{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t0\n\tApplication Name:\t-\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.99\n\tSource Port:\t\t48104\n\tDestination Address:\t239.255.255.250\n\tDestination Port:\t\t1900\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t67683\n\tLayer Name:\t\tTransport\n\tLayer Run-Time ID:\t13","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"3654a8bf6c9ab45fe7678ec08812337d8aa2596dff8336c8b63a2cad80f9c6fc","action":"Filtering Platform Packet Drop","created":"2026-05-05T08:02:15.597Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:02:14.101Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1756}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","event_id":5152,"opcode":"Info","api":"wineventlog","keywords":["Audit Failure"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":253525790,"task":"Filtering Platform Packet Drop","event_data":{"SourcePort":"48104","DestPort":"1900","ProcessId":"0","DestAddress":"239.255.255.250","SourceAddress":"172.30.4.99","Protocol":"17","LayerName":"%%14597","Application":"-","LayerRTID":"13","FilterRTID":"67683","Direction":"%%14592"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t4\n\tApplication Name:\tSystem\n\nNetwork Information:\n\tDirection:\t\tOutbound\n\tSource Address:\t\tfe80::fe:3f96:53e1:fb32\n\tSource Port:\t\t59349\n\tDestination Address:\tfe80::fe:3f96:53e1:fb32\n\tDestination Port:\t\t445\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t65788\n\tLayer Name:\t\tConnect\n\tLayer Run-Time ID:\t50","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"95bee2d9b6d404396de144dbfbc12b0fa493aeb9f71fadf5f6566c9c0cc7a7d3","action":"Filtering Platform Connection","created":"2026-05-05T08:07:48.531Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:07:47.002Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":4796}},"event_id":5156,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"opcode":"Info","version":1,"record_id":204126960,"task":"Filtering Platform Connection","event_data":{"Direction":"%%14593","DestPort":"445","DestAddress":"fe80::fe:3f96:53e1:fb32","SourceAddress":"fe80::fe:3f96:53e1:fb32","ProcessID":"4","LayerName":"%%14611","Protocol":"6","RemoteMachineID":"S-1-0-0","Application":"System","LayerRTID":"50","RemoteUserID":"S-1-0-0","FilterRTID":"65788","SourcePort":"59349"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t4\n\tApplication Name:\tSystem\n\nNetwork Information:\n\tDirection:\t\tOutbound\n\tSource Address:\t\tfe80::fe:3f96:53e1:fb32\n\tSource Port:\t\t59349\n\tDestination Address:\tfe80::fe:3f96:53e1:fb32\n\tDestination Port:\t\t445\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t65788\n\tLayer Name:\t\tConnect\n\tLayer Run-Time ID:\t50","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"95bee2d9b6d404396de144dbfbc12b0fa493aeb9f71fadf5f6566c9c0cc7a7d3","action":"Filtering Platform Connection","created":"2026-05-05T08:07:48.531Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:07:47.003Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":1008}},"event_id":5156,"opcode":"Info","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","version":1,"api":"wineventlog","record_id":204126962,"task":"Filtering Platform Connection","event_data":{"SourcePort":"59349","DestPort":"445","DestAddress":"fe80::fe:3f96:53e1:fb32","SourceAddress":"fe80::fe:3f96:53e1:fb32","ProcessID":"4","Protocol":"6","LayerName":"%%14611","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","Application":"System","LayerRTID":"50","FilterRTID":"65788","Direction":"%%14593"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t660\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t::1\n\tSource Port:\t\t55958\n\tDestination Address:\t::1\n\tDestination Port:\t\t389\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t65786\n\tLayer Name:\t\tReceive/Accept\n\tLayer Run-Time ID:\t46","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"87c4c8634f1891837762d77f3bf79f3912873091bdc0d1309e9e59a81db94ed9","action":"Filtering Platform Connection","created":"2026-05-05T08:02:15.597Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:02:14.926Z","agent":{"name":"w2016ad-n25","id":"16b27c50-d19b-4829-8363-ff3aabf1f846","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":2320}},"event_id":5156,"api":"wineventlog","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","version":1,"record_id":253525793,"task":"Filtering Platform Connection","event_data":{"Direction":"%%14592","DestPort":"389","DestAddress":"::1","SourceAddress":"::1","ProcessID":"660","LayerName":"%%14610","Protocol":"6","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","LayerRTID":"46","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","FilterRTID":"65786","SourcePort":"55958"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t4\n\tApplication Name:\tSystem\n\nNetwork Information:\n\tDirection:\t\tOutbound\n\tSource Address:\t\tfe80::fe:3f96:53e1:fb32\n\tSource Port:\t\t59349\n\tDestination Address:\tfe80::fe:3f96:53e1:fb32\n\tDestination Port:\t\t445\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t65788\n\tLayer Name:\t\tConnect\n\tLayer Run-Time ID:\t50","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"95bee2d9b6d404396de144dbfbc12b0fa493aeb9f71fadf5f6566c9c0cc7a7d3","action":"Filtering Platform Connection","created":"2026-05-05T08:07:48.531Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:07:47.004Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1008}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5156,"opcode":"Info","version":1,"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","keywords":["Audit Success"],"record_id":204126964,"task":"Filtering Platform Connection","event_data":{"SourcePort":"59349","DestPort":"445","DestAddress":"fe80::fe:3f96:53e1:fb32","SourceAddress":"fe80::fe:3f96:53e1:fb32","ProcessID":"4","LayerName":"%%14611","Protocol":"6","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","LayerRTID":"50","Application":"System","FilterRTID":"65788","Direction":"%%14593"},"channel":"Security"}}
{"message":"An account was successfully logged on.\n\nSubject:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\t-\n\tAccount Domain:\t\t-\n\tLogon ID:\t\t0x0\n\nLogon Information:\n\tLogon Type:\t\t3\n\tRestricted Admin Mode:\t-\n\tVirtual Account:\t\tNo\n\tElevated Token:\t\tYes\n\nImpersonation Level:\t\tDelegation\n\nNew Logon:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM.CSOC\n\tLogon ID:\t\t0x592749\n\tLinked Logon ID:\t\t0x0\n\tNetwork Account Name:\t-\n\tNetwork Account Domain:\t-\n\tLogon GUID:\t\t{637F0EAF-8FDF-6F9D-3C71-ADA619886470}\n\nProcess Information:\n\tProcess ID:\t\t0x0\n\tProcess Name:\t\t-\n\nNetwork Information:\n\tWorkstation Name:\t-\n\tSource Network Address:\tfe80::fe:3f96:53e1:fb32\n\tSource Port:\t\t59349\n\nDetailed Authentication Information:\n\tLogon Process:\t\tKerberos\n\tAuthentication Package:\tKerberos\n\tTransited Services:\t-\n\tPackage Name (NTLM only):\t-\n\tKey Length:\t\t0\n\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\n\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\n\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\n\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\n\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\n\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\n\nThe authentication information fields provide detailed information about this specific logon request.\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\n\t- Transited services indicate which intermediate services have participated in this logon request.\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"d672bec8be9cbd91bedd181083984ea08a46c31799e3833e95d377a96f454445","action":"Logon","created":"2026-05-05T08:07:48.531Z","code":4624,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:07:47.004Z","agent":{"name":"WIN-MDLQ2GQ94V9","id":"829caaa0-db4b-40b2-8076-11ac1493a97b","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"channel":"Security","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":4624,"process":{"pid":684,"thread":{"id":1040}},"opcode":"Info","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","version":2,"api":"wineventlog","record_id":204126966,"task":"Logon","event_data":{"TargetUserName":"WIN-MDLQ2GQ94V9$","SubjectUserName":"-","ProcessId":"0x0","AuthenticationPackageName":"Kerberos","WorkstationName":"-","TransmittedServices":"-","SubjectUserSid":"S-1-0-0","TargetLinkedLogonId":"0x0","SubjectLogonId":"0x0","ElevatedToken":"%%1842","LogonType":"3","KeyLength":"0","TargetDomainName":"TDARPLATFORM.CSOC","LogonProcessName":"Kerberos","TargetUserSid":"S-1-5-18","SubjectDomainName":"-","TargetOutboundUserName":"-","ProcessName":"-","TargetOutboundDomainName":"-","ImpersonationLevel":"%%1840","LogonGuid":"{637F0EAF-8FDF-6F9D-3C71-ADA619886470}","TargetLogonId":"0x592749","LmPackageName":"-","VirtualAccount":"%%1843","IpPort":"59349","IpAddress":"fe80::fe:3f96:53e1:fb32","RestrictedAdminMode":"-"},"activity_id":"{DE6A64BE-DBBC-0003-C764-6ADEBCDBDC01}"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T08:02:30.715Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:02:29.414Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":2892}},"computer_name":"w2016ad-n25.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":4703,"opcode":"Info","api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"record_id":253525808,"task":"Token Right Adjusted Events","event_data":{"TargetUserName":"W2016AD-N25$","SubjectUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t4\n\tApplication Name:\tSystem\n\nNetwork Information:\n\tDirection:\t\tOutbound\n\tSource Address:\t\tfe80::fe:3f96:53e1:fb32\n\tSource Port:\t\t59349\n\tDestination Address:\tfe80::fe:3f96:53e1:fb32\n\tDestination Port:\t\t445\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t65788\n\tLayer Name:\t\tConnect\n\tLayer Run-Time ID:\t50","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"95bee2d9b6d404396de144dbfbc12b0fa493aeb9f71fadf5f6566c9c0cc7a7d3","action":"Filtering Platform Connection","created":"2026-05-05T08:07:48.532Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:07:47.007Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","process":{"pid":4,"thread":{"id":4796}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","event_id":5156,"api":"wineventlog","version":1,"keywords":["Audit Success"],"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":204126979,"task":"Filtering Platform Connection","event_data":{"Direction":"%%14593","DestPort":"445","DestAddress":"fe80::fe:3f96:53e1:fb32","SourceAddress":"fe80::fe:3f96:53e1:fb32","ProcessID":"4","Protocol":"6","LayerName":"%%14611","RemoteMachineID":"S-1-0-0","Application":"System","LayerRTID":"50","RemoteUserID":"S-1-0-0","FilterRTID":"65788","SourcePort":"59349"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t4\n\tApplication Name:\tSystem\n\nNetwork Information:\n\tDirection:\t\tOutbound\n\tSource Address:\t\tfe80::fe:3f96:53e1:fb32\n\tSource Port:\t\t59349\n\tDestination Address:\tfe80::fe:3f96:53e1:fb32\n\tDestination Port:\t\t445\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t65788\n\tLayer Name:\t\tConnect\n\tLayer Run-Time ID:\t50","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"95bee2d9b6d404396de144dbfbc12b0fa493aeb9f71fadf5f6566c9c0cc7a7d3","action":"Filtering Platform Connection","created":"2026-05-05T08:07:48.532Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:07:47.007Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":4796}},"event_id":5156,"api":"wineventlog","version":1,"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"opcode":"Info","record_id":204126981,"task":"Filtering Platform Connection","event_data":{"SourcePort":"59349","DestPort":"445","DestAddress":"fe80::fe:3f96:53e1:fb32","SourceAddress":"fe80::fe:3f96:53e1:fb32","ProcessID":"4","Protocol":"6","LayerName":"%%14611","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","LayerRTID":"50","Application":"System","FilterRTID":"65788","Direction":"%%14593"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T08:02:30.715Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:02:29.426Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":2892}},"event_id":4703,"api":"wineventlog","keywords":["Audit Success"],"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":253525814,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"W2016AD-N25$","TargetUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","SubjectUserSid":"S-1-5-18","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t4\n\tApplication Name:\tSystem\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.205\n\tSource Port:\t\t0\n\tDestination Address:\t224.0.0.251\n\tDestination Port:\t\t0\n\tProtocol:\t\t2\n\nFilter Information:\n\tFilter Run-Time ID:\t65787\n\tLayer Name:\t\tReceive/Accept\n\tLayer Run-Time ID:\t44","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"545161f1bc97c75d6e1f1c2b2f21cd228b666f634c2648968175d61da9f8df31","action":"Filtering Platform Connection","created":"2026-05-05T08:07:49.533Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:07:47.605Z","agent":{"name":"WIN-MDLQ2GQ94V9","id":"829caaa0-db4b-40b2-8076-11ac1493a97b","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":4796}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","event_id":5156,"opcode":"Info","version":1,"keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","record_id":204126984,"task":"Filtering Platform Connection","event_data":{"Direction":"%%14592","DestPort":"0","DestAddress":"224.0.0.251","SourceAddress":"172.30.4.205","ProcessID":"4","LayerName":"%%14610","Protocol":"2","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","LayerRTID":"44","Application":"System","FilterRTID":"65787","SourcePort":"0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t2488\n\tApplication Name:\t\\device\\harddiskvolume2\\program files (x86)\\ossec-agent\\wazuh-agent.exe\n\nNetwork Information:\n\tDirection:\t\tOutbound\n\tSource Address:\t\t172.30.4.206\n\tSource Port:\t\t55960\n\tDestination Address:\t172.30.2.163\n\tDestination Port:\t\t1514\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t67057\n\tLayer Name:\t\tConnect\n\tLayer Run-Time ID:\t48","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"68985c66694473c4c7a89ac973c3c292192d23fbd357b19b1649b0063998f4ed","action":"Filtering Platform Connection","created":"2026-05-05T08:02:32.728Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:02:31.143Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1096}},"computer_name":"w2016ad-n25.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5156,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","version":1,"api":"wineventlog","keywords":["Audit Success"],"record_id":253525817,"task":"Filtering Platform Connection","event_data":{"Direction":"%%14593","DestPort":"1514","DestAddress":"172.30.2.163","SourceAddress":"172.30.4.206","ProcessID":"2488","LayerName":"%%14611","Protocol":"6","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","LayerRTID":"48","Application":"\\device\\harddiskvolume2\\program files (x86)\\ossec-agent\\wazuh-agent.exe","FilterRTID":"67057","SourcePort":"55960"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t0\n\tApplication Name:\t-\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.2.163\n\tSource Port:\t\t1514\n\tDestination Address:\t172.30.4.206\n\tDestination Port:\t\t55960\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t67042\n\tLayer Name:\t\tICMP Error\n\tLayer Run-Time ID:\t28","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"11f926491e81a3244a89cddfd3e44f5a100db0b4a90ca5030f3eaf39b3a0cf90","action":"Filtering Platform Packet Drop","created":"2026-05-05T08:02:35.750Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:02:34.258Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":2892}},"event_id":5152,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Failure"],"api":"wineventlog","record_id":253525819,"task":"Filtering Platform Packet Drop","event_data":{"SourcePort":"1514","DestPort":"55960","ProcessId":"0","DestAddress":"172.30.4.206","SourceAddress":"172.30.2.163","Protocol":"6","LayerName":"%%14601","Application":"-","LayerRTID":"28","FilterRTID":"67042","Direction":"%%14592"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t0\n\tApplication Name:\t-\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.2.163\n\tSource Port:\t\t1514\n\tDestination Address:\t172.30.4.206\n\tDestination Port:\t\t55960\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t67042\n\tLayer Name:\t\tICMP Error\n\tLayer Run-Time ID:\t28","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"11f926491e81a3244a89cddfd3e44f5a100db0b4a90ca5030f3eaf39b3a0cf90","action":"Filtering Platform Packet Drop","created":"2026-05-05T08:02:40.796Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:02:40.268Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","process":{"pid":4,"thread":{"id":2320}},"computer_name":"w2016ad-n25.tdarplatform.csoc","event_id":5152,"api":"wineventlog","keywords":["Audit Failure"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","record_id":253525824,"task":"Filtering Platform Packet Drop","event_data":{"SourcePort":"1514","DestPort":"55960","ProcessId":"0","DestAddress":"172.30.4.206","SourceAddress":"172.30.2.163","Protocol":"6","LayerName":"%%14601","Application":"-","LayerRTID":"28","FilterRTID":"67042","Direction":"%%14592"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T08:02:50.871Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:02:49.433Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":2892}},"computer_name":"w2016ad-n25.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":4703,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"opcode":"Info","record_id":253525829,"task":"Token Right Adjusted Events","event_data":{"TargetUserName":"W2016AD-N25$","SubjectUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t0\n\tApplication Name:\t-\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.99\n\tSource Port:\t\t1900\n\tDestination Address:\t239.255.255.250\n\tDestination Port:\t\t58977\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t67801\n\tLayer Name:\t\tTransport\n\tLayer Run-Time ID:\t13","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"c09919385eb3f83fa132178a387680a0c25695a40905a9de77b27380a8fe8fad","action":"Filtering Platform Packet Drop","created":"2026-05-05T08:07:53.543Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:07:52.352Z","agent":{"name":"WIN-MDLQ2GQ94V9","id":"829caaa0-db4b-40b2-8076-11ac1493a97b","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":1416}},"event_id":5152,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","keywords":["Audit Failure"],"record_id":204126991,"task":"Filtering Platform Packet Drop","event_data":{"SourcePort":"1900","DestPort":"58977","ProcessId":"0","DestAddress":"239.255.255.250","SourceAddress":"172.30.4.99","LayerName":"%%14597","Protocol":"17","Application":"-","LayerRTID":"13","FilterRTID":"67801","Direction":"%%14592"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T08:02:50.872Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:02:49.433Z","agent":{"name":"w2016ad-n25","id":"16b27c50-d19b-4829-8363-ff3aabf1f846","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":2892}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","event_id":4703,"api":"wineventlog","keywords":["Audit Success"],"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":253525830,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"W2016AD-N25$","TargetUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectUserSid":"S-1-5-18","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t0\n\tApplication Name:\t-\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.2.163\n\tSource Port:\t\t1514\n\tDestination Address:\t172.30.4.205\n\tDestination Port:\t\t59350\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t67096\n\tLayer Name:\t\tICMP Error\n\tLayer Run-Time ID:\t28","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"a0415d62a921cd567ea48585e757ab2513e7c5075cab3862c1d222ff6cac7eb2","action":"Filtering Platform Packet Drop","created":"2026-05-05T08:07:53.543Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:07:52.611Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":1416}},"event_id":5152,"opcode":"Info","keywords":["Audit Failure"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","record_id":204126992,"task":"Filtering Platform Packet Drop","event_data":{"SourcePort":"1514","DestPort":"59350","ProcessId":"0","DestAddress":"172.30.4.205","SourceAddress":"172.30.2.163","Protocol":"6","LayerName":"%%14601","Application":"-","LayerRTID":"28","FilterRTID":"67096","Direction":"%%14592"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T08:02:50.872Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:02:49.434Z","agent":{"name":"w2016ad-n25","id":"16b27c50-d19b-4829-8363-ff3aabf1f846","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":2892}},"computer_name":"w2016ad-n25.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":4703,"api":"wineventlog","opcode":"Info","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":253525831,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"W2016AD-N25$","TargetUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T08:02:50.872Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:02:49.446Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":2892}},"computer_name":"w2016ad-n25.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":4703,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"api":"wineventlog","record_id":253525832,"task":"Token Right Adjusted Events","event_data":{"TargetUserName":"W2016AD-N25$","SubjectUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"Special privileges assigned to new logon.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x5928C5\n\nPrivileges:\t\tSeSecurityPrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeDebugPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeImpersonatePrivilege\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\n\t\t\tSeEnableDelegationPrivilege","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"3a2c387355cc798f8ed00754f95a40a3d32ebe65b07b6176db7f49a71e869eef","action":"Special Logon","created":"2026-05-05T08:07:54.552Z","code":4672,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:07:52.987Z","agent":{"name":"WIN-MDLQ2GQ94V9","id":"829caaa0-db4b-40b2-8076-11ac1493a97b","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":684,"thread":{"id":2072}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":4672,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"api":"wineventlog","record_id":204126996,"task":"Special Logon","event_data":{"SubjectDomainName":"TDARPLATFORM","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-MDLQ2GQ94V9$","SubjectLogonId":"0x5928c5","PrivilegeList":"SeSecurityPrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeDebugPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeImpersonatePrivilege\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\n\t\t\tSeEnableDelegationPrivilege"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t0\n\tApplication Name:\t-\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.196\n\tSource Port:\t\t53193\n\tDestination Address:\t239.255.255.250\n\tDestination Port:\t\t1900\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t67683\n\tLayer Name:\t\tTransport\n\tLayer Run-Time ID:\t13","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"e250820e9ab7f6881c8b17f9d497ff591be22c4eb1cd6574175565d671ded60a","action":"Filtering Platform Packet Drop","created":"2026-05-05T08:02:59.938Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:02:58.349Z","agent":{"name":"w2016ad-n25","id":"16b27c50-d19b-4829-8363-ff3aabf1f846","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","process":{"pid":4,"thread":{"id":2892}},"computer_name":"w2016ad-n25.tdarplatform.csoc","event_id":5152,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Failure"],"api":"wineventlog","record_id":253525839,"task":"Filtering Platform Packet Drop","event_data":{"Direction":"%%14592","DestPort":"1900","ProcessId":"0","DestAddress":"239.255.255.250","SourceAddress":"172.30.4.196","Protocol":"17","LayerName":"%%14597","Application":"-","LayerRTID":"13","FilterRTID":"67683","SourcePort":"53193"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t4\n\tApplication Name:\tSystem\n\nNetwork Information:\n\tSource Address:\t\t::\n\tSource Port:\t\t59356\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t38","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"9da422da88d3483fd0aa180e43ce5152da7e2c6379281ba4f15dd7081c1c6e66","action":"Filtering Platform Connection","created":"2026-05-05T08:07:58.642Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:07:57.341Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":1416}},"event_id":5158,"api":"wineventlog","opcode":"Info","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":204127032,"task":"Filtering Platform Connection","event_data":{"Protocol":"6","LayerName":"%%14608","ProcessId":"4","Application":"System","LayerRTID":"38","SourceAddress":"::","FilterRTID":"0","SourcePort":"59356"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t4\n\tApplication Name:\tSystem\n\nNetwork Information:\n\tDirection:\t\tOutbound\n\tSource Address:\t\tfe80::fe:3f96:53e1:fb32\n\tSource Port:\t\t59356\n\tDestination Address:\tfe80::fe:3f96:53e1:fb32\n\tDestination Port:\t\t445\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t65788\n\tLayer Name:\t\tConnect\n\tLayer Run-Time ID:\t50","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"9c351877579f19973c90564d6e2a4f047e9c74c60c0aafb7adc9dcacd3a8264f","action":"Filtering Platform Connection","created":"2026-05-05T08:07:58.642Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:07:57.342Z","agent":{"name":"WIN-MDLQ2GQ94V9","id":"829caaa0-db4b-40b2-8076-11ac1493a97b","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1416}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","event_id":5156,"opcode":"Info","keywords":["Audit Success"],"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","version":1,"record_id":204127033,"task":"Filtering Platform Connection","event_data":{"Direction":"%%14593","DestPort":"445","DestAddress":"fe80::fe:3f96:53e1:fb32","SourceAddress":"fe80::fe:3f96:53e1:fb32","ProcessID":"4","LayerName":"%%14611","Protocol":"6","RemoteMachineID":"S-1-0-0","Application":"System","LayerRTID":"50","RemoteUserID":"S-1-0-0","FilterRTID":"65788","SourcePort":"59356"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t4\n\tApplication Name:\tSystem\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\tfe80::fe:3f96:53e1:fb32\n\tSource Port:\t\t59356\n\tDestination Address:\tfe80::fe:3f96:53e1:fb32\n\tDestination Port:\t\t445\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t65786\n\tLayer Name:\t\tReceive/Accept\n\tLayer Run-Time ID:\t46","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"0fc3785ff6e3f5f27481f5c027000a9999d5602b3eb89c642320bf3c34130d7a","action":"Filtering Platform Connection","created":"2026-05-05T08:07:58.642Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:07:57.342Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1416}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5156,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","version":1,"keywords":["Audit Success"],"opcode":"Info","record_id":204127034,"task":"Filtering Platform Connection","event_data":{"SourcePort":"59356","DestPort":"445","DestAddress":"fe80::fe:3f96:53e1:fb32","SourceAddress":"fe80::fe:3f96:53e1:fb32","ProcessID":"4","LayerName":"%%14610","Protocol":"6","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","LayerRTID":"46","Application":"System","FilterRTID":"65786","Direction":"%%14592"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t4\n\tApplication Name:\tSystem\n\nNetwork Information:\n\tDirection:\t\tOutbound\n\tSource Address:\t\tfe80::fe:3f96:53e1:fb32\n\tSource Port:\t\t59356\n\tDestination Address:\tfe80::fe:3f96:53e1:fb32\n\tDestination Port:\t\t445\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t65788\n\tLayer Name:\t\tConnect\n\tLayer Run-Time ID:\t50","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"9c351877579f19973c90564d6e2a4f047e9c74c60c0aafb7adc9dcacd3a8264f","action":"Filtering Platform Connection","created":"2026-05-05T08:07:58.642Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:07:57.342Z","agent":{"name":"WIN-MDLQ2GQ94V9","id":"829caaa0-db4b-40b2-8076-11ac1493a97b","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","process":{"pid":4,"thread":{"id":1416}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","event_id":5156,"opcode":"Info","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","version":1,"api":"wineventlog","record_id":204127035,"task":"Filtering Platform Connection","event_data":{"SourcePort":"59356","DestPort":"445","DestAddress":"fe80::fe:3f96:53e1:fb32","SourceAddress":"fe80::fe:3f96:53e1:fb32","ProcessID":"4","Protocol":"6","LayerName":"%%14611","RemoteMachineID":"S-1-0-0","Application":"System","LayerRTID":"50","RemoteUserID":"S-1-0-0","FilterRTID":"65788","Direction":"%%14593"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t4\n\tApplication Name:\tSystem\n\nNetwork Information:\n\tDirection:\t\tOutbound\n\tSource Address:\t\tfe80::fe:3f96:53e1:fb32\n\tSource Port:\t\t59356\n\tDestination Address:\tfe80::fe:3f96:53e1:fb32\n\tDestination Port:\t\t445\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t65788\n\tLayer Name:\t\tConnect\n\tLayer Run-Time ID:\t50","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"9c351877579f19973c90564d6e2a4f047e9c74c60c0aafb7adc9dcacd3a8264f","action":"Filtering Platform Connection","created":"2026-05-05T08:07:58.642Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:07:57.342Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":1416}},"event_id":5156,"opcode":"Info","version":1,"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"api":"wineventlog","record_id":204127036,"task":"Filtering Platform Connection","event_data":{"SourcePort":"59356","DestPort":"445","DestAddress":"fe80::fe:3f96:53e1:fb32","SourceAddress":"fe80::fe:3f96:53e1:fb32","ProcessID":"4","Protocol":"6","LayerName":"%%14611","RemoteMachineID":"S-1-0-0","Application":"System","RemoteUserID":"S-1-0-0","LayerRTID":"50","FilterRTID":"65788","Direction":"%%14593"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t4\n\tApplication Name:\tSystem\n\nNetwork Information:\n\tDirection:\t\tOutbound\n\tSource Address:\t\tfe80::fe:3f96:53e1:fb32\n\tSource Port:\t\t59356\n\tDestination Address:\tfe80::fe:3f96:53e1:fb32\n\tDestination Port:\t\t445\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t65788\n\tLayer Name:\t\tConnect\n\tLayer Run-Time ID:\t50","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"9c351877579f19973c90564d6e2a4f047e9c74c60c0aafb7adc9dcacd3a8264f","action":"Filtering Platform Connection","created":"2026-05-05T08:07:58.642Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:07:57.342Z","agent":{"name":"WIN-MDLQ2GQ94V9","id":"829caaa0-db4b-40b2-8076-11ac1493a97b","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","process":{"pid":4,"thread":{"id":4796}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","event_id":5156,"opcode":"Info","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","version":1,"api":"wineventlog","record_id":204127037,"task":"Filtering Platform Connection","event_data":{"SourcePort":"59356","DestPort":"445","DestAddress":"fe80::fe:3f96:53e1:fb32","SourceAddress":"fe80::fe:3f96:53e1:fb32","ProcessID":"4","LayerName":"%%14611","Protocol":"6","RemoteMachineID":"S-1-0-0","Application":"System","RemoteUserID":"S-1-0-0","LayerRTID":"50","FilterRTID":"65788","Direction":"%%14593"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t4\n\tApplication Name:\tSystem\n\nNetwork Information:\n\tDirection:\t\tOutbound\n\tSource Address:\t\tfe80::fe:3f96:53e1:fb32\n\tSource Port:\t\t59356\n\tDestination Address:\tfe80::fe:3f96:53e1:fb32\n\tDestination Port:\t\t445\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t65788\n\tLayer Name:\t\tConnect\n\tLayer Run-Time ID:\t50","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"9c351877579f19973c90564d6e2a4f047e9c74c60c0aafb7adc9dcacd3a8264f","action":"Filtering Platform Connection","created":"2026-05-05T08:07:58.642Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:07:57.342Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":4796}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","event_id":5156,"api":"wineventlog","keywords":["Audit Success"],"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","version":1,"record_id":204127038,"task":"Filtering Platform Connection","event_data":{"Direction":"%%14593","DestPort":"445","DestAddress":"fe80::fe:3f96:53e1:fb32","SourceAddress":"fe80::fe:3f96:53e1:fb32","ProcessID":"4","Protocol":"6","LayerName":"%%14611","RemoteMachineID":"S-1-0-0","Application":"System","LayerRTID":"50","RemoteUserID":"S-1-0-0","FilterRTID":"65788","SourcePort":"59356"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t4\n\tApplication Name:\tSystem\n\nNetwork Information:\n\tDirection:\t\tOutbound\n\tSource Address:\t\tfe80::fe:3f96:53e1:fb32\n\tSource Port:\t\t59356\n\tDestination Address:\tfe80::fe:3f96:53e1:fb32\n\tDestination Port:\t\t445\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t65788\n\tLayer Name:\t\tConnect\n\tLayer Run-Time ID:\t50","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"9c351877579f19973c90564d6e2a4f047e9c74c60c0aafb7adc9dcacd3a8264f","action":"Filtering Platform Connection","created":"2026-05-05T08:07:58.642Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:07:57.342Z","agent":{"name":"WIN-MDLQ2GQ94V9","id":"829caaa0-db4b-40b2-8076-11ac1493a97b","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":4796}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5156,"api":"wineventlog","version":1,"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"opcode":"Info","record_id":204127039,"task":"Filtering Platform Connection","event_data":{"SourcePort":"59356","DestPort":"445","DestAddress":"fe80::fe:3f96:53e1:fb32","SourceAddress":"fe80::fe:3f96:53e1:fb32","ProcessID":"4","LayerName":"%%14611","Protocol":"6","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","LayerRTID":"50","Application":"System","FilterRTID":"65788","Direction":"%%14593"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t4\n\tApplication Name:\tSystem\n\nNetwork Information:\n\tDirection:\t\tOutbound\n\tSource Address:\t\tfe80::fe:3f96:53e1:fb32\n\tSource Port:\t\t59356\n\tDestination Address:\tfe80::fe:3f96:53e1:fb32\n\tDestination Port:\t\t445\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t65788\n\tLayer Name:\t\tConnect\n\tLayer Run-Time ID:\t50","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"9c351877579f19973c90564d6e2a4f047e9c74c60c0aafb7adc9dcacd3a8264f","action":"Filtering Platform Connection","created":"2026-05-05T08:07:58.642Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:07:57.344Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":4796}},"event_id":5156,"opcode":"Info","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","version":1,"record_id":204127040,"task":"Filtering Platform Connection","event_data":{"SourcePort":"59356","DestPort":"445","DestAddress":"fe80::fe:3f96:53e1:fb32","SourceAddress":"fe80::fe:3f96:53e1:fb32","ProcessID":"4","Protocol":"6","LayerName":"%%14611","RemoteMachineID":"S-1-0-0","Application":"System","LayerRTID":"50","RemoteUserID":"S-1-0-0","FilterRTID":"65788","Direction":"%%14593"},"channel":"Security"}}
{"message":"Special privileges assigned to new logon.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x592BBA\n\nPrivileges:\t\tSeSecurityPrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeDebugPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeImpersonatePrivilege\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\n\t\t\tSeEnableDelegationPrivilege","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"c176cc24ddb7715af954febce5e1dfadd28bd3d646ee8e93619057195950d1b7","action":"Special Logon","created":"2026-05-05T08:07:58.642Z","code":4672,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:07:57.344Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":684,"thread":{"id":1040}},"event_id":4672,"channel":"Security","api":"wineventlog","keywords":["Audit Success"],"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":204127041,"task":"Special Logon","event_data":{"SubjectDomainName":"TDARPLATFORM","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-MDLQ2GQ94V9$","PrivilegeList":"SeSecurityPrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeDebugPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeImpersonatePrivilege\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\n\t\t\tSeEnableDelegationPrivilege","SubjectLogonId":"0x592bba"},"activity_id":"{DE6A64BE-DBBC-0003-C764-6ADEBCDBDC01}"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x124\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"9bc7c5f2ac31ab3658a5fd52924314bfdb24b2a602e67e1e82efdb87cd26e038","action":"Token Right Adjusted Events","created":"2026-05-05T07:53:18.746Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:17.581Z","agent":{"name":"WIN-MDLQ2GQ94V9","id":"829caaa0-db4b-40b2-8076-11ac1493a97b","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":4900}},"event_id":4703,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","keywords":["Audit Success"],"record_id":204125194,"task":"Token Right Adjusted Events","event_data":{"TargetUserName":"WIN-MDLQ2GQ94V9$","SubjectUserName":"WIN-MDLQ2GQ94V9$","ProcessId":"0x124","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectUserSid":"S-1-5-18","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t0\n\tApplication Name:\t-\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.99\n\tSource Port:\t\t44767\n\tDestination Address:\t239.255.255.250\n\tDestination Port:\t\t1900\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t67683\n\tLayer Name:\t\tTransport\n\tLayer Run-Time ID:\t13","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"419fad6eb46b65bfd53f6c134054926b81cea01225f9d60caac927b86965b930","action":"Filtering Platform Packet Drop","created":"2026-05-05T07:43:32.158Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:43:31.057Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":120}},"event_id":5152,"opcode":"Info","keywords":["Audit Failure"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","record_id":253523606,"task":"Filtering Platform Packet Drop","event_data":{"SourcePort":"44767","DestPort":"1900","ProcessId":"0","DestAddress":"239.255.255.250","SourceAddress":"172.30.4.99","Protocol":"17","LayerName":"%%14597","Application":"-","LayerRTID":"13","FilterRTID":"67683","Direction":"%%14592"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x124\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"9bc7c5f2ac31ab3658a5fd52924314bfdb24b2a602e67e1e82efdb87cd26e038","action":"Token Right Adjusted Events","created":"2026-05-05T07:53:18.746Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:17.582Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":4900}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":4703,"api":"wineventlog","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","record_id":204125195,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"WIN-MDLQ2GQ94V9$","TargetUserName":"WIN-MDLQ2GQ94V9$","ProcessId":"0x124","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectUserSid":"S-1-5-18","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t0\n\tApplication Name:\t-\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.2.163\n\tSource Port:\t\t1514\n\tDestination Address:\t172.30.4.206\n\tDestination Port:\t\t55857\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t67042\n\tLayer Name:\t\tICMP Error\n\tLayer Run-Time ID:\t28","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"82d780d1ec48359fb01c685f2da3003d73138442154f957c2e4e48ffd880faa6","action":"Filtering Platform Packet Drop","created":"2026-05-05T07:43:35.173Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:43:33.809Z","agent":{"name":"w2016ad-n25","id":"16b27c50-d19b-4829-8363-ff3aabf1f846","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":1756}},"event_id":5152,"opcode":"Info","keywords":["Audit Failure"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","record_id":253523607,"task":"Filtering Platform Packet Drop","event_data":{"Direction":"%%14592","DestPort":"55857","ProcessId":"0","DestAddress":"172.30.4.206","SourceAddress":"172.30.2.163","Protocol":"6","LayerName":"%%14601","Application":"-","LayerRTID":"28","FilterRTID":"67042","SourcePort":"1514"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x124\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"9bc7c5f2ac31ab3658a5fd52924314bfdb24b2a602e67e1e82efdb87cd26e038","action":"Token Right Adjusted Events","created":"2026-05-05T07:53:18.746Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:17.595Z","agent":{"name":"WIN-MDLQ2GQ94V9","id":"829caaa0-db4b-40b2-8076-11ac1493a97b","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":4900}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":4703,"opcode":"Info","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","record_id":204125196,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"WIN-MDLQ2GQ94V9$","TargetUserName":"WIN-MDLQ2GQ94V9$","ProcessId":"0x124","SubjectDomainName":"TDARPLATFORM","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t0\n\tApplication Name:\t-\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.196\n\tSource Port:\t\t41807\n\tDestination Address:\t239.255.255.250\n\tDestination Port:\t\t1900\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t67683\n\tLayer Name:\t\tTransport\n\tLayer Run-Time ID:\t13","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"3354b778926a79b0d6f9f99c2082cb96ff54936b0374dac14aa3eed93bf9d056","action":"Filtering Platform Packet Drop","created":"2026-05-05T07:43:37.188Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:43:35.991Z","agent":{"name":"w2016ad-n25","id":"16b27c50-d19b-4829-8363-ff3aabf1f846","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":2748}},"event_id":5152,"opcode":"Info","api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Failure"],"record_id":253523608,"task":"Filtering Platform Packet Drop","event_data":{"SourcePort":"41807","DestPort":"1900","ProcessId":"0","DestAddress":"239.255.255.250","SourceAddress":"172.30.4.196","Protocol":"17","LayerName":"%%14597","Application":"-","LayerRTID":"13","FilterRTID":"67683","Direction":"%%14592"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x124\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"9bc7c5f2ac31ab3658a5fd52924314bfdb24b2a602e67e1e82efdb87cd26e038","action":"Token Right Adjusted Events","created":"2026-05-05T07:53:18.746Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:17.595Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":4900}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":4703,"opcode":"Info","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","record_id":204125197,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"WIN-MDLQ2GQ94V9$","TargetUserName":"WIN-MDLQ2GQ94V9$","ProcessId":"0x124","SubjectDomainName":"TDARPLATFORM","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t0\n\tApplication Name:\t-\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.2.163\n\tSource Port:\t\t1514\n\tDestination Address:\t172.30.4.206\n\tDestination Port:\t\t55857\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t67042\n\tLayer Name:\t\tICMP Error\n\tLayer Run-Time ID:\t28","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"82d780d1ec48359fb01c685f2da3003d73138442154f957c2e4e48ffd880faa6","action":"Filtering Platform Packet Drop","created":"2026-05-05T07:43:37.188Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:43:36.819Z","agent":{"name":"w2016ad-n25","id":"16b27c50-d19b-4829-8363-ff3aabf1f846","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":2748}},"event_id":5152,"api":"wineventlog","opcode":"Info","keywords":["Audit Failure"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":253523609,"task":"Filtering Platform Packet Drop","event_data":{"Direction":"%%14592","DestPort":"55857","ProcessId":"0","DestAddress":"172.30.4.206","SourceAddress":"172.30.2.163","LayerName":"%%14601","Protocol":"6","Application":"-","LayerRTID":"28","FilterRTID":"67042","SourcePort":"1514"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x124\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"9bc7c5f2ac31ab3658a5fd52924314bfdb24b2a602e67e1e82efdb87cd26e038","action":"Token Right Adjusted Events","created":"2026-05-05T07:53:18.746Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:17.595Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":4900}},"event_id":4703,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","keywords":["Audit Success"],"record_id":204125198,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"WIN-MDLQ2GQ94V9$","TargetUserName":"WIN-MDLQ2GQ94V9$","ProcessId":"0x124","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectUserSid":"S-1-5-18","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t0\n\tApplication Name:\t-\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.2.163\n\tSource Port:\t\t1514\n\tDestination Address:\t172.30.4.206\n\tDestination Port:\t\t55857\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t67042\n\tLayer Name:\t\tICMP Error\n\tLayer Run-Time ID:\t28","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"82d780d1ec48359fb01c685f2da3003d73138442154f957c2e4e48ffd880faa6","action":"Filtering Platform Packet Drop","created":"2026-05-05T07:43:44.259Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:43:42.819Z","agent":{"name":"w2016ad-n25","id":"16b27c50-d19b-4829-8363-ff3aabf1f846","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":2748}},"computer_name":"w2016ad-n25.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5152,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Failure"],"opcode":"Info","record_id":253523610,"task":"Filtering Platform Packet Drop","event_data":{"SourcePort":"1514","DestPort":"55857","ProcessId":"0","DestAddress":"172.30.4.206","SourceAddress":"172.30.2.163","Protocol":"6","LayerName":"%%14601","Application":"-","LayerRTID":"28","FilterRTID":"67042","Direction":"%%14592"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x124\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"9bc7c5f2ac31ab3658a5fd52924314bfdb24b2a602e67e1e82efdb87cd26e038","action":"Token Right Adjusted Events","created":"2026-05-05T07:53:18.746Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:17.596Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":4900}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":4703,"api":"wineventlog","keywords":["Audit Success"],"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":204125199,"task":"Token Right Adjusted Events","event_data":{"TargetUserName":"WIN-MDLQ2GQ94V9$","SubjectUserName":"WIN-MDLQ2GQ94V9$","ProcessId":"0x124","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectUserSid":"S-1-5-18","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t0\n\tApplication Name:\t-\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.2.163\n\tSource Port:\t\t1514\n\tDestination Address:\t172.30.4.205\n\tDestination Port:\t\t59268\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t67096\n\tLayer Name:\t\tICMP Error\n\tLayer Run-Time ID:\t28","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"41f4909e995d310863b6fc5467892e63126e6f30d588eba084b1374edda43f21","action":"Filtering Platform Packet Drop","created":"2026-05-05T07:53:21.749Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:20.621Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":2912}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5152,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","keywords":["Audit Failure"],"record_id":204125200,"task":"Filtering Platform Packet Drop","event_data":{"SourcePort":"1514","DestPort":"59268","ProcessId":"0","DestAddress":"172.30.4.205","SourceAddress":"172.30.2.163","Protocol":"6","LayerName":"%%14601","Application":"-","LayerRTID":"28","FilterRTID":"67096","Direction":"%%14592"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T07:43:50.314Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:43:48.973Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":120}},"event_id":4703,"api":"wineventlog","keywords":["Audit Success"],"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":253523611,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"W2016AD-N25$","TargetUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t0\n\tApplication Name:\t-\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.99\n\tSource Port:\t\t56851\n\tDestination Address:\t239.255.255.250\n\tDestination Port:\t\t1900\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t67801\n\tLayer Name:\t\tTransport\n\tLayer Run-Time ID:\t13","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"d340cd3fcc9395808c6b229aa8d32c9ea38f0d62b1faf6cbd9940f40bc99c349","action":"Filtering Platform Packet Drop","created":"2026-05-05T07:53:27.771Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:26.745Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","process":{"pid":4,"thread":{"id":3200}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","event_id":5152,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","keywords":["Audit Failure"],"record_id":204125201,"task":"Filtering Platform Packet