Microsoft-Windows-Threat-Intelligence

34 events across 1 channel

Event IDTitleChannel
1Analytic
2Analytic
3Analytic
4Analytic
5Analytic
6Analytic
7Analytic
8Analytic
11Analytic
12Analytic
13Analytic
14Analytic
15Analytic
16Analytic
17Analytic
18Analytic
19Analytic
20Analytic
21Analytic
22Analytic
23Analytic
24Analytic
25Analytic
26Analytic
27Analytic
28Analytic
29Analytic
30Analytic
31Analytic
32Analytic
33Analytic
34Analytic
35Analytic
36Analytic

Event ID 1 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
CallingProcessId
CallingProcessCreateTime
CallingProcessStartKey
CallingProcessSignatureLevel
CallingProcessSectionSignatureLevel
CallingProcessProtection
CallingThreadId
CallingThreadCreateTime
TargetProcessId
TargetProcessCreateTime
TargetProcessStartKey
TargetProcessSignatureLevel
TargetProcessSectionSignatureLevel
TargetProcessProtection
OriginalProcessId
OriginalProcessCreateTime
OriginalProcessStartKey
OriginalProcessSignatureLevel
OriginalProcessSectionSignatureLevel
OriginalProcessProtection
BaseAddress
RegionSize
AllocationType
ProtectionMask

Event ID 2 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
CallingProcessId
CallingProcessCreateTime
CallingProcessStartKey
CallingProcessSignatureLevel
CallingProcessSectionSignatureLevel
CallingProcessProtection
CallingThreadId
CallingThreadCreateTime
TargetProcessId
TargetProcessCreateTime
TargetProcessStartKey
TargetProcessSignatureLevel
TargetProcessSectionSignatureLevel
TargetProcessProtection
OriginalProcessId
OriginalProcessCreateTime
OriginalProcessStartKey
OriginalProcessSignatureLevel
OriginalProcessSectionSignatureLevel
OriginalProcessProtection
BaseAddress
RegionSize
ProtectionMask
LastProtectionMask
VaVadQueryResult
VaVadAllocationBase
VaVadAllocationProtect
VaVadRegionType
VaVadRegionSize
VaVadCommitSize
VaVadMmfName
TargetAddress
FullRegionSize

Event ID 3 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
CallingProcessId
CallingProcessCreateTime
CallingProcessStartKey
CallingProcessSignatureLevel
CallingProcessSectionSignatureLevel
CallingProcessProtection
CallingThreadId
CallingThreadCreateTime
TargetProcessId
TargetProcessCreateTime
TargetProcessStartKey
TargetProcessSignatureLevel
TargetProcessSectionSignatureLevel
TargetProcessProtection
BaseAddress
ViewSize
AllocationType
ProtectionMask

Event ID 4 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
CallingProcessId
CallingProcessCreateTime
CallingProcessStartKey
CallingProcessSignatureLevel
CallingProcessSectionSignatureLevel
CallingProcessProtection
CallingThreadId
CallingThreadCreateTime
TargetProcessId
TargetProcessCreateTime
TargetProcessStartKey
TargetProcessSignatureLevel
TargetProcessSectionSignatureLevel
TargetProcessProtection
TargetThreadId
TargetThreadCreateTime
OriginalProcessId
OriginalProcessCreateTime
OriginalProcessStartKey
OriginalProcessSignatureLevel
OriginalProcessSectionSignatureLevel
OriginalProcessProtection
TargetThreadAlertable
ApcRoutine
ApcArgument1
ApcArgument2
ApcArgument3
RealEventTime
ApcRoutineVadQueryResult
ApcRoutineVadAllocationBase
ApcRoutineVadAllocationProtect
ApcRoutineVadRegionType
ApcRoutineVadRegionSize
ApcRoutineVadCommitSize
ApcRoutineVadMmfName
ApcArgument1VadQueryResult
ApcArgument1VadAllocationBase
ApcArgument1VadAllocationProtect
ApcArgument1VadRegionType
ApcArgument1VadRegionSize
ApcArgument1VadCommitSize
ApcArgument1VadMmfName

