Microsoft-Windows-CAPI2

74 events across 3 channels

Event IDTitleChannel
10For more details for this event, please refer to the "Details" sectionOperational
11For more details for this event, please refer to the "Details" sectionOperational
12For more details for this event, please refer to the "Details" sectionOperational
13For more details for this event, please refer to the "Details" sectionOperational
14For more details for this event, please refer to the "Details" sectionOperational
15For more details for this event, please refer to the "Details" sectionOperational
16For more details for this event, please refer to the "Details" sectionOperational
17For more details for this event, please refer to the "Details" sectionOperational
18For more details for this event, please refer to the "Details" sectionOperational
19For more details for this event, please refer to the "Details" sectionOperational
20For more details for this event, please refer to the "Details" sectionOperational
21For more details for this event, please refer to the "Details" sectionOperational
22For more details for this event, please refer to the "Details" sectionOperational
23For more details for this event, please refer to the "Details" sectionOperational
24For more details for this event, please refer to the "Details" sectionOperational
30For more details for this event, please refer to the "Details" sectionOperational
40For more details for this event, please refer to the "Details" sectionOperational
41For more details for this event, please refer to the "Details" sectionOperational
42For more details for this event, please refer to the "Details" sectionOperational
50For more details for this event, please refer to the "Details" sectionOperational
51For more details for this event, please refer to the "Details" sectionOperational
52For more details for this event, please refer to the "Details" sectionOperational
53For more details for this event, please refer to the "Details" sectionOperational
60For more details for this event, please refer to the "Details" sectionOperational
70For more details for this event, please refer to the "Details" sectionOperational
71For more details for this event, please refer to the "Details" sectionOperational
80For more details for this event, please refer to the "Details" sectionOperational
81For more details for this event, please refer to the "Details" sectionOperational
82For more details for this event, please refer to the "Details" sectionOperational
90For more details for this event, please refer to the "Details" sectionOperational
256The Cryptographic Services service failed to initialize the Catalog Database.Application
257The Cryptographic Services service failed to initialize the Catalog Database.Application
512The Cryptographic Services service failed to initialize the VSS backup "System …Application
513Cryptographic Services failed while processing the OnIdentity() call in the …Application
4097Successful auto update of third-party root certificate:: Subject: <OU=Go Daddy …Application
4098Successful auto update retrieval of third-party root list cab from: <.Application
4099Failed auto update retrieval of third-party root list cab from: <.Application
4100Successful auto update retrieval of third-party root certificate from: <.Application
4101Failed auto update retrieval of third-party root certificate from: <.Application
4102Reached crypt32 threshold of %1 events and will suspend logging for %2 minutes.Application
4103Successful auto update retrieval of third-party root list sequence number from: …Application
4104Failed auto update retrieval of third-party root list sequence number from: <.Application
4105Untrusted root certificate:: Subject: <.Application
4106Partial Chain:: Issuer: <.Application
4107Failed extract of third-party root list from auto update cab at: <.Application
4108Successful auto delete of third-party root certificate:: Subject: <OU=Class 3 …Application
4109Successful auto property update of third-party root certificate:: Subject: …Application
4110Failed to add certificate to Third-Party Root Certification Authorities store …Application
4111Successful auto update of third-party root list with effective date: ‎Tuesday, …Application
4112Successful auto update of disallowed certificate list with effective date: …Application
4113Successful auto update of pin rules with effective date: ‎Wednesday, ‎May ‎31, …Application
4114Server: %1 has unexpected certificates under trusted authority: <%2> with …Application
4115Added public key pinning rule for domain: %1 with header thumbprint: %2.Application
4116Server: %1 has unexpected certificates under trusted authority: <%2> with …Application
4117Server: %1 has unexpected certificates under trusted authority: <%2> with …Application
4128Successful pre-fetch of certificate revocation list from: <.Application
4129Failed pre-fetch of certificate revocation list from: <.Application
4130Certificate signature verify failed.Application
4131LDAP CryptRetrieveObjectByUrlW failed.Application
4176PFX operation failed as AuthSafes count doesn't lie in expected range.Application
4177PFX operation failed as Iteration count doesn't lie in expected range.Application
4178PFX operation failed as SafeBags count doesn't lie in expected range.Application
8192The catalog file %2 is being added to subsystem %1.Catalog Database Debug
8193Addition of the catalog file completed.Catalog Database Debug
8194The catalog file %2 is being removed from the subsystem %1.Catalog Database Debug
8195Removal of the catalog file completed.Catalog Database Debug
8196The catalog file %2 is being synced to the subsystem %1.Catalog Database Debug
8197Sync of the catalog file completed.Catalog Database Debug
8198The Catalog Database is being rebuilt for subsystem %1.Catalog Database Debug
8199Rebuild of the Catalog Database for the chosen subsystem has completed.Catalog Database Debug
8200A hash of type %2, length %3 and value %4 is being searched for in subsystem %1.Catalog Database Debug
8201The hash search completed and was found in %2 catalogs.Catalog Database Debug
8202Sync of subsystem %1 has started.Catalog Database Debug
8203Sync of the subsystem completed.Catalog Database Debug