Drop","event_data":{"Direction":"%%14592","DestPort":"1900","ProcessId":"0","DestAddress":"239.255.255.250","SourceAddress":"172.30.4.99","LayerName":"%%14597","Protocol":"17","Application":"-","LayerRTID":"13","FilterRTID":"67801","SourcePort":"56851"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T07:43:50.315Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:43:48.973Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":120}},"event_id":4703,"api":"wineventlog","opcode":"Info","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":253523612,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"W2016AD-N25$","TargetUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t0\n\tApplication Name:\t-\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.99\n\tSource Port:\t\t1900\n\tDestination Address:\t239.255.255.250\n\tDestination Port:\t\t56851\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t67801\n\tLayer Name:\t\tTransport\n\tLayer Run-Time ID:\t13","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"a25e8a8995531ba112ab1402f589b660d5e80dc140fce5d10c39ba3a57e56cb6","action":"Filtering Platform Packet Drop","created":"2026-05-05T07:53:27.771Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:26.745Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":3200}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5152,"api":"wineventlog","keywords":["Audit Failure"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","record_id":204125202,"task":"Filtering Platform Packet Drop","event_data":{"SourcePort":"1900","DestPort":"56851","ProcessId":"0","DestAddress":"239.255.255.250","SourceAddress":"172.30.4.99","Protocol":"17","LayerName":"%%14597","Application":"-","LayerRTID":"13","FilterRTID":"67801","Direction":"%%14592"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T07:43:50.315Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:43:48.976Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":120}},"event_id":4703,"api":"wineventlog","opcode":"Info","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":253523613,"task":"Token Right Adjusted Events","event_data":{"TargetUserName":"W2016AD-N25$","SubjectUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\tfe80::6c1c:1afd:b16:ecb9\n\tSource Port:\t\t59154\n\tDestination Address:\tfe80::6c1c:1afd:b16:ecb9\n\tDestination Port:\t\t389\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t65786\n\tLayer Name:\t\tReceive/Accept\n\tLayer Run-Time ID:\t46","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"624c3c16b6052bd2e0cfc414ee56b48947659b226cc93319ea4f9c2d097b4a23","action":"Filtering Platform Connection","created":"2026-05-05T07:53:30.800Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:29.471Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":3200}},"event_id":5156,"opcode":"Info","keywords":["Audit Success"],"api":"wineventlog","version":1,"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":204125203,"task":"Filtering Platform Connection","event_data":{"SourcePort":"59154","DestPort":"389","DestAddress":"fe80::6c1c:1afd:b16:ecb9","SourceAddress":"fe80::6c1c:1afd:b16:ecb9","ProcessID":"684","LayerName":"%%14610","Protocol":"6","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","LayerRTID":"46","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","FilterRTID":"65786","Direction":"%%14592"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T07:43:50.315Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:43:48.984Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":120}},"event_id":4703,"opcode":"Info","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","record_id":253523614,"task":"Token Right Adjusted Events","event_data":{"TargetUserName":"W2016AD-N25$","SubjectUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectUserSid":"S-1-5-18","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t2452\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\dfsrs.exe\n\nNetwork Information:\n\tSource Address:\t\t::\n\tSource Port:\t\t59269\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t38","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"6d1d6e2c52f59859b0e2bcc55e6865f07b0443cd84c5fe83e45e95794bb3469f","action":"Filtering Platform Connection","created":"2026-05-05T07:53:30.800Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:29.473Z","agent":{"name":"WIN-MDLQ2GQ94V9","id":"829caaa0-db4b-40b2-8076-11ac1493a97b","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":3200}},"event_id":5158,"api":"wineventlog","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","record_id":204125204,"task":"Filtering Platform Connection","event_data":{"Protocol":"6","LayerName":"%%14608","ProcessId":"2452","Application":"\\device\\harddiskvolume2\\windows\\system32\\dfsrs.exe","LayerRTID":"38","SourceAddress":"::","FilterRTID":"0","SourcePort":"59269"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T07:43:50.315Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:43:48.984Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":120}},"event_id":4703,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"api":"wineventlog","record_id":253523615,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"W2016AD-N25$","TargetUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t2452\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\dfsrs.exe\n\nNetwork Information:\n\tDirection:\t\tOutbound\n\tSource Address:\t\tfe80::6c1c:1afd:b16:ecb9\n\tSource Port:\t\t59269\n\tDestination Address:\tfe80::6c1c:1afd:b16:ecb9\n\tDestination Port:\t\t135\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t65788\n\tLayer Name:\t\tConnect\n\tLayer Run-Time ID:\t50","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"66b85a75119a9502351bb28ec1299e5b1cf04546f75d1ba8e6008eefd75f60aa","action":"Filtering Platform Connection","created":"2026-05-05T07:53:30.800Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:29.473Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":3200}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","event_id":5156,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"version":1,"api":"wineventlog","record_id":204125205,"task":"Filtering Platform Connection","event_data":{"Direction":"%%14593","DestPort":"135","DestAddress":"fe80::6c1c:1afd:b16:ecb9","SourceAddress":"fe80::6c1c:1afd:b16:ecb9","ProcessID":"2452","LayerName":"%%14611","Protocol":"6","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","LayerRTID":"50","Application":"\\device\\harddiskvolume2\\windows\\system32\\dfsrs.exe","FilterRTID":"65788","SourcePort":"59269"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T07:43:50.315Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:43:48.985Z","agent":{"name":"w2016ad-n25","id":"16b27c50-d19b-4829-8363-ff3aabf1f846","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":120}},"computer_name":"w2016ad-n25.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":4703,"api":"wineventlog","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","record_id":253523616,"task":"Token Right Adjusted Events","event_data":{"TargetUserName":"W2016AD-N25$","SubjectUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t928\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\svchost.exe\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\tfe80::6c1c:1afd:b16:ecb9\n\tSource Port:\t\t59269\n\tDestination Address:\tfe80::6c1c:1afd:b16:ecb9\n\tDestination Port:\t\t135\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t65786\n\tLayer Name:\t\tReceive/Accept\n\tLayer Run-Time ID:\t46","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"a964b818b476262fc3c0edeede2156cca6f60a76c433d8eaee73a3f2042dec12","action":"Filtering Platform Connection","created":"2026-05-05T07:53:30.800Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:29.474Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":3200}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","event_id":5156,"opcode":"Info","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","version":1,"api":"wineventlog","record_id":204125206,"task":"Filtering Platform Connection","event_data":{"Direction":"%%14592","DestPort":"135","DestAddress":"fe80::6c1c:1afd:b16:ecb9","SourceAddress":"fe80::6c1c:1afd:b16:ecb9","ProcessID":"928","LayerName":"%%14610","Protocol":"6","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","Application":"\\device\\harddiskvolume2\\windows\\system32\\svchost.exe","LayerRTID":"46","FilterRTID":"65786","SourcePort":"59269"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\tfe80::6c1c:1afd:b16:ecb9\n\tSource Port:\t\t56915\n\tDestination Address:\tfe80::6c1c:1afd:b16:ecb9\n\tDestination Port:\t\t49669\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t65786\n\tLayer Name:\t\tReceive/Accept\n\tLayer Run-Time ID:\t46","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"15024eeaf378706099a53c553033121b0eb8180200e0e2a6a921ab1cc4054ad1","action":"Filtering Platform Connection","created":"2026-05-05T07:53:30.800Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:29.474Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":3200}},"event_id":5156,"opcode":"Info","version":1,"api":"wineventlog","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":204125207,"task":"Filtering Platform Connection","event_data":{"SourcePort":"56915","DestPort":"49669","DestAddress":"fe80::6c1c:1afd:b16:ecb9","SourceAddress":"fe80::6c1c:1afd:b16:ecb9","ProcessID":"684","Protocol":"6","LayerName":"%%14610","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"46","FilterRTID":"65786","Direction":"%%14592"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T07:43:50.315Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:43:48.986Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":120}},"computer_name":"w2016ad-n25.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":4703,"opcode":"Info","api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"record_id":253523617,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"W2016AD-N25$","TargetUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t0\n\tApplication Name:\t-\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.196\n\tSource Port:\t\t41807\n\tDestination Address:\t239.255.255.250\n\tDestination Port:\t\t1900\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t67801\n\tLayer Name:\t\tTransport\n\tLayer Run-Time ID:\t13","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"3c0dee3dbdc8565097384cc8cdbc889fe46f51b786ea28610447469ffa05bb90","action":"Filtering Platform Packet Drop","created":"2026-05-05T07:53:37.841Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:36.015Z","agent":{"name":"WIN-MDLQ2GQ94V9","id":"829caaa0-db4b-40b2-8076-11ac1493a97b","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1008}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5152,"api":"wineventlog","keywords":["Audit Failure"],"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":204125208,"task":"Filtering Platform Packet Drop","event_data":{"SourcePort":"41807","DestPort":"1900","ProcessId":"0","DestAddress":"239.255.255.250","SourceAddress":"172.30.4.196","Protocol":"17","LayerName":"%%14597","Application":"-","LayerRTID":"13","FilterRTID":"67801","Direction":"%%14592"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t0\n\tApplication Name:\t-\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.197\n\tSource Port:\t\t35339\n\tDestination Address:\t239.255.255.250\n\tDestination Port:\t\t1900\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t67801\n\tLayer Name:\t\tTransport\n\tLayer Run-Time ID:\t13","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"55abd428527411b891ebc71e27ec774af786c2a698f308069fe95fc678f83caf","action":"Filtering Platform Packet Drop","created":"2026-05-05T07:53:38.856Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:37.116Z","agent":{"name":"WIN-MDLQ2GQ94V9","id":"829caaa0-db4b-40b2-8076-11ac1493a97b","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":1008}},"event_id":5152,"api":"wineventlog","opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Failure"],"record_id":204125209,"task":"Filtering Platform Packet Drop","event_data":{"SourcePort":"35339","DestPort":"1900","ProcessId":"0","DestAddress":"239.255.255.250","SourceAddress":"172.30.4.197","LayerName":"%%14597","Protocol":"17","Application":"-","LayerRTID":"13","FilterRTID":"67801","Direction":"%%14592"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T07:43:50.315Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:43:48.995Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":120}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","event_id":4703,"opcode":"Info","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","record_id":253523618,"task":"Token Right Adjusted Events","event_data":{"TargetUserName":"W2016AD-N25$","SubjectUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t0\n\tApplication Name:\t-\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.197\n\tSource Port:\t\t35339\n\tDestination Address:\t239.255.255.250\n\tDestination Port:\t\t1900\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t67801\n\tLayer Name:\t\tTransport\n\tLayer Run-Time ID:\t13","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"55abd428527411b891ebc71e27ec774af786c2a698f308069fe95fc678f83caf","action":"Filtering Platform Packet Drop","created":"2026-05-05T07:53:38.856Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:37.116Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1008}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","event_id":5152,"api":"wineventlog","keywords":["Audit Failure"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","record_id":204125210,"task":"Filtering Platform Packet Drop","event_data":{"SourcePort":"35339","DestPort":"1900","ProcessId":"0","DestAddress":"239.255.255.250","SourceAddress":"172.30.4.197","LayerName":"%%14597","Protocol":"17","Application":"-","LayerRTID":"13","FilterRTID":"67801","Direction":"%%14592"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T07:43:50.315Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:43:48.995Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":120}},"computer_name":"w2016ad-n25.