Microsoft-Windows-LUA
45 events across 2 channels
| Event ID | Title | Channel |
|---|---|---|
| 15001 | Diagnostic | |
| 15002 | Diagnostic | |
| 15003 | Diagnostic | |
| 15004 | Diagnostic | |
| 15005 | Diagnostic | |
| 15006 | Diagnostic | |
| 15007 | Diagnostic | |
| 15008 | Diagnostic | |
| 15009 | Diagnostic | |
| 15010 | Diagnostic | |
| 15011 | Diagnostic | |
| 15012 | Diagnostic | |
| 15013 | Diagnostic | |
| 15014 | Diagnostic | |
| 15015 | Diagnostic | |
| 15016 | Diagnostic | |
| 15017 | Diagnostic | |
| 15018 | Diagnostic | |
| 15019 | Diagnostic | |
| 15020 | Diagnostic | |
| 15021 | Diagnostic | |
| 15022 | Diagnostic | |
| 15023 | Diagnostic | |
| 15024 | Diagnostic | |
| 15025 | Diagnostic | |
| 15026 | Diagnostic | |
| 15027 | Diagnostic | |
| 15028 | Diagnostic | |
| 15029 | Diagnostic | |
| 15030 | Diagnostic | |
| 15031 | Diagnostic | |
| 15031 | Success: Elevation prompt for executable FullCommandLine (ProgramName published … | Elevation |
| 15032 | Diagnostic | |
| 15032 | Elevation prompt for executable FullCommandLine (ProgramName published by … | Elevation |
| 16001 | Diagnostic | |
| 16002 | Diagnostic | |
| 16003 | Diagnostic | |
| 16004 | Diagnostic | |
| 16005 | Diagnostic | |
| 16006 | Diagnostic | |
| 16007 | Diagnostic | |
| 16008 | Diagnostic | |
| 16009 | Diagnostic | |
| 16010 | Diagnostic | |
| 16011 | Diagnostic |
Event ID 15001 —
Event ID 15002 —
Event ID 15003 —
Event ID 15004 —
Event ID 15005 —
Event ID 15006 —
Event ID 15007 —
Event ID 15008 —
Event ID 15009 —
Event ID 15010 —
Event ID 15011 —
Event ID 15012 —
Event ID 15013 —
Event ID 15014 —
Event ID 15015 —
Event ID 15016 —
Event ID 15017 —
Event ID 15018 —
Event ID 15019 —
Event ID 15020 —
Event ID 15021 —
Event ID 15022 —
Event ID 15023 —
Event ID 15024 —
Event ID 15025 —
Event ID 15026 —
Event ID 15027 —
Event ID 15028 —
Fields #
| Name | Description |
|---|---|
Parameters Pointer | — |
Event ID 15029 —
Event ID 15030 —
Event ID 15031 —
Description
Success: Elevation prompt for executable ( published by ) answered by , will elevate as .
Fields #
| Name | Description |
|---|---|
ProgramName UnicodeString | — |
Publisher UnicodeString | — |
FullCommandLine UnicodeString | — |
UserName UnicodeString | — |
ShadowAdmin UnicodeString | — |
ShadowAdminSID UnicodeString | — |
ReturnCode UInt32 | — |
ReturnMessage UnicodeString | — |
Event ID 15031 — Success: Elevation prompt for executable FullCommandLine (ProgramName published by Publisher) answered by UserName, will elevate as ShadowAdmin.
Description
Success: Elevation prompt for executable FullCommandLine (ProgramName published by Publisher) answered by UserName, will elevate as ShadowAdmin.
Message #
Fields #
| Name | Description |
|---|---|
ProgramName UnicodeString | — |
Publisher UnicodeString | — |
FullCommandLine UnicodeString | — |
UserName UnicodeString | — |
ShadowAdmin UnicodeString | — |
ShadowAdminSID UnicodeString | — |
ReturnCode UInt32 | — |
ReturnMessage UnicodeString | — |
Event ID 15032 —
Description
Elevation prompt for executable ( published by ) answered by . Error : .
Fields #
| Name | Description |
|---|---|
ProgramName UnicodeString | — |
Publisher UnicodeString | — |
FullCommandLine UnicodeString | — |
UserName UnicodeString | — |
ShadowAdmin UnicodeString | — |
ShadowAdminSID UnicodeString | — |
ReturnCode UInt32 | — |
ReturnMessage UnicodeString | — |
Event ID 15032 — Elevation prompt for executable FullCommandLine (ProgramName published by Publisher) answered by UserName.
Description
Elevation prompt for executable FullCommandLine (ProgramName published by Publisher) answered by UserName. Error ReturnCode: ReturnMessage.
Message #
Fields #
| Name | Description |
|---|---|
ProgramName UnicodeString | — |
Publisher UnicodeString | — |
FullCommandLine UnicodeString | — |
UserName UnicodeString | — |
ShadowAdmin UnicodeString | — |
ShadowAdminSID UnicodeString | — |
ReturnCode UInt32 | — |
ReturnMessage UnicodeString | — |
Event ID 16001 —
Fields #
| Name | Description |
|---|---|
EventId UInt32 | — |
UACElevateFileID UnicodeString | — |
Event ID 16002 —
Fields #
| Name | Description |
|---|---|
EventId UInt32 | — |
UACElevateFileID UnicodeString | — |
Event ID 16003 —
Fields #
| Name | Description |
|---|---|
EventId UInt32 | — |
UACElevateFileID UnicodeString | — |
Event ID 16004 —
Fields #
| Name | Description |
|---|---|
EventId UInt32 | — |
UACElevateFileID UnicodeString | — |
Event ID 16005 —
Fields #
| Name | Description |
|---|---|
EventId UInt32 | — |
UACElevateFileID UnicodeString | — |
Event ID 16006 —
Fields #
| Name | Description |
|---|---|
EventId UInt32 | — |
UACElevateFileID UnicodeString | — |
Event ID 16007 —
Fields #
| Name | Description |
|---|---|
EventId UInt32 | — |
UACElevateFileID UnicodeString | — |
Event ID 16008 —
Fields #
| Name | Description |
|---|---|
EventId UInt32 | — |
UACElevateFileID UnicodeString | — |
Event ID 16009 —
Fields #
| Name | Description |
|---|---|
EventId UInt32 | — |
UACElevateFileID UnicodeString | — |
Event ID 16010 —
Fields #
| Name | Description |
|---|---|
EventId UInt32 | — |
UACElevateFileID UnicodeString | — |
Event ID 16011 —
Fields #
| Name | Description |
|---|---|
EventId UInt32 | — |
UACElevateFileID UnicodeString | — |