Event Id | 4696 |
Source | Microsoft-Windows-Security-Auditing |
Description | A primary token was assigned to process. Subject: Security ID:<Security ID> Account Name:<Account Name> Account Domain:<Domain name> Logon ID:<Logon ID> Process Information: Process ID: <Process ID> Process Name:<Process Name> Target Process: Target Process ID:<Target Process ID> Target Process Name:<Target Process Name> New Token Information: Security ID:<Security ID> Account Name:<Account Name> Account Domain:<Domain name> Logon ID:<Logon ID> |
Event Information | Cause : This event is logged when a service starts or a scheduled task starts under the authority of a different user. Resolution : This is an information event and no user action is required. |
Reference Links |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.