Loading...
Timelines

Certighost (CVE-2026-54121)

242 02.08.2026 21:28
Clear Filter
Matched Events: 85 / Total Events: 85
2026-08-02 19:45:05

Special privileges assigned to new logon (4672 "Security")

DC.socpedia.net
DC$
Privileges
SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege SeEnableDelegationPrivilege
Subject: Security ID
S-1-5-18
Subject: Account Name
DC$
Subject: Account Domain
SOCPEDIA
Subject: Logon ID
0xc74d4f2
Privileges
SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege SeEnableDelegationPrivilege
Computer
DC.socpedia.net
ProcessID
848
ThreadID
7696
2026-08-02 19:45:05

An account was successfully logged on (4624 "Security")

DC.socpedia.net
DC$
Network Information: Source Network Address
::1
Subject: Security ID
S-1-0-0
Subject: Account Name
-
Subject: Account Domain
-
Subject: Logon ID
0x0
Logon Information: Logon Type
3
Logon Information: Restricted Admin Mode
-
Logon Information: Remote Credential Guard
-
ImpersonationLevel
%%1833
New Logon: Security ID
S-1-5-18
New Logon: Account Name
DC$
New Logon: Account Domain
SOCPEDIA.NET
New Logon: Logon ID
0xc74d4f2
Account Information: Logon GUID
{8d0578f3-4885-5887-c50a-7800ad89f1fc}
Process Information: Process ID
0x0
Process Information: Process Name
-
Network Information: Workstation Name
-
Network Information: Source Network Address
::1
Network Information: Client Port
53459
Detailed Authentication Information: Logon Process
Kerberos
Detailed Authentication Information: Authentication Package
Kerberos
Computer
DC.socpedia.net
ProcessID
848
ThreadID
7696
2026-08-02 19:45:05

Group membership information (4627 "Security")

DC.socpedia.net
DC$
GroupMembership
%{S-1-5-32-544} %{S-1-1-0} %{S-1-5-32-545} %{S-1-5-32-554} %{S-1-5-32-560} %{S-1-5-2} %{S-1-5-11} %{S-1-5-15} %{S-1-5-21-1838030176-2987033226-1986555923-1000} %{S-1-5-21-1838030176-2987033226-1986555923-516} %{S-1-5-9} %{S-1-18-1} %{S-1-5-21-1838030176-2987033226-1986555923-572} %{S-1-16-16384}
Subject: Security ID
S-1-0-0
Subject: Account Name
-
Subject: Account Domain
-
Subject: Logon ID
0x0
Logon Type
3
New Logon: Security ID
S-1-5-18
New Logon: Account Name
DC$
New Logon: Account Domain
SOCPEDIA.NET
New Logon: Logon ID
0xc74d4f2
GroupMembership
%{S-1-5-32-544} %{S-1-1-0} %{S-1-5-32-545} %{S-1-5-32-554} %{S-1-5-32-560} %{S-1-5-2} %{S-1-5-11} %{S-1-5-15} %{S-1-5-21-1838030176-2987033226-1986555923-1000} %{S-1-5-21-1838030176-2987033226-1986555923-516} %{S-1-5-9} %{S-1-18-1} %{S-1-5-21-1838030176-2987033226-1986555923-572} %{S-1-16-16384}
Computer
DC.socpedia.net
ProcessID
848
ThreadID
7696
2026-08-02 19:45:05

An account was logged off (4634 "Security")

DC.socpedia.net
DC$
Logon Type
3
Subject: Security ID
S-1-5-18
Subject: Account Name
DC$
Subject: Account Domain
SOCPEDIA
Subject: Logon ID
0xc74d4f2
Logon Type
3
Computer
DC.socpedia.net
ProcessID
848
ThreadID
5368
2026-08-02 19:45:54

Network security: Restrict NTLM: Audit Incoming NTLM Traffic (8002 "Microsoft-Windows-NTLM/Operational")

DC.socpedia.net
DC$
Calling process name
C:\Windows\System32\lsass.exe
Calling process name
C:\Windows\System32\lsass.exe
PID
848
Calling process user identity
DC$
Calling process domain identity
SOCPEDIA
Mechanism
1.3.6.1.4.1.311.2.2.10
Computer
DC.socpedia.net
ProcessID
848
ThreadID
7696
2026-08-02 19:45:54

Group membership information (4627 "Security")

DC.socpedia.net
user01
GroupMembership
%{S-1-5-21-1838030176-2987033226-1986555923-513} %{S-1-1-0} %{S-1-5-32-545} %{S-1-5-32-554} %{S-1-5-2} %{S-1-5-11} %{S-1-5-15} %{S-1-5-64-10} %{S-1-16-8448}
Subject: Security ID
S-1-0-0
Subject: Account Name
-
Subject: Account Domain
-
Subject: Logon ID
0x0
Logon Type
3
New Logon: Security ID
S-1-5-21-1838030176-2987033226-1986555923-1105
New Logon: Account Name
user01
New Logon: Account Domain
SOCPEDIA
New Logon: Logon ID
0xc74d8c5
GroupMembership
%{S-1-5-21-1838030176-2987033226-1986555923-513} %{S-1-1-0} %{S-1-5-32-545} %{S-1-5-32-554} %{S-1-5-2} %{S-1-5-11} %{S-1-5-15} %{S-1-5-64-10} %{S-1-16-8448}
Computer
DC.socpedia.net
ProcessID
848
ThreadID
7696
2026-08-02 19:45:54

The computer attempted to validate the credentials for an account (4776 "Security")

DC.socpedia.net
user01
Error Code
0x0
Authentication Package
MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon Account
user01
Error Code
0x0
Computer
DC.socpedia.net
ProcessID
848
ThreadID
7696
2026-08-02 19:45:54

An account was successfully logged on (4624 "Security")

DC.socpedia.net
user01
Network Information: Source Network Address
192.168.0.237
Subject: Security ID
S-1-0-0
Subject: Account Name
-
Subject: Account Domain
-
Subject: Logon ID
0x0
Logon Information: Logon Type
3
Logon Information: Restricted Admin Mode
-
Logon Information: Remote Credential Guard
-
ImpersonationLevel
%%1833
New Logon: Security ID
S-1-5-21-1838030176-2987033226-1986555923-1105
New Logon: Account Name
user01
New Logon: Account Domain
SOCPEDIA
New Logon: Logon ID
0xc74d8c5
Account Information: Logon GUID
{00000000-0000-0000-0000-000000000000}
Process Information: Process ID
0x0
Process Information: Process Name
-
Network Information: Workstation Name
-
Network Information: Source Network Address
192.168.0.237
Network Information: Client Port
37158
Detailed Authentication Information: Logon Process
NtLmSsp
Detailed Authentication Information: Authentication Package
NTLM
Computer
DC.socpedia.net
ProcessID
848
ThreadID
7696
2026-08-02 19:45:54

Network security: Restrict NTLM: Audit Incoming NTLM Traffic (8002 "Microsoft-Windows-NTLM/Operational")

DC.socpedia.net
DC$
Calling process name
PID
4
Calling process user identity
DC$
Calling process domain identity
SOCPEDIA
Mechanism
1.3.6.1.4.1.311.2.2.10
Computer
DC.socpedia.net
ProcessID
848
ThreadID
6296
2026-08-02 19:45:54

The computer attempted to validate the credentials for an account (4776 "Security")

DC.socpedia.net
user01
Error Code
0x0
Authentication Package
MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon Account
user01
Error Code
0x0
Computer
DC.socpedia.net
ProcessID
848
ThreadID
6296
2026-08-02 19:45:54

An account was successfully logged on (4624 "Security")

DC.socpedia.net
user01
Network Information: Source Network Address
192.168.0.237
Subject: Security ID
S-1-0-0
Subject: Account Name
-
Subject: Account Domain
-
Subject: Logon ID
0x0
Logon Information: Logon Type
3
Logon Information: Restricted Admin Mode
-
Logon Information: Remote Credential Guard
-
ImpersonationLevel
%%1833
New Logon: Security ID
S-1-5-21-1838030176-2987033226-1986555923-1105
New Logon: Account Name
user01
New Logon: Account Domain
SOCPEDIA
New Logon: Logon ID
0xc74d988
Account Information: Logon GUID
{00000000-0000-0000-0000-000000000000}
Process Information: Process ID
0x0
Process Information: Process Name
-
Network Information: Workstation Name
-
Network Information: Source Network Address
192.168.0.237
Network Information: Client Port
56970
Detailed Authentication Information: Logon Process
NtLmSsp
Detailed Authentication Information: Authentication Package
NTLM
Computer
DC.socpedia.net
ProcessID
848
ThreadID
6296
2026-08-02 19:45:54

