{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T08:05:31.259Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:05:29.484Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":3948}},"computer_name":"w2016ad-n25.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":4703,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","keywords":["Audit Success"],"record_id":253526218,"task":"Token Right Adjusted Events","event_data":{"TargetUserName":"W2016AD-N25$","SubjectUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectUserSid":"S-1-5-18","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tSource Address:\t\t0.0.0.0\n\tSource Port:\t\t55600\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t36","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"95a03f5ee033168fa8cd8545738d73479527f73dfa02af5412ad0c309e24ba04","action":"Filtering Platform Connection","created":"2026-05-05T08:11:59.584Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:11:58.838Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":4796}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5158,"api":"wineventlog","opcode":"Info","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":204127613,"task":"Filtering Platform Connection","event_data":{"Protocol":"17","LayerName":"%%14608","ProcessId":"684","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"36","SourceAddress":"0.0.0.0","FilterRTID":"0","SourcePort":"55600"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T08:05:31.259Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:05:29.486Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":3948}},"event_id":4703,"api":"wineventlog","opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"record_id":253526219,"task":"Token Right Adjusted Events","event_data":{"TargetUserName":"W2016AD-N25$","SubjectUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectUserSid":"S-1-5-18","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tSource Address:\t\t0.0.0.0\n\tSource Port:\t\t63485\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t36","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"837439a06a5cfc3ad00b096506e35a2095e6312d76ae528b5095d041061ba0f0","action":"Filtering Platform Connection","created":"2026-05-05T08:11:59.584Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:11:58.838Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":4796}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5158,"api":"wineventlog","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","record_id":204127614,"task":"Filtering Platform Connection","event_data":{"Protocol":"17","LayerName":"%%14608","ProcessId":"684","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"36","SourceAddress":"0.0.0.0","FilterRTID":"0","SourcePort":"63485"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T08:05:31.259Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:05:29.495Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":3948}},"computer_name":"w2016ad-n25.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":4703,"opcode":"Info","api":"wineventlog","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":253526220,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"W2016AD-N25$","TargetUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","SubjectUserSid":"S-1-5-18","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tDirection:\t\tOutbound\n\tSource Address:\t\t172.30.4.205\n\tSource Port:\t\t63485\n\tDestination Address:\t172.30.4.205\n\tDestination Port:\t\t53\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t65789\n\tLayer Name:\t\tConnect\n\tLayer Run-Time ID:\t48","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"ff529b61d7f0790c0c4e50f14ba019a7687f381073b8320581dc71d770838a1c","action":"Filtering Platform Connection","created":"2026-05-05T08:11:59.584Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:11:58.838Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":4796}},"event_id":5156,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","version":1,"keywords":["Audit Success"],"api":"wineventlog","record_id":204127615,"task":"Filtering Platform Connection","event_data":{"SourcePort":"63485","DestPort":"53","DestAddress":"172.30.4.205","SourceAddress":"172.30.4.205","ProcessID":"684","LayerName":"%%14611","Protocol":"17","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","LayerRTID":"48","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","FilterRTID":"65789","Direction":"%%14593"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T08:05:31.259Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:05:29.495Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":3948}},"event_id":4703,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"api":"wineventlog","record_id":253526221,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"W2016AD-N25$","TargetUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectUserSid":"S-1-5-18","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t2444\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\dns.exe\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.205\n\tSource Port:\t\t63485\n\tDestination Address:\t172.30.4.205\n\tDestination Port:\t\t53\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t65787\n\tLayer Name:\t\tReceive/Accept\n\tLayer Run-Time ID:\t44","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"1046b11241a0c1d84ddb7efb6f4e6824091179b26e5991335c620f04ef255d04","action":"Filtering Platform Connection","created":"2026-05-05T08:11:59.584Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:11:58.838Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":4796}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5156,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","version":1,"api":"wineventlog","keywords":["Audit Success"],"record_id":204127616,"task":"Filtering Platform Connection","event_data":{"SourcePort":"63485","DestPort":"53","DestAddress":"172.30.4.205","SourceAddress":"172.30.4.205","ProcessID":"2444","LayerName":"%%14610","Protocol":"17","RemoteMachineID":"S-1-0-0","Application":"\\device\\harddiskvolume2\\windows\\system32\\dns.exe","LayerRTID":"44","RemoteUserID":"S-1-0-0","FilterRTID":"65787","Direction":"%%14592"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T08:05:31.259Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:05:29.495Z","agent":{"name":"w2016ad-n25","id":"16b27c50-d19b-4829-8363-ff3aabf1f846","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":3948}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","event_id":4703,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"opcode":"Info","record_id":253526222,"task":"Token Right Adjusted Events","event_data":{"TargetUserName":"W2016AD-N25$","SubjectUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t::1\n\tSource Port:\t\t59132\n\tDestination Address:\t::1\n\tDestination Port:\t\t389\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t65786\n\tLayer Name:\t\tReceive/Accept\n\tLayer Run-Time ID:\t46","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"93506dfb3abecd4fe8f124b5dc22f381e7878dc2c3f8645da1e0cb83f73c9a8e","action":"Filtering Platform Connection","created":"2026-05-05T08:11:59.584Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:11:58.839Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":4796}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5156,"opcode":"Info","keywords":["Audit Success"],"version":1,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":204127617,"task":"Filtering Platform Connection","event_data":{"Direction":"%%14592","DestPort":"389","DestAddress":"::1","SourceAddress":"::1","ProcessID":"684","Protocol":"6","LayerName":"%%14610","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","LayerRTID":"46","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","FilterRTID":"65786","SourcePort":"59132"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tSource Address:\t\t::\n\tSource Port:\t\t63485\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t36","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"66bbda52ed4a2a4ee9a93fc2c928150778a34ab5d6b680a72beea644311f9de4","action":"Filtering Platform Connection","created":"2026-05-05T08:11:59.584Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:11:58.876Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":4796}},"event_id":5158,"api":"wineventlog","keywords":["Audit Success"],"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":204127618,"task":"Filtering Platform Connection","event_data":{"LayerName":"%%14608","Protocol":"17","ProcessId":"684","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"36","SourceAddress":"::","FilterRTID":"0","SourcePort":"63485"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T08:05:31.259Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:05:29.497Z","agent":{"name":"w2016ad-n25","id":"16b27c50-d19b-4829-8363-ff3aabf1f846","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":3948}},"computer_name":"w2016ad-n25.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":4703,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","keywords":["Audit Success"],"record_id":253526223,"task":"Token Right Adjusted Events","event_data":{"TargetUserName":"W2016AD-N25$","SubjectUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectUserSid":"S-1-5-18","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tSource Address:\t\t::\n\tSource Port:\t\t63485\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t38","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"31ad9c3fcae7ab76876eb1002b7a6b3f65f29ef83dccb320187a8a4067f7318f","action":"Filtering Platform Connection","created":"2026-05-05T08:11:59.584Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:11:58.876Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":4796}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","event_id":5158,"opcode":"Info","api":"wineventlog","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":204127619,"task":"Filtering Platform Connection","event_data":{"Protocol":"17","LayerName":"%%14608","ProcessId":"684","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"38","SourceAddress":"::","FilterRTID":"0","SourcePort":"63485"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T08:05:31.259Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:05:29.510Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","process":{"pid":4,"thread":{"id":3948}},"computer_name":"w2016ad-n25.tdarplatform.csoc","event_id":4703,"api":"wineventlog","opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"record_id":253526224,"task":"Token Right Adjusted Events","event_data":{"TargetUserName":"W2016AD-N25$","SubjectUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tDirection:\t\tOutbound\n\tSource Address:\t\t::1\n\tSource Port:\t\t63485\n\tDestination Address:\t::1\n\tDestination Port:\t\t53\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t65788\n\tLayer Name:\t\tConnect\n\tLayer Run-Time ID:\t50","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"8c241c1569437ee50c68075816eb552cd9b1b5e80958d4fecb58960d3af38815","action":"Filtering Platform Connection","created":"2026-05-05T08:11:59.584Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:11:58.876Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","process":{"pid":4,"thread":{"id":4796}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","event_id":5156,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","version":1,"api":"wineventlog","keywords":["Audit Success"],"record_id":204127620,"task":"Filtering Platform Connection","event_data":{"SourcePort":"63485","DestPort":"53","DestAddress":"::1","SourceAddress":"::1","ProcessID":"684","LayerName":"%%14611","Protocol":"17","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","LayerRTID":"50","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","FilterRTID":"65788","Direction":"%%14593"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T08:05:31.259Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:05:29.510Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":3948}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","event_id":4703,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","keywords":["Audit Success"],"record_id":253526225,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"W2016AD-N25$","TargetUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T08:05:31.259Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:05:29.510Z","agent":{"name":"w2016ad-n25","id":"16b27c50-d19b-4829-8363-ff3aabf1f846","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":3948}},"event_id":4703,"api":"wineventlog","opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"record_id":253526226,"task":"Token Right Adjusted Events","event_data":{"TargetUserName":"W2016AD-N25$","SubjectUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t2444\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\dns.exe\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t::1\n\tSource Port:\t\t63485\n\tDestination Address:\t::1\n\tDestination Port:\t\t53\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t65786\n\tLayer Name:\t\tReceive/Accept\n\tLayer Run-Time ID:\t46","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"e4214e681c4c0a58f62eee50a4b81dd1c34e8d6163d5200ad202c9da528faa5e","action":"Filtering Platform Connection","created":"2026-05-05T08:11:59.584Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:11:58.876Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":4796}},"event_id":5156,"opcode":"Info","api":"wineventlog","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","version":1,"record_id":204127621,"task":"Filtering Platform Connection","event_data":{"SourcePort":"63485","DestPort":"53","DestAddress":"::1","SourceAddress":"::1","ProcessID":"2444","LayerName":"%%14610","Protocol":"17","RemoteMachineID":"S-1-0-0","Application":"\\device\\harddiskvolume2\\windows\\system32\\dns.exe","LayerRTID":"46","RemoteUserID":"S-1-0-0","FilterRTID":"65786","Direction":"%%14592"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T08:05:31.259Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:05:29.511Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":3948}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","event_id":4703,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","keywords":["Audit Success"],"record_id":253526227,"task":"Token Right Adjusted Events","event_data":{"TargetUserName":"W2016AD-N25$","SubjectUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectUserSid":"S-1-5-18","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tSource Address:\t\t::\n\tSource Port:\t\t63485\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t38","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"31ad9c3fcae7ab76876eb1002b7a6b3f65f29ef83dccb320187a8a4067f7318f","action":"Filtering Platform Connection","created":"2026-05-05T08:11:59.584Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:11:58.877Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":4796}},"event_id":5158,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","keywords":["Audit