Event ID 10 — For more details for this event, please refer to the "Details" section

Provider
Microsoft-Windows-CAPI2
Channel
Operational

Message

For more details for this event, please refer to the "Details" section

Fields

NameDescription
EventWriteData

Event ID 11 — For more details for this event, please refer to the "Details" section

Provider
Microsoft-Windows-CAPI2
Channel
Operational

Message

For more details for this event, please refer to the "Details" section

Fields

NameDescription
EventWriteData

References

Event ID 12 — For more details for this event, please refer to the "Details" section

Provider
Microsoft-Windows-CAPI2
Channel
Operational

Message

For more details for this event, please refer to the "Details" section

Fields

NameDescription
EventWriteData

Event ID 13 — For more details for this event, please refer to the "Details" section

Provider
Microsoft-Windows-CAPI2
Channel
Operational

Message

For more details for this event, please refer to the "Details" section

Fields

NameDescription
EventWriteData

Event ID 14 — For more details for this event, please refer to the "Details" section

Provider
Microsoft-Windows-CAPI2
Channel
Operational

Message

For more details for this event, please refer to the "Details" section

Fields

NameDescription
EventWriteData

Event ID 15 — For more details for this event, please refer to the "Details" section

Provider
Microsoft-Windows-CAPI2
Channel
Operational

Message

For more details for this event, please refer to the "Details" section

Fields

NameDescription
EventWriteData

Event ID 16 — For more details for this event, please refer to the "Details" section

Provider
Microsoft-Windows-CAPI2
Channel
Operational

Message

For more details for this event, please refer to the "Details" section

Fields

NameDescription
EventWriteData

Event ID 17 — For more details for this event, please refer to the "Details" section

Provider
Microsoft-Windows-CAPI2
Channel
Operational

Message

For more details for this event, please refer to the "Details" section

Fields

NameDescription
EventWriteData

Event ID 18 — For more details for this event, please refer to the "Details" section

Provider
Microsoft-Windows-CAPI2
Channel
Operational

Message

For more details for this event, please refer to the "Details" section

Fields

NameDescription
EventWriteData

Event ID 19 — For more details for this event, please refer to the "Details" section

Provider
Microsoft-Windows-CAPI2
Channel
Operational

Message

For more details for this event, please refer to the "Details" section

Fields

NameDescription
EventWriteData

Event ID 20 — For more details for this event, please refer to the "Details" section

Provider
Microsoft-Windows-CAPI2
Channel
Operational

Message

For more details for this event, please refer to the "Details" section

Fields

NameDescription
EventWriteData

Event ID 21 — For more details for this event, please refer to the "Details" section

Provider
Microsoft-Windows-CAPI2
Channel
Operational

Message

For more details for this event, please refer to the "Details" section

Fields

NameDescription
EventWriteData

Event ID 22 — For more details for this event, please refer to the "Details" section

