From 3fe803767b891a90343ea4ca326247f45430009e Mon Sep 17 00:00:00 2001 From: pex7hfbnt <1584881064@qq.com> Date: Wed, 16 Oct 2024 23:43:35 +0800 Subject: [PATCH] ADD file via upload --- .../samples/Sample_Object_Access_Events.csv | 14715 ++++++++++++++++ 1 file changed, 14715 insertions(+) create mode 100644 source/samples/Sample_Object_Access_Events.csv diff --git a/source/samples/Sample_Object_Access_Events.csv b/source/samples/Sample_Object_Access_Events.csv new file mode 100644 index 0000000..01dbd53 --- /dev/null +++ b/source/samples/Sample_Object_Access_Events.csv @@ -0,0 +1,14715 @@ +Date and Time,timestamp,Event ID,Account Name,Object Name,Object Type,Process Name,Computer Name,Channel,Original Event Log +2020-03-09T02:11:34.340693+04:00,1583705494.340693,4663,IEUser,\Device\HarddiskVolume1\Windows\System32\lsass.exe,Process,C:\Windows\System32\cscript.exe,MSEDGEWIN10,Security," + + + + + 4663 + 1 + 0 + 12802 + 0 + 0x8020000000000000 + + + 314462 + + + + + Security + MSEDGEWIN10 + + + + + S-1-5-21-3461203602-4096304019-2269080069-1000 + IEUser + MSEDGEWIN10 + 0x33392 + Security + Process + \Device\HarddiskVolume1\Windows\System32\lsass.exe + 0x558 + %%4484 + + 0x10 + 0x1688 + C:\Windows\System32\cscript.exe + - + +" +2020-03-09T02:11:34.340693+04:00,1583705494.340693,4663,IEUser,\Device\HarddiskVolume1\Windows\System32\lsass.exe,Process,C:\Windows\System32\cscript.exe,MSEDGEWIN10,Security," + + + + + 4663 + 1 + 0 + 12802 + 0 + 0x8020000000000000 + + + 314462 + + + + + Security + MSEDGEWIN10 + + + + + S-1-5-21-3461203602-4096304019-2269080069-1000 + IEUser + MSEDGEWIN10 + 0x33392 + Security + Process + \Device\HarddiskVolume1\Windows\System32\lsass.exe + 0x558 + %%4484 + + 0x10 + 0x1688 + C:\Windows\System32\cscript.exe + - + +" +2020-03-09T02:11:34.340693+04:00,1583705494.340693,4663,IEUser,\Device\HarddiskVolume1\Windows\System32\lsass.exe,Process,C:\Windows\System32\cscript.exe,MSEDGEWIN10,Security," + + + + + 4663 + 1 + 0 + 12802 + 0 + 0x8020000000000000 + + + 314462 + + + + + Security + MSEDGEWIN10 + + + + + S-1-5-21-3461203602-4096304019-2269080069-1000 + IEUser + MSEDGEWIN10 + 0x33392 + Security + Process + \Device\HarddiskVolume1\Windows\System32\lsass.exe + 0x558 + %%4484 + + 0x10 + 0x1688 + C:\Windows\System32\cscript.exe + - + +" +1601-01-01T04:00:00+04:00,-11644473600.0,4663,IEUser,C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4991 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2019-04-27T23:33:50.134293+04:00,1556393630.134293,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4990 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2019-04-27T23:33:18.699755+04:00,1556393598.699755,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4989 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2019-04-27T23:33:05.308188+04:00,1556393585.308188,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4988 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2020-03-09T02:11:34.340693+04:00,1583705494.340693,4663,IEUser,\Device\HarddiskVolume1\Windows\System32\lsass.exe,Process,C:\Windows\System32\cscript.exe,MSEDGEWIN10,Security," + + + + + 4663 + 1 + 0 + 12802 + 0 + 0x8020000000000000 + + + 314462 + + + + + Security + MSEDGEWIN10 + + + + + S-1-5-21-3461203602-4096304019-2269080069-1000 + IEUser + MSEDGEWIN10 + 0x33392 + Security + Process + \Device\HarddiskVolume1\Windows\System32\lsass.exe + 0x558 + %%4484 + + 0x10 + 0x1688 + C:\Windows\System32\cscript.exe + - + +" +1601-01-01T04:00:00+04:00,-11644473600.0,4663,IEUser,C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4991 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2019-04-27T23:33:50.134293+04:00,1556393630.134293,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4990 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2019-04-27T23:33:18.699755+04:00,1556393598.699755,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4989 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2019-04-27T23:33:05.308188+04:00,1556393585.308188,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4988 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2020-03-09T02:11:34.340693+04:00,1583705494.340693,4663,IEUser,\Device\HarddiskVolume1\Windows\System32\lsass.exe,Process,C:\Windows\System32\cscript.exe,MSEDGEWIN10,Security," + + + + + 4663 + 1 + 0 + 12802 + 0 + 0x8020000000000000 + + + 314462 + + + + + Security + MSEDGEWIN10 + + + + + S-1-5-21-3461203602-4096304019-2269080069-1000 + IEUser + MSEDGEWIN10 + 0x33392 + Security + Process + \Device\HarddiskVolume1\Windows\System32\lsass.exe + 0x558 + %%4484 + + 0x10 + 0x1688 + C:\Windows\System32\cscript.exe + - + +" +1601-01-01T04:00:00+04:00,-11644473600.0,4663,IEUser,C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4991 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2019-04-27T23:33:50.134293+04:00,1556393630.134293,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4990 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2019-04-27T23:33:18.699755+04:00,1556393598.699755,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4989 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2019-04-27T23:33:05.308188+04:00,1556393585.308188,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4988 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2020-03-09T02:11:34.340693+04:00,1583705494.340693,4663,IEUser,\Device\HarddiskVolume1\Windows\System32\lsass.exe,Process,C:\Windows\System32\cscript.exe,MSEDGEWIN10,Security," + + + + + 4663 + 1 + 0 + 12802 + 0 + 0x8020000000000000 + + + 314462 + + + + + Security + MSEDGEWIN10 + + + + + S-1-5-21-3461203602-4096304019-2269080069-1000 + IEUser + MSEDGEWIN10 + 0x33392 + Security + Process + \Device\HarddiskVolume1\Windows\System32\lsass.exe + 0x558 + %%4484 + + 0x10 + 0x1688 + C:\Windows\System32\cscript.exe + - + +" +1601-01-01T04:00:00+04:00,-11644473600.0,4663,IEUser,C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4991 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2019-04-27T23:33:50.134293+04:00,1556393630.134293,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4990 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2019-04-27T23:33:18.699755+04:00,1556393598.699755,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4989 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2019-04-27T23:33:05.308188+04:00,1556393585.308188,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4988 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2020-03-09T02:11:34.340693+04:00,1583705494.340693,4663,IEUser,\Device\HarddiskVolume1\Windows\System32\lsass.exe,Process,C:\Windows\System32\cscript.exe,MSEDGEWIN10,Security," + + + + + 4663 + 1 + 0 + 12802 + 0 + 0x8020000000000000 + + + 314462 + + + + + Security + MSEDGEWIN10 + + + + + S-1-5-21-3461203602-4096304019-2269080069-1000 + IEUser + MSEDGEWIN10 + 0x33392 + Security + Process + \Device\HarddiskVolume1\Windows\System32\lsass.exe + 0x558 + %%4484 + + 0x10 + 0x1688 + C:\Windows\System32\cscript.exe + - + +" +1601-01-01T04:00:00+04:00,-11644473600.0,4663,IEUser,C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4991 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2019-04-27T23:33:50.134293+04:00,1556393630.134293,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4990 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2019-04-27T23:33:18.699755+04:00,1556393598.699755,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4989 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2019-04-27T23:33:05.308188+04:00,1556393585.308188,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4988 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2020-03-09T02:11:34.340693+04:00,1583705494.340693,4663,IEUser,\Device\HarddiskVolume1\Windows\System32\lsass.exe,Process,C:\Windows\System32\cscript.exe,MSEDGEWIN10,Security," + + + + + 4663 + 1 + 0 + 12802 + 0 + 0x8020000000000000 + + + 314462 + + + + + Security + MSEDGEWIN10 + + + + + S-1-5-21-3461203602-4096304019-2269080069-1000 + IEUser + MSEDGEWIN10 + 0x33392 + Security + Process + \Device\HarddiskVolume1\Windows\System32\lsass.exe + 0x558 + %%4484 + + 0x10 + 0x1688 + C:\Windows\System32\cscript.exe + - + +" +1601-01-01T04:00:00+04:00,-11644473600.0,4663,IEUser,C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4991 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2019-04-27T23:33:50.134293+04:00,1556393630.134293,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4990 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2019-04-27T23:33:18.699755+04:00,1556393598.699755,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4989 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2019-04-27T23:33:05.308188+04:00,1556393585.308188,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4988 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452905 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452904 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452903 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452902 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452901 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452900 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452899 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452898 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452897 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452896 