<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event"> | |
<System> | |
<Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" /> | |
<EventID>4672</EventID> | |
<Version>0</Version> | |
<Level>0</Level> | |
<Task>12548</Task> | |
<Opcode>0</Opcode> | |
<Keywords>0x8020000000000000</Keywords> | |
<TimeCreated SystemTime="2019-08-27T14:37:56.104234800Z" /> | |
<EventRecordID>2575952</EventRecordID> | |
<Correlation ActivityID="{47aa1c15-3cc3-0006-e859-7fa1025cd501}" /> | |
<Execution ProcessID="840" ThreadID="11544" /> | |
<Channel>Security</Channel> | |
<Computer>TestComputer</Computer> | |
<Security /> | |
</System> | |
<EventData> | |
<Data Name="SubjectUserSid">S-1-8-6-5-3-0-9</Data> | |
<Data Name="PrivilegeList">SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege</Data> | |
</EventData> | |
</Event> |