Group membership information (4627 "Security")

DC.socpedia.net
user01
GroupMembership
%{S-1-5-21-1838030176-2987033226-1986555923-513} %{S-1-1-0} %{S-1-5-32-545} %{S-1-5-32-554} %{S-1-5-2} %{S-1-5-11} %{S-1-5-15} %{S-1-5-64-10} %{S-1-16-8448}
Subject: Security ID
S-1-0-0
Subject: Account Name
-
Subject: Account Domain
-
Subject: Logon ID
0x0
Logon Type
3
New Logon: Security ID
S-1-5-21-1838030176-2987033226-1986555923-1105
New Logon: Account Name
user01
New Logon: Account Domain
SOCPEDIA
New Logon: Logon ID
0xc74d988
GroupMembership
%{S-1-5-21-1838030176-2987033226-1986555923-513} %{S-1-1-0} %{S-1-5-32-545} %{S-1-5-32-554} %{S-1-5-2} %{S-1-5-11} %{S-1-5-15} %{S-1-5-64-10} %{S-1-16-8448}
Computer
DC.socpedia.net
ProcessID
848
ThreadID
6296
2026-08-02 19:45:54

A network share object was accessed (5140 "Security")

DC.socpedia.net
user01
Network Information: Source Network Address
192.168.0.237
Subject: Security ID
S-1-5-21-1838030176-2987033226-1986555923-1105
Subject: Account Name
user01
Subject: Account Domain
SOCPEDIA
Subject: Logon ID
0xc74d988
Network Information: Object Type
File
Network Information: Source Network Address
192.168.0.237
Network Information: Client Port
56970
Share Information: Share Name
\\*\IPC$
Access Request Information: Access Mask
0x1
Access Request Information: Accesses
%%4416
Computer
DC.socpedia.net
ProcessID
4
ThreadID
10732
2026-08-02 19:45:54

A computer account was created (4741 "Security")

DC.socpedia.net
user01
New Computer Account: Account Name
GHOSTPYUVHAOB$
Subject: Security ID
S-1-5-21-1838030176-2987033226-1986555923-1105
Subject: Account Name
user01
Subject: Account Domain
SOCPEDIA
Subject: Logon ID
0xc74d988
New Computer Account: Security ID
S-1-5-21-1838030176-2987033226-1986555923-1116
New Computer Account: Account Name
GHOSTPYUVHAOB$
New Computer Account: Account Domain
SOCPEDIA
Attributes: SAM Account Name
GHOSTPYUVHAOB$
Attributes: Display Name
%%1793
Attributes: User Principal Name
-
Attributes: Home Directory
%%1793
Attributes: Home Drive
%%1793
Attributes: Script Path
%%1793
Attributes: Profile Path
%%1793
Attributes: User Workstations
%%1793
Attributes: Password Last Set
%%1794
Attributes: Account Expires
%%1794
Attributes: Primary Group ID
515
Attributes: AllowedToDelegateTo
-
Attributes: Old UAC Value
0x0
Attributes: New UAC Value
0x84
Attributes: User Account Control
%%2082 %%2087
Attributes: User Parameters
%%1792
Attributes: SID History
-
Attributes: Logon Hours
%%1793
Attributes: DNS Host Name
-
Attributes: Service Principal Names
-
Additional Information: Privileges
SeMachineAccountPrivilege
Computer
DC.socpedia.net
ProcessID
848
ThreadID
6296
2026-08-02 19:45:54

An attempt was made to reset an account's password (4724 "Security")

DC.socpedia.net
GHOSTPYUVHAOB$
Subject: Account Name
user01
Subject: Security ID
S-1-5-21-1838030176-2987033226-1986555923-1105
Subject: Account Name
user01
Subject: Account Domain
SOCPEDIA
Subject: Logon ID
0xc74d988
Target Account: Security ID
S-1-5-21-1838030176-2987033226-1986555923-1116
Target Account: Account Name
GHOSTPYUVHAOB$
Target Account: Account Domain
SOCPEDIA
Computer
DC.socpedia.net
ProcessID
848
ThreadID
6296
2026-08-02 19:45:54

A computer account was changed (4742 "Security")

DC.socpedia.net
GHOSTPYUVHAOB$
Subject: Account Name
user01
Subject: Security ID
S-1-5-21-1838030176-2987033226-1986555923-1105
Subject: Account Name
user01
Subject: Account Domain
SOCPEDIA
Subject: Logon ID
0xc74d988
Computer Account That Was Changed: Security ID
S-1-5-21-1838030176-2987033226-1986555923-1116
Computer Account That Was Changed: Account Name
GHOSTPYUVHAOB$
Computer Account That Was Changed: Account Domain
SOCPEDIA
Changed Attributes: SAM Account Name
-
Changed Attributes: Display Name
-
Changed Attributes: User Principal Name
-
Changed Attributes: Home Directory
-
Changed Attributes: Home Drive
-
Changed Attributes: Script Path
-
Changed Attributes: Profile Path
-
Changed Attributes: User Workstations
-
Changed Attributes: Password Last Set
-
Changed Attributes: Account Expires
-
Changed Attributes: Primary Group ID
-
Changed Attributes: AllowedToDelegateTo
-
Changed Attributes: Old UAC Value
-
Changed Attributes: New UAC Value
-
Changed Attributes: User Account Control
-
Changed Attributes: User Parameters
-
Changed Attributes: SID History
-
Changed Attributes: Logon Hours
-
Changed Attributes: DNS Host Name
-
Changed Attributes: Service Principal Names
-
Additional Information: Privileges
-
Computer
DC.socpedia.net
ProcessID
848
ThreadID
6296
2026-08-02 19:45:55

An account was logged off (4634 "Security")

DC.socpedia.net
user01
Logon Type
3
Subject: Security ID
S-1-5-21-1838030176-2987033226-1986555923-1105
Subject: Account Name
user01
Subject: Account Domain
SOCPEDIA
Subject: Logon ID
0xc74d988
Logon Type
3
Computer
DC.socpedia.net
ProcessID
848
ThreadID
6296
2026-08-02 19:45:55

Decrypt call failed (1015 "Microsoft-Windows-SMBServer/Security")

DC.socpedia.net
Client Address
Client Name
\
Computer
DC.socpedia.net
ProcessID
4
ThreadID
10172
2026-08-02 19:45:56

Network security: Restrict NTLM: Audit Incoming NTLM Traffic (8002 "Microsoft-Windows-NTLM/Operational")

ADCS.socpedia.net
ADCS$
Calling process name
PID
4
Calling process user identity
ADCS$
Calling process domain identity
SOCPEDIA
Mechanism
1.3.6.1.4.1.311.2.2.10
Computer
ADCS.socpedia.net
ProcessID
832
ThreadID
896
2026-08-02 19:45:56

Group membership information (4627 "Security")

DC.socpedia.net
ADCS$
GroupMembership
%{S-1-5-21-1838030176-2987033226-1986555923-515} %{S-1-1-0} %{S-1-5-32-554} %{S-1-5-32-545} %{S-1-5-2} %{S-1-5-11} %{S-1-5-15} %{S-1-18-1} %{S-1-5-21-1838030176-2987033226-1986555923-517} %{S-1-5-21-1838030176-2987033226-1986555923-572} %{S-1-16-8448}
Subject: Security ID
S-1-0-0
Subject: Account Name
-
Subject: Account Domain
-
Subject: Logon ID
0x0
Logon Type
3
New Logon: Security ID
S-1-5-21-1838030176-2987033226-1986555923-1106
New Logon: Account Name
ADCS$
New Logon: Account Domain
SOCPEDIA.NET
New Logon: Logon ID
0xc74da4b
GroupMembership
%{S-1-5-21-1838030176-2987033226-1986555923-515} %{S-1-1-0} %{S-1-5-32-554} %{S-1-5-32-545} %{S-1-5-2} %{S-1-5-11} %{S-1-5-15} %{S-1-18-1} %{S-1-5-21-1838030176-2987033226-1986555923-517} %{S-1-5-21-1838030176-2987033226-1986555923-572} %{S-1-16-8448}
Computer
DC.socpedia.net
ProcessID
848
ThreadID
5368
2026-08-02 19:45:56

