4, 8 | |
| FilePath | string | 12, 1058, 1096, 12295 | |
| FilterId | string | 204, 205, 215 | |
| FilterName | string | 1205, 1206 | |
| FilterNameLength | string | 1205, 1206 | |
| FinalStatus | string | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 10100, 10101 | 0x8000002a |
| FirstDripsEntryInUs | string | 0, 5, 7 | |
| FirstPage | string | 1, 2 | |
| FirstRefresh | integer | 2, 4 | 0 |
| Flags | string | 1, 2, 3, 9, 42, 43, 264, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24643, 24645, 24652, 24653, 24654, 24657, 24658, 24659, 24672 | |
| FrameworkVersion | string | 0, 0, 0, 0, 1 | |
| FreePersistentPages | string | 1, 1, 5 | |
| FriendlyName | string | 1001, 10111, 10112, 10115, 10116, 14206, 14210 | EVTX-PC: evtx: |
| FullChargeCapacity | string | 0, 1, 5 | |
| FullChargeCapacityRatio | string | 0, 5, 7 | |
| FullResume | string | 1, 1, 3 | |
| Function | string | 16, 17, 40, 41, 218 | |
| FunctionNumber | string | 26, 27, 44, 45 | |
| FwMemoryAttributes | string | 0, 1 | |
| FwMemoryType | string | 0, 1 | |
| FwPageCount | string | 0, 1 | |
| FwStartPage | string | 0, 1 | |
| FxVersion | string | 10001, 10002 | |
| GPOCNName | string | 1058, 1065, 1096, 1104 | |
| GPODisplayName | string | 0, 1, 1, 3 | |
| GPOFileSystemPath | string | 0, 1, 1, 3 | |
| GPOScriptCommandString | string | 0, 1, 1, 3 | |
| GdiOnTime | string | 0, 5, 7 | |
| GetTestResult_Data | string | 2, 7 | |
| Group | integer | 26, 55 | 0 |
| Group | string | 26, 33, 34, 35, 36, 37, 54, 55 | |
| GroupName | string | 16387, 16389, 16391, 16393, 16394, 16401, 16402, 16407, 16413 | Performance Log Users |
| Guid | string | 1, 3, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 50, 52, 55, 98, 104, 109, 134, 137, 139, 143, 153, 172, 201, 206, 238, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2003, 2004, 5211, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | "{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}" |
| HRESULT | string | 0, 0, 0, 1 | |
| HResult | string | 517, 518, 1538 | |
| HardwareEnabled | string | 1, 2, 9 | |
| HardwareID | string | 1 | |
| HardwareId | string | 1, 5, 6, 10, 14, 15 | |
| HardwarePresent | string | 1, 2, 9 | |
| HeaderFlags | string | 5, 5 | |
| HeaderLog | string | 16, 17, 40, 41 | |
| HeaderLog0 | string | 1, 8 | |
| HeaderLog1 | string | 1, 8 | |
| HeaderLog2 | string | 1, 8 | |
| HeaderLog3 | string | 1, 8 | |
| HelperClassName | string | 4000, 5000, 5100, 5200, 6100 | |
| HiberPagesWritten | string | 1 | |
| HiberReadDuration | string | 1 | |
| HiberWriteDuration | string | 1 | |
| HibernateTime | string | 8, 8 | |
| HiveName | string | 15, 16 | \SystemRoot\System32\Config\SOFTWARE |
| HiveNameLength | string | 15, 16 | |
| HostName | string | 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038 | quadra |
| HostOSName | string | 0, 0, 2, 3 | Windows (TM) 10 Preinstallation Environment |
| HostOSbuildversion | string | 0, 0, 2, 3 | |
| HostOSmajorversion | string | 0, 0, 2, 3 | |
| HostOSminorversion | string | 0, 0, 2, 3 | |
| HostOSservicepackName | string | 0, 0, 2, 3 | |
| HostOSservicepackmajorversion | string | 0, 0, 2, 3 | |
| HostOSservicepackminorversion | string | 0, 0, 2, 3 | |
| HostOSwasWindowsPE | string | 0, 0, 2, 3 | true |
| Host_OS_Name | string | 0, 0, 2, 3 | Windows (TM) Code Name "Longhorn" Preinstallation Environment |
| Host_OS_build_version | integer | 0, 0, 2, 3 | 7600 |
| Host_OS_major_version | integer | 0, 0, 2, 3 | 6 |
| Host_OS_minor_version | integer | 0, 0, 2, 3 | 1 |
| Host_OS_service_pack_major_version | integer | 0, 0, 2, 3 | 0 |
| Host_OS_service_pack_minor_version | integer | 0, 0, 2, 3 | 0 |
| Host_OS_was_Windows_PE | string | 0, 0, 2, 3 | true |
| HwDripsResidencyInUs | string | 0, 5, 7 | |
| HypervisorVersion | string | 0, 4 | |
| IPSecOffloadLimit | string | 4, 9 | |
| IdleImplementation | string | 5, 5 | |
| IdleSessionTimeout | string | 0, 1, 3 | |
| IdleStateCount | integer | 26, 55 | 1 |
| IdleStateCount | string | 4, 26, 55 | |
| IfGuid | string | 10317, 10400 | |
| IfIndex | string | 41, 42, 10317, 10400 | |
| IfLuid | string | 10317, 10400 | |
| ImageFileName | string | 7, 9 | |
| ImageName | string | 1, 34, 36, 37, 152, 153 | |
| ImagePath | string | 0, 4, 5, 7 | %SystemRoot%\PSEXESVC.exe |
| Index | string | 2, 4, 5 | |
| Info | string | 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218 | |
| InputSuppressionActionCount | string | 0, 5, 7 | |
| InstallStatus | string | 20001, 20002 | |
| Install_was_an_upgrade | string | 0, 0, 2, 3 | false |
| Installwasanupgrade | string | 0, 0, 2, 3 | false |
| InstanceId | string | 78, 80, 92, 93, 10111, 10112, 10113, 10115, 10116 | |
| InstanceName | string | 0, 4 | |
| InstanceNameLength | string | 0, 4 | |
| Interface | string | 4002, 4200, 4201, 4202 | |
| InterfaceDesc | string | 4000, 5000, 5100, 5200 | |
| InterfaceGUID | string | 4000, 5000, 5100, 5200 | |
| InternalCode | string | 1, 1 | |
| InternalInfo | string | 1, 2, 9 | |
| InterruptModeration | string | 4, 9 | |
| IoApicId | string | 1, 4, 7 | |
| IoctlCode | string | 2, 6, 7 | |
| IovOffloadWeight | string | 4, 9 | |
| IpFamily | string | 0, 0, 3, 4 | |
| IpHTTPSReasonCode | string | 0, 2, 3, 4 | |
| Ipaddress | string | 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038 | 192.168.86.7 |
| Irql | string | 4 | |
| IsAcOnline | string | 2, 4, 5 | |
| IsBootVolume | string | 0, 1, 5 | |
| IsCsSessionInProgressOnExit | string | 0, 5, 7 | |
| IsDriverOEM | string | 20001, 20002 | |
| IsPowerActionCallIgnored | string | 2, 4, 5 | |
| IsPowerPolicyEnabled | string | 2, 4, 5 | |
| IsTestConfig | string | 1, 4 | |
| IsatapRouter | string | 0, 0, 1, 4 | |
| KeyFlags | string | 3, 6, 6, 8, 8 | |
| KeyName | string | 3, 6, 6, 8, 8 | |
| KeyProtectionMechanism | string | 1, 2 | |
| KeyType | string | 3, 6, 6, 8, 8 | |
| KeysUpdated | string | 1, 6 | |
| Keywords | string | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 201, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 262, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 285, 286, 289, 290, 300, 301, 302, 379, 380, 381, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 566, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1025, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1056, 1058, 1060, 1061, 1065, 1068, 1074, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1281, 1282, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2001, 2003, 2004, 2005, 2042, 3261, 4000, 4001, 4002, 4003, 4004, 4005, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5202, 5203, 5211, 5300, 5774, 5781, 5782, 5805, 5823, 6000, 6005, 6006, 6009, 6011, 6013, 6027, 6033, 6035, 6036, 6037, 6038, 6040, 6041, 6100, 6145, 6146, 6148, 6400, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 9009, 10000, 10001, 10002, 10003, 10004, 10005, 10010, 10016, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10121, 10148, 10149, 10154, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14206, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 14531, 14533, 15007, 15008, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16647, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 16983, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 20010, 24576, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50036, 50037, 50038, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 0x8080000000000000 |
| Language | string | 1002, 1003, 1006, 1008, 1009, 1013, 1014, 1015, 1017, 1018, 1040, 1042, 1043 | |
| Language1 | string | 1009, 1016, 1041, 1060, 1061 | |
| Language2 | string | 1009, 1016, 1041, 1060, 1061 | |
| LastBootGood | string | 0, 2 | true |
| LastBootId | string | 0, 2 | |
| LastPage | string | 1, 2 | |
| LastShutdownGood | string | 0, 2 | true |
| LaunchType | string | 1001, 1002, 1003, 1101, 1102, 1103, 1104 | |
| Leaf | string | 4, 8 | |
| LeafNumber | string | 7, 9 | |
| Length | string | 1, 2, 3, 6, 8, 10, 12, 14, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 40, 41, 42, 43, 44, 45, 46, 47 | |
| Level | integer | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 4 |
| Level | string | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 300, 301, 302, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1058, 1060, 1061, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2003, 2004, 2005, 2042, 4000, 4001, 4002, 4003, 4004, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5300, 6000, 6027, 6033, 6035, 6036, 6037, 6040, 6041, 6100, 6145, 6146, 6400, 7001, 7002, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 10000, 10001, 10002, 10003, 10004, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50037, 50038, 51047, 51057 | |
| LidOpenState | string | 506, 507 | |
| LifetimeId | string | 10110, 10111, 10112, 10113, 10115, 10116 | |
| LightestSystemState | string | 1, 7, 8 | |
| Limit | string | 2, 8 | |
| LoadBalancingAlgorithm | string | 206, 207, 208, 209, 210, 211 | |
| LoadOSImageStart | string | 0, 3 | |
| LoadOptions | string | 2, 7 | NOEXECUTE=OPTIN |
| LocalAddr | string | 0, 9 | |
| LocalAddrLen | string | 0, 9 | |
| LocalAddress | string | 96, 98 | |
| LocalAddressLength | string | 96, 98 | |
| LocalCertSubjectName | string | 0, 3, 6, 8, 8 | |
| LocalIPAddr | string | 0, 1, 3 | |
| LocalIPAddrLen | string | 0, 1, 3 | |
| LocalPort | string | 0, 1, 3 | |
| LocalPortLen | string | 0, 1, 3 | |
| LocalPrefix | string | 0, 9 | |
| Location | string | 241, 1008, 1012, 10111, 10112, 10115, 10116 | |
| LogFile | string | 19, 20 | |
| LogStatus | string | 1, 1, 2, 2, 9 | |
| MCABank | string | 18, 19, 20, 21 | |
| MIDR_EL1 | string | 28, 29 | |
| MPIDR_EL1 | string | 28, 29 | |
| MSRIndex | string | 4, 6 | |
| MacAddress | string | 25, 28, 29, 30, 31, 204 | |
| MacAddressLen | string | 25, 28, 29, 30, 31 | |
| MacLength | string | 0, 2, 4 | |
| MajorVersion | integer | 1, 2 | 10 |
| MajorVersion | string | 12, 29 | |
| ManualPeer | string | 16, 17, 47, 48, 137 | time.windows.com,0x8 |
| MaxBandCount | string | 1, 2 | |
| MaxDelta | string | 1, 4, 5 | |
| MaxSystemTimeChangeSeconds | string | 3, 4 | |
| Maximum | string | 1, 3, 5, 6, 6 | |
| MaximumPerformancePercent | string | 5, 5 | |
| MciAddr | string | 18, 19, 20, 21, 48, 49 | |
| MciMisc | string | 18, 19, 20, 21, 48, 49 | |
| MciStat | string | 18, 19, 20, 21 | |
| MciStatus | string | 48, 49 | |
| MemHierarchyLvl | string | 6, 8, 10, 12, 14, 16, 17, 18, 19 | |
| Member | string | 184, 185, 186, 187, 188, 189 | |
| MemberAdapterFriendlyName | string | 2, 2, 9 | |
| MemberAdapterFriendlyNameLen | string | 2, 2, 9 | |
| MemberAdapterName | string | 2, 2, 9 | |
| MemberAdapterNameLen | string | 2, 2, 9 | |
| MemorIO | string | 6, 8, 10, 12, 14, 16, 17, 18, 19 | |
| MemoryRequired | string | 0, 4 | |
| MemorySize | string | 1101, 1102, 1103, 1104 | |
| Message | string | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 300, 301, 302, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1058, 1060, 1061, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2003, 2004, 2005, 2042, 4000, 4001, 4002, 4003, 4004, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5300, 6000, 6027, 6033, 6035, 6036, 6037, 6040, 6041, 6100, 6145, 6146, 6400, 7001, 7002, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 10000, 10001, 10002, 10003, 10004, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50037, 50038, 51047, 51057 | The application was unable to start correctly (0xc0000142). Click OK to close the application. |
| MinDelta | string | 1, 4, 5 | |
| MinPerfPercent | string | 2, 9 | |
| MinThrottlePercent | string | 2, 9 | |
| MinimumPasswordLength | integer | 1, 6, 7, 7, 9 | 0 |
| MinimumPasswordLength | string | 16977, 16978, 16979 | |
| MinimumPasswordLengthAudit | integer | 1, 6, 7, 7, 9 | -1 |
| MinimumPasswordLengthAudit | string | 16977, 16978 | |
| MinimumPerformancePercent | string | 5, 5 | |
| MinimumThrottle | string | 1, 2, 5 | |
| MinimumThrottlePercent | string | 5, 5 | |
| MiniportEventEnum | string | 0, 1, 1, 3, 7 | |
| MiniportName | string | 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 37, 38, 41, 42, 43, 44, 45 | Microsoft Hyper-V Network Adapter |
| MiniportNameLen | integer | 3, 10, 11 | 33 |
| MiniportNameLen | string | 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 37, 38, 41, 42, 43, 44, 45 | |
| MinorVersion | integer | 1, 2 | 0 |
| MinorVersion | string | 12, 29 | |
| MissingCAPDNs | string | 1, 4, 5, 6 | |
| ModernSleepAppliedActionsBitmask | string | 0, 5, 7 | |
| ModernSleepEnabledActionsBitmask | string | 0, 5, 7 | |
| Module | string | 4, 22, 23, 46, 47 | |
| ModuleHandle | string | 22, 23, 46, 47 | |
| ModuleName | string | 3, 5, 6, 6, 8 | |
| MonitorMode | string | 8, 8 | |
| MonitorPowerOnTime | string | 0, 5, 7 | |
| MonitorReason | integer | 5, 6, 6 | 12 |
| MonitorSession | string | 8, 8 | |
| NTStatus | integer | 3 | |
| NdisOid | string | 2, 5, 9 | |
| NdisStatus | string | 0, 2, 6 | |
| NdkEnabled | string | 44, 45 | |
| NetEvent | string | 38, 43, 149, 254 | |
| NetStatusCode | string | 4097, 4099 | |
| NewBias | string | 2, 2 | |
| NewLogFilePath | string | 2, 7 | |
| NewSchemeGuid | string | 12, 51 | 381B4222-F694-41F0-9685-FF5BB260DF2E |
| NewSize | string | 1, 5 | |
| NewTime | string | 1 | 2022-04-07 08:10:56.757996 UTC |
| NewValue | string | 1, 5, 5, 6, 6 | |
| NextSessionId | integer | 5, 6, 6 | 1 |
| NextSessionType | integer | 5, 6, 6 | 0 |
| NicFName | string | 5, 6, 7, 8, 13, 16, 17, 18, 19, 20, 21, 22, 23, 24, 29, 30, 31, 32, 33, 35, 61, 76, 77, 87, 96, 98, 99, 106, 113, 120, 122, 146, 147, 149, 150, 151, 190, 191, 192, 193, 197, 202, 203, 216, 232, 233, 236, 238, 243, 244, 254, 256, 257, 258, 259, 263, 265, 266, 269, 270, 276 | |
| NicFNameLen | string | 5, 6, 7, 8, 13, 16, 17, 18, 19, 20, 21, 22, 23, 24, 29, 30, 31, 32, 33, 35, 61, 76, 77, 87, 96, 98, 99, 106, 113, 120, 122, 146, 147, 149, 150, 151, 190, 191, 192, 193, 197, 202, 203, 216, 232, 233, 236, 238, 243, 244, 254, 256, 257, 258, 259, 263, 265, 266, 269, 270, 276 | |
| NicFriendlyName | string | 212, 213, 214 | |
| NicFriendlyNameLen | string | 212, 213, 214 | |
| NicIndex | string | 204, 205, 212, 213, 214, 215, 229 | |
| NicName | string | 5, 6, 7, 8, 13, 16, 17, 18, 19, 20, 21, 22, 23, 24, 29, 30, 31, 32, 33, 35, 61, 76, 77, 87, 96, 98, 99, 106, 113, 120, 122, 146, 147, 149, 150, 151, 190, 191, 192, 193, 197, 202, 203, 212, 213, 214, 216, 232, 233, 234, 235, 236, 238, 243, 244, 254, 256, 257, 258, 259, 263, 265, 266, 269, 270, 276 | |
| NicNameLen | string | 5, 6, 7, 8, 13, 16, 17, 18, 19, 20, 21, 22, 23, 24, 29, 30, 31, 32, 33, 35, 61, 76, 77, 87, 96, 98, 99, 106, 113, 120, 122, 146, 147, 149, 150, 151, 190, 191, 192, 193, 197, 202, 203, 212, 213, 214, 216, 232, 233, 234, 235, 236, 238, 243, 244, 254, 256, 257, 258, 259, 263, 265, 266, 269, 270, 276 | |
| NoMultiStageResumeReason | string | 1 | |
| Node | string | 22, 23, 46, 47 | |
| NominalFrequency | string | 5, 5 | |
| NonActivatedCpuInUs | string | 0, 5, 7 | |
| NonAttributedCpuInUs | string | 0, 5, 7 | |
| NonDripsTimeActivatedInUs | string | 0, 5, 7 | |
| NonPagedPoolTag_1 | string | 0, 0, 2, 4 | |
| NonPagedPoolTag_2 | string | 0, 0, 2, 4 | |
| NonPagedPoolTag_3 | string | 0, 0, 2, 4 | |
| NonPagedPoolUsage | string | 0, 0, 2, 4 | |
| NonPagedPoolUsed_1 | string | 0, 0, 2, 4 | |
| NonPagedPoolUsed_2 | string | 0, 0, 2, 4 | |
| NonPagedPoolUsed_3 | string | 0, 0, 2, 4 | |
| NonResiliencyTimeInUs | string | 0, 5, 7 | |
| NormalProcessId | string | 1, 2, 4 | |
| NotAffectedAtom | string | 1, 5, 6 | |
| NotAffectedRdclNo | string | 1, 5, 6 | |
| NotifyType | string | 1, 2 | |
| NtStatus | string | 0, 8 | |
| NumAttempts | string | 1001, 1002 | |
| NumBadPages | string | 1101, 1102, 1103, 1104 | |
| NumPagesTested | string | 1101, 1102, 1103, 1104 | |
| NumPagesUnTested | string | 1101, 1102, 1103, 1104 | |
| NumRootCauses | string | 1001, 1002 | |
| Number | integer | 26, 55 | 0 |
| Number | string | 26, 33, 34, 35, 36, 37, 54, 55 | |
| NumberOfGroupPolicyObjects | string | 1502, 1503 | |
| NvgreEnabled | string | 0, 2, 3 | |
| OID | string | 16944, 16945, 16946, 16947 | |
| OSEditionID | string | 0, 0, 2, 4 | ServerStandardEval |
| OSName | string | 0, 0, 2, 4 | Windows Server 2022 Standard Evaluation |
| OS_EditionID | string | 0, 0, 2, 4 | Professional |
| OS_Name | string | 0, 0, 2, 4 | Windows 7 Professional |
| OS_build_version | integer | 0, 0, 2, 4 | 7600 |
| OS_major_version | integer | 0, 0, 2, 4 | 6 |
| OS_minor_version | integer | 0, 0, 2, 4 | 1 |
| OS_service_pack_major_version | integer | 0, 0, 2, 4 | 0 |
| OS_service_pack_minor_version | integer | 0, 0, 2, 4 | 0 |
| OSbuildversion | string | 0, 0, 2, 4 | |
| OSmajorversion | string | 0, 0, 2, 4 | |
| OSminorversion | string | 0, 0, 2, 4 | |
| OSservicepackName | string | 0, 0, 2, 4 | |
| OSservicepackmajorversion | string | 0, 0, 2, 4 | |
| OSservicepackminorversion | string | 0, 0, 2, 4 | |
| ObjectName | string | 4, 132, 133, 513, 514, 515, 516, 519, 520, 521, 522 | |
| ObjectNameLength | string | 132, 133, 513, 514, 515, 516, 519, 520, 521, 522 | |
| ObjectSize | string | 4 | |
