﻿<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>WinSecWiki » Windows Security Settings » Popular Articles</title><generator>InstantKB.NET 2.0.3</generator><description>WinSecWiki</description><link>http://www.ultimatewindowssecurity.com/wiki/</link><webMaster>noreply@ultimatewindowssecurity.com</webMaster><lastBuildDate>Wed, 22 May 2013 08:30:09 GMT</lastBuildDate><ttl>20</ttl><item><title>Other System Events</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50618.aspx</link><description>&lt;font color="#000000"&gt;&lt;font size="1"&gt;This is a hodge podge of events dominated by Windows Firewall system service activity which would seem to belong elsewhere. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=4&amp;amp;subcatid=6"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4615" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4615"&gt;4615&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4615" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4615"&gt;Invalid use of LPC port.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5024" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5024"&gt;5024&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5024" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5024"&gt;The Windows Firewall Service has started successfully.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5025" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5025"&gt;5025&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5025" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5025"&gt;The Windows Firewall Service has been stopped.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5027" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5027"&gt;5027&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5027" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5027"&gt;The Windows Firewall Service was unable to retrieve the security policy from the local storage&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5028" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5028"&gt;5028&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5028" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5028"&gt;The Windows Firewall Service was unable to parse the new security policy.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5029" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5029"&gt;5029&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5029" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5029"&gt;The Windows Firewall Service failed to initialize the driver.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5030" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5030"&gt;5030&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5030" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5030"&gt;The Windows Firewall Service failed to start.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5032" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5032"&gt;5032&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5032" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5032"&gt;Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5033" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5033"&gt;5033&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5033" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5033"&gt;The Windows Firewall Driver has started successfully.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5034" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5034"&gt;5034&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5034" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5034"&gt;The Windows Firewall Driver has been stopped.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5035" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5035"&gt;5035&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5035" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5035"&gt;The Windows Firewall Driver failed to start.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5037" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5037"&gt;5037&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5037" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5037"&gt;The Windows Firewall Driver detected critical runtime error. Terminating&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5058" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5058"&gt;5058&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5058" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5058"&gt;Key file operation.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5059" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5059"&gt;5059&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5059" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5059"&gt;Key migration operation.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 17:42:33 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>IPsec Driver</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50617.aspx</link><description>&lt;font color="#000000" size="1"&gt;This category tracks activity related to the operation of the IPSec system service. For events related to IPSec network traffic see the IPSec subcategories in the &lt;/font&gt;&lt;a title="Audit Category: Logon/Logoff (Vista and Windows Server 2008)" class="pagelink" href="/wiki/WindowsSecuritySettings/64"&gt;&lt;font color="#000000" size="1"&gt;Logon/Logoff&lt;/font&gt;&lt;/a&gt;&lt;font color="#000000"&gt;&lt;font size="1"&gt; category. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=4&amp;amp;subcatid=5"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5478" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5478"&gt;5478&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5478" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5478"&gt;IPsec Services has started successfully.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5479" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5479"&gt;5479&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5479" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5479"&gt;IPsec Services has been shut down successfully&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5480" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5480"&gt;5480&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5480" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5480"&gt;IPsec Services failed to get the complete list of network interfaces on the computer.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5483" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5483"&gt;5483&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5483" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5483"&gt;IPsec Services failed to initialize RPC server. IPsec Services could not be started..&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5484" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5484"&gt;5484&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5484" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5484"&gt;IPsec Services has experienced a critical failure and has been shut down.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5485" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5485"&gt;5485&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5485" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5485"&gt;IPsec Services failed to process some IPsec filters on a plug-and-play event for network interfaces.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 17:41:21 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>System Integrity</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50616.aspx</link><description>&lt;font color="#000000"&gt;&lt;font size="1"&gt;This category logs at least 3 events that could impact the over all integrity of the system. As will all subcategories you must use auditpol to enable or disable it.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=4&amp;amp;subcatid=4"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5038" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5038"&gt;5038&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5038" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5038"&gt;Code integrity determined that the image hash of a file is not valid.