An account was successfully logged on (4624 "Security")

DC.socpedia.net
ADCS$
Network Information: Source Network Address
192.168.0.211
Subject: Security ID
S-1-0-0
Subject: Account Name
-
Subject: Account Domain
-
Subject: Logon ID
0x0
Logon Information: Logon Type
3
Logon Information: Restricted Admin Mode
-
Logon Information: Remote Credential Guard
-
ImpersonationLevel
%%1833
New Logon: Security ID
S-1-5-21-1838030176-2987033226-1986555923-1106
New Logon: Account Name
ADCS$
New Logon: Account Domain
SOCPEDIA.NET
New Logon: Logon ID
0xc74da4b
Account Information: Logon GUID
{b4a346ad-1a84-6be2-f2f5-0935bfd74f85}
Process Information: Process ID
0x0
Process Information: Process Name
-
Network Information: Workstation Name
-
Network Information: Source Network Address
192.168.0.211
Network Information: Client Port
54088
Detailed Authentication Information: Logon Process
Kerberos
Detailed Authentication Information: Authentication Package
Kerberos
Computer
DC.socpedia.net
ProcessID
848
ThreadID
5368
2026-08-02 19:45:56

The computer attempted to validate the credentials for an account (4776 "Security")

DC.socpedia.net
GHOSTPYUVHAOB$
Error Code
0x0
Authentication Package
MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon Account
GHOSTPYUVHAOB$
Error Code
0x0
Computer
DC.socpedia.net
ProcessID
848
ThreadID
5368
2026-08-02 19:45:56

Domain Controller Blocked Audit: Audit NTLM authentication to this domain controller (8004 "Microsoft-Windows-NTLM/Operational")

DC.socpedia.net
GHOSTPYUVHAOB$
User
GHOSTPYUVHAOB$
Domain
socpedia.net
Computer
DC.socpedia.net
ProcessID
848
ThreadID
5368
2026-08-02 19:45:56

NTLM server blocked in the domain audit: Audit NTLM authentication in this domain (8003 "Microsoft-Windows-NTLM/Operational")

ADCS.socpedia.net
GHOSTPYUVHAOB$
Process
User
GHOSTPYUVHAOB$
Domain
socpedia.net
Workstation
(NULL)
PID
4
Logon type
3
Mechanism
(NULL)
Computer
ADCS.socpedia.net
ProcessID
832
ThreadID
896
2026-08-02 19:45:56

An account was successfully logged on (4624 "Security")

ADCS.socpedia.net
GHOSTPYUVHAOB$
Network Information: Source Network Address
192.168.0.237
Subject: Security ID
S-1-0-0
Subject: Account Name
-
Subject: Account Domain
-
Subject: Logon ID
0x0
Logon Information: Logon Type
3
Logon Information: Restricted Admin Mode
-
Logon Information: Remote Credential Guard
-
ImpersonationLevel
%%1833
New Logon: Security ID
S-1-5-21-1838030176-2987033226-1986555923-1116
New Logon: Account Name
GHOSTPYUVHAOB$
New Logon: Account Domain
SOCPEDIA
New Logon: Logon ID
0xb4a8aaa
Account Information: Logon GUID
{00000000-0000-0000-0000-000000000000}
Process Information: Process ID
0x0
Process Information: Process Name
-
Network Information: Workstation Name
-
Network Information: Source Network Address
192.168.0.237
Network Information: Client Port
44622
Detailed Authentication Information: Logon Process
NtLmSsp
Detailed Authentication Information: Authentication Package
NTLM
Computer
ADCS.socpedia.net
ProcessID
832
ThreadID
896
2026-08-02 19:45:56

Group membership information (4627 "Security")

ADCS.socpedia.net
GHOSTPYUVHAOB$
GroupMembership
%{S-1-5-21-1838030176-2987033226-1986555923-515} %{S-1-1-0} %{S-1-5-32-545} %{S-1-5-32-574} %{S-1-5-2} %{S-1-5-11} %{S-1-5-15} %{S-1-5-64-10} %{S-1-16-8192}
Subject: Security ID
S-1-0-0
Subject: Account Name
-
Subject: Account Domain
-
Subject: Logon ID
0x0
Logon Type
3
New Logon: Security ID
S-1-5-21-1838030176-2987033226-1986555923-1116
New Logon: Account Name
GHOSTPYUVHAOB$
New Logon: Account Domain
SOCPEDIA
New Logon: Logon ID
0xb4a8aaa
GroupMembership
%{S-1-5-21-1838030176-2987033226-1986555923-515} %{S-1-1-0} %{S-1-5-32-545} %{S-1-5-32-574} %{S-1-5-2} %{S-1-5-11} %{S-1-5-15} %{S-1-5-64-10} %{S-1-16-8192}
Computer
ADCS.socpedia.net
ProcessID
832
ThreadID
896
2026-08-02 19:45:56

A network share object was accessed (5140 "Security")

ADCS.socpedia.net
GHOSTPYUVHAOB$
Network Information: Source Network Address
192.168.0.237
Subject: Security ID
S-1-5-21-1838030176-2987033226-1986555923-1116
Subject: Account Name
GHOSTPYUVHAOB$
Subject: Account Domain
SOCPEDIA
Subject: Logon ID
0xb4a8aaa
Network Information: Object Type
File
Network Information: Source Network Address
192.168.0.237
Network Information: Client Port
44622
Share Information: Share Name
\\*\IPC$
Access Request Information: Access Mask
0x1
Access Request Information: Accesses
%%4416
Computer
ADCS.socpedia.net
ProcessID
4
ThreadID
9100
2026-08-02 19:45:56

Pipe Connected (18 "Microsoft-Windows-Sysmon/Operational")

ADCS.socpedia.net
NT AUTHORITY\SYSTEM
PipeName
\cert
RuleName
v2-6_eventID17,18
EventType
ConnectPipe
ProcessGuid
{e4c645e2-94a9-6a67-eb03-000000000000}
ProcessId
4
PipeName
\cert
Image
System
User
NT AUTHORITY\SYSTEM
Computer
ADCS.socpedia.net
ProcessID
6656
ThreadID
7772
2026-08-02 19:45:56

Network security: Restrict NTLM: Audit Incoming NTLM Traffic (8002 "Microsoft-Windows-NTLM/Operational")

ADCS.socpedia.net
ADCS$
Calling process name
C:\Windows\System32\certsrv.exe
Calling process name
C:\Windows\System32\certsrv.exe
PID
6396
Calling process user identity
ADCS$
Calling process domain identity
SOCPEDIA
Mechanism
(NULL)
Computer
ADCS.socpedia.net
ProcessID
832
ThreadID
896
2026-08-02 19:45:56

The computer attempted to validate the credentials for an account (4776 "Security")

DC.socpedia.net
GHOSTPYUVHAOB$
Error Code
0x0
Authentication Package
MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon Account
GHOSTPYUVHAOB$
Error Code
0x0
Computer
DC.socpedia.net
ProcessID
848
ThreadID
5368
2026-08-02 19:45:56

Domain Controller Blocked Audit: Audit NTLM authentication to this domain controller (8004 "Microsoft-Windows-NTLM/Operational")

DC.socpedia.net
GHOSTPYUVHAOB$
User
GHOSTPYUVHAOB$
Domain
socpedia.net
Computer
DC.socpedia.net
ProcessID
848
ThreadID
5368
2026-08-02 19:45:56

NTLM server blocked in the domain audit: Audit NTLM authentication in this domain (8003 "Microsoft-Windows-NTLM/Operational")

ADCS.socpedia.net
GHOSTPYUVHAOB$
Process
C:\Windows\System32\certsrv.exe
User
GHOSTPYUVHAOB$
Domain
socpedia.net
Workstation
(NULL)
PID
6396
Process
C:\Windows\System32\certsrv.exe
Logon type
3
Mechanism
(NULL)
Computer
ADCS.socpedia.net
ProcessID
832
ThreadID
896
2026-08-02 19:45:56

Group membership information (4627 "Security")

