// REFERENCE

4673 — Sensitive privilege use

Log: Security Medium risk

A sensitive privilege was exercised (e.g. SeDebugPrivilege, SeBackupPrivilege). Abuse of SeDebugPrivilege often precedes LSASS credential dumping; it is noisy, so filter by privilege and process.

Related tools

Work with this in:

Related

Original descriptions based on Microsoft's public documentation. IDs and fields may vary with the Windows version and the active audit policy.