| OidFailureStatus | string | 2, 5, 9 | |
| OldBias | string | 2, 2 | |
| OldSchemeGuid | string | 12, 51 | 381B4222-F694-41F0-9685-FF5BB260DF2E |
| OldTime | string | 1 | 2022-04-07 08:10:56.760687 UTC |
| Opcode | integer | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5782, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 69 |
| Opcode | string | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 300, 301, 302, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1058, 1060, 1061, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2003, 2004, 2005, 2042, 4000, 4001, 4002, 4003, 4004, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5300, 6000, 6027, 6033, 6035, 6036, 6037, 6040, 6041, 6100, 6145, 6146, 6400, 7001, 7002, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 10000, 10001, 10002, 10003, 10004, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50037, 50038, 51047, 51057 | |
| Operation | string | 75, 76, 78, 80, 82, 92, 93, 100, 227, 233, 261, 16948 | |
| OperationType | string | 18, 19, 28, 29 | |
| OptionSelected | string | 1, 2 | |
| OptionalGUID | string | 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24643, 24645, 24652, 24653, 24654, 24657, 24658, 24659, 24672 | |
| OriginalSize | string | 1, 5 | |
| Outcome | string | 5, 5 | |
| OverThrottleThreshold | string | 1, 2, 5 | |
| Owner | string | 0, 1, 3, 6, 9 | |
| OwnerService | string | 9, 42, 43, 264 | |
| PCIXCommand | string | 24, 25, 42, 43 | |
| PID | string | 6036, 6037 | |
| PSCIState | string | 28, 29 | |
| Package | string | 5000, 6040, 45057 | |
| PagedPoolTag_1 | string | 0, 0, 2, 4 | |
| PagedPoolTag_2 | string | 0, 0, 2, 4 | |
| PagedPoolTag_3 | string | 0, 0, 2, 4 | |
| PagedPoolUsage | string | 0, 0, 2, 4 | |
| PagedPoolUsed_1 | string | 0, 0, 2, 4 | |
| PagedPoolUsed_2 | string | 0, 0, 2, 4 | |
| PagedPoolUsed_3 | string | 0, 0, 2, 4 | |
| Param1 | string | 10, 100, 101, 102 | |
| Param2 | string | 10, 100, 101, 102 | |
| Param3 | string | 10, 100, 101, 102 | |
| Param4 | string | 10, 100, 101, 102 | |
| Parameter | string | 414, 1004, 1005, 1007 | |
| Parameter1 | string | 1, 8 | |
| ParentHypervisorFlushes | string | 1, 5, 6 | |
| Participation | string | 6, 8, 10, 12, 14, 16, 17, 18, 19, 28, 29 | |
| PartitionId | string | 1, 2, 144, 145, 146, 148, 149 | |
| PccChanges | string | 3, 7 | |
| Peer | string | 22, 23, 51, 53 | |
| Pending | string | 1, 3 | |
| PerfStateCount | integer | 2, 6 | 0 |
| PerfStateCount | string | 4, 26 | |
| PerformanceImplementation | string | 5, 5 | |
| Persisted | string | 1, 3 | |
| PersistentMemoryDiskGuid | string | 300, 301, 302 | |
| Phase | string | 63, 124 | |
| PhysicalAddress | string | 22, 23, 31, 46, 47 | |
| PhysicalAddressMask | string | 22, 23, 46, 47 | |
| PhysicalFaultAddress | string | 28, 29 | |
| PhysicalMemorySize | string | 0, 0, 2, 4 | |
| PhysicalMemoryUsage | string | 0, 0, 2, 4 | |
| Pid | integer | 9, 10 | |
| PlatformDirected | string | 1, 3 | |
| PlatformId | string | 1, 2 | |
| Policy | string | 1, 2, 9 | |
| Port1FName | string | 25, 28 | |
| Port1FNameLen | string | 25, 28 | |
| Port1Name | string | 25, 28 | |
| Port1NameLen | string | 25, 28 | |
| Port2FName | string | 25, 28 | |
| Port2FNameLen | string | 25, 28 | |
| Port2Name | string | 25, 28 | |
| Port2NameLen | string | 25, 28 | |
| PortFName | string | 12, 15, 17, 18, 32, 33, 34, 35, 46, 68, 70, 72, 73, 74, 75, 78, 82, 87, 88, 90, 92, 94, 95, 96, 98, 99, 119, 121, 127, 128, 129, 130, 232, 256, 257, 264 | |
| PortFNameLen | string | 12, 15, 17, 18, 32, 33, 34, 35, 46, 68, 70, 72, 73, 74, 75, 78, 82, 87, 88, 90, 92, 94, 95, 96, 98, 99, 119, 121, 127, 128, 129, 130, 232, 256, 257, 264 | |
| PortName | string | 12, 15, 17, 18, 32, 33, 34, 35, 46, 68, 70, 72, 73, 74, 75, 78, 82, 87, 88, 90, 92, 94, 95, 96, 98, 99, 119, 121, 127, 128, 129, 130, 232, 234, 235, 256, 257, 264 | |
| PortNameLen | string | 12, 15, 17, 18, 32, 33, 34, 35, 46, 68, 70, 72, 73, 74, 75, 78, 82, 87, 88, 90, 92, 94, 95, 96, 98, 99, 119, 121, 127, 128, 129, 130, 232, 234, 235, 256, 257, 264 | |
| PortType | string | 16, 17, 40, 41 | |
| PowerButtonTimestamp | string | 1, 4 | |
| PowerPolicyAction | string | 2, 4, 5 | |
| PowerPolicyBatteryLevel | string | 2, 4, 5 | |
| PowerPolicyEventCode | string | 2, 4, 5 | |
| PowerPolicyMinState | string | 2, 4, 5 | |
| PowerStateAc | string | 507, 566 | true |
| PpcChanges | string | 7, 37 | |
| PrecisePC | string | 28, 29 | |
| PreviousEnergyCapacityAtEnd | integer | 5, 6, 6 | 50000 |
| PreviousEnergyCapacityAtStart | integer | 5, 6, 6 | 50000 |
| PreviousFullEnergyCapacityAtEnd | integer | 5, 6, 6 | 50000 |
| PreviousFullEnergyCapacityAtStart | integer | 5, 6, 6 | 50000 |
| PreviousSessionDurationInUs | integer | 5, 6, 6 | 1055562550 |
| PreviousSessionId | integer | 5, 6, 6 | 0 |
| PreviousSessionType | integer | 5, 6, 6 | 0 |
| PrimaryDeviceName | string | 16, 17, 40, 41 | |
| PrimaryService | string | 20003, 20004 | |
| Problem | string | 0, 0, 1, 1, 1 | |
| Problems | string | 1, 2, 9 | |
| ProcessCommitCharge | string | 0, 0, 2, 4 | |
| ProcessID | integer | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 300, 301, 302, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1058, 1060, 1061, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2003, 2004, 2005, 2042, 4000, 4001, 4002, 4003, 4004, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5300, 6000, 6027, 6033, 6035, 6036, 6037, 6040, 6041, 6100, 6145, 6146, 6400, 7001, 7002, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 10000, 10001, 10002, 10003, 10004, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50037, 50038, 51047, 51057 | |
| ProcessID | string | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5782, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | "976" |
| ProcessId | integer | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5782, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 976 |
| ProcessId | string | 41, 97, 150, 225, 6400 | |
| ProcessNameLength | string | 2, 2, 5 | |
| ProcessPath | string | 12, 21, 51 | C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.20348.557_none_f1edaeb8515fa10d\TiWorker.exe |
| ProcessPid | integer | 1, 2 | 1292 |
| ProcessPid | string | 12, 51 | |
| Process_1_CommitCharge | string | 0, 0, 2, 4 | |
| Process_1_CreationTime | string | 0, 0, 2, 4 | |
| Process_1_HandleCount | string | 0, 0, 2, 4 | |
| Process_1_ID | string | 0, 0, 2, 4 | |
| Process_1_Name | string | 0, 0, 2, 4 | |
| Process_1_TypeInfo | string | 0, 0, 2, 4 | |
| Process_1_Version | string | 0, 0, 2, 4 | |
| Process_2_CommitCharge | string | 0, 0, 2, 4 | |
| Process_2_CreationTime | string | 0, 0, 2, 4 | |
| Process_2_HandleCount | string | 0, 0, 2, 4 | |
| Process_2_ID | string | 0, 0, 2, 4 | |
| Process_2_Name | string | 0, 0, 2, 4 | |
| Process_2_TypeInfo | string | 0, 0, 2, 4 | |
| Process_2_Version | string | 0, 0, 2, 4 | |
| Process_3_CommitCharge | string | 0, 0, 2, 4 | |
| Process_3_CreationTime | string | 0, 0, 2, 4 | |
| Process_3_HandleCount | string | 0, 0, 2, 4 | |
| Process_3_ID | string | 0, 0, 2, 4 | |
| Process_3_Name | string | 0, 0, 2, 4 | |
| Process_3_TypeInfo | string | 0, 0, 2, 4 | |
| Process_3_Version | string | 0, 0, 2, 4 | |
| Process_4_CommitCharge | string | 0, 0, 2, 4 | |
| Process_4_CreationTime | string | 0, 0, 2, 4 | |
| Process_4_HandleCount | string | 0, 0, 2, 4 | |
| Process_4_ID | string | 0, 0, 2, 4 | |
| Process_4_Name | string | 0, 0, 2, 4 | |
| Process_4_TypeInfo | string | 0, 0, 2, 4 | |
| Process_4_Version | string | 0, 0, 2, 4 | |
| Process_5_CommitCharge | string | 0, 0, 2, 4 | |
| Process_5_CreationTime | string | 0, 0, 2, 4 | |
| Process_5_HandleCount | string | 0, 0, 2, 4 | |
| Process_5_ID | string | 0, 0, 2, 4 | |
| Process_5_Name | string | 0, 0, 2, 4 | |
| Process_5_TypeInfo | string | 0, 0, 2, 4 | |
| Process_5_Version | string | 0, 0, 2, 4 | |
| Process_6_CommitCharge | string | 0, 0, 2, 4 | |
| Process_6_CreationTime | string | 0, 0, 2, 4 | |
| Process_6_HandleCount | string | 0, 0, 2, 4 | |
| Process_6_ID | string | 0, 0, 2, 4 | |
| Process_6_Name | string | 0, 0, 2, 4 | |
| Process_6_TypeInfo | string | 0, 0, 2, 4 | |
| Process_6_Version | string | 0, 0, 2, 4 | |
| ProcessingMode | integer | 1006, 1129, 1500, 1501, 1502, 1503 | 1 |
| ProcessingMode | string | 1002, 1006, 1007, 1030, 1052, 1053, 1054, 1055, 1058, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1104, 1109, 1110, 1112, 1125, 1126, 1127, 1129, 1500, 1501, 1502, 1503 | |