Provider
Microsoft-Windows-CAPI2
Channel
Operational

Message

For more details for this event, please refer to the "Details" section

Fields

NameDescription
EventWriteData

Event ID 23 — For more details for this event, please refer to the "Details" section

Provider
Microsoft-Windows-CAPI2
Channel
Operational

Message

For more details for this event, please refer to the "Details" section

Fields

NameDescription
EventWriteData

Event ID 24 — For more details for this event, please refer to the "Details" section

Provider
Microsoft-Windows-CAPI2
Channel
Operational

Message

For more details for this event, please refer to the "Details" section

Fields

NameDescription
EventWriteData

Event ID 30 — For more details for this event, please refer to the "Details" section

Provider
Microsoft-Windows-CAPI2
Channel
Operational

Message

For more details for this event, please refer to the "Details" section

Fields

NameDescription
EventWriteData

Event ID 40 — For more details for this event, please refer to the "Details" section

Provider
Microsoft-Windows-CAPI2
Channel
Operational

Message

For more details for this event, please refer to the "Details" section

Fields

NameDescription
EventWriteData

Event ID 41 — For more details for this event, please refer to the "Details" section

Provider
Microsoft-Windows-CAPI2
Channel
Operational

Message

For more details for this event, please refer to the "Details" section

Fields

NameDescription
EventWriteData

Event ID 42 — For more details for this event, please refer to the "Details" section

Provider
Microsoft-Windows-CAPI2
Channel
Operational

Message

For more details for this event, please refer to the "Details" section

Fields

NameDescription
EventWriteData

Event ID 50 — For more details for this event, please refer to the "Details" section

Provider
Microsoft-Windows-CAPI2
Channel
Operational

Message

For more details for this event, please refer to the "Details" section

Fields

NameDescription
EventWriteData

Event ID 51 — For more details for this event, please refer to the "Details" section

Provider
Microsoft-Windows-CAPI2
Channel
Operational

Message

For more details for this event, please refer to the "Details" section

Fields

NameDescription
EventWriteData

Event ID 52 — For more details for this event, please refer to the "Details" section

Provider
Microsoft-Windows-CAPI2
Channel
Operational

Message

For more details for this event, please refer to the "Details" section

Fields

NameDescription
EventWriteData

Event ID 53 — For more details for this event, please refer to the "Details" section

Provider
Microsoft-Windows-CAPI2
Channel
Operational

Message

For more details for this event, please refer to the "Details" section

Fields

NameDescription
EventWriteData

Event ID 60 — For more details for this event, please refer to the "Details" section

Provider
Microsoft-Windows-CAPI2
Channel
Operational

Message

For more details for this event, please refer to the "Details" section

Fields

NameDescription
EventWriteData

Event ID 70 — For more details for this event, please refer to the "Details" section

Provider
Microsoft-Windows-CAPI2
Channel
Operational
Level
4
Samples
1

Message

For more details for this event, please refer to the "Details" section

Fields

NameDescription
CryptAcquireCertificatePrivateKey

Example Event

system:
  provider: Microsoft-Windows-CAPI2
  guid: '{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}'
  event_source_name: ''
  event_id: 70
  version: 0
  level: 4
  task: 70
  opcode: 0
  keywords: 4611686018427388032
  time_created: '2020-07-11T13:21:11.693103Z'
  event_record_id: 13969076
  correlation: {}
  execution:
    process_id: 5708
    thread_id: 5712
  channel: Microsoft-Windows-CAPI2/Operational
  computer: wec02
  security:
    user_id: S-1-5-21-1153173314-1076311963-3278442693-500
user_data:
  CryptAcquireCertificatePrivateKey:
    Certificate:
      '#attributes':
        fileRef: 3CD6B0EFAF68549EFE9ED2316426FCD7FF81A6A8.cer
        subjectName: wec02.offsec.lan
    Flags:
      '#attributes':
        value: '10000'
        CRYPT_ACQUIRE_ALLOW_NCRYPT_KEY_FLAG: 'true'
    EventAuxInfo:
      '#attributes':
        ProcessName: mimikatz.exe
    CorrelationAuxInfo:
      '#attributes':
        TaskId: '{973F48B9-7001-410B-A904-B1DD8692B60A}'
        SeqNumber: '2'
    Result:
      '#attributes':
        value: '0'