ADCS.socpedia.net
GHOSTPYUVHAOB$
GroupMembership
%{S-1-5-21-1838030176-2987033226-1986555923-515} %{S-1-1-0} %{S-1-5-32-545} %{S-1-5-32-574} %{S-1-5-2} %{S-1-5-11} %{S-1-5-15} %{S-1-5-64-10} %{S-1-16-8192}
Subject: Security ID
S-1-0-0
Subject: Account Name
-
Subject: Account Domain
-
Subject: Logon ID
0x0
Logon Type
3
New Logon: Security ID
S-1-5-21-1838030176-2987033226-1986555923-1116
New Logon: Account Name
GHOSTPYUVHAOB$
New Logon: Account Domain
SOCPEDIA
New Logon: Logon ID
0xb4a8b6e
GroupMembership
%{S-1-5-21-1838030176-2987033226-1986555923-515} %{S-1-1-0} %{S-1-5-32-545} %{S-1-5-32-574} %{S-1-5-2} %{S-1-5-11} %{S-1-5-15} %{S-1-5-64-10} %{S-1-16-8192}
Computer
ADCS.socpedia.net
ProcessID
832
ThreadID
896
2026-08-02 19:45:56

An account was successfully logged on (4624 "Security")

ADCS.socpedia.net
GHOSTPYUVHAOB$
Network Information: Source Network Address
-
Subject: Security ID
S-1-0-0
Subject: Account Name
-
Subject: Account Domain
-
Subject: Logon ID
0x0
Logon Information: Logon Type
3
Logon Information: Restricted Admin Mode
-
Logon Information: Remote Credential Guard
-
ImpersonationLevel
%%1833
New Logon: Security ID
S-1-5-21-1838030176-2987033226-1986555923-1116
New Logon: Account Name
GHOSTPYUVHAOB$
New Logon: Account Domain
SOCPEDIA
New Logon: Logon ID
0xb4a8b6e
Account Information: Logon GUID
{00000000-0000-0000-0000-000000000000}
Process Information: Process ID
0x0
Process Information: Process Name
-
Network Information: Workstation Name
-
Network Information: Source Network Address
-
Network Information: Client Port
-
Detailed Authentication Information: Logon Process
NtLmSsp
Detailed Authentication Information: Authentication Package
NTLM
Computer
ADCS.socpedia.net
ProcessID
832
ThreadID
896
2026-08-02 19:45:56

A Kerberos service ticket was requested (4769 "Security")

DC.socpedia.net
ADCS$@SOCPEDIA.NET
Network Information: Client Address
::ffff:192.168.0.211
Account Information: Account Name
ADCS$@SOCPEDIA.NET
Account Information: Account Domain
SOCPEDIA.NET
Account Information: Logon GUID
{599f1e34-b452-ebc9-20e3-4a954ba452ea}
Service Information: Service Name
ADCS$
Service Information: Service ID
S-1-5-21-1838030176-2987033226-1986555923-1106
Network Information: Client Address
::ffff:192.168.0.211
Network Information: Source Port
54090
Additional Information: Ticket Options
0x40810000
Additional Information: Ticket Encryption Type
0x12
Additional Information: Failure Code
0x0
Additional Information: Transited Services
-
Ticket information: Request ticket hash
eOpCIeup+9yoZOnJ1eUOVEO0ub+WKGZ4bMAadpu+BSc=
Ticket information: Response ticket hash
hPniGjBOxXH5psn0CWnnqSl2z8jOWw/JGPjhrBq4UoE=
Computer
DC.socpedia.net
ProcessID
848
ThreadID
3840
2026-08-02 19:45:56

Attempt to get credential key by call package blocked by Credential Guard (4014 "Microsoft-Windows-NTLM/Operational")

ADCS.socpedia.net
Calling Process Name
lsass
Calling Process Name
lsass
Computer
ADCS.socpedia.net
ProcessID
832
ThreadID
896
2026-08-02 19:45:56

Network security: Restrict NTLM: Audit Incoming NTLM Traffic (8002 "Microsoft-Windows-NTLM/Operational")

DC.socpedia.net
DC$
Calling process name
C:\Windows\System32\lsass.exe
Calling process name
C:\Windows\System32\lsass.exe
PID
848
Calling process user identity
DC$
Calling process domain identity
SOCPEDIA
Mechanism
(NULL)
Computer
DC.socpedia.net
ProcessID
848
ThreadID
6296
2026-08-02 19:45:56

Attempt to get credential key by call package blocked by Credential Guard (4014 "Microsoft-Windows-NTLM/Operational")

ADCS.socpedia.net
Calling Process Name
lsass
Calling Process Name
lsass
Computer
ADCS.socpedia.net
ProcessID
832
ThreadID
896
2026-08-02 19:45:56

Group membership information (4627 "Security")

DC.socpedia.net
ANONYMOUS LOGON
GroupMembership
%{S-1-0-0} %{S-1-5-2} %{S-1-5-15} %{S-1-5-64-10} %{S-1-16-0}
Subject: Security ID
S-1-0-0
Subject: Account Name
-
Subject: Account Domain
-
Subject: Logon ID
0x0
Logon Type
3
New Logon: Security ID
S-1-5-7
New Logon: Account Name
ANONYMOUS LOGON
New Logon: Account Domain
NT AUTHORITY
New Logon: Logon ID
0xc74da7a
GroupMembership
%{S-1-0-0} %{S-1-5-2} %{S-1-5-15} %{S-1-5-64-10} %{S-1-16-0}
Computer
DC.socpedia.net
ProcessID
848
ThreadID
6296
2026-08-02 19:45:56

An account was successfully logged on (4624 "Security")

DC.socpedia.net
ANONYMOUS LOGON
Network Information: Source Network Address
192.168.0.211
Subject: Security ID
S-1-0-0
Subject: Account Name
-
Subject: Account Domain
-
Subject: Logon ID
0x0
Logon Information: Logon Type
3
Logon Information: Restricted Admin Mode
-
Logon Information: Remote Credential Guard
-
ImpersonationLevel
%%1833
New Logon: Security ID
S-1-5-7
New Logon: Account Name
ANONYMOUS LOGON
New Logon: Account Domain
NT AUTHORITY
New Logon: Logon ID
0xc74da7a
Account Information: Logon GUID
{00000000-0000-0000-0000-000000000000}
Process Information: Process ID
0x0
Process Information: Process Name
-
Network Information: Workstation Name
ADCS
Network Information: Source Network Address
192.168.0.211
Network Information: Client Port
54089
Detailed Authentication Information: Logon Process
NtLmSsp
Detailed Authentication Information: Authentication Package
NTLM
Computer
DC.socpedia.net
ProcessID
848
ThreadID
6296
2026-08-02 19:45:56

An account was logged off (4634 "Security")

DC.socpedia.net
ANONYMOUS LOGON
Logon Type
3
Subject: Security ID
S-1-5-7
Subject: Account Name
ANONYMOUS LOGON
Subject: Account Domain
NT AUTHORITY
Subject: Logon ID
0xc74da7a
Logon Type
3
Computer
DC.socpedia.net
ProcessID
848
ThreadID
6296
2026-08-02 19:45:56

Group membership information (4627 "Security")

DC.socpedia.net
ADCS$
GroupMembership
%{S-1-5-21-1838030176-2987033226-1986555923-515} %{S-1-1-0} %{S-1-5-32-554} %{S-1-5-32-545} %{S-1-5-2} %{S-1-5-11} %{S-1-5-15} %{S-1-18-1} %{S-1-5-21-1838030176-2987033226-1986555923-517} %{S-1-5-21-1838030176-2987033226-1986555923-572} %{S-1-16-8448}
Subject: Security ID
S-1-0-0
Subject: Account Name
-
Subject: Account Domain
-
Subject: Logon ID
0x0
Logon Type
3
New Logon: Security ID
S-1-5-21-1838030176-2987033226-1986555923-1106
New Logon: Account Name
ADCS$
New Logon: Account Domain
SOCPEDIA.NET
New Logon: Logon ID
0xc74da99
GroupMembership
%{S-1-5-21-1838030176-2987033226-1986555923-515} %{S-1-1-0} %{S-1-5-32-554} %{S-1-5-32-545} %{S-1-5-2} %{S-1-5-11} %{S-1-5-15} %{S-1-18-1} %{S-1-5-21-1838030176-2987033226-1986555923-517} %{S-1-5-21-1838030176-2987033226-1986555923-572} %{S-1-16-8448}
Computer
DC.socpedia.net
ProcessID
848
ThreadID
5368
2026-08-02 19:45:56

