From 3fe803767b891a90343ea4ca326247f45430009e Mon Sep 17 00:00:00 2001
From: pex7hfbnt <1584881064@qq.com>
Date: Wed, 16 Oct 2024 23:43:35 +0800
Subject: [PATCH] ADD file via upload
---
.../samples/Sample_Object_Access_Events.csv | 14715 ++++++++++++++++
1 file changed, 14715 insertions(+)
create mode 100644 source/samples/Sample_Object_Access_Events.csv
diff --git a/source/samples/Sample_Object_Access_Events.csv b/source/samples/Sample_Object_Access_Events.csv
new file mode 100644
index 0000000..01dbd53
--- /dev/null
+++ b/source/samples/Sample_Object_Access_Events.csv
@@ -0,0 +1,14715 @@
+Date and Time,timestamp,Event ID,Account Name,Object Name,Object Type,Process Name,Computer Name,Channel,Original Event Log
+2020-03-09T02:11:34.340693+04:00,1583705494.340693,4663,IEUser,\Device\HarddiskVolume1\Windows\System32\lsass.exe,Process,C:\Windows\System32\cscript.exe,MSEDGEWIN10,Security,"
+
+
+
+
+ 4663
+ 1
+ 0
+ 12802
+ 0
+ 0x8020000000000000
+
+
+ 314462
+
+
+
+
+ Security
+ MSEDGEWIN10
+
+
+
+
+ S-1-5-21-3461203602-4096304019-2269080069-1000
+ IEUser
+ MSEDGEWIN10
+ 0x33392
+ Security
+ Process
+ \Device\HarddiskVolume1\Windows\System32\lsass.exe
+ 0x558
+ %%4484
+
+ 0x10
+ 0x1688
+ C:\Windows\System32\cscript.exe
+ -
+
+"
+2020-03-09T02:11:34.340693+04:00,1583705494.340693,4663,IEUser,\Device\HarddiskVolume1\Windows\System32\lsass.exe,Process,C:\Windows\System32\cscript.exe,MSEDGEWIN10,Security,"
+
+
+
+
+ 4663
+ 1
+ 0
+ 12802
+ 0
+ 0x8020000000000000
+
+
+ 314462
+
+
+
+
+ Security
+ MSEDGEWIN10
+
+
+
+
+ S-1-5-21-3461203602-4096304019-2269080069-1000
+ IEUser
+ MSEDGEWIN10
+ 0x33392
+ Security
+ Process
+ \Device\HarddiskVolume1\Windows\System32\lsass.exe
+ 0x558
+ %%4484
+
+ 0x10
+ 0x1688
+ C:\Windows\System32\cscript.exe
+ -
+
+"
+2020-03-09T02:11:34.340693+04:00,1583705494.340693,4663,IEUser,\Device\HarddiskVolume1\Windows\System32\lsass.exe,Process,C:\Windows\System32\cscript.exe,MSEDGEWIN10,Security,"
+
+
+
+
+ 4663
+ 1
+ 0
+ 12802
+ 0
+ 0x8020000000000000
+
+
+ 314462
+
+
+
+
+ Security
+ MSEDGEWIN10
+
+
+
+
+ S-1-5-21-3461203602-4096304019-2269080069-1000
+ IEUser
+ MSEDGEWIN10
+ 0x33392
+ Security
+ Process
+ \Device\HarddiskVolume1\Windows\System32\lsass.exe
+ 0x558
+ %%4484
+
+ 0x10
+ 0x1688
+ C:\Windows\System32\cscript.exe
+ -
+
+"
+1601-01-01T04:00:00+04:00,-11644473600.0,4663,IEUser,C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4991
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2019-04-27T23:33:50.134293+04:00,1556393630.134293,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4990
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2019-04-27T23:33:18.699755+04:00,1556393598.699755,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4989
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2019-04-27T23:33:05.308188+04:00,1556393585.308188,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4988
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2020-03-09T02:11:34.340693+04:00,1583705494.340693,4663,IEUser,\Device\HarddiskVolume1\Windows\System32\lsass.exe,Process,C:\Windows\System32\cscript.exe,MSEDGEWIN10,Security,"
+
+
+
+
+ 4663
+ 1
+ 0
+ 12802
+ 0
+ 0x8020000000000000
+
+
+ 314462
+
+
+
+
+ Security
+ MSEDGEWIN10
+
+
+
+
+ S-1-5-21-3461203602-4096304019-2269080069-1000
+ IEUser
+ MSEDGEWIN10
+ 0x33392
+ Security
+ Process
+ \Device\HarddiskVolume1\Windows\System32\lsass.exe
+ 0x558
+ %%4484
+
+ 0x10
+ 0x1688
+ C:\Windows\System32\cscript.exe
+ -
+
+"
+1601-01-01T04:00:00+04:00,-11644473600.0,4663,IEUser,C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4991
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2019-04-27T23:33:50.134293+04:00,1556393630.134293,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4990
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2019-04-27T23:33:18.699755+04:00,1556393598.699755,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4989
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2019-04-27T23:33:05.308188+04:00,1556393585.308188,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4988
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2020-03-09T02:11:34.340693+04:00,1583705494.340693,4663,IEUser,\Device\HarddiskVolume1\Windows\System32\lsass.exe,Process,C:\Windows\System32\cscript.exe,MSEDGEWIN10,Security,"
+
+
+
+
+ 4663
+ 1
+ 0
+ 12802
+ 0
+ 0x8020000000000000
+
+
+ 314462
+
+
+
+
+ Security
+ MSEDGEWIN10
+
+
+
+
+ S-1-5-21-3461203602-4096304019-2269080069-1000
+ IEUser
+ MSEDGEWIN10
+ 0x33392
+ Security
+ Process
+ \Device\HarddiskVolume1\Windows\System32\lsass.exe
+ 0x558
+ %%4484
+
+ 0x10
+ 0x1688
+ C:\Windows\System32\cscript.exe
+ -
+
+"
+1601-01-01T04:00:00+04:00,-11644473600.0,4663,IEUser,C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4991
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2019-04-27T23:33:50.134293+04:00,1556393630.134293,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4990
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2019-04-27T23:33:18.699755+04:00,1556393598.699755,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4989
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2019-04-27T23:33:05.308188+04:00,1556393585.308188,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4988
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2020-03-09T02:11:34.340693+04:00,1583705494.340693,4663,IEUser,\Device\HarddiskVolume1\Windows\System32\lsass.exe,Process,C:\Windows\System32\cscript.exe,MSEDGEWIN10,Security,"
+
+
+
+
+ 4663
+ 1
+ 0
+ 12802
+ 0
+ 0x8020000000000000
+
+
+ 314462
+
+
+
+
+ Security
+ MSEDGEWIN10
+
+
+
+
+ S-1-5-21-3461203602-4096304019-2269080069-1000
+ IEUser
+ MSEDGEWIN10
+ 0x33392
+ Security
+ Process
+ \Device\HarddiskVolume1\Windows\System32\lsass.exe
+ 0x558
+ %%4484
+
+ 0x10
+ 0x1688
+ C:\Windows\System32\cscript.exe
+ -
+
+"
+1601-01-01T04:00:00+04:00,-11644473600.0,4663,IEUser,C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4991
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2019-04-27T23:33:50.134293+04:00,1556393630.134293,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4990
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2019-04-27T23:33:18.699755+04:00,1556393598.699755,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4989
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2019-04-27T23:33:05.308188+04:00,1556393585.308188,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4988
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2020-03-09T02:11:34.340693+04:00,1583705494.340693,4663,IEUser,\Device\HarddiskVolume1\Windows\System32\lsass.exe,Process,C:\Windows\System32\cscript.exe,MSEDGEWIN10,Security,"
+
+
+
+
+ 4663
+ 1
+ 0
+ 12802
+ 0
+ 0x8020000000000000
+
+
+ 314462
+
+
+
+
+ Security
+ MSEDGEWIN10
+
+
+
+
+ S-1-5-21-3461203602-4096304019-2269080069-1000
+ IEUser
+ MSEDGEWIN10
+ 0x33392
+ Security
+ Process
+ \Device\HarddiskVolume1\Windows\System32\lsass.exe
+ 0x558
+ %%4484
+
+ 0x10
+ 0x1688
+ C:\Windows\System32\cscript.exe
+ -
+
+"
+1601-01-01T04:00:00+04:00,-11644473600.0,4663,IEUser,C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4991
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2019-04-27T23:33:50.134293+04:00,1556393630.134293,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4990
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2019-04-27T23:33:18.699755+04:00,1556393598.699755,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4989
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2019-04-27T23:33:05.308188+04:00,1556393585.308188,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4988
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2020-03-09T02:11:34.340693+04:00,1583705494.340693,4663,IEUser,\Device\HarddiskVolume1\Windows\System32\lsass.exe,Process,C:\Windows\System32\cscript.exe,MSEDGEWIN10,Security,"
+
+
+
+
+ 4663
+ 1
+ 0
+ 12802
+ 0
+ 0x8020000000000000
+
+
+ 314462
+
+
+
+
+ Security
+ MSEDGEWIN10
+
+
+
+
+ S-1-5-21-3461203602-4096304019-2269080069-1000
+ IEUser
+ MSEDGEWIN10
+ 0x33392
+ Security
+ Process
+ \Device\HarddiskVolume1\Windows\System32\lsass.exe
+ 0x558
+ %%4484
+
+ 0x10
+ 0x1688
+ C:\Windows\System32\cscript.exe
+ -
+
+"
+1601-01-01T04:00:00+04:00,-11644473600.0,4663,IEUser,C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4991
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2019-04-27T23:33:50.134293+04:00,1556393630.134293,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4990
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2019-04-27T23:33:18.699755+04:00,1556393598.699755,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4989
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2019-04-27T23:33:05.308188+04:00,1556393585.308188,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4988
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452905
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452904
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452903
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452902
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452901
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452900
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452899
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452898
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452897
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452896
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452895
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452894
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452893
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452892
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452891
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452890
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452889
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452888
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452887
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452886
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452885
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452884
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452883
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452882
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452881
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452880
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452879
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452878
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452877
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452876
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452875
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452874
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452873
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452872
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452871
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452870
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452869
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452868
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452867
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452866
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452865
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452864
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452863
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452862
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452861
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452860
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452859
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452858
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452857
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452856
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452855
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452854
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452853
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452852
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452851
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452850
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452849
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452848
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452847
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452846
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452845
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452844
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452843
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452842
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452841
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452840
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452839
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452838
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452837
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452836
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452835
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452834
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452833
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452832
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452831
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452830
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452829
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452828
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452827
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452826
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.215261+04:00,1553038515.215261,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452825
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.215261+04:00,1553038515.215261,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452824
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.215261+04:00,1553038515.215261,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452823
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.205246+04:00,1553038515.205246,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452822
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.185218+04:00,1553038515.185218,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452821
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.185218+04:00,1553038515.185218,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452820
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.045016+04:00,1553038515.045016,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452819
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.045016+04:00,1553038515.045016,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452818
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:14.904814+04:00,1553038514.904814,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452817
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:14.904814+04:00,1553038514.904814,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452816
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:14.764613+04:00,1553038514.764613,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452815
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:14.764613+04:00,1553038514.764613,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452814
