Event ID 4693 — Recovery of data protection master key was attempted.
Description
Recovery of data protection master key was attempted.
Message #
Fields #
| Name | Description |
|---|---|
Security_ID SID | [Subject] Security ID. |
Account_Name UnicodeString | [Subject] Account Name. |
Account_Domain UnicodeString | [Subject] Account Domain. |
Logon_ID HexInt64 | [Subject] Logon ID. |
Key_Identifier UnicodeString | [Key Information] Key Identifier. |
Recovery_Server HexInt32 | [Key Information] Recovery Server. |
Recovery_Reason UnicodeString | [Key Information] Recovery Reason. |
Recovery_Key_ID UnicodeString | [Key Information] Recovery Key ID. |
Status_Code HexInt32 | [Status Information] Status Code. |
SubjectUserSid SID | [Subject] Security ID |
SubjectUserName UnicodeString | [Subject] Account Name |
SubjectDomainName UnicodeString | [Subject] Account Domain |
SubjectLogonId HexInt64 | [Subject] Logon ID |
MasterKeyId UnicodeString | [Key Information] Key Identifier |
RecoveryReason HexInt32 | [Key Information] Recovery Server |
RecoveryServer UnicodeString | [Key Information] Recovery Reason |
RecoveryKeyId UnicodeString | [Key Information] Recovery Key ID |
FailureId HexInt32 | [Status Information] Status Code |
Community Notes #
May appear when an attacker re-uses offline profiles or moves tokens between hosts. Correlate with LogonType 7/9 in 4624. Detecting Credential Stealing Attacks Through Active In-Network Defense
References #
- Microsoft Learn https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4693
- Microsoft Learn Audit Policy https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-dpapi-activity
- Ultimate Windows Security https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4693