Sigma Rules

References

Event ID 71 — For more details for this event, please refer to the "Details" section

Provider
Microsoft-Windows-CAPI2
Channel
Operational

Message

For more details for this event, please refer to the "Details" section

Fields

NameDescription
EventWriteData

Event ID 80 — For more details for this event, please refer to the "Details" section

Provider
Microsoft-Windows-CAPI2
Channel
Operational

Message

For more details for this event, please refer to the "Details" section

Fields

NameDescription
EventWriteData

Event ID 81 — For more details for this event, please refer to the "Details" section

Provider
Microsoft-Windows-CAPI2
Channel
Operational

Message

For more details for this event, please refer to the "Details" section

Fields

NameDescription
EventWriteData

Event ID 82 — For more details for this event, please refer to the "Details" section

Provider
Microsoft-Windows-CAPI2
Channel
Operational

Message

For more details for this event, please refer to the "Details" section

Fields

NameDescription
EventWriteData

Event ID 90 — For more details for this event, please refer to the "Details" section

Provider
Microsoft-Windows-CAPI2
Channel
Operational

Message

For more details for this event, please refer to the "Details" section

Fields

NameDescription
EventWriteData

Event ID 256 — The Cryptographic Services service failed to initialize the Catalog Database.

Provider
Microsoft-Windows-CAPI2
Channel
Application

Message

The Cryptographic Services service failed to initialize the Catalog Database. The error was: %1 : %2.

Fields

NameDescription
1
2

Event ID 257 — The Cryptographic Services service failed to initialize the Catalog Database.

Provider
Microsoft-Windows-CAPI2
Channel
Application

Message

The Cryptographic Services service failed to initialize the Catalog Database. The ESENT error was: %1.

Fields

NameDescription
1

Event ID 512 — The Cryptographic Services service failed to initialize the VSS backup "System Writer" object.

Provider
Microsoft-Windows-CAPI2
Channel
Application

Message

The Cryptographic Services service failed to initialize the VSS backup "System Writer" object.%1.

Fields

NameDescription
1

Event ID 513 — Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Provider
Microsoft-Windows-CAPI2
Channel
Application

Message

Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.%1.

Fields

NameDescription
1

Event ID 4097 — Successful auto update of third-party root certificate:: Subject: <OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.

Provider
Microsoft-Windows-CAPI2
Channel
Application
Level
4
Samples
1

Message

Successful auto update of third-party root certificate:: Subject: <%1> Sha1 thumbprint: <%2>.

Fields

NameDescription
Data

Example Event

system:
  provider: Microsoft-Windows-CAPI2
  guid: '{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}'
  event_source_name: Microsoft-Windows-CAPI2
  event_id: 4097
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 9259400833873739776
  time_created: '2023-11-05T23:13:48.717808+00:00'
  event_record_id: 1679
  correlation: {}
  execution:
    process_id: 1140
    thread_id: 1340
  channel: Application
  computer: WinDev2310Eval
  security:
    user_id: ''
event_data:
  Data:
  - OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=US
  - 2796BAE63F1801E277261BA0D77770028F20EEE4
message: 'Successful auto update of third-party root certificate:: Subject: <OU=Go
  Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=US> Sha1
  thumbprint: <2796BAE63F1801E277261BA0D77770028F20EEE4>.'

References

Event ID 4098 — Successful auto update retrieval of third-party root list cab from: <.

Provider
Microsoft-Windows-CAPI2
Channel
Application

Message

Successful auto update retrieval of third-party root list cab from: <%1>.

Fields

NameDescription
1

Event ID 4099 — Failed auto update retrieval of third-party root list cab from: <.

Provider
Microsoft-Windows-CAPI2
Channel
Application

Message

Failed auto update retrieval of third-party root list cab from: <%1> with error: %2.

Fields

NameDescription
1
2

Event ID 4100 — Successful auto update retrieval of third-party root certificate from: <.

Provider
Microsoft-Windows-CAPI2
Channel
Application
Level
4
Samples
1

Message

Successful auto update retrieval of third-party root certificate from: <%1>.

Fields

NameDescription
URL

Example Event

system:
  provider: Microsoft-Windows-CAPI2
  guid: '{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}'
  event_source_name: Microsoft-Windows-CAPI2
  event_id: 4100
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 9259400833873739776
  time_created: '2016-08-24T21:26:02.343750Z'
  event_record_id: 1650
  correlation: {}
  execution:
    process_id: 1124
    thread_id: 1712
  channel: Application
  computer: IE10Win7
  security:
    user_id: ''
event_data: {}

References

Event ID 4101 — Failed auto update retrieval of third-party root certificate from: <.

Provider
Microsoft-Windows-CAPI2
Channel
Application

Message

Failed auto update retrieval of third-party root certificate from: <%1> with error: %2.

Fields

NameDescription
1
2

Event ID 4102 — Reached crypt32 threshold of %1 events and will suspend logging for %2 minutes.

Provider
Microsoft-Windows-CAPI2
Channel
Application

Message

Reached crypt32 threshold of %1 events and will suspend logging for %2 minutes.

Fields

NameDescription
1
2

Event ID 4103 — Successful auto update retrieval of third-party root list sequence number from: <.

Provider
Microsoft-Windows-CAPI2
Channel
Application

Message

Successful auto update retrieval of third-party root list sequence number from: <%1>.

Fields

NameDescription
1

Event ID 4104 — Failed auto update retrieval of third-party root list sequence number from: <.

Provider
Microsoft-Windows-CAPI2
Channel
Application

Message

Failed auto update retrieval of third-party root list sequence number from: <%1> with error: %2.

Fields

NameDescription
1
2

Event ID 4105 — Untrusted root certificate:: Subject: <.

Provider
Microsoft-Windows-CAPI2
Channel
Application

Message

Untrusted root certificate:: Subject: <%1> Sha1 thumbprint: <%2>.

Fields

NameDescription
1
2

Event ID 4106 — Partial Chain:: Issuer: <.

Provider
Microsoft-Windows-CAPI2
Channel
Application

Message

Partial Chain:: Issuer: <%1> Subject Sha1 thumbprint: <%2>.

Fields

NameDescription
1
2

Event ID 4107 — Failed extract of third-party root list from auto update cab at: <.

Provider
Microsoft-Windows-CAPI2
Channel
Application

Message

Failed extract of third-party root list from auto update cab at: <%1> with error: %2.

Fields

NameDescription
1
2

References

Event ID 4108 — Successful auto delete of third-party root certificate:: Subject: <OU=Class 3 Public Primary Certification Authority, O="VeriSign, Inc.

Provider
Microsoft-Windows-CAPI2
Channel
Application
Level
4
Samples
1

Message

Successful auto delete of third-party root certificate:: Subject: <%1> Sha1 thumbprint: <%2>.

Fields

NameDescription
Data

Example Event

system:
  provider: Microsoft-Windows-CAPI2
  guid: '{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}'
  event_source_name: Microsoft-Windows-CAPI2
  event_id: 4108
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 9259400833873739776
  time_created: '2022-04-07T17:04:18.250448+00:00'
  event_record_id: 217
  correlation: {}
  execution:
    process_id: 2432
    thread_id: 2344
  channel: Application
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: ''
event_data:
  Data:
  - OU=Class 3 Public Primary Certification Authority, O="VeriSign, Inc.", C=US
  - 4F65566336DB6598581D584A596C87934D5F2AB4
message: 'Successful auto delete of third-party root certificate:: Subject: <OU=Class
  3 Public Primary Certification Authority, O="VeriSign, Inc.", C=US> Sha1 thumbprint:
  <4F65566336DB6598581D584A596C87934D5F2AB4>.'

