J
JasonW
I am seeing repeated occurances of an failure audit in my security log
MS says that this (SeTcbPrivilege) is a process trying to authenticate as
though it were a user. I have checked the application and system logs and
there does not seem to be a corresponding event. Any suggestions on how I
might track the process accosicated with this event? The hex umber shown
with the Primary Logon ID changes each time, but I don't know any way to
decipher what this means.
Event Type: Failure Audit
Event Source: Security
Event Category: Privilege Use
Event ID: 577
Date: 8/5/2003
Time: 9:23:14 AM
User: J1\RC
Computer: J1
Description:
Privileged Service Called:
Server: Security
Service: -
Primary User Name: RC
Primary Domain: J1
Primary Logon ID: (0x0,0xD82C)
Client User Name: -
Client Domain: -
Client Logon ID: -
Privileges: SeTcbPrivilege
-JasonW
MS says that this (SeTcbPrivilege) is a process trying to authenticate as
though it were a user. I have checked the application and system logs and
there does not seem to be a corresponding event. Any suggestions on how I
might track the process accosicated with this event? The hex umber shown
with the Primary Logon ID changes each time, but I don't know any way to
decipher what this means.
Event Type: Failure Audit
Event Source: Security
Event Category: Privilege Use
Event ID: 577
Date: 8/5/2003
Time: 9:23:14 AM
User: J1\RC
Computer: J1
Description:
Privileged Service Called:
Server: Security
Service: -
Primary User Name: RC
Primary Domain: J1
Primary Logon ID: (0x0,0xD82C)
Client User Name: -
Client Domain: -
Client Logon ID: -
Privileges: SeTcbPrivilege
-JasonW