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":4703,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","keywords":["Audit Success"],"record_id":253523619,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"W2016AD-N25$","TargetUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectUserSid":"S-1-5-18","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x124\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"9bc7c5f2ac31ab3658a5fd52924314bfdb24b2a602e67e1e82efdb87cd26e038","action":"Token Right Adjusted Events","created":"2026-05-05T07:53:38.856Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:37.578Z","agent":{"name":"WIN-MDLQ2GQ94V9","id":"829caaa0-db4b-40b2-8076-11ac1493a97b","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1008}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","event_id":4703,"api":"wineventlog","opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"record_id":204125211,"task":"Token Right Adjusted Events","event_data":{"TargetUserName":"WIN-MDLQ2GQ94V9$","SubjectUserName":"WIN-MDLQ2GQ94V9$","ProcessId":"0x124","SubjectDomainName":"TDARPLATFORM","SubjectUserSid":"S-1-5-18","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T07:43:50.315Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:43:48.996Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":120}},"computer_name":"w2016ad-n25.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":4703,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","keywords":["Audit Success"],"record_id":253523620,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"W2016AD-N25$","TargetUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x124\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"9bc7c5f2ac31ab3658a5fd52924314bfdb24b2a602e67e1e82efdb87cd26e038","action":"Token Right Adjusted Events","created":"2026-05-05T07:53:38.856Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:37.579Z","agent":{"name":"WIN-MDLQ2GQ94V9","id":"829caaa0-db4b-40b2-8076-11ac1493a97b","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1008}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":4703,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"opcode":"Info","record_id":204125212,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"WIN-MDLQ2GQ94V9$","TargetUserName":"WIN-MDLQ2GQ94V9$","ProcessId":"0x124","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T07:43:50.315Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:43:48.997Z","agent":{"name":"w2016ad-n25","id":"16b27c50-d19b-4829-8363-ff3aabf1f846","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":120}},"event_id":4703,"opcode":"Info","keywords":["Audit Success"],"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":253523621,"task":"Token Right Adjusted Events","event_data":{"TargetUserName":"W2016AD-N25$","SubjectUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x124\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"9bc7c5f2ac31ab3658a5fd52924314bfdb24b2a602e67e1e82efdb87cd26e038","action":"Token Right Adjusted Events","created":"2026-05-05T07:53:38.856Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:37.582Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","process":{"pid":4,"thread":{"id":1008}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","event_id":4703,"api":"wineventlog","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","record_id":204125213,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"WIN-MDLQ2GQ94V9$","TargetUserName":"WIN-MDLQ2GQ94V9$","ProcessId":"0x124","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectUserSid":"S-1-5-18","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t2476\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\dfsrs.exe\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\tfe80::6c1c:1afd:b16:ecb9\n\tSource Port:\t\t59201\n\tDestination Address:\tfe80::cd46:3442:b9b4:26f4\n\tDestination Port:\t\t54781\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t66908\n\tLayer Name:\t\tReceive/Accept\n\tLayer Run-Time ID:\t46","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"0652f0efc8ce5c436c573f71fabed22d6a8c8d5f1a28fd803696369a983015dd","action":"Filtering Platform Connection","created":"2026-05-05T07:43:50.315Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:43:49.373Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":2748}},"computer_name":"w2016ad-n25.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5156,"api":"wineventlog","keywords":["Audit Success"],"version":1,"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","record_id":253523622,"task":"Filtering Platform Connection","event_data":{"Direction":"%%14592","DestPort":"54781","DestAddress":"fe80::cd46:3442:b9b4:26f4","SourceAddress":"fe80::6c1c:1afd:b16:ecb9","ProcessID":"2476","Protocol":"6","LayerName":"%%14610","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","Application":"\\device\\harddiskvolume2\\windows\\system32\\dfsrs.exe","LayerRTID":"46","FilterRTID":"66908","SourcePort":"59201"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x124\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"9bc7c5f2ac31ab3658a5fd52924314bfdb24b2a602e67e1e82efdb87cd26e038","action":"Token Right Adjusted Events","created":"2026-05-05T07:53:38.856Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:37.591Z","agent":{"name":"WIN-MDLQ2GQ94V9","id":"829caaa0-db4b-40b2-8076-11ac1493a97b","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1008}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","event_id":4703,"api":"wineventlog","opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"record_id":204125214,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"WIN-MDLQ2GQ94V9$","TargetUserName":"WIN-MDLQ2GQ94V9$","ProcessId":"0x124","SubjectDomainName":"TDARPLATFORM","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"An account was logged off.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-21-2744872422-3021103393-397187185-1104\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x15544C5\n\nLogon Type:\t\t\t3\n\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"fb271a3f296e29e5a07f177c547936c9076b00177afa7603af8fd308af94ed98","action":"Logoff","created":"2026-05-05T07:43:50.315Z","code":4634,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:43:49.373Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":660,"thread":{"id":2484}},"computer_name":"w2016ad-n25.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":4634,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","keywords":["Audit Success"],"record_id":253523623,"task":"Logoff","event_data":{"LogonType":"3","TargetUserName":"WIN-MDLQ2GQ94V9$","TargetLogonId":"0x15544c5","TargetUserSid":"S-1-5-21-2744872422-3021103393-397187185-1104","TargetDomainName":"TDARPLATFORM"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x124\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"9bc7c5f2ac31ab3658a5fd52924314bfdb24b2a602e67e1e82efdb87cd26e038","action":"Token Right Adjusted Events","created":"2026-05-05T07:53:38.856Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:37.591Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1008}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":4703,"api":"wineventlog","keywords":["Audit Success"],"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":204125215,"task":"Token Right Adjusted Events","event_data":{"TargetUserName":"WIN-MDLQ2GQ94V9$","SubjectUserName":"WIN-MDLQ2GQ94V9$","ProcessId":"0x124","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectUserSid":"S-1-5-18","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t0\n\tApplication Name:\t-\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.197\n\tSource Port:\t\t58566\n\tDestination Address:\t239.255.255.250\n\tDestination Port:\t\t1900\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t67683\n\tLayer Name:\t\tTransport\n\tLayer Run-Time ID:\t13","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"ef8ea3ba3bf447b9e0895b9844bb8d4e16720b215915870ac59965a69c916f95","action":"Filtering Platform Packet Drop","created":"2026-05-05T07:43:50.315Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:43:49.754Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":2748}},"event_id":5152,"api":"wineventlog","keywords":["Audit Failure"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","record_id":253523624,"task":"Filtering Platform Packet Drop","event_data":{"Direction":"%%14592","DestPort":"1900","ProcessId":"0","DestAddress":"239.255.255.250","SourceAddress":"172.30.4.197","Protocol":"17","LayerName":"%%14597","Application":"-","LayerRTID":"13","FilterRTID":"67683","SourcePort":"58566"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x124\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"9bc7c5f2ac31ab3658a5fd52924314bfdb24b2a602e67e1e82efdb87cd26e038","action":"Token Right Adjusted Events","created":"2026-05-05T07:53:38.856Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:37.591Z","agent":{"name":"WIN-MDLQ2GQ94V9","id":"829caaa0-db4b-40b2-8076-11ac1493a97b","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1008}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","event_id":4703,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","keywords":["Audit Success"],"record_id":204125216,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"WIN-MDLQ2GQ94V9$","TargetUserName":"WIN-MDLQ2GQ94V9$","ProcessId":"0x124","SubjectDomainName":"TDARPLATFORM","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t0\n\tApplication Name:\t-\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.197\n\tSource Port:\t\t1900\n\tDestination Address:\t239.255.255.250\n\tDestination Port:\t\t58566\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t67683\n\tLayer Name:\t\tTransport\n\tLayer Run-Time ID:\t13","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"90fe785bc8b1f696533ef5f6c56fa4a6194a524d92d56d035328725bbfb984dc","action":"Filtering Platform Packet Drop","created":"2026-05-05T07:43:50.315Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:43:49.754Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":2748}},"event_id":5152,"opcode":"Info","api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Failure"],"record_id":253523625,"task":"Filtering Platform Packet Drop","event_data":{"SourcePort":"1900","DestPort":"58566","ProcessId":"0","DestAddress":"239.255.255.250","SourceAddress":"172.30.4.197","LayerName":"%%14597","Protocol":"17","Application":"-","LayerRTID":"13","FilterRTID":"67683","Direction":"%%14592"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t2476\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\dfsrs.exe\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\tfe80::6c1c:1afd:b16:ecb9\n\tSource Port:\t\t56924\n\tDestination Address:\tfe80::cd46:3442:b9b4:26f4\n\tDestination Port:\t\t54781\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t66908\n\tLayer Name:\t\tReceive/Accept\n\tLayer Run-Time ID:\t46","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"5cd78fcbcf4507547e0a5e97c377e85c212dab39028cef2c9ea214fd1cca1c60","action":"Filtering