Windows Events
Attempt to get credential key by call package blocked by Credential Guard
Event ID 4014
Microsoft-Windows-NTLM/Operational
Main fields
IP address
IP
Windows
IP
ELK
-
Microsoft Sentinel
-
QRadar
-
Splunk
-
Computer name
Computer
Windows
Computer
ELK
winlog.computer_name
Microsoft Sentinel
-
QRadar
-
Splunk
-
User name
Not selected
Important field
ImageName
Windows
Calling Process Name
ELK
winlog.event_data.ImageName
Microsoft Sentinel
-
QRadar
-
Splunk
-
Fields
| Windows Raw | Windows | ELK | Microsoft Sentinel | QRadar | Splunk |
|---|---|---|---|---|---|
| ImageName | Calling Process Name | winlog.event_data.ImageName | - | - | - |
| SvcHostTag | Service Host Tag | - | - | - | - |
| IP System field | IP System field | - | - | - | - |
| Computer System field | Computer System field | winlog.computer_name | - | - | - |
| ProcessID System field | ProcessID System field | winlog.process.pid | - | - | - |
| ThreadID System field | ThreadID System field | winlog.process.thread.id | - | - | - |
Sample Event
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
<Provider Name="Microsoft-Windows-NTLM" Guid="{ac43300d-5fcc-4800-8e99-1bd3f85f0320}" />
<EventID>4014</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000000</Keywords>
<TimeCreated SystemTime="2026-08-02T14:45:56.3924760Z" />
<EventRecordID>977</EventRecordID>
<Correlation ActivityID="{fdc2cf05-1dec-0001-ebcf-c2fdec1ddd01}" />
<Execution ProcessID="832" ThreadID="896" />
<Channel>Microsoft-Windows-NTLM/Operational</Channel>
<Computer>ADCS.socpedia.net</Computer>
<Security UserID="S-1-5-18" />
</System>
- <EventData>
<Data Name="ImageName">lsass</Data>
<Data Name="SvcHostTag" />
</EventData>
</Event>