An account was successfully logged on (4624 "Security")

DC.socpedia.net
ADCS$
Network Information: Source Network Address
192.168.0.211
Subject: Security ID
S-1-0-0
Subject: Account Name
-
Subject: Account Domain
-
Subject: Logon ID
0x0
Logon Information: Logon Type
3
Logon Information: Restricted Admin Mode
-
Logon Information: Remote Credential Guard
-
ImpersonationLevel
%%1833
New Logon: Security ID
S-1-5-21-1838030176-2987033226-1986555923-1106
New Logon: Account Name
ADCS$
New Logon: Account Domain
SOCPEDIA.NET
New Logon: Logon ID
0xc74da99
Account Information: Logon GUID
{b5a4343f-c5a2-c57d-6f5e-abaa73ceda85}
Process Information: Process ID
0x0
Process Information: Process Name
-
Network Information: Workstation Name
-
Network Information: Source Network Address
192.168.0.211
Network Information: Client Port
54092
Detailed Authentication Information: Logon Process
Kerberos
Detailed Authentication Information: Authentication Package
Kerberos
Computer
DC.socpedia.net
ProcessID
848
ThreadID
5368
2026-08-02 19:45:56

Certificate Services received a certificate request (4886 "Security")

ADCS.socpedia.net
SOCPEDIA\GHOSTPYUVHAOB$
Attributes
CertificateTemplate:Machine SAN:dns=DC.socpedia.net cdc:192.168.0.237 rmd:DC.socpedia.net
Request ID
16
Requester
SOCPEDIA\GHOSTPYUVHAOB$
Attributes
CertificateTemplate:Machine SAN:dns=DC.socpedia.net cdc:192.168.0.237 rmd:DC.socpedia.net
Subject from CSR
CN=GHOSTPYUVHAOB.socpedia.net
SAN from CSR
DNS Name=DC.socpedia.net
Certificate Template
Machine
Authentication Service
NTLM
Authentication Level
Privacy
DCOMorRPC
RPC
Computer
ADCS.socpedia.net
ProcessID
832
ThreadID
896
2026-08-02 19:45:56

Group membership information (4627 "Security")

DC.socpedia.net
ADCS$
GroupMembership
%{S-1-5-21-1838030176-2987033226-1986555923-515} %{S-1-1-0} %{S-1-5-32-554} %{S-1-5-32-545} %{S-1-5-2} %{S-1-5-11} %{S-1-5-15} %{S-1-18-1} %{S-1-5-21-1838030176-2987033226-1986555923-517} %{S-1-5-21-1838030176-2987033226-1986555923-572} %{S-1-16-8448}
Subject: Security ID
S-1-0-0
Subject: Account Name
-
Subject: Account Domain
-
Subject: Logon ID
0x0
Logon Type
3
New Logon: Security ID
S-1-5-21-1838030176-2987033226-1986555923-1106
New Logon: Account Name
ADCS$
New Logon: Account Domain
SOCPEDIA.NET
New Logon: Logon ID
0xc74dab0
GroupMembership
%{S-1-5-21-1838030176-2987033226-1986555923-515} %{S-1-1-0} %{S-1-5-32-554} %{S-1-5-32-545} %{S-1-5-2} %{S-1-5-11} %{S-1-5-15} %{S-1-18-1} %{S-1-5-21-1838030176-2987033226-1986555923-517} %{S-1-5-21-1838030176-2987033226-1986555923-572} %{S-1-16-8448}
Computer
DC.socpedia.net
ProcessID
848
ThreadID
7696
2026-08-02 19:45:56

An account was successfully logged on (4624 "Security")

DC.socpedia.net
ADCS$
Network Information: Source Network Address
192.168.0.211
Subject: Security ID
S-1-0-0
Subject: Account Name
-
Subject: Account Domain
-
Subject: Logon ID
0x0
Logon Information: Logon Type
3
Logon Information: Restricted Admin Mode
-
Logon Information: Remote Credential Guard
-
ImpersonationLevel
%%1833
New Logon: Security ID
S-1-5-21-1838030176-2987033226-1986555923-1106
New Logon: Account Name
ADCS$
New Logon: Account Domain
SOCPEDIA.NET
New Logon: Logon ID
0xc74dab0
Account Information: Logon GUID
{b5a4343f-c5a2-c57d-6f5e-abaa73ceda85}
Process Information: Process ID
0x0
Process Information: Process Name
-
Network Information: Workstation Name
-
Network Information: Source Network Address
192.168.0.211
Network Information: Client Port
54093
Detailed Authentication Information: Logon Process
Kerberos
Detailed Authentication Information: Authentication Package
Kerberos
Computer
DC.socpedia.net
ProcessID
848
ThreadID
7696
2026-08-02 19:45:56

Attempt to get credential key by call package blocked by Credential Guard (4014 "Microsoft-Windows-NTLM/Operational")

ADCS.socpedia.net
Calling Process Name
Computer
ADCS.socpedia.net
ProcessID
832
ThreadID
8252
2026-08-02 19:45:56

Attempt to get credential key by call package blocked by Credential Guard (4014 "Microsoft-Windows-NTLM/Operational")

ADCS.socpedia.net
Calling Process Name
Computer
ADCS.socpedia.net
ProcessID
832
ThreadID
8252
2026-08-02 19:45:56

The SMB redirector selected the connection initiated with the following parameters (30830 "Microsoft-Windows-SmbClient/Connectivity")

ADCS.socpedia.net
Server name
192.168.0.237
Server name
192.168.0.237
Connection Type
1
Remote Address
020001BDC0A800ED0000000000000000
Instance Name
\Device\LanmanRedirector
Port Origin
4
Error Code
0x0
Computer
ADCS.socpedia.net
2026-08-02 19:45:56

Attempt to get credential key by call package blocked by Credential Guard (4014 "Microsoft-Windows-NTLM/Operational")

ADCS.socpedia.net
Calling Process Name
Computer
ADCS.socpedia.net
ProcessID
832
ThreadID
8252
2026-08-02 19:45:56

Attempt to get credential key by call package blocked by Credential Guard (4014 "Microsoft-Windows-NTLM/Operational")

ADCS.socpedia.net
Calling Process Name
Computer
ADCS.socpedia.net
ProcessID
832
ThreadID
8252
2026-08-02 19:45:56

Netlogon Warning (5840 "System")

DC.socpedia.net
GHOSTPYUVHAOB$
param4
192.168.0.237
param1
GHOSTPYUVHAOB$
param2
socpedia.net.
param3
Domain Member
param4
192.168.0.237
param5
600fffff
Computer
DC.socpedia.net
ProcessID
848
2026-08-02 19:45:56

The computer attempted to validate the credentials for an account (4776 "Security")

DC.socpedia.net
ADCS$
Error Code
0x0
Authentication Package
MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon Account
ADCS$
Error Code
0x0
Computer
DC.socpedia.net
ProcessID
848
ThreadID
6296
2026-08-02 19:45:56

Domain Controller Blocked Audit: Audit NTLM authentication to this domain controller (8004 "Microsoft-Windows-NTLM/Operational")

DC.socpedia.net
ADCS$
User
ADCS$
Domain
SOCPEDIA
Computer
DC.socpedia.net
ProcessID
848
ThreadID
6296
2026-08-02 19:45:56

Attempt to get credential key by call package blocked by Credential Guard (4014 "Microsoft-Windows-NTLM/Operational")

ADCS.socpedia.net
Calling Process Name
Computer
ADCS.socpedia.net
ProcessID
832
ThreadID
8252
2026-08-02 19:45:56

Network connection detected: (3 "Microsoft-Windows-Sysmon/Operational")

DC.socpedia.net
SourceIp
192.168.0.237
DestinationHostname
DC.socpedia.net
DestinationIp
192.168.0.210
DestinationIsIpv6
false
DestinationPort
445
DestinationPortName
microsoft-ds
Image
System
Initiated
false
ProcessGuid
{d062d9b1-8c7c-6a67-eb03-000000000000}
ProcessId
4
Protocol
tcp
RuleName
v1-0_eventID3
SourceHostname
-
SourceIp
192.168.0.237
SourceIsIpv6
false
SourcePort
56970
SourcePortName
-
User
NT AUTHORITY\SYSTEM
UtcTime
2026-08-02 14:45:54.765
Computer
DC.socpedia.net
ProcessID
3024
ThreadID
5432
2026-08-02 19:45:56