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452895 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452894 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452893 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452892 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452891 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452890 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452889 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452888 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452887 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452886 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452885 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452884 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452883 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452882 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452881 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452880 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452879 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452878 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452877 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452876 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452875 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452874 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452873 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452872 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452871 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452870 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452869 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452868 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452867 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452866 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452865 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452864 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452863 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452862 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452861 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452860 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452859 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452858 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452857 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452856 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452855 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452854 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452853 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452852 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452851 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452850 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452849 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452848 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452847 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452846 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452845 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452844 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452843 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452842 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452841 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452840 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452839 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452838 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452837 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452836 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452835 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452834 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452833 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452832 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452831 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452830 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452829 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452828 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452827 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452826 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.215261+04:00,1553038515.215261,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452825 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.215261+04:00,1553038515.215261,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452824 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.215261+04:00,1553038515.215261,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452823 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.205246+04:00,1553038515.205246,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452822 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.185218+04:00,1553038515.185218,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452821 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.185218+04:00,1553038515.185218,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452820 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.045016+04:00,1553038515.045016,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452819 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.045016+04:00,1553038515.045016,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452818 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:14.904814+04:00,1553038514.904814,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452817 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:14.904814+04:00,1553038514.904814,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452816 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:14.764613+04:00,1553038514.764613,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452815 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:14.764613+04:00,1553038514.764613,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452814 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:14.634426+04:00,1553038514.634426,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452813 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +1601-01-01T04:00:00+04:00,-11644473600.0,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452922 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.365477+04:00,1553038515.365477,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452921 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.365477+04:00,1553038515.365477,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452920 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.365477+04:00,1553038515.365477,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452919 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.365477+04:00,1553038515.365477,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452918 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452917 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452916 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452915 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452914 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452913 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452912 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452911 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452910 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452909 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452908 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452907 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452906 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452905 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452904 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452903 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452902 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452901 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452900 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452899 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452898 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452897 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452896 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452895 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452894 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452893 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452892 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452891 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452890 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452889 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452888 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452887 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452886 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452885 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452884 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452883 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452882 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452881 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452880 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452879 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452878 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452877 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452876 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452875 