Event ID 5 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
CallingProcessId
CallingProcessCreateTime
CallingProcessStartKey
CallingProcessSignatureLevel
CallingProcessSectionSignatureLevel
CallingProcessProtection
CallingThreadId
CallingThreadCreateTime
TargetProcessId
TargetProcessCreateTime
TargetProcessStartKey
TargetProcessSignatureLevel
TargetProcessSectionSignatureLevel
TargetProcessProtection
TargetThreadId
TargetThreadCreateTime
ContextFlags
ContextMask
Pc
Sp
Lr
Fp
Reg0
Reg1
Reg2
Reg3
Reg4
Reg5
Reg6
Reg7
RealEventTime
PcVadQueryResult
PcVadAllocationBase
PcVadAllocationProtect
PcVadRegionType
PcVadRegionSize
PcVadCommitSize
PcVadMmfName

Event ID 6 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
CallingProcessId
CallingProcessCreateTime
CallingProcessStartKey
CallingProcessSignatureLevel
CallingProcessSectionSignatureLevel
CallingProcessProtection
CallingThreadId
CallingThreadCreateTime
TargetProcessId
TargetProcessCreateTime
TargetProcessStartKey
TargetProcessSignatureLevel
TargetProcessSectionSignatureLevel
TargetProcessProtection
OriginalProcessId
OriginalProcessCreateTime
OriginalProcessStartKey
OriginalProcessSignatureLevel
OriginalProcessSectionSignatureLevel
OriginalProcessProtection
BaseAddress
RegionSize
AllocationType
ProtectionMask

Event ID 7 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
CallingProcessId
CallingProcessCreateTime
CallingProcessStartKey
CallingProcessSignatureLevel
CallingProcessSectionSignatureLevel
CallingProcessProtection
CallingThreadId
CallingThreadCreateTime
TargetProcessId
TargetProcessCreateTime
TargetProcessStartKey
TargetProcessSignatureLevel
TargetProcessSectionSignatureLevel
TargetProcessProtection
OriginalProcessId
OriginalProcessCreateTime
OriginalProcessStartKey
OriginalProcessSignatureLevel
OriginalProcessSectionSignatureLevel
OriginalProcessProtection
BaseAddress
RegionSize
ProtectionMask
LastProtectionMask
VaVadQueryResult
VaVadAllocationBase
VaVadAllocationProtect
VaVadRegionType
VaVadRegionSize
VaVadCommitSize
VaVadMmfName
TargetAddress
FullRegionSize

Event ID 8 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
CallingProcessId
CallingProcessCreateTime
CallingProcessStartKey
CallingProcessSignatureLevel
CallingProcessSectionSignatureLevel
CallingProcessProtection
CallingThreadId
CallingThreadCreateTime
TargetProcessId
TargetProcessCreateTime
TargetProcessStartKey
TargetProcessSignatureLevel
TargetProcessSectionSignatureLevel
TargetProcessProtection
BaseAddress
ViewSize
AllocationType
ProtectionMask

Event ID 11 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
OperationStatus
CallingProcessId
CallingProcessCreateTime
CallingProcessStartKey
CallingProcessSignatureLevel
CallingProcessSectionSignatureLevel
CallingProcessProtection
CallingThreadId
CallingThreadCreateTime
TargetProcessId
TargetProcessCreateTime
TargetProcessStartKey
TargetProcessSignatureLevel
TargetProcessSectionSignatureLevel
TargetProcessProtection
BaseAddress
BytesCopied
VaVadQueryResult
VaVadAllocationBase
VaVadAllocationProtect
VaVadRegionType
VaVadRegionSize
VaVadCommitSize
VaVadMmfName

Event ID 12 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
OperationStatus
CallingProcessId
CallingProcessCreateTime
CallingProcessStartKey
CallingProcessSignatureLevel
CallingProcessSectionSignatureLevel
CallingProcessProtection
CallingThreadId
CallingThreadCreateTime
TargetProcessId
TargetProcessCreateTime
TargetProcessStartKey
TargetProcessSignatureLevel
TargetProcessSectionSignatureLevel
TargetProcessProtection
BaseAddress
BytesCopied
VaVadQueryResult
VaVadAllocationBase
VaVadAllocationProtect
VaVadRegionType
VaVadRegionSize
VaVadCommitSize
VaVadMmfName

Event ID 13 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
OperationStatus
CallingProcessId
CallingProcessCreateTime
CallingProcessStartKey
CallingProcessSignatureLevel
CallingProcessSectionSignatureLevel
CallingProcessProtection
CallingThreadId
CallingThreadCreateTime
TargetProcessId
TargetProcessCreateTime
TargetProcessStartKey
TargetProcessSignatureLevel
TargetProcessSectionSignatureLevel
TargetProcessProtection
BaseAddress
BytesCopied
VaVadQueryResult
VaVadAllocationBase
VaVadAllocationProtect
VaVadRegionType
VaVadRegionSize
VaVadCommitSize
VaVadMmfName