| ProcessingTimeInMilliseconds | integer | 1006, 1129, 1500, 1501, 1502, 1503 | 94 |
| ProcessingTimeInMilliseconds | string | 1002, 1006, 1007, 1030, 1052, 1053, 1054, 1055, 1058, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1104, 1109, 1110, 1112, 1125, 1126, 1127, 1129, 1500, 1501, 1502, 1503 | |
| Processor | string | 1, 2, 3, 4, 7 | |
| ProcessorIndex | string | 252, 253 | |
| ProductName | string | 1, 2 | |
| ProductVersion | string | 1, 2 | |
| ProgrammedWakeTimeAc | string | 0, 1, 7 | |
| ProgrammedWakeTimeDc | string | 0, 1, 7 | |
| PropertyId | string | 78, 80, 92, 93 | |
| ProtectorGUID | string | 513, 514, 515, 516, 517 | |
| Protocol | string | 130, 36874, 36880, 40960, 40962, 40965, 40966, 40967, 40969 | |
| ProtocolType | string | 4200, 4201, 4202 | |
| ProviderGUID | string | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 300, 301, 302, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1058, 1060, 1061, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2003, 2004, 2005, 2042, 4000, 4001, 4002, 4003, 4004, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5300, 6000, 6027, 6033, 6035, 6036, 6037, 6040, 6041, 6100, 6145, 6146, 6400, 7001, 7002, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 10000, 10001, 10002, 10003, 10004, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50037, 50038, 51047, 51057 | |
| ProviderName | string | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 300, 301, 302, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1058, 1060, 1061, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2003, 2004, 2005, 2042, 4000, 4001, 4002, 4003, 4004, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5300, 6000, 6027, 6033, 6035, 6036, 6037, 6040, 6041, 6100, 6145, 6146, 6400, 7001, 7002, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 10000, 10001, 10002, 10003, 10004, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50037, 50038, 51047, 51057 | |
| PtNicFName | string | 146, 147, 150, 151, 216, 259 | |
| PtNicFNameLen | string | 146, 147, 150, 151, 216, 259 | |
| PtNicName | string | 146, 147, 150, 151, 216 | |
| PtNicNameLen | string | 146, 147, 150, 151, 216 | |
| Publisher | string | 0, 0, 4, 6 | |
| PublisherGuid | string | 0, 3 | |
| QfeVersion | string | 1, 2 | |
| Qualifiers | string | 2, 3, 4, 13, 18, 26, 27, 28, 32, 35, 46, 48, 129, 153, 262, 285, 286, 289, 290, 379, 380, 381, 1001, 1007, 1056, 1074, 1500, 2001, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 7000, 7001, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 9009, 10005, 10010, 10016, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 24576, 24577, 24579 | "7" |
| QueryName | string | 0, 1, 1, 4 | wpad |
| QueueLimitMBytes | string | 252, 253 | |
| QueueMode | string | 106, 122 | |
| QueuePairs | string | 4, 9 | |
| QueueSizeMBytes | string | 252, 253 | |
| RankNumber | string | 22, 23, 46, 47 | |
| RawData | string | 1, 2, 3, 6, 8, 10, 12, 14, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 40, 41, 42, 43, 44, 45, 46, 47 | |
| RdmaWeight | string | 256, 257 | |
| ReadSize | string | 2, 3, 4, 4, 8 | |
| ReaderName | string | 1000, 1001 | |
| Reason | integer | 1, 172, 566 | 6 |
| Reason | string | 1, 3, 5, 12, 14, 42, 172, 237, 506, 507, 508, 1002 | |
| ReasonPhrase | string | 7, 9 | |
| RebootOption | string | 20001, 20002 | |
| RebootTime | string | 0, 0, 0, 2, 9 | |
| RecordId | string | 1, 2 | |
| RecordNumber | integer | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 93485 |
| Register | string | 48, 97 | |
| RelaxMinimumPasswordLengthLimits | integer | 1, 6, 7, 7, 9 | 0 |
| RemainingCapacity | string | 0, 1, 5 | |
| RemainingPercentage | string | 2, 4, 5 | |
| RemainingRids | string | 1, 5, 6, 6, 8 | |
| RemoteAddr | string | 0, 9 | |
| RemoteAddrLen | string | 0, 9 | |
| RemoteAddress | string | 96, 98 | |
| RemoteAddressLength | string | 96, 98 | |
| RemoteCertSubjectName | string | 0, 3, 6, 8, 8 | |
| RemoteIPAddr | string | 0, 1, 3 | |
| RemoteIPAddrLen | string | 0, 1, 3 | |
| RemotePort | string | 0, 1, 3 | |
| RemotePortLen | string | 0, 1, 3 | |
| RemotePrefix | string | 0, 9 | |
| RemovedMemorySize | string | 1001, 1003 | |
| RepairData | string | 130, 131 | |
| RepairDataLength | string | 130, 131 | |
| RepairDetail | string | 130, 131 | |
| RepairGUID | string | 4000, 5000, 5100, 5200 | |
| RepairOption | string | 4000, 5000, 5100, 5200 | |
| RepairStatus | string | 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218 | |
| RequestHandled | string | 41, 42 | |
| RequestQueue | string | 7, 9 | |
| RequestType | string | 6, 8, 10, 12, 14, 16, 17, 18, 19 | |
| RequestedVlanIDs | string | 243, 244 | |
| RequesterId | string | 22, 23, 24, 25, 42, 43, 46, 47 | |
| Reservation | string | 82, 84, 100 | |
| Reserved1 | string | 1, 2 | |
| Reserved2 | string | 1, 2 | |
| ResetCount | string | 0, 0, 0, 1, 4 | |
| ResetEndStart | string | 0, 3 | |
| ResetReason | string | 0, 0, 0, 1, 4 | |
| ResetReasonMask | string | 1, 2, 4 | |
| ResiliencyDripsTimeInUs | string | 0, 5, 7 | |
| ResiliencyHwDripsTimeInUs | string | 0, 5, 7 | |
| ResponderId | string | 22, 23, 46, 47 | |
| RestartCount | string | 10111, 10112, 10115, 10116 | |
| RestartablePC | string | 28, 29 | |
| ResultCode | string | 401, 404, 405, 406, 407, 408, 409, 412, 413, 701, 702, 703, 704, 705, 716, 718 | |
| ResultHR | string | 4200, 5300 | |
| ResumeCount | string | 1, 1, 3 | |
| RetryMinutes | integer | 1, 3, 4 | 15 |
| RetryMinutes | string | 14, 17, 18, 29, 48, 129, 130, 131, 132, 133, 134, 135, 136 | |
| RetryWaitTime | string | 0, 1, 3, 6, 9 | |
| Revision | string | 1, 2 | |
| RmDescription | string | 2 | |
| RmDescriptionLength | string | 2 | |
| RmId | string | 2, 11 | |
| RootCause | string | 4000, 5000, 5100, 5200 | |
| RootCauseGUID | string | 4000, 5000, 5100, 5200 | |
| RoutingDomainGuid | string | 1, 2, 9 | |
| RoutingDomainGuidLen | string | 1, 2, 9 | |
| RoutingDomainName | string | 1, 2, 9 | |
| RoutingDomainNameLen | string | 1, 2, 9 | |
| Row | string | 22, 23, 46, 47 | |
| RpcEndPointError | string | 0, 2, 8 | |
| RssQueueIndex | string | 0, 2, 6 | |
| RuleId | string | 4 | |
| RuleName | string | 0, 1, 2, 3 | |
| RunningMode | string | 1, 1, 2, 5 | Classic |
| RunningState | string | 28, 29 | |
| SID | string | 0, 3, 5, 6 | |
| SIDTypeRequired | string | 4000, 5000, 5100, 5200 | |
| SampleData | string | 5, 5 | |
| SampleLength | string | 5, 5 | |
| ScenarioInstanceId | string | 506, 507 | |
| ScenarioInstanceIdV2 | string | 506, 507 | |
| ScheduleType | string | 1001, 1002, 1003 | |
| SchedulerType | string | 2 | |
| ScriptType | string | 0, 1, 1, 3 | |
| SecondaryBus | string | 16, 17, 40, 41 | |
| SecondaryDevice | string | 16, 17, 40, 41 | |
| SecondaryDeviceName | string | 16, 17, 40, 41 | |
| SecondaryFunction | string | 16, 17, 40, 41 | |
| SecondsRequired | string | 4000, 5000, 5100, 5200 | |
| Secret | string | 0, 2, 6, 7 | |
| SectionCount | string | 1, 2 | |
| SecurityPackage | string | 12302, 16398 | |
| Segment | string | 16, 17, 40, 41 | |
| SegmentNumber | string | 26, 27, 44, 45 | |
| SendStatus | string | 7, 9 | |
| Sent_UpdateServer | string | 0, 1, 8, 8 | 192.168.86.45:53 |
| ServerName | string | 0, 0, 3, 4 | |
| ServerUrl | string | 0, 0, 3, 4 | |
| ServerVersion | string | 2, 6 | |
| ServerVersionLen | string | 2, 6 | |
| ServiceName | integer | 7009, 10005, 10111 | 50 |
| ServiceName | string | 10, 1074, 7000, 7001, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 10001, 10002, 10010, 10016, 10117, 14200, 14201, 14202, 14203, 14204, 14205, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 20003, 20004 | {4991D34B-80A1-4291-83B6-3328366B9097} |
| ServiceNameLength | string | 0, 1 | |
| ServiceType | string | 0, 4, 5, 7 | user mode service |
| ServiceVersion | string | 1, 2 | |
| SettingType | string | 0, 2, 2, 4 | |
| SetupClass | string | 20001, 20002 | |
| Severity | string | 1, 2, 55 | |
| ShutdownActionType | string | 0, 1, 9 | |
| ShutdownEventCode | string | 0, 1, 9 | |
| ShutdownReason | string | 0, 1, 9 | |
| ShutdownTime | string | 86, 108 | |
| SigmaEventCode | integer | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 98 |
| Signature | string | 1, 2, 55 | |
| SiloCommand | string | 1, 1 | |
| SiloStatus | string | 1, 1 | |
| SiteID | integer | 0, 0, 1, 7 | 2 |
| SleepDuration | string | 1 | |
| SleepInProgress | string | 1, 4 | false |
| SleepState | string | 1, 3, 7 | |
| SleepTime | string | 1 | |
| Slot | string | 16, 17, 40, 41 | |
| SmtEnabled | string | 1, 5, 6 | |
| SniHostname | string | 96, 98 | |
| SoftRestartCount | string | 1, 8 | |
| SourceFile | string | 55, 131, 134, 139, 140 | |
| SourceIdBus | string | 1, 8 | |
| SourceIdDev | string | 1, 8 | |
| SourceIdFun | string | 1, 8 | |
| SourceLine | string | 55, 131, 134, 139, 140 | |
| SourceTag | string | 55, 131, 134, 139, 140 | |
| SpareMemoryCount | string | 2, 2, 4 | |
| SpareMemorySize | string | 2, 2, 4 | |
| SparePath | string | 240, 241, 242 | |
| SpareProcessorCount | string | 2, 2, 4 | |
| SrcVPortId | string | 0, 2, 5 | |
| StartBias | string | 0, 1, 8 | |
| StartDeviceFailReason | string | 1, 4 | |
| StartOSImageStart | string | 0, 3 | |
| StartTime | string | 12, 1001, 1002 | 2021-11-09 21:42:16.500 UTC |
| StartType | string | 0, 4, 5, 7 | demand start |
| State | integer | 1, 2, 7 | 2 |
| State | string | 172, 8193 | |
| Stateful | string | 0, 1, 3 | |
| Status | integer | 1, 2, 3, 4, 5, 6, 8, 10, 11, 12, 13, 14, 15, 16, 17, 18, 20, 32, 34, 35, 37, 38, 39, 40, 41, 42, 43, 44, 45, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 82, 84, 96, 97, 100, 113, 116, 122, 124, 132, 149, 152, 153, 156, 190, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 217, 218, 219, 227, 235, 236, 238, 239, 241, 254, 256, 257, 258, 261, 267, 269, 276, 1003, 10110, 16976, 24832, 32780 | 0 |
| StatusCode | string | 97, 1004, 1018, 50038 | |
| StopTime | string | 1, 3 | 2021-11-09 21:05:12.054501 UTC |
| StormLimit | string | 8, 8 | |
| String | string | 8, 9, 11, 1000, 19999 | |
| StringCount | string | 1, 1 | |
| SubKeyOrValueName | string | 0, 1, 4, 5, 6 | |
| SubjectDomainName | string | 0, 1, 4 | |
| SubjectUserName | string | 0, 1, 4 | |
| SubkeyName | string | 5 | |
| SubkeyNameLen | string | 5 | |
| SupportInfo1 | integer | 1006, 1129, 1500, 1501, 1502, 1503 | 1 |
| SupportInfo1 | string | 1002, 1006, 1007, 1030, 1052, 1053, 1054, 1055, 1058, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1104, 1109, 1110, 1112, 1125, 1126, 1127, 1128, 1129, 1130, 1500, 1501, 1502, 1503 | |
| SupportInfo2 | integer | 1006, 1129, 1500, 1501, 1502, 1503 | 6191 |
| SupportInfo2 | string | 1002, 1006, 1007, 1030, 1052, 1053, 1054, 1055, 1058, 1065, 1068, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1104, 1109, 1110, 1112, 1125, 1126, 1127, 1128, 1129, 1130, 1500, 1501, 1502, 1503 | |
| SuspendEnd | string | 0, 1, 3 | |
| SuspendStart | string | 0, 1, 3 | |
| SwitchFName | string | 9, 10, 11, 12, 14, 15, 17, 18, 32, 33, 34, 35, 41, 42, 43, 46, 63, 65, 68, 70, 72, 73, 74, 75, 78, 80, 82, 84, 88, 90, 92, 93, 94, 95, 97, 98, 99, 100, 106, 113, 119, 120, 121, 122, 127, 128, 129, 130, 132, 227, 232, 237, 239, 243, 244, 252, 253, 259, 260, 261, 264, 265, 266, 270 | |
| SwitchFNameLen | string | 9, 10, 11, 12, 14, 15, 17, 18, 32, 33, 34, 35, 41, 42, 43, 46, 63, 65, 68, 70, 72, 73, 74, 75, 78, 80, 82, 84, 88, 90, 92, 93, 94, 95, 97, 98, 99, 100, 106, 113, 119, 120, 121, 122, 127, 128, 129, 130, 132, 227, 232, 237, 239, 243, 244, 252, 253, 259, 260, 261, 264, 265, 266, 270 | |
| SwitchFriendlyName | string | 206, 207, 208, 209, 210, 211, 212, 213, 214, 229, 230 | |
| SwitchFriendlyNameLen | string | 206, 207, 208, 209, 210, 211, 212, 213, 214, 229, 230 | |
| SwitchName | string | 9, 10, 11, 12, 14, 15, 17, 18, 32, 33, 34, 35, 41, 42, 43, 46, 63, 65, 68, 70, 72, 73, 74, 75, 78, 80, 82, 84, 88, 90, 92, 93, 94, 95, 97, 98, 99, 100, 106, 113, 119, 120, 121, 122, 127, 128, 129, 130, 132, 206, 207, 208, 209, 210, 211, 212, 213, 214, 227, 229, 230, 232, 237, 239, 243, 244, 252, 253, 260, 261, 264, 265, 266, 270 | |
| SwitchNameLen | string | 9, 10, 11, 12, 14, 15, 17, 18, 32, 33, 34, 35, 41, 42, 43, 46, 63, 65, 68, 70, 72, 73, 74, 75, 78, 80, 82, 84, 88, 90, 92, 93, 94, 95, 97, 98, 99, 100, 106, 113, 119, 120, 121, 122, 127, 128, 129, 130, 132, 206, 207, 208, 209, 210, 211, 212, 213, 214, 227, 229, 230, 232, 237, 239, 243, 244, 252, 253, 260, 261, 264, 265, 266, 270 | |
| SystemAction | string | 1, 7, 8 | |
| SystemAssignedAccountName | string | 0, 1, 2, 3, 4 | |
| SystemCommitCharge | string | 0, 0, 2, 4 | |
| SystemCommitLimit | string | 0, 0, 2, 4 | |
| SystemSleepTransitionsToOn | string | 1, 4 | |
| SystemTime | string | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | '2022-07-28 14:13:42.451381 UTC' |
| SystemTimeChangeSeconds | integer | 3, 4 | 21 |
| SystemTimeChangeSeconds | string | 33, 34 | |
| System_Props_Xml | string | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 |
|
| T10NumBadPages | string | 1101, 1102, 1103, 1104 | |
| T11NumBadPages | string | 1101, 1102, 1103, 1104 | |
| T12NumBadPages | string | 1101, 1102, 1103, 1104 | |
| T13NumBadPages | string | 1101, 1102, 1103, 1104 | |
| T14NumBadPages | string | 1101, 1102, 1103, 1104 | |
| T15NumBadPages | string | 1101, 1102, 1103, 1104 | |
| T16NumBadPages | string | 1101, 1102, 1103, 1104 | |
| T1NumBadPages | string | 1101, 1102, 1103, 1104 | |
| T2NumBadPages | string | 1101, 1102, 1103, 1104 | |
| T3NumBadPages | string | 1101, 1102, 1103, 1104 | |
| T4NumBadPages | string | 1101, 1102, 1103, 1104 | |
| T5NumBadPages | string | 1101, 1102, 1103, 1104 | |
| T6NumBadPages | string | 1101, 1102, 1103, 1104 | |
| T7NumBadPages | string | 1101, 1102, 1103, 1104 | |
| T8NumBadPages | string | 1101, 1102, 1103, 1104 | |
| T9NumBadPages | string | 1101, 1102, 1103, 1104 | |
| TCGInvokingID | string | 1, 1 | |
| TCGMethodID | string | 1, 1 | |
| TLBOperationType | string | 28, 29 | |
| TPM_PT_FIRMWARE_VERSION_1 | string | 2, 7 | |
| TPM_PT_FIRMWARE_VERSION_2 | string | 2, 7 | |
| TPM_PT_MANUFACTURER | string | 2, 7 | |
| TPM_PT_VEDNOR_STRING_2 | string | 2, 7 | |
| TPM_PT_VEDNOR_STRING_3 | string | 2, 7 | |
| TPM_PT_VEDNOR_STRING_4 | string | 2, 7 | |
| TPM_PT_VEDNOR_TPM_TYPE | string | 2, 7 | |
| TPM_PT_VENDOR_STRING_1 | string | 2, 7 | |
| TSId | string | 7001, 7002 | |
| TableIndex | string | 0, 1, 5 | |
| TargetAffinity | string | 2, 2, 4 | |
| TargetDomain | string | 32773, 32774, 32775 | |
| TargetId | string | 22, 23, 24, 25, 42, 43, 46, 47 | |
| TargetMemoryCount | string | 2, 2, 4 | |
| TargetMemorySize | string | 2, 2, 4 | |
| TargetName | string | 6037, 6040, 6041, 36880, 36888 | |
| TargetPath | string | 240, 241, 242 | |
| TargetProcessorCount | string | 2, 2, 4 | |
| TargetRunLevel | string | 13, 14, 15, 16 | |
| TargetState | string | 1, 42, 107 | |
| TargetVersion | string | 0, 1, 4, 6 | |
| TaskName | string | 1, 4, 4 | |
| TaskProcessID | string | 2, 11 | |
| TaskType | string | 1, 5, 6, 10, 14, 15 | |
| TeamingMode | string | 206, 207, 208, 209, 210, 211 | |
| TeredoReasonCode | string | 0, 0, 1, 4 | |
| TestCount | string | 1101, 1102, 1103, 1104 | |
| TestDuration | string | 1101, 1102, 1103, 1104 | |
| TestType | string | 1101, 1102, 1103, 1104 | |
| ThermalZoneDeviceInstance | string | 86, 88, 89, 125 | |
| ThermalZoneDeviceInstanceLength | string | 86, 88, 89, 125 | |
| ThreadCount | string | 7, 9 | |
| ThreadID | string | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 201, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 262, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 285, 286, 289, 290, 300, 301, 302, 379, 380, 381, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 566, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1025, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1056, 1058, 1060, 1061, 1065, 1068, 1074, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1281, 1282, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2001, 2003, 2004, 2005, 2042, 3261, 4000, 4001, 4002, 4003, 4004, 4005, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5202, 5203, 5211, 5300, 5774, 5782, 5823, 6000, 6005, 6006, 6009, 6011, 6013, 6027, 6033, 6035, 6036, 6037, 6038, 6040, 6041, 6100, 6145, 6146, 6148, 6400, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 9009, 10000, 10001, 10002, 10003, 10004, 10005, 10010, 10016, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10121, 10148, 10149, 10154, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14206, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 14531, 14533, 15007, 15008, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16647, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 16983, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 20010, 24576, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50036, 50037, 50038, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | "956" |
| ThreadId | integer | 7, 9 | |
| ThrottleStateCount | integer | 2, 6 | 0 |
| ThrottleStateCount | string | 4, 26 | |
| Thumbprint | string | 96, 98, 516, 517, 518 | |