Success"],"record_id":204127622,"task":"Filtering Platform Connection","event_data":{"LayerName":"%%14608","Protocol":"17","ProcessId":"684","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"38","SourceAddress":"::","FilterRTID":"0","SourcePort":"63485"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t0\n\tApplication Name:\t-\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.2.163\n\tSource Port:\t\t1514\n\tDestination Address:\t172.30.4.206\n\tDestination Port:\t\t55976\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t67042\n\tLayer Name:\t\tICMP Error\n\tLayer Run-Time ID:\t28","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"78a917ba31383fb0ccad92206158bdbd0f275ceb6e9dd0c5596d3eb4d2a36061","action":"Filtering Platform Packet Drop","created":"2026-05-05T08:05:31.259Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:05:30.461Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1096}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","event_id":5152,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Failure"],"api":"wineventlog","record_id":253526228,"task":"Filtering Platform Packet Drop","event_data":{"SourcePort":"1514","DestPort":"55976","ProcessId":"0","DestAddress":"172.30.4.206","SourceAddress":"172.30.2.163","Protocol":"6","LayerName":"%%14601","Application":"-","LayerRTID":"28","FilterRTID":"67042","Direction":"%%14592"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tSource Address:\t\t0.0.0.0\n\tSource Port:\t\t63485\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t36","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"837439a06a5cfc3ad00b096506e35a2095e6312d76ae528b5095d041061ba0f0","action":"Filtering Platform Connection","created":"2026-05-05T08:11:59.584Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:11:58.877Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":4796}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5158,"api":"wineventlog","opcode":"Info","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":204127623,"task":"Filtering Platform Connection","event_data":{"Protocol":"17","LayerName":"%%14608","ProcessId":"684","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"36","SourceAddress":"0.0.0.0","FilterRTID":"0","SourcePort":"63485"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t0\n\tApplication Name:\t-\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.196\n\tSource Port:\t\t41807\n\tDestination Address:\t239.255.255.250\n\tDestination Port:\t\t1900\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t67683\n\tLayer Name:\t\tTransport\n\tLayer Run-Time ID:\t13","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"3354b778926a79b0d6f9f99c2082cb96ff54936b0374dac14aa3eed93bf9d056","action":"Filtering Platform Packet Drop","created":"2026-05-05T08:05:37.313Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:05:36.071Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":3948}},"computer_name":"w2016ad-n25.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5152,"opcode":"Info","keywords":["Audit Failure"],"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":253526229,"task":"Filtering Platform Packet Drop","event_data":{"SourcePort":"41807","DestPort":"1900","ProcessId":"0","DestAddress":"239.255.255.250","SourceAddress":"172.30.4.196","LayerName":"%%14597","Protocol":"17","Application":"-","LayerRTID":"13","FilterRTID":"67683","Direction":"%%14592"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tSource Address:\t\t::\n\tSource Port:\t\t50244\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t36","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"15d62ab3b452005a60c399db4db416a29f819f691ea2a84d4a5d9282a2af50d3","action":"Filtering Platform Connection","created":"2026-05-05T08:11:59.584Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:11:58.877Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":4796}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","event_id":5158,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","keywords":["Audit Success"],"record_id":204127624,"task":"Filtering Platform Connection","event_data":{"Protocol":"17","LayerName":"%%14608","ProcessId":"684","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"36","SourceAddress":"::","FilterRTID":"0","SourcePort":"50244"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t0\n\tApplication Name:\t-\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.2.163\n\tSource Port:\t\t1514\n\tDestination Address:\t172.30.4.206\n\tDestination Port:\t\t55976\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t67042\n\tLayer Name:\t\tICMP Error\n\tLayer Run-Time ID:\t28","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"78a917ba31383fb0ccad92206158bdbd0f275ceb6e9dd0c5596d3eb4d2a36061","action":"Filtering Platform Packet Drop","created":"2026-05-05T08:05:37.313Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:05:36.471Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":3948}},"computer_name":"w2016ad-n25.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5152,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Failure"],"opcode":"Info","record_id":253526230,"task":"Filtering Platform Packet Drop","event_data":{"Direction":"%%14592","DestPort":"55976","ProcessId":"0","DestAddress":"172.30.4.206","SourceAddress":"172.30.2.163","Protocol":"6","LayerName":"%%14601","Application":"-","LayerRTID":"28","FilterRTID":"67042","SourcePort":"1514"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tSource Address:\t\t::\n\tSource Port:\t\t50244\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t38","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"61bd97d931f5ba452dc4de11b43760ce17dd1fe36e377197236adf2ddd2fa601","action":"Filtering Platform Connection","created":"2026-05-05T08:11:59.584Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:11:58.877Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":4796}},"event_id":5158,"opcode":"Info","keywords":["Audit Success"],"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":204127625,"task":"Filtering Platform Connection","event_data":{"Protocol":"17","LayerName":"%%14608","ProcessId":"684","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"38","SourceAddress":"::","FilterRTID":"0","SourcePort":"50244"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tDirection:\t\tOutbound\n\tSource Address:\t\t172.30.4.205\n\tSource Port:\t\t50244\n\tDestination Address:\t172.30.4.206\n\tDestination Port:\t\t53\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t67111\n\tLayer Name:\t\tConnect\n\tLayer Run-Time ID:\t48","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"25ecfb142a02ad97e956471ba5c206de834bc80bef46f58d87cc540f8fcdc30f","action":"Filtering Platform Connection","created":"2026-05-05T08:11:59.584Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:11:58.877Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":4796}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","event_id":5156,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","version":1,"keywords":["Audit Success"],"opcode":"Info","record_id":204127626,"task":"Filtering Platform Connection","event_data":{"SourcePort":"50244","DestPort":"53","DestAddress":"172.30.4.206","SourceAddress":"172.30.4.205","ProcessID":"684","LayerName":"%%14611","Protocol":"17","RemoteMachineID":"S-1-0-0","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","RemoteUserID":"S-1-0-0","LayerRTID":"48","FilterRTID":"67111","Direction":"%%14593"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t0\n\tApplication Name:\t-\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.197\n\tSource Port:\t\t53146\n\tDestination Address:\t239.255.255.250\n\tDestination Port:\t\t1900\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t67683\n\tLayer Name:\t\tTransport\n\tLayer Run-Time ID:\t13","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"21549c77efca8573ef4e6c86f9ff355e7d6d1b4096c3546bc499131f6c97c64b","action":"Filtering Platform Packet Drop","created":"2026-05-05T08:05:39.343Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:05:37.280Z","agent":{"name":"w2016ad-n25","id":"16b27c50-d19b-4829-8363-ff3aabf1f846","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","process":{"pid":4,"thread":{"id":1096}},"computer_name":"w2016ad-n25.tdarplatform.csoc","event_id":5152,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","keywords":["Audit Failure"],"record_id":253526231,"task":"Filtering Platform Packet Drop","event_data":{"Direction":"%%14592","DestPort":"1900","ProcessId":"0","DestAddress":"239.255.255.250","SourceAddress":"172.30.4.197","Protocol":"17","LayerName":"%%14597","Application":"-","LayerRTID":"13","FilterRTID":"67683","SourcePort":"53146"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t0\n\tApplication Name:\t-\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.197\n\tSource Port:\t\t53146\n\tDestination Address:\t239.255.255.250\n\tDestination Port:\t\t1900\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t67683\n\tLayer Name:\t\tTransport\n\tLayer Run-Time ID:\t13","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"21549c77efca8573ef4e6c86f9ff355e7d6d1b4096c3546bc499131f6c97c64b","action":"Filtering Platform Packet Drop","created":"2026-05-05T08:05:39.343Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:05:37.280Z","agent":{"name":"w2016ad-n25","id":"16b27c50-d19b-4829-8363-ff3aabf1f846","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":1096}},"event_id":5152,"opcode":"Info","keywords":["Audit Failure"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","record_id":253526232,"task":"Filtering Platform Packet Drop","event_data":{"SourcePort":"53146","DestPort":"1900","ProcessId":"0","DestAddress":"239.255.255.250","SourceAddress":"172.30.4.197","LayerName":"%%14597","Protocol":"17","Application":"-","LayerRTID":"13","FilterRTID":"67683","Direction":"%%14592"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tSource Address:\t\t::\n\tSource Port:\t\t63485\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t38","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"31ad9c3fcae7ab76876eb1002b7a6b3f65f29ef83dccb320187a8a4067f7318f","action":"Filtering Platform Connection","created":"2026-05-05T08:11:59.584Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:11:58.878Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","process":{"pid":4,"thread":{"id":4796}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","event_id":5158,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"opcode":"Info","record_id":204127627,"task":"Filtering Platform Connection","event_data":{"Protocol":"17","LayerName":"%%14608","ProcessId":"684","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"38","SourceAddress":"::","FilterRTID":"0","SourcePort":"63485"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t4\n\tApplication Name:\tSystem\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.254\n\tSource Port:\t\t0\n\tDestination Address:\t224.0.0.1\n\tDestination Port:\t\t0\n\tProtocol:\t\t2\n\nFilter Information:\n\tFilter Run-Time ID:\t66906\n\tLayer Name:\t\tReceive/Accept\n\tLayer Run-Time ID:\t44","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"32be4e7bd564687a554f50e5cb0aa419311d6f01b77114a69558b50c8f05a6b3","action":"Filtering Platform Connection","created":"2026-05-05T08:05:40.354Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:05:38.742Z","agent":{"name":"w2016ad-n25","id":"16b27c50-d19b-4829-8363-ff3aabf1f846","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":1756}},"event_id":5156,"api":"wineventlog","keywords":["Audit Success"],"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","version":1,"record_id":253526233,"task":"Filtering Platform Connection","event_data":{"SourcePort":"0","DestPort":"0","DestAddress":"224.0.0.1","SourceAddress":"172.30.4.254","ProcessID":"4","Protocol":"2","LayerName":"%%14610","RemoteMachineID":"S-1-0-0","Application":"System","LayerRTID":"44","RemoteUserID":"S-1-0-0","FilterRTID":"66906","Direction":"%%14592"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tSource Address:\t\t0.0.0.0\n\tSource Port:\t\t63485\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t36","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"837439a06a5cfc3ad00b096506e35a2095e6312d76ae528b5095d041061ba0f0","action":"Filtering Platform Connection","created":"2026-05-05T08:11:59.584Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:11:58.878Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":4796}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5158,"api":"wineventlog","keywords":["Audit Success"],"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":204127628,"task":"Filtering Platform Connection","event_data":{"Protocol":"17","LayerName":"%%14608","ProcessId":"684","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"36","SourceAddress":"0.0.0.0","FilterRTID":"0","SourcePort":"63485"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t4\n\tApplication Name:\tSystem\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.206\n\tSource Port:\t\t0\n\tDestination Address:\t239.255.255.250\n\tDestination Port:\t\t0\n\tProtocol:\t\t2\n\nFilter Information:\n\tFilter Run-Time ID:\t66906\n\tLayer Name:\t\tReceive/Accept\n\tLayer Run-Time ID:\t44","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"fa3fdde9c098dcbb48204031b7a11321d32152e29e7222facf92e07b9875bed1","action":"Filtering Platform Connection","created":"2026-05-05T08:05:40.354Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:05:38.806Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1756}},"computer_name":"w2016ad-n25.