Network connection detected: (3 "Microsoft-Windows-Sysmon/Operational")

DC.socpedia.net
SourceIp
192.168.0.237
DestinationHostname
DC.socpedia.net
DestinationIp
192.168.0.210
DestinationIsIpv6
false
DestinationPort
135
DestinationPortName
epmap
Image
C:\Windows\System32\svchost.exe
Initiated
false
ProcessGuid
{d062d9b1-8c92-6a67-0e00-000000000400}
ProcessId
424
Protocol
tcp
RuleName
v1-0_eventID3
SourceHostname
-
SourceIp
192.168.0.237
SourceIsIpv6
false
SourcePort
33620
SourcePortName
-
User
NT AUTHORITY\NETWORK SERVICE
UtcTime
2026-08-02 14:45:54.757
Computer
DC.socpedia.net
ProcessID
3024
ThreadID
5432
2026-08-02 19:45:56

Attempt to get credential key by call package blocked by Credential Guard (4014 "Microsoft-Windows-NTLM/Operational")

ADCS.socpedia.net
Calling Process Name
certsrv
Calling Process Name
certsrv
Computer
ADCS.socpedia.net
ProcessID
832
ThreadID
8252
2026-08-02 19:45:56

Attempt to get credential key by call package blocked by Credential Guard (4014 "Microsoft-Windows-NTLM/Operational")

ADCS.socpedia.net
Calling Process Name
certsrv
Calling Process Name
certsrv
Computer
ADCS.socpedia.net
ProcessID
832
ThreadID
8252
2026-08-02 19:45:56

The computer attempted to validate the credentials for an account (4776 "Security")

DC.socpedia.net
ADCS$
Error Code
0x0
Authentication Package
MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon Account
ADCS$
Error Code
0x0
Computer
DC.socpedia.net
ProcessID
848
ThreadID
6296
2026-08-02 19:45:56

Domain Controller Blocked Audit: Audit NTLM authentication to this domain controller (8004 "Microsoft-Windows-NTLM/Operational")

DC.socpedia.net
ADCS$
User
ADCS$
Domain
SOCPEDIA
Computer
DC.socpedia.net
ProcessID
848
ThreadID
6296
2026-08-02 19:45:56

Group membership information (4627 "Security")

DC.socpedia.net
ADCS$
GroupMembership
%{S-1-5-21-1838030176-2987033226-1986555923-515} %{S-1-1-0} %{S-1-5-32-554} %{S-1-5-32-545} %{S-1-5-2} %{S-1-5-11} %{S-1-5-15} %{S-1-18-1} %{S-1-5-21-1838030176-2987033226-1986555923-517} %{S-1-5-21-1838030176-2987033226-1986555923-572} %{S-1-16-8448}
Subject: Security ID
S-1-0-0
Subject: Account Name
-
Subject: Account Domain
-
Subject: Logon ID
0x0
Logon Type
3
New Logon: Security ID
S-1-5-21-1838030176-2987033226-1986555923-1106
New Logon: Account Name
ADCS$
New Logon: Account Domain
SOCPEDIA.NET
New Logon: Logon ID
0xc74df1a
GroupMembership
%{S-1-5-21-1838030176-2987033226-1986555923-515} %{S-1-1-0} %{S-1-5-32-554} %{S-1-5-32-545} %{S-1-5-2} %{S-1-5-11} %{S-1-5-15} %{S-1-18-1} %{S-1-5-21-1838030176-2987033226-1986555923-517} %{S-1-5-21-1838030176-2987033226-1986555923-572} %{S-1-16-8448}
Computer
DC.socpedia.net
ProcessID
848
ThreadID
3840
2026-08-02 19:45:56

An account was successfully logged on (4624 "Security")

DC.socpedia.net
ADCS$
Network Information: Source Network Address
192.168.0.211
Subject: Security ID
S-1-0-0
Subject: Account Name
-
Subject: Account Domain
-
Subject: Logon ID
0x0
Logon Information: Logon Type
3
Logon Information: Restricted Admin Mode
-
Logon Information: Remote Credential Guard
-
ImpersonationLevel
%%1833
New Logon: Security ID
S-1-5-21-1838030176-2987033226-1986555923-1106
New Logon: Account Name
ADCS$
New Logon: Account Domain
SOCPEDIA.NET
New Logon: Logon ID
0xc74df1a
Account Information: Logon GUID
{b5a4343f-c5a2-c57d-6f5e-abaa73ceda85}
Process Information: Process ID
0x0
Process Information: Process Name
-
Network Information: Workstation Name
-
Network Information: Source Network Address
192.168.0.211
Network Information: Client Port
54096
Detailed Authentication Information: Logon Process
Kerberos
Detailed Authentication Information: Authentication Package
Kerberos
Computer
DC.socpedia.net
ProcessID
848
ThreadID
3840
2026-08-02 19:45:56

A Kerberos authentication ticket (TGT) was requested (4768 "Security")

DC.socpedia.net
ADCS$
Network Information: Source Network Address
::ffff:192.168.0.211
Account Information: Account Name
ADCS$
Account Information: Account Domain
SOCPEDIA.NET
Account Information: User ID
S-1-5-21-1838030176-2987033226-1986555923-1106
Service Information: Service Name
krbtgt
Service Information: Service ID
S-1-5-21-1838030176-2987033226-1986555923-502
Additional Information: Ticket Options
0x40810010
Additional Information: Failure Code
0x0
Additional Information: Ticket Encryption Type
0x12
Additional Information: Pre-Authentication Type
2
Network Information: Source Network Address
::ffff:192.168.0.211
Network Information: Client Port
54098
Ticket information: Response ticket hash
sl5YdlVdvqeVRQOpA34HmHXYeL51lfRqK+0vFptIw4I=
Computer
DC.socpedia.net
ProcessID
848
ThreadID
3840
2026-08-02 19:45:56

A Kerberos service ticket was requested (4769 "Security")

DC.socpedia.net
ADCS$@SOCPEDIA.NET
Network Information: Client Address
::ffff:192.168.0.211
Account Information: Account Name
ADCS$@SOCPEDIA.NET
Account Information: Account Domain
SOCPEDIA.NET
Account Information: Logon GUID
{599f1e34-b452-ebc9-20e3-4a954ba452ea}
Service Information: Service Name
ADCS$
Service Information: Service ID
S-1-5-21-1838030176-2987033226-1986555923-1106
Network Information: Client Address
::ffff:192.168.0.211
Network Information: Source Port
54099
Additional Information: Ticket Options
0x40810000
Additional Information: Ticket Encryption Type
0x12
Additional Information: Failure Code
0x0
Additional Information: Transited Services
-
Ticket information: Request ticket hash
sl5YdlVdvqeVRQOpA34HmHXYeL51lfRqK+0vFptIw4I=
Ticket information: Response ticket hash
TRx1NCBmUkVkV5RoRuTUMFUQrraRssLmnlVmNyVrVuM=
Computer
DC.socpedia.net
ProcessID
848
ThreadID
3840
2026-08-02 19:45:56

A logon was attempted using explicit credentials (4648 "Security")

ADCS.socpedia.net
ADCS$
Network Information: Network Address
-
Subject: Security ID
S-1-5-18
Subject: Account Name
ADCS$
Subject: Account Domain
SOCPEDIA
Subject: Logon ID
0x3e7
Subject: Logon GUID
{00000000-0000-0000-0000-000000000000}
Account Whose Credentials Were Used: Account Name
ADCS$
Account Whose Credentials Were Used: Account Domain
SOCPEDIA.NET
Account Whose Credentials Were Used: Logon GUID
{599f1e34-b452-ebc9-20e3-4a954ba452ea}
Target Server: Target Server Name
adcs$
Target Server: Additional Information
adcs$
Process Information: Process ID
0x18fc
Process Information: Process Name
C:\Windows\System32\certsrv.exe
Network Information: Network Address
-
Network Information: Port
-
Computer
ADCS.socpedia.net
ProcessID
832
ThreadID
8252
2026-08-02 19:45:56

An account was successfully logged on (4624 "Security")