Event ID 14 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
OperationStatus
CallingProcessId
CallingProcessCreateTime
CallingProcessStartKey
CallingProcessSignatureLevel
CallingProcessSectionSignatureLevel
CallingProcessProtection
CallingThreadId
CallingThreadCreateTime
TargetProcessId
TargetProcessCreateTime
TargetProcessStartKey
TargetProcessSignatureLevel
TargetProcessSectionSignatureLevel
TargetProcessProtection
BaseAddress
BytesCopied
VaVadQueryResult
VaVadAllocationBase
VaVadAllocationProtect
VaVadRegionType
VaVadRegionSize
VaVadCommitSize
VaVadMmfName

Event ID 15 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
OperationStatus
CallingProcessId
CallingProcessCreateTime
CallingProcessStartKey
CallingProcessSignatureLevel
CallingProcessSectionSignatureLevel
CallingProcessProtection
CallingThreadId
CallingThreadCreateTime
TargetProcessId
TargetProcessCreateTime
TargetProcessStartKey
TargetProcessSignatureLevel
TargetProcessSectionSignatureLevel
TargetProcessProtection
TargetThreadId
TargetThreadCreateTime

Event ID 16 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
OperationStatus
CallingProcessId
CallingProcessCreateTime
CallingProcessStartKey
CallingProcessSignatureLevel
CallingProcessSectionSignatureLevel
CallingProcessProtection
CallingThreadId
CallingThreadCreateTime
TargetProcessId
TargetProcessCreateTime
TargetProcessStartKey
TargetProcessSignatureLevel
TargetProcessSectionSignatureLevel
TargetProcessProtection
TargetThreadId
TargetThreadCreateTime

Event ID 17 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
OperationStatus
CallingProcessId
CallingProcessCreateTime
CallingProcessStartKey
CallingProcessSignatureLevel
CallingProcessSectionSignatureLevel
CallingProcessProtection
CallingThreadId
CallingThreadCreateTime
TargetProcessId
TargetProcessCreateTime
TargetProcessStartKey
TargetProcessSignatureLevel
TargetProcessSectionSignatureLevel
TargetProcessProtection

Event ID 18 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
OperationStatus
CallingProcessId
CallingProcessCreateTime
CallingProcessStartKey
CallingProcessSignatureLevel
CallingProcessSectionSignatureLevel
CallingProcessProtection
CallingThreadId
CallingThreadCreateTime
TargetProcessId
TargetProcessCreateTime
TargetProcessStartKey
TargetProcessSignatureLevel
TargetProcessSectionSignatureLevel
TargetProcessProtection

Event ID 19 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
OperationStatus
CallingProcessId
CallingProcessCreateTime
CallingProcessStartKey
CallingProcessSignatureLevel
CallingProcessSectionSignatureLevel
CallingProcessProtection
CallingThreadId
CallingThreadCreateTime
TargetProcessId
TargetProcessCreateTime
TargetProcessStartKey
TargetProcessSignatureLevel
TargetProcessSectionSignatureLevel
TargetProcessProtection

Event ID 20 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
OperationStatus
CallingProcessId
CallingProcessCreateTime
CallingProcessStartKey
CallingProcessSignatureLevel
CallingProcessSectionSignatureLevel
CallingProcessProtection
CallingThreadId
CallingThreadCreateTime
TargetProcessId
TargetProcessCreateTime
TargetProcessStartKey
TargetProcessSignatureLevel
TargetProcessSectionSignatureLevel
TargetProcessProtection

Event ID 21 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
CallingProcessId
CallingProcessCreateTime
CallingProcessStartKey
CallingProcessSignatureLevel
CallingProcessSectionSignatureLevel
CallingProcessProtection
CallingThreadId
CallingThreadCreateTime
TargetProcessId
TargetProcessCreateTime
TargetProcessStartKey
TargetProcessSignatureLevel
TargetProcessSectionSignatureLevel
TargetProcessProtection
OriginalProcessId
OriginalProcessCreateTime
OriginalProcessStartKey
OriginalProcessSignatureLevel
OriginalProcessSectionSignatureLevel
OriginalProcessProtection
BaseAddress
RegionSize
AllocationType
ProtectionMask

