Microsoft-Windows-Security-Auditing › Event 4675

Event ID 4675 — SIDs were filtered.

Provider
Microsoft-Windows-Security-Auditing
Channel
Security
Audit Policy
Logon/Logoff → Logon
Collection Priority
Recommended (Palantir, others)
Opcode
Info

Description

SIDs were filtered.

Message #

SIDs were filtered.

Target Account:
	Security ID: %1
	Account Name: %2
	Account Domain: %3

Trust Information:
	Trust Direction: %4
	Trust Attributes: %5
	Trust Type: %6
	TDO Domain SID: %7

Filtered SIDs: %8

Fields #

NameDescription
Security_ID SID[Target Account] Security ID.
Account_Name UnicodeString[Target Account] Account Name.
Account_Domain UnicodeString[Target Account] Account Domain.
Trust_Direction UInt32[Trust Information] Trust Direction.
Trust_Attributes UInt32[Trust Information] Trust Attributes.
Trust_Type UInt32[Trust Information] Trust Type.
TDO_Domain_SID SID[Trust Information] TDO Domain SID.
Filtered_SIDs UnicodeString[Trust Information] Filtered SIDs.
TargetUserSid SID[Target Account] Security ID
TargetUserName UnicodeString[Target Account] Account Name
TargetDomainName UnicodeString[Target Account] Account Domain
TdoDirection UInt32[Trust Information] Trust Direction
TdoAttributes UInt32[Trust Information] Trust Attributes
TdoType UInt32[Trust Information] Trust Type
TdoSid SID[Trust Information] TDO Domain SID
SidList UnicodeStringFiltered SIDs

Detection Patterns #

References #