ADCS.socpedia.net
ADCS$
Network Information: Source Network Address
-
Subject: Security ID
S-1-0-0
Subject: Account Name
-
Subject: Account Domain
-
Subject: Logon ID
0x0
Logon Information: Logon Type
3
Logon Information: Restricted Admin Mode
-
Logon Information: Remote Credential Guard
-
ImpersonationLevel
%%1833
New Logon: Security ID
S-1-5-18
New Logon: Account Name
ADCS$
New Logon: Account Domain
SOCPEDIA.NET
New Logon: Logon ID
0xb4a8d7d
Account Information: Logon GUID
{599f1e34-b452-ebc9-20e3-4a954ba452ea}
Process Information: Process ID
0x0
Process Information: Process Name
-
Network Information: Workstation Name
-
Network Information: Source Network Address
-
Network Information: Client Port
-
Detailed Authentication Information: Logon Process
Kerberos
Detailed Authentication Information: Authentication Package
Kerberos
Computer
ADCS.socpedia.net
ProcessID
832
ThreadID
8252
2026-08-02 19:45:56

Special privileges assigned to new logon (4672 "Security")

ADCS.socpedia.net
ADCS$
Privileges
SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
Subject: Security ID
S-1-5-18
Subject: Account Name
ADCS$
Subject: Account Domain
SOCPEDIA
Subject: Logon ID
0xb4a8d7d
Privileges
SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
Computer
ADCS.socpedia.net
ProcessID
832
ThreadID
8252
2026-08-02 19:45:56

Group membership information (4627 "Security")

ADCS.socpedia.net
ADCS$
GroupMembership
%{S-1-5-32-544} %{S-1-1-0} %{S-1-5-32-545} %{S-1-5-32-574} %{S-1-5-2} %{S-1-5-11} %{S-1-5-15} %{S-1-5-21-1838030176-2987033226-1986555923-1106} %{S-1-5-21-1838030176-2987033226-1986555923-515} %{S-1-18-1} %{S-1-5-21-1838030176-2987033226-1986555923-517} %{S-1-5-21-1838030176-2987033226-1986555923-572} %{S-1-16-16384}
Subject: Security ID
S-1-0-0
Subject: Account Name
-
Subject: Account Domain
-
Subject: Logon ID
0x0
Logon Type
3
New Logon: Security ID
S-1-5-18
New Logon: Account Name
ADCS$
New Logon: Account Domain
SOCPEDIA.NET
New Logon: Logon ID
0xb4a8d7d
GroupMembership
%{S-1-5-32-544} %{S-1-1-0} %{S-1-5-32-545} %{S-1-5-32-574} %{S-1-5-2} %{S-1-5-11} %{S-1-5-15} %{S-1-5-21-1838030176-2987033226-1986555923-1106} %{S-1-5-21-1838030176-2987033226-1986555923-515} %{S-1-18-1} %{S-1-5-21-1838030176-2987033226-1986555923-517} %{S-1-5-21-1838030176-2987033226-1986555923-572} %{S-1-16-16384}
Computer
ADCS.socpedia.net
ProcessID
832
ThreadID
8252
2026-08-02 19:45:56

An account was logged off (4634 "Security")

ADCS.socpedia.net
ADCS$
Logon Type
3
Subject: Security ID
S-1-5-18
Subject: Account Name
ADCS$
Subject: Account Domain
SOCPEDIA
Subject: Logon ID
0xb4a8d7d
Logon Type
3
Computer
ADCS.socpedia.net
ProcessID
832
ThreadID
8252
2026-08-02 19:45:56

An account was logged off (4634 "Security")

DC.socpedia.net
ADCS$
Logon Type
3
Subject: Security ID
S-1-5-21-1838030176-2987033226-1986555923-1106
Subject: Account Name
ADCS$
Subject: Account Domain
SOCPEDIA
Subject: Logon ID
0xc74df1a
Logon Type
3
Computer
DC.socpedia.net
ProcessID
848
ThreadID
6296
2026-08-02 19:45:56

Certificate Services approved a certificate request and issued a certificate (4887 "Security")

ADCS.socpedia.net
SOCPEDIA\GHOSTPYUVHAOB$
Attributes
CertificateTemplate:Machine SAN:dns=DC.socpedia.net cdc:192.168.0.237 rmd:DC.socpedia.net
Request ID
16
Requester
SOCPEDIA\GHOSTPYUVHAOB$
Attributes
CertificateTemplate:Machine SAN:dns=DC.socpedia.net cdc:192.168.0.237 rmd:DC.socpedia.net
Certificate Subject
CN=DC.socpedia.net
Certificate SAN
DNS Name=DC.socpedia.net
Certificate Template
Machine
Authentication Service
NTLM
Authentication Level
Privacy
DCOMorRPC
RPC
Computer
ADCS.socpedia.net
ProcessID
832
ThreadID
896
2026-08-02 19:45:57

A Kerberos authentication ticket (TGT) was requested (4768 "Security")

DC.socpedia.net
DC$
Network Information: Source Network Address
::ffff:192.168.0.237
Account Information: Account Name
DC$
Account Information: Account Domain
SOCPEDIA.NET
Account Information: User ID
S-1-5-21-1838030176-2987033226-1986555923-1000
Service Information: Service Name
krbtgt
Service Information: Service ID
S-1-5-21-1838030176-2987033226-1986555923-502
Additional Information: Ticket Options
0x40800010
Additional Information: Failure Code
0x0
Additional Information: Ticket Encryption Type
0x12
Additional Information: Pre-Authentication Type
16
Network Information: Source Network Address
::ffff:192.168.0.237
Network Information: Client Port
38762
Certificate Information: Certificate Issuer Name
socpedia-ADCS-CA
Certificate Information: Certificate Serial Number
3D000000101F12030BDE0B6179000000000010
Certificate Information: Certificate Thumbprint
498245C480668A3C668D41E27B2FC7326185CF05
Ticket information: Response ticket hash
7HBipXt3WPGjqkSRiGYRUNK8aWIiZ2KeP2t19Cu/j54=
Computer
DC.socpedia.net
ProcessID
848
ThreadID
3840
2026-08-02 19:45:57

A Kerberos service ticket was requested (4769 "Security")

DC.socpedia.net
dc$@SOCPEDIA.NET
Network Information: Client Address
::ffff:192.168.0.237
Account Information: Account Name
dc$@SOCPEDIA.NET
Account Information: Account Domain
SOCPEDIA.NET
Account Information: Logon GUID
{e1d45ca1-ed2f-84dd-6438-e4a0cc6bb92e}
Service Information: Service Name
DC$
Service Information: Service ID
S-1-5-21-1838030176-2987033226-1986555923-1000
Network Information: Client Address
::ffff:192.168.0.237
Network Information: Source Port
38776
Additional Information: Ticket Options
0x40810018
Additional Information: Ticket Encryption Type
0x12
Additional Information: Failure Code
0x0
Additional Information: Transited Services
-
Ticket information: Request ticket hash
7HBipXt3WPGjqkSRiGYRUNK8aWIiZ2KeP2t19Cu/j54=
Ticket information: Response ticket hash
sYW9cYl+HwkTYp1bGGKBczzdRwOVJqhLNJDMZljCnts=
Computer
DC.socpedia.net
ProcessID
848
ThreadID
3840
2026-08-02 19:45:57

An account was logged off (4634 "Security")

DC.socpedia.net
user01
Logon Type
3
Subject: Security ID
S-1-5-21-1838030176-2987033226-1986555923-1105
Subject: Account Name
user01
Subject: Account Domain
SOCPEDIA
Subject: Logon ID
0xc74d8c5
Logon Type
3
Computer
DC.socpedia.net
ProcessID
848
ThreadID
5368
2026-08-02 19:45:57

Network connection detected: (3 "Microsoft-Windows-Sysmon/Operational")

DC.socpedia.net
SourceIp
192.168.0.211
DestinationHostname
DC.socpedia.net
DestinationIp
192.168.0.210
DestinationIsIpv6
false
DestinationPort
49680
DestinationPortName
-
Image
C:\Windows\System32\lsass.exe
Initiated
false
ProcessGuid
{d062d9b1-8c8c-6a67-0c00-000000000400}
ProcessId
848
Protocol
tcp
RuleName
v1-0_eventID3
SourceHostname
-
SourceIp
192.168.0.211
SourceIsIpv6
false
SourcePort
54089
SourcePortName
-
User
NT AUTHORITY\SYSTEM
UtcTime
2026-08-02 14:45:56.281
Computer
DC.socpedia.net
ProcessID
3024
ThreadID
5432
2026-08-02 19:45:57

