name: Windows Event Log Security 4886 id: c5abd97d-b468-451f-bd65-b4f97efa4ecc version: 4 creation_date: '2024-05-22' modification_date: '2026-05-13' author: Patrick Bareiss, Splunk description: Logs the deletion of a cryptographic key container, including details about the key container name and the user performing the action. mitre_components: - Certificate Registration - User Account Metadata - Application Log Content - OS API Execution source: XmlWinEventLog:Security sourcetype: XmlWinEventLog separator: EventCode separator_value: '4886' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 version: 10.0.1 fields: - _time - ActivityID - Attributes - Channel - Computer - Error_Code - EventCode - EventData_Xml - EventID - EventRecordID - Guid - Keywords - Level - Name - Opcode - ProcessID - RecordNumber - RequestId - Requester - SystemTime - System_Props_Xml - Task - ThreadID - Version - action - app - date_hour - date_mday - date_minute - date_month - date_second - date_wday - date_year - date_zone - dest - dvc - dvc_nt_host - event_id - eventtype - host - id - index - linecount - name - product - punct - signature - signature_id - source - sourcetype - splunk_server - status - subject - ta_windows_action - tag - tag::action - tag::eventtype - timeendpos - timestartpos - vendor - vendor_product output_fields: - dest example_log: 4886001280500x802000000000000015379925Securitywin-dc-mhaag-attack-range-84.attackrange.local7ATTACKRANGE\administrator