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:14.634426+04:00,1553038514.634426,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452813
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+1601-01-01T04:00:00+04:00,-11644473600.0,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452922
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.365477+04:00,1553038515.365477,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452921
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.365477+04:00,1553038515.365477,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452920
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.365477+04:00,1553038515.365477,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452919
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.365477+04:00,1553038515.365477,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452918
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452917
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452916
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452915
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452914
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452913
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452912
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452911
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452910
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452909
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452908
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452907
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452906
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452905
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452904
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452903
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452902
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452901
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452900
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452899
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452898
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452897
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452896
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452895
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452894
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452893
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452892
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452891
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452890
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452889
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452888
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452887
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452886
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452885
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452884
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452883
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452882
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452881
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452880
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452879
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452878
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452877
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452876
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452875
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452874
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452873
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452872
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452871
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452870
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452869
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452868
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452867
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452866
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452865
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452864
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452863
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452862
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452861
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452860
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452859
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452858
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452857
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452856
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452855
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452854
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452853
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452852
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452851
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452850
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452849
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452848
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452847
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452846
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452845
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452844
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452843
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452842
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452841
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452840
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452839
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452838
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452837
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452836
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452835
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452834
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452833
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452832
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452831
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452830
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452829
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452828
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452827
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452826
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.215261+04:00,1553038515.215261,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452825
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.215261+04:00,1553038515.215261,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452824
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.215261+04:00,1553038515.215261,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452823
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.205246+04:00,1553038515.205246,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452822
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.185218+04:00,1553038515.185218,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452821
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.185218+04:00,1553038515.185218,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452820
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.045016+04:00,1553038515.045016,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452819
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.045016+04:00,1553038515.045016,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452818
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:14.904814+04:00,1553038514.904814,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452817