Network connection detected: (3 "Microsoft-Windows-Sysmon/Operational")

DC.socpedia.net
SourceIp
192.168.0.211
DestinationHostname
DC.socpedia.net
DestinationIp
192.168.0.210
DestinationIsIpv6
false
DestinationPort
135
DestinationPortName
epmap
Image
C:\Windows\System32\svchost.exe
Initiated
false
ProcessGuid
{d062d9b1-8c92-6a67-0e00-000000000400}
ProcessId
424
Protocol
tcp
RuleName
v1-0_eventID3
SourceHostname
-
SourceIp
192.168.0.211
SourceIsIpv6
false
SourcePort
54087
SourcePortName
-
User
NT AUTHORITY\NETWORK SERVICE
UtcTime
2026-08-02 14:45:56.236
Computer
DC.socpedia.net
ProcessID
3024
ThreadID
5432
2026-08-02 19:45:57

Network connection detected: (3 "Microsoft-Windows-Sysmon/Operational")

DC.socpedia.net
SourceIp
192.168.0.211
DestinationHostname
DC.socpedia.net
DestinationIp
192.168.0.210
DestinationIsIpv6
false
DestinationPort
49680
DestinationPortName
-
Image
C:\Windows\System32\lsass.exe
Initiated
false
ProcessGuid
{d062d9b1-8c8c-6a67-0c00-000000000400}
ProcessId
848
Protocol
tcp
RuleName
v1-0_eventID3
SourceHostname
-
SourceIp
192.168.0.211
SourceIsIpv6
false
SourcePort
54092
SourcePortName
-
User
NT AUTHORITY\SYSTEM
UtcTime
2026-08-02 14:45:56.398
Computer
DC.socpedia.net
ProcessID
3024
ThreadID
5432
2026-08-02 19:45:57

Network connection detected: (3 "Microsoft-Windows-Sysmon/Operational")

ADCS.socpedia.net
SourceIp
192.168.0.237
DestinationHostname
ADCS.socpedia.net
DestinationIp
192.168.0.211
DestinationIsIpv6
false
DestinationPort
445
DestinationPortName
microsoft-ds
Image
System
Initiated
false
ProcessGuid
{e4c645e2-94a9-6a67-eb03-000000000000}
ProcessId
4
Protocol
tcp
RuleName
v2-6_eventID3
SourceHostname
-
SourceIp
192.168.0.237
SourceIsIpv6
false
SourcePort
44622
SourcePortName
-
User
NT AUTHORITY\SYSTEM
UtcTime
2026-08-02 14:45:56.113
Computer
ADCS.socpedia.net
ProcessID
6656
ThreadID
6728
2026-08-02 19:45:57

Network connection detected: (3 "Microsoft-Windows-Sysmon/Operational")

ADCS.socpedia.net
SourceIp
192.168.0.211
DestinationHostname
DC
DestinationIp
192.168.0.210
DestinationIsIpv6
false
DestinationPort
49680
DestinationPortName
-
Image
C:\Windows\System32\lsass.exe
Initiated
true
ProcessGuid
{e4c645e2-94ac-6a67-0c00-000000000400}
ProcessId
832
Protocol
tcp
RuleName
v2-6_eventID3
SourceHostname
ADCS.socpedia.net
SourceIp
192.168.0.211
SourceIsIpv6
false
SourcePort
54089
SourcePortName
-
User
NT AUTHORITY\SYSTEM
UtcTime
2026-08-02 14:45:56.281
Computer
ADCS.socpedia.net
ProcessID
6656
ThreadID
6728
2026-08-02 19:45:57

Network connection detected: (3 "Microsoft-Windows-Sysmon/Operational")

ADCS.socpedia.net
SourceIp
192.168.0.211
DestinationHostname
-
DestinationIp
192.168.0.237
DestinationIsIpv6
false
DestinationPort
445
DestinationPortName
microsoft-ds
Image
System
Initiated
true
ProcessGuid
{e4c645e2-94a9-6a67-eb03-000000000000}
ProcessId
4
Protocol
tcp
RuleName
v2-6_eventID3
SourceHostname
ADCS.socpedia.net
SourceIp
192.168.0.211
SourceIsIpv6
false
SourcePort
54094
SourcePortName
-
User
NT AUTHORITY\SYSTEM
UtcTime
2026-08-02 14:45:56.531
Computer
ADCS.socpedia.net
ProcessID
6656
ThreadID
6728
2026-08-02 19:45:57

Network connection detected: (3 "Microsoft-Windows-Sysmon/Operational")

ADCS.socpedia.net
SourceIp
192.168.0.211
DestinationHostname
DC
DestinationIp
192.168.0.210
DestinationIsIpv6
false
DestinationPort
49680
DestinationPortName
-
Image
C:\Windows\System32\lsass.exe
Initiated
true
ProcessGuid
{e4c645e2-94ac-6a67-0c00-000000000400}
ProcessId
832
Protocol
tcp
RuleName
v2-6_eventID3
SourceHostname
ADCS.socpedia.net
SourceIp
192.168.0.211
SourceIsIpv6
false
SourcePort
54092
SourcePortName
-
User
NT AUTHORITY\SYSTEM
UtcTime
2026-08-02 14:45:56.398
Computer
ADCS.socpedia.net
ProcessID
6656
ThreadID
6728
2026-08-02 19:45:57

Network connection detected: (3 "Microsoft-Windows-Sysmon/Operational")

ADCS.socpedia.net
SourceIp
192.168.0.211
DestinationHostname
DC
DestinationIp
192.168.0.210
DestinationIsIpv6
false
DestinationPort
135
DestinationPortName
epmap
Image
C:\Windows\System32\lsass.exe
Initiated
true
ProcessGuid
{e4c645e2-94ac-6a67-0c00-000000000400}
ProcessId
832
Protocol
tcp
RuleName
v2-6_eventID3
SourceHostname
ADCS.socpedia.net
SourceIp
192.168.0.211
SourceIsIpv6
false
SourcePort
54087
SourcePortName
-
User
NT AUTHORITY\SYSTEM
UtcTime
2026-08-02 14:45:56.235
Computer
ADCS.socpedia.net
ProcessID
6656
ThreadID
6728
2026-08-02 19:45:58

Network connection detected: (3 "Microsoft-Windows-Sysmon/Operational")

DC.socpedia.net
SourceIp
192.168.0.237
DestinationHostname
DC.socpedia.net
DestinationIp
192.168.0.210
DestinationIsIpv6
false
DestinationPort
135
DestinationPortName
epmap
Image
C:\Windows\System32\svchost.exe
Initiated
false
ProcessGuid
{d062d9b1-8c92-6a67-0e00-000000000400}
ProcessId
424
Protocol
tcp
RuleName
v1-0_eventID3
SourceHostname
-
SourceIp
192.168.0.237
SourceIsIpv6
false
SourcePort
33622
SourcePortName
-
User
NT AUTHORITY\NETWORK SERVICE
UtcTime
2026-08-02 14:45:56.541
Computer
DC.socpedia.net
ProcessID
3024
ThreadID
5432
2026-08-02 19:45:58

Network connection detected: (3 "Microsoft-Windows-Sysmon/Operational")

DC.socpedia.net
SourceIp
192.168.0.237
DestinationHostname
DC.socpedia.net
DestinationIp
192.168.0.210
DestinationIsIpv6
false
DestinationPort
135
DestinationPortName
epmap
Image
C:\Windows\System32\svchost.exe
Initiated
false
ProcessGuid
{d062d9b1-8c92-6a67-0e00-000000000400}
ProcessId
424
Protocol
tcp
RuleName
v1-0_eventID3
SourceHostname
-
SourceIp
192.168.0.237
SourceIsIpv6
false
SourcePort
33628
SourcePortName
-
User
NT AUTHORITY\NETWORK SERVICE
UtcTime
2026-08-02 14:45:56.667
Computer
DC.socpedia.net
ProcessID
3024
ThreadID
5432

SOCpedia - knowledge platform

This section contains materials on SOC and Blue Team practices: articles, news, books, and translations.