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5156,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","version":1,"opcode":"Info","keywords":["Audit Success"],"record_id":253526234,"task":"Filtering Platform Connection","event_data":{"SourcePort":"0","DestPort":"0","DestAddress":"239.255.255.250","SourceAddress":"172.30.4.206","ProcessID":"4","Protocol":"2","LayerName":"%%14610","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","Application":"System","LayerRTID":"44","FilterRTID":"66906","Direction":"%%14592"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tSource Address:\t\t0.0.0.0\n\tSource Port:\t\t63485\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t36","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"837439a06a5cfc3ad00b096506e35a2095e6312d76ae528b5095d041061ba0f0","action":"Filtering Platform Connection","created":"2026-05-05T08:11:59.584Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:11:58.879Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","process":{"pid":4,"thread":{"id":4796}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","event_id":5158,"opcode":"Info","api":"wineventlog","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":204127629,"task":"Filtering Platform Connection","event_data":{"LayerName":"%%14608","Protocol":"17","ProcessId":"684","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"36","SourceAddress":"0.0.0.0","FilterRTID":"0","SourcePort":"63485"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t4\n\tApplication Name:\tSystem\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.206\n\tSource Port:\t\t0\n\tDestination Address:\t224.0.0.252\n\tDestination Port:\t\t0\n\tProtocol:\t\t2\n\nFilter Information:\n\tFilter Run-Time ID:\t66906\n\tLayer Name:\t\tReceive/Accept\n\tLayer Run-Time ID:\t44","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"870d25250e08accc62aff130fee422a198bea2d662e6b875ec26ae07e4aaefb9","action":"Filtering Platform Connection","created":"2026-05-05T08:05:47.394Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:05:46.303Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1756}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","event_id":5156,"api":"wineventlog","opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","version":1,"keywords":["Audit Success"],"record_id":253526235,"task":"Filtering Platform Connection","event_data":{"SourcePort":"0","DestPort":"0","DestAddress":"224.0.0.252","SourceAddress":"172.30.4.206","ProcessID":"4","Protocol":"2","LayerName":"%%14610","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","LayerRTID":"44","Application":"System","FilterRTID":"66906","Direction":"%%14592"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tDirection:\t\tOutbound\n\tSource Address:\t\t172.30.4.205\n\tSource Port:\t\t63485\n\tDestination Address:\t172.30.4.206\n\tDestination Port:\t\t53\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t67111\n\tLayer Name:\t\tConnect\n\tLayer Run-Time ID:\t48","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"c6418b9a0555d645562e7647187cc3522c11fe6b1ba63f2c2b0dabfe61fb893a","action":"Filtering Platform Connection","created":"2026-05-05T08:11:59.584Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:11:58.879Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":4796}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5156,"api":"wineventlog","keywords":["Audit Success"],"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","version":1,"record_id":204127630,"task":"Filtering Platform Connection","event_data":{"SourcePort":"63485","DestPort":"53","DestAddress":"172.30.4.206","SourceAddress":"172.30.4.205","ProcessID":"684","Protocol":"17","LayerName":"%%14611","RemoteMachineID":"S-1-0-0","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"48","RemoteUserID":"S-1-0-0","FilterRTID":"67111","Direction":"%%14593"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t4\n\tApplication Name:\tSystem\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.206\n\tSource Port:\t\t0\n\tDestination Address:\t224.0.0.251\n\tDestination Port:\t\t0\n\tProtocol:\t\t2\n\nFilter Information:\n\tFilter Run-Time ID:\t66906\n\tLayer Name:\t\tReceive/Accept\n\tLayer Run-Time ID:\t44","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"ffd3ac094d35d7eb47fadbc9784a53dc3656eb785ba824f31e27cb962b13d1ff","action":"Filtering Platform Connection","created":"2026-05-05T08:05:49.406Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:05:47.802Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1096}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","event_id":5156,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","keywords":["Audit Success"],"version":1,"record_id":253526236,"task":"Filtering Platform Connection","event_data":{"SourcePort":"0","DestPort":"0","DestAddress":"224.0.0.251","SourceAddress":"172.30.4.206","ProcessID":"4","Protocol":"2","LayerName":"%%14610","RemoteMachineID":"S-1-0-0","Application":"System","LayerRTID":"44","RemoteUserID":"S-1-0-0","FilterRTID":"66906","Direction":"%%14592"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t1180\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\svchost.exe\n\nNetwork Information:\n\tSource Address:\t\t::\n\tSource Port:\t\t63485\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t36","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"956dd06b9ac67196204b710c470351c67642bf6b8ce0d5542ceb8d02f3c2cef6","action":"Filtering Platform Connection","created":"2026-05-05T08:11:59.584Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:11:58.892Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":4796}},"event_id":5158,"api":"wineventlog","keywords":["Audit Success"],"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":204127631,"task":"Filtering Platform Connection","event_data":{"Protocol":"17","LayerName":"%%14608","ProcessId":"1180","Application":"\\device\\harddiskvolume2\\windows\\system32\\svchost.exe","LayerRTID":"36","SourceAddress":"::","FilterRTID":"0","SourcePort":"63485"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T08:05:51.433Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:05:49.487Z","agent":{"name":"w2016ad-n25","id":"16b27c50-d19b-4829-8363-ff3aabf1f846","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":1756}},"event_id":4703,"opcode":"Info","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","record_id":253526237,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"W2016AD-N25$","TargetUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectUserSid":"S-1-5-18","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t1180\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\svchost.exe\n\nNetwork Information:\n\tSource Address:\t\t::\n\tSource Port:\t\t63485\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t38","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"f3ef500cb672ef33dee52f99a40a9b7b7d075045bb1ecb4e1e92b5c53f632565","action":"Filtering Platform Connection","created":"2026-05-05T08:11:59.584Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:11:58.892Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":4796}},"event_id":5158,"api":"wineventlog","keywords":["Audit Success"],"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":204127632,"task":"Filtering Platform Connection","event_data":{"Protocol":"17","LayerName":"%%14608","ProcessId":"1180","Application":"\\device\\harddiskvolume2\\windows\\system32\\svchost.exe","LayerRTID":"38","SourceAddress":"::","FilterRTID":"0","SourcePort":"63485"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T08:05:51.433Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:05:49.488Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":1756}},"event_id":4703,"api":"wineventlog","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","record_id":253526238,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"W2016AD-N25$","TargetUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t1180\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\svchost.exe\n\nNetwork Information:\n\tDirection:\t\tOutbound\n\tSource Address:\t\t::1\n\tSource Port:\t\t63485\n\tDestination Address:\t::1\n\tDestination Port:\t\t53\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t65788\n\tLayer Name:\t\tConnect\n\tLayer Run-Time ID:\t50","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"b30bd574a89bbd9224a95a9ab231e4a9d200c9d48b1d810aaee50ac447cbba24","action":"Filtering Platform Connection","created":"2026-05-05T08:11:59.584Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:11:58.892Z","agent":{"name":"WIN-MDLQ2GQ94V9","id":"829caaa0-db4b-40b2-8076-11ac1493a97b","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","process":{"pid":4,"thread":{"id":4796}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","event_id":5156,"api":"wineventlog","keywords":["Audit Success"],"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","version":1,"record_id":204127633,"task":"Filtering Platform Connection","event_data":{"SourcePort":"63485","DestPort":"53","DestAddress":"::1","SourceAddress":"::1","ProcessID":"1180","Protocol":"17","LayerName":"%%14611","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","Application":"\\device\\harddiskvolume2\\windows\\system32\\svchost.exe","LayerRTID":"50","FilterRTID":"65788","Direction":"%%14593"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T08:05:51.434Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:05:49.492Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":1756}},"event_id":4703,"api":"wineventlog","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","record_id":253526239,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"W2016AD-N25$","TargetUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tSource Address:\t\t::\n\tSource Port:\t\t52657\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t36","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"7576981dc256202e8c5f2b899d32d627e5b72b72e98d24d284abf6af81d50f41","action":"Filtering Platform Connection","created":"2026-05-05T08:11:59.584Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:11:58.893Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":4796}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5158,"api":"wineventlog","opcode":"Info","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":204127634,"task":"Filtering Platform Connection","event_data":{"Protocol":"17","LayerName":"%%14608","ProcessId":"684","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"36","SourceAddress":"::","FilterRTID":"0","SourcePort":"52657"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T08:05:51.434Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:05:49.501Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1756}},"computer_name":"w2016ad-n25.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":4703,"api":"wineventlog","opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"record_id":253526240,"task":"Token Right Adjusted Events","event_data":{"TargetUserName":"W2016AD-N25$","SubjectUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tSource Address:\t\t::\n\tSource Port:\t\t52657\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t38","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"91232bbee0d0e23641b6553fba5a74c38a7141dee59b582a8547538563d06687","action":"Filtering Platform Connection","created":"2026-05-05T08:11:59.584Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:11:58.893Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":4796}},"event_id":5158,"opcode":"Info","api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"record_id":204127635,"task":"Filtering Platform Connection","event_data":{"Protocol":"17","LayerName":"%%14608","ProcessId":"684","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"38","SourceAddress":"::","FilterRTID":"0","SourcePort":"52657"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tDirection:\t\tOutbound\n\tSource Address:\t\t::1\n\tSource Port:\t\t52657\n\tDestination Address:\t::1\n\tDestination Port:\t\t53\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t65788\n\tLayer Name:\t\tConnect\n\tLayer Run-Time ID:\t50","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"2d13fcaacc60f055abce90580da965ef8e162e8bd5c559942cc0add14f5b7a36","action":"Filtering Platform Connection","created":"2026-05-05T08:11:59.584Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:11:58.893Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":4796}},"event_id":5156,"api":"wineventlog","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","version":1,"opcode":"Info","record_id":204127636,"task":"Filtering Platform Connection","event_data":{"SourcePort":"52657","DestPort":"53","DestAddress":"::1","SourceAddress":"::1","ProcessID":"684","LayerName":"%%14611","Protocol":"17","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"50","FilterRTID":"65788","Direction":"%%14593"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T08:05:51.434Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:05:49.501Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1756}},"computer_name":"w2016ad-n25.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":4703,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","keywords":["Audit Success"],"record_id":253526241,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"W2016AD-N25$","TargetUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t2444\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\dns.exe\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t::1\n\tSource Port:\t\t52657\n\tDestination Address:\t::1\n\tDestination Port:\t\t53\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t65786\n\tLayer Name:\t\tReceive/Accept\n\tLayer Run-Time ID:\t46","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"8bdd1a0311d852cae78a30fe7ed11ea9ba0565d9c7bc697f1058a5aa098df695","action":"Filtering Platform Connection","created":"2026-05-05T08:11:59.584Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:11:58.893Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":4796}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5156,"api":"wineventlog","keywords":["Audit Success"],"version":1,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":204127637,"task":"Filtering Platform Connection","event_data":{"Direction":"%%14592","DestPort":"53","DestAddress":"::1","SourceAddress":"::1","ProcessID":"2444","LayerName":"%%14610","Protocol":"17","RemoteMachineID":"S-1-0-0","Application":"\\device\\harddiskvolume2\\windows\\system32\\dns.exe","LayerRTID":"46","RemoteUserID":"S-1-0-0","FilterRTID":"65786","SourcePort":"52657"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T08:05:51.434Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:05:49.502Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1756}},"computer_name":"w2016ad-n25.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":4703,"api":"wineventlog","opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"record_id":253526242,"task":"Token Right Adjusted Events","event_data":{"TargetUserName":"W2016AD-N25$","SubjectUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tSource Address:\t\t::\n\tSource Port:\t\t52255\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t38","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"96c5f2bd16917ec8d2fb8196c333611b428e72e9550d3c096c19fb20b91abd27","action":"Filtering Platform Connection","created":"2026-05-05T08:11:59.584Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:11:58.893Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":4796}},"event_id":5158,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"opcode":"Info","record_id":204127638,"task":"Filtering Platform Connection","event_data":{"Protocol":"17","LayerName":"%%14608","ProcessId":"684","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"38","SourceAddress":"::","FilterRTID":"0","SourcePort":"52255"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T08:05:51.434Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:05:49.503Z","agent":{"name":"w2016ad-n25","id":"16b27c50-d19b-4829-8363-ff3aabf1f846","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1756}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","event_id":4703,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","keywords":["Audit Success"],"record_id":253526243,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"W2016AD-N25$","TargetUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tSource Address:\t\t0.0.0.0\n\tSource Port:\t\t55030\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t36","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"50f10fb727d295c211928e159454c478d312db208b0ffb502bfeaf20f8b125b4","action":"Filtering Platform Connection","created":"2026-05-05T08:11:59.584Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:11:58.893Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":4796}},"event_id":5158,"api":"wineventlog","opcode":"Info","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":204127639,"task":"Filtering Platform Connection","event_data":{"Protocol":"17","LayerName":"%%14608","ProcessId":"684","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"36","SourceAddress":"0.0.0.0","FilterRTID":"0","SourcePort":"55030"},"channel":"Security"}}
