This page (revision-1) was last changed on 29-Nov-2024 16:16 by UnknownAuthor

Only authorized users are allowed to rename pages.

Only authorized users are allowed to delete pages.

Page revision history

Version Date Modified Size Author Changes ... Change note

Page References

Incoming links Outgoing links
Event 4673...nobody

Version management

Difference between version and

At line 1 added 166 lines
!!! Overview
[{$pagename}] is an [Windows Security Log Event] within the [Microsoft Windows] [Logging] system indicating that the specified user exercised the user right specified in the [Privileges] field.
The [Windows Logon] fields are used to determine details on the [logging] [event]
Unfortunately, [Microsoft] has overloaded these [privileges] so that each privilege may govern your authority to perform many different operations and which [privilege] is required for which operations is not well documented. Therefore seeing that a privilege was exercised doesn't really tell you much. In
[Windows Server 2008] this has been improved with better information in the Server: and Service Name: fields.\\
In general though, [{$applicationname}] still classifies these events as __"noise"__\\
[Microsoft] admits: "These are high volume events, which typically do not contain sufficient information to act upon since they do not describe what operation occurred."
Note: [{$pagename}] and 4674 do not log any activity associated with Logon Rights such as the SeNetworkLogonRight. Do not confuse events [{$pagename}] and 4674 with events 4717 and 4718 which document rights assignment changes as opposed to the exercise of rights which is the purpose of events [{$pagename}] and 4674.
!! More Information
There might be more information for this subject on one of the following:
[{ReferringPagesPlugin before='*' after='\n' }]
----
* [#1] - [4673(S, F): A privileged service was called|https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4673|target='_blank'] - based on information obtained 2018-03-27
* [#2] - [Windows Security Log Event ID 4673|https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4673||target='_blank'] - based on information obtained 2018-03-27 - based on information obtained 2018-03-27