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5056" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5056"&gt;5056&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5056" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5056"&gt;A cryptographic self test was performed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5061" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5061"&gt;5061&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5061" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5061"&gt;Cryptographic operation.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 17:39:58 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Security System Extension</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50615.aspx</link><description>&lt;font color="#000000"&gt;&lt;font size="1"&gt;The Windows security infrastructure supports extensibility and through various types of plug-ins and this category logs all activity with such plug-ins. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=4&amp;amp;subcatid=3"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4610" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4610"&gt;4610&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4610" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4610"&gt;An authentication package has been loaded by the Local Security Authority&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4611" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4611"&gt;4611&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4611" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4611"&gt;A trusted logon process has been registered with the Local Security Authority&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4614" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4614"&gt;4614&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4614" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4614"&gt;A notification package has been loaded by the Security Account Manager.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4622" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4622"&gt;4622&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4622" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4622"&gt;A security package has been loaded by the Local Security Authority.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4697" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4697"&gt;4697&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4697" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4697"&gt;A service was installed in the system&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 17:38:48 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Security State Change</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50614.aspx</link><description>&lt;font color="#000000" size="1"&gt;This category tracks keys system changes such as system clock changes and the startup and shutdown of the actual system. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=4&amp;amp;subcatid=2"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/span&gt;&lt;br /&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4608" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4608"&gt;4608&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4608" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4608"&gt;Windows is starting up&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4609" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4609"&gt;4609&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4609" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4609"&gt;Windows is shutting down&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4616" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4616"&gt;4616&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4616" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4616"&gt;The system time was changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 17:37:37 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>RPC Events</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50613.aspx</link><description>&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;&lt;font size="2"&gt;&lt;font color="#000000"&gt;&lt;font size="1"&gt;This category logs events related to Remote Procedure Call security. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.&lt;br /&gt;&lt;br /&gt;Coverage on events generated by this category are currently in the &lt;/font&gt;&lt;a href="/securitylog/encyclopedia/Default.aspx?catid=3&amp;amp;subcatid=34"&gt;&lt;font size="1"&gt;Security Log Encyclopedia&lt;/font&gt;&lt;/a&gt;&lt;font size="1"&gt;:&lt;/font&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4816" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4816"&gt;4816&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4816" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4816"&gt;RPC detected an integrity violation while decrypting an incoming message.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5712" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5712"&gt;5712&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5712" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5712"&gt;A Remote Procedure Call (RPC) was attempted.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;br /&gt;</description><pubDate>Tue, 28 Aug 2012 17:36:11 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>DPAPI Activity</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50612.aspx</link><description>&lt;font color="#000000"&gt;&lt;font size="1"&gt;This category reports activity concerning the Data Protection API. Per Microsoft: "The Data Protection API (DPAPI) helps to protect data in Windows 2000 and later operating systems. DPAPI is used to help protect private keys, stored credentials (in Windows XP and later), and other confidential information that the operating system or a program wants to keep confidential." To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=3&amp;amp;subcatid=33"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4692" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4692"&gt;4692&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4692" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4692"&gt;Backup of data protection master key was attempted&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4693" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4693"&gt;4693&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4693" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4693"&gt;Recovery of data protection master key was attempted.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4694" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4694"&gt;4694&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4694" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4694"&gt;Protection of auditable protected data was attempted&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4695" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4695"&gt;4695&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4695" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4695"&gt;Unprotection of auditable protected data was attempted.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 17:34:54 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Process Termination</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50611.aspx</link><description>&lt;font color="#000000"&gt;&lt;font size="1"&gt;This category is logged on all types of computers and allows you to track the completion of every program that executes on the local computer. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=3&amp;amp;subcatid=32"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4689" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4689"&gt;4689&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4689" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4689"&gt;A process has exited&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 17:33:19 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Process Creation</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50610.aspx</link><description>&lt;font size="1"&gt;&lt;font color="#000000"&gt;This category is logged on all types of computers and allows you to track every program that starts on the local computer. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;/font&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;&lt;font size="2"&gt;&lt;font size="1"&gt;Coverage on events generated by this category are currently in the &lt;/font&gt;&lt;a href="/securitylog/encyclopedia/Default.aspx?catid=3&amp;amp;subcatid=31"&gt;&lt;font size="1"&gt;Security Log Encyclopedia&lt;/font&gt;&lt;/a&gt;&lt;font size="1"&gt;:&lt;/font&gt;&lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4688" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4688"&gt;4688&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4688" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4688"&gt;A new process has been created&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4696" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4696"&gt;4696&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4696" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4696"&gt;A primary token was assigned to process.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 17:32:08 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Other Privilege Use Events</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50609.aspx</link><description>&lt;font color="#000000"&gt;I have not observed any events logged by this category. If you have, help us out and post them in this event's discussion forum.&lt;br /&gt;&lt;br /&gt;To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.&lt;/font&gt; </description><pubDate>Tue, 28 Aug 2012 17:30:25 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Non Sensitive Privilege Use</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50608.aspx</link><description>This category supposedly allows you to track the exercise of so-called non-sensitive privileges which are assigned in &lt;a title="User Rights Assignment " class="pagelink" href="/wiki/WindowsSecuritySettings/18"&gt;User Rights Assignment&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;I have not observed any events logged by this category. If you have, help us out and post them in this event's discussion forum.&lt;br /&gt;&lt;br /&gt;To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy. </description><pubDate>Tue, 28 Aug 2012 17:29:10 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Sensitive Privilege Use</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50607.aspx</link><description>&lt;font color="#000000" size="1"&gt;This category allows you to track the exercise of so-called sensitive privileges which are assigned in &lt;/font&gt;&lt;a title="User Rights Assignment " class="pagelink" href="/wiki/WindowsSecuritySettings/18"&gt;&lt;font color="#000000" size="1"&gt;User Rights Assignment&lt;/font&gt;&lt;/a&gt;&lt;font size="1"&gt;&lt;font color="#000000"&gt;. But the value of these events is compromised by factors explained in the articles below. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy&lt;/font&gt;&lt;/font&gt;&lt;font color="#000000"&gt;&lt;font size="1"&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=8&amp;amp;subcatid=28"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4673" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4673"&gt;4673&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4673" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4673"&gt;A privileged service was called&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4674" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4674"&gt;4674&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4674" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4674"&gt;An operation was attempted on a privileged object&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 17:27:38 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Other Policy Change Events</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50606.aspx</link><description>&lt;font color="#000000" size="1"&gt;So far I've only found one event in this category and it should clearly be in the &lt;/font&gt;&lt;a title="Audit Category: Filtering Platform Policy Change (Vista and Windows Server 2008)" class="pagelink" href="/wiki/WindowsSecuritySettings/Filtering-Platform-Policy-Change"&gt;&lt;font color="#000000" size="1"&gt;Filtering Platform Policy Change&lt;/font&gt;&lt;/a&gt;&lt;font color="#000000" size="1"&gt; subcategory instead. As with all subcategories you must use auditpol to enable to disable these events.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=5&amp;amp;subcatid=40"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/span&gt;&lt;br /&gt;&lt;/font&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5447" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5447"&gt;5447&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5447" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5447"&gt;A Windows Filtering Platform filter has been changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 17:25:52 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Filtering Platform Policy Change</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50605.aspx</link><description>&lt;font color="#000000"&gt;&lt;font size="1"&gt;This chatty category documents the current configuration of the Windows Filtering Platform (related for lower level than the Windows Firewall) whenever it starts as well as any changes to it's configuration. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=5&amp;amp;subcatid=39"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5440" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5440"&gt;5440&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5440" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5440"&gt;The following callout was present when the Windows Filtering Platform Base Filtering Engine started&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5441" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5441"&gt;5441&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5441" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5441"&gt;The following filter was present when the Windows Filtering Platform Base Filtering Engine started.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5442" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5442"&gt;5442&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5442" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5442"&gt;The following provider was present when the Windows Filtering Platform Base Filtering Engine started.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5443" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5443"&gt;5443&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5443" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5443"&gt;The following provider context was present when the Windows Filtering Platform Base Filtering Engine started.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5444" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5444"&gt;5444&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5444" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5444"&gt;The following sub-layer was present when the Windows Filtering Platform Base Filtering Engine started.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5446" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5446"&gt;5446&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5446" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5446"&gt;A Windows Filtering Platform callout has been changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5448" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5448"&gt;5448&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5448" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5448"&gt;A Windows Filtering Platform provider has been changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5449" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5449"&gt;5449&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5449" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5449"&gt;A Windows Filtering Platform provider context has been changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5450" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5450"&gt;5450&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5450" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5450"&gt;A Windows Filtering Platform sub-layer has been changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 17:24:23 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>MPSSVC Rule-Level Policy Change</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50604.aspx</link><description>&lt;font color="#000000"&gt;&lt;font size="1"&gt;This chatty category documents the current configuration of the Windows Firewall (aka MPSSVC) whenever it starts as well as any changes to it's configuration. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=5&amp;amp;subcatid=38"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4944" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4944"&gt;4944&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4944" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4944"&gt;The following policy was active when the Windows Firewall started.