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452874 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452873 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452872 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452871 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452870 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452869 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452868 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452867 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452866 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452865 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452864 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452863 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452862 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452861 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452860 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452859 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452858 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452857 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452856 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452855 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452854 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452853 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452852 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452851 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452850 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452849 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452848 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452847 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452846 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452845 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452844 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452843 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452842 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452841 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452840 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452839 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452838 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452837 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452836 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452835 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452834 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452833 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452832 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452831 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452830 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452829 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452828 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452827 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452826 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.215261+04:00,1553038515.215261,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452825 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.215261+04:00,1553038515.215261,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452824 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.215261+04:00,1553038515.215261,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452823 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.205246+04:00,1553038515.205246,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452822 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.185218+04:00,1553038515.185218,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452821 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.185218+04:00,1553038515.185218,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452820 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.045016+04:00,1553038515.045016,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452819 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.045016+04:00,1553038515.045016,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452818 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:14.904814+04:00,1553038514.904814,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452817 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:14.904814+04:00,1553038514.904814,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452816 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:14.764613+04:00,1553038514.764613,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452815 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:14.764613+04:00,1553038514.764613,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452814 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:14.634426+04:00,1553038514.634426,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452813 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +1601-01-01T04:00:00+04:00,-11644473600.0,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452922 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.365477+04:00,1553038515.365477,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452921 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.365477+04:00,1553038515.365477,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452920 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.365477+04:00,1553038515.365477,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452919 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.365477+04:00,1553038515.365477,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452918 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452917 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452916 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452915 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452914 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452913 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452912 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452911 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452910 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452909 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452908 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452907 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452906 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2020-03-09T02:11:34.340693+04:00,1583705494.340693,4663,IEUser,\Device\HarddiskVolume1\Windows\System32\lsass.exe,Process,C:\Windows\System32\cscript.exe,MSEDGEWIN10,Security," + + + + + 4663 + 1 + 0 + 12802 + 0 + 0x8020000000000000 + + + 314462 + + + + + Security + MSEDGEWIN10 + + + + + S-1-5-21-3461203602-4096304019-2269080069-1000 + IEUser + MSEDGEWIN10 + 0x33392 + Security + Process + \Device\HarddiskVolume1\Windows\System32\lsass.exe + 0x558 + %%4484 + + 0x10 + 0x1688 + C:\Windows\System32\cscript.exe + - + +" +1601-01-01T04:00:00+04:00,-11644473600.0,4663,IEUser,C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4991 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2019-04-27T23:33:50.134293+04:00,1556393630.134293,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4990 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2019-04-27T23:33:18.699755+04:00,1556393598.699755,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4989 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2019-04-27T23:33:05.308188+04:00,1556393585.308188,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4988 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2020-03-09T02:11:34.340693+04:00,1583705494.340693,4663,IEUser,\Device\HarddiskVolume1\Windows\System32\lsass.exe,Process,C:\Windows\System32\cscript.exe,MSEDGEWIN10,Security," + + + + + 4663 + 1 + 0 + 12802 + 0 + 0x8020000000000000 + + + 314462 + + + + + Security + MSEDGEWIN10 + + + + + S-1-5-21-3461203602-4096304019-2269080069-1000 + IEUser + MSEDGEWIN10 + 0x33392 + Security + Process + \Device\HarddiskVolume1\Windows\System32\lsass.exe + 0x558 + %%4484 + + 0x10 + 0x1688 + C:\Windows\System32\cscript.exe + - + +" +1601-01-01T04:00:00+04:00,-11644473600.0,4663,IEUser,C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4991 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2019-04-27T23:33:50.134293+04:00,1556393630.134293,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4990 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2019-04-27T23:33:18.699755+04:00,1556393598.699755,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4989 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2019-04-27T23:33:05.308188+04:00,1556393585.308188,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4988 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452905 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452904 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452903 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452902 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452901 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452900 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452899 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452898 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452897 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452896 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452895 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452894 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452893 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452892 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452891 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452890 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452889 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452888 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452887 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452886 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452885 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452884 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452883 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452882 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452881 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452880 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452879 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452878 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452877 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452876 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452875 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452874 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452873 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452872 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452871 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452870 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452869 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452868 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452867 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452866 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452865 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452864 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452863 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452862 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452861 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452860 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452859 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452858 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452857 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452856 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452855 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452854 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452853 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452852 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452851 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452850 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452849 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452848 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452847 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452846 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452845 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452844 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452843 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452842 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452841 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452840 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452839 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452838 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452837 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452836 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452835 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452834 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452833 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452832 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452831 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452830 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452829 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452828 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452827 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452826 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.215261+04:00,1553038515.215261,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452825 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.215261+04:00,1553038515.215261,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452824 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.215261+04:00,1553038515.215261,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452823 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.205246+04:00,1553038515.205246,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452822 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.185218+04:00,1553038515.185218,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452821 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.185218+04:00,1553038515.185218,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452820 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.045016+04:00,1553038515.045016,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452819 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.045016+04:00,1553038515.045016,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452818 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:14.904814+04:00,1553038514.904814,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452817 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:14.904814+04:00,1553038514.904814,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452816 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:14.764613+04:00,1553038514.764613,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452815 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:14.764613+04:00,1553038514.764613,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452814 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x520 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:14.634426+04:00,1553038514.634426,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452813 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x468 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +1601-01-01T04:00:00+04:00,-11644473600.0,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452922 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.365477+04:00,1553038515.365477,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452921 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.365477+04:00,1553038515.365477,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452920 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.365477+04:00,1553038515.365477,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452919 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.365477+04:00,1553038515.365477,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452918 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452917 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452916 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452915 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452914 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452913 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452912 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452911 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452910 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452909 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452908 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x1ac + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452907 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security," + + + + + 4663 + 0 + 0 + 12801 + 0 + 0x8020000000000000 + + + 452906 + + + + + Security + PC01.example.corp + + + + + S-1-5-19 + LOCAL SERVICE + NT AUTHORITY + 0x3e5 + Security + Key + \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa + 0x420 + %%4432 + + 0x1 + 0x5a8 + C:\Windows\System32\svchost.exe + +" +2020-03-09T02:11:34.340693+04:00,1583705494.340693,4663,IEUser,\Device\HarddiskVolume1\Windows\System32\lsass.exe,Process,C:\Windows\System32\cscript.exe,MSEDGEWIN10,Security," + + + + + 4663 + 1 + 0 + 12802 + 0 + 0x8020000000000000 + + + 314462 + + + + + Security + MSEDGEWIN10 + + + + + S-1-5-21-3461203602-4096304019-2269080069-1000 + IEUser + MSEDGEWIN10 + 0x33392 + Security + Process + \Device\HarddiskVolume1\Windows\System32\lsass.exe + 0x558 + %%4484 + + 0x10 + 0x1688 + C:\Windows\System32\cscript.exe + - + +" +1601-01-01T04:00:00+04:00,-11644473600.0,4663,IEUser,C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4991 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2019-04-27T23:33:50.134293+04:00,1556393630.134293,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4990 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2019-04-27T23:33:18.699755+04:00,1556393598.699755,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4989 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +" +2019-04-27T23:33:05.308188+04:00,1556393585.308188,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security," + + + + + 4663 + 0 + 0 + 12800 + 0 + 0x8020000000000000 + + + 4988 + + + + + Security + IEWIN7 + + + + + S-1-5-21-3583694148-1414552638-2922671848-1000 + IEUser + IEWIN7 + 0xffa8 + Security + File + C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data + 0x50 + %%4416 + + 0x1 + 0x134c + C:\Users\Defau1t\wsus.exe + +"