Coming soon - Get a detailed view of why an account is flagged as spam!
view details

This post has been de-listed

It is no longer included in search results and normal feeds (front page, hot posts, subreddit posts, etc). It remains visible only via the author's post history.

4
Lsass access lsass
Post Flair (click to view more posts with a particular flair)
Post Body

Hello everyone, I have a problem about event 4656 that I have never encountered before. Please explain to me. I dont know value "Access Mask: 0x1478 " and why lsass access lsass, Its false positive?

Detail event:

%NICWIN-4-Security_4656_Microsoft-Windows-Security-Auditing: Security,rn=5487362336 cid=852 eid=844,Mon Nov 27 09:09:32 2023,4656,Microsoft-Windows-Security-Auditing,,Audit Success,srv-ex16.local,Kernel Object,,A handle to an object was requested. Subject: Security ID: S-1-5-18 Account Name: SRV-EX16$ Account Domain: test Logon ID: 0x3E7 Object: Object Server: Security Object Type: Process Object Name: \Device\HarddiskVolume2\Windows\System32\lsass.exe Handle ID: 0x66d04 Resource Attributes: - Process Information: Process ID: 0x34c Process Name: C:\Windows\System32\lsass.exe Access Request Information: Transaction ID: {00000000-0000-0000-0000-000000000000} Accesses: Perform virtual memory operation Read from process memory Write to process memory Duplicate handle into or out of process Query process information Undefined Access (no effect) Bit 12 Access Reasons: - Access Mask: 0x1478 Privileges Used for Access Check: - Restricted SID Count: 0

Author
Account Strength
80%
Account Age
4 years
Verified Email
Yes
Verified Flair
No
Total Karma
4
Link Karma
4
Comment Karma
n/a
Profile updated: 1 day ago

Subreddit

Post Details

We try to extract some basic information from the post title. This is not always successful or accurate, please use your best judgement and compare these values to the post title and body for confirmation.
Posted
11 months ago