Platform Connection","created":"2026-05-05T07:43:53.324Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:43:51.825Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","process":{"pid":4,"thread":{"id":2748}},"computer_name":"w2016ad-n25.tdarplatform.csoc","event_id":5156,"opcode":"Info","api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"version":1,"record_id":253523626,"task":"Filtering Platform Connection","event_data":{"Direction":"%%14592","DestPort":"54781","DestAddress":"fe80::cd46:3442:b9b4:26f4","SourceAddress":"fe80::6c1c:1afd:b16:ecb9","ProcessID":"2476","Protocol":"6","LayerName":"%%14610","RemoteMachineID":"S-1-0-0","Application":"\\device\\harddiskvolume2\\windows\\system32\\dfsrs.exe","LayerRTID":"46","RemoteUserID":"S-1-0-0","FilterRTID":"66908","SourcePort":"56924"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x124\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"9bc7c5f2ac31ab3658a5fd52924314bfdb24b2a602e67e1e82efdb87cd26e038","action":"Token Right Adjusted Events","created":"2026-05-05T07:53:38.856Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:37.593Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":1008}},"event_id":4703,"api":"wineventlog","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","record_id":204125217,"task":"Token Right Adjusted Events","event_data":{"TargetUserName":"WIN-MDLQ2GQ94V9$","SubjectUserName":"WIN-MDLQ2GQ94V9$","ProcessId":"0x124","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t660\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t::1\n\tSource Port:\t\t55802\n\tDestination Address:\t::1\n\tDestination Port:\t\t389\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t65786\n\tLayer Name:\t\tReceive/Accept\n\tLayer Run-Time ID:\t46","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"6e69593add3abb2dc976d49cb731e80bddda402bd7c122a804325066f013349f","action":"Filtering Platform Connection","created":"2026-05-05T07:43:56.349Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:43:55.032Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":120}},"event_id":5156,"opcode":"Info","version":1,"keywords":["Audit Success"],"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":253523627,"task":"Filtering Platform Connection","event_data":{"SourcePort":"55802","DestPort":"389","DestAddress":"::1","SourceAddress":"::1","ProcessID":"660","Protocol":"6","LayerName":"%%14610","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","LayerRTID":"46","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","FilterRTID":"65786","Direction":"%%14592"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t2488\n\tApplication Name:\t\\device\\harddiskvolume2\\program files (x86)\\ossec-agent\\wazuh-agent.exe\n\nNetwork Information:\n\tSource Address:\t\t0.0.0.0\n\tSource Port:\t\t55858\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t36","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"742a93642791c02e1dbb12c24b2b7720540ce501fca466f615093de673a542fb","action":"Filtering Platform Connection","created":"2026-05-05T07:44:03.407Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:44:01.839Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":120}},"event_id":5158,"api":"wineventlog","keywords":["Audit Success"],"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":253523628,"task":"Filtering Platform Connection","event_data":{"LayerName":"%%14608","Protocol":"6","ProcessId":"2488","Application":"\\device\\harddiskvolume2\\program files (x86)\\ossec-agent\\wazuh-agent.exe","LayerRTID":"36","SourceAddress":"0.0.0.0","FilterRTID":"0","SourcePort":"55858"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x124\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"9bc7c5f2ac31ab3658a5fd52924314bfdb24b2a602e67e1e82efdb87cd26e038","action":"Token Right Adjusted Events","created":"2026-05-05T07:53:38.856Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:37.602Z","agent":{"name":"WIN-MDLQ2GQ94V9","id":"829caaa0-db4b-40b2-8076-11ac1493a97b","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1008}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","event_id":4703,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"api":"wineventlog","record_id":204125218,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"WIN-MDLQ2GQ94V9$","TargetUserName":"WIN-MDLQ2GQ94V9$","ProcessId":"0x124","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t2488\n\tApplication Name:\t\\device\\harddiskvolume2\\program files (x86)\\ossec-agent\\wazuh-agent.exe\n\nNetwork Information:\n\tDirection:\t\tOutbound\n\tSource Address:\t\t172.30.4.206\n\tSource Port:\t\t55858\n\tDestination Address:\t172.30.2.163\n\tDestination Port:\t\t1514\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t67057\n\tLayer Name:\t\tConnect\n\tLayer Run-Time ID:\t48","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"4b23cfd131ed8e04b943dfa8a6d80d741b7e4f243e37552e2d69d3350cf78eca","action":"Filtering Platform Connection","created":"2026-05-05T07:44:03.407Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:44:01.839Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":120}},"computer_name":"w2016ad-n25.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5156,"opcode":"Info","keywords":["Audit Success"],"version":1,"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","record_id":253523629,"task":"Filtering Platform Connection","event_data":{"SourcePort":"55858","DestPort":"1514","DestAddress":"172.30.2.163","SourceAddress":"172.30.4.206","ProcessID":"2488","LayerName":"%%14611","Protocol":"6","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","Application":"\\device\\harddiskvolume2\\program files (x86)\\ossec-agent\\wazuh-agent.exe","LayerRTID":"48","FilterRTID":"67057","Direction":"%%14593"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x124\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"9bc7c5f2ac31ab3658a5fd52924314bfdb24b2a602e67e1e82efdb87cd26e038","action":"Token Right Adjusted Events","created":"2026-05-05T07:53:38.856Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:37.603Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":1008}},"event_id":4703,"opcode":"Info","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","record_id":204125219,"task":"Token Right Adjusted Events","event_data":{"TargetUserName":"WIN-MDLQ2GQ94V9$","SubjectUserName":"WIN-MDLQ2GQ94V9$","ProcessId":"0x124","SubjectDomainName":"TDARPLATFORM","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t4\n\tApplication Name:\tSystem\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.112\n\tSource Port:\t\t1\n\tDestination Address:\t172.30.4.206\n\tDestination Port:\t\t5\n\tProtocol:\t\t1\n\nFilter Information:\n\tFilter Run-Time ID:\t67043\n\tLayer Name:\t\tReceive/Accept\n\tLayer Run-Time ID:\t44","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"59d4e6fd3efc9fdfbf21ddc742f8e54b5fdd460bf3a7c4c72da1d8e7bd0a7eb2","action":"Filtering Platform Packet Drop","created":"2026-05-05T07:44:04.418Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:44:03.120Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":2320}},"event_id":5152,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","keywords":["Audit Failure"],"record_id":253523630,"task":"Filtering Platform Packet Drop","event_data":{"Direction":"%%14592","DestPort":"5","ProcessId":"4","DestAddress":"172.30.4.206","SourceAddress":"172.30.4.112","Protocol":"1","LayerName":"%%14610","Application":"System","LayerRTID":"44","FilterRTID":"67043","SourcePort":"1"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x124\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"9bc7c5f2ac31ab3658a5fd52924314bfdb24b2a602e67e1e82efdb87cd26e038","action":"Token Right Adjusted Events","created":"2026-05-05T07:53:38.856Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:37.603Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":1008}},"event_id":4703,"opcode":"Info","api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"record_id":204125220,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"WIN-MDLQ2GQ94V9$","TargetUserName":"WIN-MDLQ2GQ94V9$","ProcessId":"0x124","SubjectDomainName":"TDARPLATFORM","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a connection.\n\nApplication Information:\n\tProcess ID:\t\t4\n\tApplication Name:\tSystem\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.112\n\tSource Port:\t\t1\n\tDestination Address:\t172.30.4.206\n\tDestination Port:\t\t5\n\tProtocol:\t\t1\n\nFilter Information:\n\tFilter Run-Time ID:\t67043\n\tLayer Name:\t\tReceive/Accept\n\tLayer Run-Time ID:\t44","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"6987b944789e44488a6c2f71ef2527b4b6b877145ed23dd5763b3bb3078a497f","action":"Filtering Platform Connection","created":"2026-05-05T07:44:04.418Z","code":5157,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:44:03.120Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":2320}},"event_id":5157,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Failure"],"version":1,"api":"wineventlog","record_id":253523631,"task":"Filtering Platform Connection","event_data":{"SourcePort":"1","DestPort":"5","DestAddress":"172.30.4.206","SourceAddress":"172.30.4.112","ProcessID":"4","Protocol":"1","LayerName":"%%14610","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","Application":"System","LayerRTID":"44","FilterRTID":"67043","Direction":"%%14592"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tWIN-MDLQ2GQ94V9$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x124\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"9bc7c5f2ac31ab3658a5fd52924314bfdb24b2a602e67e1e82efdb87cd26e038","action":"Token Right Adjusted Events","created":"2026-05-05T07:53:38.856Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:37.604Z","agent":{"name":"WIN-MDLQ2GQ94V9","id":"829caaa0-db4b-40b2-8076-11ac1493a97b","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1008}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","event_id":4703,"api":"wineventlog","opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"record_id":204125221,"task":"Token Right Adjusted Events","event_data":{"TargetUserName":"WIN-MDLQ2GQ94V9$","SubjectUserName":"WIN-MDLQ2GQ94V9$","ProcessId":"0x124","SubjectDomainName":"TDARPLATFORM","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t4\n\tApplication Name:\tSystem\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.112\n\tSource Port:\t\t1\n\tDestination Address:\t172.30.4.206\n\tDestination Port:\t\t5\n\tProtocol:\t\t1\n\nFilter Information:\n\tFilter Run-Time ID:\t67043\n\tLayer Name:\t\tReceive/Accept\n\tLayer Run-Time ID:\t44","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"59d4e6fd3efc9fdfbf21ddc742f8e54b5fdd460bf3a7c4c72da1d8e7bd0a7eb2","action":"Filtering Platform Packet Drop","created":"2026-05-05T07:44:06.433Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:44:04.710Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1096}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","event_id":5152,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","keywords":["Audit Failure"],"record_id":253523632,"task":"Filtering Platform Packet Drop","event_data":{"Direction":"%%14592","DestPort":"5","ProcessId":"4","DestAddress":"172.30.4.206","SourceAddress":"172.30.4.112","LayerName":"%%14610","Protocol":"1","Application":"System","LayerRTID":"44","FilterRTID":"67043","SourcePort":"1"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t2668\n\tApplication Name:\t\\device\\harddiskvolume2\\program files (x86)\\ossec-agent\\wazuh-agent.exe\n\nNetwork Information:\n\tSource Address:\t\t0.0.0.0\n\tSource Port:\t\t59270\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t36","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"ca70d9d3f1e9da1e9f0e19776915e804425d75bce9c048405b3b652d39bae283","action":"Filtering Platform Connection","created":"2026-05-05T07:53:40.862Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:39.650Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":3200}},"event_id":5158,"api":"wineventlog","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","record_id":204125222,"task":"Filtering Platform Connection","event_data":{"Protocol":"6","LayerName":"%%14608","ProcessId":"2668","Application":"\\device\\harddiskvolume2\\program files (x86)\\ossec-agent\\wazuh-agent.exe","LayerRTID":"36","SourceAddress":"0.0.0.0","FilterRTID":"0","SourcePort":"59270"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a connection.