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:14.904814+04:00,1553038514.904814,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452816
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:14.764613+04:00,1553038514.764613,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452815
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:14.764613+04:00,1553038514.764613,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452814
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:14.634426+04:00,1553038514.634426,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452813
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+1601-01-01T04:00:00+04:00,-11644473600.0,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452922
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.365477+04:00,1553038515.365477,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452921
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.365477+04:00,1553038515.365477,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452920
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.365477+04:00,1553038515.365477,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452919
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.365477+04:00,1553038515.365477,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452918
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452917
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452916
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452915
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452914
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452913
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452912
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452911
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452910
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452909
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452908
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452907
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452906
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2020-03-09T02:11:34.340693+04:00,1583705494.340693,4663,IEUser,\Device\HarddiskVolume1\Windows\System32\lsass.exe,Process,C:\Windows\System32\cscript.exe,MSEDGEWIN10,Security,"
+
+
+
+
+ 4663
+ 1
+ 0
+ 12802
+ 0
+ 0x8020000000000000
+
+
+ 314462
+
+
+
+
+ Security
+ MSEDGEWIN10
+
+
+
+
+ S-1-5-21-3461203602-4096304019-2269080069-1000
+ IEUser
+ MSEDGEWIN10
+ 0x33392
+ Security
+ Process
+ \Device\HarddiskVolume1\Windows\System32\lsass.exe
+ 0x558
+ %%4484
+
+ 0x10
+ 0x1688
+ C:\Windows\System32\cscript.exe
+ -
+
+"
+1601-01-01T04:00:00+04:00,-11644473600.0,4663,IEUser,C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4991
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2019-04-27T23:33:50.134293+04:00,1556393630.134293,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4990
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2019-04-27T23:33:18.699755+04:00,1556393598.699755,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4989
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2019-04-27T23:33:05.308188+04:00,1556393585.308188,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4988
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2020-03-09T02:11:34.340693+04:00,1583705494.340693,4663,IEUser,\Device\HarddiskVolume1\Windows\System32\lsass.exe,Process,C:\Windows\System32\cscript.exe,MSEDGEWIN10,Security,"
+
+
+
+
+ 4663
+ 1
+ 0
+ 12802
+ 0
+ 0x8020000000000000
+
+
+ 314462
+
+
+
+
+ Security
+ MSEDGEWIN10
+
+
+
+
+ S-1-5-21-3461203602-4096304019-2269080069-1000
+ IEUser
+ MSEDGEWIN10
+ 0x33392
+ Security
+ Process
+ \Device\HarddiskVolume1\Windows\System32\lsass.exe
+ 0x558
+ %%4484
+
+ 0x10
+ 0x1688
+ C:\Windows\System32\cscript.exe
+ -
+
+"
+1601-01-01T04:00:00+04:00,-11644473600.0,4663,IEUser,C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4991
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2019-04-27T23:33:50.134293+04:00,1556393630.134293,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4990
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2019-04-27T23:33:18.699755+04:00,1556393598.699755,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4989
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2019-04-27T23:33:05.308188+04:00,1556393585.308188,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4988
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452905
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452904
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452903
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452902
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452901
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452900
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452899
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452898
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452897
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452896
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452895
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452894
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452893
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452892
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452891
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452890
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452889
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452888
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452887
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452886
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452885
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452884
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452883
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452882
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452881
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452880
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452879
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452878
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452877
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452876
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452875
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452874
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452873
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452872
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452871
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452870
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452869
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452868
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452867
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.325419+04:00,1553038515.325419,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452866
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452865
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452864
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452863
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452862
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452861
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452860
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452859
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452858
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452857
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452856
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452855
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452854
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452853
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452852
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452851
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452850
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452849
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.315405+04:00,1553038515.315405,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452848
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452847
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452846
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452845
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452844
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452843
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452842
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452841
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452840
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452839
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452838
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452837
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452836
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452835
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452834
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452833
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452832
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452831
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452830
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452829
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452828
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452827
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.295376+04:00,1553038515.295376,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452826
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.215261+04:00,1553038515.215261,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452825
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.215261+04:00,1553038515.215261,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452824
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.215261+04:00,1553038515.215261,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452823
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.205246+04:00,1553038515.205246,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452822
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.185218+04:00,1553038515.185218,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452821
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.185218+04:00,1553038515.185218,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452820
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.045016+04:00,1553038515.045016,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452819
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.045016+04:00,1553038515.045016,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452818
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:14.904814+04:00,1553038514.904814,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452817
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:14.904814+04:00,1553038514.904814,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452816
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:14.764613+04:00,1553038514.764613,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452815
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:14.764613+04:00,1553038514.764613,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452814
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x520
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:14.634426+04:00,1553038514.634426,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452813
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x468
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+1601-01-01T04:00:00+04:00,-11644473600.0,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452922
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.365477+04:00,1553038515.365477,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452921
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.365477+04:00,1553038515.365477,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452920
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.365477+04:00,1553038515.365477,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452919
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.365477+04:00,1553038515.365477,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452918
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452917
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452916
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452915
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452914
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452913
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452912
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452911
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452910
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452909
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452908
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x1ac
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452907
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2019-03-20T03:35:15.335434+04:00,1553038515.335434,4663,LOCAL SERVICE,\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa,Key,C:\Windows\System32\svchost.exe,PC01.example.corp,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12801
+ 0
+ 0x8020000000000000
+
+
+ 452906
+
+
+
+
+ Security
+ PC01.example.corp
+
+
+
+
+ S-1-5-19
+ LOCAL SERVICE
+ NT AUTHORITY
+ 0x3e5
+ Security
+ Key
+ \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Lsa
+ 0x420
+ %%4432
+
+ 0x1
+ 0x5a8
+ C:\Windows\System32\svchost.exe
+
+"
+2020-03-09T02:11:34.340693+04:00,1583705494.340693,4663,IEUser,\Device\HarddiskVolume1\Windows\System32\lsass.exe,Process,C:\Windows\System32\cscript.exe,MSEDGEWIN10,Security,"
+
+
+
+
+ 4663
+ 1
+ 0
+ 12802
+ 0
+ 0x8020000000000000
+
+
+ 314462
+
+
+
+
+ Security
+ MSEDGEWIN10
+
+
+
+
+ S-1-5-21-3461203602-4096304019-2269080069-1000
+ IEUser
+ MSEDGEWIN10
+ 0x33392
+ Security
+ Process
+ \Device\HarddiskVolume1\Windows\System32\lsass.exe
+ 0x558
+ %%4484
+
+ 0x10
+ 0x1688
+ C:\Windows\System32\cscript.exe
+ -
+
+"
+1601-01-01T04:00:00+04:00,-11644473600.0,4663,IEUser,C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4991
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Local\Google\Chrome\User Data\Default\Login Data
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2019-04-27T23:33:50.134293+04:00,1556393630.134293,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4990
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\logins.json
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2019-04-27T23:33:18.699755+04:00,1556393598.699755,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4989
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Roaming\Mozilla\Firefox\Profiles\kushu3sd.default\key4.db
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"
+2019-04-27T23:33:05.308188+04:00,1556393585.308188,4663,IEUser,C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data,File,C:\Users\Defau1t\wsus.exe,IEWIN7,Security,"
+
+
+
+
+ 4663
+ 0
+ 0
+ 12800
+ 0
+ 0x8020000000000000
+
+
+ 4988
+
+
+
+
+ Security
+ IEWIN7
+
+
+
+
+ S-1-5-21-3583694148-1414552638-2922671848-1000
+ IEUser
+ IEWIN7
+ 0xffa8
+ Security
+ File
+ C:\Users\IEUser\AppData\Roaming\Opera Software\Opera Stable\Login Data
+ 0x50
+ %%4416
+
+ 0x1
+ 0x134c
+ C:\Users\Defau1t\wsus.exe
+
+"