Skip to content
Security

Event ID 4673: Privileged service called

A privileged service was calledSecurity event 4673 logs a call to a privileged system service, such as registering a logon process with SeTcbPrivilege, and whether the call succeeded.
4673
Event ID
4673
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Processes
Default logging
Needs configuration

What event 4673 means

Event 4673 is written when a process calls a privileged system service that requires a specific privilege — for example LsaRegisterLogonProcess() with SeTcbPrivilege. Success records show the privilege was held and used; Failure records show the caller tried without holding it.

The Service and PrivilegeList fields are the heart of the event, together with ProcessName. Most records come from well-known system processes and are routine; the interesting ones are unusual processes, user-writable paths, or failures from processes that should not be asking.

The subcategory is noisy on busy systems, so it is often left disabled or filtered at collection. When enabled, baseline the ProcessName / Service combinations first and alert on new ones.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Privilege Use > Audit Sensitive Privilege Use (Success and/or Failure). Audit Non Sensitive Privilege Use also generates it for non-sensitive privileges.

High volume on servers and workstations. Failure auditing alone is a cheaper way to catch processes attempting privileged calls they are not entitled to.

Key fields

FieldWhat it tells you
SubjectUserNameAccount whose token was used for the call.
SubjectLogonIdLogon session; pivot to 4624 and 4688.
ObjectServerSubsystem that handled the call, e.g. NT Local Security Authority / Authentication Service or Security.
ServicePrivileged service or function called, e.g. LsaRegisterLogonProcess(). May be - when not supplied.
PrivilegeListPrivilege(s) required for the call, e.g. SeTcbPrivilege, SeSystemtimePrivilege, SeCreateGlobalPrivilege.
ProcessNameProcess that made the call. Evaluate this against the privilege requested.
ProcessIdHexadecimal PID of that process.

Common benign sources

  • System processes such as lsass.exe, services.exe and svchost.exe using privileges during normal operation.
  • Security and backup agents registering with LSA or using privileged services.
  • Time synchronization and system management tools using SeSystemtimePrivilege and similar rights.

What attackers do that produces it

  • Offensive tools running from a user or temp folder calling LsaRegisterLogonProcess() to interact with authentication packages, for example to manipulate Kerberos tickets.
  • Failure records showing a non-privileged process repeatedly trying to use SeTcbPrivilege or SeDebugPrivilege-protected services.

Investigation tips

  • Build a baseline of ProcessName + Service + PrivilegeList; triage new combinations.
  • Check the process path and signature, then pivot SubjectLogonId to 4688 for the command line.
  • Correlate with 4672 (special privileges at logon) and 4703 (privileges enabled in the token).

Sigma rules for this event

2 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 1
  • Medium · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading