Where can I report criminal intent found on the dark web? If the SID cannot be resolved, you will see the source data in the event.Note  A security identifier (SID) is a unique value of variable length used to identify a trustee (security This is one of the trusted logon processes identified by 4611. Windows Security Log Event ID 4648 Operating Systems Windows 2008 R2 and 7 Windows 2012 R2 and 8.1 Windows 2016 and 10 Category • SubcategoryLogon/Logoff • Logon Type Success Corresponding events in

Event details from the PC (Windows 7 Professional) out on the floor: A logon was attempted using explicit credentials. DateTime 10.10.2000 19:00:00 Source Name of an Application or System Service originating the event. It is a 128-bit integer number used to identify resources, activities or instances.Target Server:Target Server Name [Type = UnicodeString]: the name of the server on which the new process was run. Subject: Security ID: Account Name: Account Domain: Logon ID: Logon GUID: Account Whose Credentials Were Used: Account Name: Account Domain: Logon GUID: Target

Subject: Security ID: WIN-R9H529RIO4Y\Administrator Account Name: Administrator Account Domain: WIN-R9H529RIO4Y Logon ID: 0x1ba0e Logon GUID: {00000000-0000-0000-0000-000000000000} Account Whose Credentials Were Used: Account Name: [email protected]

If you've printed using your AD credentials (say to a network printer on the domain), then spoolsv.exe will be using those credentials in order to complete your print request. The system uses the SID in the access token to identify the user in all subsequent interactions with Windows security.

Again, thank you very much guys - I am learning a lot about this from here ! Process ID is the process ID specified when the executable started as logged in 4688.

Unfortunately Subject does not identify the end user.

For instance logging on interactively to a member server (Win2008 RC1) with a domain account produces an instance of this event in addition to 2 instances of 4624. For more information about SIDs, see Security identifiers.Account Name [Type = UnicodeString]: the name of the account that requested the new logon session with explicit credentials.Account Domain [Type = UnicodeString]: subject's Each account has a unique SID that is issued by an authority, such as an Active Directory domain controller, and stored in a security database.