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4945" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4945"&gt;4945&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4945" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4945"&gt;A rule was listed when the Windows Firewall started.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4946" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4946"&gt;4946&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4946" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4946"&gt;A change has been made to Windows Firewall exception list. A rule was added.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4947" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4947"&gt;4947&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4947" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4947"&gt;A change has been made to Windows Firewall exception list. A rule was modified.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4948" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4948"&gt;4948&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4948" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4948"&gt;A change has been made to Windows Firewall exception list. A rule was deleted.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4949" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4949"&gt;4949&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4949" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4949"&gt;Windows Firewall settings were restored to the default values.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4950" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4950"&gt;4950&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4950" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4950"&gt;A Windows Firewall setting has changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4951" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4951"&gt;4951&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4951" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4951"&gt;A rule has been ignored because its major version number was not recognized by Windows Firewall.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4952" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4952"&gt;4952&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4952" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4952"&gt;Parts of a rule have been ignored because its minor version number was not recognized by Windows Firewall.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4954" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4954"&gt;4954&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4954" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4954"&gt;Windows Firewall Group Policy settings has changed. The new settings have been applied.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4956" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4956"&gt;4956&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4956" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4956"&gt;Windows Firewall has changed the active profile.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4957" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4957"&gt;4957&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4957" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4957"&gt;Windows Firewall did not apply the following rule:&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4958" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4958"&gt;4958&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4958" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4958"&gt;Windows Firewall did not apply the following rule because the rule referred to items not configured on this computer:&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;div id="MainFooterDiv"&gt;&lt;!-- Used for layout purposes only --&gt;&lt;/div&gt;</description><pubDate>Tue, 28 Aug 2012 17:22:38 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Authorization Policy Change</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50603.aspx</link><description>&lt;font color="#000000" size="1"&gt;I've only isolated a few events logged by this category. Let me know via a discussion post on this event if you know of more. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.&lt;br /&gt;&lt;br /&gt;&lt;/font&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;&lt;font color="#000000" size="2"&gt;&lt;font size="1"&gt;Coverage on events generated by this category are currently in the &lt;/font&gt;&lt;a href="/securitylog/encyclopedia/Default.aspx?catid=5&amp;amp;subcatid=37"&gt;&lt;font size="1"&gt;Security Log Encyclopedia&lt;/font&gt;&lt;/a&gt;&lt;font size="1"&gt;:&lt;/font&gt;&lt;br /&gt;&lt;/font&gt;&lt;span&gt;&lt;font color="#000000" size="2"&gt;&lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4704" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4704"&gt;4704&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4704" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4704"&gt;A user right was assigned.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4705" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4705"&gt;4705&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4705" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4705"&gt;A user right was removed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4714" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4714"&gt;4714&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4714" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4714"&gt;Encrypted data recovery policy was changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 17:21:14 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Authentication Policy Change</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50602.aspx</link><description>&lt;font color="#000000"&gt;&lt;font size="1"&gt;This category tracks any configuration changes that would impact how user accounts are authenticated although password and lockout policies are conspicuously missing. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.&lt;br /&gt;&lt;br /&gt;&lt;/font&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;&lt;font size="2"&gt;&lt;font size="1"&gt;Coverage on events generated by this category are currently in the &lt;/font&gt;&lt;a href="/securitylog/encyclopedia/Default.aspx?catid=5&amp;amp;subcatid=36"&gt;&lt;font size="1"&gt;Security Log Encyclopedia&lt;/font&gt;&lt;/a&gt;&lt;font size="1"&gt;:&lt;/font&gt;&lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4706" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4706"&gt;4706&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4706" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4706"&gt;A new trust was created to a domain.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4707" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4707"&gt;4707&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4707" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4707"&gt;A trust to a domain was removed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4713" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4713"&gt;4713&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4713" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4713"&gt;Kerberos policy was changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4716" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4716"&gt;4716&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4716" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4716"&gt;Trusted domain information was modified.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4717" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4717"&gt;4717&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4717" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4717"&gt;System security access was granted to an account.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4718" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4718"&gt;4718&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4718" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4718"&gt;System security access was removed from an account.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4865" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4865"&gt;4865&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4865" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4865"&gt;A trusted forest information entry was added.