{"message":"A Windows Filtering Platform filter has been changed.\n\t\nSubject:\n\tSecurity ID:\t\tS-1-5-19\n\tAccount Name:\t\tNT AUTHORITY\\LOCAL SERVICE\n\nProcess Information:\n\tProcess ID:\t1236\n\nProvider Information:\n\tID:\t\t{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}\n\tName:\t\tMicrosoft Corporation\n\nChange Information:\n\tChange Type:\tDelete\n\nFilter Information:\n\tID:\t\t{CB747004-D094-42A9-9400-A1CC019BB234}\n\tName:\t\tDFS Replication (RPC-EPMAP)\n\tType:\t\tNot persistent\n\tRun-Time ID:\t84497\n\nLayer Information:\n\tID:\t\t{7AC9DE24-17DD-4814-B4BD-A9FBC95A321B}\n\tName:\t\tALE Listen v6 Layer\n\tRun-Time ID:\t42\n\nCallout Information:\n\tID:\t\t{00000000-0000-0000-0000-000000000000}\n\tName:\t\t-\n\nAdditional Information:\n\tWeight:\t10376293541528731616\t\n\tConditions:\t\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0087\n\n\tFilter Action:\tPermit","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"f0f53020de1ce9a141a639a9822a123906cda615be959ddfd1d65ead3600139d","action":"Other Policy Change Events","created":"2026-05-05T08:06:05.661Z","code":5447,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:06:04.660Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":660,"thread":{"id":3956}},"computer_name":"w2016ad-n25.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5447,"channel":"Security","api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"opcode":"Info","record_id":253526320,"task":"Other Policy Change Events","event_data":{"ProcessId":"1236","FilterType":"%%16388","UserSid":"S-1-5-19","FilterKey":"{CB747004-D094-42A9-9400-A1CC019BB234}","ChangeType":"%%16385","ProviderName":"Microsoft Corporation","LayerKey":"{7AC9DE24-17DD-4814-B4BD-A9FBC95A321B}","UserName":"NT AUTHORITY\\LOCAL SERVICE","ProviderKey":"{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}","FilterName":"DFS Replication (RPC-EPMAP)","CalloutName":"-","Weight":"10376293541528731616","LayerName":"ALE Listen v6 Layer","Conditions":"\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0087","Action":"%%16390","FilterId":"84497","CalloutKey":"{00000000-0000-0000-0000-000000000000}","LayerId":"42"},"activity_id":"{33A57B7F-DBBD-0002-997B-A533BDDBDC01}"}}
{"message":"A Windows Filtering Platform filter has been changed.\n\t\nSubject:\n\tSecurity ID:\t\tS-1-5-19\n\tAccount Name:\t\tNT AUTHORITY\\LOCAL SERVICE\n\nProcess Information:\n\tProcess ID:\t1236\n\nProvider Information:\n\tID:\t\t{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}\n\tName:\t\tMicrosoft Corporation\n\nChange Information:\n\tChange Type:\tDelete\n\nFilter Information:\n\tID:\t\t{B7B0FE5F-5A38-41EB-97A1-E684432F6B50}\n\tName:\t\tDFS Replication (RPC-EPMAP)\n\tType:\t\tNot persistent\n\tRun-Time ID:\t84498\n\nLayer Information:\n\tID:\t\t{A3B42C97-9F04-4672-B87E-CEE9C483257F}\n\tName:\t\tALE Receive/Accept v6 Layer\n\tRun-Time ID:\t46\n\nCallout Information:\n\tID:\t\t{00000000-0000-0000-0000-000000000000}\n\tName:\t\t-\n\nAdditional Information:\n\tWeight:\t10376540038224674816\t\n\tConditions:\t\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0087\n\n\tCondition ID:\t{3971ef2b-623e-4f9a-8cb1-6e79b806b9a7}\n\tMatch value:\tEqual to\n\tCondition value:\t0x06\n\n\tFilter Action:\tPermit","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"383b28ea0125c58e87c4244955559464690ca3850b75b960b5bed41415f02373","action":"Other Policy Change Events","created":"2026-05-05T08:06:05.661Z","code":5447,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:06:04.660Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":660,"thread":{"id":3956}},"computer_name":"w2016ad-n25.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","channel":"Security","event_id":5447,"api":"wineventlog","opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"record_id":253526321,"task":"Other Policy Change Events","event_data":{"ProcessId":"1236","FilterType":"%%16388","UserSid":"S-1-5-19","CalloutKey":"{00000000-0000-0000-0000-000000000000}","ChangeType":"%%16385","ProviderName":"Microsoft Corporation","LayerKey":"{A3B42C97-9F04-4672-B87E-CEE9C483257F}","Action":"%%16390","ProviderKey":"{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}","FilterName":"DFS Replication (RPC-EPMAP)","LayerName":"ALE Receive/Accept v6 Layer","Weight":"10376540038224674816","CalloutName":"-","Conditions":"\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0087\n\n\tCondition ID:\t{3971ef2b-623e-4f9a-8cb1-6e79b806b9a7}\n\tMatch value:\tEqual to\n\tCondition value:\t0x06","FilterKey":"{B7B0FE5F-5A38-41EB-97A1-E684432F6B50}","FilterId":"84498","UserName":"NT AUTHORITY\\LOCAL SERVICE","LayerId":"46"},"activity_id":"{33A57B7F-DBBD-0002-997B-A533BDDBDC01}"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t2444\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\dns.exe\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.205\n\tSource Port:\t\t51014\n\tDestination Address:\t172.30.4.205\n\tDestination Port:\t\t53\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t65787\n\tLayer Name:\t\tReceive/Accept\n\tLayer Run-Time ID:\t44","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"863f86e052637dd45bdafa8f093add3ec440911a8f75a208c5dcf665436f6fb4","action":"Filtering Platform Connection","created":"2026-05-05T08:12:07.681Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:12:06.318Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1416}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5156,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","version":1,"keywords":["Audit Success"],"opcode":"Info","record_id":204127704,"task":"Filtering Platform Connection","event_data":{"SourcePort":"51014","DestPort":"53","DestAddress":"172.30.4.205","SourceAddress":"172.30.4.205","ProcessID":"2444","Protocol":"17","LayerName":"%%14610","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","Application":"\\device\\harddiskvolume2\\windows\\system32\\dns.exe","LayerRTID":"44","FilterRTID":"65787","Direction":"%%14592"},"channel":"Security"}}
{"message":"A Windows Filtering Platform filter has been changed.\n\t\nSubject:\n\tSecurity ID:\t\tS-1-5-19\n\tAccount Name:\t\tNT AUTHORITY\\LOCAL SERVICE\n\nProcess Information:\n\tProcess ID:\t1236\n\nProvider Information:\n\tID:\t\t{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}\n\tName:\t\tMicrosoft Corporation\n\nChange Information:\n\tChange Type:\tDelete\n\nFilter Information:\n\tID:\t\t{603146C7-7966-44B5-945D-64BFA2C42AB1}\n\tName:\t\tDFS Replication (RPC-EPMAP)\n\tType:\t\tNot persistent\n\tRun-Time ID:\t84499\n\nLayer Information:\n\tID:\t\t{7AC9DE24-17DD-4814-B4BD-A9FBC95A321B}\n\tName:\t\tALE Listen v6 Layer\n\tRun-Time ID:\t42\n\nCallout Information:\n\tID:\t\t{00000000-0000-0000-0000-000000000000}\n\tName:\t\t-\n\nAdditional Information:\n\tWeight:\t10376293541528731616\t\n\tConditions:\t\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0251\n\n\tFilter Action:\tPermit","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"4dc27a8b0d92f52bc5bcc82ea416037ead467535804a4c6a687d35ed0679d72a","action":"Other Policy Change Events","created":"2026-05-05T08:06:05.661Z","code":5447,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:06:04.660Z","agent":{"name":"w2016ad-n25","id":"16b27c50-d19b-4829-8363-ff3aabf1f846","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":660,"thread":{"id":3956}},"computer_name":"w2016ad-n25.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5447,"activity_id":"{33A57B7F-DBBD-0002-997B-A533BDDBDC01}","api":"wineventlog","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","record_id":253526322,"task":"Other Policy Change Events","event_data":{"ProcessId":"1236","UserSid":"S-1-5-19","FilterType":"%%16388","CalloutKey":"{00000000-0000-0000-0000-000000000000}","ProviderName":"Microsoft Corporation","ChangeType":"%%16385","Conditions":"\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0251","UserName":"NT AUTHORITY\\LOCAL SERVICE","CalloutName":"-","FilterName":"DFS Replication (RPC-EPMAP)","Action":"%%16390","Weight":"10376293541528731616","ProviderKey":"{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}","FilterKey":"{603146C7-7966-44B5-945D-64BFA2C42AB1}","LayerKey":"{7AC9DE24-17DD-4814-B4BD-A9FBC95A321B}","FilterId":"84499","LayerName":"ALE Listen v6 Layer","LayerId":"42"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tSource Address:\t\t::\n\tSource Port:\t\t63485\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t36","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"66bbda52ed4a2a4ee9a93fc2c928150778a34ab5d6b680a72beea644311f9de4","action":"Filtering Platform Connection","created":"2026-05-05T08:12:07.681Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:12:06.319Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1416}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5158,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","keywords":["Audit Success"],"record_id":204127705,"task":"Filtering Platform Connection","event_data":{"Protocol":"17","LayerName":"%%14608","ProcessId":"684","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"36","SourceAddress":"::","FilterRTID":"0","SourcePort":"63485"},"channel":"Security"}}
{"message":"A Windows Filtering Platform filter has been changed.\n\t\nSubject:\n\tSecurity ID:\t\tS-1-5-19\n\tAccount Name:\t\tNT AUTHORITY\\LOCAL SERVICE\n\nProcess Information:\n\tProcess ID:\t1236\n\nProvider Information:\n\tID:\t\t{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}\n\tName:\t\tMicrosoft Corporation\n\nChange Information:\n\tChange Type:\tDelete\n\nFilter Information:\n\tID:\t\t{CEC28864-6E05-4475-A967-620D4870CC82}\n\tName:\t\tDFS Replication (RPC-EPMAP)\n\tType:\t\tNot persistent\n\tRun-Time ID:\t84500\n\nLayer Information:\n\tID:\t\t{A3B42C97-9F04-4672-B87E-CEE9C483257F}\n\tName:\t\tALE Receive/Accept v6 Layer\n\tRun-Time ID:\t46\n\nCallout Information:\n\tID:\t\t{00000000-0000-0000-0000-000000000000}\n\tName:\t\t-\n\nAdditional Information:\n\tWeight:\t10376540038224674816\t\n\tConditions:\t\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0251\n\n\tCondition ID:\t{3971ef2b-623e-4f9a-8cb1-6e79b806b9a7}\n\tMatch value:\tEqual to\n\tCondition value:\t0x06\n\n\tFilter Action:\tPermit","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"bc7ab579e29da145cbcdf769871380849c9e6d2c755bebf396677f924f8fa77a","action":"Other Policy Change Events","created":"2026-05-05T08:06:05.661Z","code":5447,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:06:04.660Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":660,"thread":{"id":3956}},"provider_name":"Microsoft-Windows-Security-Auditing","channel":"Security","event_id":5447,"computer_name":"w2016ad-n25.tdarplatform.csoc","api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"opcode":"Info","record_id":253526323,"task":"Other Policy Change Events","event_data":{"ProcessId":"1236","FilterType":"%%16388","UserSid":"S-1-5-19","CalloutKey":"{00000000-0000-0000-0000-000000000000}","Action":"%%16390","FilterKey":"{CEC28864-6E05-4475-A967-620D4870CC82}","Conditions":"\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0251\n\n\tCondition ID:\t{3971ef2b-623e-4f9a-8cb1-6e79b806b9a7}\n\tMatch value:\tEqual to\n\tCondition value:\t0x06","LayerName":"ALE Receive/Accept v6 Layer","ProviderKey":"{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}","FilterName":"DFS Replication (RPC-EPMAP)","UserName":"NT AUTHORITY\\LOCAL SERVICE","Weight":"10376540038224674816","CalloutName":"-","ProviderName":"Microsoft Corporation","LayerKey":"{A3B42C97-9F04-4672-B87E-CEE9C483257F}","FilterId":"84500","ChangeType":"%%16385","LayerId":"46"},"activity_id":"{33A57B7F-DBBD-0002-997B-A533BDDBDC01}"}}
{"message":"A Windows Filtering Platform filter has been changed.\n\t\nSubject:\n\tSecurity ID:\t\tS-1-5-19\n\tAccount Name:\t\tNT AUTHORITY\\LOCAL SERVICE\n\nProcess Information:\n\tProcess ID:\t1236\n\nProvider Information:\n\tID:\t\t{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}\n\tName:\t\tMicrosoft Corporation\n\nChange Information:\n\tChange Type:\tDelete\n\nFilter Information:\n\tID:\t\t{CB09EE0D-8079-460B-86F5-87C63595B5EF}\n\tName:\t\tFile Replication (RPC-EPMAP)\n\tType:\t\tNot persistent\n\tRun-Time ID:\t84501\n\nLayer Information:\n\tID:\t\t{88BB5DAD-76D7-4227-9C71-DF0A3ED7BE7E}\n\tName:\t\tALE Listen v4 Layer\n\tRun-Time ID:\t40\n\nCallout Information:\n\tID:\t\t{00000000-0000-0000-0000-000000000000}\n\tName:\t\t-\n\nAdditional Information:\n\tWeight:\t10376293542535364576\t\n\tConditions:\t\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0087\n\n\tFilter Action:\tPermit","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"b0d9307c9e82b41fb64b2f2a989be3a1ccd93dfdbe6ad117b888ee5294fbc406","action":"Other Policy Change Events","created":"2026-05-05T08:06:05.661Z","code":5447,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:06:04.660Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":660,"thread":{"id":3956}},"event_id":5447,"channel":"Security","api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"opcode":"Info","record_id":253526324,"task":"Other Policy Change Events","event_data":{"ProcessId":"1236","UserSid":"S-1-5-19","FilterType":"%%16388","CalloutKey":"{00000000-0000-0000-0000-000000000000}","ChangeType":"%%16385","ProviderName":"Microsoft Corporation","LayerKey":"{88BB5DAD-76D7-4227-9C71-DF0A3ED7BE7E}","Action":"%%16390","Conditions":"\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0087","FilterName":"File Replication (RPC-EPMAP)","UserName":"NT AUTHORITY\\LOCAL SERVICE","CalloutName":"-","ProviderKey":"{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}","FilterKey":"{CB09EE0D-8079-460B-86F5-87C63595B5EF}","Weight":"10376293542535364576","FilterId":"84501","LayerName":"ALE Listen v4 Layer","LayerId":"40"},"activity_id":"{33A57B7F-DBBD-0002-997B-A533BDDBDC01}"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tSource Address:\t\t::\n\tSource Port:\t\t63485\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t38","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"31ad9c3fcae7ab76876eb1002b7a6b3f65f29ef83dccb320187a8a4067f7318f","action":"Filtering Platform Connection","created":"2026-05-05T08:12:07.681Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:12:06.319Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":1416}},"event_id":5158,"api":"wineventlog","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","record_id":204127706,"task":"Filtering Platform Connection","event_data":{"Protocol":"17","LayerName":"%%14608","ProcessId":"684","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"38","SourceAddress":"::","FilterRTID":"0","SourcePort":"63485"},"channel":"Security"}}
