Loading...
Windows Events

Special privileges assigned to new logon

Event ID 4672 Security Audit Special Logon

Main fields

IP address
IP
Windows IP
ELK -
Microsoft Sentinel -
QRadar -
Splunk -
Computer name
Computer
Windows Computer
ELK winlog.computer_name
Microsoft Sentinel -
QRadar -
Splunk -
User name
SubjectUserName
Windows Subject: Account Name
ELK winlog.event_data.SubjectUserName
Microsoft Sentinel -
QRadar -
Splunk -
Important field
PrivilegeList
Windows Privileges
ELK winlog.event_data.PrivilegeList
Microsoft Sentinel -
QRadar -
Splunk -

Fields

Windows Raw Windows ELK Microsoft Sentinel QRadar Splunk
SubjectUserSid Subject: Security ID winlog.event_data.SubjectUserSid - - -
SubjectUserName Subject: Account Name winlog.event_data.SubjectUserName - - -
SubjectDomainName Subject: Account Domain winlog.event_data.SubjectDomainName - - -
SubjectLogonId Subject: Logon ID winlog.event_data.SubjectLogonId - - -
PrivilegeList Privileges winlog.event_data.PrivilegeList - - -
Computer System field Computer System field winlog.computer_name - - -
ProcessID System field ProcessID System field winlog.process.pid - - -
IP System field IP System field - - - -
ThreadID System field ThreadID System field winlog.process.thread.id - - -

Sample Event

- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
  <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" /> 
  <EventID>4672</EventID> 
  <Version>0</Version> 
  <Level>0</Level> 
  <Task>12548</Task> 
  <Opcode>0</Opcode> 
  <Keywords>0x8020000000000000</Keywords> 
  <TimeCreated SystemTime="2026-08-02T14:55:36.9645305Z" /> 
  <EventRecordID>156856</EventRecordID> 
  <Correlation /> 
  <Execution ProcessID="848" ThreadID="7696" /> 
  <Channel>Security</Channel> 
  <Computer>DC.socpedia.net</Computer> 
  <Security /> 
  </System>
- <EventData>
  <Data Name="SubjectUserSid">S-1-5-21-1838030176-2987033226-1986555923-1104</Data> 
  <Data Name="SubjectUserName">cs_admin</Data> 
  <Data Name="SubjectDomainName">SOCPEDIA</Data> 
  <Data Name="SubjectLogonId">0xc77469e</Data> 
  <Data Name="PrivilegeList">SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege SeEnableDelegationPrivilege</Data> 
  </EventData>
  </Event>

SOCpedia - knowledge platform

This section contains materials on SOC and Blue Team practices: articles, news, books, and translations.