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4866" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4866"&gt;4866&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4866" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4866"&gt;A trusted forest information entry was removed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4867" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4867"&gt;4867&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4867" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4867"&gt;A trusted forest information entry was modified.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 17:16:14 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Audit Policy Change</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50601.aspx</link><description>&lt;font size="1"&gt;&lt;font color="#000000"&gt;This category tracks any policy changes that would affect what gets reported to the security log. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy&lt;/font&gt;&lt;/font&gt;&lt;font size="1"&gt;&lt;font color="#000000"&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=5&amp;amp;subcatid=35"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/span&gt;&lt;/font&gt;&lt;br /&gt;&lt;/font&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4715" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4715"&gt;4715&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4715" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4715"&gt;The audit policy (SACL) on an object was changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4719" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4719"&gt;4719&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4719" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4719"&gt;System audit policy was changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4902" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4902"&gt;4902&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4902" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4902"&gt;The Per-user audit policy table was created.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4904" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4904"&gt;4904&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4904" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4904"&gt;An attempt was made to register a security event source.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4905" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4905"&gt;4905&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4905" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4905"&gt;An attempt was made to unregister a security event source.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4906" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4906"&gt;4906&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4906" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4906"&gt;The CrashOnAuditFail value has changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4907" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4907"&gt;4907&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4907" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4907"&gt;Auditing settings on object were changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4912" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4912"&gt;4912&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4912" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4912"&gt;Per User Audit Policy was changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 17:11:41 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Other Object Access Events</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50600.aspx</link><description>&lt;font color="#000000"&gt;&lt;font size="1"&gt;This is a hodgepodge of miscellaneous Object Access events. The most valuable event in this category are the ones allowing you to monitor changes to Scheduled Tasks and file deletion. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=9&amp;amp;subcatid=27"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4656" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4656"&gt;4656&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4656" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4656"&gt;A handle to an object was requested&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4658" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4658"&gt;4658&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4658" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4658"&gt;The handle to an object was closed&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4659" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4659"&gt;4659&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4659" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4659"&gt;A handle to an object was requested with intent to delete&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4660" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4660"&gt;4660&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4660" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4660"&gt;An object was deleted&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4663" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4663"&gt;4663&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4663" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4663"&gt;An attempt was made to access an object&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4664" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4664"&gt;4664&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4664" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4664"&gt;An attempt was made to create a hard link.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4691" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4691"&gt;4691&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4691" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4691"&gt;Indirect access to an object was requested&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4698" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4698"&gt;4698&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4698" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4698"&gt;A scheduled task was created&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4699" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4699"&gt;4699&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4699" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4699"&gt;A scheduled task was deleted.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4700" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4700"&gt;4700&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4700" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4700"&gt;A scheduled task was enabled.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4701" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4701"&gt;4701&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4701" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4701"&gt;A scheduled task was disabled&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4702" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4702"&gt;4702&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4702" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4702"&gt;A scheduled task was updated.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 17:09:08 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Filtering Platform Connection</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50599.aspx</link><description>&lt;font color="#000000"&gt;&lt;font size="1"&gt;As the name would indicate, this category logs events associated with network connections permitted or blocked by Windows Firewall and the lower level Windows Filtering Platform. What's it doing in the higher level Object Access category? Who knows. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=9&amp;amp;subcatid=26"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5031" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5031"&gt;5031&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5031" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5031"&gt;The Windows Firewall Service blocked an application from accepting incoming connections on the network.