{"message":"A Windows Filtering Platform filter has been changed.\n\t\nSubject:\n\tSecurity ID:\t\tS-1-5-19\n\tAccount Name:\t\tNT AUTHORITY\\LOCAL SERVICE\n\nProcess Information:\n\tProcess ID:\t1236\n\nProvider Information:\n\tID:\t\t{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}\n\tName:\t\tMicrosoft Corporation\n\nChange Information:\n\tChange Type:\tDelete\n\nFilter Information:\n\tID:\t\t{34D6CF8F-030F-4B4B-BD72-6DC30BF05CFE}\n\tName:\t\tFile Replication (RPC-EPMAP)\n\tType:\t\tNot persistent\n\tRun-Time ID:\t84502\n\nLayer Information:\n\tID:\t\t{E1CD9FE7-F4B5-4273-96C0-592E487B8650}\n\tName:\t\tALE Receive/Accept v4 Layer\n\tRun-Time ID:\t44\n\nCallout Information:\n\tID:\t\t{00000000-0000-0000-0000-000000000000}\n\tName:\t\t-\n\nAdditional Information:\n\tWeight:\t10378405428420673536\t\n\tConditions:\t\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0087\n\n\tCondition ID:\t{3971ef2b-623e-4f9a-8cb1-6e79b806b9a7}\n\tMatch value:\tEqual to\n\tCondition value:\t0x06\n\n\tFilter Action:\tPermit","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"61cee7f1beaba5ce3205a45402c6af36b66c6caca89f4719bb5c1f33e6ae89e7","action":"Other Policy Change Events","created":"2026-05-05T08:06:05.661Z","code":5447,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:06:04.660Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"channel":"Security","provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","event_id":5447,"process":{"pid":660,"thread":{"id":3956}},"opcode":"Info","keywords":["Audit Success"],"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":253526325,"task":"Other Policy Change Events","event_data":{"ProcessId":"1236","FilterType":"%%16388","UserSid":"S-1-5-19","CalloutKey":"{00000000-0000-0000-0000-000000000000}","Action":"%%16390","FilterKey":"{34D6CF8F-030F-4B4B-BD72-6DC30BF05CFE}","LayerKey":"{E1CD9FE7-F4B5-4273-96C0-592E487B8650}","UserName":"NT AUTHORITY\\LOCAL SERVICE","Conditions":"\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0087\n\n\tCondition ID:\t{3971ef2b-623e-4f9a-8cb1-6e79b806b9a7}\n\tMatch value:\tEqual to\n\tCondition value:\t0x06","FilterName":"File Replication (RPC-EPMAP)","CalloutName":"-","Weight":"10378405428420673536","ProviderKey":"{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}","ProviderName":"Microsoft Corporation","ChangeType":"%%16385","FilterId":"84502","LayerName":"ALE Receive/Accept v4 Layer","LayerId":"44"},"activity_id":"{33A57B7F-DBBD-0002-997B-A533BDDBDC01}"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tDirection:\t\tOutbound\n\tSource Address:\t\t::1\n\tSource Port:\t\t63485\n\tDestination Address:\t::1\n\tDestination Port:\t\t53\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t65788\n\tLayer Name:\t\tConnect\n\tLayer Run-Time ID:\t50","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"8c241c1569437ee50c68075816eb552cd9b1b5e80958d4fecb58960d3af38815","action":"Filtering Platform Connection","created":"2026-05-05T08:12:07.681Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:12:06.319Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1416}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","event_id":5156,"api":"wineventlog","keywords":["Audit Success"],"version":1,"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","record_id":204127707,"task":"Filtering Platform Connection","event_data":{"Direction":"%%14593","DestPort":"53","DestAddress":"::1","SourceAddress":"::1","ProcessID":"684","LayerName":"%%14611","Protocol":"17","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","LayerRTID":"50","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","FilterRTID":"65788","SourcePort":"63485"},"channel":"Security"}}
{"message":"A Windows Filtering Platform filter has been changed.\n\t\nSubject:\n\tSecurity ID:\t\tS-1-5-19\n\tAccount Name:\t\tNT AUTHORITY\\LOCAL SERVICE\n\nProcess Information:\n\tProcess ID:\t1236\n\nProvider Information:\n\tID:\t\t{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}\n\tName:\t\tMicrosoft Corporation\n\nChange Information:\n\tChange Type:\tDelete\n\nFilter Information:\n\tID:\t\t{2D04312D-7FF5-4877-8956-60E23FBD5083}\n\tName:\t\tFile Replication (RPC-EPMAP)\n\tType:\t\tNot persistent\n\tRun-Time ID:\t84503\n\nLayer Information:\n\tID:\t\t{88BB5DAD-76D7-4227-9C71-DF0A3ED7BE7E}\n\tName:\t\tALE Listen v4 Layer\n\tRun-Time ID:\t40\n\nCallout Information:\n\tID:\t\t{00000000-0000-0000-0000-000000000000}\n\tName:\t\t-\n\nAdditional Information:\n\tWeight:\t10376293542535364576\t\n\tConditions:\t\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0251\n\n\tFilter Action:\tPermit","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"73385924641b501486051fab98ec2319bca1934dc41ee620ae59590b40b0691f","action":"Other Policy Change Events","created":"2026-05-05T08:06:05.661Z","code":5447,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:06:04.660Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","activity_id":"{33A57B7F-DBBD-0002-997B-A533BDDBDC01}","process":{"pid":660,"thread":{"id":3956}},"event_id":5447,"computer_name":"w2016ad-n25.tdarplatform.csoc","api":"wineventlog","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","record_id":253526326,"task":"Other Policy Change Events","event_data":{"ProcessId":"1236","FilterType":"%%16388","UserSid":"S-1-5-19","CalloutKey":"{00000000-0000-0000-0000-000000000000}","ProviderName":"Microsoft Corporation","ChangeType":"%%16385","LayerKey":"{88BB5DAD-76D7-4227-9C71-DF0A3ED7BE7E}","UserName":"NT AUTHORITY\\LOCAL SERVICE","ProviderKey":"{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}","Action":"%%16390","Conditions":"\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0251","Weight":"10376293542535364576","LayerName":"ALE Listen v4 Layer","FilterName":"File Replication (RPC-EPMAP)","FilterKey":"{2D04312D-7FF5-4877-8956-60E23FBD5083}","FilterId":"84503","CalloutName":"-","LayerId":"40"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tSource Address:\t\t::\n\tSource Port:\t\t63485\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t38","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"31ad9c3fcae7ab76876eb1002b7a6b3f65f29ef83dccb320187a8a4067f7318f","action":"Filtering Platform Connection","created":"2026-05-05T08:12:07.681Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:12:06.319Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","process":{"pid":4,"thread":{"id":1416}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","event_id":5158,"opcode":"Info","api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"record_id":204127708,"task":"Filtering Platform Connection","event_data":{"LayerName":"%%14608","Protocol":"17","ProcessId":"684","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"38","SourceAddress":"::","FilterRTID":"0","SourcePort":"63485"},"channel":"Security"}}
{"message":"A Windows Filtering Platform filter has been changed.\n\t\nSubject:\n\tSecurity ID:\t\tS-1-5-19\n\tAccount Name:\t\tNT AUTHORITY\\LOCAL SERVICE\n\nProcess Information:\n\tProcess ID:\t1236\n\nProvider Information:\n\tID:\t\t{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}\n\tName:\t\tMicrosoft Corporation\n\nChange Information:\n\tChange Type:\tDelete\n\nFilter Information:\n\tID:\t\t{2C0705E6-12A5-4DFA-B8A8-5135F14B8EA6}\n\tName:\t\tFile Replication (RPC-EPMAP)\n\tType:\t\tNot persistent\n\tRun-Time ID:\t84504\n\nLayer Information:\n\tID:\t\t{E1CD9FE7-F4B5-4273-96C0-592E487B8650}\n\tName:\t\tALE Receive/Accept v4 Layer\n\tRun-Time ID:\t44\n\nCallout Information:\n\tID:\t\t{00000000-0000-0000-0000-000000000000}\n\tName:\t\t-\n\nAdditional Information:\n\tWeight:\t10378405428420673536\t\n\tConditions:\t\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0251\n\n\tCondition ID:\t{3971ef2b-623e-4f9a-8cb1-6e79b806b9a7}\n\tMatch value:\tEqual to\n\tCondition value:\t0x06\n\n\tFilter Action:\tPermit","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"2710438dcd7e691bdcda85b7b5e5b197c6564b3ec158ed6496cf90c15d6bf537","action":"Other Policy Change Events","created":"2026-05-05T08:06:05.661Z","code":5447,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:06:04.661Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":660,"thread":{"id":3956}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","event_id":5447,"channel":"Security","api":"wineventlog","keywords":["Audit Success"],"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":253526327,"task":"Other Policy Change Events","event_data":{"ProcessId":"1236","FilterType":"%%16388","UserSid":"S-1-5-19","CalloutKey":"{00000000-0000-0000-0000-000000000000}","ProviderName":"Microsoft Corporation","LayerName":"ALE Receive/Accept v4 Layer","Conditions":"\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0251\n\n\tCondition ID:\t{3971ef2b-623e-4f9a-8cb1-6e79b806b9a7}\n\tMatch value:\tEqual to\n\tCondition value:\t0x06","UserName":"NT AUTHORITY\\LOCAL SERVICE","CalloutName":"-","ChangeType":"%%16385","Action":"%%16390","FilterKey":"{2C0705E6-12A5-4DFA-B8A8-5135F14B8EA6}","FilterName":"File Replication (RPC-EPMAP)","Weight":"10378405428420673536","ProviderKey":"{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}","FilterId":"84504","LayerKey":"{E1CD9FE7-F4B5-4273-96C0-592E487B8650}","LayerId":"44"},"activity_id":"{33A57B7F-DBBD-0002-997B-A533BDDBDC01}"}}
{"message":"A Windows Filtering Platform filter has been changed.\n\t\nSubject:\n\tSecurity ID:\t\tS-1-5-19\n\tAccount Name:\t\tNT AUTHORITY\\LOCAL SERVICE\n\nProcess Information:\n\tProcess ID:\t1236\n\nProvider Information:\n\tID:\t\t{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}\n\tName:\t\tMicrosoft Corporation\n\nChange Information:\n\tChange Type:\tDelete\n\nFilter Information:\n\tID:\t\t{B86F8033-787B-4FBA-80C8-468CEAC7779F}\n\tName:\t\tFile Replication (RPC-EPMAP)\n\tType:\t\tNot persistent\n\tRun-Time ID:\t84505\n\nLayer Information:\n\tID:\t\t{7AC9DE24-17DD-4814-B4BD-A9FBC95A321B}\n\tName:\t\tALE Listen v6 Layer\n\tRun-Time ID:\t42\n\nCallout Information:\n\tID:\t\t{00000000-0000-0000-0000-000000000000}\n\tName:\t\t-\n\nAdditional Information:\n\tWeight:\t10376293541528731616\t\n\tConditions:\t\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0087\n\n\tFilter Action:\tPermit","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"67b56bd963616a8147740eba0961101dec36c2b4aafc8eed03f927a4809f2a69","action":"Other Policy Change Events","created":"2026-05-05T08:06:05.661Z","code":5447,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:06:04.661Z","agent":{"name":"w2016ad-n25","id":"16b27c50-d19b-4829-8363-ff3aabf1f846","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":660,"thread":{"id":3956}},"computer_name":"w2016ad-n25.tdarplatform.csoc","channel":"Security","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5447,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"opcode":"Info","record_id":253526328,"task":"Other Policy Change Events","event_data":{"ProcessId":"1236","FilterType":"%%16388","UserSid":"S-1-5-19","CalloutKey":"{00000000-0000-0000-0000-000000000000}","ProviderName":"Microsoft Corporation","LayerName":"ALE Listen v6 Layer","LayerKey":"{7AC9DE24-17DD-4814-B4BD-A9FBC95A321B}","Conditions":"\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0087","CalloutName":"-","FilterName":"File Replication (RPC-EPMAP)","ProviderKey":"{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}","Weight":"10376293541528731616","UserName":"NT AUTHORITY\\LOCAL SERVICE","FilterKey":"{B86F8033-787B-4FBA-80C8-468CEAC7779F}","ChangeType":"%%16385","FilterId":"84505","Action":"%%16390","LayerId":"42"},"activity_id":"{33A57B7F-DBBD-0002-997B-A533BDDBDC01}"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tSource Address:\t\t0.0.0.0\n\tSource Port:\t\t53310\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t36","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"0ca9db72c17bdd04334b5b45cd51cbbcc3f6fdc825b749cac913ada6999fa3ce","action":"Filtering Platform Connection","created":"2026-05-05T08:12:07.682Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:12:06.320Z","agent":{"name":"WIN-MDLQ2GQ94V9","id":"829caaa0-db4b-40b2-8076-11ac1493a97b","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":1416}},"event_id":5158,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"opcode":"Info","record_id":204127709,"task":"Filtering Platform Connection","event_data":{"Protocol":"17","LayerName":"%%14608","ProcessId":"684","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"36","SourceAddress":"0.0.0.0","FilterRTID":"0","SourcePort":"53310"},"channel":"Security"}}
{"message":"A Windows Filtering Platform filter has been changed.\n\t\nSubject:\n\tSecurity ID:\t\tS-1-5-19\n\tAccount Name:\t\tNT AUTHORITY\\LOCAL SERVICE\n\nProcess Information:\n\tProcess ID:\t1236\n\nProvider Information:\n\tID:\t\t{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}\n\tName:\t\tMicrosoft Corporation\n\nChange Information:\n\tChange Type:\tDelete\n\nFilter Information:\n\tID:\t\t{F8B106BD-B901-4F75-A1DD-84678F8F35C5}\n\tName:\t\tFile Replication (RPC-EPMAP)\n\tType:\t\tNot persistent\n\tRun-Time ID:\t84506\n\nLayer Information:\n\tID:\t\t{A3B42C97-9F04-4672-B87E-CEE9C483257F}\n\tName:\t\tALE Receive/Accept v6 Layer\n\tRun-Time ID:\t46\n\nCallout Information:\n\tID:\t\t{00000000-0000-0000-0000-000000000000}\n\tName:\t\t-\n\nAdditional Information:\n\tWeight:\t10376540038224674816\t\n\tConditions:\t\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0087\n\n\tCondition ID:\t{3971ef2b-623e-4f9a-8cb1-6e79b806b9a7}\n\tMatch value:\tEqual to\n\tCondition value:\t0x06\n\n\tFilter Action:\tPermit","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"e79830789103f7a4a625f9a32884cae3628d997ae4926b739138bad796989170","action":"Other Policy Change Events","created":"2026-05-05T08:06:05.661Z","code":5447,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:06:04.661Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"activity_id":"{33A57B7F-DBBD-0002-997B-A533BDDBDC01}","provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","event_id":5447,"process":{"pid":660,"thread":{"id":3956}},"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"api":"wineventlog","record_id":253526329,"task":"Other Policy Change Events","event_data":{"ProcessId":"1236","UserSid":"S-1-5-19","FilterType":"%%16388","CalloutKey":"{00000000-0000-0000-0000-000000000000}","Action":"%%16390","FilterKey":"{F8B106BD-B901-4F75-A1DD-84678F8F35C5}","LayerKey":"{A3B42C97-9F04-4672-B87E-CEE9C483257F}","UserName":"NT AUTHORITY\\LOCAL SERVICE","ProviderKey":"{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}","CalloutName":"-","Conditions":"\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0087\n\n\tCondition ID:\t{3971ef2b-623e-4f9a-8cb1-6e79b806b9a7}\n\tMatch value:\tEqual to\n\tCondition value:\t0x06","Weight":"10376540038224674816","FilterName":"File Replication (RPC-EPMAP)","LayerName":"ALE Receive/Accept v6 Layer","ProviderName":"Microsoft Corporation","FilterId":"84506","ChangeType":"%%16385","LayerId":"46"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tSource Address:\t\t0.0.0.0\n\tSource Port:\t\t54343\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t36","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"b26d2e4b88520d4a6e2be4d544f040b09b8cdcdf1bf620130a46515dc0b264f8","action":"Filtering Platform Connection","created":"2026-05-05T08:12:07.682Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:12:06.320Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1416}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","event_id":5158,"opcode":"Info","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","record_id":204127710,"task":"Filtering Platform Connection","event_data":{"LayerName":"%%14608","Protocol":"17","ProcessId":"684","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"36","SourceAddress":"0.0.0.0","FilterRTID":"0","SourcePort":"54343"},"channel":"Security"}}