\n\nApplication Information:\n\tProcess ID:\t\t4\n\tApplication Name:\tSystem\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.112\n\tSource Port:\t\t1\n\tDestination Address:\t172.30.4.206\n\tDestination Port:\t\t5\n\tProtocol:\t\t1\n\nFilter Information:\n\tFilter Run-Time ID:\t67043\n\tLayer Name:\t\tReceive/Accept\n\tLayer Run-Time ID:\t44","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"6987b944789e44488a6c2f71ef2527b4b6b877145ed23dd5763b3bb3078a497f","action":"Filtering Platform Connection","created":"2026-05-05T07:44:06.433Z","code":5157,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:44:04.710Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1096}},"computer_name":"w2016ad-n25.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5157,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","version":1,"opcode":"Info","keywords":["Audit Failure"],"record_id":253523633,"task":"Filtering Platform Connection","event_data":{"Direction":"%%14592","DestPort":"5","DestAddress":"172.30.4.206","SourceAddress":"172.30.4.112","ProcessID":"4","Protocol":"1","LayerName":"%%14610","RemoteMachineID":"S-1-0-0","Application":"System","LayerRTID":"44","RemoteUserID":"S-1-0-0","FilterRTID":"67043","SourcePort":"1"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t0\n\tApplication Name:\t-\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.2.163\n\tSource Port:\t\t1514\n\tDestination Address:\t172.30.4.206\n\tDestination Port:\t\t55858\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t67042\n\tLayer Name:\t\tICMP Error\n\tLayer Run-Time ID:\t28","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"41ffdf434c477bff91d848e12f55fe6f3553471c99915dfd16187bd567b6479b","action":"Filtering Platform Packet Drop","created":"2026-05-05T07:44:06.433Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:44:04.850Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1096}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","event_id":5152,"opcode":"Info","keywords":["Audit Failure"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","record_id":253523634,"task":"Filtering Platform Packet Drop","event_data":{"Direction":"%%14592","DestPort":"55858","ProcessId":"0","DestAddress":"172.30.4.206","SourceAddress":"172.30.2.163","LayerName":"%%14601","Protocol":"6","Application":"-","LayerRTID":"28","FilterRTID":"67042","SourcePort":"1514"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t2668\n\tApplication Name:\t\\device\\harddiskvolume2\\program files (x86)\\ossec-agent\\wazuh-agent.exe\n\nNetwork Information:\n\tDirection:\t\tOutbound\n\tSource Address:\t\t172.30.4.205\n\tSource Port:\t\t59270\n\tDestination Address:\t172.30.2.163\n\tDestination Port:\t\t1514\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t67111\n\tLayer Name:\t\tConnect\n\tLayer Run-Time ID:\t48","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"5b8e234e8af08033bac4469b6fbc2e8c90fead0dcc85f620930aede21fa8790e","action":"Filtering Platform Connection","created":"2026-05-05T07:53:40.862Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:39.650Z","agent":{"name":"WIN-MDLQ2GQ94V9","id":"829caaa0-db4b-40b2-8076-11ac1493a97b","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":3200}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5156,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"opcode":"Info","version":1,"record_id":204125223,"task":"Filtering Platform Connection","event_data":{"SourcePort":"59270","DestPort":"1514","DestAddress":"172.30.2.163","SourceAddress":"172.30.4.205","ProcessID":"2668","Protocol":"6","LayerName":"%%14611","RemoteMachineID":"S-1-0-0","Application":"\\device\\harddiskvolume2\\program files (x86)\\ossec-agent\\wazuh-agent.exe","LayerRTID":"48","RemoteUserID":"S-1-0-0","FilterRTID":"67111","Direction":"%%14593"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t0\n\tApplication Name:\t-\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.2.163\n\tSource Port:\t\t1514\n\tDestination Address:\t172.30.4.206\n\tDestination Port:\t\t55858\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t67042\n\tLayer Name:\t\tICMP Error\n\tLayer Run-Time ID:\t28","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"41ffdf434c477bff91d848e12f55fe6f3553471c99915dfd16187bd567b6479b","action":"Filtering Platform Packet Drop","created":"2026-05-05T07:44:06.433Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:44:04.850Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1096}},"computer_name":"w2016ad-n25.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5152,"opcode":"Info","keywords":["Audit Failure"],"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":253523635,"task":"Filtering Platform Packet Drop","event_data":{"Direction":"%%14592","DestPort":"55858","ProcessId":"0","DestAddress":"172.30.4.206","SourceAddress":"172.30.2.163","Protocol":"6","LayerName":"%%14601","Application":"-","LayerRTID":"28","FilterRTID":"67042","SourcePort":"1514"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t0\n\tApplication Name:\t-\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.2.163\n\tSource Port:\t\t1514\n\tDestination Address:\t172.30.4.205\n\tDestination Port:\t\t59270\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t67096\n\tLayer Name:\t\tICMP Error\n\tLayer Run-Time ID:\t28","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"1e972e021441351ddc185b601b77c046361307beb161b6ed6e143a1bfe51af68","action":"Filtering Platform Packet Drop","created":"2026-05-05T07:53:43.889Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:42.641Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":2912}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5152,"api":"wineventlog","keywords":["Audit Failure"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","record_id":204125224,"task":"Filtering Platform Packet Drop","event_data":{"Direction":"%%14592","DestPort":"59270","ProcessId":"0","DestAddress":"172.30.4.205","SourceAddress":"172.30.2.163","LayerName":"%%14601","Protocol":"6","Application":"-","LayerRTID":"28","FilterRTID":"67096","SourcePort":"1514"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t0\n\tApplication Name:\t-\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.196\n\tSource Port:\t\t41807\n\tDestination Address:\t239.255.255.250\n\tDestination Port:\t\t1900\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t67683\n\tLayer Name:\t\tTransport\n\tLayer Run-Time ID:\t13","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"3354b778926a79b0d6f9f99c2082cb96ff54936b0374dac14aa3eed93bf9d056","action":"Filtering Platform Packet Drop","created":"2026-05-05T07:44:07.441Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:44:05.993Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":1096}},"event_id":5152,"opcode":"Info","keywords":["Audit Failure"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","record_id":253523636,"task":"Filtering Platform Packet Drop","event_data":{"Direction":"%%14592","DestPort":"1900","ProcessId":"0","DestAddress":"239.255.255.250","SourceAddress":"172.30.4.196","LayerName":"%%14597","Protocol":"17","Application":"-","LayerRTID":"13","FilterRTID":"67683","SourcePort":"41807"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t4\n\tApplication Name:\tSystem\n\nNetwork Information:\n\tDirection:\t\tOutbound\n\tSource Address:\t\t172.30.4.205\n\tSource Port:\t\t137\n\tDestination Address:\t172.30.4.25\n\tDestination Port:\t\t137\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t67111\n\tLayer Name:\t\tConnect\n\tLayer Run-Time ID:\t48","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"15e8487ee02ae362c3433394d2eabfbacb8a9e6034d49a29be808afe0a90e1f8","action":"Filtering Platform Connection","created":"2026-05-05T07:53:43.889Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:43.370Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":4796}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","event_id":5156,"opcode":"Info","keywords":["Audit Success"],"version":1,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":204125225,"task":"Filtering Platform Connection","event_data":{"SourcePort":"137","DestPort":"137","DestAddress":"172.30.4.25","SourceAddress":"172.30.4.205","ProcessID":"4","LayerName":"%%14611","Protocol":"17","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","LayerRTID":"48","Application":"System","FilterRTID":"67111","Direction":"%%14593"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T07:44:10.473Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:44:08.975Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1096}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","event_id":4703,"api":"wineventlog","keywords":["Audit Success"],"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":253523637,"task":"Token Right Adjusted Events","event_data":{"TargetUserName":"W2016AD-N25$","SubjectUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectUserSid":"S-1-5-18","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T07:44:10.474Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:44:08.976Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","process":{"pid":4,"thread":{"id":1096}},"computer_name":"w2016ad-n25.tdarplatform.csoc","event_id":4703,"api":"wineventlog","keywords":["Audit Success"],"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":253523638,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"W2016AD-N25$","TargetUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","SubjectUserSid":"S-1-5-18","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t4\n\tApplication Name:\tSystem\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.112\n\tSource Port:\t\t1\n\tDestination Address:\t172.30.4.205\n\tDestination Port:\t\t5\n\tProtocol:\t\t1\n\nFilter Information:\n\tFilter Run-Time ID:\t67097\n\tLayer Name:\t\tReceive/Accept\n\tLayer Run-Time ID:\t44","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"e4ccf948fee2b28b71f542fec3c0e29ccfa0a27f71cb89735b6a060f8f80819e","action":"Filtering Platform Packet Drop","created":"2026-05-05T07:53:46.915Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:44.885Z","agent":{"name":"WIN-MDLQ2GQ94V9","id":"829caaa0-db4b-40b2-8076-11ac1493a97b","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":4796}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5152,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Failure"],"api":"wineventlog","record_id":204125226,"task":"Filtering Platform Packet Drop","event_data":{"SourcePort":"1","DestPort":"5","ProcessId":"4","DestAddress":"172.30.4.205","SourceAddress":"172.30.4.112","Protocol":"1","LayerName":"%%14610","Application":"System","LayerRTID":"44","FilterRTID":"67097","Direction":"%%14592"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a connection.\n\nApplication Information:\n\tProcess ID:\t\t4\n\tApplication Name:\tSystem\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.112\n\tSource Port:\t\t1\n\tDestination Address:\t172.30.4.205\n\tDestination Port:\t\t5\n\tProtocol:\t\t1\n\nFilter Information:\n\tFilter Run-Time ID:\t67097\n\tLayer Name:\t\tReceive/Accept\n\tLayer Run-Time ID:\t44","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"2650b9dcb8f7490e0a4c12167d313655d0392728c3e53a27bcb4e2444ee23b3e","action":"Filtering Platform Connection","created":"2026-05-05T07:53:46.915Z","code":5157,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:53:44.885Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":4796}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5157,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Failure"],"opcode":"Info","version":1,"record_id":204125227,"task":"Filtering Platform Connection","event_data":{"Direction":"%%14592","DestPort":"5","DestAddress":"172.30.4.205","SourceAddress":"172.30.4.112","ProcessID":"4","Protocol":"1","LayerName":"%%14610","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","LayerRTID":"44","Application":"System","FilterRTID":"67097","SourcePort":"1"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T07:44:10.474Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T07:44:08.978Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1096}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","event_id":4703,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"api":"wineventlog","record_id":253523639,"task":"Token Right Adjusted Events","event_data":{"TargetUserName":"W2016AD-N25$","SubjectUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectUserSid":"S-1-5-18","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}