Event ID 4703: Token right adjusted
- Event ID
- 4703
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Processes
- Default logging
- Needs configuration
What event 4703 means
Event 4703 is written when a process enables or disables privileges in a token through the AdjustTokenPrivileges API. Privileges held by a token are usually disabled until needed; enabling one is the moment the process prepares to use it. EnabledPrivilegeList and DisabledPrivilegeList show exactly what changed, and ProcessName shows who did it.
The classic example is SeDebugPrivilege: tools that read or inject into other processes' memory, including credential dumpers, enable it first. Other privileges worth watching are SeTakeOwnershipPrivilege, SeLoadDriverPrivilege, SeBackupPrivilege, SeRestorePrivilege and SeImpersonatePrivilege.
Available from Windows 10 / Server 2016. Volume can be very high because many services adjust privileges on every operation; Microsoft calls out Configuration Manager WMI activity through svchost.exe as a heavy source.
When it is logged
Advanced Audit Policy Configuration > Detailed Tracking > Audit Token Right Adjusted (Success).
The Microsoft event page lists the subcategory as Audit Authorization Policy Change, while the Audit Token Right Adjusted page documents 4703 as its event; check both with auditpol. Windows 10 / Server 2016 and later only.
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserName | Account that requested the enable or disable operation. |
| SubjectLogonId | Logon session of the requester. |
| TargetUserName | Account whose token was adjusted — usually the same as the subject. |
| TargetLogonId | Logon session of the adjusted token; pivot to 4624 and 4672. |
| ProcessName | Process that adjusted its token. The key field for triage. |
| ProcessId | Hexadecimal PID of that process. |
| EnabledPrivilegeList | Privileges that were enabled, space separated, or -. |
| DisabledPrivilegeList | Privileges that were disabled, or -. |
Common benign sources
svchost.exe,services.exeand management agents enabling privileges as part of normal work.- Configuration Manager and other WMI-heavy tooling generating bursts of 4703.
- Debuggers and administrative tools enabling
SeDebugPrivilegefor legitimate troubleshooting.
What attackers do that produces it
SeDebugPrivilegeenabled by an unusual process (script host, binary in a temp or user folder) shortly before LSASS access — typical of credential dumping.SeLoadDriverPrivilegeenabled by a non-system process, preceding a malicious driver load.SeTakeOwnershipPrivilegeorSeRestorePrivilegeenabled to take over protected files or keys.
Investigation tips
- Exclude known system processes, then group by
ProcessNameandEnabledPrivilegeList. - Pivot on
ProcessIdandSubjectLogonIdto 4688 for the command line and parent process. - Look for follow-on activity, such as 4656 handles on
lsass.exeor Sysmon 10 process access.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.