{"message":"A Windows Filtering Platform filter has been changed.\n\t\nSubject:\n\tSecurity ID:\t\tS-1-5-19\n\tAccount Name:\t\tNT AUTHORITY\\LOCAL SERVICE\n\nProcess Information:\n\tProcess ID:\t1236\n\nProvider Information:\n\tID:\t\t{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}\n\tName:\t\tMicrosoft Corporation\n\nChange Information:\n\tChange Type:\tDelete\n\nFilter Information:\n\tID:\t\t{9C5424DB-DD05-4527-8BC0-BE7396381730}\n\tName:\t\tFile Replication (RPC-EPMAP)\n\tType:\t\tNot persistent\n\tRun-Time ID:\t84507\n\nLayer Information:\n\tID:\t\t{7AC9DE24-17DD-4814-B4BD-A9FBC95A321B}\n\tName:\t\tALE Listen v6 Layer\n\tRun-Time ID:\t42\n\nCallout Information:\n\tID:\t\t{00000000-0000-0000-0000-000000000000}\n\tName:\t\t-\n\nAdditional Information:\n\tWeight:\t10376293541528731616\t\n\tConditions:\t\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0251\n\n\tFilter Action:\tPermit","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"c2290dc43eae26ec554073519769ec8fc53db1789dcb2125196abe09ffc2ba0f","action":"Other Policy Change Events","created":"2026-05-05T08:06:05.662Z","code":5447,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:06:04.661Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","activity_id":"{33A57B7F-DBBD-0002-997B-A533BDDBDC01}","event_id":5447,"process":{"pid":660,"thread":{"id":3956}},"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","keywords":["Audit Success"],"record_id":253526330,"task":"Other Policy Change Events","event_data":{"ProcessId":"1236","FilterType":"%%16388","UserSid":"S-1-5-19","CalloutKey":"{00000000-0000-0000-0000-000000000000}","Action":"%%16390","LayerName":"ALE Listen v6 Layer","Conditions":"\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0251","ProviderName":"Microsoft Corporation","CalloutName":"-","ProviderKey":"{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}","ChangeType":"%%16385","Weight":"10376293541528731616","FilterKey":"{9C5424DB-DD05-4527-8BC0-BE7396381730}","UserName":"NT AUTHORITY\\LOCAL SERVICE","FilterName":"File Replication (RPC-EPMAP)","FilterId":"84507","LayerKey":"{7AC9DE24-17DD-4814-B4BD-A9FBC95A321B}","LayerId":"42"},"channel":"Security"}}
{"message":"A Windows Filtering Platform filter has been changed.\n\t\nSubject:\n\tSecurity ID:\t\tS-1-5-19\n\tAccount Name:\t\tNT AUTHORITY\\LOCAL SERVICE\n\nProcess Information:\n\tProcess ID:\t1236\n\nProvider Information:\n\tID:\t\t{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}\n\tName:\t\tMicrosoft Corporation\n\nChange Information:\n\tChange Type:\tDelete\n\nFilter Information:\n\tID:\t\t{36E33997-7F13-477A-AA8D-6B699F7F764E}\n\tName:\t\tFile Replication (RPC-EPMAP)\n\tType:\t\tNot persistent\n\tRun-Time ID:\t84508\n\nLayer Information:\n\tID:\t\t{A3B42C97-9F04-4672-B87E-CEE9C483257F}\n\tName:\t\tALE Receive/Accept v6 Layer\n\tRun-Time ID:\t46\n\nCallout Information:\n\tID:\t\t{00000000-0000-0000-0000-000000000000}\n\tName:\t\t-\n\nAdditional Information:\n\tWeight:\t10376540038224674816\t\n\tConditions:\t\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0251\n\n\tCondition ID:\t{3971ef2b-623e-4f9a-8cb1-6e79b806b9a7}\n\tMatch value:\tEqual to\n\tCondition value:\t0x06\n\n\tFilter Action:\tPermit","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"28ee42c56c6f22632248af0c275d1eb3fad604ac0dbd9262074f00c1d764036c","action":"Other Policy Change Events","created":"2026-05-05T08:06:05.662Z","code":5447,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:06:04.661Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":660,"thread":{"id":3956}},"computer_name":"w2016ad-n25.tdarplatform.csoc","activity_id":"{33A57B7F-DBBD-0002-997B-A533BDDBDC01}","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5447,"opcode":"Info","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","record_id":253526331,"task":"Other Policy Change Events","event_data":{"ProcessId":"1236","UserSid":"S-1-5-19","FilterType":"%%16388","FilterKey":"{36E33997-7F13-477A-AA8D-6B699F7F764E}","Action":"%%16390","CalloutKey":"{00000000-0000-0000-0000-000000000000}","Conditions":"\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0251\n\n\tCondition ID:\t{3971ef2b-623e-4f9a-8cb1-6e79b806b9a7}\n\tMatch value:\tEqual to\n\tCondition value:\t0x06","UserName":"NT AUTHORITY\\LOCAL SERVICE","CalloutName":"-","LayerKey":"{A3B42C97-9F04-4672-B87E-CEE9C483257F}","ProviderName":"Microsoft Corporation","ChangeType":"%%16385","LayerName":"ALE Receive/Accept v6 Layer","Weight":"10376540038224674816","ProviderKey":"{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}","FilterId":"84508","FilterName":"File Replication (RPC-EPMAP)","LayerId":"46"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tDirection:\t\tOutbound\n\tSource Address:\t\t172.30.4.205\n\tSource Port:\t\t54343\n\tDestination Address:\t172.30.4.205\n\tDestination Port:\t\t53\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t65789\n\tLayer Name:\t\tConnect\n\tLayer Run-Time ID:\t48","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"bb58d445f5695434679c8fa58f803ef8c1d7f5cbb98b0c937180d0756758c216","action":"Filtering Platform Connection","created":"2026-05-05T08:12:07.682Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:12:06.320Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":1416}},"event_id":5156,"api":"wineventlog","version":1,"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"opcode":"Info","record_id":204127711,"task":"Filtering Platform Connection","event_data":{"SourcePort":"54343","DestPort":"53","DestAddress":"172.30.4.205","SourceAddress":"172.30.4.205","ProcessID":"684","Protocol":"17","LayerName":"%%14611","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","LayerRTID":"48","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","FilterRTID":"65789","Direction":"%%14593"},"channel":"Security"}}
{"message":"A Windows Filtering Platform filter has been changed.\n\t\nSubject:\n\tSecurity ID:\t\tS-1-5-19\n\tAccount Name:\t\tNT AUTHORITY\\LOCAL SERVICE\n\nProcess Information:\n\tProcess ID:\t1236\n\nProvider Information:\n\tID:\t\t{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}\n\tName:\t\tMicrosoft Corporation\n\nChange Information:\n\tChange Type:\tDelete\n\nFilter Information:\n\tID:\t\t{95768837-B138-409E-B855-182D53E70289}\n\tName:\t\tActive Directory Domain Controller (RPC-EPMAP)\n\tType:\t\tNot persistent\n\tRun-Time ID:\t84509\n\nLayer Information:\n\tID:\t\t{88BB5DAD-76D7-4227-9C71-DF0A3ED7BE7E}\n\tName:\t\tALE Listen v4 Layer\n\tRun-Time ID:\t40\n\nCallout Information:\n\tID:\t\t{00000000-0000-0000-0000-000000000000}\n\tName:\t\t-\n\nAdditional Information:\n\tWeight:\t10376293542535364576\t\n\tConditions:\t\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0087\n\n\tFilter Action:\tPermit","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"c32a2fda1c1a4168c594641425278589950cb77165c23d290f766743a5aa855f","action":"Other Policy Change Events","created":"2026-05-05T08:06:05.662Z","code":5447,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:06:04.661Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","process":{"pid":660,"thread":{"id":3956}},"computer_name":"w2016ad-n25.tdarplatform.csoc","event_id":5447,"channel":"Security","api":"wineventlog","keywords":["Audit Success"],"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":253526332,"task":"Other Policy Change Events","event_data":{"ProcessId":"1236","UserSid":"S-1-5-19","FilterType":"%%16388","CalloutKey":"{00000000-0000-0000-0000-000000000000}","Action":"%%16390","ProviderName":"Microsoft Corporation","LayerKey":"{88BB5DAD-76D7-4227-9C71-DF0A3ED7BE7E}","UserName":"NT AUTHORITY\\LOCAL SERVICE","ProviderKey":"{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}","Conditions":"\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0087","CalloutName":"-","LayerName":"ALE Listen v4 Layer","FilterName":"Active Directory Domain Controller (RPC-EPMAP)","FilterKey":"{95768837-B138-409E-B855-182D53E70289}","Weight":"10376293542535364576","ChangeType":"%%16385","FilterId":"84509","LayerId":"40"},"activity_id":"{33A57B7F-DBBD-0002-997B-A533BDDBDC01}"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t2444\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\dns.exe\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.205\n\tSource Port:\t\t54343\n\tDestination Address:\t172.30.4.205\n\tDestination Port:\t\t53\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t65787\n\tLayer Name:\t\tReceive/Accept\n\tLayer Run-Time ID:\t44","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"3a53df4c45778823d40a53bf676333738cfe381a776cd4fd2bec35b0e101751b","action":"Filtering Platform Connection","created":"2026-05-05T08:12:07.682Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:12:06.320Z","agent":{"name":"WIN-MDLQ2GQ94V9","id":"829caaa0-db4b-40b2-8076-11ac1493a97b","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":1416}},"event_id":5156,"api":"wineventlog","opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"version":1,"record_id":204127712,"task":"Filtering Platform Connection","event_data":{"Direction":"%%14592","DestPort":"53","DestAddress":"172.30.4.205","SourceAddress":"172.30.4.205","ProcessID":"2444","LayerName":"%%14610","Protocol":"17","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","LayerRTID":"44","Application":"\\device\\harddiskvolume2\\windows\\system32\\dns.exe","FilterRTID":"65787","SourcePort":"54343"},"channel":"Security"}}
{"message":"A Windows Filtering Platform filter has been changed.\n\t\nSubject:\n\tSecurity ID:\t\tS-1-5-19\n\tAccount Name:\t\tNT AUTHORITY\\LOCAL SERVICE\n\nProcess Information:\n\tProcess ID:\t1236\n\nProvider Information:\n\tID:\t\t{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}\n\tName:\t\tMicrosoft Corporation\n\nChange Information:\n\tChange Type:\tDelete\n\nFilter Information:\n\tID:\t\t{A8258ED7-51E6-4AF8-BA39-9B37D6483249}\n\tName:\t\tActive Directory Domain Controller (RPC-EPMAP)\n\tType:\t\tNot persistent\n\tRun-Time ID:\t84510\n\nLayer Information:\n\tID:\t\t{E1CD9FE7-F4B5-4273-96C0-592E487B8650}\n\tName:\t\tALE Receive/Accept v4 Layer\n\tRun-Time ID:\t44\n\nCallout Information:\n\tID:\t\t{00000000-0000-0000-0000-000000000000}\n\tName:\t\t-\n\nAdditional Information:\n\tWeight:\t10378405428420673536\t\n\tConditions:\t\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0087\n\n\tCondition ID:\t{3971ef2b-623e-4f9a-8cb1-6e79b806b9a7}\n\tMatch value:\tEqual to\n\tCondition value:\t0x06\n\n\tFilter Action:\tPermit","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"09a88f475b2c93f21c41e73136e29a280113ef183e957e90d41b774b572cfee1","action":"Other Policy Change Events","created":"2026-05-05T08:06:05.662Z","code":5447,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:06:04.661Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","activity_id":"{33A57B7F-DBBD-0002-997B-A533BDDBDC01}","event_id":5447,"process":{"pid":660,"thread":{"id":3956}},"opcode":"Info","api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"record_id":253526333,"task":"Other Policy Change Events","event_data":{"ProcessId":"1236","UserSid":"S-1-5-19","FilterType":"%%16388","CalloutKey":"{00000000-0000-0000-0000-000000000000}","Action":"%%16390","ProviderName":"Microsoft Corporation","Conditions":"\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0087\n\n\tCondition ID:\t{3971ef2b-623e-4f9a-8cb1-6e79b806b9a7}\n\tMatch value:\tEqual to\n\tCondition value:\t0x06","UserName":"NT AUTHORITY\\LOCAL SERVICE","ChangeType":"%%16385","CalloutName":"-","LayerName":"ALE Receive/Accept v4 Layer","ProviderKey":"{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}","FilterName":"Active Directory Domain Controller (RPC-EPMAP)","FilterKey":"{A8258ED7-51E6-4AF8-BA39-9B37D6483249}","LayerKey":"{E1CD9FE7-F4B5-4273-96C0-592E487B8650}","FilterId":"84510","Weight":"10378405428420673536","LayerId":"44"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tSource Address:\t\t::\n\tSource Port:\t\t52480\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t36","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"60f3202dddf388add72ddeaf94c3e2b94e4a1cc95f8e86a880257968ce4e24ed","action":"Filtering Platform Connection","created":"2026-05-05T08:12:07.682Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:12:06.321Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1416}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","event_id":5158,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"opcode":"Info","record_id":204127713,"task":"Filtering Platform Connection","event_data":{"LayerName":"%%14608","Protocol":"17","ProcessId":"684","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"36","SourceAddress":"::","FilterRTID":"0","SourcePort":"52480"},"channel":"Security"}}
{"message":"A Windows Filtering Platform filter has been changed.\n\t\nSubject:\n\tSecurity ID:\t\tS-1-5-19\n\tAccount Name:\t\tNT AUTHORITY\\LOCAL SERVICE\n\nProcess Information:\n\tProcess ID:\t1236\n\nProvider Information:\n\tID:\t\t{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}\n\tName:\t\tMicrosoft Corporation\n\nChange Information:\n\tChange Type:\tDelete\n\nFilter Information:\n\tID:\t\t{FBF90DC7-E5A7-4C3D-BAEA-DC20213F8864}\n\tName:\t\tActive Directory Domain Controller (RPC-EPMAP)\n\tType:\t\tNot persistent\n\tRun-Time ID:\t84511\n\nLayer Information:\n\tID:\t\t{88BB5DAD-76D7-4227-9C71-DF0A3ED7BE7E}\n\tName:\t\tALE Listen v4 Layer\n\tRun-Time ID:\t40\n\nCallout Information:\n\tID:\t\t{00000000-0000-0000-0000-000000000000}\n\tName:\t\t-\n\nAdditional Information:\n\tWeight:\t10376293542535364576\t\n\tConditions:\t\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0251\n\n\tFilter Action:\tPermit","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"c0a8ab6c53017a53b337af57885cd89b340065b89b322427c5b1baf5d33a285d","action":"Other Policy Change Events","created":"2026-05-05T08:06:05.662Z","code":5447,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:06:04.661Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":660,"thread":{"id":3956}},"activity_id":"{33A57B7F-DBBD-0002-997B-A533BDDBDC01}","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5447,"computer_name":"w2016ad-n25.tdarplatform.csoc","opcode":"Info","api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"record_id":253526334,"task":"Other Policy Change Events","event_data":{"ProcessId":"1236","UserSid":"S-1-5-19","FilterType":"%%16388","FilterKey":"{FBF90DC7-E5A7-4C3D-BAEA-DC20213F8864}","ProviderName":"Microsoft Corporation","LayerName":"ALE Listen v4 Layer","Conditions":"\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0251","UserName":"NT AUTHORITY\\LOCAL SERVICE","CalloutName":"-","LayerKey":"{88BB5DAD-76D7-4227-9C71-DF0A3ED7BE7E}","ProviderKey":"{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}","Weight":"10376293542535364576","FilterName":"Active Directory Domain Controller (RPC-EPMAP)","Action":"%%16390","CalloutKey":"{00000000-0000-0000-0000-000000000000}","FilterId":"84511","ChangeType":"%%16385","LayerId":"40"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tSource Address:\t\t::\n\tSource Port:\t\t52480\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t38","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"64030934dfc273fc41f3b96622e96d20149c87813942492d33011a75e2576816","action":"Filtering Platform Connection","created":"2026-05-05T08:12:07.682Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:12:06.321Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":1416}},"event_id":5158,"api":"wineventlog","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","record_id":204127714,"task":"Filtering Platform Connection","event_data":{"Protocol":"17","LayerName":"%%14608","ProcessId":"684","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"38","SourceAddress":"::","FilterRTID":"0","SourcePort":"52480"},"channel":"Security"}}
{"message":"A Windows Filtering Platform filter has been changed.\n\t\nSubject:\n\tSecurity ID:\t\tS-1-5-19\n\tAccount Name:\t\tNT AUTHORITY\\LOCAL SERVICE\n\nProcess Information:\n\tProcess ID:\t1236\n\nProvider Information:\n\tID:\t\t{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}\n\tName:\t\tMicrosoft Corporation\n\nChange Information:\n\tChange Type:\tDelete\n\nFilter Information:\n\tID:\t\t{B010A177-CFCC-403B-BD7B-F5D063D84154}\n\tName:\t\tActive Directory Domain Controller (RPC-EPMAP)\n\tType:\t\tNot persistent\n\tRun-Time ID:\t84512\n\nLayer Information:\n\tID:\t\t{E1CD9FE7-F4B5-4273-96C0-592E487B8650}\n\tName:\t\tALE Receive/Accept v4 Layer\n\tRun-Time ID:\t44\n\nCallout Information:\n\tID:\t\t{00000000-0000-0000-0000-000000000000}\n\tName:\t\t-\n\nAdditional Information:\n\tWeight:\t10378405428420673536\t\n\tConditions:\t\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0251\n\n\tCondition ID:\t{3971ef2b-623e-4f9a-8cb1-6e79b806b9a7}\n\tMatch value:\tEqual to\n\tCondition value:\t0x06\n\n\tFilter Action:\tPermit","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"7bdcfe9d7277ed93a61b0e04d0c136ffaec01f79578e7569f81a9f87bdc02dd5","action":"Other Policy Change Events","created":"2026-05-05T08:06:05.662Z","code":5447,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:06:04.662Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":660,"thread":{"id":3956}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","activity_id":"{33A57B7F-DBBD-0002-997B-A533BDDBDC01}","event_id":5447,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"api":"wineventlog","record_id":253526335,"task":"Other Policy Change Events","event_data":{"ProcessId":"1236","UserSid":"S-1-5-19","FilterType":"%%16388","FilterKey":"{B010A177-CFCC-403B-BD7B-F5D063D84154}","ChangeType":"%%16385","ProviderName":"Microsoft Corporation","LayerKey":"{E1CD9FE7-F4B5-4273-96C0-592E487B8650}","UserName":"NT AUTHORITY\\LOCAL SERVICE","ProviderKey":"{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}","CalloutName":"-","FilterName":"Active Directory Domain Controller (RPC-EPMAP)","Weight":"10378405428420673536","Action":"%%16390","LayerName":"ALE Receive/Accept v4 Layer","CalloutKey":"{00000000-0000-0000-0000-000000000000}","FilterId":"84512","Conditions":"\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0251\n\n\tCondition ID:\t{3971ef2b-623e-4f9a-8cb1-6e79b806b9a7}\n\tMatch value:\tEqual to\n\tCondition value:\t0x06","LayerId":"44"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tDirection:\t\tOutbound\n\tSource Address:\t\t::1\n\tSource Port:\t\t52480\n\tDestination Address:\t::1\n\tDestination Port:\t\t53\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t65788\n\tLayer Name:\t\tConnect\n\tLayer Run-Time ID:\t50","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"1c4c1a8065cfee2b47ead1a444e27faab39a0833eabe6f57cbcc5e6212ba910c","action":"Filtering Platform Connection","created":"2026-05-05T08:12:07.682Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:12:06.321Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1416}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5156,"opcode":"Info","api":"wineventlog","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","version":1,"record_id":204127715,"task":"Filtering Platform Connection","event_data":{"SourcePort":"52480","DestPort":"53","DestAddress":"::1","SourceAddress":"::1","ProcessID":"684","LayerName":"%%14611","Protocol":"17","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"50","FilterRTID":"65788","Direction":"%%14593"},"channel":"Security"}}
{"message":"A Windows Filtering Platform filter has been changed.\n\t\nSubject:\n\tSecurity ID:\t\tS-1-5-19\n\tAccount Name:\t\tNT AUTHORITY\\LOCAL SERVICE\n\nProcess Information:\n\tProcess ID:\t1236\n\nProvider Information:\n\tID:\t\t{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}\n\tName:\t\tMicrosoft Corporation\n\nChange Information:\n\tChange Type:\tDelete\n\nFilter Information:\n\tID:\t\t{9ADAAEB6-6148-43B3-BA81-C6905191259F}\n\tName:\t\tActive Directory Domain Controller (RPC-EPMAP)\n\tType:\t\tNot persistent\n\tRun-Time ID:\t84513\n\nLayer Information:\n\tID:\t\t{7AC9DE24-17DD-4814-B4BD-A9FBC95A321B}\n\tName:\t\tALE Listen v6 Layer\n\tRun-Time ID:\t42\n\nCallout Information:\n\tID:\t\t{00000000-0000-0000-0000-000000000000}\n\tName:\t\t-\n\nAdditional Information:\n\tWeight:\t10376293541528731616\t\n\tConditions:\t\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0087\n\n\tFilter Action:\tPermit","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"a5a76bf227a9681ff9f227ff05ee4aefc35f678ba26ef9c71a487bf8e9ff4bcc","action":"Other Policy Change Events","created":"2026-05-05T08:06:05.662Z","code":5447,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:06:04.662Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"activity_id":"{33A57B7F-DBBD-0002-997B-A533BDDBDC01}","process":{"pid":660,"thread":{"id":3956}},"provider_name":"Microsoft-Windows-Security-Auditing","event_id":5447,"computer_name":"w2016ad-n25.tdarplatform.csoc","api":"wineventlog","opcode":"Info","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":253526336,"task":"Other Policy Change Events","event_data":{"ProcessId":"1236","FilterType":"%%16388","UserSid":"S-1-5-19","FilterKey":"{9ADAAEB6-6148-43B3-BA81-C6905191259F}","Action":"%%16390","LayerName":"ALE Listen v6 Layer","LayerKey":"{7AC9DE24-17DD-4814-B4BD-A9FBC95A321B}","ProviderName":"Microsoft Corporation","CalloutName":"-","ChangeType":"%%16385","CalloutKey":"{00000000-0000-0000-0000-000000000000}","Weight":"10376293541528731616","ProviderKey":"{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}","Conditions":"\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0087","UserName":"NT AUTHORITY\\LOCAL SERVICE","FilterId":"84513","FilterName":"Active Directory Domain Controller (RPC-EPMAP)","LayerId":"42"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t2444\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\dns.exe\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t::1\n\tSource Port:\t\t52480\n\tDestination Address:\t::1\n\tDestination Port:\t\t53\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t65786\n\tLayer Name:\t\tReceive/Accept\n\tLayer Run-Time ID:\t46","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"3bbc7aeaa4eb25b7221ca1124a5fcfe3c2f527e3e76b9bb4f89c74b3f8c139c6","action":"Filtering Platform Connection","created":"2026-05-05T08:12:07.682Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:12:06.321Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1416}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5156,"opcode":"Info","keywords":["Audit Success"],"version":1,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":204127716,"task":"Filtering Platform Connection","event_data":{"Direction":"%%14592","DestPort":"53","DestAddress":"::1","SourceAddress":"::1","ProcessID":"2444","Protocol":"17","LayerName":"%%14610","RemoteMachineID":"S-1-0-0","Application":"\\device\\harddiskvolume2\\windows\\system32\\dns.exe","LayerRTID":"46","RemoteUserID":"S-1-0-0","FilterRTID":"65786","SourcePort":"52480"},"channel":"Security"}}
{"message":"A Windows Filtering Platform filter has been changed.\n\t\nSubject:\n\tSecurity ID:\t\tS-1-5-19\n\tAccount Name:\t\tNT AUTHORITY\\LOCAL SERVICE\n\nProcess Information:\n\tProcess ID:\t1236\n\nProvider Information:\n\tID:\t\t{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}\n\tName:\t\tMicrosoft Corporation\n\nChange Information:\n\tChange Type:\tDelete\n\nFilter Information:\n\tID:\t\t{E5B02C5F-4707-4CD7-99E3-6A7F90388262}\n\tName:\t\tActive Directory Domain Controller (RPC-EPMAP)\n\tType:\t\tNot persistent\n\tRun-Time ID:\t84514\n\nLayer Information:\n\tID:\t\t{A3B42C97-9F04-4672-B87E-CEE9C483257F}\n\tName:\t\tALE Receive/Accept v6 Layer\n\tRun-Time ID:\t46\n\nCallout Information:\n\tID:\t\t{00000000-0000-0000-0000-000000000000}\n\tName:\t\t-\n\nAdditional Information:\n\tWeight:\t10376540038224674816\t\n\tConditions:\t\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0087\n\n\tCondition ID:\t{3971ef2b-623e-4f9a-8cb1-6e79b806b9a7}\n\tMatch value:\tEqual to\n\tCondition value:\t0x06\n\n\tFilter Action:\tPermit","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"cec958141d93b8043259a37605b04943c1c6d53678deff34c5f3ecfb37daf83c","action":"Other Policy Change Events","created":"2026-05-05T08:06:05.662Z","code":5447,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:06:04.662Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"channel":"Security","process":{"pid":660,"thread":{"id":3956}},"provider_name":"Microsoft-Windows-Security-Auditing","event_id":5447,"computer_name":"w2016ad-n25.tdarplatform.csoc","api":"wineventlog","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","record_id":253526337,"task":"Other Policy Change Events","event_data":{"ProcessId":"1236","FilterType":"%%16388","UserSid":"S-1-5-19","CalloutKey":"{00000000-0000-0000-0000-000000000000}","Action":"%%16390","FilterKey":"{E5B02C5F-4707-4CD7-99E3-6A7F90388262}","LayerKey":"{A3B42C97-9F04-4672-B87E-CEE9C483257F}","Conditions":"\n\tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971}\n\tMatch value:\tEqual to\n\tCondition value:\t\n 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\.\n 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k.\n 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 32 00 5c 00 v.o.l.u.m.e.2.\\.\n 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\.\n 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2.\n 00000050 5c 00 73 00 76 00 63 00-68 00 6f 00 73 00 74 00 \\.s.v.c.h.o.s.t.\n 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e...\n\n\n\tCondition ID:\t{af043a0a-b34d-4f86-979c-c90371af6e66}\n\tMatch value:\tEqual to\n\tCondition value:\t\nO:SYG:SYD:(A;;CCRC;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)\n\n\n\tCondition ID:\t{0c1ba1af-5765-453f-af22-a8f791ac775b}\n\tMatch value:\tEqual to\n\tCondition value:\t0x0087\n\n\tCondition ID:\t{3971ef2b-623e-4f9a-8cb1-6e79b806b9a7}\n\tMatch value:\tEqual to\n\tCondition value:\t0x06","CalloutName":"-","ProviderKey":"{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}","UserName":"NT AUTHORITY\\LOCAL SERVICE","Weight":"10376540038224674816","ProviderName":"Microsoft Corporation","FilterName":"Active Directory Domain Controller (RPC-EPMAP)","ChangeType":"%%16385","FilterId":"84514","LayerName":"ALE Receive/Accept v6 Layer","LayerId":"46"},"activity_id":"{33A57B7F-DBBD-0002-997B-A533BDDBDC01}"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t0\n\tApplication Name:\t-\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.196\n\tSource Port:\t\t41807\n\tDestination Address:\t239.255.255.250\n\tDestination Port:\t\t1900\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t67683\n\tLayer Name:\t\tTransport\n\tLayer Run-Time ID:\t13","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"3354b778926a79b0d6f9f99c2082cb96ff54936b0374dac14aa3eed93bf9d056","action":"Filtering Platform Packet Drop","created":"2026-05-05T08:09:07.153Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:09:06.086Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":1756}},"event_id":5152,"opcode":"Info","keywords":["Audit Failure"],"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":253526581,"task":"Filtering Platform Packet Drop","event_data":{"SourcePort":"41807","DestPort":"1900","ProcessId":"0","DestAddress":"239.255.255.250","SourceAddress":"172.30.4.196","LayerName":"%%14597","Protocol":"17","Application":"-","LayerRTID":"13","FilterRTID":"67683","Direction":"%%14592"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tSource Address:\t\t::\n\tSource Port:\t\t63485\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t36","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"66bbda52ed4a2a4ee9a93fc2c928150778a34ab5d6b680a72beea644311f9de4","action":"Filtering Platform Connection","created":"2026-05-05T08:13:24.454Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:13:22.915Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":1416}},"event_id":5158,"api":"wineventlog","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","record_id":204127965,"task":"Filtering Platform Connection","event_data":{"Protocol":"17","LayerName":"%%14608","ProcessId":"684","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"36","SourceAddress":"::","FilterRTID":"0","SourcePort":"63485"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has blocked a packet.\n\nApplication Information:\n\tProcess ID:\t\t0\n\tApplication Name:\t-\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.2.163\n\tSource Port:\t\t1514\n\tDestination Address:\t172.30.4.206\n\tDestination Port:\t\t55989\n\tProtocol:\t\t6\n\nFilter Information:\n\tFilter Run-Time ID:\t67042\n\tLayer Name:\t\tICMP Error\n\tLayer Run-Time ID:\t28","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"3f9e43c3d90a5c62d253488049be90c2a388a28d97553e73369596dce698da27","action":"Filtering Platform Packet Drop","created":"2026-05-05T08:09:07.153Z","code":5152,"outcome":"failure","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:09:06.574Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1756}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","event_id":5152,"opcode":"Info","keywords":["Audit Failure"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","record_id":253526582,"task":"Filtering Platform Packet Drop","event_data":{"Direction":"%%14592","DestPort":"55989","ProcessId":"0","DestAddress":"172.30.4.206","SourceAddress":"172.30.2.163","LayerName":"%%14601","Protocol":"6","Application":"-","LayerRTID":"28","FilterRTID":"67042","SourcePort":"1514"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tSource Address:\t\t::\n\tSource Port:\t\t63485\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t38","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"31ad9c3fcae7ab76876eb1002b7a6b3f65f29ef83dccb320187a8a4067f7318f","action":"Filtering Platform Connection","created":"2026-05-05T08:13:24.454Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:13:22.915Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1416}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5158,"api":"wineventlog","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","opcode":"Info","record_id":204127966,"task":"Filtering Platform Connection","event_data":{"Protocol":"17","LayerName":"%%14608","ProcessId":"684","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"38","SourceAddress":"::","FilterRTID":"0","SourcePort":"63485"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T08:09:11.197Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:09:09.602Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1756}},"computer_name":"w2016ad-n25.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":4703,"opcode":"Info","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","record_id":253526583,"task":"Token Right Adjusted Events","event_data":{"TargetUserName":"W2016AD-N25$","SubjectUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectUserSid":"S-1-5-18","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tDirection:\t\tOutbound\n\tSource Address:\t\t::1\n\tSource Port:\t\t63485\n\tDestination Address:\t::1\n\tDestination Port:\t\t53\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t65788\n\tLayer Name:\t\tConnect\n\tLayer Run-Time ID:\t50","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"8c241c1569437ee50c68075816eb552cd9b1b5e80958d4fecb58960d3af38815","action":"Filtering Platform Connection","created":"2026-05-05T08:13:24.454Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:13:22.915Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1416}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":5156,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","version":1,"keywords":["Audit Success"],"record_id":204127967,"task":"Filtering Platform Connection","event_data":{"SourcePort":"63485","DestPort":"53","DestAddress":"::1","SourceAddress":"::1","ProcessID":"684","LayerName":"%%14611","Protocol":"17","RemoteMachineID":"S-1-0-0","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","RemoteUserID":"S-1-0-0","LayerRTID":"50","FilterRTID":"65788","Direction":"%%14593"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tSource Address:\t\t::\n\tSource Port:\t\t50874\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t38","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"4a3aafb01f15a296d92b67b85a68b2aebda5c68b0802f3e2d0b75793f6881a7f","action":"Filtering Platform Connection","created":"2026-05-05T08:13:24.454Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:13:22.915Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","process":{"pid":4,"thread":{"id":1416}},"computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","event_id":5158,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"api":"wineventlog","record_id":204127968,"task":"Filtering Platform Connection","event_data":{"Protocol":"17","LayerName":"%%14608","ProcessId":"684","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"38","SourceAddress":"::","FilterRTID":"0","SourcePort":"50874"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T08:09:11.197Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:09:09.602Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":1756}},"event_id":4703,"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","api":"wineventlog","keywords":["Audit Success"],"record_id":253526584,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"W2016AD-N25$","TargetUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectUserSid":"S-1-5-18","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tSource Address:\t\t0.0.0.0\n\tSource Port:\t\t52313\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t36","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"9b96cc88a4e66134f536a1a62e600c675cbc4fa0ce7fc5aa4b6c95425429751f","action":"Filtering Platform Connection","created":"2026-05-05T08:13:24.454Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:13:22.915Z","agent":{"name":"WIN-MDLQ2GQ94V9","id":"829caaa0-db4b-40b2-8076-11ac1493a97b","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":1416}},"event_id":5158,"api":"wineventlog","keywords":["Audit Success"],"opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":204127969,"task":"Filtering Platform Connection","event_data":{"Protocol":"17","LayerName":"%%14608","ProcessId":"684","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"36","SourceAddress":"0.0.0.0","FilterRTID":"0","SourcePort":"52313"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T08:09:11.197Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:09:09.605Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":1756}},"event_id":4703,"opcode":"Info","api":"wineventlog","keywords":["Audit Success"],"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":253526585,"task":"Token Right Adjusted Events","event_data":{"TargetUserName":"W2016AD-N25$","SubjectUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T08:09:11.197Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"9ca2332f-614b-4da2-897e-35dfbc072591","name":"w2016ad-n25.tdarplatform.csoc","hostname":"w2016ad-n25","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:09:09.614Z","agent":{"name":"w2016ad-n25","id":"16b27c50-d19b-4829-8363-ff3aabf1f846","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"w2016ad-n25.tdarplatform.csoc","process":{"pid":4,"thread":{"id":1756}},"event_id":4703,"opcode":"Info","keywords":["Audit Success"],"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":253526586,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"W2016AD-N25$","TargetUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectUserSid":"S-1-5-18","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a bind to a local port.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tSource Address:\t\t0.0.0.0\n\tSource Port:\t\t64596\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t0\n\tLayer Name:\t\tResource Assignment\n\tLayer Run-Time ID:\t36","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"3bb26a59e8b48691f92366c07d3546a6bf58e17a871ee9099b9f67a89f3e2dae","action":"Filtering Platform Connection","created":"2026-05-05T08:13:24.454Z","code":5158,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"platform":"windows","name":"Windows Server 2016 Standard","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:13:22.916Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1416}},"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","event_id":5158,"opcode":"Info","keywords":["Audit Success"],"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":204127970,"task":"Filtering Platform Connection","event_data":{"LayerName":"%%14608","Protocol":"17","ProcessId":"684","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"36","SourceAddress":"0.0.0.0","FilterRTID":"0","SourcePort":"64596"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T08:09:11.197Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:09:09.615Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"process":{"pid":4,"thread":{"id":1756}},"computer_name":"w2016ad-n25.tdarplatform.csoc","provider_name":"Microsoft-Windows-Security-Auditing","event_id":4703,"opcode":"Info","keywords":["Audit Success"],"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","record_id":253526587,"task":"Token Right Adjusted Events","event_data":{"SubjectUserName":"W2016AD-N25$","TargetUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t684\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\lsass.exe\n\nNetwork Information:\n\tDirection:\t\tOutbound\n\tSource Address:\t\t172.30.4.205\n\tSource Port:\t\t64596\n\tDestination Address:\t172.30.4.205\n\tDestination Port:\t\t53\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t65789\n\tLayer Name:\t\tConnect\n\tLayer Run-Time ID:\t48","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"d580807102378863e869bfb15c2f91c6085b40b5c59c6fe79c9dffb267a162cd","action":"Filtering Platform Connection","created":"2026-05-05T08:13:24.454Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:13:22.916Z","agent":{"name":"WIN-MDLQ2GQ94V9","id":"829caaa0-db4b-40b2-8076-11ac1493a97b","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":1416}},"event_id":5156,"api":"wineventlog","opcode":"Info","version":1,"provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"record_id":204127971,"task":"Filtering Platform Connection","event_data":{"Direction":"%%14593","DestPort":"53","DestAddress":"172.30.4.205","SourceAddress":"172.30.4.205","ProcessID":"684","LayerName":"%%14611","Protocol":"17","RemoteMachineID":"S-1-0-0","RemoteUserID":"S-1-0-0","Application":"\\device\\harddiskvolume2\\windows\\system32\\lsass.exe","LayerRTID":"48","FilterRTID":"65789","SourcePort":"64596"},"channel":"Security"}}
{"message":"A token right was adjusted.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-18\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nTarget Account:\n\tSecurity ID:\t\tS-1-0-0\n\tAccount Name:\t\tW2016AD-N25$\n\tAccount Domain:\t\tTDARPLATFORM\n\tLogon ID:\t\t0x3E7\n\nProcess Information:\n\tProcess ID:\t\t0x158\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\n\nEnabled Privileges:\n\t\t\tSeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege\n\nDisabled Privileges:\n\t\t\t-","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"429f9a471e1012249cb9022fdf09eaebc60f1a5dedeed53c40cb621e6908e7a2","action":"Token Right Adjusted Events","created":"2026-05-05T08:09:11.197Z","code":4703,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"name":"w2016ad-n25.tdarplatform.csoc","id":"9ca2332f-614b-4da2-897e-35dfbc072591","hostname":"w2016ad-n25","os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.2430","version":"10.0","kernel":"10.0.14393.2430 (rs1_release_inmarket_aim.180806-1810)","family":"windows"},"mac":["00:50:56:bf:9f:79","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"ip":["fe80::cd46:3442:b9b4:26f4","172.30.4.206","fe80::5efe:ac1e:4ce","2001:0:4625:9904:2045:2a14:53e1:fb31","fe80::2045:2a14:53e1:fb31"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:09:09.615Z","agent":{"id":"16b27c50-d19b-4829-8363-ff3aabf1f846","name":"w2016ad-n25","ephemeral_id":"436fbb1d-254b-4868-9ca3-33dd28e8ff2a","hostname":"w2016ad-n25","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","process":{"pid":4,"thread":{"id":1756}},"computer_name":"w2016ad-n25.tdarplatform.csoc","event_id":4703,"api":"wineventlog","opcode":"Info","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","keywords":["Audit Success"],"record_id":253526588,"task":"Token Right Adjusted Events","event_data":{"TargetUserName":"W2016AD-N25$","SubjectUserName":"W2016AD-N25$","ProcessId":"0x158","SubjectDomainName":"TDARPLATFORM","EnabledPrivilegeList":"SeAssignPrimaryTokenPrivilege\n\t\t\tSeIncreaseQuotaPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeSystemtimePrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeShutdownPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeUndockPrivilege\n\t\t\tSeManageVolumePrivilege","SubjectUserSid":"S-1-5-18","ProcessName":"C:\\Windows\\System32\\svchost.exe","SubjectLogonId":"0x3e7","TargetLogonId":"0x3e7","TargetDomainName":"TDARPLATFORM","DisabledPrivilegeList":"-","TargetUserSid":"S-1-0-0"},"channel":"Security"}}
{"message":"The Windows Filtering Platform has permitted a connection.\n\nApplication Information:\n\tProcess ID:\t\t2444\n\tApplication Name:\t\\device\\harddiskvolume2\\windows\\system32\\dns.exe\n\nNetwork Information:\n\tDirection:\t\tInbound\n\tSource Address:\t\t172.30.4.205\n\tSource Port:\t\t64596\n\tDestination Address:\t172.30.4.205\n\tDestination Port:\t\t53\n\tProtocol:\t\t17\n\nFilter Information:\n\tFilter Run-Time ID:\t65787\n\tLayer Name:\t\tReceive/Accept\n\tLayer Run-Time ID:\t44","log":{"level":"information"},"type":"winlogbeat","event":{"provider":"Microsoft-Windows-Security-Auditing","hash":"5efde32aa7c8d4cc05ff912e3ea53d1f8cc8adbfd128ca9ba5251c9cc96c6e0f","action":"Filtering Platform Connection","created":"2026-05-05T08:13:24.454Z","code":5156,"outcome":"success","kind":"event"},"ecs":{"version":"1.5.0"},"@version":"1","event_type":"windows","host":{"id":"d3fe0a29-15df-481b-ab7d-fd4eb311fbc5","name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","hostname":"WIN-MDLQ2GQ94V9","mac":["00:50:56:bf:cb:a8","00:00:00:00:00:00:00:e0","00:00:00:00:00:00:00:e0"],"os":{"name":"Windows Server 2016 Standard","platform":"windows","build":"14393.5717","version":"10.0","kernel":"10.0.14393.5717 (rs1_release.230203-1742)","family":"windows"},"ip":["fe80::6c1c:1afd:b16:ecb9","172.30.4.205","fe80::5efe:ac1e:4cd","2001:0:4625:9904:fe:3f96:53e1:fb32","fe80::fe:3f96:53e1:fb32"],"architecture":"x86_64"},"@timestamp":"2026-05-05T08:13:22.916Z","agent":{"id":"829caaa0-db4b-40b2-8076-11ac1493a97b","name":"WIN-MDLQ2GQ94V9","ephemeral_id":"0650b63b-73b4-4557-ba3a-e762f876c508","hostname":"WIN-MDLQ2GQ94V9","version":"7.10.2","type":"winlogbeat"},"tags":["beats_input_codec_plain_applied"],"winlog":{"provider_name":"Microsoft-Windows-Security-Auditing","computer_name":"WIN-MDLQ2GQ94V9.tdarplatform.csoc","process":{"pid":4,"thread":{"id":1416}},"event_id":5156,"api":"wineventlog","provider_guid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","version":1,"keywords":["Audit Success"],"opcode":"Info","record_id":204127972,"task":"Filtering Platform Connection","event_data":{"Direction":"%%14592","DestPort":"53","DestAddress":"172.30.4.205","SourceAddress":"172.30.4.205","ProcessID":"2444","Protocol":"17","LayerName":"%%14610","RemoteMachineID":"S-1-0-0","Application":"\\device\\harddiskvolume2\\windows\\system32\\dns.exe","LayerRTID":"44","RemoteUserID":"S-1-0-0","FilterRTID":"65787","SourcePort":"64596"},"channel":"Security"}}