Жүктелуде...
Windows оқиғалары

Certificate Services received a certificate request

Сертификат қызметтері сертификатқа сұраныс алды AI
Event ID 4889 Security Audit Certification Services

Негізгі өрістер

IP мекенжайы
IP
Windows IP
ELK -
Microsoft Sentinel -
QRadar -
Splunk -
Компьютер атауы
Computer
Windows Computer
ELK winlog.computer_name
Microsoft Sentinel -
QRadar -
Splunk -
Пайдаланушы аты
Requester
Windows Requester
ELK winlog.event_data.Requester
Microsoft Sentinel -
QRadar -
Splunk -
Маңызды өріс
Attributes
Windows Attributes
ELK winlog.event_data.Attributes
Microsoft Sentinel -
QRadar -
Splunk -

Өрістер

Windows Raw Windows ELK Microsoft Sentinel QRadar Splunk
RequestId Request ID winlog.event_data.RequestId - - -
Requester Requester winlog.event_data.Requester - - -
Attributes Attributes winlog.event_data.Attributes - - -
Subject Subject winlog.event_data.Subject - - -
SubjectAlternativeName SubjectAlternativeName winlog.event_data.SubjectAlternativeName - - -
CertificateTemplate Certificate Template winlog.event_data.CertificateTemplate - - -
RequestOSVersion RequestOSVersion - - - -
RequestCSPProvider RequestCSPProvider - - - -
RequestClientInfo RequestClientInfo - - - -
AuthenticationService Authentication Service winlog.event_data.AuthenticationService - - -
AuthenticationLevel Authentication Level winlog.event_data.AuthenticationLevel - - -
DCOMorRPC DCOMorRPC winlog.event_data.DCOMorRPC - - -
IP Жүйелік өріс IP Жүйелік өріс - - - -
Computer Жүйелік өріс Computer Жүйелік өріс winlog.computer_name - - -
ProcessID Жүйелік өріс ProcessID Жүйелік өріс winlog.process.pid - - -
ThreadID Жүйелік өріс ThreadID Жүйелік өріс winlog.process.thread.id - - -

Оқиға мысалы

- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
  <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" /> 
  <EventID>4886</EventID> 
  <Version>1</Version> 
  <Level>0</Level> 
  <Task>12805</Task> 
  <Opcode>0</Opcode> 
  <Keywords>0x8020000000000000</Keywords> 
  <TimeCreated SystemTime="2026-08-02T14:45:56.4067638Z" /> 
  <EventRecordID>26400</EventRecordID> 
  <Correlation ActivityID="{fdc2cf05-1dec-0001-ebcf-c2fdec1ddd01}" /> 
  <Execution ProcessID="832" ThreadID="896" /> 
  <Channel>Security</Channel> 
  <Computer>ADCS.socpedia.net</Computer> 
  <Security /> 
  </System>
- <EventData>
  <Data Name="RequestId">16</Data> 
  <Data Name="Requester">SOCPEDIA\GHOSTPYUVHAOB$</Data> 
  <Data Name="Attributes">CertificateTemplate:Machine SAN:dns=DC.socpedia.net cdc:192.168.0.237 rmd:DC.socpedia.net</Data> 
  <Data Name="Subject">CN=GHOSTPYUVHAOB.socpedia.net</Data> 
  <Data Name="SubjectAlternativeName">DNS Name=DC.socpedia.net</Data> 
  <Data Name="CertificateTemplate">Machine</Data> 
  <Data Name="RequestOSVersion" /> 
  <Data Name="RequestCSPProvider" /> 
  <Data Name="RequestClientInfo" /> 
  <Data Name="AuthenticationService">NTLM</Data> 
  <Data Name="AuthenticationLevel">Privacy</Data> 
  <Data Name="DCOMorRPC">RPC</Data> 
  </EventData>
  </Event>

SOCpedia - білім платформасы

Мұнда SOC және Blue Team тәжірибелері бойынша материалдар жинақталған: мақалалар, жаңалықтар, кітаптар және аудармалар.