// REFERENCE
4673 — Sensitive privilege use
Log: Security
Medium risk
A sensitive privilege was exercised (e.g. SeDebugPrivilege, SeBackupPrivilege). Abuse of SeDebugPrivilege often precedes LSASS credential dumping; it is noisy, so filter by privilege and process.
Related tools
Work with this in:
Related
4672
4672 — Special privileges assigned to new logon 4688
4688 — A new process was created 4689
4689 — A process has exited
4672 — Special privileges assigned to new logon 4688
4688 — A new process was created 4689
4689 — A process has exited
Original descriptions based on Microsoft's public documentation. IDs and fields may vary with the Windows version and the active audit policy.