Link to home
Start Free TrialLog in
Avatar of nourben
nourbenFlag for United States of America

asked on

Take ownership attempts based on object access events

I am getting tons of these:

A handle to an object was requested.

Subject:

      Security ID:            S-1-5-18

      Account Name:            DC01$ (domain controler name)

      Account Domain:            XXXXX (domain name)

      Logon ID:            

Object:

      Object Server:            Security

      Object Type:            Key

      Object Name:            \REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\SamSs

      Handle ID:            1260

Process Information:

      Process ID:            2696

      Process Name:            C:\Windows\System32\CpqMgmt\cqmghost\cqmghost.exe

Access Request Information:

      Transaction ID:            00000000-0000-0000-0000-000000000000

      Accesses:            DELETE

                  READ_CONTROL

                  WRITE_DAC

                  WRITE_OWNER

                  Query key value

                  Set key value

                  Create sub-key

                  Enumerate sub-keys

                  Notify about changes to keys

                  Create Link

                  

      Access Mask:            

      Privileges Used for Access Check:      -

      Restricted SID Count:      0



ASKER CERTIFIED SOLUTION
Avatar of Ady Foot
Ady Foot
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial