Event ID: 577

Privileged Service Called

Privileged Service Called:
    Server:            %1
    Service:           %2
    Primary User Name: %3
    Primary Domain:    %4
    Primary Logon ID:  %5
    Client User Name:  %6
    Client Domain:     %7
    Client Logon ID:   %8
    Privileges:        %9
    Process ID:        %10
    Process Name:      %11

Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /category:"Privilege Use"
How to enable Windows Auditing

Audit Category:
Privilege Use

LEFT/RIGHT arrow keys for navigation

Back to List