Event ID 22 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
CallingProcessId
CallingProcessCreateTime
CallingProcessStartKey
CallingProcessSignatureLevel
CallingProcessSectionSignatureLevel
CallingProcessProtection
CallingThreadId
CallingThreadCreateTime
TargetProcessId
TargetProcessCreateTime
TargetProcessStartKey
TargetProcessSignatureLevel
TargetProcessSectionSignatureLevel
TargetProcessProtection
OriginalProcessId
OriginalProcessCreateTime
OriginalProcessStartKey
OriginalProcessSignatureLevel
OriginalProcessSectionSignatureLevel
OriginalProcessProtection
BaseAddress
RegionSize
ProtectionMask
LastProtectionMask
VaVadQueryResult
VaVadAllocationBase
VaVadAllocationProtect
VaVadRegionType
VaVadRegionSize
VaVadCommitSize
VaVadMmfName
TargetAddress
FullRegionSize

Event ID 23 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
CallingProcessId
CallingProcessCreateTime
CallingProcessStartKey
CallingProcessSignatureLevel
CallingProcessSectionSignatureLevel
CallingProcessProtection
CallingThreadId
CallingThreadCreateTime
TargetProcessId
TargetProcessCreateTime
TargetProcessStartKey
TargetProcessSignatureLevel
TargetProcessSectionSignatureLevel
TargetProcessProtection
BaseAddress
ViewSize
AllocationType
ProtectionMask

Event ID 24 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
CallingProcessId
CallingProcessCreateTime
CallingProcessStartKey
CallingProcessSignatureLevel
CallingProcessSectionSignatureLevel
CallingProcessProtection
CallingThreadId
CallingThreadCreateTime
TargetProcessId
TargetProcessCreateTime
TargetProcessStartKey
TargetProcessSignatureLevel
TargetProcessSectionSignatureLevel
TargetProcessProtection
TargetThreadId
TargetThreadCreateTime
OriginalProcessId
OriginalProcessCreateTime
OriginalProcessStartKey
OriginalProcessSignatureLevel
OriginalProcessSectionSignatureLevel
OriginalProcessProtection
TargetThreadAlertable
ApcRoutine
ApcArgument1
ApcArgument2
ApcArgument3
RealEventTime
ApcRoutineVadQueryResult
ApcRoutineVadAllocationBase
ApcRoutineVadAllocationProtect
ApcRoutineVadRegionType
ApcRoutineVadRegionSize
ApcRoutineVadCommitSize
ApcRoutineVadMmfName
ApcArgument1VadQueryResult
ApcArgument1VadAllocationBase
ApcArgument1VadAllocationProtect
ApcArgument1VadRegionType
ApcArgument1VadRegionSize
ApcArgument1VadCommitSize
ApcArgument1VadMmfName

Event ID 25 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
CallingProcessId
CallingProcessCreateTime
CallingProcessStartKey
CallingProcessSignatureLevel
CallingProcessSectionSignatureLevel
CallingProcessProtection
CallingThreadId
CallingThreadCreateTime
TargetProcessId
TargetProcessCreateTime
TargetProcessStartKey
TargetProcessSignatureLevel
TargetProcessSectionSignatureLevel
TargetProcessProtection
TargetThreadId
TargetThreadCreateTime
ContextFlags
ContextMask
Pc
Sp
Lr
Fp
Reg0
Reg1
Reg2
Reg3
Reg4
Reg5
Reg6
Reg7
RealEventTime
PcVadQueryResult
PcVadAllocationBase
PcVadAllocationProtect
PcVadRegionType
PcVadRegionSize
PcVadCommitSize
PcVadMmfName

Event ID 26 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
CallingProcessId
CallingProcessCreateTime
CallingProcessStartKey
CallingProcessSignatureLevel
CallingProcessSectionSignatureLevel
CallingProcessProtection
CallingThreadId
CallingThreadCreateTime
TargetProcessId
TargetProcessCreateTime
TargetProcessStartKey
TargetProcessSignatureLevel
TargetProcessSectionSignatureLevel
TargetProcessProtection
OriginalProcessId
OriginalProcessCreateTime
OriginalProcessStartKey
OriginalProcessSignatureLevel
OriginalProcessSectionSignatureLevel
OriginalProcessProtection
BaseAddress
RegionSize
AllocationType
ProtectionMask