| ThumbprintLength | string | 96, 98 | |
| TimeDifferenceMilliseconds | string | 0, 5 | |
| TimeDifferenceSeconds | string | 1, 5 | |
| TimeOffsetSeconds | string | 2, 5 | |
| TimeProvider | string | 1, 2, 3, 4, 5, 7, 8, 9, 10, 40, 43, 158 | |
| TimeQuiesced | string | 2, 2, 4 | |
| TimeRemainingToSetLocalClockFreeRunningSeconds | string | 3, 6 | |
| TimeSampleSeconds | string | 0, 5 | |
| TimeSource | string | 34, 35, 37, 38, 132, 135 | time.windows.com,0x8 (ntp.m |
| TimeSourceRefId | string | 3, 5 | |
| TimeStamp | string | 0, 4, 5, 5, 8 | |
| TimeToQuiesce | string | 2, 2, 4 | |
| TimeToWake | string | 2, 2, 4 | |
| TimeTotal | string | 2, 2, 4 | |
| TimeZoneInfoCacheUpdated | integer | 2, 4 | 0 |
| Timeout | string | 18, 19, 28, 29 | |
| Timestamp | string | 1, 2 | |
| TimestampForced | string | 0, 1, 8 | |
| Title | string | 16385, 16386, 16390 | PreSignInSettingsConfigJSON |
| TmId | string | 1, 1 | |
| TmIdentity | string | 3, 4 | |
| TmLogFileName | string | 3, 4 | |
| TmLogFileNameLength | string | 3, 4 | |
| ToolsCount | string | 1, 9 | |
| TotalProcesses | string | 0, 0, 2, 4 | |
| TpcChanges | string | 7, 37 | |
| TpmCommandOrdinal | string | 1, 7 | |
| TpmResponseCode | string | 1, 7 | |
| TransactionType | string | 6, 8, 10, 12, 14, 16, 17, 18, 19, 28, 29 | |
| TransitionStartTime | string | 1, 8 | |
| TransitionsToOn | string | 2, 4 | |
| TransmissionDelayMilliseconds | string | 1, 5 | |
| TriggerID | string | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15 | |
| TrustletIdentity | string | 1, 2, 4 | |
| TryComplete | string | 1, 2, 4 | |
| Turn | string | 2, 2 | |
| TxDescription | string | 1, 2, 3, 4 | |
| TxDescriptionLength | string | 1, 2, 3, 4 | |
| TxUow | string | 1, 2, 3, 4 | |
| TxtStatus | string | 2, 2, 2 | |
| URL | string | 1, 3, 3, 4, 5 | |
| UncorrectableErrorStatus | string | 16, 17, 18, 40, 41 | |
| Uncorrected | string | 1, 3 | |
| UniqueEvent | string | 4, 6, 8, 10, 11, 12, 13, 14, 15, 16, 18, 20, 32, 34, 35, 41, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 132, 190, 235, 236, 238, 239, 258, 269, 276 | |
| UniqueEventValue | string | 4, 15 | |
| UnitBaseAddress | string | 1, 4, 8 | |
| UnsynchronizedTimeSeconds | string | 3, 6 | |
| UpdateDllName | string | 6, 8 | |
| UpdateReason | string | 0, 2 | |
| UpdateService | string | 20003, 20004 | |
| UpdateType | string | 0, 2, 2, 4 | |
| Upgrade | string | 10001, 10002 | |
| UpgradeDevice | string | 20001, 20002 | |
| Url | string | 97, 15007, 15008 | http://+:3387/rdp/ |
| UrlPrefix | string | 0, 0, 1, 7 | http://*:80/ |
| UserData_Xml | string | 104, 1001, 1121, 1206, 1208, 10000, 10001, 10100, 20001, 20003, 20010 |
|
| UserID | string | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 61, 63, 65, 68, 70, 72, 73, 74, 75, 76, 77, 78, 80, 81, 82, 84, 86, 87, 88, 89, 90, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 104, 105, 106, 107, 108, 109, 113, 115, 116, 119, 120, 121, 122, 124, 125, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 156, 157, 158, 159, 172, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 195, 196, 197, 201, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211, 212, 213, 214, 215, 216, 217, 218, 219, 222, 225, 227, 229, 230, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 252, 253, 254, 256, 257, 258, 259, 260, 261, 263, 264, 265, 266, 267, 268, 269, 270, 276, 280, 300, 301, 302, 401, 404, 405, 406, 407, 408, 409, 412, 413, 414, 506, 507, 508, 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 566, 701, 702, 703, 704, 705, 716, 718, 769, 809, 823, 824, 1000, 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1023, 1025, 1026, 1029, 1030, 1031, 1040, 1041, 1042, 1043, 1052, 1053, 1054, 1055, 1058, 1060, 1061, 1065, 1068, 1074, 1079, 1080, 1085, 1088, 1089, 1090, 1091, 1095, 1096, 1097, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1136, 1137, 1138, 1139, 1140, 1141, 1201, 1202, 1203, 1204, 1205, 1206, 1207, 1208, 1209, 1210, 1211, 1212, 1213, 1214, 1215, 1216, 1217, 1218, 1281, 1282, 1500, 1501, 1502, 1503, 1537, 1538, 1539, 2003, 2004, 2005, 2042, 4000, 4001, 4002, 4003, 4004, 4096, 4097, 4098, 4099, 4100, 4200, 4201, 4202, 4300, 4302, 5000, 5100, 5200, 5300, 6000, 6027, 6033, 6035, 6036, 6037, 6040, 6041, 6100, 6145, 6146, 6148, 6400, 7001, 7002, 7040, 7042, 7045, 8001, 8002, 8003, 8004, 8005, 8006, 8007, 8008, 8009, 8010, 8011, 8012, 8013, 8014, 8015, 8016, 8017, 8018, 8019, 8020, 8021, 8022, 8023, 8024, 8025, 8026, 8027, 8028, 8029, 8030, 8031, 8032, 8033, 8034, 8035, 8036, 8037, 8038, 8193, 8194, 10000, 10001, 10002, 10003, 10004, 10005, 10010, 10016, 10100, 10101, 10110, 10111, 10112, 10113, 10115, 10116, 10117, 10317, 10400, 12288, 12289, 12291, 12293, 12294, 12295, 12296, 12297, 12298, 12299, 12302, 12303, 12304, 12305, 14200, 14201, 14202, 14203, 14204, 14205, 14210, 14300, 14301, 14302, 14303, 14304, 14305, 14306, 14307, 14308, 14309, 14310, 14311, 14312, 14313, 14314, 14315, 14316, 14317, 14318, 14319, 14320, 14321, 14322, 14323, 14326, 14327, 14328, 14329, 14330, 14331, 14333, 14337, 14338, 14339, 14340, 14341, 14342, 14343, 14345, 14346, 14347, 14348, 14349, 14351, 14352, 14353, 14354, 14355, 14356, 14357, 14358, 14359, 16384, 16385, 16386, 16387, 16388, 16389, 16390, 16391, 16392, 16393, 16394, 16395, 16396, 16397, 16398, 16399, 16400, 16401, 16402, 16403, 16404, 16405, 16406, 16407, 16409, 16410, 16411, 16412, 16413, 16642, 16643, 16644, 16645, 16646, 16647, 16648, 16649, 16651, 16653, 16655, 16656, 16657, 16658, 16935, 16936, 16937, 16944, 16945, 16946, 16947, 16948, 16949, 16950, 16951, 16952, 16953, 16962, 16963, 16964, 16965, 16968, 16969, 16976, 16977, 16978, 16979, 16983, 17005, 19999, 20001, 20002, 20003, 20004, 20005, 20006, 20007, 20008, 20009, 20010, 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686, 24832, 24833, 24834, 24835, 24836, 24837, 24838, 24839, 24840, 24841, 24842, 24843, 24844, 24845, 24846, 24847, 24848, 32773, 32774, 32775, 32780, 36865, 36867, 36868, 36869, 36870, 36871, 36872, 36874, 36876, 36877, 36878, 36879, 36880, 36881, 36882, 36883, 36884, 36887, 36888, 36889, 36912, 40960, 40961, 40962, 40965, 40966, 40967, 40969, 45057, 45058, 50036, 50037, 50038, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | "S-1-5-21-582766833-432816504-4207985818-1009" |
| UserName | string | 12294, 12302, 16385, 16400, 16406, 45058 | |
| UserSID | string | 21, 23 | |
| UserSid | string | 7001, 7002 | S-1-5-21-1103654211-1238870038-1204021333-1002 |
| Username | string | 0, 4, 5, 5, 7 | |
| VMId | string | 26, 61, 102 | |
| VMIdLen | string | 26, 61, 102 | |
| VMName | string | 26, 33, 61, 102 | |
| VMNameLen | string | 26, 33, 61, 102 | |
| VMQOffloadWeight | string | 4, 9 | |
| ValidBatteryCount | string | 1, 2, 5 | |
| ValidBits | string | 16, 17, 22, 23, 24, 25, 26, 27, 40, 41, 42, 43, 44, 45, 46, 47 | |
| ValidationBits | string | 1, 2 | |
| Value | string | 6, 7, 10113 | |
| Vcb | string | 143, 144 | |
| VendorID | string | 16, 17, 40, 41 | |
| VendorId | string | 26, 27, 44, 45 | |
| Verb | string | 55, 97, 99 | |
| Verbosity | string | 7, 9 | |
| Version | integer | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5782, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 2 |
| Version | string | 1, 2, 16, 17, 40, 41, 219 | |
| VersionLen | integer | 1 | 3 |
| VersionLen | string | 1, 2 | |
| VersionSupported | string | 0, 4 | |
| VfAdapterName | string | 41, 42, 46, 47, 48 | \DEVICE{651F97F9-A838-4081-A596-E6A86FBB1145} |
| VfAdapterNameLen | integer | 4, 6 | 46 |
| VfAdapterNameLen | string | 41, 42, 46, 47, 48 | |
| VirtualFaultAddress | string | 28, 29 | |
| VirtualSubnetId | string | 88, 130 | |
| VlanID | string | 1, 7, 9 | |
| VlanId | string | 0, 2, 4 | |
| VmqIndex | string | 0, 2, 6 | |
| VmqSumOfQueues | string | 206, 207, 208, 209, 210, 211 | |
| Volume | string | 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686 | |
| VolumeGUID | string | 513, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 524, 525, 526, 527, 528, 529, 530, 531, 823, 824, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24643, 24645, 24652, 24653, 24654, 24657, 24658, 24659, 24672 | |
| VolumeGuid | string | 143, 144, 150 | |
| VolumeId | string | 130, 131, 134, 135, 136, 137, 138, 139, 140, 210, 211, 517, 518 | |
| VolumeIdLength | string | 130, 131, 134, 135, 136, 137, 138, 139, 140, 517, 518 | |
| VolumeLabel | string | 1, 3, 4 | |
| VolumeLabelLength | string | 1, 3, 4 | |
| VolumeName | string | 143, 144, 150, 1206 | |
| VolumeNameLength | string | 143, 144, 150, 1206 | |