References

Event ID 4109 — Successful auto property update of third-party root certificate:: Subject: <OU=Class 3 Public Primary Certification Authority, O="VeriSign, Inc.

Provider
Microsoft-Windows-CAPI2
Channel
Application
Level
4
Samples
1

Message

Successful auto property update of third-party root certificate:: Subject: <%1> Sha1 thumbprint: <%2>.

Fields

NameDescription
Data

Example Event

system:
  provider: Microsoft-Windows-CAPI2
  guid: '{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}'
  event_source_name: Microsoft-Windows-CAPI2
  event_id: 4109
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 9259400833873739776
  time_created: '2022-04-07T17:04:18.250448+00:00'
  event_record_id: 216
  correlation: {}
  execution:
    process_id: 2432
    thread_id: 2344
  channel: Application
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: ''
event_data:
  Data:
  - OU=Class 3 Public Primary Certification Authority, O="VeriSign, Inc.", C=US
  - 742C3192E607E424EB4549542BE1BBC53E6174E2
message: 'Successful auto property update of third-party root certificate:: Subject:
  <OU=Class 3 Public Primary Certification Authority, O="VeriSign, Inc.", C=US> Sha1
  thumbprint: <742C3192E607E424EB4549542BE1BBC53E6174E2>.'

References

Event ID 4110 — Failed to add certificate to Third-Party Root Certification Authorities store with error.

Provider
Microsoft-Windows-CAPI2
Channel
Application

Message

Failed to add certificate to Third-Party Root Certification Authorities store with error: %2

Fields

NameDescription
1
2

Event ID 4111 — Successful auto update of third-party root list with effective date: ‎Tuesday, ‎February ‎22, ‎2022 11:44:40 AM.

Provider
Microsoft-Windows-CAPI2
Channel
Application
Level
4
Samples
1

Message

Successful auto update of third-party root list with effective date: %1.

Fields

NameDescription
DataSuccessful auto update of third-party root list with effective date.

Example Event

system:
  provider: Microsoft-Windows-CAPI2
  guid: '{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}'
  event_source_name: Microsoft-Windows-CAPI2
  event_id: 4111
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 9259400833873739776
  time_created: '2022-04-07T17:04:18.250448+00:00'
  event_record_id: 218
  correlation: {}
  execution:
    process_id: 2432
    thread_id: 2344
  channel: Application
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: ''
event_data:
  Data:
  - ‎Tuesday, ‎February ‎22, ‎2022 11:44:40 AM
message: 'Successful auto update of third-party root list with effective date: ‎Tuesday,
  ‎February ‎22, ‎2022 11:44:40 AM.'

References

Event ID 4112 — Successful auto update of disallowed certificate list with effective date: ‎Tuesday, ‎March ‎16, ‎2021 12:29:24 AM.

Provider
Microsoft-Windows-CAPI2
Channel
Application
Level
4
Samples
1

Message

Successful auto update of disallowed certificate list with effective date: %1.

Fields

NameDescription
DataSuccessful auto update of disallowed certificate list with effective date.

Example Event

system:
  provider: Microsoft-Windows-CAPI2
  guid: '{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}'
  event_source_name: Microsoft-Windows-CAPI2
  event_id: 4112
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 9259400833873739776
  time_created: '2022-04-07T08:11:02.801955+00:00'
  event_record_id: 49
  correlation: {}
  execution:
    process_id: 2436
    thread_id: 4712
  channel: Application
  computer: WIN-FPV0DSIC9O6
  security:
    user_id: ''
event_data:
  Data:
  - ‎Tuesday, ‎March ‎16, ‎2021 12:29:24 AM
message: 'Successful auto update of disallowed certificate list with effective date:
  ‎Tuesday, ‎March ‎16, ‎2021 12:29:24 AM.'

References

Event ID 4113 — Successful auto update of pin rules with effective date: ‎Wednesday, ‎May ‎31, ‎2017 4:28:59 PM.