Event ID 27 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
CallingProcessId
CallingProcessCreateTime
CallingProcessStartKey
CallingProcessSignatureLevel
CallingProcessSectionSignatureLevel
CallingProcessProtection
CallingThreadId
CallingThreadCreateTime
TargetProcessId
TargetProcessCreateTime
TargetProcessStartKey
TargetProcessSignatureLevel
TargetProcessSectionSignatureLevel
TargetProcessProtection
OriginalProcessId
OriginalProcessCreateTime
OriginalProcessStartKey
OriginalProcessSignatureLevel
OriginalProcessSectionSignatureLevel
OriginalProcessProtection
BaseAddress
RegionSize
ProtectionMask
LastProtectionMask
VaVadQueryResult
VaVadAllocationBase
VaVadAllocationProtect
VaVadRegionType
VaVadRegionSize
VaVadCommitSize
VaVadMmfName
TargetAddress
FullRegionSize

Event ID 28 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
CallingProcessId
CallingProcessCreateTime
CallingProcessStartKey
CallingProcessSignatureLevel
CallingProcessSectionSignatureLevel
CallingProcessProtection
CallingThreadId
CallingThreadCreateTime
TargetProcessId
TargetProcessCreateTime
TargetProcessStartKey
TargetProcessSignatureLevel
TargetProcessSectionSignatureLevel
TargetProcessProtection
BaseAddress
ViewSize
AllocationType
ProtectionMask

Event ID 29 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
DriverNameLength
DriverName
CodeIntegrityOption

Event ID 30 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
DriverNameLength
DriverName

Event ID 31 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
DriverNameLength
DriverName
DeviceNameLength
DeviceName

Event ID 32 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
DriverNameLength
DriverName
DeviceNameLength
DeviceName

Event ID 33 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
CallingProcessId
CallingProcessCreateTime
CallingProcessStartKey
CallingProcessSignatureLevel
CallingProcessSectionSignatureLevel
CallingProcessProtection
CallingThreadId
CallingThreadCreateTime
PreviousTokenQueryResult
PreviousTokenType
PreviousTokenElevation
PreviousTokenElevationType
PreviousTokenImpersonationLevel
PreviousTokenUser
PreviousTokenTrustLevelCount
PreviousTokenTrustLevel
PreviousTokenIntegrityLevel
PreviousTokenSessionId
PreviousTokenLowBoxNumber
PreviousTokenAuthenticationId
PreviousTokenGroupsCount
PreviousTokenGroups
CurrentTokenQueryResult
CurrentTokenType
CurrentTokenElevation
CurrentTokenElevationType
CurrentTokenImpersonationLevel
CurrentTokenUser
CurrentTokenTrustLevelCount
CurrentTokenTrustLevel
CurrentTokenIntegrityLevel
CurrentTokenSessionId
CurrentTokenLowBoxNumber
CurrentTokenAuthenticationId
CurrentTokenGroupsCount
CurrentTokenGroups

Event ID 34 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
CallingProcessId
CallingProcessCreateTime
CallingProcessStartKey
CallingProcessSignatureLevel
CallingProcessSectionSignatureLevel
CallingProcessProtection
CallingThreadId
CallingThreadCreateTime

Event ID 35 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
CallingProcessId
CallingProcessCreateTime
CallingProcessStartKey
CallingProcessSignatureLevel
CallingProcessSectionSignatureLevel
CallingProcessProtection
CallingThreadId
CallingThreadCreateTime
SessionId
SyscallEnum
IsSandboxedToken

Event ID 36 —

Provider
Microsoft-Windows-Threat-Intelligence
Channel
Analytic

Fields

NameDescription
CallingProcessId
CallingProcessCreateTime
CallingProcessStartKey
CallingProcessSignatureLevel
CallingProcessSectionSignatureLevel
CallingProcessProtection
CallingThreadId
CallingThreadCreateTime
PreviousTokenQueryResult
PreviousTokenType
PreviousTokenElevation
PreviousTokenElevationType
PreviousTokenImpersonationLevel
PreviousTokenUser
PreviousTokenTrustLevelCount
PreviousTokenTrustLevel
PreviousTokenIntegrityLevel
PreviousTokenSessionId
PreviousTokenLowBoxNumber
PreviousTokenAuthenticationId
PreviousTokenGroupsCount
PreviousTokenGroups
CurrentTokenQueryResult
CurrentTokenType
CurrentTokenElevation
CurrentTokenElevationType
CurrentTokenImpersonationLevel
CurrentTokenUser
CurrentTokenTrustLevelCount
CurrentTokenTrustLevel
CurrentTokenIntegrityLevel
CurrentTokenSessionId
CurrentTokenLowBoxNumber
CurrentTokenAuthenticationId
CurrentTokenGroupsCount
CurrentTokenGroups