| VolumeNames | string | 1 | |
| VportsSupported | string | 204, 205, 215 | |
| VsmPolicy | integer | 1, 3, 5 | 0 |
| VsmPolicy | string | 153, 156 | |
| VxLanEnabled | string | 0, 2, 3 | |
| WDFDEVICE | string | 0, 0, 1, 3 | |
| WakeDuration | string | 1 | |
| WakeFromState | string | 0, 1, 7 | |
| WakeRequesterTypeAc | string | 0, 1, 7 | |
| WakeRequesterTypeDc | string | 0, 1, 7 | |
| WakeSourceText | string | 1 | |
| WakeSourceTextLength | string | 1 | |
| WakeSourceType | string | 1 | |
| WakeTime | string | 1 | |
| WakeTimerContext | string | 1 | |
| WakeTimerContextLength | string | 1 | |
| WakeTimerOwner | string | 1 | |
| WakeTimerOwnerLength | string | 1 | |
| Weight | string | 82, 84, 100, 130 | |
| Win32Err | integer | 2 | |
| WinError | string | 12295, 12296 | |
| WorkingSetSize | string | 7, 9 | |
| WritePhase | string | 24577, 24578, 24579, 24580, 24581, 24582, 24583, 24584, 24585, 24586, 24587, 24588, 24589, 24590, 24591, 24592, 24593, 24594, 24595, 24596, 24597, 24598, 24599, 24600, 24601, 24602, 24603, 24604, 24605, 24606, 24607, 24608, 24609, 24610, 24611, 24612, 24613, 24614, 24615, 24616, 24617, 24618, 24619, 24620, 24621, 24622, 24623, 24624, 24625, 24626, 24627, 24628, 24629, 24630, 24631, 24632, 24633, 24634, 24635, 24636, 24637, 24638, 24639, 24640, 24641, 24642, 24643, 24644, 24645, 24646, 24647, 24648, 24649, 24650, 24651, 24652, 24653, 24654, 24655, 24656, 24657, 24658, 24659, 24660, 24661, 24662, 24663, 24664, 24665, 24666, 24667, 24668, 24669, 24670, 24671, 24672, 24673, 24674, 24675, 24676, 24677, 24678, 24679, 24680, 24681, 24682, 24683, 24684, 24685, 24686 | |
| binaryData | string | 36867, 36869 | |
| body | string | 2, 6 | The application was unable to start correctly (0xc0000142). Click OK to close the application. |
| certificateContext | string | 36881, 36882, 36883, 36884 | |
| currentLimit | string | 16397, 16398, 16400, 16401, 16402 | |
| currentSize | string | 16397, 16398, 16400, 16401, 16402 | |
| dest | string | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | win10-base |
| dvc | string | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | win10-base |
| dvc_nt_host | string | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | win7-x86 |
| entityName | string | 16397, 16398, 16400, 16401, 16402 | |
| error | integer | 0, 1, 1, 4, 5 | 1355 |
| errorCode | string | 20, 24, 213 | 0x8024200b |
| event_id | integer | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 93485 |
| evtAdditionalInfo | string | 1 | |
| evtErrorId | string | 1 | |
| evtHiveName | string | 1, 2 | |
| evtHiveNameLength | string | 1, 2 | |
| evtStatus | string | 1, 3, 4 | |
| failureReason | string | 37, 38, 39, 43 | |
| fid_DripsWatchdogResult | string | 195, 196 | |
| fid_UcxController | string | 1, 4 | |
| fid_UsbDevice | string | 195, 196 | |
| fid_bcdDevice | string | 195, 196 | |
| fid_idProduct | string | 195, 196 | |
| fid_idVendor | string | 195, 196 | |
| filename | string | 24840, 24841 | |
| function | string | 0, 1, 4, 4, 6 | |
| locationCode | string | 2, 12, 14, 15, 16, 17, 18, 19, 20, 22, 25, 26, 27 | 0x140000d6 |
| offset | string | 24840, 24841 | |
| pCertificateContext | string | 36876, 36877, 36878, 36879 | |
| param1 | integer | 7009, 10005, 10111 | 50 |
| param1 | string | 1074, 7000, 7001, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 10010, 10016 | {4991D34B-80A1-4291-83B6-3328366B9097} |
| param10 | string | 0, 0, 1, 1, 6 | Unavailable |
| param11 | string | 0, 0, 1, 1, 6 | Unavailable |
| param2 | integer | 7031, 7034, 7039 | 5748 |
| param2 | string | 1074, 7000, 7001, 7009, 7023, 7024, 7036, 7038, 7040, 7042, 10005, 10016 | stopped |
| param3 | integer | 7031, 7039 | 30000 |
| param3 | string | 1074, 7001, 7038, 7040, 7042, 10005, 10016 | demand start |
| param4 | integer | 0, 1, 3, 7 | 1 |
| param4 | string | 1074, 7040, 7042, 10005, 10016 | Windows.SecurityCenter.SecurityAppBroker |
| param5 | string | 1074, 7031, 7042, 10016 | restart |
| param6 | string | 1074, 10016 | Reboot initiated by Ansible |
| param7 | string | 1074, 10016 | SYSTEM |
| param8 | string | 0, 0, 1, 1, 6 | S-1-5-18 |
| param9 | string | 0, 0, 1, 1, 6 | LocalHost (Using LRPC) |
| restarttime | string | 2, 2 | |
| schedinstalldate | string | 1, 8 | |
| schedinstalltime | string | 1, 8 | |
| serverName | string | 32, 33 | |
| serviceGuid | string | 19, 20, 23, 24, 212 | 9482F4B4-E343-43B6-B170-9A65BC822C77 |
| service_name | integer | 7009, 10005, 10111 | 50 |
| service_name | string | 1074, 7000, 7001, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 10010, 10016, 14204, 14205 | {4991D34B-80A1-4291-83B6-3328366B9097} |
| sigma_product | string | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | windows |
| sigma_service | string | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | system |
| signature | string | 19, 20, 43, 44, 519, 566 | Security Intelligence Update for Microsoft Defender Antivirus - KB2267602 (Version 1.353.706.0) |
| signature_id | integer | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 98 |
| spn1 | string | 0, 1, 1, 4, 5 | WSMAN/WIN-FPV0DSIC9O6.sigma.fr |
| spn2 | string | 0, 1, 1, 4, 5 | WSMAN/WIN-FPV0DSIC9O6 |
| start_mode | string | 7040, 7045 | manual |
| statusActive | string | 2, 4 | |
| statusEnabled | string | 2, 4 | |
| string | string | 19, 17005 | |
| string2 | string | 0, 0, 1, 5, 7 | |
| string3 | string | 0, 0, 1, 5, 7 | |
| subject | string | 519, 566 | Object Operation (W3 Active Directory) |
| timeendpos | integer | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 594 |
| timestartpos | integer | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | 564 |
| updateGuid | string | 19, 20, 23, 24, 43, 44, 212, 213, 214, 215 | 6CE0FD31-E410-43E3-AACA-EDD43C217639 |
| updateRevisionNumber | integer | 19, 20, 43, 44 | 200 |
| updateRevisionNumber | string | 19, 20, 23, 24, 43, 44, 212, 213, 214, 215 | |
| updateTitle | string | 19, 20, 23, 43, 44, 212, 214, 215 | Security Intelligence Update for Microsoft Defender Antivirus - KB2267602 (Version 1.353.706.0) |
| updatelist | string | 17, 18, 21, 22, 24, 213 | |
| user_id | string | 1, 3, 5, 6, 10, 11, 12, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 50, 52, 55, 98, 104, 134, 137, 139, 143, 153, 172, 201, 206, 238, 519, 521, 566, 1001, 1006, 1014, 1025, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2003, 2004, 6148, 7001, 7002, 7040, 7042, 7045, 8018, 10000, 10001, 10005, 10010, 10016, 10100, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | "S-1-5-21-582766833-432816504-4207985818-1009" |
| vPortId | string | 204, 215 | |
| vendor | string | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | Microsoft |
| vendor_product | string | 1, 2, 3, 4, 5, 6, 10, 11, 12, 13, 14, 15, 16, 18, 19, 20, 22, 24, 25, 26, 27, 28, 30, 32, 34, 35, 36, 37, 41, 43, 44, 46, 47, 48, 50, 52, 55, 98, 104, 109, 129, 134, 137, 139, 143, 153, 172, 201, 206, 238, 262, 285, 286, 289, 290, 379, 380, 381, 519, 521, 566, 1001, 1006, 1007, 1014, 1025, 1056, 1074, 1121, 1129, 1206, 1208, 1281, 1282, 1500, 1501, 1502, 1503, 2001, 2003, 2004, 3261, 4005, 5200, 5202, 5203, 5211, 5774, 5781, 5782, 5805, 5823, 6005, 6006, 6009, 6011, 6013, 6038, 6148, 7000, 7001, 7002, 7009, 7022, 7023, 7024, 7026, 7030, 7031, 7034, 7036, 7038, 7039, 7040, 7042, 7043, 7045, 8018, 9009, 10000, 10001, 10005, 10010, 10016, 10100, 10111, 10121, 10148, 10149, 10154, 14204, 14205, 14206, 14531, 14533, 15007, 15008, 16385, 16392, 16401, 16403, 16413, 16647, 16648, 16937, 16962, 16977, 16983, 20001, 20003, 20010, 24576, 24577, 24579, 36887, 50036, 50037, 50103, 50104, 50105, 50106, 51046, 51047, 51057 | Microsoft Windows |
| volume | string | 2, 3, 4, 5, 8 | |
| wimFile | string | 24837, 24838, 24839, 24843, 24844, 24845, 24846 | |
| wimHashFile | string | 24837, 24838, 24839, 24843, 24844, 24845, 24846 |
taskscheduler
| Field | Data Type | Event IDs | Example |
|---|---|---|---|
| Account | string | 1, 1, 7 | |
| Command | string | 310, 311 | |
| Computer | string | 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717 | win-dc-469.attackrange.local |
| EventID | integer | 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717 | 330 |
| Name | string | 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 330, 332, 400, 402, 700 | 'Microsoft-Windows-TaskScheduler' |
| Path | string | 1, 2, 9 | %windir%\system32\wermgr.exe |
| Task | integer | 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330 | 330 |
| Task | string | 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717 | |