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5154" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5154"&gt;5154&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5154" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5154"&gt;The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5155" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5155"&gt;5155&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5155" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5155"&gt;The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5156" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5156"&gt;5156&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5156" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5156"&gt;The Windows Filtering Platform has allowed a connection&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5157" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5157"&gt;5157&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5157" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5157"&gt;The Windows Filtering Platform has blocked a connection&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5158" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5158"&gt;5158&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5158" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5158"&gt;The Windows Filtering Platform has permitted a bind to a local port.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5159" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5159"&gt;5159&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5159" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5159"&gt;The Windows Filtering Platform has blocked a bind to a local port.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 17:07:33 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Filtering Platform Packet Drop</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50598.aspx</link><description>&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;&lt;span&gt;&lt;font color="#000000" size="2"&gt;&lt;font color="#000000"&gt;&lt;font size="1"&gt;As the name would indicate, the category logs events associated with packets blocked by Windows Firewall and the lower level Windows Filtering Platform. What's it doing in the higher level Object Access category? Who knows. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;&lt;font color="#000000"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=9&amp;amp;subcatid=25"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5152" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5152"&gt;5152&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5152" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5152"&gt;The Windows Filtering Platform blocked a packet.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5153" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5153"&gt;5153&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5153" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5153"&gt;A more restrictive Windows Filtering Platform filter has blocked a packet.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/span&gt;</description><pubDate>Tue, 28 Aug 2012 17:04:56 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>File Share</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50597.aspx</link><description>&lt;font size="1"&gt;&lt;font color="#000000"&gt;This category logs one and only one event. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy&lt;/font&gt;&lt;/font&gt;&lt;font color="#000000"&gt;&lt;font size="1"&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=9&amp;amp;subcatid=24"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5140" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5140"&gt;5140&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5140" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5140"&gt;A network share object was accessed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 17:03:00 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Handle Manipulation</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50596.aspx</link><description>&lt;font size="1"&gt;&lt;font color="#000000"&gt;This category logs one and only one event. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy&lt;/font&gt;&lt;/font&gt;&lt;font color="#000000"&gt;&lt;font size="1"&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=9&amp;amp;subcatid=23"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4690" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4690"&gt;4690&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4690" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4690"&gt;An attempt was made to duplicate a handle to an object&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 17:00:44 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Application Generated</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50595.aspx</link><description>&lt;font color="#000000"&gt;&lt;font size="1"&gt;This category apparently logs provides a way for applications to report audit events to the security log and is no doubt related to Authorization Manager. I've not researched this category and welcome any help from the community in documenting it. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.&lt;br /&gt;&lt;br /&gt;This category is also used by the &lt;a href="/sharepoint/logbindersp/default.aspx"&gt;LOGbinder&lt;/a&gt; family of agents for reporting application audit events from SharePoint, SQL Server and more.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=9&amp;amp;subcatid=22"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/span&gt;&lt;/font&gt;&lt;br /&gt;&lt;/font&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4665" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4665"&gt;4665&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4665" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4665"&gt;An attempt was made to create an application client context.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4666" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4666"&gt;4666&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4666" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4666"&gt;An application attempted an operation&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4667" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4667"&gt;4667&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4667" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4667"&gt;An application client context was deleted&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4668" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4668"&gt;4668&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4668" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4668"&gt;An application was initialized.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="/securitylog/encyclopedia/Default.aspx?source=sp"&gt;10-59&lt;/a&gt;    &lt;/td&gt;&lt;td&gt;SharePoint Audit Events Generated by &lt;a href="/sharepoint/logbindersp/default.aspx"&gt;LOGbinder SP&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 16:57:30 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Certification Services</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50594.aspx</link><description>&lt;font color="#000000"&gt;&lt;font size="1"&gt;Certification Services is the built-in Certification Authority and related PKI functionality in Windows Server and this category provides exhaustive auditing of related activity. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=9&amp;amp;subcatid=21"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4868" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4868"&gt;4868&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4868" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4868"&gt;The certificate manager denied a pending certificate request.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4869" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4869"&gt;4869&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4869" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4869"&gt;Certificate Services received a resubmitted certificate request.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4870" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4870"&gt;4870&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4870" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4870"&gt;Certificate Services revoked a certificate.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4871" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4871"&gt;4871&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4871" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4871"&gt;Certificate Services received a request to publish the certificate revocation list (CRL).&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4872" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4872"&gt;4872&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4872" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4872"&gt;Certificate Services published the certificate revocation list (CRL).&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4873" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4873"&gt;4873&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4873" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4873"&gt;A certificate request extension changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4875" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4875"&gt;4875&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4875" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4875"&gt;Certificate Services received a request to shut down.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4876" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4876"&gt;4876&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4876" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4876"&gt;Certificate Services backup started.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4877" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4877"&gt;4877&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4877" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4877"&gt;Certificate Services backup completed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4878" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4878"&gt;4878&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4878" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4878"&gt;Certificate Services restore started.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4879" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4879"&gt;4879&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4879" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4879"&gt;Certificate Services restore completed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4880" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4880"&gt;4880&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4880" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4880"&gt;Certificate Services started.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4881" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4881"&gt;4881&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4881" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4881"&gt;Certificate Services stopped.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4882" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4882"&gt;4882&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4882" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4882"&gt;The security permissions for Certificate Services changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4883" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4883"&gt;4883&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4883" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4883"&gt;Certificate Services retrieved an archived key.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4884" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4884"&gt;4884&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4884" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4884"&gt;Certificate Services imported a certificate into its database.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4885" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4885"&gt;4885&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4885" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4885"&gt;The audit filter for Certificate Services changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4886" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4886"&gt;4886&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4886" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4886"&gt;Certificate Services received a certificate request.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4887" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4887"&gt;4887&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4887" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4887"&gt;Certificate Services approved a certificate request and issued a certificate.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4888" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4888"&gt;4888&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4888" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4888"&gt;Certificate Services denied a certificate request.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4889" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4889"&gt;4889&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4889" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4889"&gt;Certificate Services set the status of a certificate request to pending.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4890" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4890"&gt;4890&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4890" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4890"&gt;The certificate manager settings for Certificate Services changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4891" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4891"&gt;4891&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4891" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4891"&gt;A configuration entry changed in Certificate Services.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4892" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4892"&gt;4892&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4892" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4892"&gt;A property of Certificate Services changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4893" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4893"&gt;4893&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4893" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4893"&gt;Certificate Services archived a key.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4894" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4894"&gt;4894&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4894" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4894"&gt;Certificate Services imported and archived a key.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4895" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4895"&gt;4895&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4895" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4895"&gt;Certificate Services published the CA certificate to Active Directory Domain Services.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4896" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4896"&gt;4896&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4896" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4896"&gt;One or more rows have been deleted from the certificate database.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4897" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4897"&gt;4897&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4897" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4897"&gt;Role separation enabled&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4898" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4898"&gt;4898&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4898" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4898"&gt;Certificate Services loaded a template.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4899" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4899"&gt;4899&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4899" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4899"&gt;A Certificate Services template was updated.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4900" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4900"&gt;4900&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4900" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4900"&gt;Certificate Services template security was updated.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 16:54:07 GMT</pubDate><dc:creator>whsmith</dc:creator></item></channel></rss>