Event ID 4673: Privileged service called
- Event ID
- 4673
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Processes
- Default logging
- Needs configuration
What event 4673 means
Event 4673 is written when a process calls a privileged system service that requires a specific privilege — for example LsaRegisterLogonProcess() with SeTcbPrivilege. Success records show the privilege was held and used; Failure records show the caller tried without holding it.
The Service and PrivilegeList fields are the heart of the event, together with ProcessName. Most records come from well-known system processes and are routine; the interesting ones are unusual processes, user-writable paths, or failures from processes that should not be asking.
The subcategory is noisy on busy systems, so it is often left disabled or filtered at collection. When enabled, baseline the ProcessName / Service combinations first and alert on new ones.
When it is logged
Advanced Audit Policy Configuration > Privilege Use > Audit Sensitive Privilege Use (Success and/or Failure). Audit Non Sensitive Privilege Use also generates it for non-sensitive privileges.
High volume on servers and workstations. Failure auditing alone is a cheaper way to catch processes attempting privileged calls they are not entitled to.
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserName | Account whose token was used for the call. |
| SubjectLogonId | Logon session; pivot to 4624 and 4688. |
| ObjectServer | Subsystem that handled the call, e.g. NT Local Security Authority / Authentication Service or Security. |
| Service | Privileged service or function called, e.g. LsaRegisterLogonProcess(). May be - when not supplied. |
| PrivilegeList | Privilege(s) required for the call, e.g. SeTcbPrivilege, SeSystemtimePrivilege, SeCreateGlobalPrivilege. |
| ProcessName | Process that made the call. Evaluate this against the privilege requested. |
| ProcessId | Hexadecimal PID of that process. |
Common benign sources
- System processes such as
lsass.exe,services.exeandsvchost.exeusing privileges during normal operation. - Security and backup agents registering with LSA or using privileged services.
- Time synchronization and system management tools using
SeSystemtimePrivilegeand similar rights.
What attackers do that produces it
- Offensive tools running from a user or temp folder calling
LsaRegisterLogonProcess()to interact with authentication packages, for example to manipulate Kerberos tickets. - Failure records showing a non-privileged process repeatedly trying to use
SeTcbPrivilegeorSeDebugPrivilege-protected services.
Investigation tips
- Build a baseline of
ProcessName+Service+PrivilegeList; triage new combinations. - Check the process path and signature, then pivot
SubjectLogonIdto 4688 for the command line. - Correlate with 4672 (special privileges at logon) and 4703 (privileges enabled in the token).
Sigma rules for this event
2 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- Medium · 1
- HighUser Couldn't Call a Privileged Service 'LsaRegisterLogonProcess'Rule by Roberto Rodriguez (source), Ilyas Ochkov (rule), oscd.community, SigmaHQ, DRL 1.1
- MediumPotential Privileged System Service Operation - SeLoadDriverPrivilegeRule by xknow (@xknow_infosec), xorxes (@xor_xes), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.