| id | integer | 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 330, 332, 400, 402, 700 | 5404 |
| ActionName | string | 200, 201, 202, 203 | NGC Pregeneration Task Handler |
| ActivityID | string | 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 330, 332, 400, 402, 700 | '{7AD1452B-31A1-4664-BAD4-57539A029944}' |
| Channel | string | 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717 | Microsoft-Windows-TaskScheduler/Operational |
| Context | string | 0, 1, 5 | |
| CurrentQuota | string | 131, 132 | |
| EnginePID | string | 200, 201, 202 | |
| ErrorDescription | string | 104, 303, 311, 403 | |
| EventCode | integer | 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 330, 332, 400, 402, 700 | 330 |
| EventData_Xml | string | 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330 | \Run NotepadATTACKRANGE\Administrator{7AD1452B-31A1-4664-BAD4-57539A029944} |
| EventRecordID | integer | 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 330, 332, 400, 402, 700 | 5404 |
| Guid | string | 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 330, 332, 400, 402, 700 | '{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}' |
| InstanceId | string | 100, 102, 103, 107, 108, 109, 110, 111, 114, 117, 118, 119, 120, 121, 122, 123, 124, 125 | {7AD1452B-31A1-4664-BAD4-57539A029944} |
| Keywords | string | 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717 | 0x8000000000000001 |
| Level | integer | 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717 | 4 |
| LogPoint | string | 1, 1, 5 | |
| Message | string | 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 403, 410, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717 | |
| NewTaskInstanceId | string | 2, 3, 3 | |
| Opcode | integer | 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330 | 2 |
| Opcode | string | 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717 | |
| Priority | string | 1, 2, 9 | |
| ProcessID | string | 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717 | '1316' |
| ProcessId | integer | 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330 | 1816 |
| ProviderGUID | string | 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717 | |
| ProviderName | string | 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717 | |
| QueuedTaskInstanceId | string | 324, 325 | 5F6009CF-535A-456B-B1EB-0B7C5C30AABF |
| RecordNumber | integer | 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 330, 332, 400, 402, 700 | 5404 |
| RelatedActivityID | string | 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 332, 400, 402, 700 | |
| ResultCode | integer | 103, 201, 202 | 2148073520 |
| ResultCode | string | 101, 103, 104, 105, 113, 115, 116, 126, 130, 146, 148, 150, 151, 201, 202, 203, 204, 205, 303, 305, 306, 307, 311, 315, 316, 331, 403, 410, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717 | |
| RunningTaskInstanceId | string | 2, 3, 4 | EC1D2D19-D309-4577-A40D-0FB4CE6B479C |
| SecurityDescriptor | string | 0, 7, 8 | |
| SessionId | string | 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 332, 400, 402, 700 | |
| SigmaEventCode | integer | 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330 | 330 |
| StoppedTaskInstanceId | string | 2, 3, 3 | |
| SystemTime | string | 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 330, 332, 400, 402, 700 | '2022-06-28 15:11:04.524776 UTC' |
| System_Props_Xml | string | 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330 |
|
| TaskCount | string | 0, 3, 9 | |
| TaskEngineName | string | 133, 134, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320 | |
| TaskInstanceId | string | 200, 201, 202, 203, 304, 320, 322, 327, 328, 329, 330, 331 | {7AD1452B-31A1-4664-BAD4-57539A029944} |
| TaskName | string | 100, 101, 102, 103, 106, 107, 108, 109, 110, 111, 112, 113, 114, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 133, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 200, 201, 202, 203, 204, 205, 304, 305, 319, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 706, 707, 708, 709, 713, 714 | \Run Notepad |
| TaskPath | string | 1, 5, 5 | |
| TaskStatus | string | 0, 6, 7 | |
| ThreadID | string | 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717 | '5004' |
| UserContext | string | 100, 101, 102, 103, 106, 110, 330 | System |
| UserID | string | 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 140, 141, 142, 146, 147, 148, 149, 150, 151, 152, 153, 155, 200, 201, 202, 203, 204, 205, 300, 301, 303, 304, 305, 306, 307, 308, 309, 310, 311, 312, 313, 314, 315, 316, 317, 318, 319, 320, 322, 323, 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334, 400, 402, 403, 410, 700, 706, 707, 708, 709, 710, 711, 712, 713, 714, 715, 717 | 'S-1-5-18' |
| UserName | string | 104, 119, 120, 121, 122, 123, 124, 125, 133, 134, 140, 141, 142, 332 | SNAPATTACK\snapattack |
| Version | integer | 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 330, 332, 400, 402, 700 | 2 |
| dvc | string | 100, 101, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 142, 153, 200, 201, 202, 203, 322, 324, 325, 328, 329, 330, 332, 400, 402, 700 | win-dc-469.attackrange.local |
| dvc_nt_host | string | 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330 | win-dc-469.attackrange.local_0d8ffca2-620a-4526-a4de-aef022b9dd48 |
| event_id | integer | 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330 | 5404 |
| sigma_product | string | 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330 | windows |
| sigma_service | string | 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330 | taskscheduler |
| signature_id | integer | 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330 | 330 |
| timeendpos | integer | 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330 | 521 |
| timestartpos | integer | 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330 | 491 |
| user_id | string | 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330 | 'S-1-5-18' |
| vendor_product | string | 100, 102, 103, 106, 107, 108, 110, 111, 114, 118, 119, 129, 140, 141, 200, 201, 202, 322, 324, 325, 330 | Microsoft Windows |
wmi
| Field | Data Type | Event IDs | Example |
|---|---|---|---|
| EventID | integer | 5857, 5858, 5859, 5860, 5861 | 5861 |
| Name | string | 5857, 5858, 5859, 5860, 5861 | Microsoft-Windows-WMI-Activity |
| ProcessName | string | 5858, 5860 | 'wsmprovhost.exe' |
| AND_TargetInstance_Minute | integer | 5859, 5861 | 33 |
| AND_TargetInstance_Second | integer | 5859, 5861 | 0 |
| ActivityID | string | 5857, 5858, 5859, 5860, 5861 | B9A944CA-4FFF-0000-E056-A9B9FF4FD801 |
| Category | integer | 1, 5, 6, 8 | 0 |
| CommandLineEventConsumer | string | 1, 5, 6, 8 | AtomicRedTeam-WMIPersistence-Example |
| CommandLineTemplate | string | 1, 5, 6, 8 | C:\Windows\System32\notepad.exe |
| CreatorSID | string | 1, 5, 6, 8 | {1, 2, 0, 0, 0, 0, 0, 5, 32, 0, 0, 0, 32, 2, 0, 0} |
| EventCode | integer | 5857, 5858, 5859, 5860, 5861 | 5861 |
| EventNamespace | string | 1, 5, 6, 8 | root\cimv2 |
| Guid | string | 5857, 5858, 5859, 5860, 5861 | 1418EF04-B0B4-4623-BF7E-D74AB47BBDAA |
| NTEventLogEventConsumer | string | 1, 5, 6, 8 | SCM Event Log Consumer |
| NameOfUserSIDProperty | string | 1, 5, 6, 8 | sid |
| OR_TargetInstance_DayOfWeek | integer | 5859, 5861 | 2 |
| ProcessID | integer | 5857, 5858, 5859, 5860, 5861 | 4168 |
| ProcessId | integer | 5857, 5858, 5859, 5860, 5861 | 4168 |
| Query | string | 1, 5, 6, 8 | select * from MSFT_SCMEventLogEvent |
| QueryLanguage | string | 1, 5, 6, 8 | WQL |
| RunInteractively | string | 1, 5, 6, 8 | FALSE |
| SigmaEventCode | integer | 5857, 5858, 5859, 5860, 5861 | 5861 |
| SourceName | string | 1, 5, 6, 8 | Service Control Manager |
| SystemTime | string | 5857, 5858, 5859, 5860, 5861 | '2022-07-05 18:43:00.611527 UTC' |
| TargetInstance_DayOfWeek | integer | 5859, 5861 | 1 |
| TargetInstance_Hour | integer | 5859, 5861 | 11 |
| TargetInstance_Minute | integer | 5859, 5861 | 30 |
| TargetInstance_Second | integer | 1, 5, 6, 8 | 40 |
| TargetInstance_Second | string | 5, 5, 8, 9 | 40 |
| ThreadID | integer | 5857, 5858, 5859, 5860, 5861 | 9020 |
| UserID | string | 5857, 5858, 5859, 5860, 5861 | S-1-5-18 |
| sigma_product | string | 5857, 5858, 5859, 5860, 5861 | windows |
| sigma_service | string | 5857, 5858, 5859, 5860, 5861 | wmi |
| timeendpos | integer | 5857, 5858, 5859, 5860, 5861 | 518 |
| timestartpos | integer | 5857, 5858, 5859, 5860, 5861 | 488 |
| xmlns | string | 5857, 5858, 5859, 5860, 5861 | http://schemas.microsoft.com/win/2004/08/events/event |