ANAVEM
Languagefr

#privilege-escalation

8 articles

News3

Windows Events5

Windows security monitoring dashboard displaying audit events and privilege tracking logs
Event 6276
Microsoft-Windows-Security-Auditing
Windows EventInformation

Windows Event ID 6276 – Microsoft-Windows-Security-Auditing: Special Privileges Assigned to New Logon

Event ID 6276 records when special privileges are assigned to a user account during logon, indicating elevated access rights have been granted for the session.

March 189 min
Windows security monitoring dashboard displaying Event ID 4976 privilege tracking logs
Event 4976
Microsoft-Windows-Security-Auditing
Windows EventInformation

Windows Event ID 4976 – Microsoft-Windows-Security-Auditing: Special Logon

Event ID 4976 records when a user account is granted special privileges during logon, typically for service accounts or administrative access requiring elevated permissions.

March 189 min
Windows security monitoring dashboard showing privilege assignment events in Event Viewer
Event 4876
Microsoft-Windows-Security-Auditing
Windows EventInformation

Windows Event ID 4876 – Security: Special Privileges Assigned to New Logon

Event ID 4876 records when special privileges are assigned to a new user logon session, indicating elevated access rights have been granted during authentication.

March 189 min
Windows security monitoring dashboard showing Event Viewer with security audit logs and system access events
Event 4717
Microsoft-Windows-Security-Auditing
Windows EventInformation

Windows Event ID 4717 – Microsoft-Windows-Security-Auditing: System Security Access Was Granted

Event ID 4717 logs when a user or process is granted system security access privileges, typically involving sensitive security operations like backup, restore, or system-level access rights.

March 189 min
Windows security monitoring dashboard displaying Event ID 4673 privilege usage logs in a cybersecurity operations center
Event 4673
Security
Windows EventInformation

Windows Event ID 4673 – Security: Sensitive Privilege Use

Event ID 4673 logs when a user or process attempts to use a sensitive privilege on Windows systems. This security audit event helps track privileged operations and potential security risks.

March 1812 min