Provider
Microsoft-Windows-CAPI2
Channel
Application
Level
4
Samples
1

Message

Successful auto update of pin rules with effective date: %1.

Fields

NameDescription
DataSuccessful auto update of pin rules with effective date.

Example Event

system:
  provider: Microsoft-Windows-CAPI2
  guid: '{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}'
  event_source_name: Microsoft-Windows-CAPI2
  event_id: 4113
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 9259400833873739776
  time_created: '2022-04-07T08:12:04.333773+00:00'
  event_record_id: 82
  correlation: {}
  execution:
    process_id: 2436
    thread_id: 5476
  channel: Application
  computer: WIN-FPV0DSIC9O6
  security:
    user_id: ''
event_data:
  Data:
  - ‎Wednesday, ‎May ‎31, ‎2017 4:28:59 PM
message: 'Successful auto update of pin rules with effective date: ‎Wednesday, ‎May
  ‎31, ‎2017 4:28:59 PM.'

References

Event ID 4114 — Server: %1 has unexpected certificates under trusted authority: <%2> with thumbprint: %3.

Provider
Microsoft-Windows-CAPI2
Channel
Application

Message

Server: %1 has unexpected certificates under trusted authority: <%2> with thumbprint: %3.

Mismatch of pin rules for domain: %4 with effective date: %5 and sequence number: %6.

Certificates saved to: <%7>.

Fields

NameDescription
1
2
3
4
5
6
7

Event ID 4115 — Added public key pinning rule for domain: %1 with header thumbprint: %2.

Provider
Microsoft-Windows-CAPI2
Channel
Application

Message

Added public key pinning rule for domain: %1 with header thumbprint: %2.

Header value: %3.

Fields

NameDescription
1
2
3

Event ID 4116 — Server: %1 has unexpected certificates under trusted authority: <%2> with thumbprint: %3.

Provider
Microsoft-Windows-CAPI2
Channel
Application

Message

Server: %1 has unexpected certificates under trusted authority: <%2> with thumbprint: %3.

Mismatch of public key pinning rule for domain: %4 added on date: %5 with header thumbprint: %6.

Certificates saved to: <%7>.

Fields

NameDescription
1
2
3
4
5
6
7

Event ID 4117 — Server: %1 has unexpected certificates under trusted authority: <%2> with thumbprint: %3.

Provider
Microsoft-Windows-CAPI2
Channel
Application

Message

Server: %1 has unexpected certificates under trusted authority: <%2> with thumbprint: %3.

Mismatch of public key pinning rule for domain: %4 added on date: %5 with header thumbprint: %6.

Certificates saved to: <%7>.

However, also matched domain: %8 added on date: %9 with header thumbprint: %10.

Fields

NameDescription
1
2
3
4
5
6
7
8
9
10

Event ID 4128 — Successful pre-fetch of certificate revocation list from: <.

Provider
Microsoft-Windows-CAPI2
Channel
Application

Message

Successful pre-fetch of certificate revocation list from: <%1>.

Fields

NameDescription
1

Event ID 4129 — Failed pre-fetch of certificate revocation list from: <.

Provider
Microsoft-Windows-CAPI2
Channel
Application

Message

Failed pre-fetch of certificate revocation list from: <%1> with error: %2.

Fields

NameDescription
1
2

Event ID 4130 — Certificate signature verify failed.

Provider
Microsoft-Windows-CAPI2
Channel
Application

Message

Certificate signature verify failed. Detected public key parameter poisoning. 

Additional Information: %1.

Fields

NameDescription
1
2

Event ID 4131 — LDAP CryptRetrieveObjectByUrlW failed.

Provider
Microsoft-Windows-CAPI2
Channel
Application

Message

LDAP CryptRetrieveObjectByUrlW failed. Detected URL with control characters. 

Additional Information: %1. 

Error Code: %2.

Fields

NameDescription
1
2

Event ID 4176 — PFX operation failed as AuthSafes count doesn't lie in expected range.

Provider
Microsoft-Windows-CAPI2
Channel
Application

Message

PFX operation failed as AuthSafes count doesn't lie in expected range. Maximum permissible value: %1. Erroneous value: %2.

Fields

NameDescription
1
2

Event ID 4177 — PFX operation failed as Iteration count doesn't lie in expected range.

Provider
Microsoft-Windows-CAPI2
Channel
Application

Message

PFX operation failed as Iteration count doesn't lie in expected range. Maximum permissible value: %1. Erroneous value: %2.

Fields

NameDescription
1
2

Event ID 4178 — PFX operation failed as SafeBags count doesn't lie in expected range.

Provider
Microsoft-Windows-CAPI2
Channel
Application

Message

PFX operation failed as SafeBags count doesn't lie in expected range. Maximum permissible value: %1. Erroneous value: %2.

Fields

NameDescription
1
2

Event ID 8192 — The catalog file %2 is being added to subsystem %1.

Provider
Microsoft-Windows-CAPI2
Channel
Catalog Database Debug

Message

The catalog file %2 is being added to subsystem %1.

Fields

NameDescription
Subsystem
FileName

Event ID 8193 — Addition of the catalog file completed.

Provider
Microsoft-Windows-CAPI2
Channel
Catalog Database Debug

Message

Addition of the catalog file completed. Status %1.

Fields

NameDescription
Status

Event ID 8194 — The catalog file %2 is being removed from the subsystem %1.

Provider
Microsoft-Windows-CAPI2
Channel
Catalog Database Debug

Message

The catalog file %2 is being removed from the subsystem %1.

Fields

NameDescription
Subsystem
FileName

Event ID 8195 — Removal of the catalog file completed.

Provider
Microsoft-Windows-CAPI2
Channel
Catalog Database Debug

Message

Removal of the catalog file completed. Status %1.

Fields

NameDescription
Status

Event ID 8196 — The catalog file %2 is being synced to the subsystem %1.

Provider
Microsoft-Windows-CAPI2
Channel
Catalog Database Debug

Message

The catalog file %2 is being synced to the subsystem %1.

Fields

NameDescription
Subsystem
FileName

Event ID 8197 — Sync of the catalog file completed.

Provider
Microsoft-Windows-CAPI2
Channel
Catalog Database Debug

Message

Sync of the catalog file completed. Status %1.

Fields

NameDescription
Status

Event ID 8198 — The Catalog Database is being rebuilt for subsystem %1.

Provider
Microsoft-Windows-CAPI2
Channel
Catalog Database Debug

Message

The Catalog Database is being rebuilt for subsystem %1.

Fields

NameDescription
Subsystem

Event ID 8199 — Rebuild of the Catalog Database for the chosen subsystem has completed.

Provider
Microsoft-Windows-CAPI2
Channel
Catalog Database Debug

Message

Rebuild of the Catalog Database for the chosen subsystem has completed. Status %1.

Fields

NameDescription
Status

Event ID 8200 — A hash of type %2, length %3 and value %4 is being searched for in subsystem %1.

Provider
Microsoft-Windows-CAPI2
Channel
Catalog Database Debug

Message

A hash of type %2, length %3 and value %4 is being searched for in subsystem %1.

Fields

NameDescription
Subsystem
Algorithm
Length
Value

Event ID 8201 — The hash search completed and was found in %2 catalogs.

Provider
Microsoft-Windows-CAPI2
Channel
Catalog Database Debug

Message

The hash search completed and was found in %2 catalogs. Status %1.

Fields

NameDescription
Status
Count

Event ID 8202 — Sync of subsystem %1 has started.

Provider
Microsoft-Windows-CAPI2
Channel
Catalog Database Debug

Message

Sync of subsystem %1 has started.

Fields

NameDescription
Subsystem

Event ID 8203 — Sync of the subsystem completed.

Provider
Microsoft-Windows-CAPI2
Channel
Catalog Database Debug

Message

Sync of the subsystem completed. Status %1.

Fields

NameDescription
Status