Skip to content
Security

Event ID 4703: Token right adjusted

A token right was adjustedSecurity event 4703 logs privileges being enabled or disabled in an access token, such as a process turning on SeDebugPrivilege before touching LSASS.
4703
Event ID
4703
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Processes
Default logging
Needs configuration

What event 4703 means

Event 4703 is written when a process enables or disables privileges in a token through the AdjustTokenPrivileges API. Privileges held by a token are usually disabled until needed; enabling one is the moment the process prepares to use it. EnabledPrivilegeList and DisabledPrivilegeList show exactly what changed, and ProcessName shows who did it.

The classic example is SeDebugPrivilege: tools that read or inject into other processes' memory, including credential dumpers, enable it first. Other privileges worth watching are SeTakeOwnershipPrivilege, SeLoadDriverPrivilege, SeBackupPrivilege, SeRestorePrivilege and SeImpersonatePrivilege.

Available from Windows 10 / Server 2016. Volume can be very high because many services adjust privileges on every operation; Microsoft calls out Configuration Manager WMI activity through svchost.exe as a heavy source.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Detailed Tracking > Audit Token Right Adjusted (Success).

The Microsoft event page lists the subcategory as Audit Authorization Policy Change, while the Audit Token Right Adjusted page documents 4703 as its event; check both with auditpol. Windows 10 / Server 2016 and later only.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that requested the enable or disable operation.
SubjectLogonIdLogon session of the requester.
TargetUserNameAccount whose token was adjusted — usually the same as the subject.
TargetLogonIdLogon session of the adjusted token; pivot to 4624 and 4672.
ProcessNameProcess that adjusted its token. The key field for triage.
ProcessIdHexadecimal PID of that process.
EnabledPrivilegeListPrivileges that were enabled, space separated, or -.
DisabledPrivilegeListPrivileges that were disabled, or -.

Common benign sources

  • svchost.exe, services.exe and management agents enabling privileges as part of normal work.
  • Configuration Manager and other WMI-heavy tooling generating bursts of 4703.
  • Debuggers and administrative tools enabling SeDebugPrivilege for legitimate troubleshooting.

What attackers do that produces it

  • SeDebugPrivilege enabled by an unusual process (script host, binary in a temp or user folder) shortly before LSASS access — typical of credential dumping.
  • SeLoadDriverPrivilege enabled by a non-system process, preceding a malicious driver load.
  • SeTakeOwnershipPrivilege or SeRestorePrivilege enabled to take over protected files or keys.

Investigation tips

  • Exclude known system processes, then group by ProcessName and EnabledPrivilegeList.
  • Pivot on ProcessId and SubjectLogonId to 4688 for the command line and parent process.
  • Look for follow-on activity, such as 4656 handles on lsass.exe or Sysmon 10 process access.

MITRE ATT&CK techniques

TechniqueTactics
T1134 Access Token ManipulationStealth, Privilege Escalation
T1003.001 OS Credential Dumping: LSASS MemoryCredential Access

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading